Internal audit explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Treasury controls decide whether the company's cash reaches the right account, whether borrowings stay within their terms and whether money moves to or from connected parties on proper approval. This guide gives an illustrative internal audit programme for cash and bank, investments and borrowings, and explains what SIA 18 asks of the internal auditor on related parties.
There is no standard on internal audit specific to treasury. The treasury approach rests on SIA 120 (internal controls), SIA 130 (risk-based audit), SIA 310 (planning) and SIA 320 (evidence); the related party part rests on SIA 18. All are from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). SIA 18 belongs to the older group in that compendium: it was published in the March 2013 issue of the ICAI journal, its note says it was recommendatory in the initial period until the Council notifies a date, and its effective date is printed blank. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner. The checklists below are TaxClue's own and illustrative; none is mandatory unless a cited standard or a linked law post says so. Check current versions on internalaudit.icai.org.
Treasury is audited from the risk assessment: bank and cash controls, investment approvals, borrowing terms and covenant monitoring. For related parties, SIA 18 makes management responsible for identifying and disclosing them, and asks the internal auditor to evaluate the related controls, look for undisclosed relationships, test arm's length claims and report significant matters to the audit committee.
Treasury: the SIA base
SIA 130 (paragraph 5.1) and SIA 310 (paragraph 3.4) ask for risk-based planning and an independent risk assessment; SIA 120 (paragraphs 5.2 and 5.3) asks for tests of design and operation of key controls linked to risks; SIA 320 (paragraph 3.1) asks for sufficient and appropriate evidence. If you need your stock, receivables and bank-reporting position prepared for lender review, our bank compliance and stock statement service can help.
Cash and bank: an illustrative control and test map
| Area | Illustrative risk | Illustrative key control | Illustrative test |
|---|---|---|---|
| Bank accounts | Unauthorised or dormant accounts | Board-approved list of accounts and signatories; periodic review | Obtain bank confirmations; compare to the register |
| Payments | Unauthorised or altered payments | Dual approval; payment file checked against approved list | Compare payment file to approvals and bank debit |
| Bank reconciliation | Unreconciled or old items hide misuse | Monthly reconciliation reviewed by someone other than the preparer | Re-perform one month; test old reconciling items |
| Cash on hand | Petty cash misuse | Imprest limit; counts; vouchers approved | Surprise count; compare to book |
| Cheque and online access | Misuse of tokens, cheque books | Custody of cheque books and tokens; access removal on exit | Review custody register and user access |
| Receipts | Diversion before deposit | Daily deposit; receipt numbering | Trace a sample of receipts to bank credit dates |
For the statutory audit view of bank balances and confirmations, see our article on audit of payables, provisions and cash and bank balances.
Investments and borrowings: an illustrative map
| Area | Illustrative risk | Illustrative key control | Illustrative test |
|---|---|---|---|
| Investments | Investment outside policy or authority | Investment policy; Board or committee approval; custody of instruments | Compare each purchase to policy and approval; confirm holdings |
| Valuation and income | Wrong carrying value; income not accrued | Periodic valuation review; accrual checks | Re-compute income; compare with statements |
| Borrowings | Drawdown or repayment errors; wrong interest | Loan register; reconciliation with lender statements | Reconcile to lender confirmations; recompute interest |
| Covenants | Breach unnoticed | Covenant calendar with owner; compliance certificate review | Test each covenant ratio at each test date; review notices |
| Security and charges | Charge not recorded or not released | Charge register; release follow-up | Compare charges recorded with lender and register data |
Our article on audit of share capital, reserves and borrowings covers the authorisation, registers and covenant side of the statutory audit.
Loans, guarantees and connected parties: by link only
Loans to directors, loans and investments by a company, and related party contracts are governed by sections 185, 186 and 188 of the Companies Act, 2013. This article does not restate them; read our posts on section 185, section 186 and related party transactions under section 188. The internal auditor compares treasury movements with the approvals and registers those posts describe.
