Internal Audit and Risk Assessment: Understanding the Key Differences

People often use “internal audit” and “risk assessment” as if they mean the same thing. They don’t. 

Risk assessment identifies what could go wrong. Internal audit checks whether the controls meant to stop that from happening are actually working. For CFOs, internal audit heads, risk managers, and compliance managers, mixing the two up leads to gaps: a company might run a solid audit every year and still miss a risk nobody assessed in the first place. 

Understanding how these functions complement each other helps organisations improve governance, strengthen internal controls, and make better business decisions. It also ensures that audit efforts remain focused on the areas that matter most. 

Key Takeaways

  • Risk assessment identifies and prioritizes any potential problem. Internal audit checks if there is a control in place.
  • In a risk-based audit strategy, the risk assessment process helps determine what areas internal audit should prioritize.
  • Enterprise risk management (ERM) is the ongoing, company-wide process. Internal audit is a periodic check within it.
  • Indian law expects both: Section 134(3)(n) of the Companies Act covers risk management, and Section 138 covers internal audit.
  • Most compliance gaps happen when one of the two is treated as optional.
Table of Contents

What Is Internal Audit?

An internal audit refers to an independent analysis to confirm whether the company’s processes, controls, and compliance procedures function as intended. It doesn’t just check numbers. It checks whether the systems around those numbers can be trusted.

A typical internal audit covers:

  • Financial controls and reconciliations
  • Statutory compliance (tax, PF, ESI, and similar)
  • Operational processes, such as procurement or inventory
  • IT general controls
  • Approval trails and segregation of duties

As per Section 138 of the Companies Act, 2013, internal auditing is mandatory for all companies whose shares are listed in the stock exchanges. Private companies and even those public companies which do not have their shares listed, but meet the prescribed turnover, borrowing or deposits threshold, also fall under the category. These are mentioned in Rule 13 of the Companies (Accounts) Rules, 2014. 

Beyond flagging what’s already gone wrong, an effective internal audit also strengthens the controls that prevent the same issue from recurring. 

What Is Risk Assessment?

Risk assessment is the process of identifying, evaluating, and ranking the things that could stop a company from meeting its objectives. It looks forward. It asks: what could happen, how likely is it, and how bad would it be?

A risk assessment results in:

  • A list of identified risks, both internal and external
  • A rating for each risk, usually by likelihood and impact
  • An owner assigned to each significant risk
  • A view of which risks the company has accepted, reduced, or transferred

Section 134(3)(n) of the Companies Act, 2013 requires the Board’s report to state whether the company has a risk management policy, and to identify any risks that, in the Board’s opinion, could threaten the company’s existence.

Internal Audit vs Risk Assessment: The Core Differences

Internal Audit and Risk Assessment comparison infographic highlighting key differences in direction, frequency, output, and ownership - MSNA ASSOCIATES

Aspect

Internal Audit

Risk Assessment

Direction

Looks backward and present: are current controls working?

Looks forward: what could go wrong next?

Frequency

Usually scheduled – quarterly, half-yearly, or once a year

Never really finishes. It gets refreshed whenever the business shifts

Output

A written report: findings and what needs fixing

A risk register, with each item ranked by likelihood and potential damage

Who owns it

Usually an internal auditor or an external audit firm, answering to the Audit Committee

Usually sits with management, often the CFO, or a dedicated risk manager

How Internal Audit and Risk Assessment Work Together: A Real-World Example

Consider a manufacturing company implementing a new ERP system. During the risk assessment, management identifies cybersecurity risks, implementation delays, employee training gaps, and potential data migration errors.

Later, the internal audit reviews whether these identified risks have been addressed through appropriate controls, approval mechanisms, user access restrictions, and monitoring procedures. This illustrates how risk assessment identifies what needs attention, while internal audit verifies whether those controls are actually working.

Neither replaces the other. A company can pass every audit and still get blindsided by a risk nobody had assessed. A company can also run a thorough risk assessment and still find, at audit time, that the controls meant to manage those risks were never properly implemented.

Our view: treating internal audit and risk assessment as two separate functions is increasingly the exception, not the norm. Globally, more Chief Audit Executives are taking on direct ERM responsibility than a decade ago. We expect Indian Audit Committees to start asking the same question sooner rather than later: not ‘do you have both,’ but ‘are they talking to each other. 

How Are Internal Audit and Risk Assessment Connected?

Risk assessment feeds internal audit. This is the link most people miss.

A well-run internal audit function doesn’t audit everything equally. It uses the risk assessment to decide where to look first, spending more time on high-risk areas and less on low-risk ones. This is called the risk-based audit approach. It is the model recommended by both the Institute of Internal Auditors (IIA) globally and the ICAI’s Standards on Internal Audit (SIA) in India.

 The most common gap we see isn’t a missing audit or a missing risk assessment. It’s the two functioning in isolation; a risk register that nobody hands to the audit team, and an audit plan built the same way it was five years ago, regardless of what’s actually changed in the business.

What Is the Risk-Based Audit Approach?

A risk-based audit approach means the internal audit plan is built directly from the risk assessment, not from habit or last year’s checklist.

This methodology forms the foundation of an effective Risk Management Audit, ensuring audit resources are directed towards the areas that pose the greatest threat to the organization’s objectives.

