On this page

How to Determine the Scope of an Internal Audit in India: Rule 13, Risk Scoring and Exclusions Explained

Scope for internal audit in India, showing financial document review, risk assessment, and compliance checks-MSNA ASSOCIATES
On this page

The scope for internal audit is the written boundary of an engagement: which processes, entities, locations and time periods are examined, how deep testing goes, and what stays out. 

Under Rule 13(2) of the Companies (Accounts) Rules, 2014, the Audit Committee, or the Board where no committee exists, decides the scope in consultation with the internal auditor. A scope that holds up under scrutiny begins with what the business wants to achieve. It is then shaped by risk ratings, legal obligations, materiality thresholds and earlier audit observations, and it is finalised only when the Audit Committee signs off on a written statement. 

CFOs, Internal Audit Heads and Audit Committees will find here a step-by-step method for setting scope, along with a scoring model and current 2026 risk data. 

Key Takeaways On The Scope for Internal Audit

  • Start by listing all the units that could be audited, and only then draw the boundary of the engagement. ICAI’s exposure draft of SIA 220 proposes this sequence 
  • Score every auditable unit on risk, materiality, regulation, change, and prior findings.
  • Record what you exclude and why. Exclusions are part of the scope.
  • Re-open scope when risks move, not only at year-end.

What Is the Scope for Internal Audit, and What Does It Include?

Scope tells the auditor which areas to examine and how thoroughly to examine them. 

Element

What it answers

Example

Objectives

Why are we auditing this?

Confirm vendor payments follow approved limits

Scope

What is in and out?

Procure-to-pay, three plants, April–September 2026

Depth

How much testing?

100% of payments above ₹10 lakh; sample the rest

Plan

When and with whom?

Q3, two auditors, 15 working days

Internal Audit Scope and Objectives: Why They Must Match

Scope and objectives need to be developed together, since each depends on the other. Weak audit objectives produce a vague scope, and a vague scope produces findings nobody can act on. Write the objective first, then size the scope to prove or disprove it.

Who Decides the Scope for Internal Audit in India?

In India, the Audit Committee, or the Board where no committee exists, formulates the scope of internal audit in consultation with the internal auditor under Rule 13(2) of the Companies (Accounts) Rules, 2014. The internal audit head drafts the plan, and management supplies context but should not restrict coverage without disclosure. 

Three layers share the decision:

  • Audit Committee or Board: sets the scope, periodicity, and methodology of the internal audit under Rule 13(2), drawing on the internal auditor’s input.
  • Internal Audit Head or engagement partner: drafts the plan and recommends scope based on risk.
  • Management: supplies context and expectations but should not restrict coverage without that restriction being disclosed.

Globally, the IIA’s Global Internal Audit Standards, effective January 9, 2025, say the chief audit executive approves engagement objectives, scope and any changes, using an engagement risk assessment.

Is Internal Audit Mandatory for Your Company? 

Under Section 138 and Rule 13, applicability depends on the preceding financial year:

Company type

Trigger (any one)

Listed

Always applicable

Unlisted public

Paid-up capital ≥ ₹50 crore; turnover ≥ ₹200 crore; loans from banks or PFIs > ₹100 crore; deposits ≥ ₹25 crore

Private

Turnover ≥ ₹200 crore; or loans from banks or PFIs > ₹100 crore

When this does not apply: 

A private company with turnover below ₹200 crore and bank or PFI borrowings of ₹100 crore or less is not required to appoint an internal auditor under Section 138. An unlisted public company is exempt only if it is below all four thresholds above. Check each threshold against the preceding financial year’s figures. Exempt companies can still commission a voluntary review, and the scoping method in this guide works at a smaller scale. 

If a company meets the Rule 13 criteria and does not appoint an internal auditor, it may face penalties under the Companies Act, depending on the circumstances. A general penalty provision such as Section 450 may apply 

What Six Inputs Decide the Scope of an Internal Audit?

Scope for internal audit: six key inputs covering business objectives, risk assessment, regulatory compliance, internal controls, materiality, and previous audit findings-MSNA ASSOCIATES

Good internal audit planning blends six inputs. Skip one and the scope develops a blind spot.

1. Business Objectives and Strategy

Start with what the business is trying to achieve this year: a new plant, an acquisition, a pricing change, an ERP migration. Audit objectives should trace back to those goals.

  • A company focused on growth needs closer attention on how it books revenue and manages customer credit. 
  • Cost programs raise the importance of procurement and inventory.
  • Fundraising raises the importance of financial reporting controls.

2. Risk Assessment and the Audit Universe

ICAI’s exposure draft of SIA 220 proposes that an audit universe be prepared before scope is set. Then each auditable unit gets an independent risk assessment. This is risk-based internal audit in practice: coverage follows risk, not habit. For the difference between the two disciplines, see internal audit and risk assessment. 

