Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026tomorrow 15 OCTPF & ESI · Contributions · Sep 2026in 5 days 20 OCTGSTR-3B · Summary return · Sep 2026in 10 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 11 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 20 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 28 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 42 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 50 days
All due dates

SIA 120, Internal Controls: what internal controls are, the internal auditor's responsibilities, evaluating design and operating effectiveness, and how this sits with internal financial controls under the Companies Act

Internal controls are risk mitigation steps that help prevent and detect errors and irregularities. The Board and management carry the overall responsibility for them (paragraph...

Published
Updated
Reading time
8 min
Views
7
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 9, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Every internal audit rests on one question: are the controls that are meant to manage the company's risks designed properly and do they actually work? SIA 120 sets out what the ICAI means by internal controls, who is responsible for them and what the internal auditor must do about them.

This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). SIA 120 was issued in January 2020 and replaces the older SIA 12; it applies to internal audits beginning on or after a date notified by the Council (paragraph 6.1). Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner; our article on the Standards on Internal Audit explains how. Check the current version on the ICAI internal audit board's site, internalaudit.icai.org.

What SIA 120 says internal controls are

Paragraph 1.2 describes internal controls as systemic and procedural steps adopted by an organisation to mitigate risks, mainly in financial accounting and reporting, operational processing and compliance with laws. The actual steps, such as review, approval, physical count or segregation of duties, are "control activities" (paragraph 3.1). The standard then sorts controls in several ways, which is useful for planning any audit.

Label in SIA 120MeaningExample given or typical
Internal financial controls (IFCs)Controls that mitigate the risk of financial exposureApproval of payments, reconciliations
Operational controls (OCs)Controls that mitigate operational risksProduction or dispatch checks
Entity level controls (ELCs)Broad controls across the entity, part of the control environmentCode of conduct (paragraph 3.2)
Process level controls (PLCs)Controls focused on one processOrder processing or payroll (paragraph 3.2)
Manual controlsOperate with human interventionSupervisor review
IT general controlsSecure the systemsAccess controls (paragraph 3.1)
Application controlsCheck processing inside an applicationSequential numbering of invoices (paragraph 3.1)

The "internal controls system" is the umbrella for all of these (paragraph 3.7). The control environment, meaning the culture, attitude and actions of the Board and management, influences how well the process controls operate. Businesses that want their control set mapped in this way can ask our compliance advisory team.

Internal controls and internal financial controls

SIA 120 explains (paragraph 3.6) that "internal controls" is a wider term than the legal "internal financial controls". The standard sets side by side the definition in the SA 315 framework, the narrower ICAI definition for internal financial controls over financial reporting, and the definition used in the Companies Act. Paragraph 4 then lists where the Act and the rules place the responsibility: the Directors' Responsibility Statement in section 134(5)(e), the Board's report under rule 8(5)(viii) of the Companies (Accounts) Rules, 2014, and the statutory auditor's reporting under section 143(3)(i). For what each of those provisions requires and to whom it applies, read our posts on the Directors' Responsibility Statement, internal financial controls under section 143(3)(i) and rules 10 and 10A; this article does not restate them. Listed entities have additional certification duties under SEBI rules that are outside this article.

Paragraph 3.9 also notes that an internal control framework is a benchmark against which a control system can be assessed, and names the COSO framework as a widely used global example; Appendix 1 of SA 315 is given for the Indian context.

