Internal Financial Controls: The Indian Reporting Requirement
An internal financial control is a control over financial reporting, and a control assertion is the claim that a stated one of them was designed adequately and operated effectively throughout the period, evidenced by testing and signed by somebody accountable. In India the Companies Act places a reporting duty on the board and on the auditor, and the text sits with the Ministry of Corporate Affairs.
The word that changes everything in that sentence is throughout. An ordinary conclusion about a control can be reached on a date: the control was in place, somebody looked at it, it worked. A control assertion is about a whole stretch of time, so a control that worked for eleven and a half months and stopped for eleven working days has not operated effectively throughout the period, however small the loss turned out to be. Everything that follows rests on that one word: why testing needs a sample spread across the period rather than a visit, why a gap has to be sized rather than waved off, and why one particular finding at the invented bank in this case cannot be left out of the conclusion even though it sits outside the assessment.
What makes a control an internal financial control rather than any other control?
An internal financial controlA control over financial reporting, standing between something that happened and a number that gets reported. is a control over financial reporting. The definition is that short, and the useful part of it is the word between. Something happened in the world, and a number about it later appears in a set of financial statements. An internal financial control stands somewhere on the road between those two events, and its job is to keep the number that arrives a fair description of the event.
The everyday version is worth holding on to. The institutional version is the same shape at a much larger scale. A street vendor selling tea outside an office building counts the cash box at closing time and writes the day's takings in a notebook. There are two very different things happening there and only one of them is a control over the notebook. Counting the cash is the control: it is where the figure gets decided. Copying the counted figure into the notebook is not where anything gets decided at all, and a check on the copying can be perfect while the count itself was rushed and wrong. The control that decides a reported number is almost never sitting next to where the number is written down. That single observation is the reason the invented bank in this case has a problem.
Not every control is an internal financial control. A door lock at a currency chest is a control and it protects cash rather than a reported figure. A password rotation rule is a control and it protects access. Both matter enormously, and neither is making a claim about a number in a set of accounts. A control joins the internal financial controls population when a reported figure moves if the control fails. The test asks about the road the number travelled rather than about how important the control feels.
What exactly does a control assertion claim?
A control assertionA claim that a stated control was designed adequately and operated effectively throughout a period, evidenced by testing and signed. is a claim, and like every claim it can be read part by part to see what is actually being promised. There are six parts, and every one of them does work that the others cannot do. A stated control, so there is something specific being talked about. Designed adequately, so the thing described would have achieved its purpose if it happened. Operated effectively, so it actually happened. Throughout the period, so it happened across the whole stretch rather than on the day somebody visited. Evidenced by testing, so somebody looked and kept what they looked at. Signed by somebody accountable, so there is a name that can be asked to produce the evidence. A control assertion is six separate promises wearing one sentence, and the fourth of them is the one that quietly goes missing.
Why does the word throughout do more work than any other word in that sentence?
Take the fourth part on its own. The fourth part decides how much evidence the other five need. Throughout the periodThe whole stretch of time being reported on. A control that stopped for eleven working days did not operate effectively across it. means the whole stretch of time the report covers, and a claim about a whole stretch cannot be supported by a visit. If a control ran on the two days somebody came to look and did not run in the eight weeks between those visits, every observation made was true and the assertion built on them is false. An assertion about a period is a claim about the days nobody was watching. The evidence for it has to be a sample spread across the period rather than a demonstration.
Vindhya Commercial Bank Limited, invented, has a clean example of the difference and it costs almost nothing in money. The collateral valuation feed at the bank was stale for eleven working days in month 10, and during those eleven days 340 loans carried the wrong mark. The stale feed is incident I10 in the bank's operational loss record, and it cost Rs 1.4 crore gross with nothing recovered, so Rs 1.4 crore net, against a whole year of net operational loss of Rs 43.8 crore. No customer lost money. On a visit basis the control looks fine. A visit almost certainly lands on one of the many working days the control was running. On a period basis it is not fine at all, and the entire distance between those two readings is the word throughout.
