Internal Audit Checklist 2024 Edition)
Internal Audit Checklist 2024 Edition)
DISCLAIMER: The views expressed in this Guide are those of author(s). The Institute of
Chartered Accountants of India may not necessarily subscribe to the views expressed by the
author(s).
E-mail : [email protected]
Price : `
ISBN :
Published by :
Printed by :
Foreword
The Internal Audit function has consistently evolved over time. Today, beyond the requirements
specified by the Companies Act, 2013, the internal auditors are expected to ensure risk and
governance aspects as well. Every organization adopts a unique approach to accepting certain
levels of risk and applying measures to reduce these risks. The success of an organization is often
closely linked to its proficiency in comprehending and managing its risk exposures. As a part of the
company's risk control ecosystem, it is essential for the internal auditor to have the necessary
skills to grasp the nature of risks and their corresponding controls.
I am happy to note that the Board of Internal Audit and Management Accounting of the Institute of
Chartered Accountants of India(ICAI) has undertaken the project of revising its publication and
issued ‘Internal Audit Checklist (2024 Edition)’ to provide step-wise guide to members to effectively
conduct the Internal Audit Process. This checklist is illustrative in nature and is based on Risk
Control Matrix. This checklist focuses on risk exposure and control effectiveness and data
analytics for each process.
I congratulate CA. Rajendra Kumar P, Chairman, CA. Charanjot Singh Nanda, Vice Chairman and
all other members of Board of Internal Audit and Management Accounting for bringing out this
revised comprehensive publication.
I am sure that this publication will assist the members in discharging their responsibilities as
internal auditors more effectively and efficiently.
We would like to thank CA. Aniket Sunil Talati, President, ICAI and CA. Ranjeet Kumar Agarwal,
Vice-President, ICAI for their continuous support and encouragement to the initiatives of the
Board. We also thank the members of our Board who have always been a significant part of all our
endeavors.
We also wish to express our sincere appreciation for CA. Arti Bansal, Secretary, Board of Internal
Audit and Management Accounting, ICAI and team member CA. Gyanender Shokeen, Professional
for their technical and administrative assistance in bringing out this Checklist.
We firmly believe that this publication would serve as a basic Guide for the members and other
readers interested in the subject.
We will be glad to receive your valuable feedback at [email protected]. We also request you to visit
our website https://internalaudit.icai.org and share your suggestions and inputs, on internal audit
and Management Accounting.
vi
Foreword to First Edition
The Chartered Accountancy profession, since its inception, is regarded as the trustee of public
interest. In the last decade or so of financial turbulence, the role of Chartered Accountancy
profession has become increasingly relevant and critical for sustenance of businesses. The CA
profession has avowed duty to public interest and this can come through with increased impetus
on ethics, trust and integrity in discharging professional assignments.
The Companies Act, 2013, has definitely shaped the way forward for internal audit function in India
and has provided a strong legal mandate for the crucial role of internal aud itors in the corporate
governance structure.
Internal auditors should rise to the task and seize the opportunity of establishing high performing
internal audit functions as per the new requirements. Internal auditors must be conscious that the
current responsibilities come with new risks and new rewards. Continuous learning and timely
application of relevant knowledge to create value will help in increasing the internal audit’s
credibility and confidence in their enhanced roles.
I am happy that the Internal Audit Standards Board is issuing this publication “Internal Audit
Checklist” to provide updated guidance for helping internal auditors to stay at the cutting edge of
best practices. This publication is quite comprehensive, providing a step-by-step guidance on
every aspect of internal audit.
At this juncture, I wish to compliment CA. Mukesh Singh Kushwah, Chairman, CA. Anil S.
Bhandari, Vice Chairman and other members of Internal Audit Standards Board, for their zeal
towards bringing out comprehensive literature on internal audit.
I am sure that this publication would prove useful to the members in efficiently discharging their
responsibilities as internal auditors.
x
MEMBERS OF THE COUNCIL [2022-25]
CA. Aniket Sunil Talati, President CA. Rohit Ruwatia Agarwal
CA. Ranjeet Kumar Agarwal, Vice President CA. Abhay Kumar Chhajed
CA. Rajkumar Satyanarayan Adukia CA. (Dr.) Anuj Goyal
CA. Piyush Sohanrajji Chhajed CA. Gyan Chandra Misra
CA. Chandrashekhar Vasant Chitale CA. Prakash Sharma
CA. Vishal Doshi CA. (Ms.) Kemisha Soni
CA. Durgesh Kabra CA. Sanjay Kumar Agarwal
CA. Dheeraj Kumar Khandelwal CA. Raj Chawla
CA. Purushottamlal Hukamichand Khandelwal CA. Hans Raj Chugh
CA. Mangesh Pandurang Kinare CA. Pramod Jain
CA. Priti Paras Savla CA. Charanjot Singh Nanda
CA. Umesh Sharma CA. Sanjeev Kumar Singhal
CA. Dayaniwas Sharma Shri Sanjay Kumar
CA. Muppala Sridhar Shri Ritvik Ranjanam Pandey
CA. Prasanna Kumar D Shri Manoj Pandey
CA. Rajendra Kumar P Shri Deepak Kapoor
CA. Cotha S Srinivas Shri Rakesh Jain
CA. Sripriya K Dr. P C Jain
CA. (Dr.) Debashis Mitra, Past President Shri Vijay Kumar Jhalani, Advocate
CA. Sushil Kumar Goyal Shri Chandra Wadhwa
MEMBERS OF THE BOARD OF INTERNAL AUDIT AND MANAGEMENT
ACCOUNTING [2023-24]
Members from the Sitting Council
CA. Rajendra Kumar P, Chairman CA. Prasanna Kumar D
CA. Charanjot Singh Nanda, Vice-Chairman CA. Cotha S Srinivas
CA. Aniket Sunil Talati, President (Ex-officio) CA. (Dr.) Debashis Mitra
CA. Ranjeet Kumar Agarwal, Vice-President (Ex-officio) CA. Rohit Ruwatia
CA. (Dr.) Rajkumar Satyanarayan Adukia CA. (Dr.) Anuj Goyal
CA. Chandrashekhar Vasant Chitale CA. Prakash Sharma
CA. Vishal Doshi CA. Sanjay Kumar Agarwal
CA. Durgesh Kumar Kabra CA. Pramod Jain
CA. Priti Savla CA. (Dr.) Sanjeev Kumar Singhal
CA. Piyush S Chhajed Shri Deepak Kapoor
CA. Sridhar Muppala Shri Chandra Wadhwa
Co-opted Members
CA. Mohit Bharti CA. Sarda Satish Girdharlal
CA. Anil Kumar Jain CA. Pankaj Soni
CA. Sharath Kumar D CA. Nitin Hukumchand Agarwal
CA. Bhupal Sing Sulhyan
Special Invitee
Shri Avinash Sopan Jadhav CA. Bisworanjan Sutar
CA. Krishnaswamy Vidyadaran CA. Gavish Uberoi
CA. P K Manoj CA. Pradeep Tyagi
CA. Savio Vincent Mendonca CA. Tarun Kansal
CA. Sana Baqai
Contents
Foreword .................................................................................................................................... iii
Preface ....................................................................................................................................... v
Foreword & Preface of previous edition ................................................................................... vii-x
Introduction .............................................................................................................................. 1-4
PART A ................................................................................................................................ 5-140
Checklist 1 : Audit Planning................................................................................................... 7-9
Checklist 2 : Entity Level Controls ...................................................................................... 10-28
Checklist 3 : Business Controls Diagnostic ......................................................................... 29-30
Checklist 4 : Financial Statement Closure Process ............................................................. 31-36
Checklist 5 : Annual Operating Plan ................................................................................... 37-41
Checklist 6 : Management Information System ................................................................... 42-44
Checklist 7 : IT Internal Controls ........................................................................................ 45-91
Checklist 8 : Standards on Internal Audit (SIAs) Compliances ........................................... 92-102
Checklist 9 : Legal and Statutory Compliances ............................................................... 103-104
Checklist 10 : Operational and Administrative Expenses ................................................... 105-110
Checklist 11 : Government Grants ..................................................................................... 111-117
Checklist 12 : Patents and Copyright ................................................................................ 118-123
Checklist 13 : Business Continuity Plan ............................................................................ 124-135
Checklist 14 : Related Party Transactions ........................................................................ 136-138
Checklist 15 : Audit Conclusion ........................................................................................ 139-140
PART B ............................................................................................................................ 141-563
Checklist 16 : Order to Cash – Manufacturing ................................................................... 143-162
Checklist 17 : Order to Cash – Services ........................................................................... 163-178
Checklist 18 : Purchase to Pay – Direct Material............................................................... 179-222
Checklist 19 : Purchase to Pay – Indirect Material and Services ....................................... 223-297
Checklist 20 : Purchase to Pay – Capital Items ................................................................. 298-378
Checklist 21 : Fixed Assets and Capex ............................................................................. 379-412
Checklist 22 : Project Management .................................................................................. 413-417
Checklist 23 : Inventory Management ............................................................................... 418-449
Checklist 24 : Cash and Bank .......................................................................................... 450-481
Checklist 25 : Treasury Management ............................................................................... 482-522
Checklist 26 : Borrowings................................................................................................. 523-530
Checklist 27 : Direct and Indirect Taxation & GST ............................................................. 531-544
Checklist 28 : Corporate Social Responsibility .................................................................. 545-550
Checklist 29 : Human Resources – Hire to Retire ............................................................. 551-556
Checklist 30 : Human Resources – Payroll Management .................................................. 557-561
Checklist 31 : Foreign Currency Transactions ................................................................... 562-563
x vi
Introduction
The objective of this Internal Audit Checklist is to ensure that all relevant tasks and procedures are
completed, and to ensure that the internal audit is done thoroughly and effectively. A checklist
ensures that all necessary steps are taken and helps to identify the areas that may need
improvement or further attention. Additionally, a checklist helps audit team to be organized and be
focused and to ensure that all necessary information is collected and reviewed.
Scope
The Scope of checklists depends on both strategic and operational needs of the engagement. As
part of the engagement, best efforts are done to identify areas where checklists are required.
operating effectiveness
exceptions
data analytics performed
results of data analytics and
issue summary or observations.
Process metrics
Order of Checklists
Part A
1. Audit Planning Checklist
2. Entity Level Controls
3. Business Controls Diagnostic
2
Introduction
Part B
1. Order to Cash – Manufacturing
2. Order to Cash – Services
3. Purchase to Pay – Direct Material
4. Purchase to Pay – Indirect Material and Services
5. Purchase to Pay – Capital Items
6. Fixed Assets and Capex
7. Project Management
8. Inventory Management
9. Cash and Bank
10. Treasury Management
11. Borrowings
12. Direct and Indirect Taxation & GST
3
Internal Audit Checklist
4
PART A
Checklist 1
Audit Planning
Process Sub- Risk Description Control Test Performed Attributes tested
process
Overall Internal Audit Risk that internal A documented process, 1. Check the 1. Whether
Internal Charter/ audits are not in listing detailed process comprehensivene documented
Audit Terms of line with the for preparing Annual ss of the Auditing process
Planning Internal Audit objectives of the audit plan keeping in plan, covers all the
Engagement internal audit view various facets of 2. Check the areas as
where it is an function, as per the coverage required. Adherence to the listed in Audit
outsources internal audit Annual Audit Plan.
engagement charter of the entity It can be part of Audit planning process 2. Step by Step
(and terms of Manual or a separate as per document. adherence to
engagement, where document. the Annual
it is an outsourced audit planning
engagement) and process as
also not in line with per document.
the overall
objectives of the
organisation.
Developing / Risk of leaving key Process of continuous Check the interactions Updation of
Enhancing elements of risk engagement with Internal Audit has with overall business
Business unattended due to stakeholders both inside inside and outside and regulatory
Knowledge lack of Business / and outside the stakeholders and knowledge.
regulatory organization. other research and
environment documents as
knowledge. referred by the
auditor.
Audit Missing of Key Risk 1. Having Audit Universe 1. Check the 1. Audit Area
Universe Area for coverage for Organisation / availability of Audit Listing
in Overall Internal Auditable Entity. Universe for the 2. Risk Rating
Audit Plan Organisation/ of the
2. Review of the Audit Auditable Entity Various Audit
Universe at regular 2. How many areas Areas
intervals. added or deleted from 3. Updation of
Audit Universe. Audit
Universe on
3. See the risk rating regular basis
of Various Audit
Universe areas and
any change in the risk
ratings.
Plan Lack of Audit Inputs from Enterprise Communication of 1. Usage of inputs
Linkages Planning process Risk Management Team inputs to and from in preparation
with linkage with Risk on key risk facing Enterprise Risk of overall
Internal Audit Checklist
8
Audit Planning
9
Checklist 2
Entity Level Controls
Final Sub-process Risk Description Control Test Attributes Sample Control
Performed tested size Frequency
Entity Ethics and Management -The company Control Documentation 100% Event
Level Code of does not has Codes of evidence of Code of Driven
Controls Conduct demonstrate Conduct that required: Conduct
character, provide guidance Signed Code of compliance/
integrity and for ethical Conduct undertaking
ethical values. behavior for all Declaration
officers, directors
and employees, Define the
partners and criteria for
consultants, as evaluating
well as suppliers. compliance
The codes with the Code
include of Conduct.
guidelines to These criteria
promote integrity, may include:
sound business a. Clarity and
practices, and accessibility of
legal compliance. the Code of
-The codes are Conduct.
reviewed and
b. Effective-ness
modified on as of
needed. communication
-Codes of channels used
Conduct are to disseminate
available on the the Code of
company Conduct.
website. c. Employee
-Annually, allawareness and
employees are understanding
asked to sign a of the Code of
Certification Form Conduct.
indicating that
d. Reporting
they have mechanisms for
received, read, potential
understood, and violations or
Entity Level Controls
11
Internal Audit Checklist
Entity Corporate The Constitutions The Board and Control Existence of 100% Yearly
Level Governance of Board and other committees evidence Corporate
Controls Guidelines other committee under the Board required: Governance
are not in line are formed/ Corporate Guidelines
with the modified with the Governance
Companies relevant statue Guidelines
Act/Regulator requirements like
requirements Companies Act, Ensure that
IRDA there is a
requirements, written
RBI requirement Corporate
etc. (As Governance
applicable to the Guideline
relevant entity) specifying
details such as
Board
Independence,
Committees,
Qualification
and expertise,
executive
compensation,
board
evaluation etc.
Ensure that the
board and other
committees as
required by the
statutes are
formed and the
roles and
responsibilities
are clearly laid
down.
Entity Board Board does not -Board powers Control Appropriatenes 100% Ongoing
Level Oversight clearly define are clearly evidence s of Board
Controls authority to be defined. required: Board oversight
exercised at -Board powers composition,
Board level and are derived from Corporate
authority Governance
12
Entity Level Controls
13
Internal Audit Checklist
committee) in
fulfilling their
respective
oversight
responsibilities.
-Verify that
board members
act
independently
-Compare the
board's
practices
against industry
best practices
and corporate
governance
guidelines.
Entity Board Board does not Board of Control Appropriatenes 100% Monthly
Level Oversight have a Directors review evidence s of Board
Controls mechanism to the performance required: Board oversight
review Internal of the company Minutes, MIS
Control over and adequacy of for the month,
Financial internal controls ICFR.
Reporting through regulara. Ensure that
(ICFR)adequacy interactions with there is a
and performance. the CFO. strong control
Monthly reporting environment
is done by Senior that promotes
Manager to the ethical behavior
CFO who in turn and a
reports to BOD. commitment to
internal
Minutes of Board controls.
Meetings where
b. Ensure that
the Internal Audit
minutes of
reports are
meetings are
reviewed and
reviewed and
adopted by the
adopted by the
Board. There is
Board.
14
Entity Level Controls
an established
c. Verify if
process of monthly MIS is
monthly reporting prepared and
on operations, reviewed by the
performance and management.
financial
reporting.
Monthly MIS
prepared by the
Senior Manager-
Finance is
reviewed by the
CFO and
Chairman &
Managing
Director.
Entity Risk and Financial On an annual Control Verification of 100% Quarterly
Level Control Matrix Reporting and basis, evidence the Risk and
Controls related management required: Control Matrix
application and performs a review Risk and and ensuring
information of controls and Control Matrix that the design
systems are not processes and operating
a. Check whether
reliable. including effectiveness
all significant
identification of of the controls
risks related to
risks and relevant are effective.
each process
financial
or activity
statement
identified and
assertions. The
included in the
final version of
risk control
the controls and
matrix.
process
narratives andb. Ensure that
any changes there is a clear
made during the and concise
year are reviewed mapping of
by the each risk to the
control/process corresponding
owners to ensure control
they are activities
accurate. The designed to
15
Internal Audit Checklist
16
Entity Level Controls
Entity Whistle Blower The complaints The Management Control Adequacy of 100% Quarterly
Level Mechanism received through monitors/reviews evidence the whistle
Controls Whistle blower the complaint required: blower
policies are not received through List of whistle complaint
enquired/ whistle blower blower process.
resolved. policy. The Define the
Ombudsman criteria for
appointed evaluating the
enquire/ do a effectiveness
investigation of and efficiency
the complaints of the whistle-
received and blower
suitable action is mechanism,
taken if found including:
guilty. On a
a. User access:
quarterly basis,
The mechanism
the report is
should be
provided to
accessible to
Managing
all relevant
Director &
stakeholders.
Company
secretary and theb. Anonymity:
same is reviewed Whistle-blowers
and placed with should be able
Board. to report
without fear of
identification.
c. Confidentiality:
The mechanism
should
safeguard the
confidentiality
of the reporter
and the
information
provided.
d.
Acknowledgm
ent and follow-
up: The system
17
Internal Audit Checklist
should
acknowledge
receipt of the
report and
allow for follow-
up
communication.
e. Timeliness:
Reports should
be processed
promptly.
f. Resolution: The
mechanism
should facilitate
appropriate
investigations
and resolution
of reported
issues.
Entity Organizational Roles and The company Check whether Existence of an 100% Yearly
Level Structure Responsibilities maintains an reporting lines approved
Controls not clearly organizational are well-defined Organizational
defined structure with and clearly Structure.
requisite communicated
positions throughout the
supported by job organization
descriptions that and roles,
explain skill responsibilities,
levels and and job
responsibilities. descriptions are
Organizational clearly outlined
chart is in place for each
and maintained position within
up to date to the
communicate organization.
lines of reporting. Review whether
The company has the succession
set in place a plan for critical
succession plan business
18
Entity Level Controls
19
Internal Audit Checklist
single person
or role
designated as
"Accountable"
for its
successful
completion
d. Role Mapping:
Validate that
each
individual's
name or role
listed in the
authority matrix
matches their
actual position
and
responsibilities
in the
organization.
e. Approval
Process: If
there is an
approval
process defined
in the authority
matrix, verify
that the steps
and criteria for
approval are
clear and
adhered to.
f. Delegation and
Escalation:
Assess whether
the authority
matrix includes
provisions for
delegation of
responsibilities
20
Entity Level Controls
and escalation
procedures for
unresolved
issues.
Entity Strategic Plan Strategic plans Management Control Existence of an 100% Yearly
Level and objectives periodically evidence approved
Controls are not clearly reviews entity- required: Strategic Plan.
defined. wide strategic Approved
plans and Strategic plans
objectives. The and objectives.
Board of Director
approves the Ensure that the
entity-wide strategic plan
strategic plans includes a clear
21
Internal Audit Checklist
22
Entity Level Controls
clearly
documented
and
communicated.
c. Verify whether
the budget
incorporates
contingency
plans to
address
unexpected
events or
changes in the
business
environment.
d. Check whether
unusual
variances and
exceptions are
identified and
justified.
Entity Financial Regulatory non- Management a. Ensure that all Existence of 100% As and
Level Reporting compliance and specifies financial employees and Policies and when
Controls financial reporting rules relevant Procedures
misstatements if and standards stakeholders (Including
suitable which are aware of the Financial
accounting consistent with organization's Reporting
principles, accounting policies and Rules and
policies or rules principles procedures Standards)
not followed. suitable andb. Verify whether
appropriate for there is a
the entity. process to
Reviews monitor and
by/consultations assess
with the Statutory compliance
Auditors as with policies
required by the regularly
regulation
c. Check whether
(annual review)
internal
23
Internal Audit Checklist
or as considered controls in
necessary by the place to detect
management, are and prevent
done. Internal non-compliance
audit coverage with policies
extends to
compliance
review.
Accounting
policies and
principles
followed are
stated in the
'Notes to
accounts' in the
financial
statements.
Circulars/email
issued for closure
of financial
transactions are
shared. Internal
audit is done by
professional firms
and Internal Audit
Reports identifies
the issues
observed.
Annual review is
done by Statutory
Auditors.
Entity Review of Absence of an Various a. Ensure that all Appropriatenes 100% As and
Level Related Party appropriate compliances related parties, s of disclosure when
Controls Transactions mechanism of under different including of related party
related party statutes in individuals, transactions
transactions relation to entities, and
identification can transactions with key
lead to regulatory a related party management
non-compliance (transfer pricing personnel,
and / or financial related identified and
24
Entity Level Controls
25
Internal Audit Checklist
Entity Information Company IT policies and a. Ensure that IT Existence of IT 100% Quarterly
Level technology infrastructure and practices are policies cover Policies and
Controls controls IT systems being properly all relevant Procedures
used for documented and areas, such as
fraudulent communicated to information
activities thereby achieve security, data
affecting the consistency privacy, IT
reputation and across business governance, IT
increasing the units. Policies are asset
legal risks communicated to management,
attached. users via the acceptable use,
Company Intranet and disaster
and policy recovery.
updates are
b. Verify if the IT
approved policies in
annually by alignment with
management. the
Adequate organization's
measures are overall
taken to protect business
sensitive objectives and
information and risk appetite.
data privacy.
c. Check whether
the IT policies
are in
compliance
26
Entity Level Controls
with relevant
laws,
regulations,
and industry
standards
applicable to
the
organization's
operations
Entity Information & In the absence of There are Control Appropriatenes 100% As and
Level Communicatio clear properly identified evidence s of grievance when
Controls n-External communicating communication required: mechanism for
Communicatio channels for channels (email Dedicated third parties
n external parties, ids) for third email id created
employee/ parties under to register
management grievance complaints;
malpractices may mechanism. details
not come to light, available on
may have a company
reputation risk website.
with respect to a. Ensure that
third parties. email ids are
created
specifically for
addressing
third party
grievance.
b. Verify whether
the email id is
made available
in the company
website.
c. Ensure that
ethical
considerations
are prioritized
in all external
communication
efforts.
27
Internal Audit Checklist
d. Verify whether
key personnel
are trained to
handle crisis
communication
effectively;
Entity Information & Risk events, Formal Control Existence of an 100% Monthly
Level Communicatio exceptional and communication evidence approved
Controls n-Management unusual events process required: MIS/Dashboar
Oversight remain established for Procedure on d
unreported to the escalating Communication
management and disruption to Protocol, MIS
hence the risk operations, a. Ensure that a
management occurrence of risk formal
framework is not events and any communication
duly enhanced. material process is
exceptional established for
event. Periodic escalating
MIS / Dash disruption for
Boards, operations.
highlighting of all
b. Verify whether
exceptions.
there is an
Board meetings,
established
management
communication
review discusses
protocol for
discuss unusual
different types
events. Monthly
of information
MIS prepared by
(e.g., financial,
the Senior
operational,
Manager -
strategic).
Finance
department c.is Ensure that the
reviewed and monthly MIS is
approved by the reviewed and
CFO, Chairman & approved by
Managing the Senior
Director. management.
28
Checklist 3
Business Controls Diagnostic
Process Sub- Risk Description Control Control Test Performed
process Owner
Business Respective Risk of non- Whether the entity has Business Review of all the Risk
Controls sub- identifying 'what prepared Risk Control Head / Control Matrix and ensure
process can go wrong' in matrix covering all Vertical its completeness and
each sub-process. risks (strategic, or accuracy and critically
operational, financial, Segment evaluating the controls that
compliance, etc.,) and Head. is place and making
ensure that risk effectively.
mitigation measures
are operating
effectively.
Business Controls Risk of controls To review the control Each Review all the controls
Controls not being effective objectives critically process- critically and check whether
and efficient. and take steps to owner it is sufficient to cover the
modify the control risk envisaged.
activity to make it
more effective. with
the approval of the
appropriate
authorities.
Business Designing Risk of ineffective Process walkthrough Each Walkthrough of all the
Controls designing or of each sub-process process- processes and review
designing gap. and analyse whether owner design gap.
there is any gap in
internal control
designing, then
document the same.
Business controls Risk of ineffective There is tracker of all Internal Follow up of all pending
Controls controls not in effective controls Auditor issues and corrective action
addressed. and step has been
taken to address it.
Business Policies Risk of There has to be a Each To check whether all the
Controls and inconsistency in Standard Operating process- steps given in the Standard
procedures applying the Procedure for all the owner Operating Procedure are
policies and sub-processes and the followed.
procedures. same needs to be
Internal Audit Checklist
Business Ineffective Risk of ineffective All ineffective controls Process All the remediated Internal
Controls controls controls not being need to be reported to Owner controls should be checked
remediated. the management and in the subsequent quarter to
a mitigation plan verify. operating
should be designed by effectiveness.
the process owner and
agreed upon with the
internal auditors.
Business Manual Risk of manual Desirable to have Process To review all manually
Controls controls intervention at more preventive and Owner tested or manually
various control IT controls than dependent controls to
points. manual interventions. explore automation
To explore automation opportunities and provide a
opportunities and plan of action to the
check how the same management.
can be implemented.
Business Process Risk of non- The internal auditor Process All mitigation plans are to
Controls Gaps reporting of Gaps should have a Owner be approved by the Board of
to the comprehensive list of Directors for their
management by gaps in the processes compliance.
the process and also suggest the
owners. mitigation plan.
Business Action Risk of non- To ensure that the Process Review of the internal audit
Controls taken compliances or internal audit reports Owner reports verify remedial
gaps not being are discussed with action taken.
addressed to. Management for their
action plan.
30
Checklist 4
Financial Statement Closure Process
Process Sub- Risk Control Test Performed Attributes Sample
process Description tested size
Schedule of Closing Risk of The Management Whether a Existence of 4 for
preparing Schedule accounting should come out proper communication monthly
financials remaining with a schedule communication activities, 2
unclosed or of closing the is done by the for Quarter
not completed books of Management activities, 1
unless there is accounts: say Director for semi-
a formal illustrative list: (Finance) or annual and
process for a. All month end CFO Office to all 100% for
formal closing activity - by 7th of the Finance and Annual
of accounts at the next month; Accounts activity.
the month end/ b. All Quarter end division or to
Quarter end. activities - by service provider
10th of the next about the
quarter beginning closure process.
month.
To also ensure
that the closure of
accounts period
is aligned to
regulatory
requirements like
SEBI LODR
Requirements for
listed companies
or Group
company norms.
Schedule of Closing Risk of ledger 1. Obtain a. Whether Correctness / 4 for
preparing Schedule balances not reasonable there is list of Accuracy of monthly
financials being updated assurance about reconciliations the ledger activities, 2
and Risk of whether the required to be balances. for Quarter
material Financial prepared. activities, 1
misstatement Statements as a b. Whether the for semi-
of financial whole are free reconciliations annual and
results. from material are reviewed 100% for
misstatement, (maker-checker Annual
Internal Audit Checklist
32
Financial Statement Closure Process
33
Internal Audit Checklist
Schedule of Closing Risk of non- The checklist can Checking of Compliance 100%
preparing Schedule compliances be used to disclosures and with regulatory
financials with regulatory conduct self- alignment to requirements
requirements audits and regulatory
on specific identify areas requirements
disclosures. where they are like SEBI LODR.
not compliant
with regulations.
The checklist can
be updated
periodically to
reflect changes in
laws and
regulations.
Review of the Material Risk of a Review by CFO Review of the Completeness 100%
financial Transaction material of the financial CFO notes and and accuracy
Results transaction not performance and action being of the financial
being reported position including taken to take results.
or reported cash flows and corrective
incorrectly. noting down action.
significant issues
and taking
corrective action.
Review of the Variance Risk of a Review of the Review of the Completeness 100%
financial Analysis material Variance Analysis CFO notes and and accuracy
Results transaction not (on Quarterly / action being of the financial
being reported Monthly / taken to take results.
or reported Annually basis / corrective
incorrectly. Budget Vs. action.
34
Financial Statement Closure Process
Approval for Approval Approval of the The Financial Whether the Ensuring 100%
publishing the process financial statement may be reviews have review is
results results without reviewed at been done with comprehensive
being reviewed various levels by respective and approved
by CFO/Director, authorities and before the
management. Statutory Auditor, the discussions results are
CEO/ MD, Audit are recorded in declared.
Committee and minutes.
Board of
Directors.
Compliance Protecting Risk of non- a. All staff to be Whether steps Ensuring 100%
with the financial compliance sensitised on have been taken compliance
guidelines on information with SEBI UPSI and PIT to protect UPSI with UPSI and
Unpublished which is Regulations on Regulations and and PIT PIT
Price classified as UPSI and obtain regulations. Regulations.
Sensitive price Prevention of confirmation from
Information sensitive. Insider Trading them in writing
(UPSI). Regulations that no price
(PIT). sensitive
information will
be disclosed to
anybody, and if
done they are
personally liable.
b. Ensuring that
price sensitive
information is
handled by senior
executives and
documented in a
structured
manner.
c. Not permitting
electronic or hard
copies of the
information to be
35
Internal Audit Checklist
36
Checklist 5
Annual Operating Plan
Process Sub- Risk Description Control Test Performed Attributes
process tested
Annual Collection of Risk of inaccurate Business objectives Check whether the 1. Annual
Operating Data for data considered or for the organisation data considered for Operating
Plan preparation incomplete data are clearly defined preparation of Plan
Annual taken into account while considering annual operating Template.
Operating for preparation of the data to be plan is adequate and 2. Projected
Plan annual operating requested for accurate. Annual
plan. preparation of Revenue
Risk of non- annual operating Check whether the Plan.
consideration of plan. factors in the
3. Projected
economic factors / Correctness of operating
monthly
current and future various factors environment in which
expenditure
market conditions considered are the entity operates
budget.
while considering verified and any have been
considered and 4. Annual
the requirements in modifications to be
current and future Manpower
the annual made to the plan
market conditions Cost.
operating plan. are verified and
approved. have also been 5. Projected
Realistic taken into Interest
expectations are consideration while Cost.
set for the preparing annual
organisation to operating plan.
achieve its
objectives.
Inputs are
requested in a pre-
defined format, for
preparation of
annual operating
plan for every
financial year.
38
Annual Operating Plan
Approval of Risk of annual The Chief Financial Check whether the 1. Final
Annual operating plan Officer (CFO) and annual operating Approved
Operating being not approved the Chief Executive plan is reviewed and Annual
Plan or presented Officer (CEO) vetted before the Operating
before audit reviews and Audit Committee and Plan.
committee or board presents the Draft Bboard of Directors 2. Minutes of
of directors. Annual Operating for consideration. Audit
Risk of not Plan for approval to Check whether any Committee
completing the the Audit revisions or changes where
preparation of Committee and suggested by the annual
annual operating Board of Directors, Audit Committee or operating
plan before who reviews the Board of Directors plan have
beginning of next major assumptions have been made. been
financial year considered in the presented
Check whether the
including approval preparation of for
annual operating
of the same. annual operating approval.
plan for the financial
Risk of non- plan.
year after all 3. Minutes of the
approval of annual Based on Draft necessary changes meeting
operating plans Annual Operating as communicated with the
lead to lack of Plan being have been duly Board of
awareness among prepared the Audit reviewed and Directors
the audit Committee or approved. where
committee Board of Directors approval of
Check whether the
members or board suggest revisions annual
final approved
of directors about or changes, if any, operating
annual operating
the plan being for achievement of
39
Internal Audit Checklist
40
Annual Operating Plan
41
Checklist 6
Management Information System
Final Sub- Risk Description Control Test Performed Attributes
process tested
Management MIS Design MIS does not meet The MIS system is Ensure that: Appropriateness
Information and the organization’s designed to meet i) The MIS system of the MIS
System Development requirement the organization's is designed to
reporting and meet the
analysis organization's
requirements and reporting and
user’s analysis
requirements, and it requirements.
is well-documented ii) User
(including the data requirements are-
flows and documented, and
processing logic). was there user
involvement
during the
designing phase.
iii) The data flows
and processing
logic is clearly
Management Information System
defined and
documented.
iv) Adequate
controls are
embedded in the
system design to
prevent errors
and fraud.
