Section 143(3)(i) of the Companies Act, 2013 requires the statutory auditor to state whether the company has adequate internal financial controls with reference to financial statements, and whether those controls were operating effectively during the year.

In practice, this is frequently treated as an afterthought to the main audit. It shouldn't be — the underlying work is substantial, and for a first-time IFC evaluation, it can take as long as the financial statement audit itself.

What's actually being evaluated

IFC reporting isn't a review of whether policies exist on paper. It requires the auditor to test, cycle by cycle, whether the controls that are supposed to prevent or detect a material misstatement are actually designed correctly, and whether they operated consistently through the year. That typically covers:

  • Order-to-cash — customer onboarding, credit approval, invoicing accuracy
  • Procure-to-pay — vendor approval, purchase authorisation, three-way matching
  • Inventory and fixed assets — physical verification, valuation, capitalisation approval
  • Payroll and treasury — access controls, approval hierarchies, bank reconciliation
  • Financial close — journal entry approval, account reconciliation, consolidation adjustments
  • IT general controls — system access, change management, backup and recovery

Design effectiveness vs. operating effectiveness

These are two separate questions, and conflating them is the most common misunderstanding we see. A control can be well-designed on paper — the right approval sits with the right person — and still fail in practice if that approval isn't consistently obtained. Testing operating effectiveness means sampling actual transactions through the year, not just reviewing the policy document once.

Why this matters for subsidiaries of overseas parents

For an Indian subsidiary reporting into a foreign parent, IFC findings often get more scrutiny from the parent's audit committee than the standalone Indian financial statements do — particularly where the parent is itself subject to group-level control requirements. A well-evidenced IFC process, with documented Risk & Control Matrices rather than reconstructed explanations after the fact, tends to move through group review faster.

This note is general commentary on IFC/ICFR reporting requirements and does not constitute advice on any specific company's control environment or reporting position.