Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates

SIA 360, SIA 370 and SIA 390: communication with management, reporting the results of an internal audit and monitoring and reporting of prior audit issues

The internal auditor agrees a written communication protocol with management (SIA 360). No internal audit report is issued in final form unless a written draft has first been...

Published
Updated
Reading time
8 min
Views
8
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 8, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

An internal audit is only useful if the findings reach the right people in a usable form and are followed until they are closed. SIA 360, 370 and 390 cover those three links: talking to management during the audit, the report itself, and the tracking of open issues afterwards. If you are on the receiving end of an internal audit, these standards explain what you should expect to be given and asked. Teams that need their reporting records put in order can look at our compliance documentation service.

This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). Each of the three applies to internal audits beginning on or after a date to be notified by the Council. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner. Check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.

SIA 360: communication with management

Paragraph 1.1 asks for effective two-way communication with management throughout, and paragraph 2.1 gives the aims: agreement on scope, approach, objectives and timing, a continuous dialogue and timely resolution of conflicts. The requirements:

  • A written communication process and protocol is set up, shared and agreed with management (paragraph 3.1). It sets out who communicates with whom and the escalation route (paragraph 4.1).
  • The process covers modes and channels (verbal or written; phone, email or file exchange), periodicity and timelines, and the essential information to be communicated (paragraphs 3.2 and 4.2 to 4.4).
  • Essential matters communicated verbally are confirmed in writing and kept as audit documentation (paragraph 3.2).
  • The Chief Internal Auditor or engagement partner plays an active role in resolving conflicts (paragraph 3.3).

Paragraph 4.4 gives examples of essential communication: the type of assurance to be given under SIA 110 is agreed in writing before work starts, periodic progress meetings under SIA 210, and the discussion with management during assignment planning under SIA 310. Communication with those charged with governance is a separate subject; see our article on SIA 210 to 250 and SIA 7.

SIA 370: reporting results

Reporting happens in two stages (paragraph 1.2): a report on each assignment, issued to the auditee with copies to local and executive management as agreed at planning, and a periodic report on the whole plan period, normally quarterly, from the Chief Internal Auditor to the audit committee. SIA 370 deals only with the first. It does not cover the form of a report that gives a written opinion under SIA 110; that is for SIA 380, which is not in the compendium held. Our article on SIA 110, 130, 140 and 150 explains when an opinion is possible.

RequirementWhat it meansParagraph
Report contentsObjectives, scope and approach; the fact that the audit followed the Standards of Internal Audit; executive summary of key observations; corrective actions required or agreed for each observation; nature of assurance, if any3.1
AssuranceAs pre-agreed with the auditee at planning, in line with SIA 1103.2
Form and contentSet by the auditor's professional judgement, in consultation with the auditee3.3, 4.3
Draft firstNo final report without a written draft shared with the auditee3.3
TimingWithin a reasonable time after the work is completed3.4

Paragraph 4.1 says conclusions rest on all the findings and not a few deviations; controls that work are acknowledged, while risk and significance decide what is prioritised for reporting. Where the audit followed the SIAs and the evidence supports it, the report states that the audit was conducted "in accordance with the Standards of Internal Audit issued by the Institute of Chartered Accountants of India" (paragraph 4.2). Copies of the drafts and final report, cross-referenced to observations, are kept, and management action plans may be countersigned (paragraph 4.4).

What a useful observation contains

The standard does not prescribe a format. A workable layout, which is our own illustration and not from the standard, is: the observation in one sentence; the criteria it is measured against; the evidence found and its extent; the risk and why it matters; the recommendation; management's response with an owner and a date; and a risk rating. Sharing the draft lets the auditee correct facts before the report is final.

SIA 390: monitoring and reporting of prior audit issues

SIA 390 covers the tracking of issues from earlier audits, usually through an action taken report (paragraph 1.1). The Chief Internal Auditor is responsible for monitoring closure through a formal process pre-agreed with management and those charged with governance, but the responsibility to carry out the action plans stays with management (paragraph 3.1).