43
Internal Audit Checklist
Management Compliance MIS System is not There is an up-to- Verify whether: Appropriateness
Information align with to the date documentation i) The MIS system of the MIS
System relevant laws and of all applicable align with relevant
audit trail of user’s laws, regulations, laws, regulations,
activities is not and standards and industry
tracked. applicable and clear standards.
documentation of ii) Audit trails are
how the MIS aligns maintained to
with each track user
requirement and activities and
control. Regular system changes.
training is provided iii) Security
to employees about assessments or
the importance of vulnerability tests
compliance and are conducted
data protection. regularly.
Logging and
tracking user
actions, periodic
audit trail reviews
and restricted
access to audit logs
are also ensured.
44
Checklist 7
IT Internal Controls
Process Sub-process Risk Control Test Performed Attribute Sampl Data
Description s tested e size analytics
performe
d
46
IT Internal Controls
47
Internal Audit Checklist
48
IT Internal Controls
49
Internal Audit Checklist
50
IT Internal Controls
Mobile & Teleworking Several risks A policy and Check the policy
Teleworking associated supporting security and
with measures shall be implementation
Teleworking / implemented to thereof.
Remote protect information
working accessed,
include: processed or stored -If any
Accessing at teleworking sites. discrepancies and
Sensitive Data report thereto.
Through
Unsafe Wi-Fi
Networks,
Using Personal
Devices for
Work, Ignoring
Basic Physical
Security
Practices in
Public Places,
Email Scams,
51
Internal Audit Checklist
52
IT Internal Controls
53
Internal Audit Checklist
54
IT Internal Controls
55
Internal Audit Checklist
56
IT Internal Controls
57
Internal Audit Checklist
58
IT Internal Controls
59
Internal Audit Checklist
60
IT Internal Controls
61
Internal Audit Checklist
62
IT Internal Controls
63
Internal Audit Checklist
64
IT Internal Controls
65
Internal Audit Checklist
66
IT Internal Controls
67
Internal Audit Checklist
68
IT Internal Controls
69
Internal Audit Checklist
70
IT Internal Controls
71
Internal Audit Checklist
72
IT Internal Controls
73
Internal Audit Checklist
74
IT Internal Controls
75
Internal Audit Checklist
76
IT Internal Controls
77
Internal Audit Checklist
78
IT Internal Controls
79
Internal Audit Checklist
80
IT Internal Controls
81
Internal Audit Checklist
82
IT Internal Controls
83
Internal Audit Checklist
84
IT Internal Controls
85
Internal Audit Checklist
86
IT Internal Controls
Information & Information & Risk that the 1. Metrics are 1. Check the IT
Communicatio Communicatio Security provided to the Security
ns ns policies are not Board of Directors, Management
working its committees and Reports that are
87
Internal Audit Checklist
88
IT Internal Controls
89
Internal Audit Checklist
90
IT Internal Controls
91
Checklist 8
Standards on Internal Audit (SIAs)
Compliances
This Checklist on Standards on Internal Audit is illustrative in nature. Members are advised to
suitably modify the same as per the facts, circumstances, and nature of the entity under internal
audit. This document neither supersedes nor is a replacement of any guidance/ pronouncements/
Standards issued by ICAI. Members are advised to read or use the Checklist in conjunction with
the Standards on Internal Audit. Members are also advised to exercise the professional judgement
while using the Checklist on Standards on Internal Audit.
Planned internal audits are in line with the objectives of the SIA 220, Conducting
internal audit function, as per the internal audit charter of the entity Overall Internal Audit
(and terms of engagement, where it is an outsourced engagement) Planning
and in line with the overall objectives of the organisation.
Confirm and agree with those charged with governance the broad
scope, methodology and depth of coverage of the internal audit
work to be undertaken in the defined time-period.
A risk-based planning exercise shall form the basis of the Internal SIA 310, Planning the
Audit Assignment Plan. The Internal Auditor shall undertake an Internal Audit Assignment
independent risk assessment exercise to prioritise and focus audit
work on high risk areas and processes, with due attention given to
matters of importance, complexity and sensitivity.
The Internal Audit Charter and the Engagement Letter shall be SIA 230, Objectives of
reviewed periodically by the Chief of Internal Audit and the Internal Audit
Engagement Partner to ensure its relevance to the changing times
or circumstances (e.g. change in scope). If found necessary, the
proposed amendments to these documents shall be put up to the
approving authority for their review and approval.
All internal audits are conducted with certain fundamental features Basic Principles of
designed to: Internal Audit
• establish the credibility of the Internal Auditor
o Independence
o Integrity and Objectivity
93
Internal Audit Checklist
The Chief Internal Auditor has the overall responsibility to ensure SIA 210, Managing the
the achievement of the objectives of the internal audit function Internal Audit Function
through a well-documented internal audit process.
Where the findings of the Expert will form part of the assurance SIA 240, Using the Work
report to be issued by the Internal Auditor, the Internal Auditor of an Expert
shall participate in defining the scope, approach and work to be
conducted by the Expert. Otherwise, the Internal Auditor shall not
incorporate the finding of the Expert in his Internal Audit report.
94
Standards on Internal Audit (SIAs) Compliances
The Internal Auditor shall obtain sufficient and appropriate audit SIA 320, Internal Audit
evidence which can form the basis of audit findings and allow Evidence
reliable conclusions to be drawn from those findings. Evidence
collected through various audit procedures shall be
complementary and relevant to the objectives of the audit
procedure conducted
95
Internal Audit Checklist
The internal auditor shall record the nature, timing and extent of SIA 330, Internal Audit
completion of all internal audit activities and testing procedures in Documentation
the form of reproducible documents.
The internal audit work paper files shall be completed prior to the
issuance of the final internal audit report. Any pending
administrative matters shall also be completed within sixty days of
the release of the final report.
The ownership and custody of the internal audit work papers shall
remain with the Internal Auditor.
The audit work is executed in accordance with the Internal Audit SIA 350, Review and
Programme and Audit Procedures are completed effectively and Supervision of Audit
timely to help achieve overall objectives of the audit assignment. Assignments
96
Standards on Internal Audit (SIAs) Compliances
All communication with management shall be clear, appropriate SIA 360, Communication
and in line with the agreed process and timelines. with Management
On the basis of the internal audit work completed, the Internal SIA 370, Reporting
Auditor shall issue a clear, well documented Internal Audit Report Results
which includes the following key elements:
(a) An overview of the objectives, scope and approach of the
audit assignments;
(b) The fact that an internal audit has been conducted in
accordance the Standards of Internal Audit;
(c) An executive summary of key observations covering all
important aspects, and specific to the scope of the
assignment;
(d) A summary of the corrective actions required (or agreed by
management) for each observation; and
(e) Nature of assurance, if any, which can be derived from the
observations.
97
Internal Audit Checklist
The Chief Internal Auditor is responsible for continuously SIA 390, Monitoring and
monitoring the closure of prior audit issues through a timely Reporting of Prior Audit
implementation of action plans included in past audits. This shall Issues
be done with a formal monitoring process, elements of which are
pre-agreed with management and those charged with governance.
The responsibility to implement the action plans remains with the
management
For critical or sensitive issues (e.g., those rated high risk or with
fraud risk), follow-up audit procedures shall be performed to
ensure that the risk has been mitigated to an acceptable level. For
98
Standards on Internal Audit (SIAs) Compliances
Audits are undertaken after due study and understanding of the SIA 520, Internal Auditing
Organisation’s ITE, which covers the IT strategy, policies, in an
operating procedures, the risks and governance mechanism in Information Technology
place to manage the ITE. Environment
An independent risk assessment, along with an evaluation of the
controls required to mitigate those risks, forms the basis of the
audit procedures.
99
Internal Audit Checklist
(indicative list):
• Security and reliability of information.
• Efficiency and effectiveness of information processing.
• Analysis and reporting of the information.
• Continuous access and availability of the information.
• Compliance of the IT related laws and regulations.
The Internal Auditor shall review both, the Pre-engagement and SIA 530, Third Party
Post engagement due diligence undertaken by the User Entity, Service Provider
including an assessment of the control environment at the TPSP.
The Internal Auditor provides a written report expressing an SIA 110, Nature of
opinion that conveys the assurance obtained about the Subject Assurance
matter.
Standard on Internal Audit (SIA) 380, “Issuing Assurance Reports”
establish the basic elements, form and content of assurance
reports. In addition, the Internal Auditor considers other reporting
responsibilities, including communicating with those charged with
governance (SIA 250) when it is appropriate to do so.
Standard on Internal Audit (SIA) 370, “Reporting Results” covers
those assignments where no formal assurance report is required,
100
Standards on Internal Audit (SIAs) Compliances
The Internal Auditor shall review the risk assessment exercise SIA 120, Internal
undertaken at the time of planning the audit assignment to Controls
establish a basis of evaluating whether adequate and appropriate
Internal Controls are in place to address the risks identified.
Where the independent assurance requires the issuance of an SIA 130, Risk
audit opinion over the design, implementation and operating Management
effectiveness of risk management, this shall be undertaken in line
with the requirements of SIA 110, “Nature of Assurance”,
especially with regard to the need to have a formal Risk
Management Framework in place, which shall form the basis of
such an assurance.
101
Internal Audit Checklist
102
Checklist 9
Legal and Statutory Compliances
Process Sub-process Risk Control Control Test Performed
Description Owner
Control Legal and Non-compliance The Board of Directors Board of Review of the Legal
Environment Statutory with legal and should clearly have a Directors and Regulatory
statutory policy on 'Compliance Compliance policy.
requirements with legal and statutory Review of the minutes
requirements' and of the meeting
demonstrate the same discussing. Audit of
by oversight legal and statutory
periodically. compliances.
Compliances Legal and Risk of Non- To have a 'compliance Legal a. Legal compliance
Statutory compliance with calendar' which enlists team calendar;
a particular all the compliance and b. Details of returns
statute requirements during the Board of filed and compliances
period / year and then Directors carried out;
circulated to the c. Minutes of the Board
department. At the due Meeting.
date, the legal team has
to ensure that the
requisite compliances
are done.
Compliance calendar to
be approved by Board
and periodically
reviewed by the
Directors.
Compliances Legal and Risk of Legal The Head of Legal Legal To review the
Statutory Compliance should ensure that any team amendments made to
calendar not amendments to law, to law (reference to
updated. the extent applicable, is website, authoritative
also reflected in the pronouncements of the
compliance calendar. Government, expert
advice, etc.) and see
whether the
amendments are
carried out.
Internal Audit Checklist
Compliances Legal and Risk of incorrect To take legal opinion Legal To review the advice
Statutory interpretation of for critical issues and team received by the legal
statutes advise the management experts and how the
accordingly. To discuss same have been
with CFO and make addressed.
necessary entries /
disclosures in financial
statements.
Compliances Legal and Risk of no All the statutory notices Legal To review all the legal
Statutory response given should be sent to CFO team notices received and
to the notice of or Chief Legal or Chief and their response is
the statutory Counsel as decided by Board of submitted within the
authorities the Board. All Directors timeframe.
communication should
be tracked with a
tracking number and
responded to within the
timeframe given by law.
Compliances Legal and Risk of No case or demand be Legal Legal team should
Statutory defending a contested without the team obtain written advice
case or legal advice. from experts before
contesting any claim is contested.
demand without On basis, legal team
legal advice. should hire an
advocate to represent
them.
Compliances Legal and Risk of hiring a Due diligence of the Legal Board to evaluate
Statutory consultant or legal team (including Team, different legal firms
legal expert who their expertise known Board of and choose the one
does not have with peers of the same Directors that meets the
experience. industry, known requirements of the
associates / affiliates entity including their
etc.,) and also to expertise, geographical
ensure that there is no spread, history of
dependency on one handling similar cases
legal expert. and their reputation.
104
Checklist 10
Operational and Administrative Expenses
Process Sub-process Risk Control Control Test Performed Attributes
Description Owner tested
Operational Expense Risk of poor The CFO Perform tests
1. Budget
and Budgeting and expense organization including data Documents
Administrative Planning budgeting and establishes accuracy, 2. Policies and
Expenses planning process comprehensive assumption procedures
lies in inaccurate controls for validation, scenario3. Email
projections, expense analysis, alignment Corresponde
underestimated budgeting and with objectives, nce
or overestimated planning, budget vs. actual
4. Meeting
costs, including data variance analysis,
Minutes
inflexibility, accuracy multi-level review,
misalignment validation, contingency 5. Actual
with objectives, multi-level planning, expense
incomplete review, collaboration reports
analysis, and alignment with assessment 6. Financial
communication strategic technology statements
gaps, which can objectives, functionality, 7. Budget
lead to financial flexible documentation revisions
strains. contingency review, continuous 8. Approval
planning, improvement Logs
regular evaluation, and
monitoring, policy adherence to
technology ensure the
utilization, and effectiveness and
continuous accuracy of the
improvement to expense budgeting
mitigate risks and planning
and ensure process.
accurate
resource
allocation.
Expense Risk of non- The Procurement 1. Expense
Approval compliance, with organization Perform tests approval
Workflow policy implements including policy records
segregation of controls such adherence checks, 2. Expense
duties issues, as enquiry, segregation of reports
inconsistent quotation duties verification,
3. Approval
Internal Audit Checklist
106
Operational and Administrative Expenses
107
Internal Audit Checklist
108
Operational and Administrative Expenses
109
Internal Audit Checklist
110
Checklist 11
Government Grants
Final Sub-process Risk Control Control Test Performed Attributes Sample
Description Owner tested size
Government Understanding Risk of To understand Auditor To understand Eligibility for the 100%
Grants the business eligible the business how the business Grant
government carefully, is eligible for
grant not including government
claimed reading grants and
necessary document how
materials and the Company has
review of been assessed or
peers in the evaluated that it
similar industry is eligible for the
as to whether grant.
the particular
business is
eligible for
government
grant.
Government Use of Risk of Periodically Corporate Review of the Eligibility for the 100%
Grants Government possible the CFO Accounts conditions for the Grant
Grant misuse of (designated Grant and have
Grant or non- employee) an understanding
compliance verifies of the compliance
with the compliance requirements and
conditions. with grant how the same is
terms, aligned to the
conditions, client's business.
and reporting
requirements
and that grant
funds are
being used for
their intended
purposes and
are in
compliance
with applicable
regulations.
Internal Audit Checklist
112
Government Grants
113
Internal Audit Checklist
114
Government Grants
115
Internal Audit Checklist
116
Government Grants
117
Checklist 12
Patents and Copyright
Process Sub- Risk Description Control Control Test Attributes
process Owner Performed tested
Intellectual Patents Risk of Patents Whenever the Legal / To check the Ensuring
Property and and copyrights Company is hiring a CFO / agreement has patents and
Rights Copyrights may be assigned consultant, or in an Human a clause copyrights are
to a third party. employment Resource mentioning not used by a
agreement or hiring about the third party.
sub-contractors ownership of
where it is intended any patents or
that the copyright in copyrights
the work arising in arising of the
the course of their work done .
engagement rests
with the entity, are
in the agreements
with them and
drafted with
sufficient care to
ensure that their
legal Impact is
considered.
Intellectual Patents Risk of patents and Review of Legal / No case is filed Non-
Property and copyrights confidentiality CFO / against the compliance with
Rights Copyrights assigned to a third clauses in the Human company by patent and
party. agreement, and no Resource third party for copyright law.
part of their work violating
would include - copyrights.
existing patented or
copyright material or
if any copyright is
included whether
the permission is
taken from the
owner.
Intellectual Patents Risk of third party Proper patents and Legal Company's Declaration of
Property and claiming the copyright notice official ownership of
Rights Copyrights patents and should be given in documents copyrights
copyrights. all publicly having
distributed reference of
newspapers or patents and
media and on the copyrights are
literature wherever reviewed.
the company's work
is communicated.
119
Internal Audit Checklist
Intellectual Patents Risk of Whether the cost of CFO To review the Valuation of
Property and overstatement of copyright is amortisation patents. and
Rights Copyrights value of amortised over the workings and copyrights.
copyrights. useful life. ensure that the
amortisation is
not beyond the
legal life.
Intellectual Patents Non-compliance Review of all the Legal / Check Non- Ensuring there
Property and with agreements. agreements of CFO compliance are no non-
Rights Copyrights acquisition, clause in compliances of
technology transfer, agreement and contractual
royalty, etc., to action how the obligations.
observe for any same are being
clauses on non- dealt with.
compliance.
Intellectual Patents Risk of Company's To ensure that all IP Legal and To check copy Possibility of
Property processes and Rights including Secretarial of registered any new
Rights copyrights being Patents and Team patents and product being
infringed by a third Copyrights copyrights and developed
party. registered with the check if and which poses a
Government infringement. risk of
authorities. competitor or
market using
the same in an
unauthorised
manner.
Intellectual Patents Risk of Company's To review the Legal and To discuss with Possibility of
Property IP Rights not being process of business Secretarial CFO and Legal any intellectual
Rights identified during acquisition as it is Team / team, how have property right
any business possible that the CFO they ensured not being
acquisition. acquiree had certain that all the accounted.
intellectual property intellectual
120
Patents and Copyright
Intellectual Patents Possibility of new To ensure the Legal / To check Risk of non-
Property and products registration of CFO patents and registration of
Rights Copyrights developed and patents and copyrights new product
launched in market copyrights after registration is patents and
without having product is taken for all copyrights.
Patents and developed. new products
Copyrights over Developed and
them. registered.
Intellectual Patents Risk of non- To a checklist of all Legal / To review the Compliance
Property and compliances with compliance required CFO compliance with local laws
Rights Copyrights specific industry as per all industry requirements of and regulations.
regulations like regulations is all the industry
Pharmaceutical, prepared. standard
Software, regulations.
Telecommunication
and technology,
consumer
electronics, food
products, etc.,
121
Internal Audit Checklist
Intellectual Patents Unauthorized use Strong licensing Legal and To review logs Risk of
Property and leading to loss of agreements and Secretarial and reports unauthorized
Rights Copyrights licensing revenue. tracking of usage. Team generated by use of licensed
software or software
systems that
track usage of
licensed
software or
intellectual
property and
ensure that the
usage data is
accurate and
comprehensive,
covering all
licensed
assets.
122
Patents and Copyright
recovered from
backups.
Intellectual Patents Lack of Intellectual Develop and Legal / To review IP To ensure that
Property and Property Policies implement clear IP CFO / policies and there are
Rights Copyrights and Procedures policies and Human procedures to policies and
covering aspects procedures and Resource ensure they are procedures for
such as ownership ensure employees well- Intellectual
of and right to use are aware of and documented, Property
the IP, Procedures trained on IP up-to-date, and
for identification, policies. comprehensive
evaluation, and verify that
protection and the policies
management of IP, comply with
procedures for relevant
cooperation with intellectual
third parties, property laws
guidelines on the and
sharing of profits regulations.
from successful
commercialization,
etc.
123
Checklist 13
Business Continuity Plan
Process Sub- Risk Control Control Test Performed Attributes
process Description Owner tested
Business Preparation Risk of not The Information Perform a 1. Risk
Continuit , Review having a BCP organization Technology comprehensive assessment
y Plan and and DRP has a formally Department series of tests reports.
(BCP) Approval document reviewed and . including 2. Business
and approved BCP evaluation of risk Impact
Disaster and DRP assessment analysis (BIA)
Recovery document process, business Documentation
Plan impact analysis, .
(DRP) scope and 3. Scope and
dependency dependency
verification, documentation
alignment with .
business 4. Alignment
objectives, threat with Business
scenario objectives
simulation, 5. Threat
documentation scenario test
review, results.
dependency 6.
mapping, Documentation
personnel training, of plans.
backup and
recovery tool
testing,
communication
plan validation,
testing of recovery
procedures, data
integrity
verification,
alternate site
activation testing,
testing frequencies
determination,
third-party vendor
testing, user
acceptance
Business Continuity Plan
125
Internal Audit Checklist
126
Business Continuity Plan
127
Internal Audit Checklist
128
Business Continuity Plan
129
Internal Audit Checklist
130
Business Continuity Plan
131
Internal Audit Checklist
132
Business Continuity Plan
133
Internal Audit Checklist
134
Business Continuity Plan
135
Checklist 14
Related Party Transactions
Final Sub- Risk Control Test Performed Attributes
process Description tested
Related Party Entity level Risk of non- The Company Secretary Obtaining copies a. Declaration
Transactions controls identification (or equivalent in absence of the declaration given by
of Related of a company secretary) by the Directors Directors;
Parties should have a policy on and whether the b. Review by
identifying related parties same have been the Board of
including obtaining discussed at the Directors
declaration from directors Board. Further, through the
regarding their interests whether the list of Minutes of the
in companies and other related parties Meeting;
business entities and the already existing c. Updated list
position they hold as are updated with of Related
directors or otherwise in any new updates Party
other business entities. from the
directors.
Related Party Entity level Risk of non- A list of related parties- Review of the Relationship
Transactions controls identification subsidiaries is prepared, notes prepared with other
of Related and other documents by the Corporate entities.
Parties - related thereto. Accounts Team
Subsidiaries Transactions carried out to understand
with subsidiaries are how they have
properly recorded. identified entities
as subsidiaries
and the tests
applied under AS
21 or under Ind
AS 110 as the
case may be.
Related Party Entity level Risk of non- A list of related parties- Review of the Relationship
Transactions controls identification Association is prepared, notes prepared with other
of Related and other documents by the Corporate entities.
Parties - related thereto. Accounts Team
Associates Transactions carried out to understand
with Associations are how they have
properly recorded. identified entities
as associates
and the tests
Related Party Transactions
Review of the
minutes of the
audit committee
and Board of
Directors.
Related Party Transaction Risk of non- Identification of Key Review of the Nature of
Transactions level identification Managerial Personnel appointment responsibilities
of Key (KMP) as related parties. letters of the
Managerial KMP, their roles
Personnel and
(KMP) as responsibilities
137
Internal Audit Checklist
138
Checklist 15
Audit Conclusion
Final Sub-process Test Performed
Audit Review Audit a) Verify whether the audit objectives set at the beginning of the audit
Conclusion Objectives and have been met.
Scope b) Ensure that the audit scope was adhered to and any deviations are
documented appropriately.
Audit Verify Audit Work a) Cross-reference workpapers, evidence received, and audit
Conclusion documentation to ensure accuracy and completeness.
b) Validate that audit procedures were performed are in accordance with
the established standards and methodologies.
Audit Assess a) Determine the thresholds for materiality used for assessing findings and
Conclusion Materiality their impact on the audit report.
b) Confirm that identified issues and discrepancies meet the defined
materiality criteria.
Audit Evaluate Internal a) Review the effectiveness of internal controls relevant to the audit
Conclusion Controls objectives.
b) Identify any weaknesses or deficiencies in internal controls and assess
their impact on audit findings.
Audit Analyse Audit a) Summarize the audit findings, including significant issues and
Conclusion Findings exceptions.
b) Categorize findings based on their severity and potential impact.
c) For each finding, identify the root cause and provide recommendations
(based on industry best practices) to address the root cause.
Audit Obtain a) Communicate audit findings and recommendations to management
Conclusion Management personnel.
Responses b) Obtain management's responses to the audit findings, including any
corrective actions planned or taken.
c) Obtain the target timeline for corrective actions.
Audit Review a) Evaluate the adequacy of proposed/implemented corrective actions to
Conclusion Corrective address audit findings.
Actions b) Ensure that management's responses are aligned with the identified
issues.
Audit Finalize the Audit a) Compile audit findings, management responses, and supporting
Conclusion Report evidence into a comprehensive audit report.
b) Ensure the report follows the organization's prescribed format and
Internal Audit Checklist
140
PART B
Checklist 16
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
Order Customer Customer chosen is Defined process to Check whether 1. Credit Whether there
to Cash Manageme not appropriate to check the customer credit Worthiness are any
nt complete the contract worthiness and worthiness of all Supporting customers
obligations resulting approval from new credit 2. Approval for where the credit
in bad debts. marketing head is customers has customer. worthiness is
needed for finalising been evaluated deteriorated
customer. by and after the
Credit worthiness documented for contract.
process should approval.
include the following:
• Analysis of
customers’ latest
available financial
statements.
• Understanding
customers’
management and
business.
• Personal guarantee.
• Site visit.
• Reference Check.
• Evaluation of 4 C's of
Credit
Proper documents Authorised Person 1. Check the 1. Customer How many data
not taken from approves onboarding customer hard Hard file fields or critical
customer at the time of a new customer file to test points in the
of onboarding. after reviewing data Customer form customer file
input with the and other are empty or
supporting's attached required data for are not filled up
with customer form. onboarding for any reason?
Documents needed
with customer form-
• GST Certificate
• PAN card
• E-mail ID
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
• Contact Details
• Bank details
• Other details as
required in Customer
KYC Form
Without necessary
documents, no
customer is
onboarded.
Inaccurate/ 1. Authorised person 1. Check that 1. Supporting
Incomplete updation approves onboarding the information documents
of customer master of a new customer so entered is 2. Approvals
after reviewing the reviewed by
data input with the Authorised
supporting's attached person.
with customer form. 2. Check with
2. Recorded changes the supporting
to the customer documents that
master file are the information
compared to has been
authorized source completely &
documents to ensure accurately
that they were input entered.
accurately.
3. Customer master
file data is
periodically reviewed
by management for
accuracy and
ongoing pertinence.
Risk of inadequate Every employee is 1. Check the Declarations by
screening viz. an mandated to inform employee the employees.
employee being a concerned division declarations Check whether
customer. head/ Superior where requirements of
conflict of interest code of conduct
exists. and Companies
Act, 2013 are
Employees are fulfilled.
required to certify
compliance with the
144
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
policy on an annual
basis.
Unauthorised Customer master can 1. Check that 1. Approvals for Check whether
modifications/alterati be updatedthe person addition / log of changes
ons made to (modifications /
making the alteration is available.
customer master. Alterations) only with
addition /
the approval of
alteration is
authorised person. authorised to do
so
Also, the access to 2. Check
make modification / approval as per
alteration to the approval matrix.
customer master is
restricted to
personnel authorised
as per approval
matrix.
Inactive/ fictitious Customer with no 1. Check the 1. Customer
customers are not transactions for a customer master Ledgers
blocked. period specified as for blocked 2. Customer
per organisation customers. Master
policy are blocked in
ERP/Accounting
Package for further
sales with approval
of authorised person
Unauthorised Block customer 1. Check list of 1. Customer
reopening of accounts can only be blocked Master
customer blocked opened again after customer 2. Approval logs
earlier. taking approval as account
per approval matrix. reopened
2. Verify proper
approvals have
been taken.
Annual Annual Targets are An annual target is Check whether Approved Sales
Target not prepared, no developed for annual sales Budget
proper planning defining the sales for budget is
leading to loss of each year. Targets prepared and
revenue. are duly approved by approved as per
145
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
the authorised the authority
personnel matrix
management/ Board.
Annual targets are Every month, Review Minutes Minutes of
not being achieved. meeting of Division of Meeting meetings
head with Marketing
team is held to keep
the annual sales
target on track.
At period end,
reasons are
identified for
variances in actual
sales with budgeted
sales and same is
considered while
formulating plan for
the next year.
Order Product prices The pricing of each Check approved Price List
Manageme catalogue is not product is decided by price list
nt approved by the Management with Verify changes
authorized person. Division heads made are
considering costing properly
and other factors and authorized.
the same is defined
in the ERP/
Accounting Package.
Also, the prices are
reviewed by the
management on a
regular basis, and
changed, if required.
Unauthorized Authorised personnel Check whether Quotations
quotations send to prepare and record the quotations
customer. the quotation in the are approved
ERP/ Accounting properly as per
Package, the the authority
quotation is approved matrix
by Approving
authority as per
146
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
authority matrix and
shared to customer.
Unauthorized Data validation is Check whether Price List
discount allowed to done in the ERP/ the pricing of Sales orders
the customers Accounting Package sales orders is Approvals for
so that the personnel according to the discount
inputting days cannot price list.
enter the price below Verify discounts
than allowed limit have been
Further Approval as approved from
per approval matrix as per approval
is required to quote a matrix.
rate/price to
customer.
Quotations not Customer inquiry for Verify quotations Quotations
shared with customer quotations is input by are being with Listing
within time sales team in time specified as
ERP/Accounting per Organisation
Package. Delayed policy.
quotation is time
flagged in
ERP/Accounting
Package. Quotations
as made are required
to be, approved and
shared to customer
within 2 Days of
receipt of inquiry of
quotations.
147
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
customer into invoice not
ERP/Accounting received.
Package and get it
signed & stamped by
the customer.
Further, work is not
started until sales
order is made.
Sales order is not Sales orders are to Check sales Authority Matrix
entered or incorrectly be reviewed (with orders are Approvals for
entered in the system respective purchase approved as per sales order
with respect to rate, order/agreement) authority matrix.
quantities & other and approved as per
terms or duplicates authority matrix.
orders are entered. Further, Invoices are
linked to sales order,
invoices can’t be
issued without sales
order.
Sales Specifications are Check sales Sales order
order/agreement mandatory field in orders are
does not prescribe the sales order and prepared with all
the correct technical cannot be specifications
specifications of circumvented (in necessary and
goods required ERP/Accounting match the sale
resulting in Package). order
procurement of Sales agreement is specification
incorrect goods approved by with customer's
approving authority purchase order
after proper review.
Delay in approving The sales order Verify sales Authority Matrix
sales order created should be orders are Organisation
approved within time approved within policy
specified as per time limit Approvals for
organisation policy. specified. sales order
Unapproved sales
order are time
flagged on
dashboard of
approving authority.
148
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
Unauthorized Request for Check sales Authority Matrix
modification/cancella modification/cancella orders are Approvals for
tion of sales tion of sales modified/ sales order
order/agreement order/agreement is cancelled as per
raised in ERP/ authority matrix
Accounting Package,
and after approval as
per authority matrix,
the request is closed.
No process of In case, sales order Check sales Listing for Sale
closing/ blocking the has not been orders are orders
old sale order in the completed within closed after time
ERP automatically time agreed, the limit specified in
sales order is closed. sales order has
Customer has to passed.
apply to the
Organisation for new
order for the
unexpired quantity.
Credit Credit policy is not in Approved credit Check whether Approved Credit
Manageme place / Unapproved policy is in place and credit policy is Policy
nt credit policy is all the customers are formulated
formulised given credit as per
the policy only. Same
is also mentioned on
invoice.
Unauthorized Credit limits are Check changes Authority Matrix
changes in credit defined in in credit limit are Approved Credit
limit, period and ERP/Accounting authorised as Limit
terms of a customers Package, any per authority
modifications made matrix
are to be approved
as per authority
matrix
Unauthorized credit Credit Limit Matrix Check credit Approved Credit
allowed to have been defined limit matrix is Limit Matrix
customers. for allowing credit prepared and
period to the clients approved
in Credit Policy.
