Internal audit plays an important role in corporate governance, risk management and internal control. However, one of the most common questions for directors, CFOs and growing businesses is whether an internal audit is legally mandatory for their company or simply a good governance practice.

Internal audit applicability in India is primarily determined by Section 138 of the Companies Act, 2013 read with Rule 13 of the Companies (Accounts) Rules, 2014. The requirements differ for listed companies, unlisted public companies and private companies, with specific thresholds based on paid-up share capital, turnover, borrowings and deposits.

Understanding these thresholds correctly is important because applicability is not determined by company size alone. A business may have relatively modest turnover but still become subject to internal audit requirements because its borrowings exceed the prescribed limit.

What Is Internal Audit Applicability Under the Companies Act?

Internal audit applicability determines whether a company is legally required to appoint an internal auditor under Section 138 of the Companies Act, 2013 and Rule 13 of the Companies (Accounts) Rules, 2014. Listed companies are covered automatically, while specified financial thresholds apply to unlisted public and private companies.

Section 138 does not require every company incorporated in India to appoint an internal auditor. Instead, it authorises the government to prescribe the classes of companies for which internal audit becomes mandatory.

Rule 13 defines those classes and the applicable thresholds.

Which Companies Are Required to Appoint an Internal Auditor?

The current statutory framework can be summarised as follows:

Type of companyInternal audit applicability
Listed companyEvery listed company
Unlisted public companyAny one of four prescribed thresholds is met
Private companyEither of two prescribed thresholds is met

The detailed thresholds are particularly important because meeting any one applicable criterion can trigger the requirement.

Internal Audit Applicability for Listed Companies

Every listed company is required to appoint an internal auditor.

There is no separate minimum turnover, paid-up capital, borrowing or deposit threshold for this category under Rule 13.

Therefore, once a company falls within the applicable listed-company category, internal audit should form part of its governance framework regardless of whether it is significantly smaller than another unlisted enterprise.

For listed companies, internal audit also supports broader expectations around governance, risk oversight, financial controls, regulatory compliance and Audit Committee supervision.

Internal Audit Applicability for Unlisted Public Companies

An unlisted public company must appoint an internal auditor if it satisfies any one of the prescribed criteria during the preceding financial year.

The thresholds are:

CriterionThreshold
Paid-up share capital₹50 crore or more
Turnover₹200 crore or more
Outstanding loans or borrowings from banks or public financial institutionsMore than ₹100 crore at any point during the preceding financial year
Outstanding deposits₹25 crore or more at any point during the preceding financial year

These tests operate independently. An unlisted public company does not need to cross all four thresholds. Crossing one applicable threshold is sufficient.

Example

Consider an unlisted public company with:

  • Paid-up capital: ₹30 crore
  • Turnover: ₹160 crore
  • Maximum bank borrowings during the year: ₹115 crore
  • Deposits: Nil

The company does not cross the capital or turnover thresholds. However, because its outstanding bank or public financial institution borrowings exceeded ₹100 crore at some point during the preceding financial year, internal audit becomes applicable.

This is why reviewing only year-end financial statements may not always be sufficient.

Internal Audit Applicability for Private Companies

Private companies are subject to fewer statutory thresholds under Rule 13.

A private company is required to appoint an internal auditor when it has:

  • Turnover of ₹200 crore or more during the preceding financial year; or
  • Outstanding loans or borrowings from banks or public financial institutions exceeding ₹100 crore at any point during the preceding financial year.

Unlike the test for unlisted public companies, Rule 13 does not separately prescribe paid-up share capital or deposit thresholds for private companies.

Example

Suppose a private company reports:

  • Turnover: ₹175 crore
  • Year-end bank borrowings: ₹92 crore
  • Highest outstanding bank borrowings during the year: ₹108 crore

The company may still fall within the internal audit requirement because the borrowing test looks at whether the applicable threshold was crossed at any point during the preceding financial year, not merely at the year-end balance.

This distinction is particularly relevant for businesses using seasonal working-capital facilities.

Quick Internal Audit Applicability Checklist

A company should review the following questions after each financial year:

Is the company listed?

If yes, internal audit is required under Rule 13.

Is it an unlisted public company?

Check whether any of these conditions were met:

  • Paid-up share capital of ₹50 crore or more
  • Turnover of ₹200 crore or more
  • Bank or public financial institution borrowings above ₹100 crore at any point
  • Outstanding deposits of ₹25 crore or more at any point

Is it a private company?

Check whether:

  • Turnover reached ₹200 crore or more; or
  • Bank or public financial institution borrowings exceeded ₹100 crore at any point

If none of the relevant thresholds apply, Section 138 may not mandate internal audit under Rule 13. However, the company may still choose to establish an internal audit function voluntarily.

