Internal Audit

Risk-based evaluation of controls, processes, and compliance

Ashish Jayalata & Associates provides risk-based internal audit services to companies, LLPs, and large partnerships in Ghaziabad, Sahibabad, and the NCR. The practice conducts internal audits under Section 138 of the Companies Act 2013, covering process reviews, internal controls testing, operational audit, and compliance audit with reporting to the Audit Committee or Board of Directors.

What This Includes

  • Process Reviews: Detailed review of key business processes — procurement, sales, treasury, payroll, inventory management, fixed assets, and receivables — to evaluate design and operating effectiveness of controls.
  • Internal Controls Testing: Testing of internal financial controls (IFC) over financial reporting, including authorization controls, segregation of duties, reconciliation procedures, and IT general controls.
  • Operational Audit: Review of operational efficiency, cost control measures, resource utilization, and process improvement opportunities across departments and functions.
  • Compliance Audit: Assessment of compliance with applicable laws and regulations — Companies Act 2013, GST, Income Tax, FEMA, labor laws, and sector-specific regulations — with identification of gaps and risk areas.
  • Risk Assessment: Identification and evaluation of business risks — financial, operational, strategic, and compliance-related — and assessment of the adequacy of the entity's risk management framework.
  • Audit Reporting: Preparation of internal audit reports with findings, observations, root cause analysis, risk ratings (high/medium/low), and actionable recommendations for improvement.
  • Follow-Up Audit: Periodic review of the implementation status of audit recommendations to ensure that identified weaknesses have been addressed and controls have been remediated.
  • Special Investigations: Investigation of specific areas of concern as directed by the Audit Committee or management, including fraud risk assessment and forensic procedures where warranted.

Who It's For

This service is applicable to listed companies, public companies with paid-up capital of ₹50 crore or more, public companies with turnover of ₹200 crore or more, and LLPs with turnover exceeding ₹40 crore or contribution exceeding ₹25 crore. Companies voluntarily adopting internal audit for governance and risk management purposes also engage this service.

Our Process

1
Planning & Risk Assessment — Understanding the entity's business, organizational structure, key processes, and risk profile. Developing the audit plan with scope, objectives, and timelines.
2
Fieldwork & Testing — Executing audit procedures — walkthroughs, tests of controls, substantive testing, interviews, and analytical review — across the processes within the audit scope.
3
Reporting — Compiling audit findings with risk ratings, root cause analysis, and recommendations. Presenting the report to the Audit Committee or management.
4
Follow-Up — Reviewing the implementation status of agreed management actions in subsequent audit cycles.

Documents Required

  • Financial statements and management accounts
  • Process documentation (SOPs, process flowcharts)
  • Internal policies and procedures manual
  • Previous internal audit reports and management responses
  • Organization chart and details of key personnel
  • Statutory audit report and management letter (if any)
  • Board and Audit Committee meeting minutes

Frequently Asked Questions

Why does my business need an internal audit?
An internal audit reviews your processes, checks whether controls are working, and identifies risks such as errors, fraud, or wastage before they become serious. Unlike a statutory audit, it is not just about compliance — it helps improve how your business runs. Growing businesses in Ghaziabad use internal audits to strengthen finance and operations.
What is the difference between internal and statutory audit?
A statutory audit is legally required for companies and checks whether financial statements are true and fair. An internal audit is a management tool that reviews processes, controls, and risks across the business. It is usually voluntary and its scope is defined by you. We can carry out both — separately or together.
What areas does your internal audit cover?
We typically cover purchases and payments, sales and collections, inventory, cash and bank, payroll, fixed assets, and compliance with internal policies. We also review IT and operational controls where relevant. After the audit, you get a findings report with practical recommendations and a priority list for fixing issues.
How often should an internal audit be done?
Most businesses run an internal audit quarterly or half-yearly so issues are caught early and corrective action can be verified. Some prefer an annual cycle if the risk level is low. We help you design a frequency that matches your transaction volume, industry risk, and management needs.
How much does an internal audit cost?
Internal audit fees depend on the number of locations, transaction volume, and the breadth of processes to be reviewed. We quote a fixed annual or per-audit fee after an initial scoping call. Since it is a recurring exercise, we can also offer a multi-period engagement at a discounted rate.
What will I receive after the internal audit?
You receive a written internal audit report with our findings, risk ratings for each issue, and practical recommendations. We also present the findings to you or your management, prioritise action items, and can follow up on the implementation of fixes in the next cycle.
Can an internal audit help detect fraud?
Yes. An internal audit tests controls around cash, payments, procurement, and inventory that are common fraud risk areas. When weaknesses are found, we recommend controls such as segregation of duties and approval limits. If you suspect fraud, we can also carry out a focused investigation with your consent.

Need help with internal audit in Ghaziabad, Sahibabad, or NCR? Contact the office to discuss your requirement.

Contact the Office →