Your corporate finance team knows the head office controls inside out. The approval limits are documented, the ERP enforces most of them, and recent statutory audits were clean. But what happens across warehouses and regional branches? An approval limit enforced automatically at head office is manually overridden elsewhere, while a weekly reconciliation happens only “around month-end” at another site.
These inconsistencies are common in businesses with ₹150–350 crore turnover across multiple locations. Controls are often designed at head office but not tested to ensure they work consistently everywhere.
With a statutory audit due in a few months, Section 143(3)(i) of the Companies Act, 2013 requires auditors to report whether Internal Financial Controls (IFC) are adequate and operating effectively. Directors must also confirm this in the annual report.
You have a choice, wait for the auditor to find the gaps, or find them yourself first and fix them.
Why IFC Gets Harder to Manage as Enterprises Add Entities
For a single-location business, IFC is manageable. You have one finance team, one set of processes, one ERP instance. The finance controller can walk to the procurement desk and verify that three-way matching is being done, the audit trail is contained.
For a multi-location enterprise, IFC is a different problem entirely:
The design versus operating effectiveness problem
A corporate approval matrix, segregation of duties policy or reconciliation calendar may look fine during a walkthrough. The real question is whether employees actually follow those controls throughout the year. That difference between control design and operating effectiveness is what’s most important.
During a busy production period, an approval may be bypassed. A bank reconciliation may remain pending for several weeks. A user may retain ERP access after moving roles. At head office, management may receive a report saying reconciliations are “up to date” without seeing the exceptions that remain unresolved at the location.
The scale problem
As you add locations, the number of control points multiplies. Each new warehouse adds inventory controls, each new branch adds procurement and payment controls.
The IFC framework that previously worked for three locations will not work for five and definitely not for ten. The controls need to scale with the business, and scaling requires standardisation, not duplication.
Legal entity boundaries problem
A group may have several subsidiaries, but even a single company with multiple plants and branches can face the same control problem. Operational complexity is driven by distance, processes and layers of management.
An IFC programme therefore needs to consider where financial reporting risks actually arise. A warehouse holding a significant portion of inventory can be a critical control location even if it is only a cost centre within the parent company.
The documentation problem
IFC requires documented policies, procedures, and evidence of operation. Across multiple locations, documentation is often incomplete or inconsistent.
Some locations have detailed process narratives and control matrices; others have nothing written down. When the auditor asks for IFC documentation, you need a complete, standardised set of records across every entity.
The ownership problem
Who owns IFC across the group? The finance team handles some controls, operations handles others, internal audit does periodic checks.
No single person has end-to-end visibility across all locations and entities. Gaps go unaddressed because there’s no clear accountability for the broader group picture.
IFC is not optional for companies like yours. Section 143(3)(i) applies to all companies, listed and unlisted. The requirement is not limited to listed entities. Your statutory auditor must report on IFC adequacy and operating effectiveness regardless of your listing status.
You must assess whether your current IFC framework across all locations is adequate and operating effectively and whether you can prove it to the auditor.
PKC’s IFC Gap Assessment Approach
For a multi-location manufacturing or mid-market enterprise, an IFC gap assessment needs to assess whether controls are well-designed, consistently applied across locations, and effective for financial reporting.
PKC’s IFC engagements begin with a planned gap assessment which aims to identify exactly where your controls are falling short, prioritise the gaps by risk, and give you a clear remediation plan.
1. Risk-based scoping
The first step is to define what needs to be assessed and where the significant financial reporting risks lie. For a business operating through multiple plants, branches or legal entities, this includes identifying:
- Entities and locations within scope
- Core processes such as procurement, revenue, inventory, payroll, fixed assets, treasury and financial close
- Relevant ERP and IT general controls
- Locations where transaction volumes, inventory values or other balances create higher financial reporting risk
This avoids applying identical testing to every location regardless of risk. A manufacturing plant holding a large proportion of inventory may require more detailed testing than a small administrative branch.
2. Process walkthroughs
PKC’s team conducts walkthroughs at each location in scope. Our team visits the locations, observes the processes, and interviews the people who actually execute the controls.
For procurement, that could mean sitting with the purchase team, reviewing how vendor approvals are obtained, how purchase orders are raised, how goods receipts are matched to invoices, and how payments are authorised.
For revenue, it could be walking through the order-to-cash cycle from customer order to cash collection. For inventory, it might be observing physical verification procedures and understanding how stock movements are recorded.