If you want to review the risk management process itself, our risk management audit guide explains how. 

The same draft asks for an audit programme that lists “what could go wrong” in each unit and the control meant to prevent it. Use that list as a sense check on your scope for internal audit: if a risk has no planned test, it is outside your scope by accident.

Quick Risk Questions per Unit

  • What could go wrong, and how badly?
  • How likely is it, given current controls?
  • Has anything changed: people, systems, volumes, vendors?

3. Regulatory and Compliance Requirements

For each unit, list the laws that touch it: the Companies Act, GST, TDS, MSME payment rules under Section 43B(h), the labour codes, and SEBI or RBI rules where the entity is regulated. A compliance audit checks whether a unit follows applicable laws as well as its own internal policies. An operational audit asks whether the work is done efficiently and delivers the results it is meant to. Decide which lens each unit needs. Our blog on the types of internal audit compares them.

4. Business Processes and the Control Environment

Walk the process end to end, then judge the control environment around it: approvals, segregation of duties, system access, management attitude. Strong controls can justify lighter testing, while weak ones justify depth. See internal controls in business operations for why paper controls and real practice drift apart.

5. Materiality

Materiality tells you which misstatements or losses matter enough to test. Set it in rupees and in qualitative terms (fraud, regulatory breach, reputational harm).

  • Quantitative: a threshold tied to revenue, profit or asset base.
  • Qualitative: items that matter regardless of size, such as related-party payments.

6. Previous Audit Findings

Open and repeat findings are among the most useful scope signals. Include:

  • Areas with unresolved observations
  • Controls that were “fixed” but never re-tested
  • Units not audited for two or more cycles

Good internal audit reporting makes this input usable, because follow-up status is visible at a glance.

Compliance Audit vs Operational Audit: How the Scope Changes

The same process can be scoped two ways. State which lens you are using, because the criteria differ.

Aspect

Compliance audit

Operational audit

Core question

Are we following the rules?

Are we running this well?

Benchmark

Laws, contracts, approved policies

SOPs, cost and cycle-time targets

Typical scope

Filings, approvals, licenses

Throughput, rework, waste

Testing style

Pass or fail against criteria

Analysis, walkthroughs, root cause

Example

GST and TDS reconciliation review

Purchase-to-pay turnaround

Many engagements blend both. Name the mix in the scope statement so nobody argues about criteria later.

Why Risk-Based Internal Audit Beats Cycle-Based Coverage ?

Cycle-based plans audit every unit on a fixed rotation. They are easy to run but blind to shifts in risk. A risk-based internal audit sends hours where the risk score is highest and rotates low-risk units less often.

  • Cycle-based: even coverage, predictable, slow to react.
  • Risk-based: concentrates effort on high-risk units; the audit universe must be maintained continuously.
  • Hybrid: in-depth review of high-scoring units and rotation review of others.

Hybrid works well for mid-size companies, as long as scoring is documented and updated.

The MSNA Scope Scoring Matrix (Illustrative 100-Point Model)

Here is an illustrative weighted model to start from. Calibrate the weights to your organization.

Factor

Max points

What to score

Inherent risk

30

Fraud exposure, complexity, volume

Materiality

25

Share of revenue, spend or assets

Regulatory exposure

20

Statutory deadlines, penalty potential

Change and complexity

15

New systems, people, vendors, entities

Prior findings and audit gap

10

Open issues, years since last audit

Decision rule: 70+ means deep-dive testing, 50-69 means standard review, and below 50 means monitor or exclude with documented rationale.

Calibrating these weights is where experience counts. A Chartered Accountant experienced in internal audit can help you tailor them to your organisation.

Worked Example: Hypothetical ₹350 Crore Manufacturer

This is an illustration, not client data.

Auditable unit

Inherent risk

Materiality

Regulatory

Change

Prior findings

Total

Scope decision

Procure-to-pay

27

22

14

9

8

80

Deep dive

IT general controls

27

15

13

13

5

73

Deep dive

Inventory and costing

25

20

10

8

9

72

Deep dive

Revenue and billing

24

20

12

6

6

68

Standard

Payroll and statutory

18

12

17

4

3

54

Standard

Treasury

15

12

8

5

2

42

Monitor

Fixed assets

12

10

6

3

2

33

Exclude, document

Deep-dive units can then borrow from our guides on procurement internal audit, inventory internal audit and the operational audit checklist for manufacturing.

What Does 2026 Risk Data Say Your Scope Should Cover?

Risk surveys help calibrate the “inherent risk” score. They do not replace your own risk assessment.

2026/27 signal

Data point

Scope implication

Cybersecurity

80% of 3,285 chief audit executives and directors rank it a top-five risk, up 7 points

Include IT general controls and access reviews

Digital disruption and AI

Ranked second at 58%, up 10 points

Add AI use, data handling and model oversight

Geopolitical and macroeconomic uncertainty

Reached 48%, up 10 points

Test vendor concentration and import exposure

Source: IIA Internal Audit Foundation, Risk in Focus 2026/2027, survey of 3,285 respondents in 132 countries and locations. 

