Your internal audit team has spent the last three years mostly on financial controls, expense approvals, inventory counts, statutory compliance checks. That coverage was adequate when the business ran out of one plant and a handful of vendors.
Now you have three manufacturing locations, an ERP system, a growing vendor base you inherited through two acquisitions and a board that has started asking pointed questions about related party dealings with a group company.
Your existing audit plan was not built for these risks. Now, the real question is how much your current internal audit team can handle and where you need additional support. This is the situation a growing number of CFOs and heads of internal audit at mid-market Indian enterprises are facing heading into 2027.
This piece looks at where internal audit’s mandate is expanding, what audit committee priorities are shifting toward and how companies with multi-layered hierarchies and 100+ employees across locations are adjusting resourcing to keep up. It reflects where corporate governance in India is heading for this segment of the market.
| TL;DR Internal audit’s scope at mid-market Indian enterprises is moving well past financial controls, with more time going into IT/ERP controls, third-party risk, and related party transaction review.Section 188 of the Companies Act 2013 and SEBI’s tightened related party transaction rules mean audit committees expect more documented scrutiny of these transactions than before.Companies with 100+ employees across multiple locations are the ones feeling the resourcing gap most, since their internal audit team was often built for a single-location, finance-only mandate.Co-sourcing lets a company add specialist coverage (IT controls, vendor risk) without replacing its existing internal audit team.Audit committees are asking for more frequent, risk-ranked reporting instead of one annual summary. |
How Internal Audit’s Mandate Is Expanding Beyond Financial Controls
For many Indian businesses, internal audits began with financial controls. Auditors checked purchase orders, invoice approvals, statutory filings and payment processes. The focus was mainly on accurate reporting, compliance and fraud prevention.
That model is no longer enough.
As businesses expand across locations, systems and supplier networks, risks are no longer limited to the finance function. ERP, CRM and cloud platforms have introduced risks around user access, segregation of duties, system configuration, cybersecurity and data integrity.
Expansion and acquisitions have also increased exposure to vendor, operational and related-party risks.
The regulatory framework has moved in the same direction. Under Section 138 of the Companies Act, 2013, internal audit is mandatory for listed companies and specified unlisted public and private companies that meet prescribed thresholds.
But the legal requirement is just the starting point. Audit committees, statutory auditors, lenders and investors expect internal audit to provide assurance across the wider business.
The scope now includes:
- IT and ERP controls: access rights, segregation of duties, system configurations and data integrity
- Vendor and Third-Party Risk: due diligence, contract compliance and business continuity
- Related-Party Transactions: identification, approvals, documentation and monitoring
- Governance and Compliance: regulatory reporting, policy adherence and board oversight
- Operational Controls: procurement, inventory, production and process risks
ESG is also becoming important. SEBI’s BRSR framework has increased the importance of value-chain sustainability information for large listed companies.
Their suppliers may be asked to provide reliable data on emissions, labour practices, safety and other ESG metrics, even when those suppliers are not directly subject to BRSR requirements.
Financial controls remain the baseline. What has changed is the definition of internal audit itself, which is now expected to provide assurance over technology, operations, compliance, governance and emerging risks.
For growing businesses, this creates a capacity challenge.
The same audit team may now be expected to cover multiple locations, systems, vendors and risk areas without specialist expertise in every field.
Internal audits now need to cover these risks and your main challenge is whether your existing team has the skills, independence, technology, and capacity to handle them effectively.
That is becoming a central issue in audit and corporate governance.
Priority Shift 1: More Focus on IT and ERP Controls
Your ERP upgrade may have improved efficiency, but it may also have introduced control risks that did not exist in the legacy system.
Consider a company running SAP, Oracle or Tally across multiple locations. During implementation, employees were given access based on their roles. Temporary permissions were added to resolve migration issues, but some were never removed.
A couple of years later, nobody may have reviewed whether those permissions are still appropriate.
An employee who can create vendors may also be able to approve purchases. Someone who can enter invoices may also have payment release access. These segregation of duties conflicts can remain unnoticed until a control failure or fraud exposes them.
Internal audit does not need to conduct a full cybersecurity audit. Its role is to check whether system access matches job responsibilities, critical duties are properly separated, and ERP changes are authorised, tested and documented.
A practical approach is to prioritise ERP modules based on financial exposure. Procurement, inventory and payment processes should generally receive more attention than lower-risk functions.
The review should cover:
- User Access: Check whether permissions are appropriate, current and removed when employees change roles or leave.
- Segregation of Duties: Test whether one person can create vendors, approve purchases and release payments.