The walkthroughs serve two purposes – they establish whether the controls exist in design and they provide evidence of whether the controls are actually operating as designed.
3. Control identification and documentation
Based on the walkthroughs, we identify the key controls relevant to each financial process. This documentation becomes the foundation for the gap assessment. It provides a clear picture of what controls exist, where they exist, and how they are supposed to operate.
These are documented in a structured format that includes:
- Risk being addressed
- Control activity
- Control owner
- Frequency of operation
- Nature of the control (preventive or detective, manual or automated)
- Evidence that demonstrates operation
Step 4: Gap identification
The gap assessment compares your existing controls against Statutory requirements under the Companies Act, 2013, ICAI’s Guidance Note on Audit of Internal Financial Controls Over Financial Reporting, industry best practices and the specific risks your business faces
Gaps are identified as:
- Design gaps: Controls that should exist but do not. For example, no documented vendor approval policy. No segregation of duties between purchase order creation and payment approval.
- Operating effectiveness gaps: Controls that exist in design but are not operating effectively. For example, a policy requiring two authorisations for payments above ₹5 lakh, but in practice, payments are approved by a single person during busy periods.
Each gap is documented with: specific risk it creates, potential impact on financial reporting, suggested remediation, and estimated effort level
Step 5: Prioritisation and reporting
Gaps vary widely. Some create material risks to financial reporting while others are lower priority.
PKC prioritises gaps based on the likelihood of the risk materialising, the potential financial impact, and the ease of remediation
Timeline and process
Usually an IFC gap assessment for a multi-location enterprise takes 6–10 weeks, depending on the number of locations and processes in scope. The engagement includes:
- Planning and scoping: 1 week
- Process walkthroughs and control identification: 2-4 weeks
- Gap analysis and prioritisation: 1-2 weeks
- Reporting and presentation: 1 week
The final report provides a clear, actionable roadmap. It tells you what to fix, in what order, and how to fix it, a prioritised plan that you can execute.
Every gap identified gets tied back to a specific process, a specific location, and a specific risk it leaves exposed, which is what makes the next stage, building a Risk Control Matrix, possible.
Building a Risk Control Matrix Across Multiple Legal Entities
Once the gap assessment is complete, the next step is building a Risk Control Matrix (RCM).
RCM maps each identified risk to the control meant to address it, who owns that control, how often it operates, and how it gets tested.
For a business operating through several plants, branches and legal entities, the RCM provides one view of financial reporting risks without forcing every location into an identical process.
Without an RCM, multi-entity enterprises risk fragmented controls across different locations and entities. One location has a control matrix, another has nothing. Corporate has a high-level framework that does not reflect local variations.
Here’s our approach to building RCM:
Build one framework, then layer in local risks
Our approach is to build one core RCM structure that applies the same process categories, risk definitions, and control types across every entity and location in the group.
The core processes covered include procurement, revenue, inventory, payroll, fixed assets, treasury and financial close. The same risk and control terminology is then used across the group.
So a procurement control at your Coimbatore plant and the equivalent control at a group subsidiary’s warehouse are described in the same language and tested against the same standard.
Entity and location-specific risks are added to that common framework rather than creating a separate control architecture. For example:
- A manufacturing plant gets controls over inventory movements, production records, cycle counts and fixed assets.
- An export-oriented entity gets additional controls over foreign exchange, export documentation and related receivables.
- A trading or retail entity gets greater exposure to customer credit, cash handling or returns.
- A holding company gets controls over consolidation, inter-company eliminations and group reporting.
- A warehouse gets an inventory shrinkage and cycle-count control line the corporate office doesn’t need.
The result is one document your CFO, your audit committee, and your statutory auditor can all read the same way, rather than a stack of location-specific spreadsheets that each need translating before anyone can compare them.
What each RCM entry captures
RCMs we built normally connects five elements:
- Risk: What could result in a material misstatement, loss or control failure?
- Control: What specific activity is intended to prevent or detect that risk?
- Control attributes: Is it preventive or detective, manual or automated, and how frequently does it operate?
- Control owner and evidence: Who is responsible, and what evidence demonstrates that the control was performed?
- Testing approach: How will operating effectiveness be assessed?
For a multi-entity group, PKC designed RCMs distinguish between group-level controls and entity or location-level controls. Group-wide approval limits, accounting policies, consolidation procedures and certain IT controls may apply across the organisation. Plant-level inventory controls or entity-specific revenue controls may require different testing.
Consolidation and inter-company risks captured explicitly
For a holding company with subsidiaries, we also map controls over inter-company reconciliations, consolidation adjustments, related party transactions and other group-level reporting activities into the RCM.
