Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates

SIA 210, 220, 230, 240, 250 and SIA 7: managing the internal audit function, the overall internal audit plan, objectives and the audit charter, using an expert, communication with those charged with governance and quality assurance

The Chief Internal Auditor is responsible for achieving the function's objectives through a documented audit process (SIA 210). The overall plan is risk-based, built on an audit...

Published
Updated
Reading time
9 min
Views
6
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 8, 2026
Reading time
9 min
0:00
Last updated: October 2026Verified against: Government sources

An internal audit function is only as good as the way it is run: who leads it, how it plans the year, what document defines its job, when it brings in specialists, what it tells the audit committee and how its own quality is checked. These six ICAI standards cover that management layer. This guide is for finance heads, audit committee members, firms appointed as internal auditors and students.

This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). SIA 210 to 250 apply to internal audits beginning on or after a date to be notified by the Council. SIA 7 belongs to the older group published as on 1 July 2013 and is recommendatory in its own front note until the Council notifies a date, and its effective-date paragraph is left blank. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner. Check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.

SIA 210: managing the internal audit function

The Chief Internal Auditor, or the person designated, is responsible for the function's activities: planning, overseeing assignments, resourcing, engaging experts, communicating with stakeholders and running a quality programme (paragraphs 1.2 and 1.3). For a company that must have an internal auditor under section 138, the individual or firm notified as the internal auditor is expected to act as Chief Internal Auditor; where internal audit is partly outsourced, the outside partner may not be able to take overall responsibility, and the limitation is documented in the terms of engagement (paragraph 1.4). Our posts on section 138 and rule 13 applicability explain who must appoint an internal auditor.

The requirements (paragraph 3) are four: a well-documented internal audit process, which the explanatory comments say should be collected in an internal audit manual; a resourcing plan matching skills to planned assignments, outsourced if not available in-house; execution, review and supervision according to the process, with progress tracked against time budgets; and a formal quality evaluation and improvement programme, run by someone with the skills and authority to act on non-compliance. Documentation includes the manual, resourcing plan, progress reports and the quality programme (paragraph 4.5).

SIA 220: the overall internal audit plan

Planning happens at two levels: an overall plan for the entity, usually yearly, presented to the Board or audit committee; and individual assignment plans, which SIA 310 covers (paragraph 1.1). SIA 220 notes that rule 13(2) of the Companies (Accounts) Rules, 2014 has the audit committee or Board formulate scope, functioning, periodicity and methodology in consultation with the internal auditor (paragraph 1.3).

RequirementWhat it means in practiceParagraph
Laid-down process, written planPlan covers technology deployment and resource allocation3.1
ApprovalReviewed and approved by the Board or audit committee3.2
Knowledge of the businessUnderstand environment and each auditable unit; discuss with management3.3
Audit universeList all locations, functions, business units, entities and relevant third parties before fixing scope3.4, 4.4
Risk-based planIndependent risk assessment, aligned with management's and the statutory auditor's, to focus on high-risk areas3.5, 4.5
Monitoring and changesSignificant plan changes only after consulting those who approved it, documented with reasons3.6

Scope limits imposed by management must be shown clearly in the plan sent to the approving body (paragraph 4.4), and the approved plan is kept with the supporting risk assessment and audit universe (paragraph 4.8). Businesses that want help drawing up a year plan from a risk map can consult our virtual CFO services team.

SIA 230: objectives, charter and engagement letter

Objectives of internal audit are set by those charged with governance and, for companies under rule 13, by the audit committee or Board with management and the Chief of Internal Audit (paragraph 1.2); elsewhere, by whoever appoints the auditor (paragraph 1.3). They are recorded either in an Internal Audit Charter for an in-house team or in an Engagement Letter with an outsourced provider (paragraph 2.2).

  • The Chief of Internal Audit must have a written charter documenting the formation and functioning of the activity (paragraph 3.1).
  • Where part of the work is outsourced, a formal engagement letter is required; if all of it is, the engagement partner acts as the Chief of Internal Audit (paragraph 3.2).
  • The Board or audit committee approves the charter; the engagement letter is approved by the competent authority under the delegation of powers, or by the Board or audit committee if all work is outsourced (paragraph 3.3).
  • Documents are communicated through formal channels (3.4) and reviewed periodically (3.5).
  • A signed engagement letter is obtained before any audit work begins (paragraph 4.3).

The charter's headings include purpose, reporting structure and independence, scope, authority, roles and quality assurance; the engagement letter's add confidentiality, reporting and compensation, ownership of working papers and termination (paragraphs 4.1 and 4.2). For the drafting of such terms, see our guides on service contracts and internal audit agreements and the board resolution for appointing an internal auditor.