- Change Management: Check whether system changes are requested, approved, tested and documented.
- Data Integrity: Verify that information transferred between systems is complete and accurate.
- AI Governance: Identify which AI tools are being used, what data they access and how their outputs are reviewed.
Change management is an area quite easy to overlook.
For example, IT may modify an approval workflow or pricing rule without maintaining a clear record of who requested the change, who approved it and whether it was tested before going live.
Internal audit does not need to review every change made over the ERP’s lifetime. Sampling changes from the audit period can quickly show whether the control works in practice or exists only on paper.
This is also where many traditional internal audit teams face a capability gap. Their experience may be strong in financial and compliance testing but limited in ERP access reviews and technology controls.
The solution can involve training existing auditors, hiring specialist expertise , or bringing in external support for specific technology reviews.
Make sure the systems running the business receive the same control scrutiny as the financial processes they support.
Priority Shift 2: Third-Party and Vendor Risk Getting More Audit Time
Your business relies on suppliers, vendors and service providers.
Procurement manages them, legal reviews contracts and finance processes payments. But internal audit also needs to assess whether the controls around these relationships are actually working.
Vendor risk often grows quietly as a business expands
New suppliers are added during plant expansions, new product launches or urgent procurement requirements, sometimes without the same due diligence applied to the original vendor base.
The risks can extend beyond fraud including:
- Duplicate vendor records
- Inactive vendors still receiving payments
- Expired contracts
- Incorrect GST details
- Outdated or unauthorised pricing
- Dependence on a single critical supplier
Internal audits can identify these issues through targeted testing
A review can compare vendor master data with payment records, check whether onboarding followed the required approval process and confirm that invoices match contractual terms.
GST details also need to be reviewed. An incorrect or outdated vendor GSTIN can create input tax credit issues that may surface much later during a GST audit or assessment.
Pricing is another crucial area to test. A manufacturer may negotiate new rates after increasing purchase volumes, but those rates may never be updated in the ERP.
Comparing purchase order rates with actual invoiced rates can identify leakage that may otherwise appear simply as unexplained margin pressure.
Third-party risk also extends to operations and business continuity.
A single-source supplier can create production risks, while a logistics provider failure can disrupt operations across multiple locations. Critical technology vendors can create similar exposure through system outages, cybersecurity incidents or data breaches.
Regulators have also increased their focus on outsourcing and third-party risk, particularly in financial services.
For other businesses, the same principle applies, the more dependent you are on an external provider, the more important it becomes to understand and monitor that dependency.
ESG reporting is creating another consideration
Suppliers working with listed companies may be asked to provide sustainability and value-chain data.
Internal audit can help verify that this information is accurate, supported by evidence and consistent with company records.
Use a Risk-Based Approach
A risk-based vendor audit is more practical than auditing every supplier every year. Start with high-value suppliers, critical vendors, single-source suppliers and vendors added outside the normal onboarding process.
This gives management better visibility into the third parties that could have the greatest financial, operational, compliance or business continuity impact.
Priority Shift 3: Related Party Transaction Scrutiny Is Rising
Related party transactions have always been an important area of corporate governance. What is changing here is the level of scrutiny around how these transactions are identified, approved, priced and documented.
For promoter-led businesses, this is important because related parties may include group companies, promoter-controlled entities, directors, family-linked businesses or entities with common management.
Transactions with them may be completely legitimate, but they still need the right controls.
Why the Scrutiny Is Increasing
SEBI has strengthened related party transaction requirements for listed companies, including greater disclosure and audit committee oversight.
While these requirements apply directly to listed entities, they are also influencing governance expectations for unlisted businesses, especially those seeking institutional funding, working with lenders or considering a future listing.
For companies governed by the Companies Act, 2013, related party transactions covered by Section 188 may require board and, in specified cases, shareholder approval. Audit committees are also required to review related party transactions where Section 177 applies.
The real risk often lies in assuming a transaction is acceptable simply because the businesses share the same promoter or the transaction has been happening for years.
Internal audit should test whether:
- All RPTs are Identified: Related parties are correctly mapped across group companies, directors and other relevant relationships.
- Approvals are in Place: Required board, audit committee or shareholder approvals were obtained before the transaction.
- Pricing is Reasonable: Transactions are supported by an arm’s length assessment where required.
- Documentation is Complete: Contracts, commercial rationale, pricing basis and approvals are properly recorded.
- Disclosures are Accurate: Board reports and other statutory disclosures match the underlying transactions and approvals.