When IFC testing identifies a weakness at one plant or subsidiary, management can see whether the same control exists elsewhere, whether the exposure is systemic, and which remediation should be prioritised first.
For a CFO, the RCM answers: What can go wrong? Which control addresses it? Can we prove that the control actually worked? Our matrix answers these questions consistently across every entity and location, and becomes a working management tool.
Standardising IFC Documentation Across Locations
IFC requires documented policies, procedures, and evidence of operation. For a multi-location enterprise, standardising this documentation is quite a challenge.
A control that operates differently, and is documented differently, at every location is almost impossible to test consistently, and it is exactly what a statutory auditor’s IFC testing under Section 143(3)(i) intends to catch.
Each location develops its own documentation style. One location has detailed process narratives, another has flowcharts, the third has nothing written down. When the auditor asks for documentation, you have an inconsistent collection of documents that do not tell a coherent story.
Standardisation solves this problem.
It ensures that every location documents its controls in the same format, using the same terminology, and providing the same level of detail. So a reviewer can tell at a glance what’s actually different in substance vs what’s just been written up differently by different people.
What standardised IFC documentation includes
PKC helps enterprises standardise their IFC documentation around a common set of process narratives and control description templates, applied across every location regardless of whether it’s a plant, a warehouse, or a retail outlet.
The documentation includes:
- Process narratives: A description of each financial process, including the key steps, the people involved, and the controls in place.
- Control matrices: A structured document linking risks to controls, including control attributes and testing approach.
- Policies and procedures: Documented policies that set out the expected control activities, and procedures that describe how those activities are executed.
- Evidence templates: Standardised templates for documenting control evidence, such as approval records, reconciliation reports, and exception logs.
PKC’s approach to standardisation involves:
At PKC, we acknowledge the genuine local variation.
A retail outlet handling daily cash reconciliation and a plant reconciling job-work stock are performing different work, and forcing identical procedures onto both would produce documentation that doesn’t reflect reality, which defeats the purpose.
What stays constant is the format: every location’s SOP answers the same set of questions in the same order, uses the same terminology for control types and risk categories, and links back to the same RCM entry.
A reviewer moving from your Surat plant’s documentation to your Vadodara warehouse’s documentation should be able to navigate both without relearning the structure each time, even though the specific procedures inside look different.
Here’s the process we follow:
- Developing a documentation template: A standard format for documenting controls across all locations and entities.
- Training location teams: Ensuring that teams at each location understand the template and how to complete it.
- Reviewing and validating documentation: Reviewing the documentation from each location to ensure consistency and completeness.
- Consolidating into a single repository: Creating a single, searchable repository of IFC documentation for the entire group.
The result is a complete, consistent, and audit-ready set of IFC documentation.
Common IFC Gaps in Multi-Location Enterprises
Based on our 20+ years of experience with multi-location enterprises, certain IFC gaps appear repeatedly. Knowing these helps you anticipate where your own controls may be weak:
1. Decentralised vendor management
In many multi-location enterprises, vendor management is decentralised. Each location onboards its own vendors, sets its own credit terms, and manages its own vendor relationships. The result is inconsistent vendor due diligence, duplicate vendor records, and payment terms that vary by location.
Gap: No group-wide vendor master, no standardised vendor onboarding process, no centralised vendor due diligence.
Risk: Payments to fictitious vendors, duplicate payments, non-compliance with GST and TDS requirements.
2. Segregation of duties breaks down locally
Segregation of duties is a fundamental control principle. The same person should not be able to initiate, authorise, and record a transaction. In multi-location enterprises, segregation of duties often breaks down because:
- Small teams at each location mean the same person performs multiple roles
- Remote locations have limited staff, making segregation difficult
- Temporary staff or contractors are given excessive access
Gap: Lack of formal segregation of duties matrices, inconsistent application of segregation principles across locations.
Risk: Increased risk of fraud, errors going undetected, lack of accountability.
3. Approvals and manual entries are bypassed
Controls that work during normal operations may weaken during production peaks or staff shortages. Payments may be approved retrospectively, while manual journal entries for inventory adjustments, inter-location transfers or other unusual transactions may receive limited review.
Gap: Approval matrices not enforced, no monitoring of approval compliance, no consequence for bypassing approvals.
Risk: Unauthorised transactions, non-compliance with delegation of authority, increased risk of fraud.