149
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
Delivery order has Credit Limits are Check whether Data for credit
been generated by linked to customer credit limits are given to
the system and the account in ERP/ breached during customer during
customers trade Accounting Package, the year. the year
debts exceed their for exceeding credit If exceeded,
credit terms/ limits. limits, prior approval Check whether
has to be taken as prior approvals
per authority matrix were taken.
Order Quality of the goods 1. Person Check reports of Quality Reports
Fulfilment delivered not in line responsible shall quality team
with the requirement regularly follow-up issued during
of the customer with the production the year.
team for the purpose
of quality of goods to
be delivered.
2. Before loading of
material, the quality
team and sales team
shall check the
quality of material on
a random basis and
shall share the
quality inspection
report to the
dispatch/document
team.
Delivery not made to Sales order validity is Check whether Outward Register
customer within time mentioned in the sale sales are made E-Way Bails
order at the time of to customer Sale Orders
creation of sale order within time
and the same is specified in
monitored by the sales order.
authorized personnel
to make all deliveries
timely.
Customers do not 1) Delivery challan to Check whether Acknowledgemen Customer
receive dispatched be taken from acknowledgeme t from customer. confirmation
products leading to transporter. nts has been Delivery Challan. obtained where
customer dispute 2) Goods receipt received from Invoice. Acknowledgem
note / material customers and ent from
150
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
receipt note as delivery challans customer is not
confirmation is taken are available. available
from respective
customer through
mail.
Order Goods are a. Items are Verify dispatch Dispatch
Shipping dispatched more dispatched on the order/packing order/packing list
than sales order basis of sales order list with sales Invoice
quantity issued by sales and order Sale order
marketing
department.
b. Inventory
Personnel ensure
that items are not
issued more than the
sales order quantity
of customer.
c. Goods are loaded
in the vehicle in the
presence of security,
marketing executive,
and inventory
personnel.
Shipping is made Sale order is not Verify advances Bank Statement
without obtaining generated until have been Sale
advance payment advance is not received as per order/Agreement
received as per the sale
PO/agreement/profor agreements/sale
ma invoice. order.
Also check that
no sale order is
generated until
advance
received.
Invoicing & dispatch Invoice and dispatch Reconcile Invoice
documents are documents are Invoices with E- E-way bills
generated but generated after the way bills
products are not dispatch team has
dispatched loaded the goods on
vehicle.
151
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
Invoice generated Based on marketing Match Invoice Invoice
and goods team communication, generated with Sale order
dispatched are not in packaging list is sales order
line with customer prepared, and goods issued and
order are identified and PO/agreement
made ready for to customer
dispatch by stores
team. Goods
dispatched note is
prepared by stores in
charge and goods
are loaded in vehicle
in presence of stores
in charge & security
in charge. Based on
packaging list and
goods dispatch note,
invoicing is done.
Delivery is made Invoice is linked with check that Invoice
without sale order sales order. Invoices have Sale order
Inventory team been linked to
issues the inventory sales order
to dispatch team
after recovering
approved sales order
form sales team.
Dispatched Goods Security in charge Verify Dispatch Invoice
have not been input/ checks outward goods have Outward register
incorrectly input in registers are updated input in outward
outward register before dispatch of register
maintained at goods from gate.
factory/company gate Security supervisor
on regular intervals
checks registers are
updated timely and
correctly.
Customer Dispatch is done Goods are not exiting Match the Outward register
Invoicing without issuing the factory gate outward register Dispatch register
invoice. before the issue of with invoice and invoices
Invoice and other dispatch
152
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
dispatch documents. register.
Invoice is not as per Dispatch team and Verify Invoices Invoices
dispatch Security in charge issued during Dispatch
order/packaging list. scrutinises the the year with order/packaging
dispatch their respective list
order/packaging list dispatch
with invoice and order/packaging
ensure both are in list
line.
Invoicing is not in Predefined format for Check the Invoices
line with statutory invoice has been format of Invoice Refer respective
requirements made in is in line with law
ERP/Accounting statutory
Package after requirements
approval of
authorised
personnel. The same
is regularly reviewed
by FP&A team.
Invoice generated Invoices are Check correct Invoices
with incorrect prepared by statutory details Refer respective
statutory details (Like authorised person, are filled for law
HSN, Place of and invoice is invoices issued
supply, GST Rate, reviewed and during the year
etc.) approved by the
authorised signatory
Invoices raised on Invoices are linked Verify invoices Invoice
unauthorized/incorre with sales order are matching Sale order
ct rates. (agreed earlier with with sales order
the customer). Rates linked to it
and other terms are
pre-specified in
invoices as per sales
order.
Invoices not For every sale, Verify Invoice
generated and delay packaging list, goods Packaging list/ Packaging list/
in generating the dispatch note & Goods dispatch Goods dispatch
invoice. invoice is created. note/order with Data
Without packaging Invoice issued
153
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
list & invoice, goods during the Year.
loaded vehicle is not
allowed to exit
factory gate.
E-way bill generated Dispatch team and Reconcile Invoice
not in line (incorrect Security in charge Invoices with E- E-way bills
item, rates, quantity, scrutinises the way bills
etc.) with the invoice dispatch documents
issued. like invoice, e-way
bill, etc and ensure
all are matching with
one-another.
Cash sales made not Invoice/cash receipts Check invoices Invoices
recorded/ under are to be issued from is issued from Cash Receipts
recorded. ERP/Accounting ERP and Reconciliation
Package for cash monthly
sales and monthly reconciliation is
reconciliation is made or not
made of invoice
generated with cash
deposit by authorised
personnel.
Cash received not Cash received Check cash is Bank Deposit
deposited in bank should be deposited deposited within Slips
within time as per at the branch office time as per the Cash
Organisation policy. as per the Organisation Reconciliations
Organisation policy. policy and
Responsible reconciliation is
Personnel should done for cash
reconcile it with receipt at
ERP/Accounting branch.
Package receipts Verify cash
and issue received for
acknowledge-ment. sales during
Responsible year has been
Personnel should deposited in
deposit the cash in bank.
bank daily basis/
next working day.
154
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
Sales Policy has not been Approved policy has Check sales Sales Return and
Return and formulated for Sales been defined for return and Refund policy
Refund return and refund. Sales Return and refund policy
Refund.
Sales return request Authorised matrix Check proper Approval for
accepted without has been defined for approvals have sales return
proper approvals approval of sales been taken for
return request approving sales
return request.
Unauthorised/ 1) Approval as per Check approvals Credit Notes
improper Credit approval matrix is for Credit notes register/ledger
notes is issued taken for issue of the issued during
credit note through the year
mail/ERP/Accounting
Package by
personnel
responsible.
2) After approval, the
credit notes are
prepared by
personnel
responsible and
shared to customer.
Sales returns are 1) After arrival of Check Report Quality team
incorrectly recorded vehicle at issued by quality report
(Quantities, Rate warehouse/factory, team for MRN for
etc.) or accounted goods are checked returned goods, Returned Goods
without physically by quality team. MRN generated Approval as per
receiving goods Report is issued and by Inventory approval matrix.
goods are forwarded team and
to inventory team. approval of
2) Inventory team Division head for
inputs the goods in Sales Return.
register and raises
material receipt note.
3) After issue of MRN
and approval from
Division head, sales
return entry is
155
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
passed in books.
Refund of sales Bank account is Check approval Approval
return made to updated in the received as per
incorrect customer ERP/accounting approval matrix
package.
Before refund,
approval as taken
per the approval
matrix.
Accounts No policy for Account statements Check whether Accounts
Receivable periodical customer for all customers has accounts Statements/Bala
balance been obtained on statement are nce confirmations
reconciliation / quarterly basis and obtained as per from customers
Incorrect customer reconciliation is Organisation
balance reflected in prepared by person policy.
books of accounts responsible. Further,
balance
confirmations are
obtained from all
customers on yearly
basis.
Identified Identified deviations Check whether Accounts
discrepancies during are reconciled by there is any Statements/Bala
reconciliation with responsible discrepancy nce confirmations
customer are not accounting personnel between from customers
adjusted correctly in and reviewed by customer Customer
the books of approving authority. statements and Ledgers
accounts Adjustment is Organisation Approvals for
entered in ledgers. adjusting entries
Accounting Package Check identified
after approved by discrepancy are
approving authority. resolved and
adjusted in
necessary books
after approvals
as per authority
matrix
Revenue is recorded Revenue for Goods Check Revenue
in books for goods sent on approval is conditions as Recognition
156
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
sent on approval, but recorded when mentioned in Policy
approval not received i) The goods have Organisation Data for Goods
from customers. been formally policy are Sent on
accepted by the satisfied before Approval.
buyer, or booking revenue Book entry
ii) The buyer has for "Goods Sent
done an act adopting on Approval".
the transaction, or
iii) The time period
for rejection has
elapsed or where no
time has been fixed,
a reasonable time
has elapsed.
Provision for bad & Organisation has Check whether Policy for
doubtful debt is not defined policy for policy is provisions.
made or made using creation of provision formulated for Customer
incomplete and for doubtful debts. recording of Ageing.
inaccurate data or Ageing for debtors is doubtful debts Approvals for
not correctly prepared. Provision and ageing is recording
accounted for in the for doubtful debts is prepared provision for
books of accounts approved by Chief regularly. doubtful debts
Financial Officer & Verify necessary
provision is entered approvals as per
in accounting authority matrix
package by have been
responsible received for
accounting personnel recording
and approved by provision for
approving authority doubtful debts.
to take legal advice
for collecting the
dues and filing suits.
Debtors written off The Accounts Check the bad Bad debts ledger
without approval receivable team debts in the Trail
share the list of ERP with the mail/Supporting's
customers who have share list by the for bad debts by
not made the authorised authorised
payment to Division person. person
157
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
heads and CFO.
Decision is taken to
written off the
balance and the
same is shared to
authorised personnel
to pass the entry in
the ERP/Accounting
Package.
Payment Regular delay in Monthly aging is Check that Aging
Collections collecting payments extracted from regular follow up Follow up mail
from customers. ERP/Accounting is done with
Package by customer whose
marketing team and payment is due
regular follow up is
done with the
customer whose
payment is due.
Cheque received but 1) Cheques received Check the Receipts data
not deposited in are collected by the deposit slip with Deposit slip
Bank marketing team and entry in the ERP
forwarded to
accounts
department, and
cheque is deposited
in bank on the same
day or next working
day.
2) Monitoring of
cheque deposit being
done on regular
basis.
Cheque deposited in After receiving the Check Bank Ledgers
bank but not cheque from the organisation Bank Statements
accounted marketing team, books are Reconciliation
entry is made in matching with
ERP/Accounting bank
Package on the statements, and
same day or next daily bank
158
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
working day. BRS is reconciliation
also prepared and statements are
monitored on daily being made
basis,
Collections are Collection is Check bank Bank
recorded incorrectly recorded in reconciliations Reconciliation
in the books with ERP/Accounting are prepared, Statements
respect to amount, Package and and appropriate
period or customer approved by journal entries
account. authorised person are passed as
after verification of per
supporting reconciliation
document. Further,
reconciliation is
performed for bank
ledger & bank
statement and
deviations are
recorded accordingly.
Incorrect calculation Interest on defaulting Check whether Customer Ageing
is done for the companies is to be the sales Invoice Receipts
interest accrued on calculated on the proceeds have data
the outstanding basis of a fixed been realised interest working
receivable balance. percentage as per within the time
approved policy and limit as per the
same is to be as per credit
approved by the given to
authorised person. customer.
Obtain collection
date & invoicing
date for all
invoice and
verify interest
has been
charged on
defaulting
companies
Reporting Revenue is not Organisation has Ensure that an Revenue
and Data recognized as per defined revenue appropriate, Recognition
Manageme applicable AS / recognition policy in consistent
159
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
nt organisation policy compliance with revenue Policy
applicable recognition
accounting standard. policy is applied
at the year end.
Ensure that the
policy adopted is
in line with
generally
accepted
accounting
principles.
Compare the
Organization’s
policy for
accounting sales
with the
significant
accounting
policies
mentioned in the
Notes to the
Accounts.
Transactions have Monthly sales Check Revenue Sales Data
been recorded in invoices, GST is recorded in GST Returns
incorrect period. returns, e-way bill & correct period Invoice Data
sales data as per and apply cut-off
Reconciliation
accounting package procedures for
are reconciled by testing.
person responsible,
to ensure no invoice
is omitted to be
recorded and
recorded in the
current financial
period/ year.
Reconciliation are
approved by
authorised person.
Fictitious /duplicate All invoices are to be Check that Approved
sales are recorded in authorised/ approved invoices are invoices
160
Order to Cash – Manufacturing
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
the books of from Authorised approved from Ledger of sale
accounts. Signatory. authorised
Further all entries are signatory and
approved as per entries are
approval matrix. approved as per
approval matrix.
Sales transactions Sales entry is passed Scrutinise sales Sales Schedule
are not properly by person ledgers on Sale leger
classified in accounts responsible, and it is overall basis,
approved by and check sales
authorised person. are recorded in
correct ledgers.
Benefits for export Export incentive Check trail Working of export
sales not availed/ working is prepared, mail/supporting' incentive
under availed by the and it is reviewed by s of approval as Trail mail
Organisation. authorised person. per approval
matrix.
Export sales are All export sales are Check export Export sale
recorded at incorrect recorded at same sale made are ledger
foreign exchange day prevailing CBEC recorded at Invoice
rate. website rate. Sales rates as CBEC rates
entry is passed as specified by
per accounting accounting
manual. manual
Accounting for Separate expense Check Books of Account
exempt sales is done and revenue ledgers accounting for
incorrectly in books are made related to exempt sale and
of account. exempt sales for taxable sale in
compliance with books
applicable tax laws
Customer No policy has been Approved Policy for 1. Obtain policy Customer
Evaluation formed for evaluation evaluation of of customer Evaluation Policy
of customer. customer has been evaluation
formed.
Customer The Customer Check whether Customer
evaluations are not Evaluation is done as customer Evaluation
being performed per policy. Marketing evaluations are forms/report
regularly. and Finance team is being
responsible for doing performed, and
161
Internal Audit Checklist
Proces Sub- Risk Description Control Test Performed Attributes Data analytics
s process tested performed
the customer approved
evaluation. Based on customer list is
the same and updated as per
subsequent the evaluations
discussions with the
approving
authorities, Sales
depart-ment revises
the approved
customer list and
block customers as
per evaluations list.
Customer No policy has been Approved Policy for 1. Obtain policy Customer Policy
Complaints for handling of handling customer of handling
customer complaints. complaints has been customer
formed. complaints
Policy made for Authorised levels are 1. Check for Customer Policy
handling of customer formulated for compliance with Complaint Log
complaints not handling a customer the policy for
complied. complaint, regular handling
monitoring is done to customer
ensure customer complaints.
complaints are
handled as per policy
by authorised
personnel.
Timely redressal of Authorised person as 1. Check status Complaint Log
customer complaints per policy handles of customer
not done. customer complaints complaints.
and take appropriate 2. Report
action. complaints
Regular monitoring is which have not
done for status of been resolved in
customer complaints time specified as
by authorised per Organisation
personnel as per policy
company policy.
162
Checklist 17
Order to Cash – Services
Process Sub- Risk Description Control Test Attributes Data
process Performed tested analytics
performed
Order to Customer Customer chosen is Defined process to Check whether 1. Credit
Cash Managem not appropriate to check the customer credit Worthiness
ent complete the contract worthiness and worthiness of Supporting
obligations resulting in approval from all new credit 2. Approval for
bad debts. marketing head is customers has customer.
needed for finalising been evaluated
customer. by checking
Credit worthiness company’s
process should include financial heath,
the following: credit’s history,
• Analysis of customers’ edit rating
latest available report and
financial statements. documented for
approval.
• Understanding
customers’
management and
business.
• Personal guarantee.
• Reference Check.
• Evaluation of 4 C's of
Credit
Proper documents not Authorised Person 1. Check the 1. Customer
taken from customer at approves onboarding customer hard Hard file
the time of onboarding. of a new customer file to test
after reviewing data Customer form
input with the and other
supporting's attached required data
with customer form. for onboarding
Documents needed
with customer form –
• GST Certificate
• PAN card
• E-mail ID
Internal Audit Checklist
164
Order to Cash – Services
165
Internal Audit Checklist
166
Order to Cash – Services
167
Internal Audit Checklist
168
Order to Cash – Services
169
Internal Audit Checklist
170
Order to Cash – Services
171
Internal Audit Checklist
172
Order to Cash – Services
173
Internal Audit Checklist
174
Order to Cash – Services
175
Internal Audit Checklist
176
Order to Cash – Services
177
Internal Audit Checklist
178
Checklist 18
Purchase to Pay – Direct Material
Process Sub- Risk Control Test Attributes Sample Data Process
process Descriptio Performed tested size analytics Metrics
n performed
Procure Vendor Risk of Defined 1. Check the 1. Approvals 30 new 1. New -Number
ment Manage chosen of process for approval for for vendors vendors of
ment incompeten vendor technical evaluations. vis-à-vis certified
t vendor evaluation evaluation 2. Support- existing suppliers.
and supply and approval and ing for vendors -Number
of inferior exists and supporting evaluations 2. Single of local
quality of includes the documents vendors for and
goods. following: thereof. non-critical global
- technical 2. Check items suppliers.
and approval for -Number
commercial commercial of
evaluation by evaluation national
cross and contracts.
functional supporting -Number
teams. documents of rate
- approval thereof. contracts.
authority. 3. Check -Supplier
- single justification developm
vendor for ent
justification exceptions, if programs
like for any. .
imports or
critical items
including
development
of new
vendors.
180
Purchase to Pay – Direct Material
181
Internal Audit Checklist
182
Purchase to Pay – Direct Material
Also, the
vendors are
required to
inform as per
the standard
terms and
conditions
printed on the
Purchase
Order, if they
have any
relations
employed
with the
organization.
183
Internal Audit Checklist
184
Purchase to Pay – Direct Material
185
Internal Audit Checklist
The company
has defined
procedure for
undertaking
the above
activities.
186
Purchase to Pay – Direct Material
187
Internal Audit Checklist
The reviewer
verifies the
details in the
PO with the
supporting.
Access to
create and
approve PO
are with
different
users in ERP
system.
188
Purchase to Pay – Direct Material
189
Internal Audit Checklist
190
Purchase to Pay – Direct Material
191
Internal Audit Checklist
192
Purchase to Pay – Direct Material
193
Internal Audit Checklist
194
Purchase to Pay – Direct Material
195
Internal Audit Checklist
196
Purchase to Pay – Direct Material
197
Internal Audit Checklist
198
Purchase to Pay – Direct Material
199
Internal Audit Checklist
Business All POs are 1. Check that Unauthorise 1. ACL Same Servicing
share reviewed and the PO is d approval 2. material time for
allocation approved as approved as rights Authority different each of
amongst per the per Authority Matrix suppliers the
different approved Matrix. 3. 30 Item cost supplier
vendors Authority 2. Check the POs Lead time for same
results in Matrix. Also, ACL and for delivery material
higher the same has confirm that of material
procureme been entered the same is for different
nt prices into ERP updated as suppliers.
software in per Authority
Access Matrix.
Control List
(ACL).
200
Purchase to Pay – Direct Material
201
Internal Audit Checklist
202
Purchase to Pay – Direct Material
203
Internal Audit Checklist
204
Purchase to Pay – Direct Material
Validity of The list of 1. Check the Open PO Open PO Open PRs Delay in
the open open POs / validity of dates listing and POs receipt of
POs / contracts is open PO / Ageing – materials
Contracts reviewed Contracts. Periodic as
monthly by Sr review and compare
Manager - closure d to PO
Commercial. process. date.
The
redundant /
expired PO
are purged
from the list.
Receivin Stock outs Open PO list 1. Check the 1. Open PO 1. 10 Open PRs Delay in
g due to is prepared instances of dates weeks and POs receipt of
delays in on a weekly stock outs 2. stock outs open PO Ageing – materials
delivery of basis by the and review list Periodic as
stocks Commercial the 2. Stock review and compare
ordered department. justification / out event closure d to PO
through This is used root cause list process. date.
open Pos. as basis for for the same.
tracking 2. Check
timely whether the
deliveries by buyers track
the buyers. deliveries
against the
Open PO list.
205
Internal Audit Checklist
206
Purchase to Pay – Direct Material
207
Internal Audit Checklist
208
Purchase to Pay – Direct Material
209
Internal Audit Checklist
210
Purchase to Pay – Direct Material
211
Internal Audit Checklist
212
Purchase to Pay – Direct Material
213
Internal Audit Checklist
214
Purchase to Pay – Direct Material
215
Internal Audit Checklist
216
Purchase to Pay – Direct Material
217
Internal Audit Checklist
218
Purchase to Pay – Direct Material
219
Internal Audit Checklist
220
Purchase to Pay – Direct Material
Non receipt The listing of 1. Check the 1. Open PO Open PO Open PRs Delay in
of material Open POs is due dates in dates listing and POs receipt of
against reviewed the open PO 2. justifi- Ageing – materials
advances monthly to / Contracts. cation for Periodic as
check the 2. Check the delays review and compare
cases of reasons for closure d to PO
delayed delays in process. date.
supplies supplies.
wherein
advances
have been
221
Internal Audit Checklist
222
Checklist 19
Purchase to Pay – Indirect Material and
Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Procure General Procurement The As per 1. Check 1. Approved Approved NA
ment of and policy and organisation compan clear procurement procurement
Indirect entity Authority has clear y policy updated policy policy
Material level matrix may not and procurement 2.
and control be prepared or comprehensi policy Completene
Services approved by ve (up to approved by ss
Board of date) Indirect BOD or
Directors and material and designated
thus leading to service authority.
risk of procurement 2. Check it
procurement at policy as addresses all
unfavorable approved by attributes
conditions to Board of related to
the Directors service
organisation. (BOD) or procurement.
designated
authority.
1. The As per 1. Check Approved Approved NA
organization compan Indirect DOA/DOP DOA/DOP
has clear y policy material and for purchase from BOD
and service
comprehensi procurement
ve (up to DOA/DOP is
date) available and
Delegation of approved by
Authority BOD.
(DOA)/
Delegation of
Power (DOP)
and Authority
Matrix.
2. Authority
Matrix is
approved by
Board of
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Directors,
defining the
authorities
for approving
purchase
transactions
or performing
various
transactions
during the
purchase
process.
Inadequate 1. Document As per 1. Check 1. Docum- 1. SOD Analyse
Segregation of defining compan documented ented SOD, 2. Access transaction
Duties and appropriate y policy SOD and Access right right List carried out
access rights Segregation Access right 2. Periodic during the
which may of Duties list which are 3. Half yearly review
review review
result in (SOD) is in duly period to
fraudulent / place. updated. document identify the
unauthorised 2. Access 2. Verify following:
transactions. rights (Write same SOD 1. Un-
/ Read / and Access authorised
Delete / right also users
Modify) to input in the performing
various system for transactions.
people in the approval of 2. Con-
origination of transactions flicting
reviewed 3. Verify transaction
periodically evidence of rights
to ensure periodic granted to
appropriate review of same
SOD and SOD and person.
avoid any Access rights 3.Internal
unauthorized in ERP Auditor to
transact- system. review the
ions. circumstanc
3. Periodic es of conflict
Review of of interest.
Segregation
of Duties and
Access rights
is conducted.
224
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
SOP may not 1. The As per 1. Check Approved Updated SOP NA
be defined to organization compan SOP SOP and
ensure has clearly y policy available and completenes
consistency defined complete in s
and Standard all aspect of
standardization Operating roles, KPIs,
of operations. Procedures Timelines
and are in and
place. frequency of
2. SOP activities,
should define etc.
the 2. Check
sequence of when SOP
activities, updated last
Roles and and enquire
Responsibiliti the reason
es, Key for not
Performance updating the
Indicators SOPs in
(KPIs), case, not
Timelines updated for
and long time.
Frequency of
activities
along with
various
documents
to be
maintained
by the
organization
for
procurement
of Indirect
material and
service
transactions.
Review system Review As per 1. Review 1. MIS MIS for 3 Analyse
to mitigate risk system is in compan appropriaten 2. RSM months various
of place to y policy ess of 3. Fraud figures
inappropriate mitigate risk Management assessment Action and reported in
transaction in Information activity step taken to MIS vis-a-vis
may not be in procurement System identify and the details
225
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
place. of indirect (MIS) for control appearing in
material and regular fraudulent ERP system
services. monitoring of activity. to identify
1. operations instances of
Management and financial incorrect
Information activities by reporting.
System senior / top
(MIS) for management Risk
monitoring of , especially management
procurement for any : To review
of indirect management the risks that
material and override of are being
services are controls. mitigated
in place. and whether
2. Risk 2. Review there is any
management appropriate risk not
system is in Risk being
place to Management mitigated.
identify and System is in Risk being
mitigate risk place to dynamic,
related to identify and whether
procurement mitigate emerging
of indirect various risk risks are
materials related to also covered
and services. procurement needs to be
3. Fraud risk activities of reviewed.
assessment the
activity organization. Fraud Risk:
conducted by Critical
management 3. Review of review of
frequently. Fraud Risk transactions
Assessment from the
activity is possibility of
conducted, fraud.
and fraud
risk are
identified
along with
relevant
controls to
avoid any
fraudulent
transactions
viz.
226
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
unapproved
transactions,
fictious
invoices and
payments,
etc.
Annual Procurement 1. Base for As per 1. Check Approved Approved Verify the
procurem budget may not preparing compan Annual budget and Budget for the accuracy of
ent be prepared budget and y policy Procurement subsequent year the Budget
budget of and monitored Budget is Budget is monitoring vs Actual
indirect on regular approved by approved by Budget Vs MIS from the
material basis to avoid the BOD the actual MIS for independent
and deviation in before start designated 3 months and data source
service future. of financial authority and upto date e,g,
year. agreed with / transactions
communicate recorded in
2. Monitoring d to the ERP to
of Budget Vs relevant identify
Actual is authorities instances of
done on delegated incorrect
monthly authority well monitoring
basis and in advance. or Budget
review of overrides. to
action plan 2. Review of understand
wherever periodic the reasons
required. monitoring of for variances
deviations and not
(variances) limited to
from the (a) incorrect
approved preparation
budget of budget (b)
conducted accounting
along with and
reasons for classification
deviations, if of errors (c)
any. use of
budgetary
3. Action provision for
plan is other
documented purposes,
and adhered etc.
for avoiding
such
227
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
identified
variance in
future.
Absence of 1. Approved As per 1. Check Approved Approved Verify the
formal planning procurement compan annual plan budget and Budget for the accuracy of
policy may lead plan is is y policy is developed subsequent year the Budget V
to increased existed for defining monitoring Actual MIS
material and prepared and the material Budget Vs from the
service cost or prepared requirement actual MIS for independent
increased based on the for each of 3 months and data source
inventory production the upto date e,g,
levels. plans or departments. transaction
business The plan is recorded in
plans. duly ERP to
approved by identify
2. the different instances of
Operations HODs and incorrect
are CEO. The monitoring
conducted as plan includes or Budget
per plan and the following overrides.
process is in factors
place to (regarding
identify and procurement)
report :
deviations. a. type of
corrective material
actions are required in
required to terms of
be taken units, price,
where there source and
are other
variances. preferences
b. frequency
of
requirement
c. autho-
rization
2. Check
based on the
Annual plan,
purchase
department
228
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
identifies the
suppliers for
the regular
material,
agreements
with the
suppliers,
communicati
on of the
plan to the
suppliers,
lead time for
delivery,
periodicity of
supply, etc.
Vendor Vendor chosen Defined As per 1. Check the 1. Approvals 20% of new 1. Analyse
Selection is not process for compan approval for of plan vendors or 20 vendor list of
and competent vendor y policy technical evaluations whichever is current year
Master resulting in evaluation evaluation 2. higher vis-à-vis
Manage inferior quality and approval and Supporting previous
ment of goods being exists and supporting for year to
supplied. includes the documents evaluations identify
following: for addition of
- technical delegation of new vendors
and authority. to increase
commercial 2. Check competition.
evaluation by approval for 2. Analyse
cross commercial sufficient no.
functional evaluation of vendor
teams. and were for
- approving supporting each type of
authority. documents service and
- single for material to
vendor for delegation of get best
imports or authority. competitive
critical items 3. Check rates,
including justification 3. Check
development for quotations
of new exceptions, if were taken
vendors. any, and to find
Any reason there competent
regulatory for. vendors on
requirements 4. See the regular basis
229
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
to be overall to give
fulfilled. approval contract to
including that appropriate
party is in parties.
approved
vendor list.
Incomplete/ 1. Pre- As per 1. Check 1. Approved 30% of new Analyse
Inaccurate defined / compan approved format for vendors or 10 Vendor
vendors Pre-designed y policy vendor creation/alte whichever is Database for
records Vendor format and ration higher any
creation all requests 2. duplicate
forms should be Completene vendor
contains key received in ss and records and
details of standard accuracy correspondin
vendor i.e. format only. g purchase /
Name, PAN, 2. Complete payment
Address, details of transactions
Contact vendors filled with such
Details, GST in format codes.
registration mentioning
details, Bank not
Account, applicable in
place of case, any
business, field is not
MSME applied.
certificate, 3, Check
Turnover system
details for e- control to
Invoicing, avoid
etc. duplicity at
2. Mandatory code level,
field are PAN and
defined in GST level,
the system address and
without contact level.
which vendor
code is not
allowed to be
created in
the system.
Selection of 1. Market As per 1. Check the Managemen Select 2 1. Analyse
inappropriate research are compan list of pre- t review and contractor that vendor
230
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
material / carried out y policy qualified approval from each
list are
vendor from time to contractor for mechanism major Service
updated by
time to different to identify and material
company on
specify the types of prospective group frequent
minimum Service vendors basis and
timeline to requirement Or as per should have
identify of business sufficient
prospective organization. need vendor who
contractor for actively
the required 2. Check due participate in
Service/ diligence and bidding.
Material. financial / 2. Check
operational company
2. and technical should not
Appropriate background be
due-diligence check dependent
and financial performed as on some
/operational per checklist. vendors for
and technical quotation
background 3. Frequency purpose.
checks be of updating
performed as of list and
per approved identify non-
checklist and responding
the bidders.
contractor be
added to the 4. Check
approved list approval
after due from
approvals. designated
3. Con- authority of
tractors who selected
do not vendor for
participate in quotation
bidding purpose.
process, are
reviewed and
removed
after
obtaining
NOC from
them.
4. Con-
231
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
tractor are
selected on
basis of pre-
qualification
and merit
basis. After
selection of
vendor, list is
approved by
designated
authority
before
asking for
quotation.
1. Open As per 1. Check Tendering PO Records Analyse
tender compan open as per policy ERP Open
system are y policy tendering of the tender,
followed for used by the company Limited
high value company for tender data
transactions high value or and verify
or critical critical that
services / service/ tendering is
material as material done as per
per the transaction policy of the
organization or for company.
policy for specific
inviting all procurement
possible s.
vendors for
indented 2. For other
procurement. services/
2. Limited material
tender limited
requests for tender
quotation are request are
given to the sent to all
pre-approved approved
vendors for vendors.
select 3. Check
category of method used
service/mate for open
rial or value tender, i.e.,
below the no. of
232
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
define limit advertisemen
as per the t in different
organization newspapers,
policy. coverage
area and in
different
languages to
create
competition
among
vendors.
4. Check
NOC are
obtained
from vendors
who did not
send quote.
Standard As per 1. Check Standard For 5 major NA
request for compan standard format used tenders and 5
Quotation / y policy format of for Tender major RFQ
tender are request are /quotation process or
prepared and approved cover 40%
circulated to and used by tender
all parties for departments. whichever is
inviting 2. Check higher.
quotations as changes
per the should be
organization’ done by only
s policy. by
addendum
after
approval.
3. If
quotation,
not in
standard
format,
should be
rejected
unless there
is a chance
to accept the
233
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
quotation.
