A business bills a client correctly for eleven months. In month twelve, a contract escalation clause never gets applied. Nobody notices, because the invoice still goes out, the payment still comes in, and nothing looks wrong on the P&L.
That’s revenue leakage: money the business earned but never actually collected, and it rarely announces itself.
A revenue leakage audit is a systematic review of billing, contracts, and revenue recognition processes to find income that was earned but never invoiced or collected correctly. Unlike fraud, nobody has to act dishonestly for it to happen. It’s usually a process gap, not a person.
In India, this review sits within the broader internal audit function and connects to three frameworks every mid-sized company should already be tracking: internal audit applicability under Section 138 of the Companies Act, 2013, internal financial controls reporting under Section 134(5), and revenue recognition under Ind AS 115.
This guide covers what revenue leakage actually looks like, how internal auditors find it, where it fits under Indian company law, and where detection is heading as it shifts from annual reviews toward continuous monitoring.
Key Takeaways
- Revenue leakage is unintentional, unlike fraud. It comes from process gaps between contracts, billing systems, and revenue recognition, not dishonest intent.
- Widely cited industry research puts the scale at roughly 1–5% of EBITDA lost annually, and MGI Research estimates 42% of companies experience some form of it.
- Internal auditors run a revenue assurance audit using three-way matching, contract compliance testing, and data analytics.
- For companies covered by Section 138 of the Companies Act, 2013, revenue leakage testing fits naturally inside the existing internal audit mandate rather than needing a separate engagement.
- A revenue leakage audit often gets folded entirely into the statutory audit, where it’s the easiest item to skip when time runs short.
What Is Revenue Leakage, and How Is It Different From Fraud?
Revenue leakage is money a business earned but never collected. It happens because of a process gap, not because someone acted dishonestly.
Fraud requires someone to act deliberately. Revenue leakage usually doesn’t. A contract renewal escalator that never gets applied, a usage-based service that goes unbilled because two systems don’t talk to each other, a discount approved verbally that was never authorized in writing – none of these need a bad actor. They need a broken handoff between departments.
That’s why they get investigated differently. A fraud investigation asks who did it. A revenue leakage audit asks where the process broke.
How Common Is Revenue Leakage?
The numbers are larger than most finance teams assume.
Source | Finding |
MGI Research | An estimated 42% of companies experience some form of revenue leakage |
EY (widely cited industry estimate) | Companies lose roughly 1–5% of EBITDA annually to leakage |
Industry data across subscription and professional-services models | Leakage runs higher in complex billing environments, closer to 5–9% of revenue for usage-based or professional-services billing |
These figures are reported consistently across independent finance and billing-industry research, and the pattern holds regardless of which specific study is cited: leakage is common, and it’s rarely visible in a standard monthly close.
For a company generating ₹300–400 crore a year, even the low end of that range represents real money quietly leaving the business every year, without a single fraudulent transaction anywhere in it.
The metric that should worry a CFO more than the percentage is the detection gap. Manual, annual review processes take weeks to months to catch a leakage pattern once it starts, and by then the same gap has usually repeated across several billing cycles. The cost isn’t just what leaked. It’s what kept leaking while nobody was looking.
Where Revenue Leakage Actually Hides ?
Leakage tends to show up in a few recurring spots mostly boring, procedural things that are easy to miss in a standard financial review.
Category | What Typically Goes Wrong |
Billing errors | Services delivered but never invoiced, or invoiced at the wrong rate |
Contract non-compliance | Escalation clauses, usage limits, or renewal terms that exist on paper but never get applied |
Unauthorized discounts | Sales-approved pricing exceptions that bypass finance sign-off |
Failed collections | Payment failures that never get followed up or re-billed |
Data mismatches | CRM, billing, and accounting systems that disagree on what was actually sold |
Unbilled revenue at period-end | Revenue recognized under Ind AS 115 that was never carried through to an actual invoice |
How Internal Auditors Identify Hidden Revenue Leakage ?
This is where a revenue leakage audit differs meaningfully from a standard financial statement audit. The focus isn’t whether the numbers add up. It’s whether every rupee that should have shown up actually did.
1. Three-Way Matching and Reconciliation
Auditors compare what was contracted, what was delivered, and what was actually billed line by line, not just at a summary level. A mismatch anywhere in that chain is where leakage tends to surface first.
2. Contract Compliance Testing
This means sampling active contracts and checking whether escalation clauses, usage caps, and renewal terms were actually applied in billing, not just written into the agreement. A contract that says pricing increases 5% annually is worth nothing if nobody ever applies the increase.
3. Data Analytics and CAATs
Computer-assisted audit techniques (CAATs) let auditors test entire transaction populations instead of small samples, flagging statistical outliers, zero-rupee invoices, duplicate credit notes, and unusual discount patterns) that a manual review of twenty-five sampled invoices would likely miss entirely.
4. Segregation of Duties Review
Auditors check who can approve a discount, who can issue a credit note, and who reconciles the billing system against the general ledger. When one person can do all three, leakage becomes both easier to create and harder to catch.
The biggest miss we see in these audits isn’t a specific transaction. It’s auditors sampling invoices without first mapping the actual revenue process end to end. If you don’t know every handoff between sales, delivery, and billing, you’re only testing the parts of the process you already understand, and leakage almost always hides in the parts nobody’s mapped.
