The scope for internal audit is the written boundary of an engagement: which processes, entities, locations and time periods are examined, how deep testing goes, and what stays out.Â
Under Rule 13(2) of the Companies (Accounts) Rules, 2014, the Audit Committee, or the Board where no committee exists, decides the scope in consultation with the internal auditor. A scope that holds up under scrutiny begins with what the business wants to achieve. It is then shaped by risk ratings, legal obligations, materiality thresholds and earlier audit observations, and it is finalised only when the Audit Committee signs off on a written statement.Â
CFOs, Internal Audit Heads and Audit Committees will find here a step-by-step method for setting scope, along with a scoring model and current 2026 risk data.Â
Key Takeaways On The Scope for Internal Audit
- Start by listing all the units that could be audited, and only then draw the boundary of the engagement. ICAI’s exposure draft of SIA 220 proposes this sequenceÂ
- Score every auditable unit on risk, materiality, regulation, change, and prior findings.
- Record what you exclude and why. Exclusions are part of the scope.
- Re-open scope when risks move, not only at year-end.
What Is the Scope for Internal Audit, and What Does It Include?
Scope tells the auditor which areas to examine and how thoroughly to examine them.Â
Element | What it answers | Example |
Objectives | Why are we auditing this? | Confirm vendor payments follow approved limits |
Scope | What is in and out? | Procure-to-pay, three plants, April–September 2026 |
Depth | How much testing? | 100% of payments above ₹10 lakh; sample the rest |
Plan | When and with whom? | Q3, two auditors, 15 working days |
Internal Audit Scope and Objectives: Why They Must Match
Scope and objectives need to be developed together, since each depends on the other. Weak audit objectives produce a vague scope, and a vague scope produces findings nobody can act on. Write the objective first, then size the scope to prove or disprove it.
Who Decides the Scope for Internal Audit in India?
In India, the Audit Committee, or the Board where no committee exists, formulates the scope of internal audit in consultation with the internal auditor under Rule 13(2) of the Companies (Accounts) Rules, 2014. The internal audit head drafts the plan, and management supplies context but should not restrict coverage without disclosure.Â
Three layers share the decision:
- Audit Committee or Board: sets the scope, periodicity, and methodology of the internal audit under Rule 13(2), drawing on the internal auditor’s input.
- Internal Audit Head or engagement partner: drafts the plan and recommends scope based on risk.
- Management: supplies context and expectations but should not restrict coverage without that restriction being disclosed.
Globally, the IIA’s Global Internal Audit Standards, effective January 9, 2025, say the chief audit executive approves engagement objectives, scope and any changes, using an engagement risk assessment.
Is Internal Audit Mandatory for Your Company?Â
Under Section 138 and Rule 13, applicability depends on the preceding financial year:
Company type | Trigger (any one) |
Listed | Always applicable |
Unlisted public | Paid-up capital ≥ ₹50 crore; turnover ≥ ₹200 crore; loans from banks or PFIs > ₹100 crore; deposits ≥ ₹25 crore |
Private | Turnover ≥ ₹200 crore; or loans from banks or PFIs > ₹100 crore |
When this does not apply:Â
A private company with turnover below ₹200 crore and bank or PFI borrowings of ₹100 crore or less is not required to appoint an internal auditor under Section 138. An unlisted public company is exempt only if it is below all four thresholds above. Check each threshold against the preceding financial year’s figures. Exempt companies can still commission a voluntary review, and the scoping method in this guide works at a smaller scale.Â
If a company meets the Rule 13 criteria and does not appoint an internal auditor, it may face penalties under the Companies Act, depending on the circumstances. A general penalty provision such as Section 450 may applyÂ
What Six Inputs Decide the Scope of an Internal Audit?
Good internal audit planning blends six inputs. Skip one and the scope develops a blind spot.
1. Business Objectives and Strategy
Start with what the business is trying to achieve this year: a new plant, an acquisition, a pricing change, an ERP migration. Audit objectives should trace back to those goals.
- A company focused on growth needs closer attention on how it books revenue and manages customer credit.Â
- Cost programs raise the importance of procurement and inventory.
- Fundraising raises the importance of financial reporting controls.
2. Risk Assessment and the Audit Universe
ICAI’s exposure draft of SIA 220 proposes that an audit universe be prepared before scope is set. Then each auditable unit gets an independent risk assessment. This is risk-based internal audit in practice: coverage follows risk, not habit. For the difference between the two disciplines, see internal audit and risk assessment.Â
If you want to review the risk management process itself, our risk management audit guide explains how.Â
The same draft asks for an audit programme that lists “what could go wrong” in each unit and the control meant to prevent it. Use that list as a sense check on your scope for internal audit: if a risk has no planned test, it is outside your scope by accident.