Our read: the gap between perceived risk and audit coverage is a scoping problem, not a staffing one. If your plan’s top risks and your audit hours do not line up, revisit the scope before adding headcount.

How to Document Exclusions and Scope Limitations ?

ICAI’s exposure draft of SIA 220 proposes that scope be derived by consciously excluding units for justifiable reasons. Where the auditor cannot cover something the scope intended to cover, that scope limitation should be reported to the Audit Committee. 

Keep a scope exclusion register with these columns:

  • Unit or process excluded
  • Reason (low risk score, recently audited, covered by another assurance provider)
  • Approver and date
  • Planned review date

This protects the auditor and gives the Audit Committee a clear view of unexamined areas.

How to Handle Scope Changes Mid-Audit ?

Scope creep and scope shrinkage both distort conclusions. Use a simple change-control rule.

Triggers to Revisit Scope

  • Fraud indicators or whistleblower complaints
  • A new regulation or notice
  • Findings that spread beyond the planned boundary
  • Limited access to data or people

Change-Control Steps

  1. Record the trigger and the proposed change.
  2. Estimate effect on time, cost and depth.
  3. Get approval from whoever approved the original scope.
  4. Update the plan and notify the auditee.

Where data allows, data analytics in internal audit can widen coverage without extending fieldwork, and continuous auditing can flag scope triggers sooner.

How Often Should Internal Audit Scope Be Reviewed in FY 2026-27?

Scope is a living document. A simple rhythm keeps it current:

  • Before April: refresh the audit universe and score every unit.
  • Q1: Audit Committee approves the plan and exclusion register.
  • Q2 and Q3: Re-score after major changes, such as a new ERP, acquisition, or notice.
  • Q4: Review coverage against plan and carry open findings forward.

How Does Internal Audit Scope Connect to the Statutory Auditor’s Report?

Under CARO 2020, the statutory auditor reports on whether the company has an internal audit system commensurate with its size and nature, and whether it considered the internal audit reports. A documented scope and exclusion register therefore also gives the statutory auditor evidence of coverage

Common Mistakes When Setting the Scope for Internal Audit

Mistake

Why it hurts

Fix

Copying last year’s scope

Ignores new risks

Re-score the audit universe annually

Scope too broad

Shallow testing

Use the scoring matrix to cut

Scope set by management alone

Independence concerns

Route through the Audit Committee

No exclusion record

Hidden blind spots

Maintain the exclusion register

Objectives missing

Findings lack direction

Write audit objectives first

What Should an Internal Audit Scope Statement Include?

A one-page scope statement can include:

  • Objective: one or two sentences
  • In scope: processes, entities, locations, period
  • Out of scope: with reasons
  • Approach: compliance audit, operational audit, or mixed; sampling or full-population testing
  • Criteria: laws, policies, SOPs used as benchmarks
  • Deliverables and timeline
  • Approvals

Final thoughts on Scope for Internal Audit

Setting the scope for internal audit is a sequence: objectives, audit universe, risk assessment, regulation, controls, materiality, findings, then documented approval. Done well, risk-based auditing puts effort where it matters and gives the Audit Committee a clear view of what was and was not examined.

If you want to test how this applies to your organization, a conversation with a Chartered Accountant experienced in internal audit services can help. You can also read about the team or see how internal audit supports governance in growing companies.

Define the Right Scope for Your Internal Audit

Strengthen risk assessment and audit planning with professional internal audit support tailored to your organisation’s requirements.

FAQs on Scope for Internal Audit

What is the scope for internal audit?

It defines the processes, entities, periods and depth an internal audit covers, plus explicit exclusions. It is agreed with the Audit Committee or Board.

Under Rule 13(2), the Audit Committee or Board formulates it in consultation with the internal auditor. The internal audit head or engagement partner drafts it.

At least annually during internal audit planning, and whenever risks, regulations or operations change materially.

Objectives state why the audit is performed. Scope states what will be examined to meet those objectives.

It means ranking auditable units by risk and materiality, then allocating audit hours in that order instead of following a fixed rotation.

Management can raise concerns, but any limitation should be disclosed to the Audit Committee or Board that approved the scope. 


Discover more from MSNA & Associates LLP

Subscribe to get the latest posts sent to your email.

Found Valuable? Share it to peers

Why Trust MSNA

Get In Touch With Our Team Today

If you need any assistance in Internal Audit, Virtual CFO, Accounting/Bookkeeping for India, US & UAE, Financial Planning & Advisory, connect with our team today!

More From The Author

Talk To Our Team

Fill the form below, our team will connect with you shortly