SIA 110 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Four standards in the ICAI's 100 series work as a set. SIA 110 says when an internal auditor may give a formal opinion and what kind. SIA 130, 140 and 150 say what the auditor does when risk management, governance or compliance with laws is the subject of the audit. They share a pattern, which makes them easier to remember than they look. A company that wants its framework ready before an internal auditor arrives can start with our compliance advisory team.
This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). Each of the four applies to internal audits beginning on or after a date to be notified by the Council. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner; see our article on the Standards on Internal Audit. Check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.
Most internal audit reports are observations and recommendations, not opinions. An assurance assignment needs a subject matter, pre-defined criteria and a conclusive outcome, and gives either reasonable or limited assurance (SIA 110). For risk, governance and compliance, the internal auditor audits the framework where management has one, and highlights exposures where none exists, but never takes over the management of the risk, governance or compliance itself.
SIA 110: the nature of assurance
Paragraph 1.1 recognises that in most situations the internal auditor reports detailed observations and issues no formal opinion. SIA 110 covers only assignments where an opinion is expressed through the report (paragraph 1.5). The following do not count as assurance assignments (paragraph 1.4): a summary of observations with ratings, agreed-upon procedures, reviews of statutory filings that report only non-compliance, and consulting or advisory work with no opinion. A rating on a single finding is not an audit opinion either (paragraphs 1.5 and 2.3).
An assurance assignment has three components (paragraph 3.1):
| Component | Meaning | Paragraph |
|---|---|---|
| Three parties | Internal auditor, auditee (responsible for the subject matter) and assurance user (for example the audit committee) | 3.2 |
| Three key elements | Subject matter, pre-defined criteria, conclusive outcome | 3.3 to 3.5 |
| Written assurance report | Opinion in a standard format | 3.6 |
Criteria can be formal (accounting standards), a framework (an established control framework), a mandate (a statute or contract) or informal (an internal code). The auditor's own expectations are not suitable criteria unless pre-agreed with the assurance users (paragraph 3.4).
Two kinds of assurance are permitted (paragraph 2.3). In a reasonable assurance assignment the opinion covers the whole subject matter after auditing the whole of it; reasonable assurance is less than absolute assurance because of selective testing, limits of controls and the persuasive rather than conclusive nature of evidence (paragraph 3.5). In a limited assurance assignment, procedures are deliberately limited and the opinion may cover part of the subject matter.
The auditor may undertake an assurance assignment only if ethical requirements will be met and the subject matter is appropriate, the criteria are suitable and available to users, enough evidence is accessible, the opinion will be in a written report and the purpose is rational (paragraph 4.2). A significant limit on scope or a user's wish to attach the auditor's name inappropriately may signal no rational purpose. Once accepted, the assignment cannot be turned into a non-assurance or a limited one without reasonable justification (paragraph 4.4). SIA 110 refers to SIA 380 on assurance reports, which is not in the compendium; the report form should be checked on the board's site.
The common pattern of SIA 130, 140 and 150
Each of the three has the same structure: a definition, the responsibility of the Board and management, the responsibility of the internal auditor, and explanatory comments. The pattern for the auditor is:
- A formal framework exists: plan and perform procedures to evaluate its design, implementation and operating effectiveness and give independent assurance to management and those charged with governance (SIA 130 paragraph 5.2; SIA 140 paragraph 5.1; SIA 150 paragraph 5.1).
- No formal framework: design procedures to highlight exposures from weak or absent activities and recommend how to strengthen them (SIA 130 paragraph 5.3; SIA 140 paragraph 5.2; SIA 150 paragraph 5.2).
- An opinion is wanted: follow SIA 110, which needs the formal framework to exist as the basis (SIA 130 paragraph 5.4; SIA 140 paragraph 5.3; SIA 150 paragraph 5.3).
- Never take over: the internal auditor does not manage risks, operate the governance framework or the compliance system, or take decisions on them (SIA 130 paragraph 5.5; SIA 140 paragraph 5.4; SIA 150 paragraph 5.5).