Quick Risk Questions per Unit
- What could go wrong, and how badly?
- How likely is it, given current controls?
- Has anything changed: people, systems, volumes, vendors?
3. Regulatory and Compliance Requirements
For each unit, list the laws that touch it: the Companies Act, GST, TDS, MSME payment rules under Section 43B(h), the labour codes, and SEBI or RBI rules where the entity is regulated. A compliance audit checks whether a unit follows applicable laws as well as its own internal policies. An operational audit asks whether the work is done efficiently and delivers the results it is meant to. Decide which lens each unit needs. Our blog on the types of internal audit compares them.
4. Business Processes and the Control Environment
Walk the process end to end, then judge the control environment around it: approvals, segregation of duties, system access, management attitude. Strong controls can justify lighter testing, while weak ones justify depth. See internal controls in business operations for why paper controls and real practice drift apart.
5. Materiality
Materiality tells you which misstatements or losses matter enough to test. Set it in rupees and in qualitative terms (fraud, regulatory breach, reputational harm).
- Quantitative: a threshold tied to revenue, profit or asset base.
- Qualitative: items that matter regardless of size, such as related-party payments.
6. Previous Audit Findings
Open and repeat findings are among the most useful scope signals. Include:
- Areas with unresolved observations
- Controls that were “fixed” but never re-tested
- Units not audited for two or more cycles
Good internal audit reporting makes this input usable, because follow-up status is visible at a glance.
Compliance Audit vs Operational Audit: How the Scope Changes
The same process can be scoped two ways. State which lens you are using, because the criteria differ.
Aspect | Compliance audit | Operational audit |
Core question | Are we following the rules? | Are we running this well? |
Benchmark | Laws, contracts, approved policies | SOPs, cost and cycle-time targets |
Typical scope | Filings, approvals, licenses | Throughput, rework, waste |
Testing style | Pass or fail against criteria | Analysis, walkthroughs, root cause |
Example | GST and TDS reconciliation review | Purchase-to-pay turnaround |
Many engagements blend both. Name the mix in the scope statement so nobody argues about criteria later.
Why Risk-Based Internal Audit Beats Cycle-Based Coverage ?
Cycle-based plans audit every unit on a fixed rotation. They are easy to run but blind to shifts in risk. A risk-based internal audit sends hours where the risk score is highest and rotates low-risk units less often.
- Cycle-based: even coverage, predictable, slow to react.
- Risk-based: concentrates effort on high-risk units; the audit universe must be maintained continuously.
- Hybrid: in-depth review of high-scoring units and rotation review of others.
Hybrid works well for mid-size companies, as long as scoring is documented and updated.
The MSNA Scope Scoring Matrix (Illustrative 100-Point Model)
Here is an illustrative weighted model to start from. Calibrate the weights to your organization.
Factor | Max points | What to score |
Inherent risk | 30 | Fraud exposure, complexity, volume |
Materiality | 25 | Share of revenue, spend or assets |
Regulatory exposure | 20 | Statutory deadlines, penalty potential |
Change and complexity | 15 | New systems, people, vendors, entities |
Prior findings and audit gap | 10 | Open issues, years since last audit |
Decision rule: 70+ means deep-dive testing, 50-69 means standard review, and below 50 means monitor or exclude with documented rationale.
Calibrating these weights is where experience counts. A Chartered Accountant experienced in internal audit can help you tailor them to your organisation.
Worked Example: Hypothetical ₹350 Crore Manufacturer
This is an illustration, not client data.
Auditable unit | Inherent risk | Materiality | Regulatory | Change | Prior findings | Total | Scope decision |
Procure-to-pay | 27 | 22 | 14 | 9 | 8 | 80 | Deep dive |
IT general controls | 27 | 15 | 13 | 13 | 5 | 73 | Deep dive |
Inventory and costing | 25 | 20 | 10 | 8 | 9 | 72 | Deep dive |
Revenue and billing | 24 | 20 | 12 | 6 | 6 | 68 | Standard |
Payroll and statutory | 18 | 12 | 17 | 4 | 3 | 54 | Standard |
Treasury | 15 | 12 | 8 | 5 | 2 | 42 | Monitor |
Fixed assets | 12 | 10 | 6 | 3 | 2 | 33 | Exclude, document |
Deep-dive units can then borrow from our guides on procurement internal audit, inventory internal audit and the operational audit checklist for manufacturing.
What Does 2026 Risk Data Say Your Scope Should Cover?
Risk surveys help calibrate the “inherent risk” score. They do not replace your own risk assessment.