A control at Vindhya Commercial Bank Limited, invented, worked on every working day of the twelve numbered months except for eleven working days in month 10. Did it operate effectively throughout the period?
Where does a control activity sit inside the five component structure of internal control?
The Committee of Sponsoring Organizations of the Treadway Commission set out the five component structure of internal control in 1992 and updated it in 2013. Its five components are the control environment, risk assessment, control activities, information and communication, and monitoring activities. A control in the ordinary sense, meaning a thing somebody does, is a control activity. Control activities are one component out of five.
A control population describes one component, so an institution can test every control it has and still say nothing about the other four. Vindhya Commercial Bank Limited, invented, has 214 key controls spread across nine processes numbered PR1 to PR9, and independent testing of those 214 produced an end to end result of 172 effective, being 80.4 per cent. Every one of the 214 sits in the control activities component. Nothing in that 80.4 per cent says anything about the tone the institution sets, about which risks it decided could go wrong with a reported figure, about whether the right facts reach the people who have to use them, or about who is watching the watching. The number 9 carries six separate meanings in this bank and needs naming carefully each time: the nine processes PR1 to PR9 used here, the nine policies PL1 to PL9, the nine letters of credit in incident I13, the nine hours of the vendor gateway failure in incident I9, the nine issues sitting in ageing bucket AG5, and the nine of the 42 control findings that carry no stated cause.
Whose five component structure of internal control is drawn above, and when was it published and updated?
Who signs a control assertion, and what is the signature actually a claim about?
Somebody has to sign, and what an accountable signatoryThe person whose name sits on the conclusion and who has to be able to show what they looked at. is claiming is narrower and harder than most readers assume. The signature does not say that nothing went wrong during the period. The signature says that a stated set of controls was assessed, that the evidence for that assessment exists and can be produced, and that the conclusion written above the name is what the evidence supports. A signature on a controls conclusion is a claim about having looked, not a claim that there was nothing to find.
Read it the other way round and the point becomes obvious. If a signature meant nothing went wrong, then any institution that found a problem during the year could never sign anything, and the honest institutions would be the silent ones. The signature does the opposite by putting a name against the work, so a person can be asked what they tested, how much of it, spread over which days, and what they did about what they found. At Vindhya Commercial Bank Limited, invented, the internal conclusion on controls over financial reporting is signed by Vivek Anantharaman, the chief financial officer, and goes to committee G3, the audit committee. The control findings and the issue ageing go to committee G3 as well. The testing that stands behind it is run by internal audit under Rustom Batliwala. The split between signing and testing is the ordinary one. The Institute of Internal Auditors restated the vocabulary for it, the three lines, in 2020: the business runs the control, the risk and compliance functions set the policy and challenge, and internal audit tests independently and reports outside management.
A material weakness was found at Vindhya Commercial Bank Limited, invented, during the period. Can anybody still sign a conclusion on internal financial controls?
Where does the Indian requirement come from, and which body holds the text?
Everything above this heading is jurisdiction free. A control over financial reporting, a six part assertion about it, evidence spread across the period and a name at the bottom: that mechanism is the same wherever an institution reports numbers to anybody. Countries differ on whether somebody is obliged to write that assertion down and publish it, on who exactly is obliged, and on what the published version has to contain. In India that obligation is company law rather than banking rules, so the same duty reaches a steel maker and a bank alike.
What is named here, and where the binding version lives
The Companies Act places a reporting dutyAn obligation to state a conclusion in a report. In India the Companies Act places it on the board and on the auditor. on the board and a separate reporting duty on the auditor, both in respect of internal financial controls. Two duties, two different people, one subject.
The text of that duty, who it applies to, who is exempt from it, and the form the report has to take all come from the Ministry of Corporate Affairs at mca.gov.in. The assurance standard and the guidance note that tell a professional how the work is done and how the conclusion is written come from the Institute of Chartered Accountants of India at icai.org. Where the reporting entity is a bank, what binds it in addition comes from the Reserve Bank of India at rbi.org.in.
