- August 24, 2026
- Sachin Aggrawal
- 0
Table of Content
- 1. What counts as an internal financial control under the Companies Act?
- 2. Which companies have to comply with internal financial controls India rules?
- 3. What is the board actually responsible for here?
- 4. What does the statutory auditor check under IFC audit s?
- 5. What framework should companies actually build on?
- 6. What happens when internal financial controls in India requirements aren't met?
- 7. Conclusion
Most Indian Company boards think they’ve handled this. They haven’t.Internal Financial Controls India, Section 134(5)(e) of the Companies Act 2013 asks directors to state, in writing, that internal financial controlsto be followed by the company and that such controls are adequate and were operating effectively.. Not that a policy document exists somewhere in a shared drive. That the controls operate.
That gap between “we have a policy” and “the policy is followed” is where audits fall apart. Internal financial controls in India isn’t a governance buzzword you sprinkle into an annual report. It’s a statutory declaration with a penalty attached if it turns out to be false, and an auditor sitting across the table checking whether it’s true.
What counts as an internal financial control under the Companies Act?
Section 134(5)names six things: orderly and efficient conduct of business, adherence to policies, safeguarding assets, prevention and detection of frauds and errors ,accurate accounting records, and timely preparation of reliable financial reporting.
That’s a wider than most CFOs assume. It’s not just about whether the ledger closes cleanly. Operational discipline counts. So does whether employees actually follow the policies written for them, not just whether the policies exist.
The word that trips people up is “effectively.” Plenty of companies can produce a binder: approval matrices, sign-off chains, delegation charts. What the law wants isevidence, that controls were operating effectively. An approval workflow that gets skipped every time someone’s in a hurry isn’t a working control, no matter how good it looks on paper.
Which companies have to comply with internal financial controls India rules?
Section 134(5)(e) expressly applies to listed companies. In addition, Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014 , requires every listed company, plus unlisted public companies to disclose in board report. . Private companies only if they’re subsidiaries of listed entities or fall into that prescribed bracket.
| Company Type | IFC Applies | Auditor Must Report |
| Listed Company | Yes, mandatory | Yes |
| Unlisted Public Company (prescribed) | Yes | Yes |
| Private Ltd, subsidiary of listed co | Yes | Yes |
| Private Ltd, standalone (prescribed) | Not mandatory | Depends on applicable exemptions |
| Small Company (Sec 2(85)) | Exempt | Exempt |
| One Person Company | Exempt | Exempt |
The small company carve-out arrived through the Companies (Amendment) Act 2017. Cross either threshold, paid-up capital above Rs. 10 crore or turnover above Rs. 100 crore, and the exemption disappears. For foreign-owned subsidiaries, as it falls under non-small Company, running lean, this is worth checking every year, not assuming once and forgetting.
What is the board actually responsible for here?
The board signs a statement claiming it built the controls, that they’re adequate, and that they work. Not a summary of what the auditor found. A claim the board makes on its own authority.
This is the part boards keep getting wrong. Signing the Directors’ Responsibility Statement isn’t a formality that happens after the CFO’s team quietly does the real work. The board can’t outsource the assertion and then rubber-stamp it.
What that signature is actually saying:
A documented framework exists covering all six elements from the Act
The framework fits how the company actually operates and where its risks sit
The controls run as designed, day to day, not just on paper
Significant control deficiencies are identified, evaluated and appropriately addressed.Listed companies get one more layer. Under SEBI’s LODR Regulations 2015, the CEO and CFO must certify to the board that any significant control deficiencies were disclosed to the auditor and audit committee. That certification is what the board’s statement rests on.
What does the statutory auditor check under IFC audits?
Under Section 143(3)(i), the auditor reports separately on whether internal financial controls over financial reporting were adequate and whether they operated effectively through the year, not just at closing.
This sits apart from the main audit opinion. It’s own paragraph, its own conclusion. The ICAI Guidance Note on Audit of Internal Financial Controls Over Financial Reporting (updated 2023) sets out how auditors get there, testing two things.
Design effectiveness: would this control, run correctly, actually catch a material error? A manual sign-off process built for paper invoices doesn’t transfer cleanly to an automated billing system just because someone copied the language across.
Operating effectiveness: does the control run as intended across the year, not just on the day the auditor shows up? That means sampling evidence from multiple points in the year, not a single snapshot.
