Implement Section 138 internal audit and Section 134(5)(e) Internal Financial Controls (IFC). Prevent financial fraud and ensure MCA compliance.
As private limited companies and unlisted public entities scale across Central India — from the heavy industrial hubs of Urla, Bhanpuri, and Siltara in Raipur to the steel fabrication belts of Durg-Bhilai and the agro-processing clusters in Kalahandi and Jayapatna — operational complexities expand exponentially. Rapid growth brings higher transaction volumes, multi-location supply chains, decentralized purchasing, and complex inventory movement.
Without robust internal controls, top-line growth frequently fails to translate into bottom-line profitability. Unmonitored scrap leakages, unverified weighbridge entries, unauthorized price discounts, split purchase orders, and ghost payroll entries quietly erode cash flows.
In our practice at Rabi Agrawal & Associates, we frequently see promoter-driven businesses focus intensely on statutory tax compliance while treating internal financial controls as an afterthought. However, the Companies Act, 2013 shifts significant responsibility onto company directors and management to establish, document, and test their Internal Financial Controls (IFC). additionally, Section 138 makes internal audit mandatory for specified classes of companies, while CARO 2020 Clause 3(xiv) requires statutory auditors to explicitly evaluate and comment on the internal audit system.
This practical advisory guide breaks down the legal mandates, control design principles, risk mitigation frameworks, and practical execution strategies necessary to build an ironclad internal control system tailored for growing enterprises.
1. Mandatory Internal Audit Thresholds under Section 138
Section 138 of the Companies Act, 2013, read with Rule 13 of the Companies (Accounts) Rules, 2014, mandates the appointment of an Internal Auditor for specified classes of companies. The internal auditor may be a Chartered Accountant, Cost Accountant, or such other professional as decided by the Board.
The statutory applicability thresholds are determined based on the financial figures of the preceding financial year:
| Entity Classification | Paid-Up Share Capital | Turnover Threshold | Outstanding Loans / Borrowings from Banks & FIs | Outstanding Deposits |
|---|---|---|---|---|
| Listed Companies | Mandatory for all listed entities | Mandatory | Mandatory | Mandatory |
| Unlisted Public Companies | ≥ ₹50 Crores | ≥ ₹200 Crores | ≥ ₹100 Crores (at any point during FY) | ≥ ₹25 Crores (at any point during FY) |
| Private Limited Companies | Not Applicable | ≥ ₹200 Crores | ≥ ₹100 Crores (at any point during FY) | Not Applicable |
Key Regulatory Nuances to Remember:
- Preceding Year Test: The applicability must be evaluated based on the audited financial statements of the immediately preceding financial year. For instance, for FY 2026-27, applicability is judged based on figures as of March 31, 2026.
- Borrowing & Deposit Timing: The ₹100 Crore borrowing limit and ₹25 Crore deposit limit apply if the threshold is touched at any point of time during the preceding financial year, even if the balance was subsequently repaid before year-end.
- Voluntary Internal Audit for MSMEs: Even if your private limited company falls below the ₹200 Crore turnover or ₹100 Crore borrowing threshold, conducting voluntary internal audits is a proven risk management practice. Mid-market manufacturing plants with turnovers between ₹25 Crore and ₹150 Crore often experience higher percentage operational leakages due to informal control environments than larger corporates with standardized ERP systems.