Every section number, rule number, threshold, applicability test, exemption, form name, ratio and effective date must be read at the source. Applicability and exemptions in this area have moved before and can move again, so the only safe reading is the current text from the body that holds it.
Which body holds the text of the Indian reporting duty on internal financial controls, and which holds the assurance standard behind it?
Why name a duty and a body rather than a section, rule or date?
Because a plausible wrong number is worse than a gap, and in a regulatory area it is much worse. A reader who is told there is a duty and sent to mca.gov.in loses two minutes and arrives at the current text. A reader who is told a section number that changed, or an exemption that was withdrawn, arrives at a conclusion and stops looking. A specific wrong answer feels finished in a way that an honest gap does not, so the second reader is worse off than if nothing had been said at all.
There is a second reason and it is about how this material ages. A mechanism such as the six part assertion is stable: it was the same idea before any of the current Indian text existed and it will survive the next amendment to it. Applicability tests, exemption schedules, thresholds and forms are the opposite: they are exactly the parts that get revised, and they get revised without anybody updating an article written three years earlier. The durable half does not move; the volatile half sits with the body that maintains it.
How is the scope of the assessment decided, and what does widening it change?
The scopeWhich processes and controls an assessment covers, decided before any evidence exists. of an internal financial controls assessment is the list of processes and controls it covers, and the single most important thing about it is when it gets decided. Scope is decided first, before any testing has happened and therefore before anybody knows what the testing will find. A control outside the scope cannot produce a finding inside it, so a scope decision made in the absence of evidence silently bounds every conclusion that follows.
Deciding in advance is not a criticism of anybody. Scope has to be decided before the work starts, and every assurance exercise ever run has the same property. The question worth asking is what the scope was drawn around. Two candidates present themselves and they give very different answers. The scope can be drawn around where the numbers are assembled, meaning the reporting and close process, and that version is tidy, quick to plan and easy to test. Or it can be drawn around where the numbers are made, meaning the operating processes in which somebody decides a value, and that is messy, slow and much larger. The first is defensible on paper. The second is where the controls that can move a reported figure actually live.
A bank scopes its internal financial controls assessment to the process that produces the financial statements. What has it left out?
The assessment at Vindhya Commercial Bank Limited, invented, covers process PR8, financial reporting and close. Before reading on: where is the finding it has to worry about likely to be sitting?
What does the assessment at this bank actually cover, and what does it leave outside?
Vindhya Commercial Bank Limited, invented, runs its internal financial controls assessmentThe exercise that gathers the evidence and reaches the conclusion the report then states. over process PR8, financial reporting and close. Process PR8 is where the numbers are assembled, and not where most of them are made. The bank has nine processes numbered PR1 to PR9 and eight of them sit outside the assessment, including the one that decides how the secured lending book is valued.
| Process | What it decides or does | In the assessment |
|---|---|---|
| PR1 | Account opening and customer onboarding | outside |
| PR2 | Lending and disbursal | outside |
| PR3 | Collateral management and valuation | outside |
| PR4 | Payments and settlement | outside |
| PR5 | Trade finance | outside |
| PR6 | Treasury dealing and settlement | outside |
| PR7 | Deposit servicing | outside |
| PR8 | Financial reporting and close | inside |
| PR9 | Access management and information security | outside |
One number followed backwards makes the point concrete. The bank holds standard asset provisionsAmounts held against expected loss. Named here as an object; how a provision is computed belongs to accounting and audit. of Rs 494.4 crore, and those sit inside other liabilities and provisions of Rs 3,120 crore rather than being netted off advances. Rs 494.4 crore is a reported number. Rs 494.4 crore depends on how the secured book is marked, and the control that decides that mark is the collateral valuation control in process PR3. So the chain that produces one reported figure at this bank starts two processes away from the process the assessment covers.
Which finding does the assessment have to consider, and why that one?
