Internal Financial Controls Reporting: What the Companies Act Actually Requires
IFC reporting under the Companies Act often gets treated as a checklist. It is actually a controls audit with its own risk assessment, testing and opinion.
Key takeaways
- Section 143(3)(i) requires the auditor's own opinion on internal financial controls over financial reporting, separate from the opinion on the financial statements
- A specific MCA exemption removes this requirement for certain private companies, but public companies get no such carve-out
- The board's broader responsibility for internal financial controls under Section 134(5)(e) is a separate obligation that survives even where the audit exemption applies
- Evaluation follows the COSO-based approach in ICAI's Guidance Note: identify risks, map controls, test design, then test operating effectiveness through the year
- Only a material weakness, not every deficiency, forces a modification to the IFC opinion itself
Ask around a statutory audit team what IFC reporting actually requires and the answers range from 'a checklist we run once a year' to a genuinely serious controls-testing exercise that shapes how much substantive work can be scaled back elsewhere. Section 143(3)(i) of the Companies Act requires the auditor to report on the adequacy and operating effectiveness of a company's internal financial controls over financial reporting, and treating that as a formality rather than a distinct audit within the audit is where most weak IFC files come from. It is also one of the more misunderstood requirements in terms of who it actually applies to, since a genuine exemption exists for a chunk of private companies that many practitioners either forget about or apply too broadly.
Who Actually Has to Report on IFC
Every company's statutory auditor is required to opine on internal financial controls over financial reporting under Section 143(3)(i), unless the company falls within a specific carve-out the Ministry of Corporate Affairs introduced for private companies. That exemption applies to a private company that is either a one person company or a small company, or one that has both turnover below a specified threshold and aggregate borrowings from banks, financial institutions or any body corporate below a specified threshold at any point during the year, provided the company has not defaulted on filing its financial statements or annual return with the Registrar. Public companies get no such exemption regardless of size. It is also worth being precise about what the exemption actually covers: it removes the auditor's specific reporting obligation, it does not touch the board's own responsibility under Section 134(5)(e) to state that internal financial controls were laid down and were adequate and operating effectively. A private company that qualifies for the audit exemption can still find its board making representations about controls in the directors' responsibility statement, so the two obligations need to be tracked separately rather than assumed to move together.
IFC Is Broader Than ICFR, and the Difference Matters
One genuinely useful distinction that gets flattened in everyday practice is that 'internal financial controls' as referenced for the board's responsibility is a wider concept than what the auditor is actually opining on. The auditor's opinion under 143(3)(i) is specifically about internal financial controls over financial reporting, the subset of controls relevant to the reliability of financial reporting and the safeguarding of assets against unauthorised use. The board's own statement can fairly be read as covering a broader universe of operational and compliance controls as well. In practice this means an auditor should not treat every control weakness raised by management or internal audit as automatically within scope for the IFC opinion. The relevant test is always whether the control addresses a risk of material misstatement in the financial statements, not simply whether it is a control the company happens to maintain.
How the Evaluation Actually Works
The ICAI Guidance Note on Audit of Internal Financial Controls over Financial Reporting sets out an approach that borrows heavily from the COSO framework's five components: control environment, risk assessment, control activities, information and communication, and monitoring. In practice, the work follows a fairly consistent sequence. The auditor identifies significant accounts and disclosures and the assertions at risk of material misstatement, maps the entity-level and process-level controls that address those risks, performs walkthroughs to confirm the controls are designed the way management describes, and then tests operating effectiveness across the period under audit rather than as a single year-end check. A control that existed on paper but was only evidenced once, at year-end, does not really demonstrate that it operated consistently through the year.
- IT general controls around user access, change management and backups, especially where a company has scaled its ERP usage faster than its access-review discipline
- Manual review controls, such as a manager's sign-off, that exist as a documented step but leave no evidence that the review actually happened
- Segregation of duties in smaller finance teams, where the same person can initiate, approve and record a transaction
- Documentation gaps, where a control clearly operates in practice but there is no risk control matrix or process narrative connecting it to a specific risk
Deficiencies, Significant Deficiencies and Material Weakness
Not every gap found during IFC testing changes the auditor's opinion. Findings are classified by severity: a deficiency is a control that is not designed or operating well enough to prevent or detect a misstatement on a timely basis, a significant deficiency is important enough to warrant attention from those charged with governance, and a material weakness is severe enough that there is a reasonable possibility a material misstatement would not be prevented or detected in time. Only a material weakness forces a modification to the IFC opinion specifically, and that opinion sits apart from the opinion on the financial statements themselves. A company can receive an unmodified opinion on its financial statements and still get a modified opinion on IFC, if the auditor concludes the numbers happened to come out right despite a control environment that should not be relied on going forward.
All deficiencies, whatever their severity, are expected to be communicated to management, with significant deficiencies and material weaknesses specifically escalated to the audit committee or board. IFC reporting is easiest to get wrong by treating it as a narrative exercise, describing controls the company says it has, rather than an evidence-based one. The approach the Guidance Note actually asks for is closer to a mini controls audit sitting inside the larger financial statement audit, with its own risk assessment, its own testing and its own opinion, and teams that build it into the audit plan from the start tend to produce both a more defensible IFC opinion and a financial statement audit that can genuinely rely on the controls being tested.
Frequently asked questions
Does every private company need an IFC opinion from its auditor?
No. Private companies that are a one person company or a small company, or that meet specified lower turnover and borrowing thresholds and have no filing defaults, are exempt from the auditor's IFC reporting requirement under the relevant MCA notification. Public companies get no equivalent exemption regardless of size.
If a private company is exempt from the auditor's IFC opinion, does the board still need to address internal controls?
Yes. The audit exemption only removes the auditor's specific reporting obligation. The board's own responsibility under Section 134(5)(e), to state that internal financial controls were laid down and are adequate and operating effectively, is a separate requirement and is not automatically waived along with it.
What is the difference between a deficiency, a significant deficiency and a material weakness?
They sit on a severity scale. A deficiency is any control not working well enough to prevent or catch a misstatement in time. A significant deficiency is serious enough to be reported to those charged with governance. A material weakness is severe enough that a material misstatement could plausibly slip through, and only a material weakness forces a modification to the IFC opinion itself.
Can a company get a clean opinion on its financial statements but a modified opinion on IFC?
Yes, and it happens more often than most people expect. The financial statements can turn out correct even where the underlying controls are weak. The auditor's job under 143(3)(i) is to assess whether the controls can be relied on going forward, not just whether this particular year's numbers happened to be right.
Is the IFC opinion based on testing done only at year-end?
It should not be. Operating effectiveness is meant to be evaluated using evidence spanning the period under audit, not a single point-in-time check, since a control that only appears to work at year-end does not demonstrate that it operated consistently through the year.
This article is for general informational purposes only and does not constitute professional tax, legal, or financial advice. Rules and rates change, so consult a qualified Chartered Accountant for advice specific to your situation.
Related reading
Key Ind AS Updates Every Practicing CA Should Track This Year
Ind AS never really sits still — it keeps absorbing convergence updates. Here's what practicing CAs should be watching, and why it matters for clients.
Forensic Audit Basics: When It's Commissioned and How It Differs From a Regular Audit
A forensic audit asks a different question than a statutory audit: not whether the statements are fair overall, but whether something specific actually happened.
Statutory Audit vs Internal Audit vs Tax Audit: Key Differences Explained
Three audits, three different laws, three different audiences — business owners often assume they're the same exercise done thrice. They rarely are, and mixing them up gets expensive.