4. Inventory and fixed asset controls vary by location
Physical verification may be performed at different frequencies, using different procedures, or by personnel who maintain the underlying records. Variances may then remain unexplained or be adjusted without adequate review.
Gap: Inconsistent verification frequency and procedures, lack of independent verification, and inadequate review and resolution of variances.
Risk: The existence, completeness, and valuation of inventory and fixed assets may not be reliably supported, increasing the risk of unexplained differences, inaccurate records, and audit findings.
5. Bank reconciliations are inconsistent
Bank reconciliations are performed at each location, but the frequency and rigour vary. Some locations reconcile daily, others reconcile monthly, or not at all. Unreconciled differences accumulate and are not investigated.
Gap: No standardised reconciliation process, no centralised monitoring, unreconciled differences not investigated.
Risk: Unidentified fraud, cash flow issues, inaccurate financial reporting.
6. Weak IT general controls
Multi-location enterprises often have fragmented IT environments. Different locations use different ERP instances. Access rights are not reviewed regularly. User accounts are not deactivated when staff leave.
Gap: Inconsistent IT controls, no centralised access management, no regular access reviews.
Risk: Unauthorised access to financial systems, data integrity issues, inability to rely on system-generated reports.
7. Inter-entity and period-end controls are incomplete
Loans, shared services, inter-company sales and cost allocations require timely reconciliation. For businesses with multiple GST registrations, revenue cut-off can also be applied differently between locations, particularly around year-end.
Related party transactions can create another blind spot when plant-level teams lack visibility of the group’s related party register.
Gap: Inter-entity reconciliations not performed regularly, differences not investigated, no centralised monitoring.
Risk: Misstated consolidation, inaccurate group financials, transfer pricing issues.
These gaps become more significant as locations multiply because management can no longer rely on informal oversight. ICAI’s guidance recognises that an internal financial control can be ineffective where material weaknesses exist, and that assessment involves understanding controls and evaluating both their design and operating effectiveness.
For a CFO, the practical test is to check whether the same critical financial controls are consistently designed, performed, evidenced and monitored across the entire organisation.
That is where a structured IFC assessment can distinguish isolated process variations from weaknesses that could affect group-level financial reporting.
Remediation and Ongoing Monitoring After the Initial Assessment
Identifying IFC gaps is only the first stage. Remediation is where the real work happens.
The remediation process we follow at PKC Management Consulting includes:
Risk-based remediation roadmap
Every finding identified through the IFC assessment and RCM is converted into a specific action. The remediation roadmap establishes:
- Priority ranking: Gaps are ranked by risk severity. High-risk gaps are addressed first.
- Action items: For each gap, a specific action to remediate it.
- Ownership: A named individual responsible for executing each action.
- Timeline: A realistic timeline for completion.
- Evidence: The documentation that will demonstrate remediation.
The remediation plan is presented to management for approval. This allows management to address high-risk weaknesses first.
For example, a segregation of duties conflict that allows one employee to create vendors and initiate payments should generally receive more immediate attention than an inconsistency in the format used for documenting a low-risk control.
Remediation can also be sequenced. Fixing a high-risk process at one representative plant, validating that the revised control works, and then applying the same framework across other locations can be more practical than running several disconnected remediation exercises at once.
Remediation execution
All findings don’t need a new policy.
A design gap, for instance may require a new approval workflow, clearer responsibilities or a revised control. An operating effectiveness gap may require a change in ownership, frequency, system enforcement, evidence collection or supervision.
PKC can support remediation execution in several ways:
- Control design: Designing new controls to address design gaps.
- Control documentation: Documenting controls in the standardised format.
- Control testing: Testing controls to confirm they are operating effectively.
- Training: Training location teams on new controls and documentation requirements.
The level of support depends on your internal capability. Some enterprises have the resources to execute remediation themselves, with PKC providing oversight and quality assurance. Others prefer our team to take a more hands-on role.
Ongoing monitoring
A control is not effectively remediated simply because management implemented it once. Staff change, ERP configurations evolve, transaction volumes increase and operating practices adapt. Without monitoring, a control that worked immediately after remediation can weaken again.
PKC helps enterprises establish ongoing monitoring through:
- Control self-assessments: Location teams complete regular self-assessments of their controls.
- Periodic testing: Key controls are tested periodically to confirm operating effectiveness.
- Issue tracking: Issues are tracked through to resolution.
- Management reporting: Regular reports to management on IFC status.
For example, if a plant introduces dual approval for payments above a defined threshold, management should not stop at documenting the procedure. Subsequent testing should establish whether the approvals occurred, whether the correct individuals approved them, and whether supporting evidence was retained.
