Get A Free Consultation
Since 2002, MBG Corporate Services has built its IFC and ICFR practice alongside a broader advisory business that now spans 600+ professionals across 18+ offices in 9 countries, serving over 100 Fortune 500 companies and 5,000+ clients globally. That scale means when your auditor flags a gap under Section 143(3)(i), or your board’s Directors’ Responsibility Statement under Section 134(5)(e) is due, you’re working with a team that has run this process before, at your scale, under real deadline pressure, not a firm building its first Risk Control Matrix on your engagement.
Our ICFR audits follow the COSO 2013 framework’s five integrated components control environment, risk assessment, control activities, information and communication, and monitoring mapped against India’s three-tier ICAI guidance for design, implementation, and operating effectiveness. In practice, this means every engagement runs through a proper Test of Design (TOD) to confirm a control is structured correctly, followed by a Test of Operating Effectiveness (TOE) to confirm it’s actually working as intended, not just documented on paper.
This methodology is applied across the specific process areas where financial reporting risk actually lives: revenue cycle controls, procurement and expenditure controls, inventory and asset controls, and IT-dependent and IT general controls (ITGC). We also work across SEBI LODR Regulation 17(8) CEO/CFO certification requirements and SOX/JSOX-aligned controls for Indian subsidiaries of US- or Japan-listed parent companies.
We start by identifying and assessing financial-reporting risk at the process and assertion level across your significant accounts, so testing effort is prioritized where the actual exposure sits, not spread evenly across low-risk areas.
We document existing controls, or build them where none exist, into a structured Risk Control Matrix covering revenue, procurement, inventory, and IT-dependent processes. Where SOPs are outdated, we revise them into an audit-ready compliance framework aligned to the RCM.
Each control in the RCM is tested through Test of Design and Test of Operating Effectiveness, supported by structured control walkthroughs, segregation-of-duties testing, and dedicated ITGC assessment for automated and system-dependent controls.
Where testing surfaces a deficiency, we translate it into a prioritised, board-ready remediation roadmap sequenced by risk severity, not just by ease of fix.
We stay through implementation, working directly with your finance and process owners until each identified weakness is genuinely closed and retested.
Once tested and remediated, we help embed the control framework into daily operations, drawing on IPPF governance standards so it holds up beyond a single audit cycle.
For finance teams without the internal bandwidth to run an ICFR programme independently, we offer full or partial outsourcing, managed end-to-end with reporting aligned to your board and audit committee calendar.
Requires the board of a listed company to confirm internal financial controls are adequate and operating effectively. Rule 8(5)(viii) of the Companies (Accounts) Rules, 2014, extends related board-report disclosure more broadly.
Requires the statutory auditor to independently opine on whether internal financial controls over financial reporting are adequate and operating effectively the finding that most often triggers an urgent ICFR engagement.
Requires an annual certificate from the CEO and CFO confirming responsibility for internal controls over financial reporting, with disclosure of any deficiencies to auditors and the audit committee.
Relevant for Indian entities that are subsidiaries of US-listed or Japan-listed parents, where Sarbanes-Oxley or J-SOX obligations typically flow down to the local entity’s controls. See our dedicated guidance on SOX in the current regulatory scenario and SOX readiness for IPO-bound companies.
IFC and ICFR engagements rarely sit in isolation. We frequently coordinate this work with our Risk Advisory for broader governance and internal audit needs, our Financial Reporting and Assurance team for statutory audit alignment, and our Financial Due Diligence practice when ICFR readiness feeds into an upcoming transaction or investor review.
We assess your existing processes, policies, and control environment against the COSO framework and applicable statutory requirements.
We build or refine your Risk Control Matrix, mapped to the specific compliance obligation driving the engagement.
We run Test of Design and Test of Operating Effectiveness against the RCM, following the same testing discipline needed for ongoing control assurance, not a one-time check.
If your auditor has flagged a control gap, your board sign-off is approaching, or you’re preparing for investor due diligence, get in touch to start with a readiness discussion no obligation, just a clear view of where your controls stand today.
Stay one step ahead in a rapidly changing world and build a sustainable future with us.
Submit your enquiries to MBG Corporate Services. We will respond as soon as possible.
Get A Free Consultation