  1. Verify, do not just accept. After the auditee confirms implementation, the auditor performs additional procedures to confirm the issue is addressed and documents either closure or the reasons for delay (paragraph 3.2).
  2. Match the effort to the risk. Paragraph 4.2 says critical or sensitive issues, such as high risk or fraud risk, need follow-up procedures; for medium risk, documentary proof may do; for low risk, a written confirmation from management may be enough. All three are documented.
  3. Escalate delays. The auditor tells the auditee and agrees a new schedule; on further delay, escalates under the pre-agreed protocol (paragraphs 3.3 and 4.3). If new facts justify the delay, a new time-bound plan may be agreed or the item carried forward to the next audit.
  4. Report the status. Periodically report to management and the audit committee, with confirmation of closure, ageing of pending issues and reasons for delay (paragraph 3.4).
  5. If an issue stays open. The auditor obtains written confirmation that management accepts the risk, or issues a note of unaddressed risks (paragraph 4.2, note).
Illustrative ATR columnPurpose
Observation reference and ratingLinks to the original report
Agreed action, owner, due dateShows accountability
Status at review dateOpen, closed, deferred
Evidence of closure checkedSupports the closure under paragraph 3.2
Age in days and reason for delaySupports paragraph 3.4 reporting

For an audit committee's role in reviewing internal audit findings, see our guide to section 177. For the statutory auditor's equivalent of reporting control weaknesses, see SA 265.

Illustrative example

Illustrative: Meghdoot Logistics Pvt Ltd's internal auditor reports six observations on warehouse stock records. A draft goes to the warehouse head on the day the fieldwork closes; she corrects one fact and adds an action plan with dates. The final report states the scope, the fact that the audit followed the SIAs, a summary, six actions with owners and the assurance position (no formal opinion). Three months later the auditor tests the two high-risk items again: one has a working control, the other still depends on a manual register. The auditor escalates to the finance director, agrees a new date, and shows the ageing in the quarterly note to the audit committee. At the next review the item is still open, and the director signs a note accepting the residual risk for six months.

Common lapses

  • Issuing the final report without a draft for the auditee.
  • A report that lists only deviations and says nothing of controls that work.
  • Closing an observation on management's email with no check, for a high-risk item.
  • Resetting due dates again and again with no escalation.
  • Action taken status shared only with the department and never with the audit committee.

Need help with internal audit reporting?

If you want a clear report format, a tracker for open observations or help drafting management responses, our team can assist through compliance documentation so that findings are closed on time.

Key takeaways

  • Agree a written communication protocol with management at the start (SIA 360, paragraph 3.1).
  • A written draft goes to the auditee before the final report (SIA 370, paragraph 3.3).
  • The report states objectives, scope, approach, key observations, corrective actions and any assurance (SIA 370, paragraph 3.1).
  • Closure of prior issues is verified by further procedures, scaled to risk (SIA 390, paragraphs 3.2 and 4.2).
  • Delays are escalated and ageing is reported to the audit committee (SIA 390, paragraphs 3.3 and 3.4).

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SIA 360

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Does SIA 370 prescribe a report format?

No. Paragraph 4.3 says the standard does not mandate any particular format or list of contents; the auditor uses professional judgement, consulting the auditee.

Must the auditee see the report before it is final?

Yes. Paragraph 3.3 says no report is issued in final form unless a written draft has previously been shared with the auditee.

Keep your documents in an order a stranger could follow — one day an officer or auditor will have to.

— TaxClue Compliance Desk

SIA 360: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. Paragraph 4.3 says the standard does not mandate any particular format or list of contents; the auditor uses professional judgement, consulting the auditee.

Yes. Paragraph 3.3 says no report is issued in final form unless a written draft has previously been shared with the auditee.

No. SIA 370 covers reports where no formal assurance report is required; opinions follow SIA 110 and SIA 380.

Management. SIA 390 paragraph 3.1 says the responsibility to implement action plans remains with management; the auditor monitors.

For critical or sensitive issues, SIA 390 paragraph 4.2 asks for follow-up procedures to see that the risk is mitigated to an acceptable level.

After escalation, the auditor obtains written confirmation that management accepts the risk, or issues a note of unaddressed risks (SIA 390, paragraph 4.2, note).