Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates

SIA 520 and SIA 530: internal auditing in an information technology environment and the internal audit of third party service providers

The objectives of an internal audit do not change in an IT environment, but the risks and controls do (SIA 520, paragraph 1.3). The auditor starts with an independent IT risk...

Published
Updated
Reading time
9 min
Views
4
Questions
6 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Accounting Standards & Bookkeeping
Published
October 4, 2026
Last updated
Oct 8, 2026
Reading time
9 min
0:00
Last updated: October 2026Verified against: Government sources

Most of a company's accounting, billing and payroll now run on software, and much of that software is hosted, supported or operated by outside providers. SIA 520 tells the internal auditor how to audit IT systems the company manages; SIA 530 covers systems and processes that sit with a third party. For finance heads, these are the standards behind the questions the internal auditor asks about access, backups and vendor contracts.

This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). Both standards apply to internal audits beginning on or after a date to be notified by the Council. Under paragraph 5.1 of the Preface the Council decided to make the SIAs mandatory in a phased manner. Check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.

SIA 520: internal audit in an IT environment

An information technology environment exists when information is captured, stored and processed by automated means under policies and procedures, and has two main components: IT infrastructure (hardware, architecture, operating systems, network, storage) and application software and data, such as ERP, customer relationship, e-commerce and robotic process automation (paragraph 1.2). The standard applies where the company manages its own IT systems (paragraph 1.4). Its aim is to evaluate the organisation's IT risks and whether IT-related controls suffice for business objectives (paragraph 1.3). Areas of assurance include security and reliability of information, efficiency of processing, reporting, continuous availability and compliance with IT-related laws (paragraph 2.1).

RequirementWhat the auditor doesParagraph
Understand and assess riskLearn business operations and the IT environment; make an independent IT risk assessment and identify the controls needed before starting IT audit work3.1, 4.1
SkillsHave or acquire the qualifications and experience; specialised skills in IT governance, application controls, infrastructure, cyber security and data privacy are called essential3.2, 4.2
ScopeAssess the environment to define scope and relevant controls; the level of risk drives nature, extent and timing3.3, 4.3
PlanDocumented understanding, risk assessment, approach, project plan, skills and team3.4, 4.4
ExecuteTest design, implementation and operating effectiveness of relevant IT controls; identify gaps, deficiencies and violations of procedures or laws3.5, 4.5
DocumentEnvironment, scope, risk assessment, planning, testing and reporting, under SIA 3303.6, 4.6
ReportShare outcome with process owners, agree action plans, document the basis of the conclusion3.7, 4.7

The explanatory comments give practical detail. Execution involves interviews, review of documents and of system configuration and settings, inspection of systems, data and reports, use of data analytics and physical walkthroughs, with evidence that is sufficient, appropriate, reliable and consistent (paragraph 4.5). The documentation includes an IT risk and controls matrix, IT test work papers and system-generated reports with supporting documents (paragraph 4.6). Before concluding on a control test the auditor considers additional evidence or mitigating measures offered by the auditee, may look into the root cause and the impact on financials, and discusses the final deficiencies with executive management (paragraph 4.7). On skills, paragraph 4.2 names the Diploma in Systems Audit or an equivalent qualification as a way to build knowledge, and notes the credentials can be acquired externally and made available for the audit. The standard's annexures give an illustrative list of audit areas and a checklist of IT controls, which are not reproduced here.

What an internal auditor may ask your IT and finance teams

Our own illustration of typical requests, not a list from the standard: the list of applications and who administers them; user access lists with join, move and exit dates; evidence that backups are taken and restored; change and release records; system-generated reports used for accounting; and the interfaces between systems. For the statutory audit view of the same topic, see our article on audit in an IT environment. Businesses preparing their systems for such a review can ask our compliance advisory team for a readiness check.

SIA 530: third party service providers

SIA 530 deals with risks where parts of the entity's operations, processes and information sit with outside providers, to whom a function or processing is outsourced (paragraph 1.1). These risks touch processing, financial and operational management, information security, legal compliance and business continuity (paragraph 1.2). How much the internal auditor must do depends on the importance of the outsourced process and on whether the provider gives its customers a third party audit and assurance report (TPAA report) (paragraph 1.3). The standard applies both to the providers and to their user entities (paragraph 1.4).