1. Technical As per 1. Check 1. Defining for 5 major Analyse
criteria are compan technical of technical tenders and 5 tracker to
defined in y policy criteria for criteria major RFQ verify
the bids as selection of 2. Deviation process or technical
per the vendor are approval cover 50% qualification,
requirement define in bids tender details are
of user and matched whichever is obtained and
department with higher. considered
and requirements for all
approved by as specified bidders.
HOD by user Note:
(purchase). department exception
2. Marks are and and check
allotted to approved by approval of
bidders on HOD. deviation are
the basis of 2. Check obtained.
technical technical
qualification qualification
and no of document
deviations and mark is
allowed. allocated to
bidders
based on it
only.
3. Check for
any deviation
from
technical
qualification,
verify
approval of
designated
authority.
Possibility of Same As per 1. Check 1. Same and for 5 major Analyse time
vendor timelines and compan bidding timely tenders and 5 tracker of
preference process are y policy document process for major RFQ
followed for and process all parties process or - Submission
all parties to verify 2. Deviation cover 50% of technical,
and deviation timeline and approval tender financial
are approved process are whichever is qualification
234
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
by common in higher document
designated case of all and approval
authority tendering thereof.
except parties - Submission
procurement 2. In case of of financial
of low value deviation bidding and
and selected approval approval
category as obtained
per from to verify all
procurement designated process are
policy. authority. followed in
time bound
manner for
all vendors.
Note
exception
and check
deviation for
same to
check
tendering
process is
monitored
properly.
Selection of 1. As per 1. Check 1. Approval For 5 major Analyse
wrong vendor Comparative compan whether on tenders and 5 ERP or other
or high cost of quotation y policy comparative comparative major RFQ softwares for
procurement. analysis sheet of bids sheet process or final
sheet drawn is prepared 2. Deviation cover 50% comparison
before or not. approval tender of rates for
purchases 2. Check 3. Sign off whichever is all vendors
are Justification by tender higher with original
approved. for selection committee rates quoted
of other than by individual
2. If lowest lowest vendor to
quotation is bidders and identify
not approval of difference.
accepted, the same.
appropriate 3. Check
justification whether
be quotation
documented opened,
and registered
235
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
approved by and
designated comparative
authority. list is
approved by
3. Quotations authorised
are opened persons.
and 4. Check
registered, quotation
and a opened in
comparative presence of
chart is tender
prepared and committee
authorised. for qualified
4. Quotations bidders and
are opened sign off by
in presence them.
of tender 5. Check
committee order given
only for the to lowest
qualified bidder but
bidders and whether
rest bid may earlier
be rejected. project was
performed by
him within
time and cost
(Check
history of
vendor).
1. Approved As per 1. Check 1. Approval for 5 major Check
note with all compan justification note with tenders and 5 justification
relevant y policy must be Justification major RFQ given in
justification prepared and process or approval
is approved by cover 50% note with
documented designated tender actual work
for selected authority. whichever is performed
vendor by higher by vendor or
designated 2. Check with
authorities. justification previous
must be work
2. Adequate supported by performed
approval (as evidence, from ERP
per i.e., project records.
236
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Companies delivered in 1. Quality
Act,2013, past. rejection
SEBI) from 2. Timely
Board of 3. Check delivery
Directors is justification 3.
in place for given in Qualitative
purchase approval delivery
from related note. Verify
parties. justification
with actual
work
performed by
vendor
during audit
period or
record of
previous
work
performed by
same
vendor.
Non- 1. Adequate As per 1. Check BOD All purchase Analyse
compliance to approval compan BOD approval from related ERP data to
requirement of from Board y policy approval and party. check rates
Companies Act of Directors obtained in justification of other
and other is in place for case of vendor with
regulations purchase purchase same
from related from related requirement
parties. party. s as of
2. Check related
2. Disclosure disclosure parties to
of related note given in verify
parties and financial transaction
purchased statement. are
from it. 3. performed at
Justification arm length
3. Adequate documented basis or not
documentati for purchase
on is in place from related
to justify parties.
price of 4. In case of
purchases purchase
from related from related
237
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
parties. party,
compliance
with relevant
provisions of
Section 188
of
Companies
Act, 2013.
5. The
procurement
price is
reasonable
according to
Section 40
A(2) of
Income Tax
Act, 1961, if
purchase is
made from
sister
concern.
System control 1. System As per 1. System System System Analyse
may not be are not compan walkthrough control for walkthrough ERP or other
implemented allowed to y policy for RFQ modification software
for modification raise RFP without at RFQ final rates
at RFQ level, without approved level, data for all
Quotation approved requisition. quotation vendors with
level, approval requisition in 2. System level, original rates
level may lead place. walkthrough Identified quoted by
to unauthorised for vendor and individual
purchase. 2. All vendor modification other vendor to
quotations in quotation information. identify
and bid are and locked difference.
locked in parties, so
modification identified,
and are check the
opened in audit trail for
presence of it.
designated 3. Check
authorities. rates of
vendors in
3. Selected final
party is comparison
238
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
identified sheet
and locked in matched with
system after rates in
all approval. individual
quotes.
4. System 4. Verify all
are not approved
allowed to vendor with
backdate / final vendor
modify any comparison
information list.
once process 5. Change
is completed. log must be
available for
all
modification
and reviewed
by
authorised
person.
Unauthorised 1. Updates As per 1. Check the 1. Approvals 40% of Analyse
updates / (Additions / compan Access for addition / addition/alter transaction
alterations may Alterations) y policy Control List alteration, ation or 20 carried out
be made to to the vendor (ACL) is as 2. ACL whichever is in vendor
vendor master. master are per approved higher master
made only authorities during the
with the matrix. review
approval of 2. Check that period to
authorised the person identify the
person on making the following:
the basis of addition / 1.
requisition in alteration is Transactions
proper authorised to performed
format from do so. by
users. 3. Verify unauthorised
vendor users.
2. Also, the creation/alter 2.
access to ation forms Conflicting
make are approved transaction
additions / by rights
alteration to authorised granted to
the vendor persons. same
master is person.
239
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
restricted to
personnel
authorised
as per
approved
Authorities
Matrix. The
Authorities
Matrix is
entered in
the Access
Control List
(ACL) in the
systems(Nor
mally
additions/
alteration
rights
provided to
IT).
Inaccurate Recorded As per 1. Check that 1. 40% of Analyse
updation in the changes to compan information Supporting alteration or vendor
vendor master. the supplier y policy so entered is documents 20 whichever master data
master file reviewed and 2. Approvals is higher to validate
are authorised. following:
compared to 2. Check
authorized with the 1. Matching
source supporting of PAN with
documents documents GST
by that the 2. GST no.
authorized information with state
person to has been code
ensure that Completely & 3. Length of
they were Accurately PAN and
input entered. GSTIN
accurately 4. Length of
and he mobile
should be number
different from 3. Check
person who bank
entered data account no.
in file. provided or
not.
240
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Analyse
Vendor
Database is
comprehensi
ve, and all
vendor
details are
complete
and accurate
– viz.,
Name, PAN,
Address,
Contact
Details, GST
registration
details,
place of
business,
etc.
Audit logs for Request to As per 1. Check the 1. 1. Request NA
changes made change compan request log Outstanding log
in vendor supplier y policy to ensure list in
master may not master file is that there are Request log
be available logged; the no long
and reviewed log is pending
that may lead reviewed to requests for
to unauthorized ensure that change.
changes. all requested
change is
processed
timely.
Steps taken
when there
are
unauthorized
changes.
Critical vendor 1. Vendors As per 1. Verify mail 1. MEME 20% of NA
data is are classified compan sent to and E- service
incomplete and correctly as y policy vendor for invoicing /material
is not up to MSME data declaration Vendor vendor
date. in master as MSME listing.
241
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
and updation and for
are done on turnover. In
yearly basis. case, there is
MSME portal for
certificates vendor,
are obtained check vendor
yearly. have
2. List of submitted
vendors who their
have to do E- credential.
Invoicing are 2. Verify
prepared and vendors’
bills are declaration
processed received and
accordingly. vendors’
record
updation is
done on the
basis of
declaration.
3. Verify E-
invoicing by
specified
vendors.
Request to As per 1. Check the 1. Sequence 1. Request NA
make compan request log of the log
change in y policy to ensure request
supplier that there is forms used.
master file is no missing
submitted request.
account and Alternatively,
ensure that there should
all requested be request
changes are cancellation
processed note in the
timely. log.
Supplier As per 1. Check the 1. Management NA
master is compan evidence of Managemen signoff or
periodically y policy the t review of approved file.
reviewed by management supplier
management review. master
for accuracy
242
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
and ongoing
pertinence.
Risk of conflict 1. As per As per 1. Check the 1. 1. NA
of Interest of Company’s company employee’s Declarations Certifications
vendor Code of policy declarations by vendors from 30%
Conduct, for and by the employees
the compliance employees. 2.Acknowledg
employees with the ement from
are ethical 20% vendors
mandated to standards. or having
inform the 2. Check the 60% business
concerned vendor’s with
HOD / acknowledge company.
Superior ments in the
where PO, if they
conflict of have relation
interest with
exists. employee.
2.
Employees
are required
to comply
with the
policy.
3. Also, the
vendors are
required to
inform as
per the
standard
terms and
conditions
printed on
the PO, if
they have
any
relations
with
employee in
organization
.
243
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
One-time 1. There is As per 1. Check by 1. Field 1. List of one- Analyse
vendors are an option of compan creating a validation to time vendors. ERP records
not subjected ticking "One y policy dummy PO, use code 2. PO for POs with
to same time flag" if the vendor one-time Records pre-define
controls as all which needs flagged off only. 3. System one-time
other vendors. to be as One time walkthrough vendor code
updated at user. and identify
the time of more than
vendor 2. Obtain a one PO are
creation. As list of One- raised with
a result, the time vendors one-time
vendor gets and compare code from
deactivated it with the PO same
after placing Records to vendors.
one PO. check
whether one-
2. Specific time vendors
vendor code have not
is used for been used
creating one- more than
time vendors once order.
(e.g. 1000
for domestic
and 1100 for
import).
Contractor 1. As per 1. Verify 1. contractor 1. For annual Analyse PO
performance Performance compan whether the Performance appraisal - record with
not reviewed Appraisal of y policy contractor evaluation check GRN records
periodically vendor is appraisals and appraisal of to identify
done once in have been appraisal 30% vendor wise:
a year for done contractor or - Cases of
long term PO annually & 15 whichever quality
/ Contract quarterly as is higher. rejection
and quarterly the case may 2. same for - Case of
for short be and it quarterly late delivery
term PO / documented. appraisal. against PO
Contract. . Verify terms
department - Cases of
2. Based on wise list of low quantity
the vendors and delivery
evaluation, total against PO
Approved appraisal quantity
contractor done during
244
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
list is audit period to ascertain
updated. by each 1. Vendor
respective department. with low
departments performance
are 2. Verify evaluation
responsible updation of have high
for doing the the approved share of
contractor contractor business
appraisals. list on basis 2. Action
of appraisal, taken
3. Based on Check list is against
the same updated on regular
and the basis of default
subsequent appraisal vendor.
discussions only.
with the user
department, 3. Mails sent
the to contractor
Purchases by
department management
revises the to take action
approved otherwise
contractor remove from
list. approved
vendor list.
Dummy/ 1. Contractor As per 1. Compare 1. dummy / 1. Active Analyse
inactive/ that have not compan the active Inactivity in vendor listing Vendor
unsatisfactory been y policy vendor listing vendors 2. PO master file
performance selected (VLOOKUP) accounts Records for Service
by contractor from a with the PO 3. /Material PO
significant listing for the Performance list of 2 to 3
period of year. evaluation years to
time are 2. Scrutinize report ascertain
reviewed by the vendor following:
purchase Records for
team and vendors with 1. Blocking
marked for common/ of vendors
deletion. dummy with whom
names or organization
2. Ensure details. had no
contractor 3. transaction
are timely Unsatisfactor 2. Restrict to
blacklisted y vendors use vendor
245
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
wherever removed code for
required for after non-
unsatisfactor performance submission
y evaluation. 4. of updated
performance User KYC
as per the department document.
defined approval for
policy. removal of
service /
3. Vendors material
are restricted vendor.
for award of 5. Check
contract, who vendor are in
are not master but
engaged with work or
organization transaction
from long could not
period and performed
are allowed with them
after updated due to
KYC restriction or
document blockage.
only. 6. Check
process to
obtain
updated KYC
document if
vendors are
used after
define
period.
Placing Inadequate Sufficiency As per 1. Check for Number of Select 1. Analyse
Order number of of compan compliance contractor vendors and vendor list
vendors are quotations, is y policy with the vis-à-vis the correspondin are updated
identified for checked purchase requirement g PO's to by company
RFQ before policy for of purchase cover major on frequent
approving identification policy item and basis and
the PO. of vendors service should have
for RFQ. category sufficient
Justification 2. Check (Cover at vendor who
for deviation whether in least 60-120 actively
from case, the PO's or more participate in
purchase requisite depend on bidding.
246
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
policy is number of quantum of 2. Check
mentioned vendors were business) company
as remarks, not available, should not
which is also the due be
reviewed by escalation dependent
the approver procedure on some
before PO is was followed vendors only
approved. 3. Ask for quotation
reason for purpose.
significant
change in
rates of
products.
Check
reason and
approval of
higher price.
4. Approval,
in case
change is
approved
vendor.
All POs are As per 1. Check the Prepare, Cover all Analyse
required to compan approvals for Review and service transaction
be approved y policy the PO with Approval of /Material and carried out
by approved the Authority purchase approval in vendor
authority Matrix. order matrix which master
matrix. The 2. In case, combinedly during the
Authority the cover more review
Matrix approvals than 30% of period to
specifies the are not as purchase identify the
expenditure per the value. following:
limits of the authority 1.
relevant matrix, Unauthorise
personnel ratification / d users
and has justification performing
been entered for the same transactions
into relevant needs to be 2.
software. checked. Conflicting
transaction
rights
granted to
same
247
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
person.
Also analyse
purchase on
same or
nearby dates
to identify
cases of
splitting of
PO to
override
authority
matrix.
PO's raised 1. PO is As per 1. Check that 1. Quantity Cover all NA
with wrong prepared by compan the PO is as per service
quantity / rates the y policy supported indent vis-à- /Material and
/ payment designated with a duly vis PO approval
terms, etc. person which approved 2. Approval matrix which
is reviewed indent. for the PO combinedly
and 2. Check that cover more
approved by the PO is than 30% of
the person approved as purchase
so per Authority value.
authorized Matrix
as per 3. Check
Authority creating and
Matrix. approving
right should
2. The be with
reviewer different
verifies the person.
details in the
PO with the
supporting.
3. Access to
create and
approve PO
are with
different
users in
system.
248
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Indent raised / The indent is As per 1. Check that 1. Approvals Cover all Analyse
approved for reviewed and compan indents are for indent service transaction
purchase when approved by y policy approved in 2. Access /Material and carried out
there is no the accordance control list approval during the
requirement for authorized with the matrix which review
goods / personnel Authority combinedly period to
services or (as per the Matrix. cover more identify the
goods are limits set out than 30% of following:
already in in approved 2. Check purchase 1.
stock Authority whether value. Unauthoirse
Matrix), Authority d users
signifying the Matrix is performing
need to configured in transactions
procure the system in 2.
material. The Access Conflicting
Authority Control List transaction
Matrix is for system rights grated
configured in control point to same
the ERP of view. person.
system in
Access
Control List
(ACL)
Unauthorised 1. The indent As per 1. Check that 1. Approvals Cover all Analyse the
indents may be is reviewed compan the indents for indent service total Service
raised for and y policy are approved 2. Budget /Material and budget
purchases. approved by in availability approval approved by
the accordance at the time matrix which department
authorized with the of indent combinedly before start
personnel Authority approval. cover more of year and
(as per the Matrix than 30% of total value of
limits set out 2. Check purchase indent
in approved service value. approved
Authority budget during
Matrix), availability budget
signifying the while period to
need to approving of verify.
procure indents.
material. The 3. Check -Indent
Authority excess approved
Matrix is budget are more than
entered in approved original
the ERP from budgeted
249
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
system in authority in without
Access case of total obtaining
Control List budget approval for
(ACL) exhausted by excess
2. Budget department budget
availability before which is
with release of against the
department service policy of
is considered indent. organization.
before
approval of
Service
indent
otherwise
indent could
not be
approved.
3. Service
budget are
approved
from
appropriate
authority to
release
indent.
The system, As per 1. Check the 1. Approval System Analyse
does not compan access for indent walkthrough records of
allow y policy control list to 2. Access and check purchase
changes to verify that no control list system despite
be made to one other allowed to same item in
the approved than HOD make hand and
indents. has changes in lying un-
They can modification approved utilised.
either access for indent.
cancelled or indent and Analyse
processed access to quantity,
for PO. The cancel specification
amendment indent. as per indent
rights are and PO
available records
only with punched in
Head of ERP system
Department for any
250
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
(HOD). deviation.
If excess
quantity
purchased,
verify excess
quantity
consumed or
not to, verify
wrong
decision of
high
purchase
against
indent.
Indent does not Specification As per 1. Check the 1. Exception Analyse
prescribe the s are compan exception Rejections report and ERP data to
correct mandatory y policy report due to Rejection compare
technical field in the generated incorrect / report for the specification
specifications indent and from ERP for missing period of as per indent
of cannot be indents specification audit. and
goods/services bypassed (in raised s. correspondin
required ERP). without any g
resulting in specification. specification
procurement of Maker 2. Check the in PO to
incorrect checker rejection identify
goods/ controls is report for the deviation.
services. established material
to verify rejected due Further,
completenes to incorrect verify
s and specification. deviation
correctness with rejected
of all details. GRN at
quality stage
to establish
rejection due
to wrong
purchase
against
indent.
Indent sent to 1. Material As per 1. Check 1. Timely Indent report Analyse
purchase and service compan indent conversion compare with ERP data of
251
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
department requisition y policy reports to of indents PO reports indent and
with delay may are sent to verify timely into PO’s PO to
hamper purchase sharing and identify
production department conversion of following:
activity. within approved
defined indent into 1. Time gap
timelines. PO. between
indent raised
2. Timeline 2. Check list and
are defined of indents approval/
for approval raised by release of
of indent and user indent.
issued department 2. Time gap
further to but not between
procurement approved indent
team for yet. release to
processing. PO approval
3. Check list date.
of approved 3. Expected
indents sent date of
but no action material as
initiated by per indent
purchase along with
team on deadline to
same. vendor in
PO for
supply.
to calculate
probable
losses due
to delay in
approval at
different
stage from
indent to
PO.
Indent does not The indent is As per 1. Check that 1. Approvals 1. System Analyse
prescribe the reviewed and compan the indents for indent walkthrough Purchase
correct approved by y policy are approved 2. Access for approval requisition
technical the in control list procedure transaction
specifications authorized accordance and to identify
of goods/ personnel with the specification. the
252
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
services (as per the Authority following:
required limits set out Matrix. 1.
resulting in in approved 2. System Incomplete
procurement of Authority walkthrough or incorrect
incorrect Matrix), to check details in PR
goods/services signifying the indent 2. PRs
. need to without backdate or
procure specification. raised after
material. The ordering
Authority 3. PRs are
Matrix is created for
entered in quantity/serv
the ERP ice in excess
system in of the
Access budgeted
Control List amount
(ACL) 4.
Indents Requisition
without the is in excess
specification of average
s are treated consumption
as or in spite of
incomplete high
since the inventory
quotations levels.
cannot be 5. Open PRs
obtained for not reviewed
the same. and closed
In case the As per Check the Service and Rejection
goods/ compan Material goods report along
services are y policy Rejection list specification with reasons.
rejected by and if it is s mentioned
Quality due to properly with
Control incorrect complete
department specification description.
or by user s.
department,
reasons for
the same are
reviewed to
ensure that
the same
were not due
253
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
to incorrect
specification
s mentioned
on indent.
Indents / PRs All As per 1. Check the Supporting Cover all Analyse PO
are not used supporting compan PO review documents service Records with
when documents y policy and approval (including /Material and Indent
purchasing (Indents/ven process. indents) approval Records to
goods or dor quote Check that matrix which verify each
services. analysis the PO is combinedly is supported
sheet/vendor supported cover more by indent.
quotes, etc.) with a duly than 30% of
are reviewed approved purchase
at the time of indent. value.
PO approval
by
authorized
personnel
(as per the
approved
Authority
Matrix).
POs do not All As per 1. Check the Supporting Cover all NA
contain supporting compan PO review documents service
accurate documents y policy and approval (including /Material and
information. (Indents/ven process. indents) approval
dor quote, 2.Check that matrix which
analysis the PO is combinedly
sheet, etc.) supported cover more
are reviewed with a duly than 30% of
at the time of approved purchase
PO approval indent. value.
by 3. To check
authorised accuracy of
personnel PO verify it
(as per the with
approved customer
Authority source
Matrix). document,
management
approval
process of
254
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
project.
All POs are As per 1. Check that 1. Approvals Cover all Analyse
required to compan the PO are 2. ACL service purchase in
be approved y policy approved as /Material and record to
by the per Authority approval identify the
authorized Matrix. matrix which following:
personnel 2. Check that combinedly 1.
(as per the the PO cover more Unauthorise
limits set out cannot be than 30% of d users
in approved created in purchase performing
Authority absence of value. transactions
Matrix), approval. 2.
verifying Conflicting
correctness transaction
and accuracy rights
thereof. The granted to
Authority same
Matrix is person.
entered in
the ERP
system in
Access
Control List
(ACL)
Service / ERP system As per 1. Check the 1. 1. PO records Analyse
Material prices requires the compan PO review Supporting 2. All cases of ERP data for
are not PO y policy and approval documents deviation in review of
competitive approving process. 2. Price rates within vendor
authority to 2.Check that fluctuations audit period quote by
review the PO is appropriate
vendor supported authority
quotes at the with a duly before
time of approved approval of
approval of indent. PO.
the PO 3. To check
accuracy of
PO to verify
it with
customer
source
document,
management
255
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
approval
process of
project.
The As per 1. Check that Sufficient Select Analyse
purchase compan specific quotes vendors and ERP data for
policy of the y policy number of obtained or correspondin number of
company quotes not g POs to quotation
requires required as cover major and compare
obtaining per purchase items and with
certain policy are services purchase
minimum obtained. (Cover at policy to
number of 2. Check that least 60-120 identify
quotations in case of PO's or more exception.
before exceptions, depend on
placing the procedure as quantum of Verify
order. In per the policy business) exception
case, the is followed. approval for
specified insufficient
number of no. of
quotes are quotes.
not available,
then as
procedure
specified in
the purchase
policy needs
to be
followed.
Change in 1. If the As per 1. Check by Price and Audit trail Analyse
order are not terms of an compan raising a scope report and change
authorised. approved PO y policy dummy PO, alteration in select 20 order record
are altered getting it original sample for to identify
for price and approved order. change order the
scope, it and then following:
automatically altering it. 1.
sends PO in 2. Check by Unauthorise
pre-approval review of the d users
stage. audit trail performing
report in transactions.
2. Original ERP, if any 2.
Pos’ terms PO has been Conflicting
are reviewed modified transaction
256
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
regarding after rights
provision for approval. granted to
change due same
to change in 2. Changes person.
price and could be
scope. done only if
original PO
permits for
changes.
1. The As per 1. Check Price and 15 PO or 50% Analyse
purchase compan whether the scope of change ERP original
policy of the y policy PO wherein alteration order POs with
company price has original whichever is change
requires that been altered order lower. orders due
in case of has been re- to price
Change in approved as revision and
Order, it per the check
needs to be Authority significant
re-approved / Matrix. impact on
re-processed 2. Check budget.
as if it is a amendment
new PO. no. shown in
PO after
2. price
Amendment change.
number must
be provided
in change in
order for trail
log of old
PO.
1. Change As per 1. Check 1. Authority 15 PO or 50%
orders are compan whether matrix for of change
approved by y policy authority change order
next higher matrix order whichever is
authority defined for 2. lower.
(DOA) or change Justification
from highest order. remark with
authority, if 2. Whether approval
changes are reason for
above changes is
defined documented
257
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
limits. and
approved
2. Reason with impact
for change on budget.
order with
proper
justification
must be
documented
which also
show impact
on budget
and should
also be
approved.
Unauthorized All Pos are As per 1. Check that Unauthorise 1. ACL Analyse
Pos/Contracts approved as compan the PO is d approval 2. Authority transaction
per the y policy approved as rights Matrix carried in
approved per Authority 3. 30 Pos purchase
Authority Matrix. record to
Matrix. Also 2. Check the identify the
the same ACL and following:
has been confirm that 1.
entered into the same is Unauthorise
ERP updated as d users
software in per Authority performing
Access Matrix. transactions
Control List 2.
(ACL). Conflicting
transaction
rights
granted to
same
person.
All As per 1. Check the Supporting 30 POs NA
supporting compan PO review documents
documents y policy and approval (including
(Indents/ process. indents)
vendor quote Check that
analysis the PO is
sheet/vendor supported
quotes, etc.) with a duly
258
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
are reviewed approved
at the time of indent.
PO approval
by
authorised
personnel
(as per the
approved
Authority
Matrix).
Unfavorable 1. General As per 1. Check General and 30 PO / NA
terms and terms and compan whether the Standard Contracts
conditions of conditions, y policy general and PO Terms
the purchase approved by standard and
order. legal team terms and Conditions;
and part of conditions Approval
Agreement/ are approved
Purchase by Legal and
order/ Work part of
order are agreement/p
pre-printed urchase
on reverse of order/work
PO. order.
2. Standard
terms and
condition,
approved by
legal team
and part of
Agreement/
Purchase
order/ Work
order.
In case of As per 1. Check Approval of 30 PO/ NA
unusual or compan whether the terms for Contracts
non-regular y policy terms and customised (Unusual and
contracts, Conditions of contracts non-regular)
the unusual or
personnel non-regular
authorised contracts are
as per approved by
259
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Authority authorised
Matrix to personnel in
approve the legal
contract are department.
required to
obtain the
approval of
person
authorised to
do so in
Legal
department.
Contracts are 1. All PO/ As per 1. Check the Existence 1. Check NA
not stored/ contract compan existence of and storage process of
kept in a copies y policy contracts of contracts maintaining
central/ safe (active/expir with documents by
repository to ed) are designated buyer/ legal
safeguard maintained authority only department.
company's with and no other 2. Check 15
interests and to department. person have PO on sample
prevent the use access for basis.
of the contract 2. Contracts same.
which might be on stamp
detrimental to paper are 2. Stamp
company's being stored paper stored
interests. centrally with centrally with
designated designated
authorities. authority
only.
Contractor, At the time of As per 1. Compare Accuracy of 30 POs NA
order details PO approval, compan the approved data
are not PO is printed y policy PO with the updation
accurately and the supporting
input in the details of the documents to
system. order, ensure
contractor accuracy of
and terms of data input.
the order are
checked for
accuracy by
the
personnel
260
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
authorised to
approve the
PO as per
the
Authorities
Matrix.
PO issued after Receipts for As per 1. Check by Existence of GRN/SRN Analyse
the goods have the goods compan raising a PO for and PO GRN/SRN
been received cannot be y policy dummy goods/servic records record or
or goods / affected in receipt e received Gate entry
services may the ERP where PO record
have been system does not having
procured unless the exist. transactions
without raising POs exist in 2. Compare of goods and
a PO the system. the service to
i.e. GRN/SRN identify:
GRN/SRN record with
cannot be the PO to - GRN/ SRN
prepared in ensure that or gate entry
the absence PO exists for without PO
of PO all the goods reference.
Reference in receipt and - PO created
the ERP the POs are after gate
system. dated prior to entry or
GRN/SRN. invoice date.
Calculate
value of
such
purchases
during audit
period to
show
impact.Also
to check
GRN
prepared but
risk of
inventory not
being
received.
Vendor As per 1. Compare Existence of Vendor-wise Analyse
261
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
invoices compan the invoices PO for Invoice listing ERP data of
cannot be y policy recorded in invoices various
processed in vendors' booked expense GL
ERP system accounts with Goods
in absence of with the PO receipt /
a PO in listing to Service
system. ensure that clearing
PO is account to
available for check
invoices expenses
booked. rooted
through 3-
way control
system i.e.
PO,
GRN/SRN
and invoice
instead of
direct
booking.
Orders not 1. Purchase As per 1. Check the Planning for GRN records Analyse
clubbed to Report is compan receipt of possible and PO purchase on
save logistics generated on y policy material vis- saving in records same or
cost monthly à-vis logistic cost closed date
basis and is locations - from same
reviewed by date wise location/city
designated and quantity- and from
authority. wise. same or
2. Check the different
2. monthly suppliers
Procurement purchases to calculate
requirements report to total logistic
are check that it saving
evaluated for is reviewed possible
scheduling by during audit
deliveries so designated period if
as to reduce authority. transported
logistics / through
freight and same
related vehicle.
costs.
Business share All POs are As per 1. Check that Unauthorise 1. ACL Analyse PO
262
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
allocation reviewed and compan the PO is d approval 2. Authority records with
among approved as y policy approved as rights Matrix GRN/SRN
different per the per Authority 3. 30 POs records to
vendors result approved Matrix. identify
in higher Authority 2. Check the vendor wise.
procurement Matrix. Also, ACL and - Cases of
prices. the same confirm that quality
has been the same is rejection
entered into updated as - Case of
ERP per Authority late delivery
software in Matrix. against PO
Access terms,
Control List - Cases of
(ACL). less quantity
delivery
against PO
quantity.
and
ascertains:-
1. Vendor
with low
performance
evaluation
have high
share of
business
2. Action
taken
against
regular
default
vendors.
1. Purchases As per 1. Check the Monthly MIS MIS for 3 Analyse
MIS is compan monthly review months ERP
reviewed on y policy purchases procurement
a monthly MIS review as per
basis by as evidence approved
cross for HODs allocation of
functional review business
team of among
Heads of 2. See the vendors or
Purchases, minutes of not.
263
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Finance and discussion
Production and check Analyse
and reasons whether the latest
/ costs for or action points quality,
due to have been delivery
allocation of implemented. reports to
procurement recommend
among 3.Check change in
different approval of share of
vendors are allocation of business
analysed. business among
among vendor. Also
2. different analyse
Exceptions, vendors and charges for
if any are check same same
taken into allocation services by
account at provided in different
the time of system for vendors.
placement of procurement
subsequent purpose. Calculate
orders. losses due
to high
allocation of
business to
high-rate
vendor even
provides low
quality
goods/servic
e or late
delivery.
Inadequate Adequate As per 1. Check that Review SOD ACL Analyse
segregation of segregation compan the user conflicts ERP data to
duties -- of duties y policy department verify ID of
Vendor (SOD) exists does not user (Indent)
identified by for all have access department
the user and purchases to raise PO and
goods/services that are by creating a purchase
ordered routed dummy PO department
directly by the through the with id of a must be
user from the buying purchase different.
vendor department department.
(including which is 2. Check the
264
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
determination different from ACL for
of purchase the user existence of
price and other department. SOD.
terms and The same is
conditions) ensured in
ERP system
through
updation of
Access
Control List
(ACL).
Service and Majority of As per 1. Check the Timely Contracts Analyse
material service compan validity of the renewal of records contract
procurement contracts are y policy contracts. Contracts tracker with
contract not generated for 2. Check the dates of
approved after a calendar time gap original
expiry and year thereby between date renewal and
procurement facilitating of expiry of actually
done against timely contract and renewed.
Invalid/expired renewal. date of
contracts. Details of actual
each of renewal to
these time- identify value
bound of service
contracts are procurement
maintained in against
a Tracker. As invalid
and when contracts.
contracts are 3. Analyse
shown due losses due to
for renewal procurement
in tracker, at old rates if
they are subsequent
reviewed to reduction in
assess price.
whether
fresh terms
and
conditions/co
ntracts need
to be drawn
up.
