Internal Financial Controls (IFC) Reporting — Auditor Responsibility Explained
Introduction
Internal Financial Controls (IFC) are no longer just an internal management exercise. For companies covered by the applicable provisions of the Companies Act, 2013, they also form an important part of the statutory auditor’s reporting responsibilities.
Under Section 143(3)(i), the auditor is required to report whether the company has adequate internal financial controls with reference to financial statements in place and whether those controls were operating effectively.
In simple terms, the auditor is not merely checking whether a control exists. The real question is: Does the control work in practice, and does it provide reasonable assurance that financial information is reliable?
What are Internal Financial Controls?
Internal financial controls are the policies and procedures designed to help a company:
Maintain accurate and complete accounting records
Prevent and detect errors and fraud
Safeguard company assets
Ensure transactions are properly authorised
Prepare reliable financial statements
Comply with applicable laws and regulations
ICAI guidance explains that the auditor’s objective is to express an opinion on the effectiveness of the company’s internal financial controls over financial reporting.
What is the Auditor’s Responsibility?
The auditor’s responsibility goes beyond simply asking management whether controls are in place.
The auditor generally needs to:
Understand the company’s processes
This includes understanding significant financial processes, systems, IT controls and relevant control activities.
Identify financial reporting risks
The auditor considers where weaknesses could result in a material misstatement in the financial statements.
Evaluate the design of controls
A control may exist on paper but still be poorly designed. The auditor needs to consider whether the control is capable of preventing or detecting a material misstatement.
Test operating effectiveness
The auditor examines whether the control actually operated during the relevant period and whether it was performed consistently.
Evaluate deficiencies
Identified deficiencies are assessed to determine their significance and their possible impact on the auditor’s IFC opinion.
Form and report an opinion
Based on sufficient appropriate audit evidence, the auditor concludes whether the company’s IFC over financial reporting were effective.
This approach also fits into the risk-based thinking required under SA 315, which requires auditors to understand the entity, its environment and relevant internal controls when identifying and assessing risks of material misstatement.
What Does “Operating Effectively” Really Mean?
This is where IFC reporting becomes more practical.
Suppose a company has a policy requiring every payment above ₹5 lakh to be approved by a senior management member. Merely having the policy document does not prove that the control is effective.
The auditor may examine actual transactions and supporting evidence to determine whether:
The required approval was obtained;
The approval was given by the appropriate person;
The control operated throughout the relevant period; and
Exceptions were properly dealt with.
So, a control can be adequately designed but still fail the operating effectiveness test.
Management vs Auditor — Who is Responsible?
A common misconception is that the auditor is responsible for creating the company’s internal controls.
That is not correct.
Management is responsible for establishing, maintaining and operating appropriate internal financial controls. The auditor’s role is to independently evaluate those controls and express an opinion based on audit evidence.
This distinction is important because an auditor should not take over management’s responsibility while performing the IFC audit.
IFC in the Technology-Driven Environment
The nature of internal controls has also changed significantly.
Modern accounting systems, ERP platforms, automated approvals, access controls and audit trails mean that many financial controls are now technology-driven. Auditors therefore need to consider not only manual controls but also relevant IT controls and automated processes.
ICAI’s recent publications continue to emphasise understanding technology, risk assessment and the effectiveness of controls as part of modern audit practice.
This is particularly relevant in 2026, when a weakness in user access, system configuration or automated approval logic can potentially affect thousands of transactions at once.
What Happens When Controls Are Weak?
If the auditor identifies a significant deficiency or material weakness, the auditor must consider its effect on the IFC opinion.
The issue is not simply whether an error occurred. The auditor needs to understand why the control failed, how significant the deficiency is, whether compensating controls exist and what impact it could have on financial reporting.
This is why proper documentation and professional judgement are critical in IFC reporting.
Conclusion
IFC reporting should not be viewed as another compliance paragraph added to the audit report. It is fundamentally about answering one important question:
Can users of the financial statements reasonably rely on the company’s financial reporting processes?
For management, effective IFC means stronger processes, accountability and better financial discipline. For auditors, it means understanding risks, testing controls and reaching an independent conclusion based on sufficient appropriate evidence.
As businesses become increasingly automated and technology-driven, IFC reporting will continue to be an important part of audit quality and financial reporting reliability.