Which Financial Year Should Be Used for Testing Applicability?

Rule 13 refers to the preceding financial year when prescribing the relevant financial thresholds.

This means management should assess applicability using the prescribed financial information from the previous financial year rather than waiting until problems emerge during the current audit cycle.

Particular attention should be paid to borrowings and deposits because the relevant rules use an “at any point of time” test.

Businesses should therefore maintain records capable of showing peak borrowing and deposit balances rather than relying solely on closing balances.

Who Can Be Appointed as an Internal Auditor?

Section 138 permits the internal auditor to be:

  • A Chartered Accountant
  • A Cost Accountant
  • Another professional considered appropriate by the Board

The Rules also provide flexibility regarding the structure of the appointment. The internal auditor may be an individual, partnership firm or body corporate, and the internal auditor may or may not be an employee of the company.

This allows companies to choose between:

  • An in-house internal audit function
  • A completely outsourced internal audit model
  • A co-sourced arrangement combining internal employees with external specialists

The appropriate model depends on business complexity, independence requirements, specialist expertise, geographic scale and the maturity of the organisation’s risk-management framework.

Can the Statutory Auditor Also Perform the Internal Audit?

Companies must carefully maintain independence between statutory audit and internal audit.

Section 144 of the Companies Act restricts an auditor appointed under the Act from providing certain prohibited non-audit services, and internal audit is specifically included among those prohibited services.

Therefore, organisations should not assume that the statutory audit firm can simply undertake the internal audit engagement as an additional service.

This separation is important because the two functions serve different purposes.

Statutory Audit

The statutory auditor provides an independent opinion on the financial statements in accordance with the applicable legal and auditing framework.

Internal Audit

Internal audit evaluates processes, controls, risks, governance and operational effectiveness across the organisation.

Maintaining appropriate independence strengthens the credibility of both functions.

Who Determines the Scope of Internal Audit?

Internal audit should not operate from a generic checklist that remains unchanged every year.

Under Rule 13, the Audit Committee or the Board, in consultation with the internal auditor, formulates the:

  • Scope
  • Functioning
  • Periodicity
  • Methodology

of the internal audit.

This is significant because the law does not prescribe one identical audit programme for every company.

The scope should reflect the organisation’s actual risk profile.

What Should an Effective Internal Audit Cover?

Depending on the business, a risk-based internal audit programme may cover:

Finance and Accounting Controls

  • General ledger controls
  • Journal entries
  • Reconciliations
  • Accounts payable
  • Accounts receivable
  • Expense management
  • Financial close

Procure-to-Pay

  • Vendor onboarding
  • Purchase approvals
  • Purchase orders
  • Invoice matching
  • Duplicate payments
  • Payment authorisation

Revenue and Receivables

  • Customer onboarding
  • Pricing controls
  • Billing
  • Credit management
  • Collections
  • Cash application

Payroll and HR

  • Employee master changes
  • Attendance
  • Payroll processing
  • Incentives
  • Reimbursements
  • Access rights

IT and Cybersecurity

  • User-access management
  • Privileged access
  • Change management
  • Data security
  • Backup controls
  • Incident management

Regulatory and Compliance Controls

  • Statutory obligations
  • Policy compliance
  • Documentation
  • Third-party risk
  • Compliance monitoring
  • Evidence retention

The audit universe should evolve when the business introduces new systems, enters new markets, acquires companies or experiences significant operational changes.

Is Internal Audit Useful Even When It Is Not Mandatory?

Yes.

A company that does not cross the statutory thresholds may still benefit significantly from a voluntary internal audit programme.

Growing businesses often develop control gaps before they become legally large enough to require a formal internal audit function.

For example, a rapidly expanding private company may experience:

  • Increasing transaction volumes
  • Multiple locations
  • Larger vendor networks
  • Employee growth
  • ERP implementation
  • Cybersecurity exposure
  • Complex approval structures
  • Higher inventory
  • Increasing regulatory obligations

Waiting for the statutory threshold before reviewing these risks may allow weaknesses to become embedded in operations.

Voluntary internal audit can therefore support governance even when internal audit applicability under Section 138 has not yet been triggered.

Internal Audit Is More Than Financial Checking

One common misconception is that internal audit exists primarily to recheck accounting entries.

Modern internal audit is much broader.

An effective internal audit function should evaluate whether:

  • Controls are appropriately designed
  • Policies are actually followed
  • Risks are identified early
  • Transactions receive proper approval
  • Systems restrict unauthorised activity
  • Regulatory requirements are operationalised
  • Management receives reliable information
  • Corrective actions are completed

This makes internal audit an important component of enterprise governance rather than simply another accounting activity.