265
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Continued Negotiations As per 1. compare Price PO records NA
procurement at are compan the approved fluctuations
higher price as conducted y policy PO with the and periodic
reduction in with subsequent review
market prices approved reductions in
and not vendors on the prices.
renegotiated an annual 2. Check the
with suppliers. and routine market rates
basis so as for the bulk
to reduce items /
cost of critical items
purchase. and their
Also, the movements
Quotes are during the
compared for period of
negotiations audit.
during the
appraisal
time of the
vendors.
This is done
by the
personnel
approved as
the Authority
Matrix.
MIS is As per 1. Check the Monthly MIS MIS for 3 NA
reviewed by compan MIS for and review months
cross y policy HODs review
functional 2. See the Minutes and
team of minutes of timely action
HODs for discussion
critical items and check
and costs. whether the
Actionable, if action points
any, are have been
flagged off actioned
for upon.
implementati
on
Duplicate MIS is As per 1. Check the Monthly MIS MIS for 3 NA
Orders reviewed by compan MIS for review months
266
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
cross y policy HODs Status of
functional review. previous
team of 2. See the issue
HODs for minutes of flagged.
critical items discussion
and costs. and check
Actionable, if whether the
any, are action points
flagged off have been
for actioned
implementati upon.
on
Exception As per 1. Check the Quantities, Invoice / PO Analyse gate
report is compan linking of the PO Records and entry, GRN,
generated at y policy attributes numbers, link with PR PO Records,
the time of and the PR Records PR Records
processing of exception reference, for any
invoices for report supplier common
POs / generated for name information
Invoices with any duplicate which show
certain same order. duplicate PO
attributes 2. Sort the raised for
such as Invoice batch same items.
supplier, / PO Records
quantity, PR on the
reference attributes
and is and check
reviewed by for the
designated common
authority. information.
All POs are As per 1. Check that Unauthorise 1. ACL NA
reviewed for compan the PO is d approval 2. Authority
accuracy and y policy approved as rights Matrix
correctness per Authority 3. 30 POs
and Matrix.
approved as 2. Check the
per the ACL and
approved confirm that
Authority the same is
Matrix. Also, updated as
the same per Authority
has been Matrix.
267
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
entered into
ERP
software in
Access
Control List
(ACL).
All POs are not PO are As per 1. Review of Serial no. PO records Analyse
recorded sequentially compan PO records if control of ERP PO
pre- y policy there are any purchase records to
numbered. missing order verify PO
The serial sequence
sequence of numbers of number.
PO the Pos.
processed is
accounted
for.
In case of As per 1. Check that Approval of Invoice Analyse
emergency compan there exists emergency records GRN record
purchases, y policy specific purchase or Gate
the approval for entry record
purchases purchases having
made without without transactions
indent / PO indent or PO of
need to be as per the Service/mat
specifically Authorities erial to
approved as Matrix. identify:
per the
Authorities - GRN/SRN
Matrix. or gate entry
without PO
reference.
- PO created
after gate
entry or
invoice date.
Calculate
value of
such
purchases
during audit
period to
268
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
show
impact.
Validity of the 1. The list of As per 1. Check the Open PO Open PO Analyse list
open POs / open POs / compan validity of dates listing of Purchase
Contracts contracts is y policy open PO / Orders for
reviewed on Contracts. following:
a monthly 2. Check the
basis by documented - Instances
purchase reason for of open
team. The delayed Pos. purchase
redundant / orders not
expired PO closed for
are purged long times.
from the list.
- may be
2. Timelines used for
of the unauthorised
procurement transactions.
activities are
monitored on Calculate
monthly financial loss
basis. to the
Reason of company
analysis is due to delay
performed in delivery, If
and possible.
documented
for all
delayed
beyond the
defined
timelines.
Audit logs for 1. Audit logs As per 1. Check Audit Logs 1. Audit logs Analyse
changes in PO are compan logs are of changes 2. monthly Audit log of
may not be generated for y policy available for in PO review on modification
available and all POs / POs/ Wos logs- 3 carried in
reviewed leads WOs raised / and Month. purchase
to unauthorized modified in modification. record to
changes. the system. 2. identify the
2. Process is Mechanism following:
in place to in place to 1.
monitor audit review audit Unauthorise
269
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
logs to logs. d users
identify any performing
inappropriate transactions
/ suspicious 2.
activity. Conflicting
transaction
rights
granted to
same
person.
quality Stock outs due Open As per 1. Check the 1. Open PO 1. 10 weeks Analyse
assessm to delays in PO/contract compan instances of dates open PO list ERP Open
ent delivery of list is y policy stock outs 2. stock outs 2. Stock out PO records
stocks ordered prepared on and review event list with daily
through open a weekly the stock details
Pos. basis by justification / to identify
designated root cause instances
department. for the same where PO is
This is used 2. Check undelivered,
as basis for whether the and material
tracking purchase is out of
timely department stock.
deliveries by track
the user deliveries
department. against the
Open PO list
Goods/ service Statements As per 1. Check that Unrecorded Top 30 NA
received may received compan the vendor services/goo vendor
not be from vendors y policy accounts ds service/materi
recorded. are reconciliation al Vendors
reconciled is done on a Reconciliation
with the periodic statements
vendor basis. or cover 40%
accounts in 2. Check the purchase
the accounts differences, value.
payable sub if any are
ledger reconciled
quarterly and and are not
differences carried
are forward.
investigated.
This is
270
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
reviewed by
Accounts
teams.
The stock at As per 1. Check the Periodicity Physical NA
the business compan working and verification
locations of y policy papers of Variances statements
the company physical noted in and
is physically verification physical reconciliation
verified at and see that verification
least once a the
year by differences,
Accounts if any, were
department / reconciled
independent and
auditors. accounted
Variances, if for.
any, are
reconciled
with the
books of
accounts to
ensure
accuracy of
the books of
accounts.
Goods and 1. The As per 1. Check GRN and PO records NA
services receiving compan whether service and GRN
accepted personnel y policy GRN / SRN against records
without proper are required can be Authorised
inspection and to match the raised for PO only 30 GRNs for
verification goods items without physical
received with a PO or that verification
the open do not meet
purchase the PO
orders. In specification
case the s
goods 2. Verify user
received do department
not match head
with the approval on
quantities or service
specification invoices
271
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
s or exceed before
the purchase booking the
order same in
quantity, the books.
same are 2. Whether
rejected. store person
2. The user sign off on
department invoice after
verifies physical
service count of
invoices of goods.
vendor with
internal
service
records and
obtained
approval of
department
head. Only
after service
booked in
system.
3. Invoice
quantity and
physical
quantity are
matched for
which store
person count
inventory
before GRN
and sign off
on invoice.
All receipts As per 1. Check that Unauthorise 1. ACL Analyse
are reviewed compan the GRN is d approval 2. Authority records of
and y policy approved as rights Matrix GRN/SRN
approved by per Authority 3. 30 GRNs with records
the Matrix. of PO
personnel as 2. Check the quantity and
per the ACL and rates to
approved confirm that identify
Authority the same is Instances of
Matrix. Also, updated as deviation.
272
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
the same per Authority
has been Matrix.
enteredinto
ERP
software in
Access
Control List
(ACL).
Quantity/servic 1. The As per 1. Check Order Vs PO Records Analyse list
e received in receiving compan possibility of Receipt qty VS GRN of GRN/SRN
excess of personnel is y policy GRN/ SRN Records and for following:
ordered required to more than Material not amended PO 1 Instance of
quantity match the PO quantity received as for change in delays in
goods/ by system per order qty. receipt of
service. So, walkthrough. specification materials/ser
received with 2. Check s vice.
the open approved 2. Instances
purchase tolerance of GRN /
orders. In limit against SRN without
case, the PO quantity PO or before
goods/ from PO
service management 3. Instances
received do side. Verify of GRN
not match cases where without gate
with the goods/servic entry
quantities or e allowed 4. Instances
specification more than of GRN
s or exceed tolerated before gate
the purchase limit. entry
order 5. Instances
quantity, the of GRN/SRN
same are more than
rejected. PO quantity
6. Instances
of GRN /
2. ERP also SRN value
has control more than
over quantity PO / SO
booking, value
system does
not allowed
booking of
quantity
273
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
more than
PO quantity.
All receipts As per 1. Check that Unauthorise 1. ACL Analyse
are reviewed compan the GRN is d approval 2. Authority ERP receipt
and y policy approved as rights Matrix record
approved by per Authority 3. 30 GRNs during the
the Matrix. review
personnel as 2. Check the period to
per the ACL and identify the
approved confirm that following:
Authority the same is 1.
Matrix. Also, updated as Unauthorise
the same per Authority d users
has been Matrix. performing
entered into transactions
ERP 2.
software in Conflicting
Access transaction
Control List rights
(ACL). granted to
same
person.
Quantity The As per 1. Check Material not PO records NA
received has receiving compan whether received as VS GRN
not been personnel is y policy GRN/SRN per records and
ordered. required to can be specification amended PO
match the raised for s for reason of
goods items without Qty and
received with a PO or that specification.
the open do not meet
purchase the PO
orders. In specification
case, the s
goods
received do
not match
with the
quantities or
specification
s or exceed
the purchase
order
274
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
quantity, the
same are
rejected.
All receipts As per 1. Check that Unauthorise 1. ACL Analyse
are reviewed compan the d approval 2. Authority ERP receipt
and y policy GRN/SRN is rights Matrix record to
approved by approved as 3. 30 GRNs identify the
the per Authority following:
personnel as Matrix 1.
per the 2. Check the Unauthorise
approved ACL and d users
Authority confirm that performing
Matrix. Also, the same is transactions
the same updated as 2.
has been per Authority Conflicting
entered into Matrix. transaction
ERP rights
software in granted to
Access same
Control List person.
(ACL).
Unauthorized All receipts As per 1. Check that Unauthorise 1. ACL Analyse
person can are reviewed compan the GRN is d approval 2. Authority ERP receipt
create and y policy approved as rights Matrix record
receiving approved by per Authority 3. 30 GRNs during the
documents the Matrix review
personnel as 2. Check the period to
per the ACL and identify the
approved confirm that following:
Authority the same is 1.
Matrix. Also, updated as Unauthoirse
the same per Authority d users
has been Matrix performing
entered into transactions
ERP 2.
software in Conflicting
Access transaction
Control List rights
(ACL). granted to
same
person.
Terms and The As per 1. Check that Appropriate 30 GRNs NA
275
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
conditions of receiving compan the GRNs stamp on
acceptance of stamp that is y policy are being the GRNs
goods at the used to marked with
factory gate acknowledge the stamp
(before the receipt of 'goods are
goods have goods at the being
been approved gate on received
by quality/ GRN, bears subject to
indenter may the count and
be detrimental inscription quality
to the interests 'goods are procedures'.
of company. being
received
subject to
count and
quality
procedures'.
Accordingly,
liability would
not accrue to
the Company
until these
procedures
are complied
with.
Inappropriate 1. Before the As per 1. Check Post QC - 1. 30 GRNs Analyse
quality of GRN is sent compan whether the rejections 2. Exception Quality and
service / to Accounts y policy GRNs have report raised Return to
material for booking been marked for post QC - Vendor for
accepted the liability or as approved rejections following:
the goods by Quality - Delays in
are sent to head. sending
store, quality 2. Review back
department exception rejected
is required to report for the material to
certify the goods vendor.
quality of rejected due - Instances
material to quality of GRN and
received in constraints at issue of
accordance the shop material
with the set floor. Check despite
guidelines. all these quality
goods are rejection.
276
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
2. The user returned to - Quality
department vendors as note are
verify service per created by
invoices of agreement. unauthorized
vendor with 3. If rejected person/
internal goods are Absence of
service not returned, SOD.
records and it should be
obtained with recorded as
approval of scrap.
department 4. Monthly
head. Only quality
after service exception list
booked in reviewed by
system. authorised
3. The store person.
clerk will not 5. Verify user
accept the department
goods unless head
the "QC approval on
checked" is service
stamped on invoices
GRN. before
booking the
4. Also, same in
Accounts will books.
not book the
liability and
process the
payment
unless the
QC checked
and stamped
on GRN is
received by
them.
5. Quality
check is not
required for
any item, the
same should
be a part of
QC
277
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
exceptions
list which is
reviewed on
a monthly
basis.
Access to As per 1. Review Access Access Analyse
certify the compan Access rights for Control List GRN and
quality of y policy Control List certifying Quality
material is for access to quality record to
restricted to personnel identify the
persons per other than following:
approved those 1.
Authority authorised Unauthorise
Matrix in for certifying d users
ERP. quality of the performing
goods. transactions
2.
Conflicting
transaction
rights
granted to
same
person.
Policy may not 1. Policy in As per 1. Check Checklist, Select 30 Analyse
be in place for place for compan policy of sampling GRN/SRN ERP Quality
sampling, quality y policy sampling and and quality Records and
methodology, testing of methodology methodolog check
checklist leads required of quality y quantity
to credit to material testing is transferred
vendor for poor including documented. to
quality service sampling, 2. Check unrestricted
/ material. methodology quality category or
and inspection not (for
documentati policy is issue
on of quality defined for purpose).
testing. all material. Check
3. Inspection quantity in
2. Quality carried out restricted
inspection as per policy category and
standards or ISO reason for
are defined certification same.
for all process.
278
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
materials. 4. Check Analyse
services ERP quality
3. Ensure all should be record of
steps are approved actual
carried out basis of sample with
as per complete define
company checklist and sampling
policy or ISO reviewer method.
certification approval.
process for Verify
quality checklist for
assessment different type
and of services.
documentati
on.
4. All service
are approved
basis of
complete
checklist.
Rejected 1. Any As per 1. Physically Storing of 4 Month Mis Analyse
material may rejection is compan verify rejected and of rejected ERP quality,
be placed segregated y policy rejected return to items GRN records
separately and stored items and vendor and
(Quarantine) separately. storage 20 Debit Vendor’s
and return to 2. All control to notes for ledger to
vendor on rejections avoid issue rejected establish
timely basis are supplied for operation. material following:
leads to risk back to 2. Check - Debit note
issue to floor vendor on rejected item raised to
and ownership. timely basis. are returned vendor or
3. and replaced not for
Department by vendors quality
ensure timely on timely rejection.
return and basis or not. - GRN
recording of 3. Verify reversal in
return. return case of
4. Material is recorded on rejected
consumed timely basis material
only after in books or - GRN
Quality not. records for
checks. 4. Ensure replacement
279
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
5. Perform material by vendor
assessment consumed against
in case of after quality same PO.
high check only. - Material
rejection in 5. Monthly are issued
the material assessment after quality
supplied by of vendor approval
the vendor wise only.
6. Debit rejection to
notes should take
be raised appropriate
immediately action
for all against
rejections regular
and return to default
vendors. vendors.
7. Credit to 6. Debit note
service raised for
vendors rejected
provided only material and
for approved by
satisfactory appropriate
services authority.
only. 7. Verify
rejected
material with
advance paid
vendors.
8. Check
whether
services are
not
performed as
per
agreement,
credit not
passed on to
vendors for
same.
Delay in The report As per Check the Demurrage Demurrage NA
clearing and on compan Demurrage charges due charges
forwarding of demurrage y policy charges paid to delay in ledger
imported charges and clearing
280
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
goods. incurred due justification 30 imported
to delay in for the same. invoices
carrying and
forwarding of
imported
items is
reviewed by
the
designated
person on a
monthly
basis. Also,
these
charges are
separately
disclosed in
the MIS for
Sr.
Management
review.
Unauthorised All As per 1. Check the Transporter 50 transporter NA
or Inaccurate transporter compan supporting charges invoices or as
release of claims are y policy for the claims authorizatio per quantum
payments for authorised viz. n of business of
transporter by the Sr. agreements, company.
dues. Manager - if any. Rate
Stores prior contract
to payment should also
by Accounts. be reviewed
This is based for any
on the changes in
agreements petrol/ diesel
with the prices.
vendors /
transporters. 2. Check
reconciliation
of purchase
register with
transporter
invoice to
avoid
duplicate
booking.
281
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
3. Check
lorry
documents
for freight
payment.
GST Input Monthly As per 1. Check the Periodicity 3 months Analysis
Credit not reconciliation compan GST Input of reconciliation GSTR-2A
availed / Short of GST Input y policy Credit reconciliatio report with
/ Excess Credit reconciliation n and purchase
availed account and for long reasons for register to
register is outstanding outstanding indemnify
done both items and items cases where
by Stores justifications GST credit
and and action available as
Accounts. taken for the per portal
same. but invoice
are not
booked or
vice versa.
Invoice Invoices may Before any As per 1. Check that Three-way 50 invoices or Analyse and
Processi be booked invoice is compan the invoice is control PO, as per compare PO
ng incorrectly approved for y policy supported by GRN and quantum of Records with
booking, AM duly Invoice transaction GRN records
- Accounts authorised to verify
performs a PO and accuracy in
three-way GRN. booking
match of the value.
PO, GRN
and Invoice Verify
transporter
charges GL
or clearing &
forwarding
or suspense
GL where
excess
invoiced
value (More
than PO
value) may
be provided
282
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
to verify
approval
process.
Analyse
ERP data of
various
expense GL
with Goods
receipt /
Service
clearing
account to
check
expenses
rooted
through
three-way
control
system i.e.
PO,
GRN/SRN
and invoice
instead of
direct
booking.
In case of As per 1. Check that Emergency 50 invoices or Compare
emergency compan the invoice is purchase as per Invoice date
purchases, y policy supported by approval quantum of and PO date
the invoice is GRN and transaction to identify
verified with post- emergency
the GRN purchase purchase.
/SRN and approval of (Invoice date
the the should be
subsequent personnel after PO
approval authorised date).
obtained for as per
the purchase Authority Verify ERP
from Matrix. records
personnel where
authorised invoices
as per booked
Authority without
283
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Matrix. three-way
control i.e.
PO, GRN
and invoice
to check
approval
procedure.
Duplicate At the time of As per Check that Defacing of 50 invoices or Analyse
booking of the booking of compan the invoices invoice to as per Vendor
invoice. invoice, y policy are defaced avoid quantum of Invoices for
invoice is at the time of duplicate transaction following:
defaced with booking. booking. 1. Incorrect/
the Stamp duplicate
"Processed" Invoices
by executive. processed
2. Check for
same
invoice
amount in
the same
period for
same
vendor.
Once a As per 1. Check that Supporting 50 invoices or Analyse POs
invoice is compan the invoice is documents as per value from
booked, the y policy supported by quantum of ERP records
supporting duly transaction and compare
documents authorised it with GRN
viz. GRN, PO and value for
PO, Indent GRN. accuracy in
are attached between.
with it.
Invoices
without
supporting,
cannot be
processed.
Unapproved The invoices As per Check the Invoice 50 invoices or Analyse
invoices are before being compan approval of approval as per GRN and
processed. processed y policy AM - from quantum of invoice
are reviewed Accounts on designated transaction record to
by the invoice. authority identify the
284
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
designated following:
authority. 1.
Unauthorise
Access rights As per Check the Transaction ACL d users
to process compan Access performed performing
the invoices y policy Control List as per transactions
are restricted for the access 2.
to the access rights rights. Conflicting
personnel given to the transaction
authorised authorised rights
as per the personnel. granted to
Authorities same
Matrix and person.
are entered
in Access
Control List
(ACL) in
ERP system
Delay in Statements As per 1. Check the Timely Reconciliation Analyse
accounting of received compan periodicity of booking of for 30 ERP data to
invoices from vendors y policy vendor invoices vendors compare
are reconciliation invoice date,
reconciled for GRN date,
with the appropriaten Quality date,
vendor ess thereof. invoice
accounts in 2. Sample booking date
the accounts check the to verify
payable pending timely
subledger items in the processing
quarterly and reconciliation of invoice.
differences s for invoices
are pending
investigated. booking and
This is confirm the
reviewed by reasons for
designated same.
authority.
The list of As per 1. Check Aging of records of Analyse
Goods compan aging of the GRN and GRN with QC ERP data to
Received y policy Temp GRN material compare
Not Invoiced raised for the being held Liability invoice date,
(GRNI)/Servi material with by QC provides for GRN date,
ce Receipt Quality non-booked Quality date,
285
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Note and the Control GRNs invoice
items with department booking date
Quality and the - to verify
Control are GRNIs. timely
reviewed on 2. Ensure processing
a monthly that the of activities
basis to same are - to check
ensure that accounted in vendor
there are no the books as liability
delays in liability in the booked on
booking the suspense timely basis
liability. accounts. so that
reconciliatio
n gaps
should be
zero or
minimum.
Booking of 1. GST Input As per 1. Check Credit 50 invoice NA
related credit are compan cenvatable booking and and as
expenditure obtained for y policy credit deduction decided with
and cenvat all eligible provided management
along with credits, and along with
invoice may it is duly invoice
not be booked. verified at booking
the time of 2. All related
recording of expenditure
invoices. like toll tax
and freight
2. All the booked along
related with
expenditure, goods/servic
such as toll es
tax, cess, 3. TDS and
freight, etc., other
are recorded deduction as
as cost of per law are
material or done and
service. recorded
3.
Appropriate
deduction
and
286
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
recording of
TDS are
done
wherever
applicable.
Delay in raising Statements As per 1. Check the Timely issue Reconciliation Analyse time
debit/ credit received compan vendor of Debit / for 30 taken to
notes from vendors y policy reconciliation Credit Notes vendors issuing debit
are for the / credit notes
reconciled to periodicity of from the
the vendor reconciliation date of
accounts in . booking of
the accounts 2. Sample invoices or
payable check the date of
subledger pending receipt/retur
quarterly and items in the n of material
differences reconciliation
are s for debit /
investigated. credit notes
This is yet to be
reviewed by raised.
AM - Confirm
Accounts reasons for
the same.
Unauthorized The debit / As per 1. Check that 1. Approvals 30 debit / Analyse
debit/ credit credit notes compan the access for credit notes number of
notes may be are approved y policy control list debit/credit debit / credit
raised by the defined in noted notes issued
personnel ERP system 2. Reasons vis-à-vis
approved in is as per the for issuance number of
the Authority approved purchases
Matrix. The Authority made.
same Matrix. Analyse
entered in 2. Check that value of
the Access adequate debit / credit
Control List back up / notes issued
existing in supporting vis-à-vis
the ERP documents value of
system exist for purchases
issuing debit made.
/ credit
notes. To check
287
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
efficiency of
purchase
Accounti Unauthorised The payment As per 1. Check that 1. Access 1. Access Analyse
ng and payments voucher with compan the Access Control List Control List Vendor
payable required y policy Control list in 2. Approved 2. Authority payment
supporting's ERP is as supporting Matrix record
is reviewed per the documents. 3. 30 during the
and approved Payment review
authorised Authority vouchers period to
by the Matrix. any identify the
personnel changes to following:
authorised the 1.
as per authorised Unauthorise
approved signatory to d users
Authority the bank performing
Matrix. The transactions transactions.
authority should be 2.
matrix is authorised Conflicting
entered in by Board and transaction
the Access intimated to rights
Control List the Bank granted to
(ACL) in immediately. same
ERP system. 2. Check that person.
requisite
The supporting is
supporting attached with
documentati the payment
on is voucher.
cancelled or 3. Check that
defaced, the
once it is supporting is
reviewed and defaced for
payment the approved
voucher is vouchers.
approved. 4. Sign of
In case vendor's
cheque representativ
payment, e.
when cheque
is handed
over to
vendor
representativ
288
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
e and
acknowledge
ment
obtained.
At the time of As per 1. Check that 1. Advance 30 vendor Analyse
processing a compan there are no amounts in accounts and vendor
vendor y policy amounts vendor per business payment for
invoice for pending accounts need following
payment, adjustment pending for
designated for vendors adjustments, 1. Same
authority is where all the 2. Multiple vendor with
required to invoices payments same date-
identify and have been on same or and more
set off all the paid. See nearby date than one
advances justification payment
pending for 2. Check
adjustment exceptions. advance is
for such 2. Scrutinise adjusted as
vendor. the vendor per contract
accounts / terms.
party 3. Check
accounts to advance
check the paid but
cases of without bank
segregation guarantee
of amounts against the
to avoid policy of the
authority company.
matrix.
3. Vendor
advance
should be
adjusted as
er contract
terms.
4. Check
cases of
advance paid
contractor
but work
performed
with slow
pace, leads
289
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
to financial
loss to the
company.
The listing of As per 1. Check that Review of 30 vendor Analyse
vendor compan the evidence payment payment lists vendor
payments is y policy of review on payment
reviewed the vendor record
prior to payment list during the
release of review
payment by period to
the identify the
personnel following:
authorised 1.
as per Unauthorize
approved d users
Authorities performing
Matrix transactions
2.
The As per 1. Check the Approval of Authority Conflicting
personnel compan approval for payment to Matrix transaction
making the y policy authority to vendors rights
payment make the granted to
(either payment. same
through 2. Check person.
cheque / DD whether the
/ wire same has
transfer) are been
authorised to communicate
do so as per d to the
the approved bank.
Authority
Matrix.
Management As per 1. Check the Review of Returned Analyse total
periodically compan evidence of returned cheques cheque
reviews the y policy the cheque issue during
returned paid management the period
cheques for review. and returned
unauthorised to verify
signatures, following:
alterations
and / or 1. Control at
alterations the time of
issue of
290
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
cheques
2. Period for
which
cheques
returned due
to
alteration/mi
smatch, etc.
Payments are 1. The As per 1. Check that 1. Access 1. Access NA
made to payment compan the ACL in Control List Control List
incorrect voucher with y policy ERP is as 2. Approved 2. Authority
vendors required per the supporting Matrix
supporting is approved document. 3. 30
reviewed and Authority Payment
authorised Matrix. vouchers
by the 2. Check that
personnel requisite
authorised supporting
as per are attached
approved with the
Authorities payment
Matrix. The voucher.
authority 3. Check that
matrix is the
entered in supporting
the Access are defaced
Control List for the
(ACL) in approved
ERP system vouchers.
2. The
supporting
documentati
on is
cancelled or
defaced,
once it is
reviewed and
payment
voucher is
approved.
1. The listing As per 1. Check that Managemen 30 vendor 1. Data
291
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
of vendor compan the evidence t review payment lists analysis of
payments is y policy of review on before the
reviewed the vendor release of Open/Long
prior to payment list payment pending
release of advances
payment by which are
the not adjusted
personnel 2. Analyse
authorised data for
as per Instances of
approved delay in
Authorities payment
Matrix made to
MSME
2. Cheques / vendors over
DD are 45 days
restrict 3. Whether
endorsed by liability write
the preparer off approval
to ensure are obtained
that they are from
paid to management
specific as per
payee policy.
Management As per 1. Check the Managemen Returned Analyse total
periodically compan evidence of t review for cheques cheque
reviews the y policy the returned issue during
returned paid management cheque and the period
cheques for review. reissue and returned
unauthorised to verify
signatures, following:
alterations
and / or 1. Control at
alterations. the time of
issue of
cheque.
2. Period for
which
cheques
returned due
to
alteration/mi
smatch, etc.
292
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Credit terms 1. Payment As per 1. Check Credit terms check ledger Analyse
may not be are compan payment and and weekly of 10 major ERP vendor
utilized processed y policy credit terms review of vendor ageing of
effectively. for approved with vendors overdue different
invoices as 10 weekly month to
per agreed 2. Review review of verify
payment document of overdue payment
terms to vendor payment made after
optimize on ageing on utilizing
using credit weekly basis credit terms
period and to maintain
efficient working
utilization of capital
working balance.
capital.
2. Vendor
ageing is
prepared and
reviewed by
the Finance
head on
weekly basis
to ensure all
overdue
payments
are
processed.
MSME Vendor Payment to As per 1. Check Timely Check Ledger 1. Data
not paid on MSME compan ageing of payment to of 20 MSME analysis of
timely basis vendors is y policy MSME MSME vendors the
reviewed and vendors on vendors Open/Long
made within different pending
defined date/months advances
timelines as which are
per terms of not adjusted
agreement or 2. Analyse
timelines data for
defined Instances of
under Micro, delay in
Small and payment
Medium made to
Enterprises MSME
293
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
Development vendors over
Act, 2006 or 45 days
amendments
thereafter
(45 days),
whichever is
earlier.
GST credit Reconciliatio As per 1. Check GST 3 Month Analyse
reconciliation n of eligible compan monthly reconciliatio reconciliation vendor wise
and payable GST credits y policy reconciliation n credit
more than 180 on GST sheet of GST available at
days portals with credit as per portal and
GST Input books with credit
credit Portal and availed/book
available and deposited. ed by the
deposited company
are and reason
performed for non-
periodically. utilization/bo
oking and
vis a vis
cases.
If payment to As per 1. Verify GST credit 1. Vendor NA
vendors is compan vendors reversal in ageing
not made y policy ageing and case of non- 2. GST
within 180 identified payment returns for
days then cases where within 180 reversal
GST credit payments days. purpose
related to are
particular outstanding
amount by more than
needs to be 180 days.
reversed.
2. Check
GST return
and verify
credit related
to this
vendor is
reversed in
particular
month or not.
294
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
3. Tracker
should be
maintained
by the
company for
credit
reversal and
subsequent
utilization
after
payment.
Duplicate 1. The As per 1. Check that 1. Access 1. Access NA
payments payment compan the Access Control List Control List
voucher with y policy Control list in 2. Approved 2. Authority
required ERP is as supporting Matrix
supporting is per the document. 3. 30
reviewed and approved Payment
authorised Authority vouchers
by the Matrix.
personnel 2. Check that
authorised requisite
as per supporting
approved are attached
Authority with the
Matrix. The payment
authority voucher.
matrix is 3. Check that
entered in the
the Access supporting
Control List are defaced
(ACL) in for the
ERP system. approved
vouchers.
2. The
supporting
documentati
on is
cancelled or
defaced,
once it is
reviewed and
payment
295
Internal Audit Checklist
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
voucher is
approved.
Non-receipt of The listing of As per 1. Check the 1. Open PO 1. Open PO Analyse PO
material Open POs is compan due dates in with listing list (where
against reviewed on y policy the open PO correspondi 2. Unadjusted timeline of
advances a monthly / Contracts. ng advances advances supply/servic
basis to 2. Check the 2. GL e has been
check the reasons for justification expired) and
cases of delays in for delays compare
delayed supplies. with
supplies/cont 3. Verify advance GL
ractor advance GL to identify
wherein for long cases where
advances pending advance
have been unadjusted unadjusted
released to advance. and vendor
them. This is POs are also
reviewed by outstanding.
the
personnel
authorised
as per the
approved
Authority
Matrix.
Ageing of the As per 1. Check the 1. Vendors Analyse
party compan debit Approvals, Account and various
balances is y policy balances 2. Amount, the Advances figures
reviewed on appearing in 3. Receipt of Aging reported in
a monthly the supplier's material statement MIS vis a vis
basis and account and 4. Due date the details
account ageing appearing in
reconciliation thereof ERP system
is done on a 2. Check to identify
quarterly whether any instances of
basis unauthorized incorrect
advance has reporting.
been given
to the
supplier (this
needs to be
checked with
296
Purchase to Pay – Indirect Material and Services
Process Sub- Risk Control Control Test Attributes Sample size Data
process Description Owner Performed tested (* may vary analytics
upon performed
organization
size, policy,
decision)
the
justification
provided and
the Authority
Matrix)
3. Check
whether the
advances
have not
been
adjusted
correctly
while
accounting
for receipt of
goods.