In practice, this looks like:

  1. Management or the risk function identifies and ranks risks
  2. The internal auditor reviews this ranking and maps it to audit areas
  3. High-risk areas get audited more frequently and in more depth
  4. Low-risk, stable areas get lighter-touch or less frequent review
  5. The plan is revisited when a major risk changes, not just once a year

SIA 1, ICAI’s standard on planning an internal audit, is built around this approach. It’s also what SEBI’s Listing Obligations and Disclosure Requirements (LODR) Regulations, 2015 expect from listed companies, whose Audit Committees are required to review the scope and findings of internal audit against the company’s risk profile.

Where Does Enterprise Risk Management (ERM) Fit In?

Enterprise risk management, or ERM, is the company-wide, ongoing system that risk assessment sits inside. If risk assessment is a single exercise, ERM is the structure that makes sure it keeps happening and actually gets used.

The COSO ERM framework, updated in 2017, is the most widely referenced model globally. It has five components:

Component

What it covers

Governance and culture

Who’s accountable for risk, and how seriously the organisation treats it

Strategy and objective-setting

Aligning risk appetite with business strategy

Performance

Identifying and assessing risks that could affect performance

Review and revision

Reassessing risk as the business and environment change

Information, communication, and reporting

Getting risk information to the people who need to act on it

A 2025 industry survey of risk oversight practices (State of Risk Oversight, NC State University) found that only 11% of organisations felt their risk management process gave them a real strategic advantage. Most companies have a risk register. Far fewer have turned it into something that actually shapes decisions, including what gets audited.

What Are the Benefits of Combining Internal Audit and Risk Assessment?

Internal Audit and Risk Assessment infographic showing the key benefits of combining both functions for stronger governance and business performance - MSNA ASSOCIATES

Organisations achieve better results when internal audit and risk assessment operate as complementary functions rather than separate activities.

Some of the advantages are:

  • Better audit planning according to the risks inherent in the business
  • Stronger internal control systems within various departments
  • Improved regulatory compliance
  • Effective utilization of audit resources
  • Early identification of risks
  • Better reporting to senior management and the Board
  • More confident business decisions

What Does Indian Regulation Require?

Requirement

What it covers

Who it applies to

Section 138, Companies Act 2013

Mandatory internal audit

Listed companies (always); private and unlisted public companies above prescribed thresholds

Section 134(3)(n), Companies Act 2013

Board must report on risk management policy and material risks

All companies, though the depth expected scales with size

SEBI LODR Regulations, 2015

Internal audit function and Audit Committee oversight

Listed companies

ICAI Standards on Internal Audit (SIA)

Professional framework for planning and conducting internal audit, including risk-based planning

ICAI members conducting internal audits

None of these regulations uses the exact phrase “risk-based audit.” But between Section 134(3)(n) requiring a risk view and Section 138 requiring an audit function, the practical expectation is that the two are connected, not run separately.

When Section 138 and Section 134(3)(n) Apply to the Same Company

Consider a private company that crosses ₹100 crore in outstanding borrowings from banks or financial institutions in a financial year. Under Rule 13 of the Companies (Accounts) Rules, 2014, that threshold alone triggers Section 138, requiring an appointed internal auditor. Section 134(3)(n), by contrast, has applied since incorporation regardless of size. So the Board’s Report has already needed to address risk management. The two obligations don’t arrive in sequence. The risk statement under Section 134(3)(n) and the newly mandatory internal audit under Section 138 land in the same reporting cycle. The internal auditor’s first-year plan should build on the existing Board’s Report risk assessment, not start from scratch.

Consulting a professional will help you work out whether your existing risk assessment is enough to build a first-year internal audit plan around, or whether that assessment needs updating first. 

 

What Are the Common Mistakes Companies Make?

In our experience, the biggest failures in this area aren’t technical. They’re organisational. Risk assessment and internal audit report to different people, use different formats, and never sit in the same room. 

  • Treating risk assessment as a once-a-year form-filling exercise, done to satisfy the Board report, then filed away until next year
  • Building the audit plan the same way every year, regardless of what the risk assessment actually flagged
  • Giving risk assessment and internal audit to two teams that don’t talk to each other, so neither informs the other
  • Assuming a clean audit report means no risk exists, when it may just mean the audit didn’t look there

Bringing the Two Together

Internal audit and risk assessment answer different questions, but a company only gets real protection when both are used together, with one feeding the other. Consulting an Internal Audit Firm in Bangalore can help you assess how well your current audit plan reflects your actual risk profile and where the gap might be.

Strengthen Your Internal Audit and Risk Framework

An effective internal audit should align with your organization's risk profile and regulatory obligations. Our Chartered Accountants can help evaluate your existing framework and identify practical areas for improvement in line with applicable standards.

Frequently Asked Questions About Internal Audit and Risk Assessment

Is risk assessment part of internal audit, or a separate function?

They’re separate but connected. Risk assessment is usually owned by management or a risk function. Internal audit uses that output to decide what to test, but internal audit is not itself the risk assessment.

No. Section 134(3)(n) requires all companies to report on risk management, but full ERM is mainly seen in larger or listed companies. Smaller companies can manage with a basic risk register

At least once a year and earlier in the case of any change, such as the introduction of a new product line, regulatory change, or operational disruption.

Yes, although it is less effective because, without a risk assessment to direct it, the audit process falls into routine, meaning that the low-risk areas are audited while the high-risk ones remain unaddressed.


Discover more from MSNA & Associates LLP

Subscribe to get the latest posts sent to your email.

Leave a Reply

Talk To Our Team

Fill the form below, our team will connect with you shortly