RequirementWhat the auditor doesParagraph
Governance of outsourcingStudy the scope of the provider's services and the user's governance and oversight of outsourcing, especially access to critical information3.1, 4.1
Due diligenceReview pre-engagement and post-engagement due diligence by the user, including a control assessment of controls retained and outsourced; recommend one where management has not done it3.2, 4.2
Risk assessmentManagement assesses each arrangement periodically; the auditor reviews it3.3, 4.3
Audit of the providerWhere permissible, audit the provider's entity-level, IT and process controls and the user's monitoring of service levels3.4, 4.4
Assurance reportsIf no audit of the provider is done, evaluate the TPAA report as work of an expert under SIA 2403.5, 4.5

Paragraph 4.1 lists signs of sound oversight: a database of all third party arrangements with business owners, categorisation by criticality and risk, objective selection, documented contract terms including those after termination, service level agreements that are measured and monitored, controls over the user's information, and the right to audit or to receive assurance reports. Paragraph 4.3 gives the example of a call centre that handles no financial transactions yet holds a customer database, and so carries a data-breach risk; it also asks that the contract permit the internal auditor to perform the risk assessment and procedures at reasonable frequency. The standard also asks the auditor to review the controls the user keeps in-house when judging the overall control position (paragraph 4.5).

How this pairs with other standards: SIA 530 points to SIA 520 for IT reviews of the provider and to SIA 240 for evaluating a TPAA report. The assurance report a provider's auditor issues is the subject of our article on SAE 3402 type 1 and type 2 reports, and the statutory auditor's side is in our SA 402 guide.

Illustrative example

Illustrative: Nimbus Retail Ltd runs an ERP in-house and outsources payroll processing to a vendor. For the ERP, the internal auditor lists applications and the data flow, rates user access and change management as high risk, then tests whether new users receive approved access, whether a sample of leavers' accounts were disabled and whether program changes were approved before release. Two leaver accounts were active months after exit; the auditor traces the cause, discusses it with the IT head and records the agreed fix. For the payroll vendor, the auditor finds that the company never performed due diligence and has no right-to-audit clause. SIA 530 paragraph 4.2 therefore leads to a recommendation to do due diligence now, and the auditor evaluates the vendor's service auditor report, noting which controls remain with Nimbus's own HR team.

Common lapses

  • Treating an IT audit as a review of policies with no testing of access and change logs.
  • No IT risk assessment before choosing the tests.
  • Accepting a vendor's assurance report without checking its scope and the controls the user retains.
  • Contracts with vendors that give no right to audit or to receive assurance reports.
  • Skills gaps filled by an expert whose independence was never checked.

Need help preparing for an IT or vendor review?

If you want your IT controls and vendor arrangements reviewed before an internal audit, our team can help through compliance advisory, including contract terms and service level monitoring.

Key takeaways

  • An IT audit starts with an independent IT risk assessment and a documented understanding of the environment (SIA 520, paragraphs 3.1 and 3.4).
  • The auditor tests design, implementation and operating effectiveness of relevant IT controls (SIA 520, paragraph 3.5).
  • For outsourced processes, the auditor reviews due diligence, risk assessment and monitoring of the provider (SIA 530, paragraphs 3.2 to 3.4).
  • A provider's assurance report is evaluated as the work of an expert (SIA 530, paragraph 3.5).
  • Contracts should allow the right to audit and to receive assurance reports (SIA 530, paragraphs 4.1 and 4.3).

Read next

Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About SIA 520

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Does the objective of internal audit change for IT systems?

No. SIA 520 paragraph 1.3 says the overall objectives do not change, but the nature of risks and controls affects the approach.

What does the IT internal auditor do first?

Gain an understanding of the business and the IT environment and perform an independent IT risk assessment before starting IT audit activities (SIA 520, paragraph 3.1).

Ask the question before you sign — it is always cheaper than asking it afterwards.

— TaxClue Compliance Desk

SIA 520: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. SIA 520 paragraph 1.3 says the overall objectives do not change, but the nature of risks and controls affects the approach.

Gain an understanding of the business and the IT environment and perform an independent IT risk assessment before starting IT audit activities (SIA 520, paragraph 3.1).

SIA 530 applies where systems and processes are managed by a third party; SIA 520 applies where the company manages its own systems (SIA 520, paragraph 1.4).

The internal auditor recommends it (SIA 530, paragraph 4.2).

The auditor evaluates it under SIA 240 and considers the controls retained by the user entity (SIA 530, paragraphs 3.5 and 4.5).

No. SIA 520 lists compliance with IT-related laws as an area of assurance but does not set out those laws. For incident reporting and log retention, see our guide to the CERT-In Directions of 2022.