SIA 310 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Once the annual plan says which unit will be audited, four ICAI standards govern the assignment itself: how it is planned, what evidence is gathered, how the working papers are kept and how the work is reviewed. They are the practical core of any internal audit and a reliable guide to what an internal auditor will ask your team for. Where a business needs its audit paperwork put in order first, our compliance documentation service covers that.
This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). Each of the four applies to internal audits beginning on or after a date to be notified by the Council. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner. Check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.
The assignment plan is risk-based, approved by the Chief Internal Auditor and turned into a written Internal Audit Programme (SIA 310). Evidence must be sufficient, appropriate, from reliable sources and recorded (SIA 320). Working papers must be reproducible, show who performed and who reviewed each step, and be complete before the final report is issued (SIA 330). Every working paper gets at least one level of review (SIA 350).
SIA 310: planning the internal audit assignment
SIA 310 covers the second level of planning, for one auditable unit, under the overall plan covered in our article on SIA 210 to 250 and SIA 7 (paragraph 1.2). The auditable unit may be a location, function, business unit or legal entity, including third parties where relevant.
| Requirement | What the auditor does | Paragraph |
|---|---|---|
| Laid-down process, written plan | Plan covers technology and resource allocation | 3.1 |
| Approval | Chief Internal Auditor or engagement partner approves | 3.2 |
| Know the unit | Study business, environment, regulation; talk to management and process owners; share relevant information, such as risk assessment, with the statutory auditor | 3.3, 4.2, 4.3 |
| Risk assessment | Independent assessment aligned with management's; identify key controls to test; missing controls point to design gaps | 3.4, 4.4 |
| Methodology and programme | Fix methodology and depth, documented in an Internal Audit Programme (IAP) | 3.5, 4.5 |
| Tell the auditee | Share the elements needed for smooth conduct before procedures start | 3.6 |
| Monitor and change | Major changes only after consulting the approvers, documented and communicated | 3.7 |
Paragraph 4.5 is worth noting for businesses that expect only a voucher check. The basic method is compliance testing of transactions and balances against policy, but the standard says depth of coverage should go beyond that: a process review testing design and operating efficiency of controls, a risk-based process review linking controls to vulnerabilities, or an entity-level control review of culture, structure, oversight and performance measurement. The plan aligns the depth with the assurance to be given. Documentation includes checklists, information gathered, meeting summaries, the risk assessment with controls identified, resources against skills, the detailed IAP and the approved plan (paragraph 4.8).
SIA 320: internal audit evidence
Internal audit evidence is all information used to reach the conclusions on which the opinion is based, from the entity's records and from audit procedures (paragraph 1.1). The standard does not cover sampling or data analytics techniques, which have their own standards (paragraph 1.3); our article on SIA 5 and SIA 6 does. Its requirements:
- Obtain sufficient and appropriate evidence that supports findings and reliable conclusions, complementary and relevant to the objective (paragraph 3.1). Sufficiency is quantity; appropriateness is quality, relevance and reliability (paragraph 4.1).
- Take evidence from reliable sources, consistent with one another (paragraph 3.2). Reliability depends on source, type, thoroughness and timing, and where doubt or conflict arises the auditor modifies or expands the procedures (paragraph 4.2).
- Record all evidence, and keep a written process for how it is gathered, reviewed, documented and stored (paragraph 3.3). Digital evidence must be reproducible and reviewable independently of the auditor (paragraph 4.3).
Paragraph 4.1 lists the ways evidence is gathered: checking, inspection, observation, inquiry, confirmation, computation, re-performance, analytical review and the help of experts. For the statutory audit equivalent, see our guide to SA 500 audit evidence.
SIA 330: internal audit documentation
Documentation is the written record, electronic or otherwise, of procedures, evidence and conclusions; "work papers" and "working papers" mean the same (paragraph 1.1). It must stand on its own, without follow-up clarification, for another person to reach the same conclusion (paragraph 2.2). Requirements:
- Record the nature, timing and extent of all procedures in reproducible documents (paragraph 3.1).