Vindhya Commercial Bank Limited, invented, produced 42 control findings in the twelve numbered months, rated on its own four point scale D1 to D4, and exactly one of them is a D4 material weakness. The D4 sits on the collateral valuation control in process PR3. The control failed for eleven working days in incident I10, and no monitoring control detected the failure. The control decides the valuation of Rs 8,640 crore of secured advances, being 15.0 per cent of net advances of Rs 57,600 crore and 9.0 per cent of total assets of Rs 96,000 crore. The base has to be named every time the share is quoted. A wrong collateral mark feeds a provision and the provision feeds a reported number, so the finding has to be considered for the internal financial controls assessment even though it sits outside the process the assessment covers.
Here is where most readers reach for the wrong measure. Incident I10 cost Rs 1.4 crore gross with nothing recovered, so Rs 1.4 crore net, against the year's whole net operational loss of Rs 43.8 crore across incidents I1 to I13. Rs 1.4 crore is a small number in a bank of this size and it is entirely the wrong number to be looking at. The loss is what this particular instance happened to cost. The assessment is not about this instance at all: it is about a control that decides the value of Rs 8,640 crore of secured advances, being 15.0 per cent of net advances of Rs 57,600 crore, and that is the size the conclusion has to reckon with. The loss booked and the book the control decides are separated by more than three orders of magnitude, and only the second of them is what an internal financial controls assessment is looking at.
Incident I10 at Vindhya Commercial Bank Limited, invented, cost Rs 1.4 crore net. Why does a Rs 1.4 crore loss have anything to do with a reporting conclusion?
One more fact about that finding changes how a reader should feel about the eleven days. The same collateral valuation feed had already gone stale for two working days in month 6, and a data quality check caught it. The two day gap is near miss N3 in the bank's near miss record. Nobody raised it as an issue. Four months later the same feed went stale for eleven working days and this time nothing caught it at all. The information that the feed could go stale was already inside the invented bank, collected and written down, four months before the failure that mattered, and the value of a near miss record is the linking rather than the recording.
An assessment covers one process and then widens one process at a time. Before the control below is moved: does the number of material weaknesses inside the assessment rise smoothly as the scope widens?
What happens to the two measures as the scope widens?
Two things can be counted as an assessment widens and they behave nothing like each other. The finding count is a smooth measure: there are 42 control findings in this invented bank, and pulling in another process pulls in roughly another slice of them. The material weakness count is not smooth at all: there is exactly one D4 in the whole year, so it is zero until the process holding it comes inside the scope and then it is one. The measure that rises evenly says how much work has been taken on, and the measure that does nothing and then jumps says whether the conclusion changes. Reading the first as though it were the second is the ordinary mistake.
The number 42 carries four separate meanings in this invented bank and needs naming carefully each time: the 42 control findings used here, the Rs 42.0 crore gross loss of incident I2, the 42 of 147 risk data elements carrying all eight attributes T1 to T8, and the 42 open issues older than 90 days. Only the first of the four is the subject here. Everything drawn below also rests on one assumption that is not in the bank's record: that the 42 findings spread evenly across the nine processes at 4.67 each. The invented record holds no per process finding count, so the smooth line is illustrative and the step is not.
Widen the scope one process at a time and watch the two measures separate
One control: how many of the nine processes sit inside the internal financial controls assessment, from one to nine. The order of entry is stated on screen. The invented record locks PR8, financial reporting and close, as the process the assessment covers, so PR8 enters first, then PR1, PR2, PR3, PR4, PR5, PR6, PR7 and PR9 in number order. At one process, about 4.7 of the 42 findings and 0 material weaknesses are inside. At three processes, about 14.0 findings and still 0 material weaknesses. At four processes PR3 has entered, so about 18.7 findings and 1 material weakness sit inside. At all nine, 42.0 findings and 1 material weakness. The finding count rises evenly the whole way, and the material weakness that decides the conclusion arrives in a single jump at four.