SIA 240: using the work of an expert

An expert is a person or entity with special skills and experience, for example in IT, engineering, actuarial work, forensic work, taxation or treasury (paragraph 1.2). An outside firm with accounting and audit expertise engaged for regular internal audit services is not an expert for this standard (paragraph 1.4). The requirements:

  1. Decide independently whether to use an expert, considering technicality, risk and materiality, and the gap in internal skills (paragraph 3.1).
  2. Have the authority to select and engage the expert; where management holds it, validate independence and objectivity and share concerns with management and those charged with governance (paragraph 3.2).
  3. Independently evaluate qualifications and credentials (paragraph 3.3).
  4. Where findings go into an assurance report, take part in defining scope, approach and work (paragraph 3.4).
  5. Evaluate whether the work is appropriate and reliable evidence (paragraph 3.5).
  6. Retain ultimate responsibility; paragraph 3.6 adds that the internal auditor shall not refer to the expert's work in the internal audit report. This differs from FAIS 230 for forensic engagements, which asks the report to state the expert's role; the two standards apply to different engagements.

SIA 250: communication with those charged with governance

Communication must be independent, objective, effective and timely (paragraph 3.1). A formal process, pre-agreed with those charged with governance, sets the form, the manner and the timing (paragraph 3.2). Essential matters include the annual plan with resources and budget, the risk assessment outcome, periodic updates on significant observations with corrective action, the function's own progress and constraints, and the status of prior audit issues with an action taken report (paragraph 4.3). Sensitive matters such as management override of controls, possible fraud indicators and scope limitations, for example long delays or unreasonably short time, are raised with management, agreed for communication, and taken to those charged with governance; the auditor may even issue a disclaimer on scope (paragraphs 3.4 and 4.4).

SIA 7: quality assurance in internal audit

SIA 7 asks for a person responsible for quality and a quality system covering leadership, ethics, acceptance of engagements, human resources, performance and monitoring (paragraphs 6 and 7). Internal quality reviews are ongoing, with results and an action plan going to management and those charged with governance (paragraphs 11 to 14). External quality review is called a critical factor, and its frequency should not in any case be less than once in three years (paragraph 15).

Illustrative example

Illustrative: Lotus Chemicals Ltd appoints a chartered accountant firm for a full outsourced internal audit. The engagement partner acts as Chief of Internal Audit and signs an engagement letter, approved by the audit committee, before any fieldwork. The audit universe lists three plants and two subsidiaries; a risk assessment puts one plant's effluent controls and a subsidiary's treasury first. In August the committee agrees to defer a low-risk review and the change is minuted. A hired environmental engineer's findings are used, after the partner checks credentials and independence, and the report states the conclusions as the firm's own.

Common lapses

  • Fieldwork starting before the engagement letter is signed.
  • A plan copied from last year with no audit universe or risk assessment.
  • Plan changes made informally, with no approval.

Need help setting up the internal audit function?

If you are drawing up an annual internal audit plan or reviewing how your function reports to the audit committee, our team can help through virtual CFO services, including the risk map the plan starts from.

Key takeaways

  • The Chief Internal Auditor owns a documented audit process, a resourcing plan and a quality programme (SIA 210).
  • The overall plan is risk-based, rests on an audit universe and is approved by the Board or audit committee (SIA 220).
  • A charter or a signed engagement letter must exist before audit work starts (SIA 230).
  • The internal auditor decides independently on experts and keeps responsibility for conclusions (SIA 240).
  • Communication with those charged with governance follows a pre-agreed process; external quality review is not less than once in three years (SIA 250, SIA 7).

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SIA 210

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What is an audit universe?

The list of all auditable units: locations, functions, business units and legal entities, including third parties where relevant (SIA 220, paragraph 4.4).

Who approves the annual internal audit plan?

The highest governing body responsible for internal audits, normally the Board or the audit committee (SIA 220, paragraph 3.2).

Reconcile the bank first; most other errors show themselves once it agrees.

— TaxClue Accounts & Audit Desk

SIA 210: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

The list of all auditable units: locations, functions, business units and legal entities, including third parties where relevant (SIA 220, paragraph 4.4).

The highest governing body responsible for internal audits, normally the Board or the audit committee (SIA 220, paragraph 3.2).

Where part or all of internal audit is outsourced, and it must be signed before audit work begins (SIA 230, paragraphs 3.2 and 4.3).

SIA 240 paragraph 3.6 says the internal auditor shall not refer to the work of an expert in the internal audit report and keeps ultimate responsibility.

SIA 7 paragraph 15 says the frequency should not in any case be less than once in three years. SIA 7 is recommendatory in its front note until notified; check current status.

SIA 250 paragraph 4.3 lists essential matters such as the plan, the risk assessment outcome, significant observations and the status of prior issues.