From Periodic Internal Audit to Continuous Control Monitoring

Traditional internal audits often test samples at scheduled intervals. This remains valuable, but technology now allows companies to analyse much larger transaction populations and identify control exceptions earlier.

Examples include automated monitoring for:

  • Duplicate payments
  • Unusual journal entries
  • Vendor bank-detail changes
  • Segregation-of-duties conflicts
  • Approval-limit breaches
  • Suspicious transactions
  • Policy exceptions

Organisations looking to strengthen this area can explore MindBridge’s management review and control assurance services, which include risk assessment, control testing, anomaly detection, continuous monitoring and reporting.

Where internal audit findings involve statutory requirements, policy gaps or regulatory exposure, MindBridge’s AI-powered compliance services can support a broader governance and compliance framework.

Common Internal Audit Applicability Mistakes

Enterprises should avoid several recurring errors.

Checking Only Turnover

Turnover is only one applicability criterion. Borrowings, capital and deposits may independently trigger the requirement depending on company type.

Using Only the Closing Borrowing Balance

For the relevant borrowing test, the rule looks at whether the threshold was crossed at any point during the preceding financial year.

Applying Public-Company Thresholds to Private Companies

The statutory criteria are not identical. Private companies have a different set of tests under Rule 13.

Assuming Internal Audit Must Be Performed Only by a Practising CA

The statutory framework provides broader flexibility regarding who may act as internal auditor, subject to the Board’s decision and applicable professional requirements.

Combining Statutory and Internal Audit Without Checking Independence

Section 144 specifically restricts statutory auditors from rendering internal audit services to the audit client in the circumstances covered by the provision.

Treating Internal Audit as an Annual Compliance Formality

A weak internal audit programme may technically produce reports without materially improving governance.

The scope should be risk-based, findings should have owners and deadlines, and unresolved issues should be escalated.

How MindBridge Supports Internal Audit and Control Review

MindBridge helps organisations strengthen internal controls through risk assessment, control testing, process monitoring, exception analysis, fraud and irregularity detection, data analytics and management reporting.

Its management review and control assurance services are designed to help organisations move beyond isolated control checks towards structured, risk-focused monitoring.

For growing businesses, this approach can help management identify process weaknesses, improve audit readiness and establish clearer visibility over control effectiveness.

The objective is not simply to complete an internal audit. It is to create a governance process in which material risks are identified, findings are prioritised and remediation is monitored.

Frequently Asked Questions

What is internal audit applicability in India?

Internal audit applicability refers to whether a company must appoint an internal auditor under Section 138 of the Companies Act, 2013 and Rule 13 of the Companies (Accounts) Rules, 2014. Applicability depends on whether the company is listed, an unlisted public company or a private company and whether prescribed financial thresholds are met.

Is internal audit mandatory for every private limited company?

No. A private company is generally covered by Rule 13 when turnover is ₹200 crore or more during the preceding financial year or qualifying bank or public financial institution borrowings exceed ₹100 crore at any point during that year.

Is internal audit mandatory for every public company?

Every listed company is covered. An unlisted public company becomes subject to the requirement when any applicable threshold relating to paid-up capital, turnover, qualifying borrowings or deposits is met. Therefore, being an unlisted public company alone does not automatically trigger Rule 13.

Can an internal auditor be an employee of the company?

Yes. Rule 13 expressly provides that the internal auditor may or may not be an employee of the company. Companies can therefore establish an in-house function or use an external or co-sourced model depending on their governance and resource requirements.

Can a company conduct internal audits voluntarily?

Yes. Companies that do not fall within the mandatory thresholds can still establish an internal audit function voluntarily. This is often useful for growing organisations that want stronger controls, fraud prevention, regulatory readiness and better risk visibility before statutory applicability is triggered.

Conclusion

Understanding internal audit applicability requires more than checking annual turnover.

Listed companies are covered automatically, while unlisted public and private companies must assess the specific thresholds prescribed under Rule 13. Particular attention should be paid to peak borrowings and deposits because certain thresholds apply when balances are reached at any point during the preceding financial year.

Management should also look beyond basic legal compliance. An effective internal audit function can identify process weaknesses, test controls, detect irregularities and provide the Board with better visibility over business risk.

Companies approaching the statutory thresholds should review applicability before the start of the next audit cycle and establish an appropriate scope, internal-audit model and governance process.

This article provides general information and should not be treated as legal or professional advice. Companies should assess their individual circumstances and current statutory requirements before making compliance decisions.

Follow MindBridge