Standards on Internal Audit explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
The Standards on Internal Audit (SIAs) are the ICAI's minimum requirements for members who carry out internal audits. They sit under a Framework, which defines internal audit, and a set of Basic Principles that every internal audit must follow. This article explains how these pieces fit and what "mandatory" means for them.
This article is from the ICAI Compendium of Standards on Internal Audit (as on 1 October 2022). Later standards or revisions may exist, so check the current versions on the ICAI internal audit board's site, internalaudit.icai.org.
The Preface (paragraph 4.1) calls the SIAs a set of minimum requirements for all ICAI members performing internal audit of any entity. Paragraph 5.1 says the Council decided to make them mandatory in a phased manner, first for members doing internal audit of listed companies under section 138 read with rule 13, and for all other companies one year after the effective date of a standard. Where a member cannot comply, the internal audit report must draw attention to the material departure and explain it (paragraph 5.3).
What the compendium contains
The compendium has a Preface, a Framework, the Basic Principles and then the standards in sections: 100 series (key concepts), 200 series (internal audit management), 300 and 400 series (conduct of assignments), 500 series, and an older group published as on 1 July 2013 (SIA 5, 6, 7, 11 and 18). Our guides to the groups follow this order: SIA 120, SIA 110, 130, 140 and 150, SIA 210 to 250 and SIA 7, SIA 310, 320, 330 and 350 and the later ones.
| Series | Standards (number and title) |
|---|---|
| 100, key concepts | 110 Nature of Assurance; 120 Internal Controls; 130 Risk Management; 140 Governance; 150 Compliance with Laws and Regulations |
| 200, internal audit management | 210 Managing the Internal Audit Function; 220 Conducting Overall Internal Audit Planning; 230 Objectives of Internal Audit; 240 Using the Work of an Expert; 250 Communication with those Charged with Governance |
| 300-400, conduct of assignments | 310 Planning the Internal Audit Assignment; 320 Internal Audit Evidence; 330 Internal Audit Documentation; 350 Review and Supervision of Audit Assignments; 360 Communication with Management; 370 Reporting Results; 390 Monitoring and Reporting of Prior Audit Issues |
| 500 | 520 Internal Auditing in an Information Technology Environment; 530 Third Party Service Provider |
| As on 1 July 2013 | 5 Sampling; 6 Analytical Procedures; 7 Quality Assurance in Internal Audit; 11 Consideration of Fraud in an Internal Audit; 18 Related Parties |
The Preface (paragraph 7.4) also reserves a 600 series for quality control and a 700 series for other matters; the compendium held contains no standards in those series. SIA 380 on issuing assurance reports is referred to inside other standards but is not in this compendium.
The Preface: who is bound, and how
- Who: all members of the ICAI performing internal audit of any entity. A footnote explains that the SIAs apply whether the member is an employee of the entity or a representative of an outside firm.
- Non-members: paragraph 4.2 notes that section 138 lets the Board appoint a cost accountant or another professional, and says ICAI recommends non-members also adopt the SIAs for consistency and quality.
- Phased mandatory status: paragraph 5.1 as printed says the Council decided to make the standards mandatory in a phased manner, initially for members performing internal audits in all listed companies as per section 138 read with rule 13 of the Companies (Accounts) Rules, 2014 from the effective date of the SIA, and all other companies from one year thereafter.
- Duty: paragraph 5.2 makes it the member's duty to comply with the SIAs read with the Preface, the Framework and the Basic Principles.
- Departures: paragraph 5.3 requires the report to draw attention to material departures with an explanation, including where a regulatory requirement conflicts with an SIA.
- Guidance: Guidance Notes, Implementation Guides and Technical Guides are recommendatory; the Internal Auditor should ordinarily follow them unless circumstances make it unnecessary (paragraph 8.3).
Who must have an internal audit at all, and the tests by company type, are covered in our posts on section 138 and on rule 13 applicability. This article does not restate them. If you want a view on how your own internal audit set-up compares, our compliance advisory team can discuss it.