2. The Legal IFC Framework: Section 134(5)(e) vs. Section 143(3)(i)
The Companies Act, 2013 introduces two distinct dimensions of Internal Financial Controls (IFC):
text ┌────────────────────────────────────────────────────────┐ │ Internal Financial Controls (IFC) │ └───────────────────────────┬────────────────────────────┘ │ ┌─────────────────────────────────┴─────────────────────────────────┐ │ │ ▼ ▼ ┌─────────────────────────────────────────┐ ┌─────────────────────────────────────────┐ │ Section 134(5)(e): Directors' Mandate │ │ Section 143(3)(i): Auditor's Reporting │ │ Applies to: Listed Companies (Extended │ │ Applies to: All Companies (Excluding │ │ to non-listed via good governance) │ │ OPC & Small Companies) │ │ Scope: Broad Financial & Operational │ │ Scope: Internal Financial Controls Over │ │ Controls (Policies, Efficiency, Assets) │ │ Financial Reporting (ICOFR) │ └─────────────────────────────────────────┘ └─────────────────────────────────────────┘ ### Directors' Responsibility under Section 134(5)(e)
For listed companies (and increasingly expected by lenders, private equity investors, and statutory auditors for large unlisted entities), the Board of Directors must state in the Director’s Responsibility Statement that:
"The directors had laid down internal financial controls to be followed by the company and that such internal financial controls are adequate and were operating effectively."
Under Section 134(5)(e), Internal Financial Controls mean the policies and procedures adopted by the company for ensuring:
- The orderly and efficient conduct of its business, including adherence to company policies.
- The safeguarding of its assets against loss or unauthorized use.
- The prevention and detection of frauds and errors.
- The accuracy and completeness of the accounting records.
- The timely preparation of reliable financial information.
Statutory Auditor's Reporting under Section 143(3)(i)
Statutory auditors are required to report whether the company has an adequate Internal Financial Controls over Financial Reporting (ICOFR) system in place and the operating effectiveness of such controls as of the balance sheet date.
3. Designing Internal Control Systems: DOA Matrix & Segregation of Duties
An effective control environment relies on two fundamental structural pillars: a clear Delegation of Authority (DOA) matrix and strict Segregation of Duties (SoD).
A. Delegation of Authority (DOA) Matrix
A DOA matrix specifies who can authorize transactions, sign contracts, release payments, and approve discounts across different monetary thresholds. Without a documented DOA, lower-level employees make unauthorized commitments, or senior management becomes bogged down approving minor routine purchases.
Sample Operational DOA Framework for a Manufacturing Unit:
| Transaction Type | Tier 1: Store/Dept Manager | Tier 2: Plant Head / GM | Tier 3: CFO / VP Finance | Tier 4: Managing Director |
|---|---|---|---|---|
| Purchase Requisition (PR) | Up to ₹50,000 | Up to ₹5,00,000 | Up to ₹25,00,000 | Above ₹25,00,000 |
| Purchase Order (PO) Approval | Up to ₹25,000 | Up to ₹2,00,000 | Up to ₹10,00,000 | Above ₹10,00,000 |
| Vendor Payment Approval | N/A | Up to ₹1,00,000 (Budgeted) | Up to ₹10,00,000 | Above ₹10,00,000 & Non-Budgeted |
| Scrap Disposal Approval | N/A | Up to ₹50,000 | Up to ₹5,00,000 | Above ₹5,00,000 |
| Customer Credit Extension | Standard terms (30 days) | Up to 45 days | Up to 60 days | Above 60 days / Special Limit |
B. Segregation of Duties (SoD) & Eliminating Conflict of Interest
Segregation of duties ensures that no single individual controls all stages of a transaction. A robust control framework mandates that key functions — Authorization, Custody, Recording, and Reconciliation — are separated.
Classic SoD Violations Identified in Ground Audits:
- Procurement Vulnerability: The purchasing manager selects the supplier, negotiates rates, creates the PO, inspects goods at the factory gate, and approves vendor invoices for payment. Mitigation: Require procurement, gate entry verification, and invoice accounting to be performed by separate employees with maker-checker controls in Tally/SAP.
- Treasury Vulnerability: The cashier handles physical cash collections, records cash ledger entries in ERP, and performs monthly bank reconciliations. Mitigation: Assign bank reconciliation verification to an independent accounts executive who does not handle cash or sign cheques.
