In this guide
Internal financial controls under Section 143(3)(i) of the Companies Act 2013 require a company's statutory auditor to give a separate opinion on whether the company has adequate internal financial controls over financial reporting and whether those controls operated effectively during the year. This opinion is annexed to the main audit report and carries the same weight as the true and fair view on the accounts. Below we explain who the requirement covers, how auditors design and test the controls, what a reportable failure looks like, and how to keep documentation that stands up to that testing. If your interest is the wider set of financial reporting rules that sit above this, our overview of Accounting Standards (AS) in India: Complete List is the better starting point.
What are internal financial controls under the Companies Act?
Internal financial control is defined in the explanation to Section 134(5)(e) of the Companies Act 2013 as the policies and procedures a company adopts for the orderly and efficient conduct of its business, including safeguarding of assets, prevention and detection of fraud and error, accuracy and completeness of accounting records, and timely preparation of reliable financial information. In everyday terms this means authorisation limits, segregation of duties, reconciliations, and IT access controls that together stop errors and misstatements before they reach the financial statements. The full text of the section is available on the Ministry of Corporate Affairs website.
A control is not a document. A written approval matrix that nobody follows is a control that has failed the moment a payment goes out without the required sign-off. This is why the definition talks about the conduct of business, not the existence of a manual.
IFC versus ICFR: the distinction that decides the auditor's scope
Two acronyms are used loosely and it costs companies time at audit. Internal financial controls (IFC) under Section 134(5)(e) are the wider set, covering operations, asset safeguarding and fraud prevention. Internal control over financial reporting (ICFR) is only the subset that makes the financial statements reliable. Section 143(3)(i) asks the auditor to opine on the adequacy and operating effectiveness of the narrower ICFR, whereas the board's responsibility statement under Section 134(5)(e) covers the wider IFC. When an auditor asks for your controls, they are scoping ICFR: the controls that touch a number in the balance sheet, profit and loss, or the notes.
Who must the auditor report on under Section 143(3)(i)?
The reporting requirement applies to every company except three categories exempted by the MCA notification dated 13 June 2017: a one person company, a small company, and a private company that has turnover below Rs 50 crore as per the latest audited financial statements and aggregate borrowings from banks or financial institutions below Rs 25 crore at any point during the financial year. Both the turnover and the borrowing tests must be satisfied for a private company to stay exempt, and the borrowing test looks at the peak balance, not the year-end figure. Listed companies and other public companies are always covered.
The table below summarises where a company lands. If you are unsure which class of company you fall into for wider financial reporting purposes, the free Ind AS Applicability Checker walks through the same turnover and borrowing thresholds that drive several Companies Act tests.
| Company type | Turnover / borrowing position | Section 143(3)(i) opinion required? |
|---|---|---|
| Listed company | Any | Yes, always |
| Public company (unlisted) | Any | Yes, always |
| One person company | Any | No (exempt) |
| Small company | Within small-company limits | No (exempt) |
| Private company | Turnover below Rs 50 cr and borrowings below Rs 25 cr | No (exempt) |
| Private company | Turnover Rs 50 cr or more, or borrowings Rs 25 cr or more | Yes |
How auditors test internal financial controls
Testing runs in two layers, and auditors follow the ICAI Guidance Note on Audit of Internal Financial Controls Over Financial Reporting, published by the Institute of Chartered Accountants of India. The steps below describe the flow an audit team follows for a single control.

- Scope the controls. The auditor identifies which accounts are material and which controls address the risks in those accounts, from revenue recognition to a bank reconciliation.
- Test design through a walkthrough. One transaction is traced end to end to confirm the control, if it operates as described, would prevent or detect a misstatement. This proves design effectiveness.
- Test operating effectiveness through sampling. A sample of instances across the full year is inspected to confirm the control actually ran each time. Sample size scales with how often the control operates.
- Evaluate deficiencies. Each exception is graded as a control deficiency, a significant deficiency, or a material weakness, depending on the likelihood and size of a possible misstatement.
- Form the opinion. The auditor concludes whether ICFR was adequate and operated effectively, and annexes the opinion to the audit report.
Evidence must show who performed each control and on what date. A month-end close checklist with initials and dates is evidence; the same checklist blank is not. This is the single most common reason a control that exists on paper is reported as not operating effectively.
