SIA 210 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
An internal audit function is only as good as the way it is run: who leads it, how it plans the year, what document defines its job, when it brings in specialists, what it tells the audit committee and how its own quality is checked. These six ICAI standards cover that management layer. This guide is for finance heads, audit committee members, firms appointed as internal auditors and students.
This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). SIA 210 to 250 apply to internal audits beginning on or after a date to be notified by the Council. SIA 7 belongs to the older group published as on 1 July 2013 and is recommendatory in its own front note until the Council notifies a date, and its effective-date paragraph is left blank. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner. Check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.
The Chief Internal Auditor is responsible for achieving the function's objectives through a documented audit process (SIA 210). The overall plan is risk-based, built on an audit universe and approved by the Board or audit committee (SIA 220). The function works under a written charter, or an engagement letter if outsourced, signed before work starts (SIA 230). Experts are used on an independent judgement (SIA 240), and communication with those charged with governance follows a pre-agreed process (SIA 250).
SIA 210: managing the internal audit function
The Chief Internal Auditor, or the person designated, is responsible for the function's activities: planning, overseeing assignments, resourcing, engaging experts, communicating with stakeholders and running a quality programme (paragraphs 1.2 and 1.3). For a company that must have an internal auditor under section 138, the individual or firm notified as the internal auditor is expected to act as Chief Internal Auditor; where internal audit is partly outsourced, the outside partner may not be able to take overall responsibility, and the limitation is documented in the terms of engagement (paragraph 1.4). Our posts on section 138 and rule 13 applicability explain who must appoint an internal auditor.
The requirements (paragraph 3) are four: a well-documented internal audit process, which the explanatory comments say should be collected in an internal audit manual; a resourcing plan matching skills to planned assignments, outsourced if not available in-house; execution, review and supervision according to the process, with progress tracked against time budgets; and a formal quality evaluation and improvement programme, run by someone with the skills and authority to act on non-compliance. Documentation includes the manual, resourcing plan, progress reports and the quality programme (paragraph 4.5).
SIA 220: the overall internal audit plan
Planning happens at two levels: an overall plan for the entity, usually yearly, presented to the Board or audit committee; and individual assignment plans, which SIA 310 covers (paragraph 1.1). SIA 220 notes that rule 13(2) of the Companies (Accounts) Rules, 2014 has the audit committee or Board formulate scope, functioning, periodicity and methodology in consultation with the internal auditor (paragraph 1.3).
| Requirement | What it means in practice | Paragraph |
|---|---|---|
| Laid-down process, written plan | Plan covers technology deployment and resource allocation | 3.1 |
| Approval | Reviewed and approved by the Board or audit committee | 3.2 |
| Knowledge of the business | Understand environment and each auditable unit; discuss with management | 3.3 |
| Audit universe | List all locations, functions, business units, entities and relevant third parties before fixing scope | 3.4, 4.4 |
| Risk-based plan | Independent risk assessment, aligned with management's and the statutory auditor's, to focus on high-risk areas | 3.5, 4.5 |
| Monitoring and changes | Significant plan changes only after consulting those who approved it, documented with reasons | 3.6 |
Scope limits imposed by management must be shown clearly in the plan sent to the approving body (paragraph 4.4), and the approved plan is kept with the supporting risk assessment and audit universe (paragraph 4.8). Businesses that want help drawing up a year plan from a risk map can consult our virtual CFO services team.
SIA 230: objectives, charter and engagement letter
Objectives of internal audit are set by those charged with governance and, for companies under rule 13, by the audit committee or Board with management and the Chief of Internal Audit (paragraph 1.2); elsewhere, by whoever appoints the auditor (paragraph 1.3). They are recorded either in an Internal Audit Charter for an in-house team or in an Engagement Letter with an outsourced provider (paragraph 2.2).
- The Chief of Internal Audit must have a written charter documenting the formation and functioning of the activity (paragraph 3.1).
- Where part of the work is outsourced, a formal engagement letter is required; if all of it is, the engagement partner acts as the Chief of Internal Audit (paragraph 3.2).
- The Board or audit committee approves the charter; the engagement letter is approved by the competent authority under the delegation of powers, or by the Board or audit committee if all work is outsourced (paragraph 3.3).