- Master Data Manipulation: Sales executives have access rights to alter customer master records, credit limits, and bank details in the accounting system. Mitigation: Lock master data editing rights strictly to the central finance team upon written approval from the CFO.
4. Ground Reality: Operational Leakages in Regional Manufacturing & Processing
Ground experience across industrial clusters in Chhattisgarh and Odisha reveals distinct operational vulnerabilities that statutory financial audits often fail to spot:
text ┌──────────────────────────────────────────────────────────────────────────────────┐ │ High-Risk Operational Leakage Vectors │ ├───────────────────────────────┬──────────────────────────────────────────────────┤ │ Steel Rerolling & Sponge Iron │ Unrecorded burning loss, scrap cash sales, │ │ (Urla, Bhanpuri, Durg) │ digital weighbridge manual overrides. │ ├───────────────────────────────┼──────────────────────────────────────────────────┤ │ Rice Milling & Processing │ Outturn ratio variance, husk/bran bypass, │ │ (Kalahandi, Jayapatna) │ moisture weight loss manipulation. │ ├───────────────────────────────┼──────────────────────────────────────────────────┤ │ PWD Civil Contractors │ Fuel consumption theft, transit material loss, │ │ (Raipur, Bhilai, Korba) │ unverified site storage registers. │ └───────────────────────────────┴──────────────────────────────────────────────────┘ ### 1. Steel Rerolling & Sponge Iron Plants (Raipur & Durg-Bhilai Belt)
- Burning Loss & Yield Variance: In steel rerolling mills, actual raw material (billet/ingot) to finished goods (TMT/structural steel) yields must be benchmarked against standard technical norms. Deviations exceeding standard burning loss tolerances often hide unbilled cash sales of finished goods or unaccounted scrap dispatches.
- Weighbridge Manipulations: Inbound scrap and iron ore trucks are weighed at the factory gate. Manual weighbridge software allows operators to manipulate tare or gross weights, leading to payment for phantom weights. Control Solution: Install digital weighbridge systems integrated directly into ERP with automatic serial photo-capture and zero-manual-entry protocols.
2. Rice Mills & Agro-Processing Units (Kalahandi & Jayapatna Region)
- Custom Milling Outturn Ratios (CMR): Paddy processing requires strict monitoring of Outturn Ratios (normative 67% for raw rice, 68% for parboiled rice). Gaps between actual outturn recovery and government norms signal unrecorded commercial sales of rice, broken rice, or rice bran.
- By-Product Realization Controls: Rice husk and de-oiled rice bran sales are frequently conducted on cash terms. Absence of pre-numbered gate passes and weighbridge cross-verification leads to unrecorded revenue leakage.
3. PWD Civil Infrastructure & Mining Contractors
- Material Consumption Mismatches: High-value raw materials (cement, rebar, bitumen, diesel) issued to project sites across Chhattisgarh and Odisha must be reconciled monthly against running account (RA) bill quantities.
- Equipment Fuel Theft: Diesel consumed by heavy machinery (excavators, tippers, loaders) should be tracked using hourly run-time logs (GPS/engine hours) versus fuel drawn, isolating fuel diversion at remote sites.
