On this page

The 2026 ICFR Audit Checklist for Indian Companies: Testing Controls and Documenting Evidence under the Companies Act 

2026 ICFR audit checklist for Indian companies showing financial control testing and audit evidence review-MSNA ASSOCIATES
On this page

If your statutory auditor asked you today to prove that your bank reconciliation control worked in every one of the last twelve months, what would you put on the table? A signed checklist? A system log? Or just the team’s assurance that “it gets done every month”? 

An ICFR audit checklist is a structured list of control objectives, risks, key controls, tests, evidence and owners that closes the gap between having a control and evidencing it. Under the Companies Act, 2013, internal controls over financial reporting (ICFR) sit behind the auditor’s reporting under Section 143(3)(i) and the Board report disclosure under Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014. 

This guide gives CFOs, finance heads, controllers, internal auditors and compliance teams a practical ICFR audit checklist covering control objectives, risk assessment, control testing, documentation, financial reporting and remediation, updated for 2026.

Key takeaways

  • An ICFR audit checklist converts “we have controls” into “we can evidence our controls.” Evidence, not intent, is what gets tested.
  • For listed companies, the directors must confirm in their Responsibility Statement that internal financial controls are in place and working, as Section 134(5)(e) lays down. Rule 8(5)(viii) asks every company’s Board report to comment on the adequacy of internal financial controls.
  • Since 1 December 2025, a small company can have paid-up capital up to ₹10 crore and turnover up to ₹100 crore (G.S.R. 880(E)). More private companies may sit outside auditor IFC reporting, yet lenders, investors and acquirers may still ask for evidence.
  • Test design before operating effectiveness. A badly designed control cannot be repaired by testing more samples.

What is an ICFR Audit Checklist, and Who Needs One in India?

An ICFR audit checklist is a working tool that links each financial reporting risk to a control, the test that proves it works and the evidence to keep, so a company can show its controls are well designed and operate throughout the year. Management uses it for self-assessment, internal auditors use it to plan control testing, and CA firms use it to prepare companies ahead of the statutory audit

How do ICFR and internal financial controls differ?

The terms overlap, which is why teams often mix them up. The table below separates them.

Term

What it covers

Where it sits

Internal financial controls (IFC)

Policies and procedures for orderly conduct of business, including safeguarding of assets, fraud prevention and detection, accuracy of records and timely, reliable financial information

Explanation to Section 134(5)(e)

ICFR

The subset of financial controls that bears on reliable financial statements, which is how the ICAI Guidance Note frames auditor reporting

Section 143(3)(i)

For the legal position, read MSNA’s guide to applicability of internal controls over financial reporting in India.

Who must comply with ICFR requirements in 2026?

ICFR compliance has two layers, namely what directors must say and what the auditor must report.

Company type

Auditor reporting under Section 143(3)(i)

Listed company

Applies. Directors’ Responsibility Statement, CEO/CFO certification under SEBI LODR and audit committee evaluation also apply

Unlisted public company

Applies

Private company with turnover of ₹50 crore or more, or borrowings of ₹25 crore or more

Generally applies, because the exemption needs both limits to be met

Private company below ₹50 crore turnover and ₹25 crore borrowings, with no default in Section 137 or Section 92 filings

Exempt under G.S.R. 583(E) dated 13 June 2017

One Person Company or small company (excludes holding and subsidiary companies, Section 8 companies and companies under special Acts)

Exempt, if no default in Section 137 or 92 filings

Every company’s Board report under Rule 8(5)(viii) still comments on internal financial controls. Lenders and acquirers may also ask for evidence of financial reporting controls during credit assessments and due diligence. 

One edge case catches many finance teams. The ₹25 crore borrowings limit in G.S.R. 583(E) is measured at any time during the financial year. A short-term working capital drawdown that crosses it for a few days can remove the exemption, even when the closing balance looks comfortable(for example, ₹18 crore at year-end but ₹27 crore for six days in January). Keep a running record of your highest borrowing level during the year, and check your exemption status with the auditor before relying on it.  

How does the COSO framework structure your ICFR Audit checklist?

The 2013 COSO Internal Control – Integrated Framework is the reference point that Indian companies commonly use to measure their controls. Its five components give your checklist a ready structure.

COSO component

What to test

Typical evidence

Control environment

Code of conduct, board oversight, reporting lines, finance team competence

Board minutes, whistle-blower log, delegation of authority matrix

Risk assessment

Whether reporting, fraud and change risks are identified and rated

Risk register, fraud risk assessment

Control activities

Approvals, reconciliations, segregation of duties, system controls

Risk and control matrix (RCM), approval trails, sign-offs

Information and communication

Data quality, reporting lines, escalation

Close calendar, MIS pack, escalation emails

Monitoring activities

Ongoing checks and internal audit

Internal audit reports, deficiency tracker, retest results

What Are the Eight Steps of an ICFR Audit Checklist?

Eight steps of an ICFR Audit Checklist-MSNA ASSOCIATES

Work through the steps in order. Each one lists what to check and what to retain.