Wrong Foreign Weekly As per 1. Compare Exchange Forex rates in NA
exchange rates foreign compan the rates rate applied 10 weeks
used for currency y policy applied for as per RBI
conversion of rates are invoice rate
foreign updated in processing
currency the ERP with the RBI
invoices. system by rate.
the
personnel
authorised
as per the
Authority
Matrix. The
rights to
update the
masters are
restricted as
per Authority
Matrix the
source of
foreign
exchange
rates should
also be
approved by
Management
.
297
Checklist 20
Purchase to Pay – Capital Items
Final Sub- Risk Control Control Test Attributes ` Data
process Descriptio Owner Performed tested analytics
n performed
Procureme General Procureme The As per 1. Check 1. Capital NA
nt of and entity nt policy organisatio company updated Approved item
Capital level and n has clear policy and Capital procureme
Items control Authority and comprehen procureme nt policy
matrix may comprehen sive capital nt policy approved
not be sive (up to procureme 2. by BOD
prepared date) nt policy Completen
or capital approved ess
approved procureme by BOD or
by Board of nt policy designated
Director approved authority.
(BOD). by Board of 2. Check it
Directors addresses
(BOD) or all
designated attributes
authority. related
Due capital
considerati items to
on given procureme
to: nt.
- Time
(speed vs
certainty of
completion
date)
- Cost
(price level
vs cost
certainty)
- Quality
(functionali
ty and
performanc
e)
1. The As per 1. Check Approved Approved NA
organisatio company capital item DOA/DOP DOA/DOP
n has clear policy procureme for capital from BOD
and nt purchase
comprehen DOA/DOP
sive (up to is available
date) and
Delegation approved
Purchase to Pay – Capital Items
299
Internal Audit Checklist
3. Periodic
Review of
Segregatio
n od Duties
and
Access
rights is
conducted.
SOP may 1. The As per 1. Check Approved Updated NA
not be organizatio company SOP SOP and SOP
defined to n has policy available completen
ensure clearly and ess
consistenc defined complete in
y and Standard all aspect
standardis Operating of roles,
ation of Procedures KPIs,
operations. and are in Timelines
place. and
2. Should frequency
define of
sequence activities,
of etc.
activities, 2. Check
Roles and when SOP
Responsibi updated
lities, Key last and
Performan enquire the
ce reason for
Indicators not
(KPIs), updating
Timelines the SOPs,
and in case,
Frequency not
of activities updated for
along with long time.
various
300
Purchase to Pay – Capital Items
3. Fraud
Risk
301
Internal Audit Checklist
302
Purchase to Pay – Capital Items
Based on
the Annual
303
Internal Audit Checklist
304
Purchase to Pay – Capital Items
305
Internal Audit Checklist
306
Purchase to Pay – Capital Items
3. Budget
are
approved
by
appropriate
authority to
release
indent.
The As per 1. Check 1. System NA
system, company the access Approvals walkthroug
does not policy control list for indent h and
allow to check 2. Access check
changes to that no one control list system
be made to other than allowed to
the HOD has make
approved modificatio changes in
indents. n access approved
They can for indent indent.
either be and access
cancelled to cancel
307
Internal Audit Checklist
308
Purchase to Pay – Capital Items
To
calculate
probable
losses due
to delay in
approval at
different
stages
from indent
to PO.
Indent 1. The As per 1. Check 1. 1. System Analyse
does not indent is company that the Approvals walkthroug Purchase
prescribe reviewed policy indents are for indent h for requisition
the correct and approved 2. Access approval transaction
technical approved in control list procedure to identify
specificatio by the accordanc and the
ns of authorized e with the specificatio following:
project/cap personnel Authority n. 1.
ital items (as per the Matrix. Incomplete
309
Internal Audit Checklist
310
Purchase to Pay – Capital Items
Project
activity are
rejected by
quality
department
if wrong
item is
utilized
against
specified
BOM item.
Indents / All As per 1. Check Supporting 30 PO or Analyse
PRs are supporting company the PO documents as per capital PO
not used documents policy review and (including business Records
when (Indents/ve approval indents) need with Indent
purchasing ndor quote process. Records to
capital analysis Check that verify each
items. sheet/vend the PO is order is
or quotes, supported supported
etc.) are with a duly by indent.
reviewed at approved
the time of indent.
PO
approval
by
authorised
personnel
(as per the
approved
Authority
Matrix).
Vendor Contractor Defined As per 1. Check 1. 30% of 1. Analyse
Selection chosen is process for company the Approvals new vender list
and Master not vendor policy approval of plan vendors or of current
Manageme competent evaluation for evaluations 10 year vis-à-
nt resulting in and technical 2. whichever vis
inferior approval evaluation Supporting is higher previous
quality in exists and and for year to
execution includes supporting evaluations identify
of projects. the documents addition of
following: thereof new
311
Internal Audit Checklist
312
Purchase to Pay – Capital Items
313
Internal Audit Checklist
4.
Contractor
is selected
on basis of
Pre -
qualificatio
n and merit
basis. After
selection of
vendor, list
is
approved
by
designated
authority
before
quotation.
1. Open As per 1. Check Tendering PO Analyse
tender company open as per Records ERP Open
system is policy tendering policy of tender,
followed used by the Limited
for high the company. tender data
value company and verify
314
Purchase to Pay – Capital Items
4. Check
NOC are
obtained
from
vendors
who did not
sent quote
to check
they obtain
quote
315
Internal Audit Checklist
316
Purchase to Pay – Capital Items
3. Check
for any
deviation
from
technical
qualificatio
n, verify
approval
obtained
from
designated
authority or
not.
Possibility Same As per 1. Check 1. Same for 5 major Analyse
of vendor timelines company bidding and timely tenders time
favoritism and policy document process for and 5 tracker of:
processes and all parties major RFQ
are process to 2. process or -
followed verify Deviation cover 50% Submissio
for all timeline approval tender n of
parties and and whichever technical
deviation process is higher. and
are are financial
approved common in qualificatio
by case of all n
designated tendering document
authority parties. and
except 2. In case approval
procureme of thereof
nt of low deviation, -
value / approval Submissio
select obtained n of
category from financial
317
Internal Audit Checklist
- to verify
all process
are time
bound for
all
vendors.
Report
exceptions
and check
deviation
for same.
Selection 1. As per 1. Check 1. Approval For 5 major NA
of Comparativ company whether of tenders
inappropria e quotation policy comparativ comparativ and 5
te analysis e sheet is e sheet major RFQ
contractor sheet prepared 2. process or
or high- drawn or not. Deviation cover 50%
cost before 2. Check approval tender
procureme purchases Justificatio 3. Signing whichever
nt of are n and by tender is higher.
capital authorized. approval committee.
goods. in case of
2. If lowest selection of
quotation other than
is not lowest
accepted, bidders.
appropriate 3. Check
justification whether
may be quotation
documente opened,
d and registered
approved and
by comparativ
designated e approved
authority. by
authorised
3. persons.
Quotations 4. Check
are opened quotation
and opened in
registered, presence
and a of
comparativ tendering
318
Purchase to Pay – Capital Items
319
Internal Audit Checklist
320
Purchase to Pay – Capital Items
321
Internal Audit Checklist
322
Purchase to Pay – Capital Items
Analyse
Vendor
Database
is
comprehen
sive, and
all vendor
details are
complete
and
accurate –
viz, Name,
PAN,
Address,
Contact
323
Internal Audit Checklist
324
Purchase to Pay – Capital Items
325
Internal Audit Checklist
2.
Employees
are
required as
per Code
of Conduct
to certify
compliance
with the
policy on
an annual
basis.
3. Also, the
vendors
are
required to
inform as
per the
standard
terms and
conditions
printed on
the PO, if
they have
any
relations
with
employee
in the
organisatio
n.
One-time 1. There is As per 1. Check 1. Field 1. List of Analyse
vendors an option company by creating validation one-time ERP
are not of ticking policy a dummy to use vendors records for
subjected "One time PO, if the code one 2. PO POs with
to same flag" which vendor time only. Records pre-define
326
Purchase to Pay – Capital Items
327
Internal Audit Checklist
328
Purchase to Pay – Capital Items
329
Internal Audit Checklist
3. BOD or
designated
authority is
approved
the project
and
provide go
ahead for
further
feasibility.
Project 1. Project As per 1. Check 1. 15 projects NA
feasibility team has company whether Feasibility Feasibility
study may done policy feasibility study or study and
not be project study with not compariso
done by feasibility complete 2. n sheet.
project study and details and Compariso 5 top
team leads evaluate approval n sheet for 5 medium
to wastage technical from inhouse 5 lower
of money if capability, project developme
330
Purchase to Pay – Capital Items
331
Internal Audit Checklist
332
Purchase to Pay – Capital Items
3. Access
to create
and
approve
PO by
different
users in
system.
POs do not All As per 1. Check Supporting Cover all NA
333
Internal Audit Checklist
334
Purchase to Pay – Capital Items
335
Internal Audit Checklist
336
Purchase to Pay – Capital Items
337
Internal Audit Checklist
338
Purchase to Pay – Capital Items
2.
Standard
terms and
condition,
approved
by legal
team and
part of
Agreement
/ Purchase
order/
Work
order.
In case of As per 1. Check Approval of 30 PO / NA
unusual or company whether if terms for Contracts
non-regular policy the terms customised (Unusual
contracts, and contracts and non-
the Conditions regular)
personnel of unusual
authorised or non-
as per regular
Authority contracts
Matrix to are
approve approved
the by
contract authorised
are personnel
required to in legal
obtain the department
approval of .
personnel
authorised
to do so in
Legal
department
.
339
Internal Audit Checklist
340
Purchase to Pay – Capital Items
Calculate
value of
such
purchases
during
audit
period to
show
impact.
Vendor As per 1. Existence Vendor- Verify ERP
invoices company Compare of PO for wise data of
cannot be policy the invoices Invoice asset GL
processed invoices booked listing with asset
in absence recorded in clearing
of a PO in vendors' account to
system. accounts check
with the assets
PO listing rooted
to ensure through 3 -
that PO is way control
available system,
for invoices i.e., PO,
booked. GRN and
invoice
instead of
341
Internal Audit Checklist
342
Purchase to Pay – Capital Items
to
ascertain:
1. Vendor
with low
performanc
e
evaluation
have high
share of
business
2. Action
taken
against
regular
default
vendors.
1. As per 1. Check Monthly MIS for 3 Analyse
Purchases company the MIS review months ERP
MIS is policy monthly procureme
reviewed purchases nt as per
monthly by MIS review approved
cross for allocation
functional evidence of of business
team of HODs among
Heads of review. vendors or
Purchases, not.
Finance 2. See the
and minutes of Analyse
Production discussion latest
and and check quality,
reasons / whether delivery
costs for or the action reports to
due to points have recommen
allocation been d change
of actioned share of
procureme upon. business
nt among among
different 3.Check vendor.
vendors approval of
are allocation Calculate
analysed. of business losses due
among to high
343
Internal Audit Checklist
344
Purchase to Pay – Capital Items
345
Internal Audit Checklist
346
Purchase to Pay – Capital Items
Calculate
value of
such
purchases
during
audit
period to
show
impact.
Validity of 1. The list As per 1. Check Open PO Open PO Analyse list
the open of open company the validity dates listing of
POs / POs / policy of open PO Purchase
Contracts contracts is / Orders for
reviewed Contracts. following:
347
Internal Audit Checklist
348
Purchase to Pay – Capital Items
349
Internal Audit Checklist
350
Purchase to Pay – Capital Items
351
Internal Audit Checklist
352
Purchase to Pay – Capital Items
353
Internal Audit Checklist
354
Purchase to Pay – Capital Items
355
Internal Audit Checklist
4. In that
case,
quality
check is
not
required
for any
item, the
same
should be
a part of
QC
exceptions
list which is
reviewed
monthly .
Access to As per 1. ReviewAccess Access Analyse
certify the company Access rights for Control List GRN and
quality of policy Control List
certifying Quality
material is for access
quality record
restricted to during the
as per personnel review
approved other than period to
Authority those identify the
Matrix in authorised following:
ERP. for 1.
certifying Unauthoris
quality of ed users
the goods. performing
transaction
s.
2.
Conflicting
transaction
rights
granted to
same
person.
Policy may 1. Policy in As per 1. Check Sampling Select 30 Analyse
not be in place for company policy of and quality GRN to ERP
place for quality policy sampling methodolo check Quality
sampling, testing of and gy quality Records
356
Purchase to Pay – Capital Items
357
Internal Audit Checklist
358
Purchase to Pay – Capital Items
359
Internal Audit Checklist
360
Purchase to Pay – Capital Items
361
Internal Audit Checklist
362
Purchase to Pay – Capital Items
363
Internal Audit Checklist
364
Purchase to Pay – Capital Items
365
Internal Audit Checklist
3.
Appropriat
e
deduction
and
recording
of TDS are
done
wherever
applicable.
Delay in Statements As per 1. Check Timely Reconciliat Analyse
raising received company the vendor issue of ion for 30 time taken
debit/ from policy reconciliati Debit / vendors for issuing
credit vendors on for the Credit debit /
notes. are periodicity Notes credit
reconciled of notes from
to the reconciliati the date of
vendor on. booking of
366
Purchase to Pay – Capital Items
367
Internal Audit Checklist
In case of
cheque
payment,
when
cheque is
handed
over to
vendor
representat
ive and
acknowled
gement is
obtained.
At the time As per 1. Check 1. Advance 30 vendor Analyse
of company that there amounts in accounts Vendor
368
Purchase to Pay – Capital Items
369
Internal Audit Checklist
370
Purchase to Pay – Capital Items
2. The
supporting
documenta
tion is
cancelled
or defaced
once it is
reviewed
and
payment
voucher is
approved.
1. The As per 1. Check Manageme 30 vendor 1. Data
listing of company that the nt review payment analysis of
vendor policy evidence of before lists the
payments review on release of Open/Long
is reviewed the vendor payment. pending
prior to payment advances
release of list. which are
payment not
by the adjusted.
371
Internal Audit Checklist
372
Purchase to Pay – Capital Items
2. Vendor
ageing is
prepared
and
reviewed
by the
Designated
Authority
on weekly
basis to
ensure all
overdue
payments
are
processed.
MSME Payment to As per 1. Check Timely Check 1. Data
Vendor not MSME company ageing of payment to Ledger of analysis of
paid on vendors is policy MSME MSME 20 MSME the
timely reviewed vendors on vendors vendors Open/Long
basis. and made different pending
within date/ advances
defined months. which are
timelines not
as per adjusted.
terms of 2. Analyse
agreement data for
or Instances
timelines of delay in
defined payment
under made to
Micro, MSME
Small and vendors
Medium over 45
373
Internal Audit Checklist
374
Purchase to Pay – Capital Items
3. Tracker
should be
maintained
by the
company
for credit
reversal
and
subsequen
t utilization
after
payment.
Duplicate 1. The As per 1. Check 1. Access 1. Access NA
payments payment company that the Control List Control List
voucher policy Access 2. 2. Authority
with Control list Supporting Matrix
required in ERP is 3. 30
supporting as per the Payment
is reviewed approved vouchers
and Authority
authorised Matrix.
by the 2. Check
person as that
per requisite
Authority supporting
Matrix. The is attached
Authority with the
Matrix is payment
entered in voucher.
the Access 3. Check
Control List that the
(ACL) in supporting
ERP is defaced
system. for the
approved
2. The vouchers.
supporting
documenta
tion is
cancelled
or defaced,
once it is
reviewed
and
375
Internal Audit Checklist
Analyse
advance
with Bank
Guarantee
(BG)
tracker for
BG
extension if
advance
pending for
adjustment
.
Ageing of As per 1. Check 1. Vendors Analyse
the party company the debit Approvals, Account various
balances is policy balances 2. Amount, and the figures
reviewed appearing 3. Receipt Advances reported in
monthly in the of material Aging MIS vis-a-
and supplier's 4. Due statement. vis the
account account date details
reconciliati and ageing appearing
on is done thereof. in ERP
376
Purchase to Pay – Capital Items
377
Internal Audit Checklist
378
Checklist 21
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
Fixed General Authority 1. The As per Check Approved Approved NA
Asset and entity matrix organisation compan capital DOA/DO DOA/DO
and level may not has clear and y policy item P for P from
Capex control be comprehensi procurem capital BOD
prepared ve (up to ent purchase
or date) DOA/DO
approved Delegation of P is
from Authority available
Board of (DOA)/ and
Director Delegation of approved
(BOD). Power (DOP) by BOD
and Authority for
Matrix. following
2. Authority activities.
matrix is
approved by 1.
Board of Requisitio
Directors, n for
defining the purchase
authorities for of
approving machiner
capital y, if any.
purchase 2.
transactions Opening
or performing of tender/
various quotation
transactions s for
during the purchase
purchase of
process. machiner
3. To y.
incorporate 3.
situations Purchase
where order for
emergency purchase
procurement of fixed
needed. assets.
4.
Comparat
ive chart
of
technical
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
and
financial
bidding.
5. Quality
check
and its
approval.
6. Issue
of Debit
note for
return/
rejection
of
machine
or for rate
difference
.
7.
Authorisa
tion of
date of
erection
and
commissi
oning of
plant and
machiner
y.
8. Ensure
the PPE
items
comply
with
safety,
regulatory
and
standards
.
9. Asset
requisitio
n report
indicating
the
payback
period.
Inadequat 1. Document As per 1. Check 1. 1. SOD Analyse
380
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
e defining compan document Documen 2. Access fixed asset
Segregati appropriate y policy ed SOD ted SOD, right List transactio
on of Segregation and Access 3. Half n carried
Duties of Duties Access right yearly out during
and (SODs) is in right list 2. review the review
access place. 2. Verify Periodic document period to
rights same review identify
which may SOD and the
result in Access following:
fraudulent 3. Periodic right also 1.
/ Review of entered in Unauthori
unauthoris Segregation system sed users
ed fixed of Duties and for performing
asset Access rights approval transactio
transactio is conducted. of ns
ns transactio 2.
ns. Transactio
3. Verify n rights
evidence granted to
of same
periodic person.
review of
SOD and
Access
rights in
ERP
system.
4. Check
only
authorize
d person
have
access to
perform
to fixed
assets.
5. Verify
the fixed
assets
transactio
ns on a
sample
basis and
trace
them
through
381
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
the
process
to identify
any
instances
where
one
person is
responsib
le for
multiple
steps
(intiating,
approving
and
recording
)
6. Check
physical
count of
assets on
a sample
basis and
reconcile
the
counts
with
Fixed
assets
register.
See for
discrepan
cies that
might
indicate
unauthori
zed
disposals
or
acquisitio
ns.
7.
Examine
any
document
s related
to
382
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
transfer
of fixed
assets
between
departme
nts or
location.
Verify
that
transfers
are
properly
authorize
d.
8. Review
the
system
audit trial
to identify
any
unusual
or
unauthori
zed
activity
relating to
fixed
assets,
that may
indicate
fraudulent
transactio
ns.
9. Check
the
system
access
log to
identify
any
unusual
or
unauthori
zed
access.
383
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
SOP may 1. The As per 1. Check Approved Updated NA
not be organization company SOP SOP and SOP
defined to has clearly policy available completene
ensure defined and ss
consistency Standard complete in
and Operating all aspect
standardisat Procedures for of roles,
ion of fixed asset and KPI,
operations. capex in place. Timelines
2. Organization and
has defined frequency
Activities, of
Roles and activities,
Responsibilitie etc.
s, Key 2. Check
Performance when fixed
Indicators asset SOP
(KPIs), updated
Timelines and last.
Frequency of
activities along
with various
documents of
capital
transactions to
be maintained .
Statutory Non- All statutory As per Ensure Complian Complian NA
complianc complianc requirements compan proof for ce under ce
e e of under various y policy complian various checklist
statutory Acis ces of act and
requireme complied. following: review
nts under 1. document
different Whether .
Acts. Schedule
II of
Compani
es Act,
2013,
which
relates to
useful life
of assets
to
compute
depreciati
on has
384
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
been
adhered
to.
2. As per
Schedule
III of
Compani
es Act,
2013,
fixed
assets
are
broadly
divided
into four
categorie
s, i.e.
tangible
assets,
intangible
assets,
capital
work in
progress,
and
intangible
assets
under
progress.
3.
Whether
the unit
has
complied
with the
provision
s of the
Factories
Act, 1948
with
regard to
hazardou
s
machine,
machine
in motion
and
385
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
transmiss
ion
machines
, etc.
4.
Whether
hoists
and lifts
are
properly
maintaine
d as per
Factories
Act 1948
and is
thoroughl
y
examined
by a
competen
t person
at least
once in
every
period of
six
months
and a
register is
kept for
this
purpose.
5.
Payment
of
Customs
duty and
custom
clearance
of
imported
machiner
y as per
Customs
Act, 1962
6.
Deductio
386
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
n and
payment
of TDS
for
installatio
n,
fabricatio
ns and
commissi
oning of
plant and
machiner
y, if
applicabl
e.
7.
Whether
the unit
has
obtained
an
appropria
te
certificate
from
Central
Pollution
Control
Board
(CPCB),
if
applicabl
e.
8.
Depreciat
ion is not
claimable
on the
amount
equal to
ITC/
Cenvat
Credit if
claimed
against
purchase
of any
387
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
machiner
y.
9. Ensure
the track
on fixed
assets for
claiming
input tax
credit
under
GST
ensuring
proper
document
ation and
reconcilia
tion on
input tax
credit
claims.
10.
Whether
a
company
is into
real
estate,
check
whether
they
complied
as per the
Transfer
of
property
act.
11.
Check
whether
the
company
has
compiled
with
labour
laws
complied
388
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
with
health
and
safety
regulation
.
Fixed Recognitio Fixed assets As per 1. Verify Recogniti 1. 30 NA
Assets n of fixed are compan that cost on of purchase
controls asset may recognized y policy of an item asset as invoice or
not be as only if they of per Ind 30% of
per Ind AS have future property, AS 16 high
16 economic plant and requirem value
Property, benefit to the equipmen ents asset
Plant and company. t shall be purchase
Equipment recognise invoice
d as an during the
asset if, year
and only whicheve
if: r is
(a) it is higher.
probable 2. 20
that installatio
future n
economic certificate
benefits
associate
d with the
item will
flow to
the entity;
and
(b) the
cost of
the item
can be
measured
reliably.
2. Items
such as
spare
parts,
stand-by
equipmen
t and
servicing
389
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
equipmen
t are
recognise
d in
accordan
ce with
this Ind
AS when
they meet
the
definition
of
property,
plant and
equipmen
t.
Otherwis
e, such
items are
classified
as
inventory
3. Check
certificate
/
Undertaki
ng of put
to use
Fixed 1. All fixed As per 1. Reconcili GL Analyse
Asset asset are compan Whether ation balances items
balances recorder in y policy the between and FAR descriptio
may not books as and reported FAR and balances n in fixed
be when fixed GL's at cut of asset
matched received and assets date. register
with updated in balance to
general Fixed Assets agrees ascertain
ledger Register with the various
balances (FAR) related assets
accordingly. account are
2. On records in correctly
monthly basis the grouped
designated general in
person ledger. different
review 2. Check heads as
General periodic per
Ledger (GL) review of nature.
390
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
balances with Fixed
Fixed asset Assets
register Register
prepare (FAR)
reconciliation and
for ensure its
difference. timely
3. All updation.
transaction 3.
are Whether
supported by recorded
vendor fixed
invoices. assets
transactio
ns tallies
with the
supportin
g
document
s, such
as,
vendor’s
invoice.
4. Check
reconcilia
tion
between
FAR and
GL must
be
reviewed
by
designate
d person,
and it
should
not have
long
pendency
.
5.
Whether
complied
with Ind
AS 16
requirem
ent or
391
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
not.
6. Check
fixed
assets
balances
with
external
parties.
7. Check
fixed
assets
transactio
ns are
recorded
in correct
accountin
g period.
Fixed 1. Company As per 1. Physical 1. Latest NA
assets have policy of compan Whether verificatio physical
may be physical y policy identificat n controls verificatio
physically verification of ion n report
verified at fixed asset at number is 2. Fixed
regular regular put on all asset
intervals intervals. the register
to identify 2. All fixed assets
unrecorde assets are and cross
d marked with verified
transactio unique with FAR.
ns, write identification 2.
off code. Whether
obsolete 3. Verification recorded
assets of asset are fixed
and gaps done along assets
with FAR. with have
identification been
of obsolete physically
machinery. examined
at regular
interval
and
compare
it with
fixed
assets
register
and
392
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
discrepan
cies, if
any,
should be
reported.
3. Check
obsolete/
non-
performin
g fixed
assets
are
periodical
ly
identified
and
document
ed. An
action
plan for
its
disposal/
alternate
use
should be
initiated.
Other 1. As per 1. Check Capitaliza Vendor NA
expenditur Expenditure compan recorded tion of invoice of
e related incurred upto y policy fixed other 30 assets
to fixed make an assets related capitalise
asset may asset are expenditu d during
not be operational correctly re the year
capitalised are classified along
along with capitalised as capital with cost
assets along with assets sheets
asset i.e. and
Installation certain
cost, expenses
commissionin that are
g cost. attributabl
2. Borrowing e for b
cost incurred that
upto date of asset to
capitalization its
also become working
part of fixed condition
393
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
assets. and use,
are to be
included
in the
cost.
2. Further
the
borrowed
cost, if
any, is
also to be
capitalize
d up to
the first
date of
acquisitio
n/
constructi
on as per
Ind AS
23.
3. Also
considere
d foreign
exchange
fluctuatio
n
provision
as per Ind
AS 21.
Ind AS 21
does not
permit
capitalisa
tion of
forex
difference
s.
4. Check
subseque
nt
expenditu
re
relating to
an item of
fixed
assets
394
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
should be
added to
its book
value
only if
they
increase
the future
benefits.
5. A cost
sheet
should be
prepared
with a
complete
breakup
of various
cost
incurred
to make
asset
operation
al.
Disclosure 1. Assets are As per 1. Check Disclosur Fixed NA
of fixed disclosed compan material e of all Assets
asset may with y policy items assets Register
not completed retiring during (FAR)
provide details of from use accountin with
complete gross, and held g period. complete
details of addition, for detail &
gross, net deletion and disposal general
and net value are to be ledger of
addition, during stated at various
deletion accounting lower of asset.
during period. net book
accountin 2. Asset for value and
g period. disposal is net
shown at net realizable
realizable value.
value or net Ensure
book value that the
whichever is cost of
lower. spare
parts of
obsolete
machiner
395
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
y is taken
at nil
value.
2. Check
fixed
assets
are
disclosed
– gross
and net
value at
the
beginning
and end
of the
accountin
g period
showing
addition,
disposal,
acquisitio
n, etc.
Assets All assets are As per 1. Check Insurance 1. NA
may not reinstated compan whether of fixed Insurance
be insured and y policy all the assets policy
to avoid reinstated fixed 2.
losses in values assets Reinstate
case of approved are ment
mis- from properly values
happening appropriate insured, 3. Gross
authority for and value of
insurance proper fixed
purposes. safety assets
measures
have
been
taken.
2. Assets
should be
insured
by
reinstated
value
instead of
gross.
Reinstate
396
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
ment
should be
approved
by
appropria
te
authority
before
insurance
quotation.
3.
Quotation
should be
obtained
from
different
vendors
and verify
all
clauses
under
different
quotation
and
according
ly obtain
insurance
policy
from
vendor
whose
quotes
match
with
business
requirem
ent.
4. Any
significan
t asset
purchase
d during
the year
should
also be
covered
under
397
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
insurance
policy by
giving
additional
premium.
5. Proper
records
have
been
maintaine
d for
sending
machiner
y for
outwards
repairs
fabricatio
n. Third
party
location
should be
insured
also
under
insurance
policy.
1.Disposa Company As per 1. Check Asset 1. 20 sale NA
l of fixed derecognised compan carrying may not invoices
assets is asset on y policy amount of be of asset
not in 1. Disposal an item of derecogni and
accordanc 2. When no property, sed correspon
e with future plant and ding entry
Company economic equipmen in Fixed
Policy. benefits are t shall be Asset GL.
2. Assets expected derecogni 2. Sale
identified from its use sed at the Register
for or time of
disposal disposal disposal.
may not 2.
be Complied
adequatel with other
y provision
safeguard of
ed against derecogni
theft or tion as
unauthoris per Ind
398
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
ed use. AS 16.
3. Check
sale
register
to verify
sale of
asset and
recognise
d as
revenue.
Depreciati Useful life 1. Useful life As per 1. Check Complian 1. Current NA
on control of assets of assets are compan useful life ce of year and
may not defined by y policy of Schedule previous
be defined considering tangible II of year FAR
as per life as per assets Company to check
Company schedule II of should Act 2013 useful life
Act 2013 Company Act not be of asset
requireme 2013. ordinarily 2.
nt and 2. different Depreciat
leads to Depreciation from the ion
inappropri method is useful life schedule
ate followed on specified as per
depreciati consistent in Part C Company
on. basis. of the Act 2013.
Schedule
II of the
Compani
es Act,
2013.
2. Check
residual
value
should
not be
more
than 5%
of the
original
cost of
the
tangible
asset.
3. Where
a
company
adopts a
399
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
different
useful life
or uses a
different
residual
value as
above,
the
company
is
required
to
disclose
such
difference
and
provide
justificatio
n, that it
is
supported
by a
technical
advice.
4. Check
depreciati
on
methods
applied
are
followed
consisten
tly.
5. Check
for
changes
needs to
be made
to comply
with the
requirem
ent of
statute,
change in
accountin
g
standard
400
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
and as
needed
for better
presentati
on.
6.
Electricity
Company
has to
continue
to charge
depreciati
on in
accordan
ce with
Electricity
Act.
7.
Depreciat
ion on
asset
which is
used in
double/
triple shift
is to be
increased
by 50%
and by
100%,
respectiv
ely.
8. Verify
the basis
of which
useful life
estimates
are made
The Depreciation As per 1. Check Complian 1. NA
depreciati method is compan complian ce with Analysis
on method used by y policy ce of Ind Ind AS 16 sheet of
may not considering AS 16, Property, future
reflect asset’s future the Plant and benefits
pattern of economic depreciati Equipmen 2.
future benefits are on t Depreciat
economic expected to method ion
401
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
benefit be consumed used schedule
from by the entity. shall as per
assets as reflect the Company
per Ind AS pattern in Act 2013.
16. which the
asset’s
future
economic
benefits
are
expected
to be
consume
d by the
entity.
2. Verify
the
depreciati
on
method
applied to
an asset
shall be
reviewed
at least at
each
financial
year-end
and, if
there has
been a
significan
t change
in the
expected
pattern of
consumpt
ion of the
future
economic
benefits
embodied
in the
asset, the
method
shall be
changed
402
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
to reflect
the
changed
pattern.
Such a
change
shall be
accounte
d for as a
change in
an
accountin
g
estimate
in
accordan
ce with
Ind AS 8.
3. Check
depreciab
le amount
of an
asset
shall be
allocated
on a
systemati
c basis
over its
useful
life.
4. Check
residual
value and
the useful
life of an
asset
shall be
reviewed
at least at
each
financial
year-end
and, if
expectati
ons differ
from
403
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
previous
estimates
, the
change(s)
shall be
accounte
d for as a
change in
an
accountin
g
estimate
in
accordan
ce with
Ind AS 8,
Accountin
g
Policies,
Changes
in
Accountin
g
Estimates
and
Errors.
Impairmen Impairmen On yearly As per 1. Check Complian Impairme NA
t t analysis basis, compan how ce of Ind nt
may not company is y policy company As 36, analysis
be performed reviews impairme of the
performed impairment the nts of company
by the analysis on carrying items of
company assets. amount of property,
its plant and
assets, equipmen
how it t
determine
s the
recoverab
le amount
of an
asset.
2. Check
when
company
recognise
404
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
s, or
reverses
the
recognitio
n of an
impairme
nt loss.
3. Check
other
complian
ce as per
Ind AS
36.