With process PR8 alone inside the assessment, about 4.7 of the 42 findings sit inside it under the even spread assumed here, and 0 of the bank's one material weakness does, because that one sits in process PR3.
Scoping by where the numbers are assembled, and what it costs
The failure does not look like one from the inside. An assessment drawn around financial reporting and close can be planned in a week, tested cleanly and concluded on time. Every control inside it can operate perfectly for twelve months. The scope memorandum is defensible, the testing is real, the evidence is filed, and the conclusion is honest about everything it covers.
Meanwhile the collateral valuation control that decides how the secured book is marked sits in process PR3, the trade finance controls sit in process PR5 and the lending and disbursal controls sit in process PR2. The secured book behind that mark carries counterparties such as Nirjhar Industries Limited, invented, the largest single name exposure of the bank. The scope decision was made before any evidence existed and it quietly bounded the conclusion, in exactly the way that choosing 214 controls as the key ones bounds every testing result this bank will ever report.
There is a second version of the same failure and it is the one the control above is built on: scoping by the size of the balance a control sits near rather than by the number the control actually feeds. Both versions produce a defensible looking scope memorandum. Nobody in the room was arguing about scope at all, so both can leave the year's single material weakness outside the assessment on a technicality nobody ever argued about.
Who actually picks up an internal financial controls conclusion, and what can they do with it?
Three kinds of reader use one, and each of them is looking for something slightly different. A lending decision rests on figures that somebody inside the borrower produced, so a credit officer at a lending institution reads the conclusion as a signal about the reliability of those numbers. An equity analyst reads it the same way and adds a second question: whether anything was reported as a weakness this year that was not there last year. A new weakness is news and a repeat weakness is a management story. A diligence team looking at an acquisition is about to inherit both the numbers and the controls that made them, so it reads the conclusion hardest of all.
All three are really reading the scope rather than the conclusion. A conclusion is short and reads the same whether the assessment covered one process or nine. The scope says what the conclusion could possibly have been about. So the useful sequence for a reader is: find what was assessed, find what period it covers, find whether anything was reported as a weakness, and only then read what the conclusion says. The conclusion is printed first, so most people read in the opposite order and finish with a comfortable feeling and almost no information.
What does a clean conclusion on internal financial controls not mean?
Two things, and both of them are properties of every assurance conclusion ever written rather than criticisms of any particular one. First, it says nothing about the controls that were not assessed. The scope was decided before any evidence existed, so a conclusion covering process PR8 at the invented bank is silent about the eight processes it did not cover, including the one holding the year's single material weakness. Second, it says nothing about today. A conclusion on internal financial controls is written in the past tense on purpose, about a period that has closed, and a control can be adequate across a whole year and stop working in the first week of the next one.
Neither of those is a reason to distrust a conclusion. Both limits are the shape of the instrument. A control assertion is a report on a closed period and a chosen scope, and the two limits it carries are exactly the two facts a reader has to establish before the conclusion means anything. Read the period, read the scope, then read the conclusion.
Vindhya Commercial Bank Limited, invented, concludes that the internal financial controls it assessed were adequate and operating effectively. What are the two things that conclusion has not said?
Sources
| Source | Document | Site |
|---|---|---|
| Ministry of Corporate Affairs | The Companies Act duty on internal financial controls: the text, who it applies to, who is exempt, and the form the report takes | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance standard and the guidance note behind reporting on internal financial controls | icai.org |
| Reserve Bank of India | What binds a bank in India in addition, including risk management arrangements, provisioning and outsourcing | rbi.org.in |
| Committee of Sponsoring Organizations of the Treadway Commission | Internal Control - Integrated Framework, the five component structure used above, published 1992 and updated 2013 | coso.org |
| Institute of Internal Auditors | The three lines model, the vocabulary for who runs, who challenges and who tests, restated 2020 | theiia.org |
Vindhya Commercial Bank Limited and Nirjhar Industries Limited are invented.
Educational material. Not advice on any investment, tax, budget or market position.
