Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates

SIA 110, SIA 130, SIA 140 and SIA 150: the nature of assurance an internal auditor gives, and the internal audit of risk management, governance and compliance with laws and regulations

Most internal audit reports are observations and recommendations, not opinions. An assurance assignment needs a subject matter, pre-defined criteria and a conclusive outcome, and...

Published
Updated
Reading time
9 min
Views
11
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 9, 2026
Reading time
9 min
0:00
Last updated: October 2026Verified against: Government sources

Four standards in the ICAI's 100 series work as a set. SIA 110 says when an internal auditor may give a formal opinion and what kind. SIA 130, 140 and 150 say what the auditor does when risk management, governance or compliance with laws is the subject of the audit. They share a pattern, which makes them easier to remember than they look. A company that wants its framework ready before an internal auditor arrives can start with our compliance advisory team.

This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). Each of the four applies to internal audits beginning on or after a date to be notified by the Council. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner; see our article on the Standards on Internal Audit. Check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.

SIA 110: the nature of assurance

Paragraph 1.1 recognises that in most situations the internal auditor reports detailed observations and issues no formal opinion. SIA 110 covers only assignments where an opinion is expressed through the report (paragraph 1.5). The following do not count as assurance assignments (paragraph 1.4): a summary of observations with ratings, agreed-upon procedures, reviews of statutory filings that report only non-compliance, and consulting or advisory work with no opinion. A rating on a single finding is not an audit opinion either (paragraphs 1.5 and 2.3).

An assurance assignment has three components (paragraph 3.1):

ComponentMeaningParagraph
Three partiesInternal auditor, auditee (responsible for the subject matter) and assurance user (for example the audit committee)3.2
Three key elementsSubject matter, pre-defined criteria, conclusive outcome3.3 to 3.5
Written assurance reportOpinion in a standard format3.6

Criteria can be formal (accounting standards), a framework (an established control framework), a mandate (a statute or contract) or informal (an internal code). The auditor's own expectations are not suitable criteria unless pre-agreed with the assurance users (paragraph 3.4).

Two kinds of assurance are permitted (paragraph 2.3). In a reasonable assurance assignment the opinion covers the whole subject matter after auditing the whole of it; reasonable assurance is less than absolute assurance because of selective testing, limits of controls and the persuasive rather than conclusive nature of evidence (paragraph 3.5). In a limited assurance assignment, procedures are deliberately limited and the opinion may cover part of the subject matter.

The auditor may undertake an assurance assignment only if ethical requirements will be met and the subject matter is appropriate, the criteria are suitable and available to users, enough evidence is accessible, the opinion will be in a written report and the purpose is rational (paragraph 4.2). A significant limit on scope or a user's wish to attach the auditor's name inappropriately may signal no rational purpose. Once accepted, the assignment cannot be turned into a non-assurance or a limited one without reasonable justification (paragraph 4.4). SIA 110 refers to SIA 380 on assurance reports, which is not in the compendium; the report form should be checked on the board's site.

The common pattern of SIA 130, 140 and 150

Each of the three has the same structure: a definition, the responsibility of the Board and management, the responsibility of the internal auditor, and explanatory comments. The pattern for the auditor is:

  1. A formal framework exists: plan and perform procedures to evaluate its design, implementation and operating effectiveness and give independent assurance to management and those charged with governance (SIA 130 paragraph 5.2; SIA 140 paragraph 5.1; SIA 150 paragraph 5.1).
  2. No formal framework: design procedures to highlight exposures from weak or absent activities and recommend how to strengthen them (SIA 130 paragraph 5.3; SIA 140 paragraph 5.2; SIA 150 paragraph 5.2).
  3. An opinion is wanted: follow SIA 110, which needs the formal framework to exist as the basis (SIA 130 paragraph 5.4; SIA 140 paragraph 5.3; SIA 150 paragraph 5.3).
  4. Never take over: the internal auditor does not manage risks, operate the governance framework or the compliance system, or take decisions on them (SIA 130 paragraph 5.5; SIA 140 paragraph 5.4; SIA 150 paragraph 5.5).

SIA 130: risk management

Paragraph 3.2 describes risk management as a continuing process to identify threats and vulnerabilities, assess severity and likelihood, prioritise and mitigate, and monitor and report. Paragraph 5.1 requires risk-based internal audits unless specially excluded, so that effort goes to important areas; paragraph 6.1 ties this to the Basic Principles and to SIA 220, 310 and 370. Where there is a framework, the audit objective is to review whether the organisation can identify risks, assess them objectively, respond through controls, keep unmitigated risks within tolerance, and monitor and report (paragraph 6.2). For an opinion, the auditor also considers the link to CEO and CFO certification on controls and the self-compliance certificates of risk owners (paragraph 6.5). Our article on the audit committee, section 177, explains the committee's role in evaluating risk management systems under the Act.