Step 1: Define control objectives and scope

Start your ICFR audit checklist with what could make the financial statements wrong, then work backwards to the controls.

  • Set materiality early, then identify the significant accounts that will shape the audit: revenue, receivables, inventory, payables, fixed assets, borrowings, payroll and tax.
  • Map each account to assertions: existence, completeness, accuracy, valuation, rights and obligations, and presentation.
  • Confirm the entities, locations and outsourced service providers in scope.
  • Confirm applicability and the reporting date, including listed status, thresholds and ROC filing status.

Step 2: Run a risk assessment

Your risk assessment determines where testing time goes. A small, routine balance needs far less scrutiny than a manually posted journal flow that feeds into revenue. Our piece on internal audit and risk assessment explains how the two disciplines differ.

Score every risk by how likely it is to occur and how much damage it could cause, and mark the fraud-related ones in a separate category. Typical risks include duplicate vendor payments in procure-to-pay, cut-off errors in order-to-cash, unreviewed manual journals in the financial close, and unidentified related-party transactions.

Step 3: Document processes and controls

Documentation is the backbone of ICFR compliance. An auditor has little to test against when a control is undocumented.

  • Prepare process narratives, flowcharts and standard operating procedures.
  • Build the RCM, where each row links a risk to a control, its type, frequency, owner and assertion.
  • Maintain a segregation of duties matrix and a current delegation of authority.
  • Mark the key controls, meaning those whose failure could lead to a material misstatement.

An RCM row should be specific enough that two people would test it the same way. Here is an example:

Field

Example

Risk

Payment released without a matching PO, goods receipt and invoice

Control

System-enforced three-way match, with exceptions approved by the AP head

Type and frequency

Preventive, automated, every transaction

Key control

Yes

Evidence

System configuration screenshot, exception report with approvals

Practitioner note: an RCM goes stale fastest after an ERP change, a new revenue stream or an acquisition. Refresh it after each of those events instead of waiting for the annual review. 

Step 4: Plan testing, with design first

Every ICFR audit checklist needs two layers of testing, and the order matters. 

1. Test of design. 

Walk one transaction end to end and ask whether the control, operating as written, would prevent or detect a material misstatement. Design gaps need a process fix, not a bigger sample.

2. Test of operating effectiveness. 

Confirm the control operated throughout the period and the right person performed it. The sample sizes below are illustrative practice ranges, not statutory numbers. Confirm them against your auditor’s methodology and the ICAI Guidance Note.

Control frequency

Illustrative sample size

Annual

1

Quarterly

2

Monthly

2 to 5

Weekly

5 to 15

Daily

20 to 40

Multiple times a day

25 to 60

Test methods run from weakest to strongest as follows:

  • Inquiry alone is the weakest and needs corroboration.
  • Observation shows a control operating at one moment.
  • Inspecting documents, approvals, and system logs provides stronger evidence.
  • Re-performance is the strongest, because the tester redoes the control.

Tests must cover the full year, and interim testing with a roll-forward to the reporting date is a common way to manage workload.

When should interim testing start for FY 2026-27?

For FY 2026-27 (1 April 2026 to 31 March 2027), a workable plan is:

  • Finish the RCM refresh and design testing by November 2026.
  • Run interim operating tests on April to September controls between October and December.
  • Roll forward to 31 March 2027 for the remaining months, with fixes in place by February so retesting is possible.
  • Agree the dates with your statutory auditor, as timelines vary by company.

Step 5: Review financial close and reporting controls

This is where most misstatements are caught or missed. Check the following:

  • Bank, intercompany and sub-ledger reconciliations are prepared on time, reviewed, and cleared of differences.
  • Manual and top-side journals have defined posters, reviewers and flags for unusual entries.
  • Estimates such as expected credit loss, provisions, impairment, and useful lives have documented assumptions and are reviewed.
  • Disclosures meet Schedule III, including trade payable ageing and MSME dues, plus Ind AS or AS and related-party requirements.

Step 6: Test IT general controls and the audit trail

Most financial controls now run through software, so reporting reliability depends on the systems underneath.

Area

What to check

Access management

Provisioning, removal on exit, privileged access, periodic reviews

Change management

Approval and testing of changes to ERP, interfaces and reports

Operations and backup

Job monitoring and daily backup of books on servers located in India (Rule 3(5))

Audit trail

Edit log of every transaction that cannot be disabled (proviso to Rule 3(1), from 1 April 2023), preserved for at least eight financial years under Section 128(5) 

End-user computing

Version control, locked formulas and review of key spreadsheet models

Third-party systems

Assurance reports from service organisations that process your data

The auditor also reports on the audit trail under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014. Our guide to audit trail applicability, limits and penalties covers the rules.

Step 7: Evaluate control deficiencies

Testing will find exceptions. What matters next is how you classify and aggregate them.

