Next due
7 OCTTDS / TCS deposit · Deducted in Sep 2026in 2 days 11 OCTGSTR-1 · Outward supplies · Sep 2026in 6 days 15 OCTPF & ESI · Contributions · Sep 2026in 10 days 20 OCTGSTR-3B · Summary return · Sep 2026in 15 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 25 days 31 OCTITR filing · Audit cases · AY 2026-27in 26 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 55 days 15 DECAdvance Tax · 3rd (75%) instalment · FY 2026-27in 71 days
All due dates

SIA 310, SIA 320, SIA 330 and SIA 350: planning an internal audit assignment, obtaining evidence, documentation and working papers, and review and supervision of the work

The assignment plan is risk-based, approved by the Chief Internal Auditor and turned into a written Internal Audit Programme (SIA 310). Evidence must be sufficient, appropriate...

Published
Updated
Reading time
8 min
Views
4
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 5, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Once the annual plan says which unit will be audited, four ICAI standards govern the assignment itself: how it is planned, what evidence is gathered, how the working papers are kept and how the work is reviewed. They are the practical core of any internal audit and a reliable guide to what an internal auditor will ask your team for. Where a business needs its audit paperwork put in order first, our compliance documentation service covers that.

This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). Each of the four applies to internal audits beginning on or after a date to be notified by the Council. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner. Check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.

SIA 310: planning the internal audit assignment

SIA 310 covers the second level of planning, for one auditable unit, under the overall plan covered in our article on SIA 210 to 250 and SIA 7 (paragraph 1.2). The auditable unit may be a location, function, business unit or legal entity, including third parties where relevant.

RequirementWhat the auditor doesParagraph
Laid-down process, written planPlan covers technology and resource allocation3.1
ApprovalChief Internal Auditor or engagement partner approves3.2
Know the unitStudy business, environment, regulation; talk to management and process owners; share relevant information, such as risk assessment, with the statutory auditor3.3, 4.2, 4.3
Risk assessmentIndependent assessment aligned with management's; identify key controls to test; missing controls point to design gaps3.4, 4.4
Methodology and programmeFix methodology and depth, documented in an Internal Audit Programme (IAP)3.5, 4.5
Tell the auditeeShare the elements needed for smooth conduct before procedures start3.6
Monitor and changeMajor changes only after consulting the approvers, documented and communicated3.7

Paragraph 4.5 is worth noting for businesses that expect only a voucher check. The basic method is compliance testing of transactions and balances against policy, but the standard says depth of coverage should go beyond that: a process review testing design and operating efficiency of controls, a risk-based process review linking controls to vulnerabilities, or an entity-level control review of culture, structure, oversight and performance measurement. The plan aligns the depth with the assurance to be given. Documentation includes checklists, information gathered, meeting summaries, the risk assessment with controls identified, resources against skills, the detailed IAP and the approved plan (paragraph 4.8).

SIA 320: internal audit evidence

Internal audit evidence is all information used to reach the conclusions on which the opinion is based, from the entity's records and from audit procedures (paragraph 1.1). The standard does not cover sampling or data analytics techniques, which have their own standards (paragraph 1.3); our article on SIA 5 and SIA 6 does. Its requirements:

  • Obtain sufficient and appropriate evidence that supports findings and reliable conclusions, complementary and relevant to the objective (paragraph 3.1). Sufficiency is quantity; appropriateness is quality, relevance and reliability (paragraph 4.1).
  • Take evidence from reliable sources, consistent with one another (paragraph 3.2). Reliability depends on source, type, thoroughness and timing, and where doubt or conflict arises the auditor modifies or expands the procedures (paragraph 4.2).
  • Record all evidence, and keep a written process for how it is gathered, reviewed, documented and stored (paragraph 3.3). Digital evidence must be reproducible and reviewable independently of the auditor (paragraph 4.3).

Paragraph 4.1 lists the ways evidence is gathered: checking, inspection, observation, inquiry, confirmation, computation, re-performance, analytical review and the help of experts. For the statutory audit equivalent, see our guide to SA 500 audit evidence.

SIA 330: internal audit documentation

Documentation is the written record, electronic or otherwise, of procedures, evidence and conclusions; "work papers" and "working papers" mean the same (paragraph 1.1). It must stand on its own, without follow-up clarification, for another person to reach the same conclusion (paragraph 2.2). Requirements:

  1. Record the nature, timing and extent of all procedures in reproducible documents (paragraph 3.1).
  2. Make documentation complete and sufficient to support analysis, findings, observations and the report, stating the purpose of each procedure, the source of evidence, the outcome and the performer and reviewer (paragraph 3.2).
  3. Keep a written process for preparing, reviewing, storing and finally discarding working papers (paragraph 3.3).
  4. Complete the work paper files before the final report is issued, with pending administrative matters closed within sixty days of its release (paragraph 3.4).
  5. Ownership and custody stay with the Internal Auditor. Where outsourced work or an expert's papers are relied on, the auditor takes ownership; where only the third party's report is relied on and its papers are retained, there must be a way to access them when required (paragraph 3.5).

