Talk to an Expert
Talk to an Expert ✆ +91 945 945 6700
Accounting and Bookkeeping · 9 min read · Jul 20, 2026 · Updated Jul 27, 2026

Internal Financial Controls (IFC) under Section 143(3)(i): Design, Testing, Reporting

CA Puja Pradhan

Internal Financial Controls (IFC) under Section 143(3)(i): Design, Testing, Reporting - Featured Image
In this guide

    Internal financial controls under Section 143(3)(i) of the Companies Act 2013 require a company's statutory auditor to give a separate opinion on whether the company has adequate internal financial controls over financial reporting and whether those controls operated effectively during the year. This opinion is annexed to the main audit report and carries the same weight as the true and fair view on the accounts. Below we explain who the requirement covers, how auditors design and test the controls, what a reportable failure looks like, and how to keep documentation that stands up to that testing. If your interest is the wider set of financial reporting rules that sit above this, our overview of Accounting Standards (AS) in India: Complete List is the better starting point.

    What are internal financial controls under the Companies Act?

    Internal financial control is defined in the explanation to Section 134(5)(e) of the Companies Act 2013 as the policies and procedures a company adopts for the orderly and efficient conduct of its business, including safeguarding of assets, prevention and detection of fraud and error, accuracy and completeness of accounting records, and timely preparation of reliable financial information. In everyday terms this means authorisation limits, segregation of duties, reconciliations, and IT access controls that together stop errors and misstatements before they reach the financial statements. The full text of the section is available on the Ministry of Corporate Affairs website.

    A control is not a document. A written approval matrix that nobody follows is a control that has failed the moment a payment goes out without the required sign-off. This is why the definition talks about the conduct of business, not the existence of a manual.

    IFC versus ICFR: the distinction that decides the auditor's scope

    Two acronyms are used loosely and it costs companies time at audit. Internal financial controls (IFC) under Section 134(5)(e) are the wider set, covering operations, asset safeguarding and fraud prevention. Internal control over financial reporting (ICFR) is only the subset that makes the financial statements reliable. Section 143(3)(i) asks the auditor to opine on the adequacy and operating effectiveness of the narrower ICFR, whereas the board's responsibility statement under Section 134(5)(e) covers the wider IFC. When an auditor asks for your controls, they are scoping ICFR: the controls that touch a number in the balance sheet, profit and loss, or the notes.

    Who must the auditor report on under Section 143(3)(i)?

    The reporting requirement applies to every company except three categories exempted by the MCA notification dated 13 June 2017: a one person company, a small company, and a private company that has turnover below Rs 50 crore as per the latest audited financial statements and aggregate borrowings from banks or financial institutions below Rs 25 crore at any point during the financial year. Both the turnover and the borrowing tests must be satisfied for a private company to stay exempt, and the borrowing test looks at the peak balance, not the year-end figure. Listed companies and other public companies are always covered.

    The table below summarises where a company lands. If you are unsure which class of company you fall into for wider financial reporting purposes, the free Ind AS Applicability Checker walks through the same turnover and borrowing thresholds that drive several Companies Act tests.

    Company typeTurnover / borrowing positionSection 143(3)(i) opinion required?
    Listed companyAnyYes, always
    Public company (unlisted)AnyYes, always
    One person companyAnyNo (exempt)
    Small companyWithin small-company limitsNo (exempt)
    Private companyTurnover below Rs 50 cr and borrowings below Rs 25 crNo (exempt)
    Private companyTurnover Rs 50 cr or more, or borrowings Rs 25 cr or moreYes
    CA Tip: The exemption is tested afresh every year. A private company that crosses Rs 50 crore turnover in the current year loses the exemption for that year even if it was exempt last year, so build the IFC documentation before the numbers cross the line, not after the auditor asks.

    How auditors test internal financial controls

    Testing runs in two layers, and auditors follow the ICAI Guidance Note on Audit of Internal Financial Controls Over Financial Reporting, published by the Institute of Chartered Accountants of India. The steps below describe the flow an audit team follows for a single control.

    Flow diagram of the five stages an auditor follows to test one internal financial control, from scoping to forming the opinion.
    IFC audit lifecycle for a single control
    1. Scope the controls. The auditor identifies which accounts are material and which controls address the risks in those accounts, from revenue recognition to a bank reconciliation.
    2. Test design through a walkthrough. One transaction is traced end to end to confirm the control, if it operates as described, would prevent or detect a misstatement. This proves design effectiveness.
    3. Test operating effectiveness through sampling. A sample of instances across the full year is inspected to confirm the control actually ran each time. Sample size scales with how often the control operates.
    4. Evaluate deficiencies. Each exception is graded as a control deficiency, a significant deficiency, or a material weakness, depending on the likelihood and size of a possible misstatement.
    5. Form the opinion. The auditor concludes whether ICFR was adequate and operated effectively, and annexes the opinion to the audit report.

    Evidence must show who performed each control and on what date. A month-end close checklist with initials and dates is evidence; the same checklist blank is not. This is the single most common reason a control that exists on paper is reported as not operating effectively.

    Common mistake: Treating a system-generated report as a control. Running a vendor balance confirmation report is not a control unless someone reviews it, investigates the differences and signs off. The review, with a name and a date, is the control the auditor tests.

    The building blocks of an ICFR framework that passes testing

    A framework that survives audit rests on a few repeatable elements rather than a thick manual. Segregation of duties keeps the person who raises a purchase order away from the person who approves the payment. Authorisation limits put a monetary ceiling on who can approve what. Reconciliations, done monthly and reviewed, catch what slips through. Three-way matching of the purchase order, goods receipt and invoice, within an agreed purchase order tolerance, stops overbilling. IT general controls restrict who can post a journal entry and keep an audit trail of changes. Documenting these in a risk control matrix, one row per control, is what turns a set of habits into an auditable system. Where you want a formal write-up, our note on SOP Drafting & Implementation covers the drafting side, and Accounts Reconciliation & Audit covers the reconciliation discipline that feeds most ICFR controls.