Classification

Meaning

Who needs to know

Control deficiency

A control is missing, badly designed or not operating as designed

Management

Significant deficiency

Less severe than a material weakness but important enough to merit attention from those overseeing reporting

Management and audit committee

Material weakness

A deficiency, or combination, creating a reasonable possibility that a material misstatement will not be prevented or detected on time

Management, audit committee and auditor’s report

When evaluating deficiencies, aggregate related gaps because several small ones in one process can add up. Look for compensating controls that operate at similar precision. Weigh the magnitude and likelihood of a misstatement, not only whether one has occurred. Document the conclusion, since the auditor will ask how you reached it.

Step 8: Remediate, retest and report

A finding is closed only when the fix has been retested. For example, a journal approval gap is closed once post-fix journals show approvals, and late reconciliations are closed once three months of timely sign-offs exist.

Report results to the audit committee before the statutory auditor finalises the report. Where the problem is design, allow time for the new control to operate before retesting, because an early sample will be too thin to rely on. For presenting findings so they get acted on, see internal audit reporting: how to create actionable audit reports.

What Audit Evidence Should your ICFR Audit Checklist Capture?

Audit evidence often decides whether a control can be relied on.  The same control can be well or poorly evidenced. A bank reconciliation backed by a signed, dated statement with a named preparer and reviewer passes, while a verbal “it is done every month” does not. A vendor master change backed by a system log showing requester, approver and timestamp passes, while an email thread with no link to the system does not. The same logic applies to journal and access reviews.

How does a one-hour evidence test work?

Pick any key control and any month from the last year. Ask the control owner to produce, within one hour, the evidence a stranger could use to re-perform the control. Three gaps tend to surface. The reviewer’s sign-off carries no date. The evidence sits in someone’s inbox rather than a shared folder. The control clearly operated, yet nobody can show who performed it. Run the exercise on five controls before your auditor does.

What Are The Common ICFR Audit Checklist Mistakes, and When Does This Checklist Not Apply?

Common ICFR Audit Checklist mistakes and exceptions-MSNA ASSOCIATES

These mistakes weaken ICFR compliance most often:

  • Treating the ICFR audit as a year-end project rather than a year-round routine.
  • Copying a boilerplate RCM that does not reflect how the business runs.
  • Failing to aggregate deficiencies, so small gaps never reach the audit committee.
  • Leaving the RCM unchanged after an ERP migration, new business line or acquisition.

This checklist does not fully apply everywhere. A parent listed in the US or Japan may bring stricter SOX or J-SOX requirements, and banks and NBFCs face sector-specific rules from their regulator. Purely operational controls belong in a wider internal audit plan.

Which 2026 updates should change your ICFR Audit checklist?

Four developments deserve a place in this year’s plan.

Update

What it means for your checklist

COSO guidance on generative AI (February 2026) applies the five components to AI use cases

Inventory AI tools used in finance, including unsanctioned ones. Define the human review and evidence needed where a control relies on AI output

Small company thresholds (from 1 December 2025)

Recheck whether auditor IFC reporting still applies. The exemption covers reporting, not the need for controls

NFRA circular of 7 January 2026 on auditor communication with those charged with governance

NFRA’s circular (aimed at listed and other NFRA-covered entities) expects documented two-way auditor–TCWG communication (SA 260, SA 265). Others can follow it as good practice. 

Audit trail requirements, with preservation reporting from FY 2024-25

Keep ITGC testing of the edit log, access restrictions and retention current every year

How can MSNA support your ICFR programme?

MSNA & Associates LLP is a Bangalore-based firm of Chartered Accountants offering internal audit, ICFR and IFC engagements, and Virtual CFO services.

Our ICFR work covers business understanding, walkthroughs, SOP drafting, RCM preparation, control testing and reporting. Outcomes differ for every company. 

To talk through how this checklist applies to your company, the team behind our internal audit services in Bangalore can walk through it with you. Finance teams wanting ongoing support can also look at our Virtual CFO services

Need Help With Your ICFR Audit Checklist?

Speak with MSNA & Associates LLP for support with ICFR documentation, control testing and remediation, in line with applicable professional standards.

Frequently Asked Questions About ICFR Audit Checklist

What is an ICFR audit checklist?

A structured list of control objectives, risks, key controls, test steps and evidence used to judge whether internal controls over financial reporting are well designed and operating effectively.

Every private company still has to say something about internal financial controls in its Board report. The auditor’s separate opinion is where the relief sits, and it covers OPCs, small companies, and private companies under ₹50 crore turnover and ₹25 crore borrowings, so long as their ROC filings are clean.

Design effectiveness asks whether a control, working as written, would prevent or detect a material misstatement, and operating effectiveness asks whether it actually worked throughout the period.

Generally no, because Section 144 of the Companies Act, 2013 restricts the statutory auditor from services such as internal audit, so management often appoints a separate CA firm or an in-house team.

 


Discover more from MSNA & Associates LLP

Subscribe to get the latest posts sent to your email.

Found Valuable? Share it to peers

Why Trust MSNA

Get In Touch With Our Team Today

If you need any assistance in Internal Audit, Virtual CFO, Accounting/Bookkeeping for India, US & UAE, Financial Planning & Advisory, connect with our team today!

Talk To Our Team

Fill the form below, our team will connect with you shortly