The explanatory comments add that it is neither practical nor necessary to document every observation, but all significant matters involving judgement and the conclusion on them must be included (paragraph 4.2); papers must undergo at least one level of review and be dependable enough that a peer reviewer reaches the same conclusion; papers are retained under law and company policy and released to outsiders only with legal advice or approval where needed (paragraph 4.3). The final report is not released until all significant evidence is collected and documented (paragraph 4.4). The statutory audit counterpart is explained in our SA 230 guide.

SIA 350: review and supervision

"Review" is the examination of plan, procedures, evidence, conclusions and working papers, generally after the work; "supervision" is the on-going oversight and guidance (paragraph 1.2). The standard applies to in-house and outsourced work and to advisory assignments (paragraph 1.3).

  • The Chief Internal Auditor or engagement partner holds overall responsibility and all documentation gets at least one level of review (paragraph 3.1). Review may be delegated to an experienced person, but responsibility stays (paragraph 4.1).
  • The frequency and extent of review are planned and documented at the planning stage (paragraph 3.2).
  • The reviewer checks that the papers are enough to reach the same conclusions and observations; evidence of review, and of any procedures done afterwards, is recorded (paragraph 3.3).
  • A written process for review and supervision is kept (paragraph 3.4); records include the signature and date of review, follow-up points and minutes of review meetings (paragraph 4.4).

Illustrative example

Illustrative: Banyan Auto Components Ltd's internal auditor plans a review of the stores unit. After a walk-through and a risk assessment that rates issue-slip approval as high risk, the auditor writes a programme with six objectives, each with its tests. Working papers record for every test its purpose, the source documents, the result, the preparer's initials and date, and the manager's review note. A reviewer finds one paper where a sample of 25 issue slips was tested but the selection basis was not recorded, so the manager has the sample re-selected and documents it before the draft report. The files are assembled and signed off before the final report goes to the audit committee, and the remaining admin tasks are closed within sixty days.

Common lapses

  • A programme copied from another unit with no link to the risk assessment.
  • Test results ticked in a checklist with no evidence reference.
  • No record of who prepared and who reviewed a paper.
  • Files completed after the report is issued.
  • Evidence from only one source for a significant finding.

Need help documenting an internal audit?

If your team is setting up working paper formats or you want an assignment plan and programme drawn up for a unit, our team can help through compliance documentation to keep the record complete and reviewable.

Key takeaways

  • The assignment plan rests on an independent risk assessment and a written Internal Audit Programme (SIA 310, paragraphs 3.4 and 3.5).
  • Evidence must be sufficient, appropriate, from reliable sources and recorded in reproducible form (SIA 320).
  • Working papers show purpose, source, outcome, performer and reviewer, and are complete before the final report (SIA 330, paragraphs 3.2 and 3.4).
  • Ownership of working papers stays with the Internal Auditor (SIA 330, paragraph 3.5).
  • Every working paper receives at least one level of review (SIA 350, paragraph 3.1).

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SIA 310

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What is an Internal Audit Programme?

The detailed document listing the audit procedures for each audit objective in line with the chosen methodology (SIA 310, paragraphs 3.5 and 4.8).

Does the working paper file have to be complete before the report is issued?

Yes. SIA 330 paragraph 3.4 says the files are completed before the final report, and pending administrative matters within sixty days of its release.

A clean record is built one small filing at a time, not in the week before an inspection.

— TaxClue Compliance Desk

SIA 310: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,327 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

The detailed document listing the audit procedures for each audit objective in line with the chosen methodology (SIA 310, paragraphs 3.5 and 4.8).

Yes. SIA 330 paragraph 3.4 says the files are completed before the final report, and pending administrative matters within sixty days of its release.

The Internal Auditor. Where outsourced work is relied on, ownership is assumed from the third party, or access is arranged if only the report is relied on (SIA 330, paragraph 3.5).

No. Paragraph 4.2 of SIA 330 says all significant matters requiring judgement, with the conclusion, must be documented, but not every matter.

Review is usually done after the work; supervision is ongoing oversight and guidance (SIA 350, paragraph 1.2).

SIA 310 paragraph 3.6 requires the elements relevant to smooth conduct to be communicated to the auditee and stakeholders before procedures begin.