- Thresholds are Monitored: Transactions are tracked against applicable materiality and approval thresholds.
Consider a promoter-led business that rents office space from another group entity or regularly purchases services from a promoter-controlled company.
The transaction may be commercially justified, but internal audit should still check whether the pricing is supportable, the required approvals were obtained and the disclosure trail is complete.
This is where internal audit adds value. It can identify gaps before they become findings in a statutory audit, lender due diligence exercise or regulatory review.
Ensure that legitimate related party transactions are transparent, properly approved, and supported by adequate documentation.
Resourcing Trends: In-House Teams vs Co-Sourced Internal Audit
As the scope of internal audit expands, the resourcing question becomes harder.
Financial controls, ERP systems, vendor risk and related party transactions require different skills, and one small team may not have all of them.
For many businesses, the choice comes down to three models:
1. Build an In-House Team
Hiring additional auditors gives the company direct control over its internal audit function. It can work well when the business has a large, complex operation and enough recurring audit work to justify permanent specialist roles.
The downside is cost and capacity. Hiring an IT auditor or ERP specialist makes less sense when that expertise is only required for a few weeks each year.
2. Co-Source Specialist Expertise
Co-sourcing keeps the core internal audit function inside the business while bringing in external specialists for specific areas.
The internal team continues to manage the audit plan, understand business processes and report to the audit committee. External specialists can then support areas such as IT and ERP controls, vendor risk or related party transaction reviews.
This model addresses a common capability gap without requiring permanent specialist headcount. It also provides an independent perspective that can strengthen the quality of reporting to the audit committee.
3. Fully Outsource Internal Audit
Full outsourcing can make sense when a company does not have an internal audit team or does not need a permanent in-house function.
An external firm manages the audit plan, fieldwork and reporting, while management and the audit committee retain oversight and decision-making responsibilities.
What Should CFOs Consider?
The right model depends on the company’s size, complexity and risk profile.
A business with one location, simple processes and limited IT complexity may be adequately served by a small in-house team. A company operating across multiple locations, using a complex ERP and facing increasing compliance requirements may benefit more from co-sourcing.
The decision should also be based on where the capability gap actually exists. An internal audit team may be strong in financial controls but need specialist support for ERP access reviews or IT general controls.
A risk-based assessment can identify where external expertise will add the most value. This avoids rebuilding the entire audit function when only specific areas require additional capability.
For CFOs, the objective is to build an internal audit model with the right skills, independence, and coverage at a proportionate cost. The model can combine internal and external audit support based on the company’s needs.
How Audit Committees Are Adjusting Reporting Expectations
Audit committees are not only asking internal audits to cover more areas. They are also changing what they expect from audit reporting.
The traditional approach was a quarterly or annual report summarising completed audits, control gaps and corrective actions. That can leave the committee looking at problems several months after they occurred.
From Periodic Reports to Timely Updates
Audit committees want a clearer view of current risks, recurring exceptions and overdue corrective actions. The focus is shifting from “What did the last audit find?” to “What risks remain open, and what is management doing about them?”
For internal audit, this means reporting should provide:
- Risk-Ranked Findings: Clearly identify high, medium and low-risk issues.
- Action Tracking: Show who is responsible for remediation and the expected closure date.
- Trend Visibility: Highlight recurring exceptions and areas where control failures are increasing.
- Forward-Looking Insights: Flag emerging risks instead of reporting only historical findings.
- Concise Dashboards: Give directors a clear summary before the detailed findings.
For Example if a high-risk ERP access issue was identified in Q1 and remains unresolved in Q3, the next report should make that status immediately visible. The committee should not have to search through previous reports to determine whether management has acted.
Reporting Is Part of the Control Framework
A finding that remains open for months without documented follow-up is not simply a management issue. It can also indicate that the audit committee’s oversight and escalation process needs strengthening.
This makes action tracking an important part of internal audit reporting. Each significant finding should have a clear owner, target date, current status and explanation where remediation is delayed.
ICAI’s evolving internal audit standards also place greater emphasis on documentation, professional standards and transparency in the audit process. This reinforces the need for internal audit reports to clearly communicate the basis for findings and any significant deviations or limitations.
What Good Reporting Looks Like
A useful audit committee report does not need to be long. A one-page summary covering key risks, open high-risk findings, overdue actions and emerging concerns can give directors a much clearer picture before they move into the detailed report.
For businesses using a co-sourced internal audit model, reporting responsibilities should also be agreed upfront. Specialist findings from an external reviewer should reach the appropriate level of oversight without being diluted or delayed as they move through management.