SIA 130: risk management
Paragraph 3.2 describes risk management as a continuing process to identify threats and vulnerabilities, assess severity and likelihood, prioritise and mitigate, and monitor and report. Paragraph 5.1 requires risk-based internal audits unless specially excluded, so that effort goes to important areas; paragraph 6.1 ties this to the Basic Principles and to SIA 220, 310 and 370. Where there is a framework, the audit objective is to review whether the organisation can identify risks, assess them objectively, respond through controls, keep unmitigated risks within tolerance, and monitor and report (paragraph 6.2). For an opinion, the auditor also considers the link to CEO and CFO certification on controls and the self-compliance certificates of risk owners (paragraph 6.5). Our article on the audit committee, section 177, explains the committee's role in evaluating risk management systems under the Act.
SIA 140: governance
Paragraph 3.1 defines governance as the set of relationships between the company and its stakeholders through which objectives are achieved, with integrity and accountability, trust and equity, transparency and justice as underpinnings. Governance activities are largely entity level controls (paragraph 3.3). The audit of an existing framework looks, among other things, at a code of conduct and a whistle-blower mechanism, defined roles, delegation of power documented and approved by the Board, active governing bodies and regular reporting (paragraph 6.1). The auditor focuses on the process of governance, not on second-guessing the decisions of governing bodies (paragraph 5.4).
SIA 150: compliance with laws and regulations
Paragraph 3.1 describes compliance as following applicable laws in letter and spirit, whether the breach is by omission or commission and whether intentional or not. Where a formal compliance framework exists, the auditor evaluates it (paragraph 5.1); the explanatory comments list the signs of one: policies, compliance owners, a database of applicable laws risk-assessed and built into processes, training, monitoring systems, and self-assessment and compliance certificates (paragraph 6.1).
A point many businesses miss is paragraph 5.4. When an auditor is asked only to find instances of non-compliance and no formal compliance framework exists, a written SIA 110 opinion may not be possible. A summary of findings can be given with the scope showing every law tested, the procedures, sample and population, a summary of work, and limitations, including that a court of law is the ultimate authority on interpretation. The auditor also does not act as chief compliance officer, own the compliance tracker or deal directly with regulators (paragraph 5.5). The tracker itself belongs to management; the auditor reviews it.
Illustrative example
Illustrative: the audit committee of Orchid Textiles Ltd asks its internal auditor for a written opinion that compliance with labour and environmental laws is adequate. The auditor checks the pre-conditions: there is no list of applicable laws, no compliance owners and no certificates. Under SIA 150 paragraph 5.4 and SIA 110 paragraph 4.2, the auditor explains that criteria are missing and that a formal opinion cannot be given. Instead, a summary of findings lists the laws tested, a sample of 25 returns and registers, the instances of non-compliance and the limitations, and recommends a compliance database with owners. The next year the framework is in place and a limited assurance opinion on the design of the compliance process is possible.
Common lapses
- Using the words "reasonable assurance" in an observation-style report with no criteria.
- Giving an opinion without agreeing the criteria with the assurance users.
- Auditor taking on the role of compliance or risk officer and then auditing it.
- Reporting findings with no statement of the laws tested or the sample.
- Treating a severity rating as if it were an audit opinion.
Need help with a compliance or risk review?
If you need a structured review of compliance, risk or governance practices before an internal audit, our team can work with you through compliance advisory to build the framework the auditor will test.
Key takeaways
- An assurance assignment needs subject matter, pre-defined criteria, a conclusive outcome and a written report (SIA 110, paragraph 3.1).
- Reasonable assurance covers the whole subject matter and is not absolute; limited assurance uses deliberately limited procedures (paragraphs 2.3 and 3.5).
- Where a framework exists, audit its design, implementation and operating effectiveness; where none exists, highlight exposures.
- The internal auditor does not manage the risk, governance or compliance activity (SIA 130, 140, 150).
- A compliance-only review without a framework may end in a summary of findings, not an opinion (SIA 150, paragraph 5.4).
Read next
- Standards on Internal Audit: framework, basic principles and which SIAs are mandatory
- SIA 120: internal controls and internal financial controls
- SIA 360, 370 and 390: internal audit report, communication and follow-up
- Section 177: the audit committee
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