Income Non- Depreciation As per 1. Check Complian Depreciat
Tax Act, complianc under Income compan whether ce with ion
1961 e under Tax Act, y policy depreciati Income schedule
Income 1961 is on is Tax as per
Tax Act, provided on provided, Act,1961 Income
1961 percentage based on requirem Tax Act
on Written block of ent.
Down Value assets.
as prescribed 2. Check
in Income whether
Tax Rule, depreciati
1962. on is
provided
on the
percentag
e on the
written
down
value
(W.D.V.)
as
prescribe
d in Rule
5(1) read
with table
of
depreciati
on
prescribe
d in
Income
Tax
Rules,
405
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
1962.
3.
Depreciat
ion for a
period of
less than
180 days
is
restricted
to 50% of
the
amount
calculate
d as
above.
4. Other
depreciati
on
provision
under
Income
Tax Act
1961.
Fixed Company As per 1. Check Complian 1. GL and NA
Assets also complied compan whether,if ce with calculatio
disposal/ Income Tax y policy any, Income n sheet of
transfers provisions in asset is Tax Act profit or
are not case of sale sold 1961 loss on
accurately of asset discarded requirem sale of
calculated , ent. asset
and demolish 2. Capital
recorded. ed in the gain
previous working
year then sheet
its written 3. 10 sale
down invoice or
value at 50%
the value of
beginning asset
of sold
previous during the
year be year
increased whicheve
by actual r is
cost of higher.
assets
406
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
acquired
in the
same
block
during the
previous
year and
be
reduced
by the
sales
considera
tion with
scrap
value, if
any, and
depreciati
on be
provided
on
balance
of such
block.
2. Verify
surplus
arising on
sale of
capital
asset is
chargeabl
e to tax
as short-
term
capital
gain by
virtue of
Section
50, these
cases
are: (a)
When the
written
down
value of a
block of
asset is
reduced
407
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
to nil
though all
the
assets
falling in
block are
not
transferre
d.
(b) When
a block of
asset
ceases to
exist.
Intangible Non- Company As per 1. Check Depreciat Depreciat NA
Asset complianc complied with compan schedule ion on ion
e with Company y policy II of intangible schedule
statutory Act, 2013 Compani asset as per
low and Income es Act, Company
requireme Tax Act, 2013 for Act and
nt 1961 the as per
requirements. Intangible Income
assets, Tax Act.
the
provision
s of
accountin
g
standards
applicabl
e for the
time
being in
force
would
apply
(except in
the case
of
intangible
asset
created
under
Build,
Operate
and
408
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
Transfer
(BOT) or
Build,
Own,
Operate
and
Transfer
(BOOT),
etc.).
2. As per
Income
Tax Act
Depreciat
ion @
25% is
allowable
on
intangible
assets,
namely,
know–
how,
patents,
copy
rights,
trademar
ks,
licenses,
franchise
s, or any
other
business
or
commerci
al rights
of similar
nature.
3. Check
the
impairme
nt tests
for
intangible
assets.
4. Review
the
amortizati
409
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
on
methods
used for
intangible
assets.
Other Due Company As per 1. Check Due 10 high NA
Control diligence performs compan reasons diligence sale
decision proper due y policy and cost performe invoices
on sale diligence in benefit d on 20 high
purchase sale, analysis various purchase
of fixed purchase and of such asset Invoices
asset may maintenance buying transactio
not be of Fixed recorded. n
performed Assets 2. Check
leads to in case of
wrong make/
decision buy
decision,
the
calculatio
n of
actual
cost.
3. Check
that
related
party
transactio
ns are
made at
arm’s
length
price.
4. Check
whether,
in
case,repl
acement
of any
machiner
y is to be
done,
check
reason
for the
same
410
Fixed Assets and Capex
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
whether it
is due to
technolog
ical
change or
obsolesc
ence of
assets.
5. Check
whether
technical
know-how
is
obtained
for
sophistica
ted
machineri
es.
6. When
any
machine
is
scrapped,
whether
way of its
disposal
is
ascertain
ed and
document
ed.
7.
Whether
break
down
analysis
of assets
is done.
8.
Whether
date-wise
obligation
for
insurance
and
maintena
411
Internal Audit Checklist
Process Sub-process Risk Control Control Test Attributes Sample Size Data
Description Owner Performed tested analytics
performed
nce is
observed.
Fixed There is a As per 1, Check Periodic 3 months NA
Assets system of compan pending reporting
Register is reporting y policy requisitio and
not various ns for analysis
maintaine information which
d and not on periodic Purchase
reviewed basis and Order
at regular correspondin (PO) is
intervals. g actions are not
taken by raised.
management. 2. Check
list of
pending
Orders
(Pos) for
which
supply is
not made.
3. Check
list of
long
outstandi
ng
advances
to
suppliers
but fixed
assets
not
supplied
with
capital
commitm
ents.
412
Checklist 22
Project Management
Process Sub-process Risk Control Control Test Attributes Sampl Data
Description Owner Performed tested e size analytics
performed
Pre-Project Business have Risk of taking Any project Review Due 100%
Readiness domain up projects that needs to whether the Diligence
expertise. which may not be taken project has of the
be financially should be been Project
or operationally assessed for approved by
viable or where its viability the Board of
the business by the Directors
does not have experts after a due
domain within the diligence is
expertise. The Company or done and its
business with support viability is
should do a of an established.
preliminary external
study of the consultant.
proposed The decision
project in terms to invest in
of viability from new project
(a) Financial vests with
(b) Operational the Board of
(c.) Legal / Directors.
Regulatory The Board of
view and also Directors
consider may entrust
whether the to review the
business has project
domain viability to a
expertise in it. committee of
Directors.
Pre-Project Budgetary Risk of Ensuring To review Adequacy 100%
Readiness Allocation adequate funds that the the of
not being budgetary budgetary Budgetary
allocated or process process to Allocation.
planned for the includes ensure that
project. consideratio the budget
n of new includes
projects funds
including allocated for
tenure, projects.
possible
borrowing
costs,
sources of
Internal Audit Checklist
To also
review the
process of
how the
Governance
(i.e., the
Board) is
considering
investment in
new project.
Pre-Project Planning Risk of Project Review of (a) Ensuring Review of 100%
414
Project Management
415
Internal Audit Checklist
416
Project Management
417
Checklist 23
Inventory Management
Process Sub- Risk Control Test Performed Attributes Sample Data
process Description Tested Size Analytics
Performed
Inventory Initialization Stores in not Stores 1. Obtain a
Managemen functioning functions certified copy of
t properly. are defined the Trial Balance
and for the period
documente under audit.
d. Alternatively,
extract the Trial
Balance from the
system.
2. Obtain:
i. Key Result
Areas/ Objectives
of the Stores
Function as well as
of the Unit/
Category under
audit;
ii. An organogram
of the Stores
Function;
iii. Delegation of
Authority;
iv. All policies,
standard operating
procedures, office
orders, etc. which
relate to the Stores
Function.
3. Ask whether any
work has been
done on IT
General Controls
(ITGC) /
Segregation of
Duties (SoD) (in
ERP environment)
controls. Review
the report thereof
and modify the
audit program
accordingly.
4. Read the
Inventory Management
419
Internal Audit Checklist
420
Inventory Management
421
Internal Audit Checklist
422
Inventory Management
423
Internal Audit Checklist
424
Inventory Management
425
Internal Audit Checklist
426
Inventory Management
427
Internal Audit Checklist
428
Inventory Management
429
Internal Audit Checklist
430
Inventory Management
431
Internal Audit Checklist
432
Inventory Management
433
Internal Audit Checklist
434
Inventory Management
435
Internal Audit Checklist
436
Inventory Management
437
Internal Audit Checklist
438
Inventory Management
439
Internal Audit Checklist
440
Inventory Management
441
Internal Audit Checklist
442
Inventory Management
443
Internal Audit Checklist
444
Inventory Management
445
Internal Audit Checklist
446
Inventory Management
447
Internal Audit Checklist
448
Inventory Management
449
Checklist 24
Cash and Bank
Process Sub- Risk Control Control Test Attributes Sample Data
process Description Owner Performed tested size analytics
performed
Cash Entity Inadequate 1. As per 1. Check 1. 1. SOD Analyse
and level Segregation Segregation compan documented Documente 2. Access transaction
Bank controls of Duties of duties y policy SOD and d SOD, right List carried out
and access relating to Access right Access 3. Half during the
rights which the following list for right yearly review period
may result in transactions: various 2. Periodic review to identify the
fraudulent / a. activity of review document following:
unauthorise Authorization cash and 1.
d of cash / bank Unauthorized
transactions bank transactions. users
transactions 2. Verify performing
b. Physical evidence of transactions
handling of periodic 2. Conflicting
cash review of transaction’s
c. Issuance SOD and rights grated
of cheques Access to same
and online rights in ERP person.
payment system. There has to
d. Recording be a
of cash and 3. Verify separate
bank same SOD report on
transaction in and Access roles
books of right also assigned to
account, entered in each of the
e. system for users and
Preparation approval of then analysis
of Bank cash and of conflicting
Reconciliatio bank roles and
n transactions. responsibiliti
Statements. es to be
reviewed.
2. Access
rights (Write /
Read /
Delete /
Modify) to
various
peoples in
the
organization
is reviewed
periodically
Cash and Bank
3. Periodic
Review of
Segregation
of Duties and
Access rights
is conducted.
Interim
rotation of
the duties
are done
periodically
by
management
.
Authority 1. Proper As per 1. Check Approved Approved 1. Identify
matrix may authorization compan cash and DOA/DOP DOA/DO transactions
not be of cash and y policy bank for cash P from for unusual
prepared or bank transactions’ and bank BOD high value
approved transactions DOA/DOP is compared to
from Board as per available other
of Director Delegation of and transactions
(BOD). Authority approved by and seek
2. Board of BOD. valid
Directors 2. In case of authorization
defines the any and
authorities authorized documentary
for approving signatory evidence.
& performing leaving the 2. Analyse
cash and Company, transactions
bank whether list to identify
transactions. of authorized possible split
signatories is to circumvent
revised payment
timely with authorization
proper Board limits as per
Resolution Delegation of
and Authority and
intimated to bank
bank. signatories
451
Internal Audit Checklist
452
Cash and Bank
453
Internal Audit Checklist
454
Cash and Bank
455
Internal Audit Checklist
456
Cash and Bank
457
Internal Audit Checklist
458
Cash and Bank
459
Internal Audit Checklist
460
Cash and Bank
2. Where the
auditor finds
that post-
461
Internal Audit Checklist
Verify control
of safe
custody of
certificate or
document to
designated
person.
462
Cash and Bank
463
Internal Audit Checklist
464
Cash and Bank
465
Internal Audit Checklist
466
Cash and Bank
2. Further as
per
Companies
Act, 2013
the following
additional
disclosures
are also
required to
be made:
(i)
Earmarked
balance with
banks e.g.,
unpaid
dividend.
(ii) Balance
with banks
held as
margin
money/
security
against
borrowings.
(iii) Bank
deposits with
more than 12
months
maturity.
(iii)
467
Internal Audit Checklist
468
Cash and Bank
3. However
in case of
RTGS, after
getting
approved
RTGS copy,
Designated
person
prepare
RTGS/NEFT
details and
upload the
same to bank
site and will
469
Internal Audit Checklist
470
Cash and Bank
471
Internal Audit Checklist
472
Cash and Bank
473
Internal Audit Checklist
474
Cash and Bank
475
Internal Audit Checklist
476
Cash and Bank
477
Internal Audit Checklist
2. Check all
cash receipt
are
deposited in
bank on
daily basis or
cash exceed
as per define
limit by
management
.
Bank High Organization As per 1. Check all Dormant Listed NA
balance balance verify compan bank account bank
Managem maintained transaction in y policy account and and closure account
ent in account bank transaction and GL
and not account, if in them.
utilised account idle 2. Verify if
properly to from long bank
save or earn period and account is
interest have balance not operative
are closed from long
after time and
approval reason for
from non closure.
management
.
Organization As per Verify Approval 20 NA
has proper compan approvals of for transfer interbank
approval y policy transfer from within transactio
policy for one ban to banks n or as
transfer of another per
balance from bank. business
one bank to need
another bank
account.
Organization As per Analyse Utilization GL of Analyse
has policy to compan Bank of funds Major Bank
review y policy transactions bank transactions
balance in to identify account to identify
major bank any idle any idle bank
account daily bank balances
and decision balances which could
of transfer of which could have been
balance or have been utilized for
478
Cash and Bank
479
Internal Audit Checklist
480
Cash and Bank
481
Checklist 25
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
Treasury Initializatio NA NA NA 1. Obtain the Overview None 1. Analyse
Manageme n Policy on and cash flows,
nt Treasury Understa investment
Management nding of transactions
as approved Treasury and foreign
by the Board. operation exchange
2. Obtain a s transactions to
copy of detect
Accounting anomalies,
Manual or unusual
Standard patterns, or
Operating unauthorized
Procedures. activities.
3. In case 2. Identify
such a discrepancies
manual or that further
SOP is not investigation.
available,
obtain an
understandin
g of the
banking
process and
the BRS
preparation/
review
process.
4. Obtain
Authority
matrix for
Delegation of
Authority
w.r.t.
operation of
bank
accounts,
BRS, etc.
5. Obtain a
certified copy
of the Trial
Balances as
on the
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
opening and
cut off dates
for the audit
period.
6. Identify all
balances with
banks,
whether
current
account,
deposit
account, etc.
7. Discuss
the nature
and the
purpose of
each bank
account with
the CFO or
any other
senior person
from the
client’s side,
to identify
any
inoperative
accounts and
understand
any specific
purpose for
which they
are
maintained.
8. For the
last year,
year, plot a
bird’s eye
view of the
total number
of bank
accounts
(E.g. Current
Account,
Deposit
Account,
etc.) vis a vis
Balance
Confirmation
483
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
s available.
Be alert for
any trend,
e.g.
confirmation
a particular
bank balance
not being
received.
Inquire into
any unusual
trends.
9. Ensure
that there is
clear
bifurcation of
responsibiliti
es to ensure
that no single
individual has
complete
control over
all aspects of
treasury
functions.
10. Distinct
roles for
activities
such as cash
management,
payment
approvals,
investment
decisions
and
reconciliation
are defined.
Treasury Risk Absence of Treasury Treasury 1. Obtain Duly 100% None
Manageme manageme a Standard objectives Head copy of Approved
nt nt Policy/ Risk and risk Treasury comprehe
framework Managemen appetite Policy and nsive
and t Framework should be assess Treasury
governanc may lead to clearly whether it is Policy
e person defined in updated and and Risk
(including specific policy approved by Control
Treasury decisions/ document. the Matrix
Policy) actions. appropriate
484
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
authority.
2. Whether
the policy
align with the
organization'
s overall
financial
objectives
and risk
appetite.
Check
whether the
policy
address
various
financial
risks,
including
liquidity risk,
interest rate
risk, credit
risk, and
foreign
exchange
risk.
3. Check
whether
clear roles
and
responsibiliti
es are
defined for
treasury
personnel.
Treasury Segregatio Lack of Segregation Treasury 1. Verify the Segregati 100% 1. Identifying
Manageme n of Duties segregation of duties is Head Segregation on of unusual
nt of duties enforced of duties is Duties in patterns in
over keys, through implemented Treasury transaction
cash/ funds organisation to the extent Activities data such as
activities. al that it is large or
structures, possible, frequent
user access given the payments.
in the number of 2. Analysing
treasury/pay staff access
ment available in permission
systems finance and identify
and related any individual
485
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
procedural functions. having
documents. 2. excessive
There Compensatin access to
should be g controls sensitive data
an effective such as or systems
segregation senior
of key management
duties oversight are
including used.
dealing,
settlement,
and
accounting/
reconciliatio
n. These
segregation
s need to be
further
strengthene
d if the
treasurer
executes
transactions
. This
segregation
is reinforced
through
procedures
documentati
on and
position
descriptions
.
Treasury Bank Unauthorise The Board Treasury 1.Confirm Authorize 100% None
Manageme Account d personnel has Head that the d
nt Manageme may open or approved Board of Opening/
nt- close bank authority Directors or Closing of
Opening accounts. matrix to other Bank
and enter/ authorized Account,
Closing of terminate body has Review of
Bank bank explicitly Inactive
Account relationship authorized bank
s, including the approval accounts
opening and authorities
closing of for entering,
bank terminating,
accounts. and
486
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
(e.g. Bank managing
accounts bank
can be relationships.
opened or 2. Identify
closed only the list of
by Bank
resolution of Accounts
the Board of Opened and
Directors or closed during
other the period by
authorized reviewing the
body or Trial Balance
official). (current and
Inactive previous
bank period).
accounts Verify that
are these were
reviewed duly
and closed. approved.
When a 3. Confirm
signatory is that inactive
no longer bank
authorized accounts
to access (those not
the account, actively
the bank used) are
should identified and
promptly reviewed
remove periodically
their and check
access. whether
This there are
prevents clear criteria
unauthorize or guidelines
d for
individuals classifying
from accounts as
conducting inactive.
transactions
.
Treasury Bank Unauthorize Signing Treasury Ensure that Signatorie 100% None
Manageme Account d person act Limits are Head there are s to Bank
nt Manageme as a clearly dual Account
nt- signatory for established/ signatories
Authorized bank stated. (for both
Signatory accounts. There must online and
Fraudulent be two cheque
487
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
or Incorrect authorized payments)
payments signatories for each bank
are made. (e.g. A account and
senior the same has
managemen been
t level non- approved by
financial the Board.
functionary
and
Corporate
Treasurer/
Assistant
Treasurer).
Signatories
for cash
disburseme
nts can be
added only
by
resolution of
the Board of
Directors or
other
authorized
body or
official
Treasury Bank Compliance I - Treasury 1. Verify that Complian 100% None
Manageme Account with bank Corporate Head Corporate ce and
nt Manageme account Treasury Treasury Disclosur
nt - restrictions maintains maintains a es
Complianc is timely up-to-date comprehensi relating to
e to GAAP reported to record of all ve record of Bank
managemen bank all bank Account
t and accounts accounts,
necessary opened/ including
disclosures closed with those that
as per their name, have been
applicable locations; opened and
GAAP are name, titles closed and
not made. and check that
functions of the records
local contain
signatories; relevant
and information,
rationale for such as, the
opening/clo bank's name,
sing an location,
488
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
account. A account
separate numbers, and
general purpose of
ledger each
account is account.
maintained 2. Verify that
for each a separate
bank general
account. ledger
account is
II – maintained
Managemen for each bank
t account and
responsible check that
for the general
monitoring ledger
compliance accounts are
with bank properly
account labelled and
restrictions identified.
(e.g. those 3. Verify that
in case of the recording
Foreign and
Currency presentation
accounts), of bank
periodically accounts in
reviews the the general
compliance ledger
status. comply with
Adequate relevant
guidelines accounting
have been standards
drawn for and
capturing principles.
necessary 4. Ensure
information Compliance
for financial to all bank
statement related
disclosures restrictions.
(i.e.
compensati
ng
balances,
overdrafts,
restrictions
on cash
balances,
489
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
etc.)
Treasury Recording Adherence I - List of Treasury 1. Evaluate Appropria 100% 1. Apply data
Manageme of Bank to authorised Head the process te analytics to
nt Transactio authorisatio signatories for approving recording detect
ns- n process are payments, of Bank potential
Authorizati may not be available including the transactio fraudulent
on of verified with the appropriate ns activities, such
payments effectively Accounts authorization as
by the Officials. levels and unauthorized
banks for The same documentatio payments or
accounts. are n required for unusual
configured different patterns in
in the payment bank
banking types (for transactions.
Portal. online 2. Perform
Specimen payments, trend analysis
signature Cheque to identify
cards are Payments). deviations
available Check from normal
with the whether Host behaviour.
finance to Host
department based
so as to payment
verify the process has
signatures been
of implemented.
appropriate 2. Evaluate
authority controls in
before UPI
making for Payments,
payment. Receipts like
All the transaction
payments Limits, Real-
should be in time
compliance Notifications,
with Transaction
statutory Reconciliatio
requirement n, etc.
s.
Treasury Recording Cheque I - Adequate Treasury 1. Evaluate Control 100% None
Manageme of Bank instruments control over Head the controls over
nt Transactio may be inventory of over physical Physical
ns - mishandled/ cheques is cheques. cheques
Physical mis-utilized. maintained. 2. Ensure
control All cheques that only
over are marked authorized
490
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
cheques as account personnel
payee. can write,
Further for sign, or
all the handle
banks, checks.
access to 3. Ensure
stock of that access
unused controls to
cheques is restrict
controlled. access to
The details cheque-
of inventory writing
of cheque software or
(including tools has
unused been
cheques) is implemented.
maintained 4. Ensure
in Excel that account
Sheet/ reconciliation
records s are
(control performed to
sheet). ensure all
issued
II - As cheques are
generally, properly
the banking recorded and
system accounted
sequentially for.
allots
cheque
numbers, in
order to
cancel a
cheque the
same needs
to be
cancelled in
the system
which can
be done
only by
designated
person in
Finance
Department.
Cancelled
cheque are
clearly
491
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
marked and
inventory of
cancelled
cheques
maintained.
In case a
cheque gets
misplaced,
cheque is
voided in
the System
and at the
same time,
a stop
payment
advice is
sent to the
bank
concerned.
Treasury Recording All receipts The Treasury Scrutinize the Recording 100% None
Manageme of Bank may not be transactions Head transactions of Bank
nt Transactio correctly to be in each bank transactio
ns - /timely conducted account and n on
Appropriat accounted through ensure that appropriat
e Account for (by the each bank all capital e
cut-off account receipts are accounts
date). should be deposited in
adequately corporate
defined. (All bank account
capital and are
receipts are utilized for
deposited in specific
corporate purposes on
bank immediate
account and basis, all
are utilized working
for specific capital
purposes on receipts are
immediate deposited in
basis. All division bank
working accounts.
capital Verify
receipts are whether
deposited in payment
division accounts
bank should be
accounts. separate
492
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
Payment from
accounts collection
should be accounts.
separate
from
collection
accounts for
better
monitoring
and control
over funds).
Treasury Recording Stale The stale Treasury Verify Reversal 100% None
Manageme of Bank cheques cheques are Head whether the of Stale
nt Transactio may not be reversed on stale cheques
ns - Stale reversed to monthly cheques are
cheques show basis to a reversed in
incorrect separate the separate
bank account account on a
balance. termed as monthly
"Stale basis.
Cheques
Payable
Account"
maintained
for this
purpose. No
direct
transfers to
Party's
Account is
made.
Amount
lying in the
"Stale
Cheques
Payable
Account"
which is
three years
old is
transferred
to the
Party's
Account.
Treasury Estimation All receipts Normal Treasury Review the Estimatio 100% 1. Assess the
Manageme of Working may not be working Head effectiveness n of accuracy of
493
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
nt capital correctly capital of the fund Working cash flow
Requireme /timely funds forecast capital forecasts by
nts accounted should be preparation requireme comparing
(by the cut- reviewed at and review nt forecasted
off date). the month procedure. values with
end for For sample actual cash
accuracy month obtain flows over a
and the forecast specified
completene and review period.
ss. Periodic the 2. Identify
financial underlying areas where
reports are assumptions forecasting
reviewed by and facts. accuracy can
Managemen be improved,
t, with and explain
comparison deviations.
to budgeted
amounts or
other
financial
data for
reasonablen
ess of cash
and bank
balances.
Treasury Bank Transaction Bank Treasury For each BRS 100% None
Manageme Reconcilia s may not reconciliatio Head BRS selected performed
nt tion be recorded n is in the by
either by performed sample, Independ
mistake or by person ensure that: ent
intentionally. independent 1. The Person
of banking person
transaction responsible
and for
accounting. reconciliation
(In cases is not a
where cheque
independent signing
treasury authority.
operating 2. The
systems are person does
used, a not have
three-way cash
reconciliatio handling
n is responsibility
between .
bank 3. The
494
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
statement, person does
treasury not have
system and bookkeeping
the ledger responsibility
balances). .
4. Adequate
maker-
checker
controls are
in place.
Treasury Bank Transaction Reconciliati Treasury 1. Review BRS 100% None
Manageme Reconcilia s may not ons Head each BRS: prepared
nt tion be recorded between a. For and
either by bank evidence of reviewed
mistake or statements review by a for all
intentionally. and general person bank
ledger are independent accounts
performed from person
on a regular responsible
basis and for
reviewed & reconciliation
approved by .
managemen b. To ensure
t. that the
Reconciling review was
items are conducted on
found and a timely
corrected as basis.
necessary. c. Check
whether the
date of
preparation,
date of
review and
date of
approval are
captured in
the BRS.
d. Ensure
that resultant
actions are
documented
(as minutes,
or emails,
etc.) and
check
whether
495
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
these have
resulted in
the desired
result (e.g.
clearance of
old items,
rectification
of errors/
omissions,
etc.)
e. For the
type of
reconciling
items. Inquire
in detail
unusual
items (E.g.
Payments
appearing in
Bank
Statement
but not in the
Bank Book,
etc.)
f. For
‘Cheques
Issued but
Not
Presented’
check
subsequent
clearance of
these, on a
100% basis.
Be alert of
any unusual
trends/
occurrences
(E.g. Large
number of
vendor
cheques or
employee
cheques
appearing as
un-presented
for unusually
long periods,
496
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
High value
vendor
cheques
appearing as
un-presented
for unusually
long periods,
etc.)
g. For
‘Cheques
Deposited
But Not
Cleared’
check
subsequent
clearance of
these on a
100% basis.
h. From the
original Bank
Statement of
the
subsequent
month, pick
up a sample
of cheques
that were
cleared in the
first 2-3
working
days. Trace
these back
into the BRS
of the
previous
month. These
cheques
should
reasonably
be appearing
in the BRS
as ‘Cheques
Issued But
Not
Presented’.
i. Specifically
inquire into
reconciling
497
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
items that are
over 60 days
old.
j. Review
Bank
Charges, if
material.
Ascertain if
these are
checked
independentl
y w.r.t. the
agreement
with Bankers
or whether
the entry is
simply picked
up from the
BRS and
effected in
the Bank
Book.
2. For all
BRSs tested,
reconcile the
opening bank
balance of
the
subsequent
period with
the closing
balance of
the period
under audit.
3. Inquire
regarding the
procedures in
place when
the persons
performing
and/ or
supervising
the
reconciliation
s are absent
at their
498
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
workplace.
Ensure that
any
substitute
persons
deployed are
competent,
compatible
with their
duties
assigned
duties and
are fully
aware of how
the
reconciliation
s are to be
performed
and
supervised.
4. Out of the
sample,
select a few
(To Be
Agreed with
Client and
Engagement
Manager/
Partner) BRS
for a detailed
verification.
For such
BRS, trace:
a. The
balance as
per Bank
Book with the
Bank
statement
b. Each
individual
reconciling
item into the
underlying
source
record
c. Check
499
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
arithmetical
accuracy of
each group
of reconciling
items as well
as the BRS
itself.
5. In cases
where BRS
has not been
prepared due
to opening
and closing
balances
being the
same, obtain
Bank
Statement for
the entire
audit period
to ensure
that there
were no
activities
during the
period. A
good control
practice is to
prepare a
formal BRS
for such
accounts as
well.
6. Similarly,
for accounts
explained to
be non-
operative,
check
whether if a
formal BRS
was
prepared.
Further,
obtain and
review the
500
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
original Bank
Statement for
the entire
audit period
to ensure
that there
were no
activities
during the
period.
7. For the
bank
accounts
selected,
ensure that
Bank
Statements
are
supported by
bank’s
balance
confirmations
, else the
bank
balances/
statements
should be
verified
online.
Proofs of
such online
confirmations
should be
retained in
the working
papers. If
none of the
above two
procedures
are
performed,
this fact
should be
clearly stated
as a
limitation in
the audit
501
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
report.
8. For all
balances on
deposit
account(s),
ensure that
the original
deposit
certificates
are
supported by
bank’s
balance
confirmations
, else the
deposits
should be
verified
online.
Proofs of
such online
confirmations
should be
retained in
the working
papers. If
none of the
above two
procedures
are
performed,
this fact
should be
clearly stated
as a
limitation in
the audit
report.
9. For all
balances on
deposit
account(s),
check the:
a. Due dates
of payment of
interest
502
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
b. Rate
(simple or
compounding
)
c.
Calculations
of ‘Interest
Accrued &
Due’ as well
as ‘Interest
Accrued But
Not Due’
d. Ensure
correct
accounting
thereof,
including Tax
Deducted at
Source
e. Ensure
correct
disclosure
thereof.
10. Review
the Bank
Book with the
Bank
Statements
for each bank
account
selected for
any unusual
entries (e.g.
inter-bank
transfers,
cash
deposits,
etc.) for a
period of 5
days before
and 5 days
after the ‘cut-
off’ date, i.e.
the period
end.
Specifically
determine
503
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
that:
a. Transfers
between
each bank
were
recorded in
the same
period, i.e.,
all transfers
prior to the
year-end
were
recorded in
each ledger
before the
year end,
and vice-
versa for post
year end
transfers.
b. Transfers
not affected
by banks
within the
same
accounting
period in
which these
were
initiated, are
properly
reflected as
reconciling
items in the
BRS.
11. Review
the trend in
balances with
banks (on
various
accounts). In
case the
entity seems
to be holding
Treasury Petty Cash Incompatibl Physical Treasury 1. Review the Physical 100% 1. Perform
Manageme transactio e tasks may cash Head controls for verificatio initial data
504
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
nt ns be assigned verification Physical n of cash exploration to
(to the same is cash understand
individual) conducted verification transaction
resulting in daily and 2. Count volume,
non- physical undeclared frequency, and
detection of verification petty cash patterns over
errors and sheets are and time.
omissions signed by a document it. 2. Analyse
person a. From the frequency and
independent above, make amount of
of the an cash
cashier. assessment replenishment
Surprise of the control s. Evaluate the
checks are of petty cash need for
made by funds. optimization.
Internal/
Statutory
auditors.
Treasury Petty Cash Incorrect/ The cash Treasury Evaluate the Reconcili 100% None
Manageme transactio incomplete ledger is Head procedure of ation of
nt ns cash reconciled reconciliation cash
transactions with the of the cash ledger
may be general ledger with with
recorded in ledger. general general
the general Discrepanci ledger. ledger
ledger. es are Physically
found , verify the
corrected, cash
and balance,
reprocessed cash Ledger
as and General
necessary Ledger
on a timely balance
basis. The during the
reconciliatio audit.
ns are
reviewed
and
approved by
appropriate
managemen
t.
Treasury Petty Cash Unauthorise I - Company Treasury Determine Approval 100% None
Manageme transactio d has clearly Head the of Petty
nt ns disburseme defined appropriaten cash
nts may be levels of ess of petty Transacti
505
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
made. authority for cash on
approving expenditures
and/or in
executing accordance
different with company
types of policies and
cash procedures
transactions by
. Monetary Judgmentally
limits have selecting a
been set for sample of
approval petty cash
and reimburseme
execution of nt vouchers.
transactions Check the
by following:
individual. 1. They have
been
II - properly
Authorizatio executed.
ns and 2. The
monetary expenditures
limits are are
regularly appropriate.
reviewed 3. The
and expenditure
updated as was
changes approved by
occur. All an authorized
updates are signatory.
communicat
ed both
internally
and
externally in
a timely
manner.
Treasury Fund Capital Application Treasury 1. Check the Applicatio 100% None
Manageme Manageme funds may of long-term Head process of n of Long-
nt nt be utilized capital review of term
for working funds and application of Funds
capital short term funds (Long and Short
requirement working term and term
s or vice capital short term) working
versa funds for the audit capital
should be period. funds.
monitored 2. Ensure
506
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
periodically. that the
short-term
Working
capital
requirement
is met
through short
term working
capital funds
and long
term capital
requirement
is done
through long
term capital
fund.