The Framework: what internal audit is
Paragraph 3.1 of the Framework defines internal audit as independent assurance on the effectiveness of internal controls and risk management processes to enhance governance and achieve organisational objectives. The explanation that follows says the function must be independent in its position, structure and reporting; an advisory role is acceptable if independence is not compromised. The internal auditor evaluates the design and operating effectiveness of controls and risk management as the management has designed and implemented them. The Framework (paragraph 4) has four components: Basic Principles, Key Concepts, SIAs and Guidance, plus the Code of Ethics as the underlying principle; all are mandatory except the Guidance. An ICAI member is also bound by the Chartered Accountants Act, 1949 and the ICAI Code of Ethics (paragraph 5.2).
The ten basic principles
The Basic Principles apply to every internal audit, and departures are disclosed in the report (paragraph 1.2). In summary:
| Principle | What it asks of the internal auditor (paragraph) |
|---|---|
| Independence | No undue influence, in mind or in appearance; position outside the audited functions; reporting to the Board or audit committee (3.1) |
| Integrity and objectivity | Honest, fair, no conflicts, no bias in evidence or conclusions (3.2) |
| Due professional care | Reasonable care and diligence in scope, risk and testing (3.3) |
| Confidentiality | Disclose only on a need-to-know basis; reports go to those who engaged the auditor (3.4) |
| Skills and competence | Take only assignments one can do; bring in experts where needed without losing independence (3.5) |
| Risk-based audit | Put effort on high-risk areas and important controls (3.6) |
| System and process focus | Look at root causes and prevention, not only errors (3.7) |
| Participation in decision making | Do not judge past decisions or take operational decisions that may later be audited (3.8) |
| Sensitivity to multiple stakeholders | Present a balanced view where interests conflict (3.9) |
| Quality and continuous improvement | Quality control, self-assessment and peer review (3.10) |
Independence deserves a closer look. Paragraph 3.1 says the function should be positioned outside the functions it audits, such as finance and accounts, and report to the Board or audit committee; administrative reporting to a chief executive with functional reporting to the audit committee chair is described as the acceptable norm. If the internal auditor is given operational tasks, they may be accepted only in a limited way with approvals and for a short period, after the auditor spells out that he or she cannot own the process or take operational decisions that could later be audited. For the statutory auditor's use of internal audit work, see our SA 610 guide.
Illustrative example
Illustrative: Sunrise Dairy Products Ltd, an unlisted public company, appoints a chartered accountant firm as internal auditor. The audit committee approves the annual plan; the firm reports findings to the committee chair and, administratively, to the chief financial officer. In the second year the CFO asks the firm to redesign the credit approval process and then to audit it. The partner agrees to advise on a short, approved, one-time basis, states in writing that the process will remain management's, and assigns a different team to audit the new process the following year. The report records the arrangement under the independence principle. Had the firm been unable to apply one SIA requirement because of a regulatory conflict, the report would have said so.
Common lapses
- Treating the SIAs as optional because the company is unlisted, without checking the current mandatory position.
- Internal auditor reporting only to the finance head whose function is being audited.
- Taking up operational work and then auditing it.
- No mention in the report of a departure from a standard.
- Copying a statutory audit programme instead of a risk-based plan.
Need help with internal audit for your company?
If you are setting up an internal audit function or reviewing whether your current arrangement meets the standards, our team can assist through compliance advisory, including scoping and reporting lines.
Key takeaways
- The SIAs are minimum requirements for ICAI members, mandatory in phases as set out in Preface paragraph 5.1.
- Internal audit is independent assurance on internal controls and risk management to enhance governance.
- Ten basic principles apply to every internal audit and any departure is disclosed in the report.
- The internal audit function should sit outside the functions it audits and report to the Board or audit committee.
- The law on who needs an internal audit is in section 138 and rule 13; see the linked posts.
Read next
- SIA 120: internal controls and internal financial controls
- SIA 210 to 250 and SIA 7: managing the internal audit function
- Section 138: internal audit
- Audit, review, agreed-upon procedures and compilation: which engagement gives what assurance
Disclaimer: Based on the Standards on Auditing, the review, assurance and related services standards, the Compendium of Standards on Internal Audit (as on 1 October 2022) and the Compendium of Forensic Accounting and Investigation Standards (as on September 2025) issued by the Institute of Chartered Accountants of India, in the versions named in the article, as consulted on 4 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org and the Companies Act provisions referred to. This article is general information, not legal advice; check the official text before acting.
