SIA 120 Internal Controls explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Every internal audit rests on one question: are the controls that are meant to manage the company's risks designed properly and do they actually work? SIA 120 sets out what the ICAI means by internal controls, who is responsible for them and what the internal auditor must do about them.
This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). SIA 120 was issued in January 2020 and replaces the older SIA 12; it applies to internal audits beginning on or after a date notified by the Council (paragraph 6.1). Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner; our article on the Standards on Internal Audit explains how. Check the current version on the ICAI internal audit board's site, internalaudit.icai.org.
Internal controls are risk mitigation steps that help prevent and detect errors and irregularities. The Board and management carry the overall responsibility for them (paragraph 4.5). The internal auditor must check the design, implementation and operating effectiveness of controls, direct work mainly at high and medium risk controls and keep a document such as a risk control matrix linking procedures to risks (paragraphs 5.2 and 5.3).
What SIA 120 says internal controls are
Paragraph 1.2 describes internal controls as systemic and procedural steps adopted by an organisation to mitigate risks, mainly in financial accounting and reporting, operational processing and compliance with laws. The actual steps, such as review, approval, physical count or segregation of duties, are "control activities" (paragraph 3.1). The standard then sorts controls in several ways, which is useful for planning any audit.
| Label in SIA 120 | Meaning | Example given or typical |
|---|---|---|
| Internal financial controls (IFCs) | Controls that mitigate the risk of financial exposure | Approval of payments, reconciliations |
| Operational controls (OCs) | Controls that mitigate operational risks | Production or dispatch checks |
| Entity level controls (ELCs) | Broad controls across the entity, part of the control environment | Code of conduct (paragraph 3.2) |
| Process level controls (PLCs) | Controls focused on one process | Order processing or payroll (paragraph 3.2) |
| Manual controls | Operate with human intervention | Supervisor review |
| IT general controls | Secure the systems | Access controls (paragraph 3.1) |
| Application controls | Check processing inside an application | Sequential numbering of invoices (paragraph 3.1) |
The "internal controls system" is the umbrella for all of these (paragraph 3.7). The control environment, meaning the culture, attitude and actions of the Board and management, influences how well the process controls operate. Businesses that want their control set mapped in this way can ask our compliance advisory team.
Internal controls and internal financial controls
SIA 120 explains (paragraph 3.6) that "internal controls" is a wider term than the legal "internal financial controls". The standard sets side by side the definition in the SA 315 framework, the narrower ICAI definition for internal financial controls over financial reporting, and the definition used in the Companies Act. Paragraph 4 then lists where the Act and the rules place the responsibility: the Directors' Responsibility Statement in section 134(5)(e), the Board's report under rule 8(5)(viii) of the Companies (Accounts) Rules, 2014, and the statutory auditor's reporting under section 143(3)(i). For what each of those provisions requires and to whom it applies, read our posts on the Directors' Responsibility Statement, internal financial controls under section 143(3)(i) and rules 10 and 10A; this article does not restate them. Listed entities have additional certification duties under SEBI rules that are outside this article.
Paragraph 3.9 also notes that an internal control framework is a benchmark against which a control system can be assessed, and names the COSO framework as a widely used global example; Appendix 1 of SA 315 is given for the Indian context.
What the internal auditor must do (paragraph 5)
- Make controls part of the scope. The mandate comes from those charged with governance, generally the audit committee for listed entities, and internal controls are a key part of scope and approach (paragraph 5.1).
- Check design, implementation and operation. Procedures must be enough to check that the controls are designed, properly implemented and operating effectively. Shortcomings lead to recommendations for improvement and for making controls more efficient (paragraph 5.2).
- Anchor to the risk assessment. Review the risk assessment done at planning as the basis for judging whether adequate controls exist, direct procedures primarily at high and medium risk controls, and keep documentation such as a risk control matrix to show the linkage of procedure to risk (paragraph 5.3).
- Treat an opinion as assurance. Where the internal auditor gives an opinion on the presence, design, implementation or operating effectiveness of controls, SIA 110 applies and a clear understanding of the control framework is needed. A written assurance report should consider an evaluation of control self-assessment by control owners and compliance certificates from owners of key controls (paragraph 5.4).
- Document scope for statutory auditor reliance. Where the statutory auditor relies on internal audit work for internal financial controls over financial reporting under SA 610, the internal auditor documents the objectives, agreed scope and approach on which reliance is to be placed (paragraph 5.5). See our SA 610 guide.
Design versus operating effectiveness
A control can be well designed and still fail because nobody performs it. Design testing asks whether the control, if performed as described, would prevent or catch the risk. Operating testing asks whether it was performed, by the right person, on every occasion tested. SIA 120 says both must be covered but leaves the tests to the auditor's judgement. The choice of sample and analytics belongs to the SIA 5 and SIA 6 articles and to the function-wise guides, such as our one on procurement and inventory.
Illustrative example
Illustrative: Greenfield Packaging Ltd has a payables process in which any purchase over an approved limit needs a second approver. The internal auditor's risk control matrix lists the risk (unauthorised or duplicated payment), the control (second approval in the accounting system), the control owner and the planned test. Design review shows the system lets the same user act as maker and approver when the second approver is on leave; that is a design gap. Operating testing of 40 payments above the limit finds two with approvals dated after the payment. The report records both findings separately: one as a design weakness with a recommendation to block self-approval, one as an operating exception with the cause given. The statutory auditor, who plans reliance under SA 610, receives the documented scope and approach.
Common lapses
- Reviewing only the written policy and not testing that the control operates.
- Treating internal financial controls as a statutory audit matter alone and not scoping them in the internal audit plan.
- A risk control matrix that is copied from the last year and not linked to the current risk assessment.
- Testing low-risk controls in depth while a key control gets a token check.
- Reporting that "controls are adequate" without saying what was tested.
Need help with an internal controls review?
If you are building a risk control matrix or want an independent view of whether your key controls work, our team can assist through compliance advisory and help you document the findings.
Key takeaways
- Internal controls are wider than the legal term internal financial controls (SIA 120, paragraph 3.6).
- The Board and management are responsible for designing and operating controls (paragraph 4.5).
- The internal auditor tests design, implementation and operating effectiveness, concentrating on high and medium risk controls (paragraphs 5.2 and 5.3).
- A risk control matrix links audit procedures to risks (paragraph 5.3).
- Provisions of the Companies Act on internal financial controls are explained in the linked posts.
Read next
- Standards on Internal Audit: framework, basic principles and which SIAs are mandatory
- SIA 110, 130, 140 and 150: assurance, risk, governance and compliance
- Internal audit of procurement and inventory
- SA 265: communicating deficiencies in internal control
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
