Get A Quote


    Risk Advisory

    Is Internal Audit Mandatory for Your Company? (2026 Thresholds Explained)

    Most companies assume an internal audit is a “listed company problem”. It isn’t. Under Section 138 of the Companies Act, 2013, a private or unlisted public company can be legally required to appoint an internal auditor purely on the basis of turnover, paid-up capital, or borrowing levels regardless of whether it’s listed at all. The thresholds are specific, and missing them isn’t a paperwork slip; it’s a compliance gap that surfaces during your next statutory audit, bank covenant review, or due diligence process.

    The mission of internal audit, as commonly defined, is to “enhance and protect organisational value by providing risk-based and objective assurance, advice, and insight.” In practice, that means internal auditors follow a structured framework: Condition, Criteria, Cause, Consequence, and Corrective Action, together known as the 5 C’s of internal audit to turn operational observations into actionable findings, not just a compliance checkbox.

    Does Internal Audit Apply to You? Check These Thresholds First

    This is the question most readers actually have, so it goes first. Internal audit is mandatory for:

    • Every listed company, with no exceptions.
    • Every unlisted public company that met any one of these thresholds in the preceding financial year: turnover of INR 200 crore or more; paid-up share capital of INR 50 crore or more; outstanding loans/borrowings from banks or financial institutions exceeding INR 100 crore at any point; or outstanding deposits of INR 25 crore or more at any point.
    • Every private company meeting any of the same four thresholds above.

    If your company crossed any one of these thresholds even briefly during the year, not just at year-end, the requirement applies. This is the detail companies most often miss: it’s a “preceding financial year, at any point” test, not a snapshot test.

    When and How You Must Appoint an Internal Auditor

    The Act doesn’t prescribe a fixed number of days for the internal auditor appointment itself, but the practical sequence is well established. The Board (in consultation with the Audit Committee, where one exists) passes a resolution appointing the internal auditor and, working with the auditor, sets the scope, periodicity, and methodology of the audit, none of which the Act fixes in advance, so this is a decision your Board needs to actually make rather than default on. The company must then file Form MGT-14 with the Registrar of Companies within 30 days of that Board meeting, under Section 117. Companies that qualify under the thresholds above are expected to have the function operational from the start of the financial year the requirement applies to — waiting until a statutory audit flags the gap is the single most common way this becomes a compliance problem instead of a routine appointment.

    Why This Gets Missed and What It Costs

    Internal audit non-compliance rarely makes headlines the way a GST raid or an SEBI penalty does, which is exactly why it’s easy to underestimate. There’s no single dramatic enforcement story attached to it in most founders’ minds, so the risk feels smaller than it is. But the actual exposure shows up in less visible ways: a statutory auditor flagging the gap under CARO 2020 Clause XIV (which specifically requires external auditors to assess whether your internal audit system is proportional to your size and business); a lender’s covenant review surfacing it during a credit renewal; or a due diligence team finding it during a fundraise or acquisition, at exactly the moment you can least afford a governance question mark.

    The Companies Act doesn’t carry a dedicated penalty clause for Section 138 non-compliance, so it falls back to Section 450’s general penalty: INR 10,000 for the company and each officer in default, rising by INR 1,000 per day of continuing default, capped at INR 2 lakh for the company and INR 50,000 per officer. The amounts are modest on paper, but they compound daily and attach personally to officers and companies that have already been penalised for exactly this. For a broader view of where audit exposure tends to concentrate across a business, see our overview of the audit and compliance risks businesses face today and our note on an actual MCA penalty order for non-appointment of an internal auditor.

    What an Internal Auditor Actually Does

    Beyond satisfying the statutory requirement, a properly functioning internal audit function does four things on an ongoing basis: reviews operations, policies, and procedures to help management strengthen controls; certifies that risk-taking stays within limits the Board has actually defined (not just assumed); continuously evaluates whether existing controls work and recommends fixes when they don’t; and supports management in catching fraud before it compounds.

    Auditors can be chartered accountants, cost accountants, or other board-designated professionals, and they’re expected to maintain independence, meaning they evaluate operations without being pulled into executive decision-making themselves. For more on how the audit relationship is structured, see What Is Internal Audit.

    SEBI’s Listing Agreement Requirements

    For listed companies specifically, SEBI Clause 49 adds further obligations: internal control weaknesses must be reported, the internal audit function must be demonstrably operational (not just on paper), suspected fraud or irregularities arising from control failures must be identified and reported, and the CEO and CFO must personally certify the effectiveness of internal controls and the actions taken on any deficiencies found.

    The Internal Audit Report: What Good Output Looks Like

    A useful internal audit report isn’t a generic template; it reflects the auditor’s professional judgement and direct consultation with the auditee, and it’s customised to what the board or audit committee actually needs to act on. At minimum, it should include clear conclusions drawn from the audit procedures and evidence reviewed; confirmation of compliance with the applicable Standards on Internal Audit (SIAs) issued by ICAI, which cover matters like audit planning, documentation, and reporting; and properly maintained draft and final versions for reference and compliance purposes.

    What This Means for You Right Now

    If your company crossed any of the thresholds above in the last financial year and doesn’t yet have an internal audit function in place, that’s a gap worth closing before it surfaces in a statutory audit, lender review, or due diligence process not after. If you already have one, the more useful question is whether it’s actually delivering risk-based insight or just producing a checkbox report each quarter. MBG’s Internal Audit Services team works with companies on both establishing the function where it’s required and strengthening it where it already exists but isn’t pulling its weight.

    Contact us:
    Email: communications@mbgcorp.com
    Phone: +91 88601-90008

    Additional Resources:

    • Tags
    • risk advisory services
    • Internal Audit Services
    • risk advisory
    • Internal Audit

    What can we help you achieve?

    Stay one step ahead in a rapidly changing world and build
    a sustainable future with us.