5. ASCII Flowchart: Internal Audit Execution & Management Reporting Cycle
The internal audit lifecycle is an interactive, continuous feedback process. The flowchart below outlines the systematic workflow from risk scoping to Audit Committee oversight:
text ┌────────────────────────────────────────────────────────────────────────┐ │ 1. RISK ASSESSMENT & ANNUAL AUDIT PLAN │ │ Identify key process areas, regulatory thresholds, & past audit gaps │ └───────────────────────────────────┬────────────────────────────────────┘ │ ▼ ┌────────────────────────────────────────────────────────────────────────┐ │ 2. SCOPING & PROCESS WALKTHROUGH │ │ Document current SOPs, map transaction flows, & review DOA controls │ └───────────────────────────────────┬────────────────────────────────────┘ │ ▼ ┌────────────────────────────────────────────────────────────────────────┐ │ 3. SAMPLE TESTING & CAAT DATA ANALYTICS │ │ Perform sub-ledger testing, 3-way matching, & ERP duplicate checks │ └───────────────────────────────────┬────────────────────────────────────┘ │ ▼ ┌────────────────────────────────────────────────────────────────────────┐ │ 4. FIELDWORK & PHYSICAL VERIFICATION │ │ Surprise cash counts, inventory spot-checks, & weighbridge audits │ └───────────────────────────────────┬────────────────────────────────────┘ │ ▼ ┌────────────────────────────────────────────────────────────────────────┐ │ 5. DRAFT FINDINGS & PROCESS OWNER DISCUSSION │ │ Validate observations with department heads & obtain management responses│ └───────────────────────────────────┬────────────────────────────────────┘ │ ▼ ┌────────────────────────────────────────────────────────────────────────┐ │ 6. ISSUE FINAL INTERNAL AUDIT REPORT & CAP │ │ Categorize findings (High/Medium/Low) & issue Corrective Action Plan │ └───────────────────────────────────┬────────────────────────────────────┘ │ ▼ ┌────────────────────────────────────────────────────────────────────────┐ │ 7. REPORTING TO AUDIT COMMITTEE / BOARD OF DIRECTORS │ │ Present audit dashboard, critical control deficiencies, & recommendations│ └───────────────────────────────────┬────────────────────────────────────┘ │ ▼ ┌────────────────────────────────────────────────────────────────────────┐ │ 8. REMEDIATION TRACKING & QUARTERLY IMPLEMENTATION AUDIT │ │ Monitor aging of open audit points & verify corrective actions taken │ └────────────────────────────────────────────────────────────────────────┘ ---
6. Comprehensive Checklist: Core Internal Audit Areas & Risk Controls
To ensure complete coverage during internal audit engagements, audit teams and internal controllers must evaluate controls across six core enterprise functions:
| Audit Domain | Key Operational Risks | Mandatory Internal Controls | Verification Procedure |
|---|---|---|---|
| Procure-to-Pay (P2P) | Ghost vendors, inflated pricing, split POs, duplicate payments. | Mandatory 3-way match (PO, GRN, Tax Invoice); vendor onboarding verification; ERP price master locks. | Sample test vendor payments against POs; run CAAT queries for duplicate GSTINs/bank accounts. |
| Order-to-Cash (O2C) | Unauthorized credit, unbilled dispatches, bad debt accumulation, manual price overrides. | System-enforced credit limits; gated dispatches tied to billing; customer balance confirmations. | Reconcile dispatch register with GST GSTR-1 sales registers; audit aging accounts >180 days. |
| Inventory & Stores | Theft, scrap leakage, unrecorded wastage, phantom weighbridge entries. | Perpetual inventory counting; digital weighbridge ERP integration; serial gate passes. | Conduct surprise physical counts; calculate raw material yield ratios against production logs. |
| Hire-to-Retire (H2R) | Ghost employees, incorrect OT payouts, statutory non-compliance (PF/ESIC). | Biometric attendance integration with payroll; HR approval for master additions; monthly PF/ESIC reconciliation. | Cross-check salary disbursements against bank payout lists and biometric logs; verify ECR filings. |
| Treasury & Cash | Cash misappropriation, unauthorized bank transfers, delayed cheque deposits. | Dual-authorization for online banking; daily cash limit enforcement; monthly independent bank reconciliations. | Perform physical cash vault counts; inspect bank reconciliation statements for long-pending items. |
| Fixed Assets & CapEx | Unrecorded asset disposal, idle machinery, capital expenditure misclassification. | Fixed asset register (FAR) linked to physical tagging (barcode/QR); physical verification schedule; CapEx DOA approvals. | Verify physical existence of high-value plant machinery; match CapEx invoices with DOA approvals. |
7. CARO 2020 Reporting: Clause 3(xiv) Scrutiny
Under the Companies (Auditor’s Report) Order, 2020 (CARO 2020), statutory auditors are subject to enhanced reporting obligations regarding a company's internal audit system under Clause 3(xiv):
Clause 3(xiv)(a): Adequacy of Internal Audit System
"Whether the company has an internal audit system commensurate with the size and nature of its business."