Deficiencies auditors keep finding, year after year:
One person able to initiate, approve, and record the same transaction
Weak IT access controls, especially around who can change what
Missing review steps at period-end close
Revenue recognition controls that don’t match actual contract terms
Management overriding controls without documenting why
A material weakness pushes the audit report toward a qualified or adverse IFC conclusion. For listed companies, that carries regulatory weight beyond the report itself.
What framework should companies actually build on?
Most Indian companies build on COSO’s Internal Control Integrated Framework (2013), the same reference the ICAI Guidance Note points to. It’s not legally mandatory, but it’s what everyone expects to see.
COSO breaks controls into five pieces: control environment, risk assessment, control activities, information flow, and monitoring. The statute doesn’t require COSO by name. It requires the six elements under Section 134(5). COSO just happens to be the shared language auditors and audit committees use to talk about it.
Foreign-owned subsidiaries often start from the parent’s global framework, frequently SOX-based. That’s a reasonable starting point and a poor ending point. SOX was built for US GAAP and SEC reporting. Ind AS has its own logic. A framework lifted wholesale from the parent, without recalibrating for Indian accounting standards and the entity’s actual risk profile, tends to fail exactly where it matters.
What happens when internal financial controls in India requirements aren’t met?
Section 134(8) applies where there is a contravention of Section 134, such as:
- failure to comply with Board’s Report requirements;
- omission of mandatory disclosures;
- non-compliance with the Directors’ Responsibility Statement requirements.
- Penalty of Rs. 3 lakh for the company, Rs. 50,000 for each officer in default.
- That’s the statutory floor. The real cost usually runs deeper:
- Mandatory disclosure in the annual report
- The audit committee has to produce and defend a remediation plan
- Credit rating assessments can move
- It shows up in investor and lender due diligence, often at the worst time
- In case of Listed Company, SEBI can open an inquiry into whether it also breached LODR disclosure duties
Here’s the piece most foreign-owned subsidiaries miss entirely: a weakness found in the Indian entity can ripple back into the parent’s own consolidated controls reporting, if that parent is listed abroad and answers to its own internal controls regime.
Conclusion
Internal financial controls in India is a board obligation first, an audit deliverable second. The Directors’ Responsibility Statement carries directors’ names, not the CFO’s and not the internal audit head’s.The Board is responsible for establishing and maintaining internal financial controls, while the statutory auditor independently reports on them where required..
Most deficiencies trace back to the same root: a control framework built three years ago that never got updated as the business grew, systems changed, or new product lines came online. Controls that made sense then may not match the risk the company carries now.
Corporate Legit Consulting LLP works with Indian companies and foreign-owned subsidiaries on building internal financial controls in India frameworks, preparing for IFC audits, getting the Directors’ Responsibility Statement right, and remediating weaknesses auditors have already flagged. Talk to us before the audit cycle starts, not after the report lands.
Frequently Asked Questions
Section 134(5)(e) expressly applies to listed companies. In addition, Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014, requires unlisted public companies must comply with internal financial controls India requirements . Private Limited companies that are subsidiaries of listed entities or fall within the prescribed class are also required to comply. Small companies under Section 2(85) and One Person Companies are specifically exempted.
The board must confirm that it has laid down internal financial controls, that such controls are adequate for the company’s operations and risk profile, and that they are operating effectively. This is a statutory confirmation made by the Board itself and is independent of the statutory auditor’s opinion..
Under Section 143(3)(i) of the Companies Act 2013, the statutory auditor must report whether the company has adequate internal financial controls with reference to financial statements and whether those controls were operating effectively. This IFC audit India opinion appears as a separate paragraph in the statutory audit report and is independent of the main audit opinion on the financial statements.
A material weakness is a deficiency or combination of deficiencies in internal financial controls in India such that there is a reasonable possibility that a material misstatement in the financial statements would not be prevented or detected and corrected on a timely basis. When found, the auditor issues a qualified or adverse IFC opinion, the company must disclose it in the annual report, and the audit committee should evaluate and remediate the deficiency promptly.. For listed companies, SEBI may review the disclosure for LODR compliance.
The ICAI ‘s Guidance Note on Audit of Internal Financial Controls over Financial Reporting specifically recognises the COSO Internal Control Integrated Framework (2013) as an internationally accepted framework. Most Indian companies use COSO as the design and documentation framework for internal financial controls India. It organises controls across five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. Using COSO provides the taxonomy that auditors and audit committees expect when reviewing IFC documentation.