Ongoing monitoring also changes the quality of management reporting. Instead of discovering control weaknesses immediately before the statutory audit, the CFO can maintain a current view of open findings, remediation status, overdue actions and newly identified exceptions.
For businesses with an Audit Committee, this creates a more useful reporting cycle. Significant control issues can be escalated when they arise, remediation can be tracked against agreed timelines, and recurring failures can be identified before they become larger financial reporting problems.
Timeline for an IFC strengthening engagement
A IFC strengthening engagement for a multi-location enterprise follows this tentative timeline:
- Gap assessment: 6–10 weeks
- RCM development: 4–6 weeks
- Documentation standardisation: 6–8 weeks (overlapping with RCM development)
- Remediation planning and execution: 12–24 weeks, depending on the number and complexity of gaps
- Ongoing monitoring: Continuous, with periodic testing
The total engagement typically takes 6–12 months from initial assessment to a fully operational IFC framework.
Now the question is, “can my internal team handle IFC remediation?”
Yes, in many cases, they can.
Internal teams understand your business, the systems and the practical realities of each location.
Where gaps are limited and sufficient resources are available, they can document controls, implement process changes and monitor remediation themselves.
External assistance becomes more relevant when objectivity, methodology, capacity or cross-location consistency is the constraint.
Internal teams may also find it difficult to challenge controls they helped design or operate, particularly when weaknesses involve staffing, approval practices or long-standing management processes.
For a multi-location enterprise, a practical model may involve management owning the remediation, with independent support used for the assessment, methodology, quality review, testing or higher-risk areas.
PKC’s approach to IFC/RCM development ensures that your risk management processes are aligned with both statutory requirements and industry best practices. We guide you in embedding controls that safeguard your business, mitigate potential risks, and drive sustainable growth.
The decision you have to take is about whether you build your IFC framework proactively, on your own timeline, or reactively, when the auditor finds gaps that you then have to fix under pressure.
If you are a multi-location enterprise evaluating your IFC framework, PKC can walk you through the firm’s approach, timeline, and fee structure for a business of your size and complexity.
The conversation is an opportunity to ask questions, understand the IFC methodology, and determine whether PKC is the right fit.
Schedule an Appointment with PKC’s IFC Team
FAQs
Q1: What is IFC (Internal Financial Controls) under the Companies Act, 2013?
Internal Financial Controls (IFC) are policies and procedures adopted by a company to ensure orderly and efficient conduct of business, adherence to policies, safeguarding of assets, prevention and detection of fraud and error, accuracy of accounting records, and timely preparation of reliable financial information. Under Section 134(5)(e), the Board of Directors must state in the annual report that they have laid down IFC and that they are adequate and operating effectively.
Q2: Which companies are required to report on IFC effectiveness?
Section 143(3)(i) requires the statutory auditor to report on the adequacy and operating effectiveness of IFC for all companies, not just listed ones. The auditor’s report must state whether the company has adequate IFC in place and whether they are operating effectively.
Q3: How does IFC differ from internal audit?
IFC is the framework of policies, procedures, and mechanisms that a company puts in place to ensure reliable financial reporting, efficient operations, and compliance. Internal audit is an independent review of the effectiveness, efficiency, and reliability of a company’s financial controls and processes. In short, IFC is the control framework; internal audit tests whether that framework is working.
Q4: How does PKC assess IFC gaps across multiple entities?
PKC’s IFC gap assessment follows a structured approach: scoping the engagement, conducting process walkthroughs at each location, identifying and documenting controls, identifying design and operating effectiveness gaps, and prioritising gaps by risk. The output is a comprehensive gap assessment report with a prioritised remediation plan.
Q5: What happens if IFC gaps are found during a statutory audit?
If the statutory auditor identifies material weaknesses in IFC, the auditor will report these in the audit report under Section 143(3)(i). This can affect the company’s credibility with banks, investors, and other stakeholders. The board will need to explain the findings and the remediation plan. Proactive identification and remediation of gaps before the statutory audit is the preferred approach.
Q6: How long does an IFC strengthening engagement typically take?
A typical IFC strengthening engagement for a multi-location enterprise takes 6–12 months from initial assessment to a fully operational IFC framework. The gap assessment takes 6–10 weeks, RCM development takes 4–6 weeks, documentation standardisation takes 6–8 weeks, and remediation planning and execution takes 12–24 weeks, depending on the number and complexity of gaps.