The building blocks of an ICFR framework that passes testing
A framework that survives audit rests on a few repeatable elements rather than a thick manual. Segregation of duties keeps the person who raises a purchase order away from the person who approves the payment. Authorisation limits put a monetary ceiling on who can approve what. Reconciliations, done monthly and reviewed, catch what slips through. Three-way matching of the purchase order, goods receipt and invoice, within an agreed purchase order tolerance, stops overbilling. IT general controls restrict who can post a journal entry and keep an audit trail of changes. Documenting these in a risk control matrix, one row per control, is what turns a set of habits into an auditable system. Where you want a formal write-up, our note on SOP Drafting & Implementation covers the drafting side, and Accounts Reconciliation & Audit covers the reconciliation discipline that feeds most ICFR controls.
Key terms
- Financial Internal Controls: the policies and procedures that keep accounting records accurate and assets safe.
- Segregation of Duties (SoD): splitting a transaction across people so no one person controls it end to end.
- Statutory vs Internal Audit: the external Companies Act audit versus management's own ongoing review.
- Standard Operating Procedure (SOP): the written step sequence a control is meant to follow.
Section 143(12): when a control failure becomes a fraud report
A weak control that lets fraud through triggers a separate and time-bound duty. The ICAI guidance on Section 143(12), read with Rule 13 of the Companies (Audit and Auditors) Rules 2014, sets out the sequence. Where the auditor has reason to believe a fraud of Rs 1 crore or more has occurred, the auditor writes to the board or audit committee within two days of learning of it, allows the board up to 45 days to reply, and then forwards the matter and the board's reply to the Central Government in Form ADT-4 within 15 days of receiving that reply. Frauds below Rs 1 crore are reported to the board and disclosed in the board's report rather than to the Central Government. The timeline below shows the clock.

Worked example: sizing the operating-effectiveness sample
The most practical question owners ask is how many items the auditor will test. Under the ICAI guidance the sample scales with how often a control runs, not with the rupee value it touches. The table below shows a common minimum-sample benchmark for a control expected to operate without deviation, applied to a company with a 31 March year-end. These sizes are indicative; the auditor sets the final number based on risk.
| Control frequency | Times it runs in the year | Typical minimum sample | Deviations allowed |
|---|---|---|---|
| Annual | 1 | 1 | 0 |
| Quarterly | 4 | 2 | 0 |
| Monthly (for example, bank reconciliation) | 12 | 2 to 3 | 0 |
| Weekly | 52 | 5 | 0 |
| Daily (for example, payment approval) | Around 250 | 25 | 0 |
| Many times a day / manual | Thousands | 25 to 40 | 0 |
Read it this way. A monthly bank reconciliation control runs 12 times, so the auditor inspects 2 to 3 of those 12 reconciliations, checking each was prepared, reviewed and signed. A daily payment approval control runs roughly 250 times, so the sample jumps to about 25. If even one item in the sample shows the control did not run, the auditor treats that as a deviation, widens the sample, and may conclude the control did not operate effectively. That is why a single missing signature on one month's reconciliation can carry weight far beyond one transaction. Budgeting for a first-time IFC documentation and testing readiness exercise typically starts from around Rs 75,000 (indicative, Exl GST) for a mid-sized private company, depending on the number of processes.
Key takeaways
- Section 143(3)(i) requires a separate auditor opinion on ICFR adequacy and operating effectiveness, annexed to the audit report.
- OPCs, small companies, and private companies below both the Rs 50 crore turnover and Rs 25 crore borrowing thresholds are exempt, tested afresh each year.
- Auditors test design once through a walkthrough and operating effectiveness through a sample sized to control frequency.
- Controls need a name and a date on the evidence; a policy that no one signs is a control that has failed.
- A suspected fraud of Rs 1 crore or more starts the Section 143(12) clock: 2 days to the board, up to 45 days to reply, Form ADT-4 within 15 days.
For a related read on how timing and measurement differences flow into the statements auditors ultimately opine on, see AS 22 vs Ind AS 12: Deferred Tax. Internal financial controls are less about paperwork than about proof: every control that touches a number should leave a dated, named trail behind it.
Decision guide