- Documents are communicated through formal channels (3.4) and reviewed periodically (3.5).
- A signed engagement letter is obtained before any audit work begins (paragraph 4.3).
The charter's headings include purpose, reporting structure and independence, scope, authority, roles and quality assurance; the engagement letter's add confidentiality, reporting and compensation, ownership of working papers and termination (paragraphs 4.1 and 4.2). For the drafting of such terms, see our guides on service contracts and internal audit agreements and the board resolution for appointing an internal auditor.
SIA 240: using the work of an expert
An expert is a person or entity with special skills and experience, for example in IT, engineering, actuarial work, forensic work, taxation or treasury (paragraph 1.2). An outside firm with accounting and audit expertise engaged for regular internal audit services is not an expert for this standard (paragraph 1.4). The requirements:
- Decide independently whether to use an expert, considering technicality, risk and materiality, and the gap in internal skills (paragraph 3.1).
- Have the authority to select and engage the expert; where management holds it, validate independence and objectivity and share concerns with management and those charged with governance (paragraph 3.2).
- Independently evaluate qualifications and credentials (paragraph 3.3).
- Where findings go into an assurance report, take part in defining scope, approach and work (paragraph 3.4).
- Evaluate whether the work is appropriate and reliable evidence (paragraph 3.5).
- Retain ultimate responsibility; paragraph 3.6 adds that the internal auditor shall not refer to the expert's work in the internal audit report. This differs from FAIS 230 for forensic engagements, which asks the report to state the expert's role; the two standards apply to different engagements.
SIA 250: communication with those charged with governance
Communication must be independent, objective, effective and timely (paragraph 3.1). A formal process, pre-agreed with those charged with governance, sets the form, the manner and the timing (paragraph 3.2). Essential matters include the annual plan with resources and budget, the risk assessment outcome, periodic updates on significant observations with corrective action, the function's own progress and constraints, and the status of prior audit issues with an action taken report (paragraph 4.3). Sensitive matters such as management override of controls, possible fraud indicators and scope limitations, for example long delays or unreasonably short time, are raised with management, agreed for communication, and taken to those charged with governance; the auditor may even issue a disclaimer on scope (paragraphs 3.4 and 4.4).
SIA 7: quality assurance in internal audit
SIA 7 asks for a person responsible for quality and a quality system covering leadership, ethics, acceptance of engagements, human resources, performance and monitoring (paragraphs 6 and 7). Internal quality reviews are ongoing, with results and an action plan going to management and those charged with governance (paragraphs 11 to 14). External quality review is called a critical factor, and its frequency should not in any case be less than once in three years (paragraph 15).
Illustrative example
Illustrative: Lotus Chemicals Ltd appoints a chartered accountant firm for a full outsourced internal audit. The engagement partner acts as Chief of Internal Audit and signs an engagement letter, approved by the audit committee, before any fieldwork. The audit universe lists three plants and two subsidiaries; a risk assessment puts one plant's effluent controls and a subsidiary's treasury first. In August the committee agrees to defer a low-risk review and the change is minuted. A hired environmental engineer's findings are used, after the partner checks credentials and independence, and the report states the conclusions as the firm's own.
Common lapses
- Fieldwork starting before the engagement letter is signed.
- A plan copied from last year with no audit universe or risk assessment.
- Plan changes made informally, with no approval.
Need help setting up the internal audit function?
If you are drawing up an annual internal audit plan or reviewing how your function reports to the audit committee, our team can help through virtual CFO services, including the risk map the plan starts from.
Key takeaways
- The Chief Internal Auditor owns a documented audit process, a resourcing plan and a quality programme (SIA 210).
- The overall plan is risk-based, rests on an audit universe and is approved by the Board or audit committee (SIA 220).
- A charter or a signed engagement letter must exist before audit work starts (SIA 230).
- The internal auditor decides independently on experts and keeps responsibility for conclusions (SIA 240).
- Communication with those charged with governance follows a pre-agreed process; external quality review is not less than once in three years (SIA 250, SIA 7).
Read next
- Standards on Internal Audit: framework, basic principles and which SIAs are mandatory
- SIA 310, 320, 330 and 350: planning an assignment, evidence, documentation and review
- SIA 360, 370 and 390: internal audit report and follow-up
- Section 177: the audit committee
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
