Get A Quote


    IFC and ICFR Audit

    Audit-ready internal controls, board sign-off confidence, and fewer surprises at year-end close.

    Get A Free Consultation

      Since 2002, MBG Corporate Services has built its IFC and ICFR practice alongside a broader advisory business that now spans 600+ professionals across 18+ offices in 9 countries, serving over 100 Fortune 500 companies and 5,000+ clients globally. That scale means when your auditor flags a gap under Section 143(3)(i), or your board’s Directors’ Responsibility Statement under Section 134(5)(e) is due, you’re working with a team that has run this process before, at your scale, under real deadline pressure, not a firm building its first Risk Control Matrix on your engagement.

      Why Companies Engage MBG for IFC & ICFR

      Our ICFR audits follow the COSO 2013 framework’s five integrated components control environment, risk assessment, control activities, information and communication, and monitoring mapped against India’s three-tier ICAI guidance for design, implementation, and operating effectiveness. In practice, this means every engagement runs through a proper Test of Design (TOD) to confirm a control is structured correctly, followed by a Test of Operating Effectiveness (TOE) to confirm it’s actually working as intended, not just documented on paper.

      This methodology is applied across the specific process areas where financial reporting risk actually lives: revenue cycle controls, procurement and expenditure controls, inventory and asset controls, and IT-dependent and IT general controls (ITGC). We also work across SEBI LODR Regulation 17(8) CEO/CFO certification requirements and SOX/JSOX-aligned controls for Indian subsidiaries of US- or Japan-listed parent companies.

      What MBG Delivers

      ICFR Risk Assessment

      We start by identifying and assessing financial-reporting risk at the process and assertion level across your significant accounts, so testing effort is prioritized where the actual exposure sits, not spread evenly across low-risk areas.

      Documentation & Revision of Controls

      We document existing controls, or build them where none exist, into a structured Risk Control Matrix covering revenue, procurement, inventory, and IT-dependent processes. Where SOPs are outdated, we revise them into an audit-ready compliance framework aligned to the RCM.

      Testing of Controls

      Each control in the RCM is tested through Test of Design and Test of Operating Effectiveness, supported by structured control walkthroughs, segregation-of-duties testing, and dedicated ITGC assessment for automated and system-dependent controls.

      Remedial Planning & Recommendations

      Where testing surfaces a deficiency, we translate it into a prioritised, board-ready remediation roadmap sequenced by risk severity, not just by ease of fix.

      Remediation of Control Weaknesses

      We stay through implementation, working directly with your finance and process owners until each identified weakness is genuinely closed and retested.

      Implementation of Control Framework

      Once tested and remediated, we help embed the control framework into daily operations, drawing on IPPF governance standards so it holds up beyond a single audit cycle.

      Project Management / Outsourcing

      For finance teams without the internal bandwidth to run an ICFR programme independently, we offer full or partial outsourcing, managed end-to-end with reporting aligned to your board and audit committee calendar.

      Regulatory Scope We Work Against

      Section 134(5)(e): Directors’ Responsibility Statement

      Requires the board of a listed company to confirm internal financial controls are adequate and operating effectively. Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014, extends related board-report disclosure more broadly.

      Section 143(3)(i): Statutory Auditor’s Opinion

      Requires the statutory auditor to independently opine on whether internal financial controls over financial reporting are adequate and operating effectively the finding that most often triggers an urgent ICFR engagement.

      SEBI LODR Regulation 17(8): CEO/CFO Certification

      Requires an annual certificate from the CEO and CFO confirming responsibility for internal controls over financial reporting, with disclosure of any deficiencies to auditors and the audit committee.

      SOX & JSOX for Indian Subsidiaries

      Relevant for Indian entities that are subsidiaries of US-listed or Japan-listed parents, where Sarbanes-Oxley or J-SOX obligations typically flow down to the local entity’s controls. See our dedicated guidance on SOX in the current regulatory scenario and SOX readiness for IPO-bound companies.

      Works Alongside Our Broader Advisory Practice

      IFC and ICFR engagements rarely sit in isolation. We frequently coordinate this work with our Risk Advisory for broader governance and internal audit needs, our Financial Reporting and Assurance team for statutory audit alignment, and our Financial Due Diligence practice when ICFR readiness feeds into an upcoming transaction or investor review.

      Our ICFR Audit Approach

      Evaluate

      We assess your existing processes, policies, and control environment against the COSO framework and applicable statutory requirements.

      Define

      We build or refine your Risk Control Matrix, mapped to the specific compliance obligation driving the engagement.

      Test

      We run Test of Design and Test of Operating Effectiveness against the RCM, following the same testing discipline needed for ongoing control assurance, not a one-time check.

      What You Receive

      Talk to Our ICFR Specialists

      If your auditor has flagged a control gap, your board sign-off is approaching, or you’re preparing for investor due diligence, get in touch to start with a readiness discussion no obligation, just a clear view of where your controls stand today.

      Supporting Resources

      Frequently Asked Questions

      - What is the difference between IFC and ICFR?
      IFC (Internal Financial Controls) is the broader term used under the Companies Act 2013, covering the full set of policies and procedures a company adopts to ensure orderly and efficient operations. ICFR (Internal Control over Financial Reporting) is the subset of IFC specifically focused on controls that ensure the reliability of financial reporting. In practice, most Indian statutory requirements, including Section 143(3)(i), are assessed through an ICFR lens even when the broader term IFC is used.
      + Who is required to comply with ICFR under the Companies Act 2013?
      + What happens if my auditor flags an ICFR deficiency?
      + How long does an ICFR audit engagement typically take?
      + Is ICFR the same as SOX compliance?
      + What is a Risk Control Matrix (RCM) and do I need one?
      + Does MBG only work with listed companies on ICFR?

      What can we help you achieve?

      Stay one step ahead in a rapidly changing world and build a sustainable future with us.

      Get a quote
      single

      Explore more Risk Advisory services:

      We're here to help you.

      Submit your enquiries to MBG Corporate Services. We will respond as soon as possible.

      Call us at: +91 88601-90008

      Get A Free Consultation