How to Conduct Internal Financial Controls Testing Under Section 143 of the Companies Act 2013
- Kaustav Chowdhury

- 2 hours ago
- 5 min read
Internal Financial Controls (IFC) testing is a statutory obligation embedded in the Companies Act, 2013 through two key provisions. Section 134(5)(e) requires the board of directors to confirm in the Board Report that they have laid down internal financial controls and that such controls are adequate and operating effectively. Section 143(3)(i) requires the statutory auditor to report on whether the company has adequate internal financial controls with reference to financial statements and whether such controls are operating effectively. For companies to which IFC reporting applies, failure to establish, test, and maintain these controls can result in audit qualifications, regulatory scrutiny, and personal liability for directors. This guide provides a structured approach to conducting IFC testing, from scoping and control identification through design testing, operating effectiveness testing, and documentation of findings.
Step 1: Determine Applicability and Scope
IFC reporting under Section 143(3)(i) applies to all companies except those exempted by MCA notification. The exempted categories include One Person Companies, small companies, and private companies that have a turnover of less than Rs 50 crore as per the latest audited financial statements and aggregate borrowings from banks and financial institutions of less than Rs 25 crore at any point during the preceding financial year. Both conditions must be met simultaneously for the exemption to apply. If the company is listed, IFC reporting is mandatory regardless of size or any other threshold.
The scope of IFC testing covers all internal controls that have a bearing on financial reporting. This includes controls over the recording of transactions, maintenance of books of account, preparation of financial statements in accordance with applicable accounting standards, safeguarding of assets, and prevention and detection of fraud. The testing scope should extend to entity-level controls (such as the control environment, risk assessment processes, and monitoring activities) as well as process-level controls for each significant financial process. The ICAI Guidance Note on Audit of Internal Financial Controls Over Financial Reporting provides the authoritative framework for scoping the IFC audit.
Step 2: Map Financial Processes and Identify Key Controls
Begin by identifying all business processes that have a material impact on the financial statements. Common processes include revenue recognition and accounts receivable, procurement and accounts payable, payroll and employee benefits, inventory management, fixed asset accounting, treasury and cash management, tax compliance and provisioning, and the financial close and reporting process. For each process, prepare a detailed process narrative or flowchart that documents the flow of transactions from initiation through recording, processing, and reporting in the financial statements.
Within each process, identify the key controls that prevent or detect material misstatements. Controls may be manual (such as management review and approval of journal entries), automated (such as system-enforced segregation of duties or three-way matching in procurement), or IT-dependent (such as access controls in the ERP system). Document each control with a unique identifier, the control objective it serves, the frequency of operation (transaction-level, daily, weekly, monthly, quarterly, or annual), and the person or system responsible for performing the control. This documentation forms the Risk and Control Matrix (RCM) that is the foundation for all subsequent testing.
Step 3: Evaluate Control Design (Design Effectiveness Testing)
Design effectiveness testing asks whether each identified control, if operating as designed, would be sufficient to prevent or detect a material misstatement. This is a conceptual evaluation, not a test of actual operation. For each control, assess whether it addresses the relevant assertion (completeness, existence, accuracy, valuation, rights, or presentation), whether it is performed by a person with adequate authority and competence, whether the control is positioned at the right point in the process to catch errors before they flow into the financial statements, and whether compensating controls exist if a single control is not sufficient on its own.
Where design gaps are identified, the company must remediate them before the controls can be tested for operating effectiveness. Common design deficiencies include lack of segregation of duties in small teams, absence of documented approval thresholds for journal entries or payment authorisations, and reliance on informal or verbal controls without documented evidence. Each design gap should be classified by severity as a deficiency, significant deficiency, or material weakness and reported to the audit committee. Material weaknesses in design must be remediated before the auditor can issue an unqualified opinion on IFC.
Step 4: Test Operating Effectiveness
Operating effectiveness testing determines whether each control is functioning as designed in practice throughout the testing period. The primary testing procedures include inquiry (interviewing the control performer), observation (watching the control being performed), inspection (reviewing documentary evidence such as approvals, reconciliations, and review sign-offs), and re-performance (independently performing the control and comparing the result). For most controls, inspection and re-performance provide the strongest audit evidence and should be the primary methods used.
Sample sizes for operating effectiveness testing depend on the frequency of the control. For controls that operate multiple times per day (such as transaction approvals), a sample of 25 to 60 items is typical for the testing period. For daily controls, 20 to 40 items may be tested. For weekly controls, a sample of 5 to 15 is common. Monthly controls may require testing all 12 instances, and quarterly and annual controls should be tested for every instance during the year. If any exception is found in the sample, the tester must evaluate whether the control failure represents an isolated deviation or a systemic breakdown, expand the sample if necessary, and determine whether compensating controls mitigate the risk of material misstatement.
Step 5: Document Findings and Prepare the IFC Report
All IFC testing work must be thoroughly documented in a manner that enables the statutory auditor to place reliance on it for the purpose of reporting under Section 143(3)(i). The documentation package should include the Risk and Control Matrix for each process, walkthrough narratives and flowcharts, design effectiveness assessments with conclusions, operating effectiveness test plans with sample selection methodology, detailed test results for each control tested, exception logs with root cause analysis and remediation status, and a summary report classifying all identified issues by severity level.
The IFC report should be presented to the audit committee before the statutory auditor finalises the audit report. Where material weaknesses are identified, the auditor must issue a qualified or adverse opinion on IFC in the audit report. The company's management should prepare a remediation plan with specific timelines for each identified weakness and present this plan to the board for approval and monitoring. Going forward, the IFC framework should be treated as a continuous process rather than a year-end exercise, with controls being monitored and tested throughout the year to ensure sustained operating effectiveness and to identify emerging risks promptly.
Key Compliance Points and Common Mistakes
Applying the IFC exemption for private companies without verifying both conditions (turnover under Rs 50 crore and borrowings under Rs 25 crore from banks and financial institutions), which must be met simultaneously for the exemption to apply
Limiting IFC testing to financial close controls and ignoring upstream process-level controls in revenue, procurement, payroll, and inventory that feed into the financial statements
Relying on inquiry alone as a testing procedure without corroborating findings with inspection or re-performance, which provides weak audit evidence under SA 330
Failing to test IT general controls such as access management, change management, and data backup that underpin the reliability of all automated application controls in the ERP system
Not classifying identified deficiencies by severity (deficiency, significant deficiency, or material weakness), which is required for proper reporting to the audit committee and in the statutory auditor's report
Treating IFC testing as a one-time annual exercise rather than integrating control monitoring into ongoing business operations throughout the financial year
Related Reading
How to Conduct an Internal Investigation for Corporate Fraud Under Section 447 of the Companies Act
How to Set Up a Compliance Calendar for a Private Limited Company in India
How to Comply with SEBI LODR Annual Compliance Requirements for Listed Companies
How to Appoint an Independent Director Under the Companies Act 2013
How to Conduct Supply Chain ESG Due Diligence for Indian Exporters Under EU CBAM and CSDDD
How to Conduct a Data Protection Impact Assessment Under the DPDP Rules 2025


Comments