Where a Revenue Leakage Audit Fits Under Indian Law ?
For companies where internal audit is mandatory under Section 138 of the Companies Act, 2013 – broadly, every listed company, plus unlisted public and private companies that cross certain turnover, capital, borrowing, or deposit limits – revenue leakage testing is a natural extension of that internal audit scope rather than a separate compliance exercise.
It also touches two related requirements:
1. Ind AS 115 (revenue recognition)
If revenue is being recognized correctly on the books but never actually invoiced or collected, that gap is exactly what a revenue leakage audit is built to surface.
2. Section 134(5) (internal financial controls, or IFC)
For companies within IFC applicability, a weak revenue cycle control can surface as a control weakness in the board’s report, independent of whether any money was actually misstated.
Practical consideration:
If your company is below the Section 138 thresholds, a formal internal audit isn’t legally required. But the underlying check (comparing contracts against actual billing) still applies. Many businesses below the mandatory limits run a scoped revenue leakage review voluntarily, ahead of a funding round or a lender’s due diligence, for exactly this reason.
Why Revenue Leakage Audits Get Buried Inside Financial Audits, and Why That's a Mistake?
Most companies never run a standalone revenue leakage audit. It gets treated as a side effect of the annual statutory or internal audit ie; a few sample invoices checked among hundreds of other line items.
That’s a real mistake, not just a scheduling problem. A financial audit is built to confirm the numbers you’ve reported are accurate. It’s not built to ask whether the number should have been bigger. Those are two different questions, and an audit plan built for the first one will naturally give less time to the second.
Our take:
Treating revenue leakage detection as a footnote inside a broader audit is one reason it can stay hidden for years in some companies. A dedicated, risk-based review of the revenue cycle (scoped and resourced on its own)tends to catch patterns that a brief glance at sampled invoices is unlikely to.
A Realistic Example: How a Leakage Pattern Gets Found
The scenario below illustrates a common, realistic leakage pattern. It is not a specific verified client engagement.
A mid-sized services company billed a long-term client correctly for year one of a multi-year contract. The contract included a standard 4% yearly rate increase. But that increase never made it from the signed contract into the billing system.
For three years, invoices went out on time, payments came in on time, and nothing in the monthly close looked off. During an internal audit, someone checked the signed contract against the actual billed rate and found the gap in under an hour. Three years of a missed 4% increase, compounding, on a contract worth several crore, had quietly gone uncollected the whole time.
Nothing about this involved fraud. It involved a handoff between the legal team that signed the contract and the billing team that never received the updated rate.
The Future of Revenue Leakage Detection: From Annual Audits to Continuous Monitoring
Detection timelines are changing faster than audit plans usually account for.
Manual, sample-based reviews can take weeks or months to catch a leakage pattern. AI-assisted, continuous monitoring tools like running reconciliation checks against the full transaction population rather than a sample can flag the same pattern within days rather than months.
This doesn’t replace the internal auditor’s judgment. It changes what the auditor spends time on. Instead of manually sampling invoices to find anomalies, the auditor reviews anomalies a system has already flagged, and spends the saved time on the harder question: why did the process break, and what stops it from breaking again.
The firms getting ahead of this aren’t necessarily the ones buying the most expensive detection software. They’re the ones that changed how the annual audit plan allocates time from mostly sampling toward mostly investigating what continuous monitoring already surfaced. The technology is only half the shift; the other half is an audit plan built around it.
How Often Should a Revenue Leakage Audit Be Done?
For most mid-sized and larger businesses, an annual, dedicated review is the practical minimum, with contract compliance testing refreshed whenever a major client agreement renews or changes. Businesses running usage-based or highly customized billing where leakage tends to run highest can benefit from a half-yearly cadence rather than waiting a full year between reviews.
Closing the Gaps Before They Compound
Revenue leakage rarely shows up as one dramatic loss. It shows up as a small, repeated gap that compounds quietly for years before anyone notices.
Internal auditor firm in Bangalore builds revenue leakage testing into the audit plan as its own scoped review, not an afterthought inside a broader engagement. Consulting a professional can help you assess whether your current revenue cycle has gaps worth checking before the next contract renewal. Reach out to our team to talk through what that would look like for your business.
Identify Hidden Revenue Gaps
Frequently Asked Questions About Revenue Leakage Audit
Is revenue leakage the same as fraud?
No, Fraud requires intent. Revenue leakage is almost always the result of a process gap ie, a missed handoff between contracts, billing, and collections.
How much revenue does the average company actually lose to leakage?
Widely cited industry estimates, most commonly attributed to EY, put it at roughly 1–5% of EBITDA annually, with higher rates in complex billing environments like usage-based or professional-services models.
Can revenue leakage be caught during a normal financial statement audit?
Rarely in full. A financial audit tests whether reported numbers are materially accurate, not whether more revenue should have been recognized.
Does Indian company law require a revenue leakage audit?
Not by that exact name. But for companies covered under Section 138 of the Companies Act, 2013 (broadly, listed companies, and unlisted public or private companies crossing the prescribed turnover, capital, borrowing, or deposit thresholds), revenue leakage testing fits naturally within the mandatory internal audit scope, and ties into revenue recognition accuracy under Ind AS 115.
Related
Discover more from MSNA & Associates LLP
Subscribe to get the latest posts sent to your email.
