Audit

Internal Financial Controls (IFC) in India: Practical Guide to RCM, Testing and Audit Readiness

A practical guide to internal financial controls with reference to financial statements, including risk-control matrices, design and operating-effectiveness testing, documentation and the difference from internal audit.

Internal Financial Controls (IFC) in India: Practical Guide to RCM, Testing and Audit Readiness

Internal financial controls with reference to financial statements (IFC-FS) are not the same thing as an internal audit. For Indian companies, the distinction matters because the Companies Act, 2013 places specific responsibilities on management and, where applicable, requires the statutory auditor to report on the adequacy and operating effectiveness of these controls.

Section 143(3)(i) of the Companies Act requires the auditor's report to state whether the company has adequate internal financial controls with reference to financial statements in place and whether those controls operated effectively. The statutory wording can be checked on India Code's Section 143 page. ICAI also publishes a dedicated Guidance Note on Audit of Internal Financial Controls Over Financial Reporting.

What does IFC-FS actually mean?

In practical terms, IFC-FS focuses on controls that support reliable financial statements. These are the processes and control activities designed to reduce the risk that material errors or fraud-related misstatements enter the financial statements without being prevented or detected in time.

Typical examples include approval controls over journal entries, three-way matching for purchases, controls over creation and modification of vendors, bank reconciliations, access controls over accounting systems, review of estimates, inventory controls and period-end financial-close controls.

IFC-FS versus internal audit

The two functions can overlap in the processes they examine, but their objectives are different. IFC-FS is a financial-reporting control framework and the statutory auditor's reporting obligation arises from company law where applicable. Internal audit is a broader assurance and advisory activity that may review operational efficiency, compliance, risk management, fraud risk, governance and financial controls.

A company can therefore have a strong internal audit function and still have weaknesses in IFC-FS. Conversely, a company can document key financial-reporting controls well but have an internal audit plan that covers much wider business risks.

A practical way to build an IFC-FS framework

  1. Define significant financial statement areas: start with material account balances, disclosures and transaction streams such as revenue, purchases, payroll, inventory, fixed assets, treasury and financial close.
  2. Identify the risks: ask what could cause a material misstatement in each process. For revenue, for example, risks may include fictitious sales, incorrect cut-off, wrong pricing or unrecorded credit notes.
  3. Map controls to each risk: document the control owner, frequency, evidence generated, systems used and the assertion addressed.
  4. Separate key controls from routine activities: not every process step is a key control. Focus on controls whose failure could reasonably allow a material misstatement to go undetected.
  5. Evaluate design: determine whether the control, if performed as described, is capable of addressing the identified risk.
  6. Test operating effectiveness: obtain evidence that the control actually operated consistently during the relevant period.
  7. Evaluate deficiencies: assess control failures individually and in combination, including their potential effect on financial reporting.

Example: revenue process

Suppose a company sells goods on credit. One financial-reporting risk is that sales may be recorded before dispatch merely to improve year-end revenue. A control could require the finance team to recognise revenue only after matching the sales invoice to dispatch evidence and to perform a specific cut-off review around year-end.

Documenting the control is only the first step. Testing should establish whether the required evidence existed, whether the review occurred at the specified frequency, who performed it, whether exceptions were investigated and whether the control operated throughout the period selected for testing.

What should an IFC risk-control matrix contain?

  • process and subprocess;
  • financial statement risk and relevant assertion;
  • control description and control objective;
  • control owner and reviewer;
  • frequency, such as daily, monthly or event-driven;
  • manual, automated or IT-dependent nature of the control;
  • evidence retained by the company;
  • whether the control is considered key;
  • design and operating-effectiveness testing performed; and
  • deficiencies, remediation owner and target date.

Entity-level and IT controls matter too

IFC-FS should not be reduced to transaction checklists. Entity-level controls can influence many financial statement areas at once. Examples include governance over financial reporting, delegation of authority, management review controls, fraud-risk processes and oversight of the financial close.

IT controls are also important where financial reporting depends on systems. User access, privileged access, program changes, interfaces and automated calculations can affect whether application controls and system-generated reports are reliable.

Smaller companies still need a proportionate approach

A smaller company may achieve effective control with fewer people, more direct owner-management review and less complex systems, but the control still needs to address the financial-reporting risk and produce sufficient evidence. ICAI's Implementation Guide for smaller, less complex companies specifically supplements the main Guidance Note and addresses practical difficulties in such audits.

Common IFC documentation mistakes

  • Copying a generic RCM: controls should reflect the company's actual processes, systems and risks.
  • Confusing a policy with a control: a written policy does not prove that a review or approval operated.
  • No evidence of review: a control described as 'management reviews monthly' is difficult to test if the review leaves no identifiable evidence.
  • Ignoring IT dependencies: a manual review may depend on a system report whose completeness and accuracy also need consideration.
  • Testing only year-end: a recurring control generally needs evidence across the period relevant to the audit approach.
  • Closing deficiencies informally: remediation should be documented and, where necessary, retested.

Management's role versus the statutory auditor's role

Management is responsible for establishing and maintaining the company's controls. The statutory auditor independently evaluates the controls for the purpose of the applicable reporting requirement; the auditor should not become the owner of the controls being audited. ICAI's Guidance Note explains the audit approach, including planning, identifying significant accounts and disclosures, understanding likely sources of misstatement, testing controls and evaluating deficiencies.

Practical takeaway

A useful IFC-FS framework begins with financial statement risks, not with a long control checklist. Map material risks to specific controls, identify accountable owners, retain evidence, test whether controls are suitably designed and actually operating, and track deficiencies to remediation. Keep internal audit and IFC-FS connected but conceptually separate: internal audit can examine the wider business, while IFC-FS is specifically anchored to reliable financial reporting and the applicable Companies Act reporting framework.

Related Articles

Subscribe To Our Newsletter

Subscribe us to get updates on latest Jobs Openings, News, Articles, Notices/ Circulars

Submit

© 2026 CA Samaaj. All rights reserved.

Join Whatsapp Group of CA Samaaj