2026/27 signal | Data point | Scope implication |
Cybersecurity | 80% of 3,285 chief audit executives and directors rank it a top-five risk, up 7 points | Include IT general controls and access reviews |
Digital disruption and AI | Ranked second at 58%, up 10 points | Add AI use, data handling and model oversight |
Geopolitical and macroeconomic uncertainty | Reached 48%, up 10 points | Test vendor concentration and import exposure |
Source: IIA Internal Audit Foundation, Risk in Focus 2026/2027, survey of 3,285 respondents in 132 countries and locations.Â
Our read: the gap between perceived risk and audit coverage is a scoping problem, not a staffing one. If your plan’s top risks and your audit hours do not line up, revisit the scope before adding headcount.
How to Document Exclusions and Scope Limitations ?
ICAI’s exposure draft of SIA 220 proposes that scope be derived by consciously excluding units for justifiable reasons. Where the auditor cannot cover something the scope intended to cover, that scope limitation should be reported to the Audit Committee.Â
Keep a scope exclusion register with these columns:
- Unit or process excluded
- Reason (low risk score, recently audited, covered by another assurance provider)
- Approver and date
- Planned review date
This protects the auditor and gives the Audit Committee a clear view of unexamined areas.
How to Handle Scope Changes Mid-Audit ?
Scope creep and scope shrinkage both distort conclusions. Use a simple change-control rule.
Triggers to Revisit Scope
- Fraud indicators or whistleblower complaints
- A new regulation or notice
- Findings that spread beyond the planned boundary
- Limited access to data or people
Change-Control Steps
- Record the trigger and the proposed change.
- Estimate effect on time, cost and depth.
- Get approval from whoever approved the original scope.
- Update the plan and notify the auditee.
Where data allows, data analytics in internal audit can widen coverage without extending fieldwork, and continuous auditing can flag scope triggers sooner.
How Often Should Internal Audit Scope Be Reviewed in FY 2026-27?
Scope is a living document. A simple rhythm keeps it current:
- Before April: refresh the audit universe and score every unit.
- Q1: Audit Committee approves the plan and exclusion register.
- Q2 and Q3: Re-score after major changes, such as a new ERP, acquisition, or notice.
- Q4: Review coverage against plan and carry open findings forward.
How Does Internal Audit Scope Connect to the Statutory Auditor’s Report?
Under CARO 2020, the statutory auditor reports on whether the company has an internal audit system commensurate with its size and nature, and whether it considered the internal audit reports. A documented scope and exclusion register therefore also gives the statutory auditor evidence of coverage
Common Mistakes When Setting the Scope for Internal Audit
Mistake | Why it hurts | Fix |
Copying last year’s scope | Ignores new risks | Re-score the audit universe annually |
Scope too broad | Shallow testing | Use the scoring matrix to cut |
Scope set by management alone | Independence concerns | Route through the Audit Committee |
No exclusion record | Hidden blind spots | Maintain the exclusion register |
Objectives missing | Findings lack direction | Write audit objectives first |
What Should an Internal Audit Scope Statement Include?
A one-page scope statement can include:
- Objective: one or two sentences
- In scope: processes, entities, locations, period
- Out of scope: with reasons
- Approach: compliance audit, operational audit, or mixed; sampling or full-population testing
- Criteria: laws, policies, SOPs used as benchmarks
- Deliverables and timeline
- Approvals
Final thoughts on Scope for Internal Audit
Setting the scope for internal audit is a sequence: objectives, audit universe, risk assessment, regulation, controls, materiality, findings, then documented approval. Done well, risk-based auditing puts effort where it matters and gives the Audit Committee a clear view of what was and was not examined.
If you want to test how this applies to your organization, a conversation with a Chartered Accountant experienced in internal audit services can help. You can also read about the team or see how internal audit supports governance in growing companies.
Define the Right Scope for Your Internal Audit
FAQs on Scope for Internal Audit
What is the scope for internal audit?
It defines the processes, entities, periods and depth an internal audit covers, plus explicit exclusions. It is agreed with the Audit Committee or Board.
Who approves the internal audit scope in a company?
Under Rule 13(2), the Audit Committee or Board formulates it in consultation with the internal auditor. The internal audit head or engagement partner drafts it.
How often should internal audit scope be reviewed?
At least annually during internal audit planning, and whenever risks, regulations or operations change materially.
What is the difference between audit scope and audit objectives?
Objectives state why the audit is performed. Scope states what will be examined to meet those objectives.
What is risk-based internal audit scoping?
It means ranking auditable units by risk and materiality, then allocating audit hours in that order instead of following a fixed rotation.
Can management limit the internal audit scope?
Management can raise concerns, but any limitation should be disclosed to the Audit Committee or Board that approved the scope.Â
Related
Discover more from MSNA & Associates LLP
Subscribe to get the latest posts sent to your email.