- Make documentation complete and sufficient to support analysis, findings, observations and the report, stating the purpose of each procedure, the source of evidence, the outcome and the performer and reviewer (paragraph 3.2).
- Keep a written process for preparing, reviewing, storing and finally discarding working papers (paragraph 3.3).
- Complete the work paper files before the final report is issued, with pending administrative matters closed within sixty days of its release (paragraph 3.4).
- Ownership and custody stay with the Internal Auditor. Where outsourced work or an expert's papers are relied on, the auditor takes ownership; where only the third party's report is relied on and its papers are retained, there must be a way to access them when required (paragraph 3.5).
The explanatory comments add that it is neither practical nor necessary to document every observation, but all significant matters involving judgement and the conclusion on them must be included (paragraph 4.2); papers must undergo at least one level of review and be dependable enough that a peer reviewer reaches the same conclusion; papers are retained under law and company policy and released to outsiders only with legal advice or approval where needed (paragraph 4.3). The final report is not released until all significant evidence is collected and documented (paragraph 4.4). The statutory audit counterpart is explained in our SA 230 guide.
SIA 350: review and supervision
"Review" is the examination of plan, procedures, evidence, conclusions and working papers, generally after the work; "supervision" is the on-going oversight and guidance (paragraph 1.2). The standard applies to in-house and outsourced work and to advisory assignments (paragraph 1.3).
- The Chief Internal Auditor or engagement partner holds overall responsibility and all documentation gets at least one level of review (paragraph 3.1). Review may be delegated to an experienced person, but responsibility stays (paragraph 4.1).
- The frequency and extent of review are planned and documented at the planning stage (paragraph 3.2).
- The reviewer checks that the papers are enough to reach the same conclusions and observations; evidence of review, and of any procedures done afterwards, is recorded (paragraph 3.3).
- A written process for review and supervision is kept (paragraph 3.4); records include the signature and date of review, follow-up points and minutes of review meetings (paragraph 4.4).
Illustrative example
Illustrative: Banyan Auto Components Ltd's internal auditor plans a review of the stores unit. After a walk-through and a risk assessment that rates issue-slip approval as high risk, the auditor writes a programme with six objectives, each with its tests. Working papers record for every test its purpose, the source documents, the result, the preparer's initials and date, and the manager's review note. A reviewer finds one paper where a sample of 25 issue slips was tested but the selection basis was not recorded, so the manager has the sample re-selected and documents it before the draft report. The files are assembled and signed off before the final report goes to the audit committee, and the remaining admin tasks are closed within sixty days.
Common lapses
- A programme copied from another unit with no link to the risk assessment.
- Test results ticked in a checklist with no evidence reference.
- No record of who prepared and who reviewed a paper.
- Files completed after the report is issued.
- Evidence from only one source for a significant finding.
Need help documenting an internal audit?
If your team is setting up working paper formats or you want an assignment plan and programme drawn up for a unit, our team can help through compliance documentation to keep the record complete and reviewable.
Key takeaways
- The assignment plan rests on an independent risk assessment and a written Internal Audit Programme (SIA 310, paragraphs 3.4 and 3.5).
- Evidence must be sufficient, appropriate, from reliable sources and recorded in reproducible form (SIA 320).
- Working papers show purpose, source, outcome, performer and reviewer, and are complete before the final report (SIA 330, paragraphs 3.2 and 3.4).
- Ownership of working papers stays with the Internal Auditor (SIA 330, paragraph 3.5).
- Every working paper receives at least one level of review (SIA 350, paragraph 3.1).
Read next
- SIA 210 to 250 and SIA 7: managing the internal audit function
- SIA 5 and SIA 6: sampling and analytical procedures
- SIA 360, 370 and 390: internal audit report and follow-up
- SA 230: audit documentation
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
