Internal Audit Services under Section 138 – Complete Risk-Based Audit Framework at ₹ 23,999

Hassle-free filing | Max Refunds | Expert Support
no-spamssecure-payment
Enter details to receive communications from Charteredone

Internal Audit Services under Section 138 – Complete Risk-Based Audit Framework

Mandatory Internal Audit for Eligible Companies under the Companies Act, 2013 with Structured Risk Assessment & Control Evaluation.

Medium-sized Private Company Starting at*

23,999

29999 (20% OFF)

Large Unlisted Public Company Starting at*

39,999

49999 (20% OFF)

Listed Companies Starting at*

55,999

69999 (20% OFF)

gauranteed

Satisfaction guaranteed or get your money-back Learn more.

5.0 Google reviews

Reviews 4,568 Execellent

4.5

About this plan

Our Internal Audit framework is designed to go beyond compliance. We focus on identifying operational inefficiencies, revenue leakages, control gaps, and compliance risks. Instead of routine checklist audits, we conduct structured risk-based reviews aligned with management objectives and board expectations.

The audit reports are structured, practical, and solution-driven — enabling promoters and directors to take informed strategic decisions.

divider

Applicability

docIcon

For Unlisted Public Companies:

docIcon

Paid-up share capital ≥ ₹50 crore

docIcon

Turnover ≥ ₹200 crore

docIcon

Outstanding loans/borrowings ≥ ₹100 crore

docIcon

Outstanding deposits ≥ ₹25 crore

docIcon

For Private Companies:

docIcon

Turnover ≥ ₹200 crore

docIcon

Outstanding loans/borrowings ≥ ₹100 crore

docIcon

For Listed Companies:

docIcon

Internal Audit mandatory irrespective of thresholds

divider

How It's Done

tick

Pre-Audit Risk Assessment

tick

Process Mapping

tick

Control Testing

tick

Transaction Sampling

tick

Compliance Review

tick

 Analytical Review

tick

Draft Report & Management Discussion

tick

Final Report with Risk Grading & Action Plan

divider

Documents Required

docIcon

MOA & AOA

docIcon

Latest audited financial statements

docIcon

Trial balance & general ledger

docIcon

GST returns (GSTR-1, 3B)

docIcon

TDS returns

docIcon

Bank statements

docIcon

Fixed asset register

docIcon

Inventory reports

docIcon

Loan agreements

docIcon

SOP documents (if available)

Internal Audit Services under Section 138 of the Companies Act, 2013: A Comprehensive Guide

Internal audit plays a vital role in strengthening corporate governance, risk management, and internal control systems. Recognizing its importance, the Companies Act, 2013 introduced specific provisions mandating internal audit for certain classes of companies under Section 138.

This article explains the legal framework, applicability, scope, and significance of internal audit services under Section 138 of the Companies Act, 2013.

divider

Legal Framework: Section 138 Overview

Section 138 of the Companies Act, 2013, read with Rule 13 of the Companies (Accounts) Rules, 2014, requires prescribed classes of companies to appoint an Internal Auditor.

The Internal Auditor may be:

  • A Chartered Accountant (CA)
  • A Cost Accountant (CMA)
  • Any other professional as decided by the Board

The objective is to evaluate internal financial controls, operational systems, risk management processes, and compliance mechanisms.

divider

Applicability of Internal Audit under Section 138

Internal audit is mandatory for:

1. Listed Companies: All listed companies are required to appoint an internal auditor.

2. Unlisted Public Companies, if any of the following criteria are met (based on preceding financial year):

  • Paid-up share capital of ₹50 crore or more
  • Turnover of ₹200 crore or more
  • Outstanding loans or borrowings from banks or public financial institutions of ₹100 crore or more
  • Outstanding deposits of ₹25 crore or more

3. Private Companies, if any of the following criteria are met:

  • Turnover of ₹200 crore or more
  • Outstanding loans or borrowings from banks or public financial institutions of ₹100 crore or more

Companies must assess applicability annually based on financial thresholds.

divider

Objective of Internal Audit under Section 138

The purpose of internal audit is not limited to compliance.

It aims to:

  • Evaluate adequacy of internal controls
  • Identify operational inefficiencies
  • Assess compliance with statutory requirements
  • Review risk management framework
  • Detect control weaknesses and potential fraud risks
  • Improve governance practices

Internal audit strengthens accountability and transparency within the organization.

divider

Scope of Internal Audit

The scope of internal audit is generally determined by the Board of Directors or Audit Committee.

It may include:

1. Financial Controls Review

  • Testing accounting systems
  • Reviewing revenue and expense processes
  • Evaluating internal financial controls

2. Operational Audit

  • Reviewing business processes
  • Assessing cost efficiency
  • Evaluating procurement and vendor management

3. Compliance Audit

  • Checking statutory compliance
  • Reviewing tax and regulatory filings
  • Ensuring adherence to Companies Act provisions

4. Risk-Based Audit

  • Identifying key business risks
  • Testing mitigation measures
  • Evaluating internal risk framework

5. IT & System Controls

  • ERP access control testing
  • Data security evaluation
  • System authorization checks

The audit scope may vary depending on industry and operational complexity.

divider

Internal Auditor Appointment & Reporting

The Board of Directors appoints the Internal Auditor through a board resolution.

