canainitsavla.com

ICFR Audit & IFC Support — Internal Controls Over Financial Reporting

Strengthening Financial Control Frameworks Under Section 143(3)(i) of the Companies Act, 2013

Internal Controls over Financial Reporting (ICFR) refers to the set of policies, procedures, and controls that a company designs and operates to provide reasonable assurance that its financial reporting is reliable, complete, and free from material misstatement — whether due to error or fraud. Under Section 143(3)(i) of the Companies Act, 2013, statutory auditors are required to report specifically on whether the company has adequate internal financial controls (IFC) and whether those controls are operating effectively. ICFR is India's equivalent of the Sarbanes-Oxley Section 404 requirement and is a key governance obligation for all prescribed companies.

ICFR covers three broad categories of controls: operational controls, financial reporting controls, and compliance controls. The statutory auditor's obligation is specifically to evaluate Internal Financial Controls (IFC) as it relates to financial reporting accuracy. Weaknesses identified in ICFR must be disclosed in the auditor's report and can significantly impact investor confidence, lender assessments, and regulatory standing. This overlaps closely with revenue audit, since revenue cycle controls are typically a high-risk area in ICFR evaluations. Companies that identify control deficiencies should also consider forensic reviews if fraud risk is implicated.

Our ICFR Audit & IFC Support Services

ICFR Framework Design & Documentation

Designing and documenting the ICFR framework from scratch — process identification, control documentation, and mapping of financial statement assertions to specific controls across all financial reporting cycles.

Risk & Control Matrix (RCM) Preparation

Developing a comprehensive Risk and Control Matrix (RCM) identifying financial reporting risks, applicable controls (preventive and detective), control owners, frequency, and evidence of operation.

Control Testing & Walk-throughs

Conducting independent walk-throughs and control testing across all key business processes — procurement-to-pay, order-to-cash, financial close, payroll, and treasury — to verify design effectiveness and operating effectiveness.

Deficiency Identification & Remediation

Classifying identified control deficiencies as control deficiencies, significant deficiencies, or material weaknesses, and providing a prioritised remediation roadmap with time-bound action plans.

CARO 2020 & Statutory Audit Support

Preparing the documentation and working papers required by the statutory auditor for their ICFR opinion under SA 265 and Section 143(3)(i), including management's assessment of internal financial controls.

IFC Maintenance & Continuous Monitoring

Setting up continuous control monitoring frameworks, periodic self-assessments, and quarterly IFC reporting processes so the company maintains a current and auditable ICFR posture year-round.

Key Facts About ICFR Audit & IFC

  • Section 143(3)(i) of the Companies Act, 2013 requires statutory auditors to expressly report on the adequacy and operating effectiveness of the company's internal financial controls over financial reporting
  • CARO 2020 (Clause 3(vi)) requires auditors to report whether the company has an internal audit system commensurate with its size and nature of business
  • The Board's Report under Section 134(5)(e) must include a Directors' Responsibility Statement on the adequacy of internal financial controls
  • Small companies with paid-up capital below ₹50 lakh and turnover below ₹2 crore are exempt from the IFC reporting requirement under the Companies Act
  • A material weakness in ICFR is a deficiency, or combination of deficiencies, that results in a reasonable possibility of material misstatement not being prevented or detected on a timely basis
  • Listed companies on Indian exchanges face heightened ICFR scrutiny from SEBI under its corporate governance and continuous disclosure regulations
  • IT general controls (ITGCs) — access management, change management, and computer operations — are an integral part of any ICFR evaluation for automated controls
  • Effective ICFR directly reduces the risk of financial fraud, misstatement, and the need for forensic investigation

Frequently Asked Questions

What is ICFR and why is it important under the Companies Act, 2013?
ICFR stands for Internal Controls over Financial Reporting. It refers to the specific subset of a company's internal controls that are designed to ensure that financial reporting is reliable — i.e., that the financial statements are prepared in accordance with applicable accounting standards (Ind AS / IGAAP) and are free from material misstatements. Under Section 143(3)(i) of the Companies Act, 2013, the statutory auditor is required to give a separate opinion on whether the company has adequate internal financial controls with reference to financial statements and whether such controls operate effectively. An adverse ICFR opinion significantly impacts the company's credibility with investors, lenders, and regulators.
What is the difference between IFC and ICFR?
The terms are often used interchangeably but there is a subtle distinction. Internal Financial Controls (IFC) is the broader term used in the Companies Act, 2013, and encompasses controls over all financial matters — including financial reporting, financial transactions, and prevention of fraud. ICFR (Internal Controls over Financial Reporting) is technically a subset — focused specifically on controls that ensure the accuracy and reliability of financial statements. In practice, when auditors evaluate IFC under Section 143(3)(i), they are evaluating ICFR. The broader IFC framework also includes controls over financial fraud, asset safeguarding, and transaction authorisation.
What does a statutory auditor check under ICFR?
The statutory auditor evaluates ICFR by: (a) obtaining an understanding of the company's significant business processes and the controls within them; (b) identifying key controls that address financial reporting risks; (c) testing the design effectiveness of those controls — i.e., whether they are capable of preventing or detecting material misstatements; and (d) testing operating effectiveness — whether the controls actually functioned as designed during the period under audit. The auditor uses this evaluation to opine whether the company had adequate internal financial controls over financial reporting and whether those controls operated effectively as of the balance sheet date.
Which companies are exempt from IFC audit requirements?
The Ministry of Corporate Affairs has exempted certain classes of companies from the IFC reporting requirement under Section 143(3)(i). Currently, One Person Companies (OPCs) and small companies (as defined under Section 2(85) of the Companies Act — with paid-up capital not exceeding ₹4 crore and turnover not exceeding ₹40 crore as per latest limits) are exempt. Private companies that are not required to have their accounts audited by a statutory auditor, and certain dormant companies, may also be exempt. However, listed companies, public companies, and large private companies are all required to have ICFR evaluated and reported upon by their statutory auditors.
What is a material weakness in internal financial controls?
A material weakness is the most severe classification of a control deficiency. It is defined as a deficiency, or a combination of deficiencies, in internal financial controls over financial reporting, such that there is a reasonable possibility that a material misstatement of the company's annual or interim financial statements will not be prevented, or detected and corrected, on a timely basis. A material weakness does not mean a fraud has occurred — it means the controls are insufficient to reliably catch or prevent one. Statutory auditors are required to report identified material weaknesses in their audit report, which becomes a public document and can have serious reputational and regulatory consequences for the company.

Build a Robust ICFR Framework for Your Company

Process documentation, RCM preparation, control testing, deficiency remediation, and statutory audit support — end to end.

Talk to an Expert