Home / Services / Internal Audit & Assurance

The checks that find problems while they are still small

Internal audit tests whether your controls actually work — not whether the accounts balance. We run internal audits, stock and receivable verification, compliance reviews, systems audits and transaction due diligence for Indian SMEs, and we report in plain language with a fix attached to every finding.

A statutory audit tells your shareholders the accounts are true and fair, once a year. Internal audit tells you, during the year, where someone can quietly cost you money — and how to close that door.

A risk and control matrix, after testing.

Every account balanced.

The statutory audit was clean. It had been clean for six years running.

One man did all four of these.

Raised the purchase orderSame person
Approved itSame person
Recorded the goods inwardSame person
Released the paymentSame person
₹1.1 Cr of purchases went through that route in a single year, without a second signature anywhere on the file.

Nothing was missing.
That was luck, not control.

A ledger that balances only tells you the entries agree with each other. It never tells you who could have moved the money.

Four people now touch
what one person used to.
Approval limits, separated duties, and a stores process with a named owner at every step — the part a statutory audit was never asked to look at.

What we audit

We scope each assignment around where the risk and the money actually are, which for most manufacturers means stores, purchase and receivables long before it means the general ledger.

  • Internal audit across purchase, stores, production, sales, payroll and accounts
  • Stock and receivable audits, including the ones your bank requires against drawing power
  • Bank guarantee and ASM audits in the formats lenders ask for
  • Compliance audits covering statutory dues, filings, licences and registrations
  • Due diligence for acquisitions, investments, partnerships and exits
  • Compilation and review services where a full audit is not required

Risk advisory: the things that are not in the ledger

Some of the biggest risks to an SME never appear in the accounts until it is far too late — a single unbacked server, one person who holds every password, a regulatory registration that lapsed, or no plan for the week after a fire or a flood.

We assess these deliberately and give you a short, prioritised list with owners and dates rather than a risk register nobody opens.

  • IT risk assessment and systems audit, including access rights and backup discipline
  • Business continuity planning for the events that would actually stop your plant
  • Regulatory compliance review across the licences and filings your business depends on
  • Process automation opportunities identified during the audit, not sold separately

How we report

One page for the promoter with the three findings that matter, then the detail. Every finding has a cause, a rupee impact where we can estimate it, a recommended fix, and a named owner with a date.

We then come back and check whether the fix was implemented. An audit finding that is never closed was a waste of everybody's time.

Client Results

What this looked like in a real business

Client names are held back for obvious reasons.

Manufacturing · stores & inventory

Stock on the system never matched stock on the floor

What was wrong
No defined process for receiving, issuing or counting material. Mismatches were common and pilferage was a real risk.
What we did
Set up goods receipt notes, issue slips, periodic physical counts and a monthly reconciliation that someone is accountable for.

Inventory differences down 50% and stock records now trusted by the bank.

Manufacturing · purchase function

Every buyer was negotiating a different price

What was wrong
Purchases went through without a standard approval route, so the same item was bought at different rates and vendor selection was informal.
What we did
Wrote a simple vendor onboarding, purchase order and approval process, with clear limits for who can approve what.

Purchase costs down 8–10%, with a clean audit trail on every order.

What you get

  • Internal audit programme and periodic reports
  • Stock and receivable verification
  • Bank-format stock and BG audits
  • Compliance and statutory review
  • Systems and IT risk assessment
  • Due diligence reports for transactions

Manufacturing · stores and inventory

Inward, issue and verification processes were undefined, producing inventory mismatches and real pilferage risk. After new goods-receipt, issue and count procedures, inventory variances dropped 50% and stock statements became reliable enough for bank reporting.

More client results

Questions we get asked

What is the difference between internal audit and statutory audit?

Statutory audit is required by law, performed by an independent auditor, and gives an opinion on whether the financial statements are true and fair. Internal audit is commissioned by management, runs through the year, and tests whether controls and processes are working. One protects shareholders; the other protects the business.

Is internal audit compulsory for our company?

Under the Companies Act, internal audit is mandatory for certain classes of companies based on turnover, borrowings and paid-up capital. Many businesses below those thresholds commission it voluntarily, usually after a loss they did not see coming. We can confirm whether the requirement applies to you.

How often should a stock audit be done?

For businesses with working capital limits, banks usually require stock audits annually or half-yearly. Internally, we recommend a full physical count at least quarterly with monthly cyclical counts of high-value items.

Can you do due diligence if we are buying a business?

Yes. We review financial, tax, compliance and process risk on the target, and report what should change the price, what should be indemnified, and what should stop the deal.

Start with a free 30-minute review of your numbers

Send us the last two years' balance sheets and the pain point that is bothering you most. We come back with things you can fix in the next quarter — no obligation, no sales deck.

CA Neel Shah
+91 93710 03780
CA Yash Patni
+91 83085 53339