Practical framework for implementing and testing Internal Financial Controls over Financial Reporting (IFCoFR) in private limited manufacturing units under Section 134(5)(e).
Under Section 134(5)(e) and Section 143(3)(i) of the Companies Act, 2013, directors and statutory auditors must evaluate the adequacy and operating effectiveness of an enterprise's Internal Financial Controls over Financial Reporting (IFCoFR). For manufacturing SMEs in Raipur, Durg, and Bilaspur, implementing a structured IFC framework isn't just a box-ticking exercise for the auditor's report — it directly mitigates fraud risk, tightens inventory management, and supports clean statutory audit opinions year after year, rather than firefighting control gaps discovered late in the audit cycle.
1. Who This Applies To
Directors' responsibility under Section 134(5)(e) to state that IFC were laid down and operating effectively applies to companies preparing a Board's Report under the Act. The statutory auditor's separate reporting obligation under Section 143(3)(i) — to state whether the company has adequate internal financial controls with reference to the financial statements, and whether such controls were operating effectively — is subject to specific exemptions for certain smaller private companies (based on criteria such as turnover, borrowings, and paid-up capital thresholds prescribed under the applicable exemption notification), so the exact scope of the auditor's IFC reporting obligation should be confirmed against the company's current size classification each year, since crossing an exemption threshold brings the fuller reporting requirement into play.
2. Key Business Cycles Evaluated in IFC Audits
A comprehensive IFC audit establishes a Risk Control Matrix (RCM) across the core operational cycles of the business:
- Procure-to-Pay (P2P): Purchase requisition approval matrices, 3-way matching (Purchase Order vs Goods Receipt Note vs Vendor Invoice), vendor master vetting and periodic review, and payment authorisation limits mapped to approval hierarchy.
- Order-to-Cash (O2C): Customer credit limit sanctioning and periodic review, sales order verification against pricing/discount policy, gate-pass controls for dispatch, e-way bill generation compliance, and periodic debtor balance confirmations.
- Inventory & Production: Bill of Materials (BOM) yield tracking and variance analysis, physical stock counts against book records, scrap handling and disposal controls, and slow-moving/obsolete inventory identification and provisioning.
- Hire-to-Retire (Payroll): Biometric/attendance system reconciliation against payroll processing, PF/ESIC deduction and deposit controls, salary revision and incentive approval authority, and full-and-final settlement approvals on exit.
- Fixed Assets Management: Fixed Asset Register (FAR) tagging and reconciliation, periodic physical asset verification, capital expenditure authorisation limits, and depreciation schedule accuracy against the FAR.
- Financial Close & Reporting: Journal entry approval and review, bank reconciliation frequency and review, GST-vs-books reconciliation, and inter-branch/inter-unit balance matching for multi-location businesses.
3. Testing Design and Operating Effectiveness
For each control identified in the Risk Control Matrix, the auditor (and, for a well-run internal control function, the company itself in advance of the statutory audit) evaluates two distinct dimensions:
- Design Effectiveness: Is the control, as documented, actually capable of preventing or detecting a material error or fraud if it occurred? A control that exists on paper but has an obvious gap (e.g. an approval limit that can be bypassed by splitting a transaction into smaller amounts) fails design effectiveness even if it is followed perfectly.
- Operating Effectiveness: Did the control actually operate consistently throughout the financial year, as evidenced by digital audit trails, physical signatures/approvals, and genuine segregation of duties — not merely at year-end when management knows the auditor will test it, but across the full period under audit.
Typical testing methodology:
- Walkthrough: Trace a small number of transactions end-to-end through the process to confirm the control, as documented, is actually how the process works in practice.
- Sample testing: Select a representative sample of transactions across the year (not clustered in one period) and verify the control operated for each — approvals obtained, reconciliations performed and reviewed, exceptions followed up.
- Re-performance (for key controls): Independently re-execute the control (e.g. recompute a reconciliation) to confirm it produces the result the company's own control asserts.
4. Classifying and Remediating Deficiencies
Where testing identifies a gap, it is typically classified along a severity scale — a deficiency (a control did not operate as designed in an isolated instance), a significant deficiency (a deficiency or combination of deficiencies important enough to merit attention by those responsible for oversight), or a material weakness (a deficiency or combination severe enough that there is a reasonable possibility a material misstatement would not be prevented or detected on a timely basis). This classification directly affects what the auditor is required to communicate, and to whom (management, audit committee where applicable, or reflected in the auditor's report itself for the most serious findings).
Practical remediation approach: Rather than treating IFC findings as a once-a-year audit event, SME manufacturers benefit most from building the Risk Control Matrix into ongoing internal audit or management review cycles — testing key controls quarterly rather than discovering gaps only during year-end statutory audit fieldwork, when remediation options are limited and any material weakness has already existed uncorrected for most of the year.
Related Advisory Services & Practice Guides
- Access expert statutory assistance for Internal audit services with our senior Chartered Accountants.
- Access expert statutory assistance for Statutory audit consultation with our senior Chartered Accountants.
Calculate Your Exact Tax Liability (Old vs New Regime)
Compare the ₹75,000 standard deduction, ₹12.75L zero-tax threshold, and Chapter VI-A deductions for your exact income.
Need Direct CA Consultation in Raipur?
Connect with our partner-led practice at GF-28, Shyam Plaza, Pandri, Raipurfor GST advisory, Income Tax audit (Sec 44AB), Bank DPR & CMA Data, Company Registration, and Chhattisgarh Industrial Subsidies.
Authored by CA Rabi Agrawal & Practice Team
Rabi Agrawal & Associates, Chartered Accountants — Head Office Raipur (CG), Branch Office Jayapatna (Odisha).