SIA 140: governance

Paragraph 3.1 defines governance as the set of relationships between the company and its stakeholders through which objectives are achieved, with integrity and accountability, trust and equity, transparency and justice as underpinnings. Governance activities are largely entity level controls (paragraph 3.3). The audit of an existing framework looks, among other things, at a code of conduct and a whistle-blower mechanism, defined roles, delegation of power documented and approved by the Board, active governing bodies and regular reporting (paragraph 6.1). The auditor focuses on the process of governance, not on second-guessing the decisions of governing bodies (paragraph 5.4).

SIA 150: compliance with laws and regulations

Paragraph 3.1 describes compliance as following applicable laws in letter and spirit, whether the breach is by omission or commission and whether intentional or not. Where a formal compliance framework exists, the auditor evaluates it (paragraph 5.1); the explanatory comments list the signs of one: policies, compliance owners, a database of applicable laws risk-assessed and built into processes, training, monitoring systems, and self-assessment and compliance certificates (paragraph 6.1).

A point many businesses miss is paragraph 5.4. When an auditor is asked only to find instances of non-compliance and no formal compliance framework exists, a written SIA 110 opinion may not be possible. A summary of findings can be given with the scope showing every law tested, the procedures, sample and population, a summary of work, and limitations, including that a court of law is the ultimate authority on interpretation. The auditor also does not act as chief compliance officer, own the compliance tracker or deal directly with regulators (paragraph 5.5). The tracker itself belongs to management; the auditor reviews it.

Illustrative example

Illustrative: the audit committee of Orchid Textiles Ltd asks its internal auditor for a written opinion that compliance with labour and environmental laws is adequate. The auditor checks the pre-conditions: there is no list of applicable laws, no compliance owners and no certificates. Under SIA 150 paragraph 5.4 and SIA 110 paragraph 4.2, the auditor explains that criteria are missing and that a formal opinion cannot be given. Instead, a summary of findings lists the laws tested, a sample of 25 returns and registers, the instances of non-compliance and the limitations, and recommends a compliance database with owners. The next year the framework is in place and a limited assurance opinion on the design of the compliance process is possible.

Common lapses

  • Using the words "reasonable assurance" in an observation-style report with no criteria.
  • Giving an opinion without agreeing the criteria with the assurance users.
  • Auditor taking on the role of compliance or risk officer and then auditing it.
  • Reporting findings with no statement of the laws tested or the sample.
  • Treating a severity rating as if it were an audit opinion.

Need help with a compliance or risk review?

If you need a structured review of compliance, risk or governance practices before an internal audit, our team can work with you through compliance advisory to build the framework the auditor will test.

Key takeaways

  • An assurance assignment needs subject matter, pre-defined criteria, a conclusive outcome and a written report (SIA 110, paragraph 3.1).
  • Reasonable assurance covers the whole subject matter and is not absolute; limited assurance uses deliberately limited procedures (paragraphs 2.3 and 3.5).
  • Where a framework exists, audit its design, implementation and operating effectiveness; where none exists, highlight exposures.
  • The internal auditor does not manage the risk, governance or compliance activity (SIA 130, 140, 150).
  • A compliance-only review without a framework may end in a summary of findings, not an opinion (SIA 150, paragraph 5.4).

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SIA 110

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Is every internal audit report an assurance report?

No. SIA 110 paragraph 1.4 lists assignments that are not assurance, such as a summary of observations with recommendations and advisory work.

What is the difference between reasonable and limited assurance in internal audit?

Reasonable assurance gives an opinion on the whole subject matter after auditing all of it. Limited assurance uses deliberately limited procedures and may cover only part (paragraphs 2.3 and 3.5).

Reconcile the bank first; most other errors show themselves once it agrees.

— TaxClue Accounts & Audit Desk

SIA 110: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. SIA 110 paragraph 1.4 lists assignments that are not assurance, such as a summary of observations with recommendations and advisory work.

Reasonable assurance gives an opinion on the whole subject matter after auditing all of it. Limited assurance uses deliberately limited procedures and may cover only part (paragraphs 2.3 and 3.5).

No. SIA 130 paragraph 5.5 says the internal auditor does not assume responsibility to manage risks or execute risk management decisions.

The auditor designs procedures to highlight exposures from weak or absent activities and recommends how to strengthen them (SIA 130 paragraph 5.3; SIA 150 paragraph 5.2).

No. SIA 110 says a rating or risk rating of an observation is not an audit opinion for the standard.

Each standard recites where the Board's responsibility arises. The detail of the Companies Act duties is in our linked section posts; the standards themselves focus on the auditor's role.