Statutory auditors must assess whether the internal audit scope, coverage, professional competence of audit staff, and frequency of audits are aligned with the scale of the company's operations. Merely appointing an internal auditor on paper without conducting comprehensive fieldwork or issuing formal reports will result in adverse comments in the CARO report.
Clause 3(xiv)(b): Consideration of Internal Audit Reports
"Whether the reports of the Internal Auditors for the period under audit were considered by the statutory auditor."
Statutory auditors must formally review all internal audit reports issued during the financial year. Key audit observations—such as significant inventory shortfalls, internal control breakdowns, or unrecovered advances—must be evaluated by the statutory auditor to determine their impact on financial statements and ICOFR reporting under Section 143(3)(i).
8. Practical Implementation Roadmap for Enterprise Boards
Building an effective Internal Financial Control framework does not require halting operational momentum. Growing companies can execute a structured 90-day implementation plan:
``text Month 1: Process Mapping & Risk Identification ├── Map core business cycles (P2P, O2C, Inventory, Payroll, Finance). ├── Document Standard Operating Procedures (SOPs) for all key functions. └── Identify high-risk gaps and lack of segregation of duties (SoD).
Month 2: Control Design & ERP Automation ├── Draft and formalize the Delegation of Authority (DOA) matrix. ├── Implement maker-checker authorization controls inside Tally/SAP/Busy. └── Integrate digital controls (weighbridge integration, biometric attendance).
Month 3: Internal Audit Deployment & Monitoring ├── Appoint qualified Internal Auditors under Section 138. ├── Establish quarterly reporting to the Audit Committee / Board. └── Create a Corrective Action Plan (CAP) tracker to remediate audit gaps.
Strategic Governance with Rabi Agrawal & Associates
At Rabi Agrawal & Associates, our Risk Advisory & Internal Audit practice delivers tailored internal audit solutions, IFC framework reviews, SOP drafting, and fraud risk reviews for growing enterprises across Central India.
Whether you operate a steel rerolling mill in Urla, a rice processing plant in Kalahandi, a civil contracting firm in Durg, or a multi-branch retail network in Raipur, our team brings deep practical experience to plug operational leakages, strengthen corporate governance, and ensure smooth compliance with Section 138, Section 134(5)(e), and CARO 2020 requirements.
Work With Our Senior Risk Advisory Team:
- Raipur Head Office: Commercial & Industrial Advisory Cell, Raipur, Chhattisgarh.
- Kalahandi Branch: Regional Compliance & Audit Desk, Jayapatna / Bhawanipatna, Odisha.
- Direct Consultation: Contact our senior partners for an initial control framework assessment and internal audit scope review.
Related Advisory Services & Practice Guides
- Access expert statutory assistance for Internal audit services in Raipur with our senior Chartered Accountants.
- Access expert statutory assistance for Statutory audit consultation with our senior Chartered Accountants.
Calculate Your Exact Tax Liability (Old vs New Regime)
Compare the ₹75,000 standard deduction, ₹12.75L zero-tax threshold, and Chapter VI-A deductions for your exact income.
Need Direct CA Consultation in Raipur?
Connect with our partner-led practice at GF-28, Shyam Plaza, Pandri, Raipurfor GST advisory, Income Tax audit (Sec 44AB), Bank DPR & CMA Data, Company Registration, and Chhattisgarh Industrial Subsidies.
Authored by CA Rabi Agrawal & Practice Team
Rabi Agrawal & Associates, Chartered Accountants — Head Office Raipur (CG), Branch Office Jayapatna (Odisha).

