Audit · Internal

Internal Audit that drives real improvement.

Risk-based internal audit that goes beyond compliance — identifying control weaknesses, process inefficiencies, and fraud risks across your business, with practical recommendations that management can actually act on.

Contact Us

Internal audit is the independent, objective assurance and consulting activity that adds value to an organisation by evaluating and improving the effectiveness of its risk management, control, and governance processes. At its best, it is a strategic business partner to the board and management — not a compliance function that generates reports nobody reads.

Internal audit under Section 138 of the Companies Act, 2013 is mandatory for all listed companies and for unlisted public or private companies that cross prescribed thresholds of paid-up capital, turnover, borrowings, or deposits. But even where it is not mandated, a well-run internal audit function is one of the most cost-effective risk management tools available to a growing business.

NDS Advisors provides internal audit services as an outsourced function, a co-sourced partner to in-house teams, or a periodic specialist reviewer. Our internal audit engagements are planned on a risk basis, executed with practical fieldwork, and reported in a format that drives management action — not a list of observations that collects dust.

Our Internal Audit Services

Outsourced Internal Audit Function

Full outsourcing of the internal audit function — including annual audit plan, fieldwork, reporting, and audit committee presentations — for companies without an in-house team.

Co-Sourced Internal Audit

Specialist support to supplement an in-house internal audit team — providing expertise in specific process areas, fraud risk, IFC testing, or IT audit.

Risk-Based Annual Audit Plan

Design of a risk-based internal audit plan that prioritises coverage of the highest-risk areas and key controls across the business.

Process & Control Reviews

In-depth review of specific business processes — finance, procurement, inventory, HR, IT — assessing control design and operating effectiveness.

IFC / ICFR Testing

Testing of key controls identified in the Risk Control Matrix to provide evidence of operating effectiveness for IFC/ICFR reporting purposes.

Fraud Risk Assessment

Identification and assessment of fraud risks across the business — with testing of anti-fraud controls and recommendations for improvement.

IT Audit

Review of IT general controls — access management, change management, computer operations, and data security — as part of the integrated internal audit plan.

Follow-Up Audit

Structured follow-up of prior internal audit findings — confirming that management actions have been implemented and controls have improved.

Our Process

1

Risk Assessment & Audit Planning

Assessment of the business risk profile — through management interviews, prior audit findings, and risk register review — to build a risk-prioritised annual audit plan.

2

Engagement Planning

Detailed planning for each audit engagement — defining objectives, scope, methodology, and timing before fieldwork begins.

3

Fieldwork & Testing

On-site or remote fieldwork — reviewing transactions, testing controls, interviewing process owners, and documenting findings with supporting evidence.

4

Reporting

Clear, action-oriented audit report — with findings, root cause analysis, risk rating, and specific management action required — delivered within agreed timelines.

5

Follow-Up & Monitoring

Tracking of management responses and implementation of agreed actions — with status reporting to the audit committee at agreed intervals.

Why It Matters

Mandatory compliance with Section 138 of the Companies Act
Identifies control gaps before they result in losses or audit findings
Provides independent assurance to the board and audit committee
Drives improvement in process efficiency and control effectiveness
Supports IFC/ICFR documentation and testing requirements
Detects and deters fraud through systematic risk-based coverage
Reduces external audit time and cost through documented controls
Provides CFO and management with actionable risk insights

Frequently Asked Questions

Internal audit is mandatory under Section 138 of the Companies Act, 2013 for all listed companies, and for unlisted public companies and private companies that meet prescribed thresholds — including paid-up capital of ₹50 crore or more, turnover of ₹200 crore or more, outstanding loans or borrowings of ₹100 crore or more, or outstanding deposits of ₹25 crore or more. The internal auditor is appointed by the Board.
Statutory audit is an external, mandatory audit that produces an opinion on whether the financial statements present a true and fair view — conducted for the benefit of external stakeholders. Internal audit is an ongoing review of internal controls, processes, and risk management — conducted for the benefit of management and the board. The two are complementary: a strong internal audit function reduces the time and cost of the external statutory audit.
Yes. Section 138 permits the internal auditor to be either an employee of the company or an external firm — a Chartered Accountant, Cost Accountant, or other professional as the Board may decide. Outsourcing the internal audit function to NDS Advisors gives companies access to a wider range of skills, a fresh perspective, and consistent methodology — without the overhead of a full-time internal audit team.
A risk-based internal audit plan prioritises the internal audit team's time and resources on the processes and controls that pose the highest risk to the organisation — rather than auditing all processes with equal frequency. The plan is built from a risk assessment of the business and updated annually to reflect changes in strategy, operations, and the control environment.
Internal audit findings should be presented to the audit committee at least quarterly. Major findings — particularly those with a high risk rating or involving fraud — should be escalated immediately. The audit committee is responsible for oversight of the internal audit function, including reviewing the annual plan, findings, and management actions.
A follow-up audit revisits prior internal audit findings to confirm that management has implemented the agreed actions and that the control gaps have been closed. Without follow-up, internal audit reports are filed and forgotten, and the same weaknesses recur in subsequent audits. Follow-up audits close the loop and demonstrate that internal audit is driving real improvement, not just generating reports.

Internal audit that drives real change.

Talk to our team about outsourced internal audit, risk-based planning, IFC testing, and audit committee reporting for your company.