Treasury Borrowing Unauthorize Every Treasury 1. Obtain and Authorizat 100% Key
Manageme s d debts are borrowing Head review the ion of Performance
nt made in the should be organization' Borrowing Indicators
company's approved as s borrowing s (KPIs):
name per the policies, 1. Set the KPIs
authorizatio procedures, to measure
n matrix and treasury
(and the guidelines to performance,
approval understand such as cash
limits). the conversion
framework cycle, return
within which on
borrowings investments,
are made. or debt ratios.
2. Review the 2. Monitor
borrowing KPIs over time
authorization to identify
and approval trends and
process to deviations.
ensure that it
is in line with
the
organization'
s governance
structure and
clearly
defines roles
and
responsibiliti
es for
borrowing
507
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
decisions.
3. For the
borrowings of
the company,
check
whether
borrowing
was
approved as
per the
authority
matrix.
Treasury Borrowing Interest on Managemen Treasury 1. Assess the Review of 100% None
Manageme s borrowings t reviews Head organization' expenses
nt or other periodic s interest associate
transactions financial rate risk d with
such as reports, with management Debt
redemption, comparison strategies,
conversion s to including the
of debt or budgeted use of
accrual of amounts or hedging
interest may other instruments,
not be financial to mitigate
timely or data, for exposure to
accurately reasonablen interest rate
recorded. ess of fluctuations.
expenses 2. Ensure
associated that the
with debt. Management
Unusual reviews
variances reasonablene
are ss of
researched expenses
and associated
corrected as with debt.
necessary.
Reviews
could
include:
- Interest
expense
- Interest
expense by
debt facility,
including
effective
rates
508
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
- Accrued
interest
payable.
Treasury Borrowing Borrowing All Treasury 1. Verify that Complian 100% None
Manageme s terms or borrowing Head all borrowing ce with
nt obligations restrictions agreements Debt
may not be are formally and related agreemen
adequately monitored documentatio ts.
met and n are
resulting in compliance complete,
liabilities assessed accurate, and
severe then regularly by compliant
that a cross with relevant
accounted section of laws and
in normal managemen regulations.
course. t including 2. Verify the
legal, organization'
accounting s compliance
and with debt
treasury terms or,
personnel. loan
Questions agreements,
or grey and other
areas may contractual
be obligations
escalated to related to
outside borrowings.
legal
counsel for
additional
consideratio
n and
advice.
Treasury Investment Unauthorise I – The Treasury 1. Obtain the Approved 100% Investment
Manageme s d personnel company Head investment investmen Performance
nt may execute has a strategy/guid t Analysis:
investment defined elines/Standa strategies 1. Evaluate the
transactions investment rd operating / performance of
. strategy procedure. guideline investment
converted Ensure that portfolios by
into these are analysing
guidelines. reviewed by returns, yield
These the Board. calculations,
Investment 2. and risk
Strategies Understand measures.
Guidelines the defined 2. Compare
509
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
should be levels of investment
timely authority and performance
reviewed by monetary against
the Board. limits for benchmarks
approving and industry
II - The and/or standards.
company executing
has also different
clearly types of
defined Investments.
levels of
authority
and
monetary
limits for
approving
and/or
executing
different
types of
Investments
. All
investment
trades are
approved by
authorized
person only.
Further,
these
monetary
limits and
guidelines
should also
be
consistent
with
Companies
Act
requirement
s. (Section
185,
Section 186
of the
Companies
Act, 2013,
etc.)
III -
510
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
Authorizatio
n and limits
are
regularly
reviewed
and
updated as
changes
occur and
communicat
ed both
internally
and
externally in
a timely
manner.
Treasury Investment Unauthorise The Treasury Obtain the Approval 100% None
Manageme s d personnel purchase of Head list of of
nt may execute self-directed investments investmen
investment financial done during t as per
transactions instruments, the audit defined
. including period. procedure
but not Check s
limited to, whether
stocks, these
bonds, investments
notes, are approved
debentures, by authorized
certificates persons.
of deposit,
commercial
paper or the
local
investment
of excess
cash
requires the
prior
approval of
the
Corporate
Treasurer.
Investments
initiated by
the
Corporate
Treasurer
511
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
are subject
to the
approval of
the Chief
Financial
Officer.
Treasury Investment Accounting I - Treasury 1. Review the Appropria 100% None
Manageme s (valuation) Managemen Head investments te
nt and t obtains to ensure valuation
disclosures mark-to- they are and
as per market appropriately accountin
applicable valuations classified as g of
GAAP may for trading per Investme
not be and accounting nts
made. available for standards
sale (e.g., held-to-
securities maturity,
as per available-for-
applicable sale, or
GAAP. trading).
These 2. Confirm
valuations that the
should be accounting
independent treatment of
and readily investments
verifiable. complies with
relevant
II - accounting
Managemen standards,
t also such as
reassess Indian
the Accounting
appropriate Standards
classificatio (IND AS 109)
n for all or Generally
debt and Accepted
equity Accounting
securities. Principles
(GAAP).
3. Check for
any
reclassificatio
ns of
investments
and ensure
they are
supported by
512
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
proper
documentatio
n and
approvals.
Treasury Writing of The Bank I - Bank Treasury Before Authorizat 100% None
Manageme Instrument Guarantee/ Guarantee/ Head issuing the ion of The
nt s - Letter LC/ BP may LC is instruments, Bank
of Credit / be opened opened by Verify that all Guarante
Bank without Appropriate instruments e/ LC/ BP
Guarantee/ proper Designated are issued
Bills authorisatio Authority and
Payable n after authorized by
receiving persons with
approved the
requisition appropriate
from authority, as
respective per the
dept. and organization’
the same is s delegation
approved by of authority
authorised policy.
signatories. 2. Review the
II - written
Standard instruments
LC terms is and ensure
drafted in that they are
consultation complete and
with the contain all
legal required
department. terms and
Any conditions.
deviation 3. Validate
from the the accuracy
same is of details
adequately such as the
vetted by beneficiary’s
legal. name,
Expiry amount,
status is payment
monitored terms, and
by expiry date,
Appropriate etc. in the
Designated instruments.
Authority. 4. The Bank
Guarantee/
LC/ BP
opened
513
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
during the
audit period.
Very if the
same was
approved as
per the
defined
guidelines.
Treasury Insurance Insurance Guidelines Treasury Ensure that Guideline 100% None
Manageme coverage for asset Head Guidelines s for
nt may not be (value wise) for insurance insurance
renewed or and risk are formally
may be (type of laid down
rendered insurance) and are
inadequate coverage approved.
are laid out
clearly. The
responsibilit
y for
obtaining
and
managing
the same is
also clearly
specified.
Cost benefit
analysis for
not covering
an asset
should be
prepared
and
reviewed by
an
appropriate
managemen
t level.
Treasury Insurance Insurance The Treasury 1. Review the Adequacy 100% None
Manageme coverage Insurance Head organization' of
nt may not be Manager s insurance Insurance
renewed or reviews the policies. ,
may be list of 2. accuracy
rendered assets Understand of
inadequate (including the terms, premium,
Additions or coverage robustnes
Deletions of limits, s in
514
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
Interest) deductibles, claims
periodically exclusions, process
and updates and other key
the terms of provisions of
insurance if each policy.
required. 3. Examine
insurance
policy
documents.
4. Ensure
that policies
are valid, up-
to-date, and
accurately
reflect the
organization'
s details and
coverage.
5. Identify
any gaps or
areas of
underinsuran
ce that need
to be
addressed
(based on
the value
insured vs
actual value
of the asset).
6. Verify that
insurance
premiums are
accurate.
7. For any
damages/los
s verify that
claims are
reported
promptly, and
that
supporting
documentatio
n is provided.
Treasury Forex Hedging I - Treasury 1.Understand Review of 100% None
Manageme Manageme strategy Organizatio Head the Hedging Hedging
nt nt - may not fully n's overall Strategy: Strategies
515
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
Hedging offset the hedging Gain a , Policies
underlying strategy, thorough and
exposure, including understandin Procedur
resulting in the g of the es
ineffectivene objectives, organization'
ss. types of s overall
risks being hedging
hedged strategy,
(e.g., including the
currency, objectives,
interest types of risks
rate, being hedged
commodity), (e.g.,
and the currency,
financial interest rate,
instruments commodity),
used for and the
hedging financial
(e.g., instruments
derivatives, used for
options, hedging
forwards) is (e.g.,
clearly derivatives,
documented options,
forwards).
II -
Organizatio 2.Review
n's hedging Hedging
policies, Policies and
procedures, Procedures:
and Examine the
guidelines organization'
are s hedging
comprehens policies,
ive, well- procedures,
defined, and and
aligned with guidelines to
the ensure they
organization are
's risk comprehensi
appetite and ve, well-
strategy. defined, and
aligned with
the
organization'
s risk
appetite and
strategy.
516
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
Note:
Conducting
an audit of
forex hedging
requires
specialized
knowledge
and expertise
in risk
management,
financial
instruments,
accounting,
and
regulatory
requirements
. Engaging
professionals
with
experience in
foreign
exchange
risk
management
and auditing
can help to
ensure the
audit is
thorough and
effective.
Treasury Forex Risk of The Treasury 1. Review the Approval 100% None
Manageme Manageme entering into Treasury Head documentatio of
nt nt - an Manager n for hedging Hedging
Hedging unauthorize based on instruments transactio
d forward careful and contracts ns
contract, analysis of to ensure
leading to the market, they are
additional decides properly
financial upon the executed,
commitment best course authorized,
s to other of action for and in
parties and the compliance
resulting in Company to with
additional limit loss on accounting
foreign foreign and
exchange exchange regulatory
517
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
loss. fluctuations. standards.
The 2. Evaluate
Treasury the approval
Head process for
authorizes initiating
the Booking hedges,
Confirmatio including
n and proper
forwards a authorization
copy to the levels and
Bank. documentatio
n of
rationale.
3. Verify the
accuracy of
fair value
measurement
s and
accounting
treatment of
hedging
instruments
in
accordance
with
accounting
standards.
Treasury Forex Risk of The Chief Chief 1.Review the Review of 100% None
Manageme Manageme inadequate Financial Financial process for profitabilit
nt nt - review and Officer Officer communicati y of
Hedging analysis on verifies the ng hedge- forward
profitability Profitability related contracts
on account Workings information to
of forward against the relevant
contracts Forward stakeholders,
entered by Contracts including
the entered. senior
Company, management
leading to and the
incorrect Board of
decision Directors.
making and Assess the
resulting in clarity and
additional accuracy of
foreign disclosures
exchange related to
loss. hedges in
518
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
financial
statements.
2. Examine
the
organization'
s process for
periodically
reviewing the
effectiveness
of hedges
and making
necessary
adjustments
based on
changing
circumstance
s.
Treasury Forex Forex Treasury Treasury 1. Examine Reporting 100% None
Manageme Manageme transactions managers Head the process of Foreign
nt nt - MIS and regularly for Currency
Reporting positions reports on communicati Transacti
reported to its Forex ng foreign ons
managemen risk currency-
t may not be managemen related
accurate t activities information to
both within relevant
and outside stakeholders,
of the including
Treasury senior
managers management
organization and the
. On a Board of
monthly Directors.
basis, 2. Assess the
Treasury clarity and
prepares accuracy of
and disclosures
circulates a related to
report that foreign
includes currency
details on transactions
underlying in financial
exposure statements.
data by For the audit
currency period, obtain
and the MIS
exposure reporting on
519
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
type; net Forex
exposure Transactions.
position;
hedge
coverage
levels vs
targets and
forecast
accuracy/va
riance
analysis.
The report
shall further
be validated
and used
for forex
accounting
and
disclosures.
Treasury Forex Forex The Treasury 1. For the Reinstate 100% None
Manageme Manageme reinstateme accounting Head transaction ment of
nt nt - nt may not treatment of during the forex
Reinstate be as per Forex audit period, currency
ment Accounting Reinstatem verify the liability
Standards ent should accurate
be done in valuation of
compliance foreign
with Ind AS currency
21. transactions
in
accordance
with
applicable
accounting
standards.
2. Review the
accounting
treatment for
foreign
currency
gains or
losses and
confirm
compliance
with reporting
requirements
.
520
Treasury Management
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
Treasury Forex Mechanisms Compliance Treasury Gain Complian 100% None
Manageme Manageme to ensure areas Head understandin ce to
nt nt - compliance related to g of the Forex
Complianc may not be foreign applicable related
e robust. currency forex regulation
transactions compliance s
are adhered requirement
to for the entity.
supported Ensure that
with all the
adequate applicable
documentati compliances
on. are adhered.
Examples of
common
compliance
consideratio
ns related
to foreign
currency:
FEMA, Anti-
Money
Laundering
(AML) and
Know Your
Customer
(KYC),
Taxation
and
Withholding,
Customs
and Trade
Compliance
, Transfer
Pricing,
Intellectual
Property
and
Royalties,
Data
Privacy and
Cross-
Border Data
Transfer,
Export
Controls
and
521
Internal Audit Checklist
Final Sub- Risk Control Control Test Attribute Sample Data analytics
process Description Owner Performed s tested size performed
Sanctions
etc.
Note: These
requirement
s may vary
based on
the
jurisdiction,
industry,
and specific
circumstanc
es of the
organization
.
522
Checklist 26
Borrowings
Final Sub- Risk Control Control Test Attributes Sample Data
process Description Owner Performed tested size analytics
performed
Borrowin Initializatio NA NA NA 1. Obtain the Overview NA 1. Analyse
gs n Standard and borrowings
Operating Understandi to detect
Procedures ng of anomalies,
relating to Borrowings unusual
borrowings. patterns, or
From the Trial unauthorized
Balance and activities.
the relevant 2. Identify
GLS, identify outliers or
the list of discrepancie
borrowing s that may
(Opening warrant
balances, new further
borrowings investigation
etc.) .
Understand 3. Develop
the nature of Key
the Performance
borrowings, Indicators
such as the (KPIs) to
purpose, type measure
(term loans, treasury
revolving performance
credit, bonds, , such as
etc.), and cash
terms and conversion
conditions cycle, return
(interest rates, on
maturity dates, investments,
repayment or debt
schedules, ratios, etc..
etc.). 4. Monitor
KPIs over
time to
Internal Audit Checklist
524
Borrowings
525
Internal Audit Checklist
526
Borrowings
527
Internal Audit Checklist
528
Borrowings
529
Internal Audit Checklist
530
Checklist 27
Direct and Indirect Taxation & GST
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
Direct Related Payment to Defined 1. Check 1. All related 1. Payment Whether the unit
Taxation Party related process for the Approvals parties to Related has incurred any
Transaction party may approval of approval for Party vis-à- expenditure to a
not be at related party for evaluations, vis non- person specified
arm’s length payment payment to 2. related party in Clause (b) of
price that includes related Supporting 2. Excess Section 40A(2) of
the party and for payment Income Tax Act,
following: supporting evaluations without any 1961. Verify
- technical documents special whether they are
and thereof. qualification, reasonable and
commercial 2. Check achievement not excessive
evaluation approval or having regard to
by cross for experience. fair market value
functional commercial of such goods/
teams evaluation services/
- approving and facilities.
authority, supporting
- justification documents
for thereof.
transaction 3. Check
with single justification
party such for
as special exceptions,
qualification, if any,
achievement approval
or from the
experience. Board /
< Members,
as required
by
regulations
including
Companies
Act 2013
and SEBI.
Direct Cash Payment to Payment in 1. Check 1. All the Data Whether the unit
Taxation Payment vendors in cash shall the Cash Approvals cash Analytics to has made any
cash be Ledger for for cash payments be done on cash payments
prohibited or payments payment all expenses against expenses
minimized made including above Rs. 10,000
2. Check cash book (or Rs. 35,000 for
Internal Audit Checklist
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
that cash to ensure goods carriages)
payment is compliance. in contravention
authorised Data of Section 40A
3. Verify analysis (3)/ 3A of Income
cash needs to be Tax Act, 1961,
payment is done to i.e., payment
not ensure the otherwise than
exceeding payments through account
the limits are not split payee cheque or
in a manner account payee
that this can bank draft
contravene
the
provisions.
Direct Payment Payment There shall 1. Check 1. All such Check the Whether the unit
Taxation within due may not be be system the due Supporting payments 'Due Date of has certain
dates made within for payment dates for documents payment' vs. payables in the
due dates in timely various 2. 'actual date form of tax, duty,
manner payments Approvals of payment'. cess or fees,
2. Check employer
whether contribution to
the provident fund
payment is and other funds,
made bonus, interest or
within the loan and
due date. borrowings from
banks and public
financial
institutions, etc.
Verify whether
such payments
have actually
been made on or
before the due
date of filing of
Income Tax
Return otherwise
the same will be
disallowed under
Section 43B of
Income Tax Act,
1961.
Direct Repayment Payment Such 1. Check 1. All such Data Whether the unit
Taxation of loans/ may be payment the cash Approvals payments Analytics to has repaid loans/
advances/ made in shall not be Ledger for for cash be done on advances/
532
Direct and Indirect Taxation & GST
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
deposits cash made in payments payment all expenses deposits in cash
cash made including of Rs. 20,000 and
2. Check cash book above in
that cash to ensure contravention of
payment is compliance. Section 269T of
authorised Data Income Tax Act,
3. Verify analysis 1961.
cash needs to be
payment is done to
not ensure the
exceeding payments
the limits. are not split
in a manner
that this can
contravene
the
provisions.
Direct Receipt of Receipt may Such receipt 1. Check 1. All such Data Whether the unit
Taxation loans/ be taken in shall not be the cash Approvals receipt Analytics to has received
advances/ cash accepted in Ledger for for cash be done on loans/ advances/
deposits cash payments receipt all expenses deposits in cash
received. including of Rs. 20,000 and
2. Check cash book above in
that cash to ensure contravention of
receipt is the Section 269SS of
authorised. compliance. Income Tax Act,
3. Verify Data 1961.
cash analytics to
receipt is be done to
not ensure the
exceeding payments
the limits. are not split
in a manner
that this can
contravene
the
provisions.
Direct Furnishing PAN may Take the Check the PAN card 30 Verify whether
Taxation of PAN by not be given self-attested PAN of copy of the vendor's the compliance of
vendors or may be copy of PAN vendor in vendors PAN Section 206AA of
incorrect. card the system Income Tax Act,
with the 1961 has been
copy of made with
PAN Card. regards to
furnishing of
533
Internal Audit Checklist
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
PAN.
Direct TDS related TDS related Timely 1. Check 1. Any 4 To analyse Verify the
Taxation matters non compliance that TDS is Supporting months all the compliance of
compliances deducted documents expense issues relating to
as per 2. accounts / TDS on salary,
appropriate Approvals payments rent, commission,
rates data to interest, payment
2. Check ensure TDS to contractor,
that provisions payment of fees
payment of have been to professional/
TDS is correctly technical person,
paid on applied. sales of goods
time 3. etc. and observe
Check TDS the following:
return is o Deduction of
submitted TDS at correct
on time. rate.
4. Check o Deduction and
TDS Deposit of TDS
certificates within time.
issued to o Filing of TDS
the return in time and
vendors on as per procedure
time. prescribed.
o Issue of TDS
certificate.
o Receipt of Form
15G/ 15H and
entry in system.
o Filing of Form
15G/ 15H with
Income Tax
Department as
per Rule 29C of
Income Tax
Rules, 1962.
Direct TCS related TCS related Timely 1. Check 1. Any 4 To analyse Verify whether
Taxation matters non- compliance that TCS is Supporting months receipt Tax Collected at
compliance collected documents accounts / Source (TCS) at
as per 2. data to the prescribed
appropriate Approvals ensure TCS rates on sale
rates provisions consideration of
2. Check have been Alcoholic Liquor,
that correctly Tendu leaves,
payment of applied. Timber, forest
534
Direct and Indirect Taxation & GST
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
TCS is produce, scrap,
paid on minerals, parking
time 3. lot, toll plaza,
Check TCS mining and
return is quarrying, motor
submitted car, foreign
on time. currency,
4. Check overseas tour
TCS package, goods
certificates are collected as
issued to per section 206C
the and observe the
vendors on following:
time. o Collection of
TCS at correct
rate.
o Collection and
Deposit of TCS
within time.
o Filing of TCS
return in time and
as per procedure
prescribed.
o Issue of TCS
certificate.
Indirect Registration Registration Proper Check Registration All (1) Whether the
Taxation related non- Compliance registration Certificates certificates entity has
compliance compliance registration
as per law certificates for the
principal place
and separate
registrations for
all other places.
Ensure that
simultaneous
registration under
CGST/ SGST/
IGST is taken in
the same state
and places of
business in other
states. PAN
based registration
is compulsory
except for non-
residents.
535
Internal Audit Checklist
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
(2) Whether the
details of
business are
correctly and
completely
mentioned/
declared in the
Registration
Certificate.
(3) Whether the
principal place of
business has
been correctly
declared in the
Registration
Certificate and all
places of
business in other
states in the
respective
Registration
Certificates.
(4) Whether all
the products,
traded/
manufactured
have been
declared in the
Registration
certificates
Indirect Issue of Issue of Proper issue Check PO, 50 (1) Ensure that
Taxation Invoice invoice not of Invoice process of Invoices invoices time of supply of
as per law issue of and goods shall be
invoice agreements earlier of: - Date
of issue of invoice
by the supplier
- due date for
issue of invoice
by the supplier, -
date on which
payment to be
entered in books
of supplier and
date on which
payment is
credited in the
536
Direct and Indirect Taxation & GST
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
bank account of
supplier.
(2) Whether
invoice or bill is
not issued
without supply of
goods and/ or
services.
(3) Whether
invoice or bill is
not issued
without supply of
goods and/ or
services.
(4) Whether
taxable goods are
transported with
the E Way Bill
along with
invoice/delivery
challan, etc.
(5) Whether
invoice is raised
under E Invoicing
system if turnover
in a year exceeds
5 crores.
(6) Whether
Letter of
Undertaking is
filed for export
without payment
of duty.
(7) Whether
original invoice is
available in case
of cancelled
invoice
(8) Whether
receipt voucher is
issued to the
customers in
case of advance
received against
services and GST
is paid on the
same.
537
Internal Audit Checklist
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
(9) Whether
payment voucher
is issued to the
vendors in case
of services or
goods covered
under RCM.
(10) CGST &
SGST or IGST is
charged as per
the Place of
Supply Provisions
on the invoice.
(11) Whether
invoice has been
signed by the
authorised
person.
Indirect GST Filing of Proper filing Check GST All returns (1) Whether all
Taxation Returns incorrect of GST GST Returns Monthly Returns/
GST returns Returns Returns Quarterly/ Annual
Return have been
filed with all
Annexure within
the prescribed
time or within the
extended period
as per Form
GSTR-1 to Form
GSTR-11 as
prescribed under
Return Rules
(Proposed). Tally
it with both the
monthly
payments and as
well as the ledger
entries of the
relevant dates.
(2) Review the
return and check
whether the
return is accurate
as to input credit,
output tax
payable,
538
Direct and Indirect Taxation & GST
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
valuation of
goods and carry
forward of credit,
etc.
(3) whether the
returns filed are
complete and
accurate in all
respect and has
been validated by
other person.
Indirect Valuation Incorrect GST is Check Invoices 50 to check (1) Whether GST
Taxation and Rates rate of GST charged on Invoices to invoices system level (Goods and
or valuation correct ensure controls on Service Tax) has
value and correct using the been charged on
as per rates and rates and sale of goods
proper rates valuation modification. traded/
manufactured at
correct rates.
(2) Whether GST
has been charged
on sale of waste
product/
discarded
product/ assets at
correct rates.
(3) Whether GST
has been charged
on sale of fixed
assets at correct
rates.
(4) If the rates
applied are
different, take a
copy of the
authority/
notification under
which such
change is
approved. For
example:
Composition
Scheme, GST
Notifications, etc.
(5) Log of
changes in the
539
Internal Audit Checklist
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
system relating to
rates, application,
etc.
Indirect Books of Records as Proper Check the Books of (1) Whether all
Taxation accounts per GST law records are books of Accounts the records and
may not be maintained accounts Books of
maintained. Accounts,
required to be
maintained, are
available at the
location.
(2) Whether
books of account
and other
documents are
kept, maintained
and retained in
accordance with
the provisions of
this Act
Indirect Input Tax Avail and Only eligible Check ITC Invoices 10-50 (1) Whether the
Taxation Credit (ITC) utilize in ITC is taken invoices invoices unit has
eligible ITC with proper p.m. purchased goods
documents. only from the
registered dealer.
GST registration
number should be
there on invoices
and Tax Invoices
must be in
prescribed format
as per the Invoice
Rules.
(2) Whether full
credit of GST is
availed till date,
that is input credit
of GST for all the
purchases is
available in the
electronic credit
ledger.
(3) Whether GST
credit is correctly
carried forward
540
Direct and Indirect Taxation & GST
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
from previous
month to next
month in every
Monthly Return
as well as Annual
Return.
(4) Whether ITC
is correctly
claimed on input
and capital
purchases
eligible for
claiming input
credit, i.e.,
whether the input
tax carried is in
books only based
on proper Tax
Invoice from the
vendor with GST
Number and all
other relevant
details mentioned
on the invoice.
(5) Whether Input
tax credit taken
and/ or utilized is
against actual
receipt of goods
and/ or services
(6) Whether ITC
is reversed on
goods distributed
as free samples /
gifts / goods lost /
stolen / destroyed
/ written-off /
donations made
etc
(7) ITC is availed
as per conditions
mentioned in
Section 16 of the
CGST Act and
rules thereof.
Also, the same
shall be cross-
541
Internal Audit Checklist
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
checked with
GSTR-2B &
GSTR-2A.
(8) Blocked ITC
as per Section 17
(5) of the CGST
Act, 2017 shall
not be availed.to
check system
level controls on
maintaining
vendor master,
system level
controls in
ensuring
programing on
whether input
credit can be
taken or not etc.,
should also be
checked.
Indirect Payment Payment of Payment of Check Challan All (1) Whether the
Taxation within due GST not on GST on time Challans challans unit has
dates time reconciled the
variance between
GST payable as
shown in books of
accounts and the
amount paid.
Variances should
be documented
and corrective
action to be
taken.
(2) Whether the
unit maintains
acknowledged
Tax challan and
deposit of CGST,
SGST and IGST
is made under the
correct head of
account.
(3) Whether the
unit deposits GST
(CGST/ SGST/
542
Direct and Indirect Taxation & GST
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
IGST) dues within
due dates under
properly filled
challan/ Bank
Transfer with
proper
acknowledgement
and check that
the amount
appears on
Electronic Credit
Ledger.
(4) Ensure GST
payment would
become due,
earliest of
conditions
mentioned:
(i) receipt of
advance
(ii) issuance of
invoice
(iii) completion of
supply.
(5) Ensure that
CGST/ SGST/
IGST payment is
paid by 20 th of
the succeeding
month on monthly
basis for
taxpayers and on
quarterly basis for
composition tax
payer.
(6) Whether
amount collected
as tax
erroneously in
contravention to
the provisions of
this Act is due to
the credit of the
appropriate
Government,
(7) Whether the
543
Internal Audit Checklist
Process Sub- Risk Control Test Attributes Sample Data Process Metrics
process Description Performed tested size analytics
performed
compliance of tax
to be paid under
reverse charge
mechanism is
done,
544
Checklist 28
Corporate Social Responsibility
Process Sub-process Risk Control Test Performed Attributes Sample Data
Description tested size analytics
performed
CSR CSR Committee Non- CSR committee 1. Ensure that 1. Minutes of 100% NA
compliance is constituted as constitution of CSR
with per Companies CSR Committee Committee
provisions of Act as per Meeting.
Companies Companies Act, 2. Approval on
Act, 2013 2023. CSR Policy of
2. All the Company.
policies and 3. Approval on
projects projects
undertaken are undertaken.
passed through 4. CFO
CSR Certificate for
Committee. CSR.
3. Check that
Certificate
issued by CFO
relating to CSR
Expenditure for
the year.
546
Corporate Social Responsibility
547
Internal Audit Checklist
548
Corporate Social Responsibility
CSR Accounting Tax CSR accounting 1. Ensure that Income Tax 100% NA
Implications is done by Expenses under Computation
of CSR persons having donation are not and Financials
Expenditure adequate claimed as CSR
which can knowledge and Expenditure.
affect same is 2. Ensure that
549
Internal Audit Checklist
550
Checklist 29
Human Resources – Hire to Retire
Process Sub-process Risk Control Test Attributes Sample Data
Description Performed tested size analytics
performed
Hiring Staff Planning Risk of not The Company Whether the Planning 100%
planning the should plan for Company has
need for staff the resource planned for the
or staff requirements at resource
movement, the beginning of requirements
which later the year and have in consultation
could be a a strategy with HR and
bottleneck in accordingly. relevant
the operations. operations
Risk of hiring a team.
greater
number of
resources than
required or not
hiring
adequate
resources.
Hiring Staff Planning Risk of HR Head should Review of how Creating new 100%
creating approve any the new job positions.
positions or position or positions is
designations designations as created or
which are not per organisation amended.
approved. hierarchy and
also the job
descriptions.
Where new
positions are
created to ensure
the organisation
hierarchy and job
description is
amended or
incorporated, as
the case may be,
it should be duly
approved.
Hiring Communication Risk of not The HR Head Whether there Communication 100%
on Need of communication should have a is a strategy in
Internal Audit Checklist
552
Human Resources – Hire to Retire
553
Internal Audit Checklist
554
Human Resources – Hire to Retire
555
Internal Audit Checklist
556
Checklist 30
Human Resources – Payroll Management
Process Sub-process Risk Control Test Attributes Sample Data
Description Performed tested size analytics
performed
Payroll Attendance Risk of The presence Review of Attendance Sample
Calculation recording remunerating of an the basis
an employee employee in attendance depending
without the office system and on the
ensuring should be also review number of
attendance to monitored whether the employees,
work. through an software / industry
attendance hardware etc.,
management systems are
system either working as
bio-metric or specified or
face desired.
recognition or
manual
signature
record, as
required by
law /
company's
policy. Any
late comings
to the Office
should be
explained by
the employee
and the Head
of the
Department /
Manager
should
approve the
same. If there
are
continuous
late comings,
there has to
be a policy on
the action to
be taken i.e.,
fixed amount
to be
deducted
Internal Audit Checklist
558
Human Resources – Payroll Management
2. Analytical
procedure of
Head Count
to be done to
ensure that
the difference
between last
month's
payroll and
current
month's
payroll is
explained.
Payroll Payroll Risk of Company Review of Operating 100%
Calculation disbursement payroll being should the payroll effectiveness
disbursed to ensure that processing of payroll.
the wrong all the payroll including the Processing
person. Risk disbursement process of
of Fraud of is through transfer of
disbursing banking files between
payroll to a channels departments
wrong bank only. The and ensuring
account. payroll maker-
statement checker
prepared by concept is
the payroll effective.
department
should be
reviewed by
the Accounts
department
and then
send a list
containing list
of employees
and payment
559
Internal Audit Checklist
560
Human Resources – Payroll Management
561
Checklist 31
Foreign Currency Transactions
Process Sub-process Risk Description Control Test Performed Attributes tested
Foreign Currency Transaction Risk Cost effective The method of Check whether FCT Contracts and
Transactions method is not used payment of import payment is made Policy
for payment of duty is selected in accordance with
duty. after due diligence guidelines
so that the risk prescribed by the
may be mitigated Company. If not,
Ineffective foreign
and can implement then check the
currency risk
hedging strategies. payment mode in
management
Eligibility for sample contracts
system.
Merchandise and compare the
Exports from India cost of undertaking
Scheme (MEIS) Foreign Currency
can be explored. Transaction.
563