    Key terms

    Section 143(12): when a control failure becomes a fraud report

    A weak control that lets fraud through triggers a separate and time-bound duty. The ICAI guidance on Section 143(12), read with Rule 13 of the Companies (Audit and Auditors) Rules 2014, sets out the sequence. Where the auditor has reason to believe a fraud of Rs 1 crore or more has occurred, the auditor writes to the board or audit committee within two days of learning of it, allows the board up to 45 days to reply, and then forwards the matter and the board's reply to the Central Government in Form ADT-4 within 15 days of receiving that reply. Frauds below Rs 1 crore are reported to the board and disclosed in the board's report rather than to the Central Government. The timeline below shows the clock.

    Timeline showing the Section 143(12) fraud reporting deadlines of two days, forty-five days and fifteen days.
    Section 143(12) fraud reporting clock (Rs 1 crore or more)
    CA Tip: The two-day and 45-day clocks are strict and personal to the auditor, so keep your own dated record of when a suspected irregularity was raised. A clean internal escalation log protects both the company and the auditor if the timeline is ever questioned.

    Worked example: sizing the operating-effectiveness sample

    The most practical question owners ask is how many items the auditor will test. Under the ICAI guidance the sample scales with how often a control runs, not with the rupee value it touches. The table below shows a common minimum-sample benchmark for a control expected to operate without deviation, applied to a company with a 31 March year-end. These sizes are indicative; the auditor sets the final number based on risk.

    Control frequencyTimes it runs in the yearTypical minimum sampleDeviations allowed
    Annual110
    Quarterly420
    Monthly (for example, bank reconciliation)122 to 30
    Weekly5250
    Daily (for example, payment approval)Around 250250
    Many times a day / manualThousands25 to 400

    Read it this way. A monthly bank reconciliation control runs 12 times, so the auditor inspects 2 to 3 of those 12 reconciliations, checking each was prepared, reviewed and signed. A daily payment approval control runs roughly 250 times, so the sample jumps to about 25. If even one item in the sample shows the control did not run, the auditor treats that as a deviation, widens the sample, and may conclude the control did not operate effectively. That is why a single missing signature on one month's reconciliation can carry weight far beyond one transaction. Budgeting for a first-time IFC documentation and testing readiness exercise typically starts from around Rs 75,000 (indicative, Exl GST) for a mid-sized private company, depending on the number of processes.

    Key takeaways

    • Section 143(3)(i) requires a separate auditor opinion on ICFR adequacy and operating effectiveness, annexed to the audit report.
    • OPCs, small companies, and private companies below both the Rs 50 crore turnover and Rs 25 crore borrowing thresholds are exempt, tested afresh each year.
    • Auditors test design once through a walkthrough and operating effectiveness through a sample sized to control frequency.
    • Controls need a name and a date on the evidence; a policy that no one signs is a control that has failed.
    • A suspected fraud of Rs 1 crore or more starts the Section 143(12) clock: 2 days to the board, up to 45 days to reply, Form ADT-4 within 15 days.

    For a related read on how timing and measurement differences flow into the statements auditors ultimately opine on, see AS 22 vs Ind AS 12: Deferred Tax. Internal financial controls are less about paperwork than about proof: every control that touches a number should leave a dated, named trail behind it.

    Decision guide

    Does the Section 143(3)(i) IFC opinion apply to my private company?
    Does the Section 143(3)(i) IFC opinion apply to my private company?
    Share this guide: Link copied!

    What is internal financial control?

    Internal financial control is defined in the explanation to Section 134(5)(e) of the Companies Act 2013 as the policies and procedures adopted for orderly and efficient conduct of business, safeguarding of assets, prevention and detection of fraud, accuracy and completeness of accounting records, and timely preparation of reliable financial information. In practice it covers authorisation limits, segregation of duties, reconciliations and IT access controls.

    When is reporting under Section 143(3)(i) applicable?

    It applies to every company except a one person company, a small company, and a private company with turnover below Rs 50 crore and aggregate borrowings below Rs 25 crore at any point in the year, exempted by the MCA notification dated 13 June 2017. Listed and other public companies are always covered, and the auditor gives a separate opinion annexed to the audit report.

    What does the guidance note on Section 143(12) require?

    It sets out how an auditor reports a suspected fraud: under Rule 13 of the Companies (Audit and Auditors) Rules 2014 the auditor writes to the board within two days, allows up to 45 days for a reply, and forwards the matter to the Central Government in Form ADT-4 within 15 days of that reply where the amount is Rs 1 crore or more.

    How are internal financial controls tested?

    Testing runs in two layers: design effectiveness through a walkthrough of one transaction per control, then operating effectiveness through sampling across the full year. Auditors follow the ICAI Guidance Note on Audit of Internal Financial Controls Over Financial Reporting, with sample sizes scaled to control frequency. Evidence must show who performed each control and on what date, not merely that a policy exists.

    What is the difference between internal financial controls and internal control over financial reporting?

    Internal financial controls under Section 134(5)(e) are the wider set covering operations, asset safeguarding and fraud prevention, while internal control over financial reporting is only the subset that makes the financial statements reliable. Section 143(3)(i) requires the auditor to opine on the adequacy and operating effectiveness of the narrower ICFR, whereas the board's responsibility statement covers the wider set.