SIA 18: related parties
SIA 18's purpose is to ensure that related party activity is captured through internal controls and is consistent with the code of conduct, conflict of interest policy, laws and disclosure requirements (paragraph 1). Management is responsible for identifying related parties, recording the transactions and disclosing them; the internal auditor evaluates the controls and informs management of deficiencies (paragraph 2). Terms not defined in SIA 18 carry their meaning in Accounting Standard 18; see our post on AS 18.
| Requirement | What the internal auditor does | Paragraph |
|---|---|---|
| Understand relationships | Gather the identity of related parties, changes from the prior period, the nature of the relationship and the transactions in the period | 7 |
| Think about hidden parties | Consider complex structures, special purpose entities, inadequate systems and management's attitude to disclosure and override | 8 |
| Inspect records | Look at bank and legal confirmations and minutes; and other records such as contracts with key management, conflict of interest statements and shareholder registers | 9 |
| Small entities | Import transaction data and sort for customers or suppliers with few but large or unusual transactions | 10 |
| When a new related party appears | Confirm it, tell the team, ask management for all transactions, consider control failure and possible fraud, and extend procedures | 11 |
| Significant transactions outside the normal course | Inspect contracts; assess rationale, consistency with explanations, accounting and authorisation | 12 |
| Arm's length claims | Obtain evidence on management's assertion; test source data and assumptions | 13 |
| Documentation and governance | Record names and relationships; tell those charged with governance of significant matters | 14 |
| Reporting | If sufficient evidence cannot be obtained, consider the effect on the report and disclose it based on materiality | 15 |
Paragraph 5 notes that transactions whose nature may indicate related parties include loans at no interest or at off-market rates, sales or purchases at prices differing significantly from appraised value, loans with no scheduled repayment and guarantees without adequate compensation. Paragraph 6 lists conditions that can motivate non-market transactions, such as lack of working capital, dependence on a few customers or suppliers, and significant litigation. The statutory auditor's parallel approach is in our SA 550 guide.
Red flags
Illustrative: advances at no interest to a connected entity; loan repayments that appear at quarter ends and are reborrowed immediately; payments to parties with the same address as a director; round-sum transfers with vague narration; guarantees given for another entity's loans with no fee; covenant ratios that pass only after unusual year-end entries; and bank accounts opened with no Board record.
Illustrative example
Illustrative: Trident Auto Parts Ltd borrows from two lenders and holds treasury surplus in funds. The internal auditor reconciles loan balances to lender statements and finds one covenant ratio fell below the agreed level at the half-year, with no record of a waiver. A scan of payments finds repeated transfers to a firm that does not appear in the related party register; its address matches a director's relative. Under SIA 18 paragraph 11 the auditor asks management to identify all transactions with the firm, considers the failure of the identification control and tells the audit committee. The report records the covenant gap and the unregistered related party as separate findings, with management actions and dates.
Common lapses
- Accepting the related party list as complete without comparing it to payments and contracts.
- Reconciling the bank balance but never testing old reconciling items.
- A covenant schedule maintained by the lender relationship manager and never reviewed by anyone else.
- Treating loans to connected parties as routine advances.
Need help preparing treasury records for lenders?
If you need bank, stock and receivable statements ready for a lender review, or a check of borrowing records, our team can help through bank compliance and stock statement support.
Key takeaways
- Treasury is audited on the SIA base of risk, control design and operation, and evidence; the checklists are illustrative.
- Management is responsible for identifying and disclosing related parties; the internal auditor evaluates the controls (SIA 18, paragraph 2).
- The auditor inspects confirmations, minutes and contracts for undisclosed related parties (SIA 18, paragraph 9).
- Significant related party matters go to those charged with governance (SIA 18, paragraph 14).
- Sections 185, 186 and 188 are covered in the linked posts and not restated here.
Read next
- Internal audit of sales and receivables
- Audit of payables, provisions and cash and bank balances
- Audit of share capital, reserves and borrowings
- SA 550: related parties
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