What the internal auditor must do (paragraph 5)

  1. Make controls part of the scope. The mandate comes from those charged with governance, generally the audit committee for listed entities, and internal controls are a key part of scope and approach (paragraph 5.1).
  2. Check design, implementation and operation. Procedures must be enough to check that the controls are designed, properly implemented and operating effectively. Shortcomings lead to recommendations for improvement and for making controls more efficient (paragraph 5.2).
  3. Anchor to the risk assessment. Review the risk assessment done at planning as the basis for judging whether adequate controls exist, direct procedures primarily at high and medium risk controls, and keep documentation such as a risk control matrix to show the linkage of procedure to risk (paragraph 5.3).
  4. Treat an opinion as assurance. Where the internal auditor gives an opinion on the presence, design, implementation or operating effectiveness of controls, SIA 110 applies and a clear understanding of the control framework is needed. A written assurance report should consider an evaluation of control self-assessment by control owners and compliance certificates from owners of key controls (paragraph 5.4).
  5. Document scope for statutory auditor reliance. Where the statutory auditor relies on internal audit work for internal financial controls over financial reporting under SA 610, the internal auditor documents the objectives, agreed scope and approach on which reliance is to be placed (paragraph 5.5). See our SA 610 guide.

Design versus operating effectiveness

A control can be well designed and still fail because nobody performs it. Design testing asks whether the control, if performed as described, would prevent or catch the risk. Operating testing asks whether it was performed, by the right person, on every occasion tested. SIA 120 says both must be covered but leaves the tests to the auditor's judgement. The choice of sample and analytics belongs to the SIA 5 and SIA 6 articles and to the function-wise guides, such as our one on procurement and inventory.

Illustrative example

Illustrative: Greenfield Packaging Ltd has a payables process in which any purchase over an approved limit needs a second approver. The internal auditor's risk control matrix lists the risk (unauthorised or duplicated payment), the control (second approval in the accounting system), the control owner and the planned test. Design review shows the system lets the same user act as maker and approver when the second approver is on leave; that is a design gap. Operating testing of 40 payments above the limit finds two with approvals dated after the payment. The report records both findings separately: one as a design weakness with a recommendation to block self-approval, one as an operating exception with the cause given. The statutory auditor, who plans reliance under SA 610, receives the documented scope and approach.

Common lapses

  • Reviewing only the written policy and not testing that the control operates.
  • Treating internal financial controls as a statutory audit matter alone and not scoping them in the internal audit plan.
  • A risk control matrix that is copied from the last year and not linked to the current risk assessment.
  • Testing low-risk controls in depth while a key control gets a token check.
  • Reporting that "controls are adequate" without saying what was tested.

Need help with an internal controls review?

If you are building a risk control matrix or want an independent view of whether your key controls work, our team can assist through compliance advisory and help you document the findings.

Key takeaways

  • Internal controls are wider than the legal term internal financial controls (SIA 120, paragraph 3.6).
  • The Board and management are responsible for designing and operating controls (paragraph 4.5).
  • The internal auditor tests design, implementation and operating effectiveness, concentrating on high and medium risk controls (paragraphs 5.2 and 5.3).
  • A risk control matrix links audit procedures to risks (paragraph 5.3).
  • Provisions of the Companies Act on internal financial controls are explained in the linked posts.

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SIA 120 Internal Controls

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What is the difference between internal controls and internal financial controls?

SIA 120 paragraph 3.6 says internal controls is the broader term: it goes beyond financial areas to cover operational areas as well.

Who is responsible for internal controls?

The Board of Directors and management carry the overall responsibility for designing, implementing and maintaining their operating effectiveness (paragraph 4.5).

One person should own every deadline. A deadline that belongs to everyone belongs to no one.

— TaxClue Compliance Desk

SIA 120 Internal Controls: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

SIA 120 paragraph 3.6 says internal controls is the broader term: it goes beyond financial areas to cover operational areas as well.

The Board of Directors and management carry the overall responsibility for designing, implementing and maintaining their operating effectiveness (paragraph 4.5).

Design, proper implementation and operating effectiveness of controls (paragraph 5.2).

Paragraph 5.3 says adequate documentation, for example a risk control matrix, should be in place to confirm the link between audit procedures and risks.

Where reliance is expected under SA 610, the internal auditor documents the objectives, agreed scope and approach on which reliance is to be placed (paragraph 5.5).

It applies for internal audits beginning on or after a date to be notified by the Council (paragraph 6.1). Check the internal audit board's site for the current position.