Give the audit committee timely, clear, and actionable information about the risks that require its attention.
What This Means for Mid-Market Enterprises With 100+ Employees
For mid-market enterprises, growth often changes the risk profile faster than the internal audit function changes with it.
Multiple locations, larger vendor networks, new ERP systems and more complex management structures can create risks that were not covered in the original audit plan.
A plan that still focuses mainly on financial controls and routine process audits can therefore miss important risks in IT systems, vendor relationships and related party transactions.
Start With a Gap Assessment
The first step is not to rebuild the function. Review the current audit plan against these risks and identify where the existing team has sufficient expertise and where specialist support may be needed.
For many mid-market enterprises, the main capability gaps will be concentrated in:
- IT and ERP controls
- Vendor and third-party risk
- Related party transaction reviews
- Risk-based reporting and action tracking
Assess the Right Resourcing Model
The existing internal audit team may already have strong knowledge of financial controls, compliance and business processes. That foundation does not need to be replaced simply because the scope is expanding.
Training can address some gaps, while co-sourcing can provide specialist expertise in areas such as ERP controls, IT audit and vendor risk without adding permanent headcount.
For mid-market enterprises, this can be more practical when specialist skills are required only periodically rather than throughout the year.
Review Governance Expectations
Internal audit requirements depend on the company’s legal structure, turnover, borrowings and other prescribed criteria. Even where Section 138 of the Companies Act, 2013 does not apply, lenders, investors and other stakeholders may still expect stronger internal controls and governance.
The important question is whether the internal audit function is equipped to address the risks the business faces today.
Before the next audit committee meeting, review whether the audit plan clearly addresses IT controls, vendor risk and related party transactions. If these areas are missing, that is the gap to address before it becomes a finding.
You can strengthen the function in stages. Start with the highest-risk areas, build the existing team’s capabilities where practical, and bring in specialist support where internal resources are not enough.
The aim is a stronger internal audit function that gives management and the board better visibility into the risks that can actually affect the business.
As a CFO, Head of Internal Audit, or audit committee member at a mid-sized enterprise in manufacturing, retail, IT/ITES, pharma, healthcare, e-commerce, infrastructure, or logistics, and you want to discuss how these trends apply to your situation, schedule a focused discussion with PKC consultant who has worked with businesses of similar scale and complexity.
FAQs
How is the scope of internal audit changing for Indian enterprises?
Internal audit is expanding beyond financial controls to cover IT and ERP controls, third-party and vendor risk, related party transaction scrutiny, and governance. The enterprise technology stack is now an interconnected web of ERPs, CRMs, and cloud platforms. Audit committees demand assurance that systems have robust, built-in controls. The ICAI has proposed mandatory Standards on Internal Audit with peer review.
What is a co-sourced internal audit and when does it make sense?
Co-sourcing means retaining a small internal audit team in-house while bringing in an external firm to supplement capacity or provide specialist skills. It is popular in organisations that want to keep strategic oversight in-house while accessing external expertise for specific areas. It makes sense when your team lacks specialised skills (like IT audit) or when you need additional capacity for a specific project.
Why is related party transaction scrutiny increasing?
SEBI introduced stricter regulations on Material Related Party Transactions effective September 1, 2025. Listed companies must provide exhaustive disclosures including shareholding, profit contribution, and pricing methodology. The definition of “related party” has expanded. For unlisted companies, lenders and investors expect similar standards.
How much of an internal audit plan should be allocated to IT and ERP controls?
There is no fixed percentage, but IT controls should be a meaningful component of any audit plan for a business running ERP systems. At a minimum, the plan should cover user access reviews, segregation of duties analysis, change management controls, and data integrity checks annually. The specific allocation depends on the complexity of your IT environment and the risks identified in your risk assessment.
How often should audit committees receive internal audit updates?
Most audit committees now expect updates at least quarterly, with more frequent reporting for high-risk areas. The traditional annual or half-yearly reporting model is no longer sufficient. Audit committees want visibility into controls on an ongoing basis, not just at the end of the audit cycle.
How does PKC structure internal audit coverage for enterprises with 100+ employees across locations?
PKC uses a structured, risk-based methodology with AI-powered tools. The firm’s experts blend industry knowledge with AI-driven methodologies to provide a 360° view of financial health and operational efficiency. PKC’s internal audit portfolio includes IFC Audit Services, Risk and Compliance Solutions, Corporate Governance Audit, IT Governance and Compliance, Internal Controls, and Financial Statement Audits. The firm has 37 years of proven expertise across diverse industries.