In companies where Audit Committee is constituted, the committee typically oversees:

  • Internal audit plan
  • Scope of review
  • Reporting structure
  • Corrective action follow-up

Internal audit findings are usually reported to the Board or Audit Committee, ensuring independent oversight.

divider

Importance of Risk-Based Internal Audit

Modern internal audit practices are risk-based rather than checklist-based. A risk-based approach:

  • Identifies high-impact risk areas
  • Prioritizes audit focus
  • Improves resource allocation
  • Enhances governance standards

It shifts the role of internal audit from routine verification to strategic risk advisory.

divider

Consequences of Non-Compliance

Failure to appoint an internal auditor when required may attract:

  • Regulatory scrutiny
  • Penalties under the Companies Act
  • Corporate governance concerns
  • Adverse observations during statutory audit

Timely compliance ensures regulatory discipline and strengthens corporate credibility.

divider

Benefits of Effective Internal Audit Framework

A well-implemented internal audit system provides:

  • Improved internal control environment
  • Early detection of irregularities
  • Strengthened compliance culture
  • Reduced fraud risk
  • Improved operational efficiency

Better decision-making support Internal audit enhances not just compliance but long-term sustainability.

Internal Audit vs Statutory Audit

Internal Audit

  • Ingoing and risk-focused
  • Evaluates processes and controls
  • Reports to management/Board
  • Preventive in nature

Statutory Audit

  • Annual compliance requirement
  • Focuses on financial statements
  • Reports to shareholders
  • Detects material misstatements

Internal audit under Section 138 of the Companies Act, 2013 is a statutory mandate for specified classes of companies. However, its importance extends far beyond compliance.

A structured internal audit framework promotes accountability, risk management, financial accuracy, and operational discipline. In an evolving regulatory and business environment, internal audit serves as a crucial governance mechanism that safeguards organizational integrity and growth.

For companies meeting the prescribed thresholds, timely appointment and effective execution of internal audit is both a legal obligation and a strategic advantage.

Why Choose CharteredONE?

  • Chartered Accountant-led internal audit
  • Section 138 compliance expertise
  • Risk-focused approach
  • Independent and objective evaluation
  • Industry-specific audit framework
  • Pan India service delivery

Internal Audit is not merely statutory compliance — it is a governance enhancement tool.

If your company falls under Section 138 or is approaching threshold limits, a structured internal audit framework ensures compliance and operational stability. Engage

CharteredONE for professional internal audit services aligned with statutory requirements and business growth objectives.

Internal Audit under Section 138 is a statutory requirement applicable to certain classes of companies as prescribed under the Companies Act, 2013 and the Companies (Accounts) Rules, 2014. It requires eligible companies to appoint an internal auditor to evaluate the adequacy of internal controls, risk management systems, compliance mechanisms, and operational efficiency within the organization. The purpose is to strengthen governance and ensure systematic monitoring of business processes.

Internal Audit is not mandatory for all companies. It applies only to specific classes of companies based on financial thresholds such as turnover, paid-up share capital, borrowings, deposits, or listing status. Companies must evaluate their applicability each year based on the financial data of the preceding financial year.

All listed companies are required to appoint an internal auditor irrespective of their size. In addition, certain unlisted public companies and private companies that exceed prescribed limits relating to turnover or outstanding borrowings are also required to comply. Applicability must be determined as per Rule 13 of the Companies (Accounts) Rules, 2014.

An internal auditor may be a Chartered Accountant, a Cost Accountant, or any other professional as determined appropriate by the Board of Directors. The appointment is made by passing a board resolution, and the scope of work is typically defined by the Board or Audit Committee.

Internal Audit is an ongoing, risk-based review mechanism that focuses on evaluating internal processes, controls, and compliance systems. It reports to the management or Audit Committee and is preventive in nature. Statutory Audit, on the other hand, is an annual financial audit required under law to express an opinion on whether the financial statements present a true and fair view. It is conducted independently and reported to shareholders.

The scope of internal audit is generally determined by the Board of Directors or the Audit Committee. It may include review of financial controls, operational processes, statutory compliance, risk management framework, fraud risk assessment, and system control evaluation. The scope may vary depending on the nature and size of the company.

While the law mandates appointment of an internal auditor, it does not prescribe a fixed frequency for conducting audits. In practice, companies conduct internal audits quarterly, half-yearly, or annually depending on size, complexity, and risk exposure. Larger companies typically follow a quarterly audit cycle for better governance.

Failure to comply with Section 138 may result in regulatory penalties under the Companies Act. Non-compliance may also raise concerns during statutory audits, regulatory inspections, or investor due diligence, thereby affecting corporate credibility and governance perception.

Internal Audit may include review and testing of internal financial controls as part of its broader scope. However, the statutory reporting on Internal Financial Controls under Section 134(5) and the auditor’s report on IFC are separate legal requirements.

Yes, companies may appoint external professionals or firms to conduct internal audit. Outsourcing is common as it ensures independence, objectivity, and access to specialized expertise while maintaining compliance with statutory requirements.

If a company meets the prescribed threshold criteria in a financial year, it is required to comply in the subsequent year. The requirement continues as long as the company remains within the prescribed limits as per the rules.

Internal Audit provides management with an independent evaluation of internal controls and operational systems. It helps identify weaknesses, mitigate risks, improve efficiency, strengthen compliance, and enhance overall corporate governance. It acts as an early warning mechanism for potential issues before they become significant problems.

6300347380