Your Business Passed the Audit - So Why Is Money Still Disappearing?
TL;DR Summary
Most Indian businesses run only one type of audit — and assume that's enough. It isn't. Internal audit and external audit solve different problems, serve different people, and catch entirely different risks. Treating one as a substitute for the other creates a compliance gap that quietly grows until it becomes expensive. PKC India helps businesses across India close that gap. Here's what you need to know — and what you need to do about it.
Q: What is the difference between internal audit and external audit?
Internal audit runs throughout the year, conducted by your own team or an outsourced firm like PKC India. It reviews operations, controls, risks, and processes. External audit is an annual legal requirement. An independent Chartered Accountant examines your financial statements and confirms whether they're accurate. The two serve different purposes and report to different people. You need both — not one or the other.
Q: What is the applicability of internal audit under Indian law?
Section 138 of the Companies Act 2013 makes internal audit mandatory for listed companies, unlisted public companies with paid-up capital above Rs. 50 crore or turnover above Rs. 200 crore, and private companies with turnover above Rs. 200 crore or loans above Rs. 100 crore. Cross any one of these thresholds last year? The applicability of internal audit starts this year. Non-compliance triggers penalties under Section 450.
Your Audits Are Running — But Is Your Business Actually Protected?
A company in Tamil Nadu passed its statutory audit three years running. In month 26, PKC India found Rs. 40 lakh missing.
That's not a dramatic opening for effect. PKC India sees this pattern in business after business across India. A clean statutory audit does not mean a healthy business. It means your financial statements look accurate to an independent auditor on the day they reviewed them. That's a narrower claim than most business owners realise.
If your audit strategy is: pass the annual review and move on — stop here. That approach leaves every operational risk, every process gap, and every internal fraud opportunity completely unchecked. And that's exactly what the compliance gap is.
This article breaks down the difference between internal audit and external audit, explains exactly who the applicability of internal audit covers under Indian law, and shows how PKC India closes the gap for businesses across every major sector.
The Audit Confusion That's Quietly Draining Indian Businesses
Two Different Instruments, Two Different Purposes
Think about it like this.
An external audit is your annual health check. You show up once a year, the doctor runs standard tests, you get a report. But if your diet is off every single day, the cholesterol reading at the annual check-up won't tell you that — your daily habits will. Internal audit is the health coach working with you throughout the year. It checks the processes, operations, and risk controls that the once-a-year review never touches.
One works for your shareholders and regulators. The other works for you.
Why 'We Passed Our Audit' Means Less Than You Think
Passing a statutory audit tells the world your financial statements are fairly presented. Full stop. It says nothing about whether your procurement process has gaps, your inventory controls hold up, your IT systems are secure, or your related-party transactions are being managed correctly. Those are internal audit responsibilities. Your statutory auditor has no brief to go there — and isn't paid to.
The Compliance Gap: What Falls Between the Two
The compliance gap is everything that sits between what your external auditor reviews and what actually drives your business day to day. Operational risks. Process failures. Fraud exposure. Regulatory non-compliance that never surfaces in a financial statement. In PKC India's experience across manufacturing, retail, healthcare, and real estate, this gap is the most consistent source of costly surprises. The answer is not more of one type of audit. It's making both types work together.
Internal Audit vs External Audit: The Definitive Breakdown for Indian Businesses
What Is Internal Audit?
Internal audit is an independent, objective review of your business's internal controls, risk management processes, and operational performance. It runs on a regular cycle — quarterly for most companies — carried out either by an in-house team or by an outsourced firm like PKC India's Risk Advisory team. The output is a detailed internal audit report with findings and specific recommendations. It reports to management and the audit committee. Its job is to protect your business from the risks already living inside it.
What Is External Audit?
External audit — the same thing as statutory audit — is a legal requirement under Section 139 of the Companies Act 2013. An independent CA examines your financial statements and gives a formal opinion on whether they show a true and fair view. It reports to shareholders and regulators, not management. The scope is narrow and fixed. It happens once a year. It does not assess your operations, processes, or internal controls.
Side-by-Side: 8 Key Differences That Matter
These differences are not just technical. They determine what risks you catch, how early you catch them, and what you can actually do about them. Understanding the difference between internal audit and external audit is where protecting your business properly starts.
Is Internal Audit Mandatory for Your Business? Here's Exactly Who It Applies To
Section 138 of the Companies Act 2013 — Plain English
Section 138 of the Companies Act 2013, read with Rule 13 of the Companies (Accounts) Rules 2014, makes internal audit a legal requirement for specific categories of companies. If your company falls within any of the thresholds below, you must appoint an internal auditor — a Chartered Accountant, Cost Accountant, or any other professional the Board decides on.
The Mandatory Applicability of Internal Audit: Who's Covered
All listed companies — regardless of size or sector
Unlisted public companies — if any one of the following applies: paid-up share capital of Rs. 50 crore or more; turnover of Rs. 200 crore or more; outstanding loans or borrowings from banks of Rs. 100 crore or more; outstanding deposits of Rs. 25 crore or more
Private companies — if turnover is Rs. 200 crore or more, or outstanding loans from banks are Rs. 100 crore or more
Important: These thresholds apply to the preceding financial year's figures. Cross any one of these marks last year, and the applicability of internal audit is triggered this year.
What Happens If You Don't Comply
Section 450 of the Companies Act covers non-compliance. The company faces a penalty of up to Rs. 10,000, plus Rs. 1,000 for every day the default continues. Officers in default face the same scale. That's the financial exposure. The reputational exposure — with lenders, investors, and the Registrar of Companies — often runs deeper.
When Internal Audit Makes Sense Even Before It's Mandatory
Even if you haven't crossed these thresholds yet, internal audit pays for itself. Fast-growing companies approaching mandatory thresholds, businesses preparing for PE investment, export-oriented units, healthcare providers, and fintech firms all face risks that a quarterly internal audit cycle catches before they become problems. PKC India works with companies at all stages — from family-owned trading businesses to funded startups — where voluntary internal audit adoption has directly prevented fraud, improved operating margins, and made investor due diligence significantly smoother.
What Happens When Indian Businesses Rely Only on External Audit
This isn't hypothetical. These are patterns PKC India has observed across Indian businesses of every size and sector.
Scenario 1: The Manufacturer That Passed Statutory Audit — And Still Lost Rs. 40 Lakh
A mid-size manufacturer in South India cleared its external audit three years in a row. Everything looked clean on paper. But inside the business, a purchase manager had been colluding with a vendor to inflate raw material invoices. The statutory audit reviewed financial statements. Nobody reviewed the procurement process. By the time PKC India was brought in to set up an internal audit framework, the scheme had been running for 26 months. PKC India's risk-based internal audit identified the pattern in the first cycle. The damage: Rs. 40 lakh and counting.
The statutory audit cleared the books. The internal audit found the fraud. Both reviewed the same company — but they were looking at completely different things.
Scenario 2: The Startup That Hit a Wall at Series B
A funded tech startup was growing fast and had statutory compliance in order. But when they approached institutional investors for a Series B, the due diligence team asked for internal audit reports. There were none. No documented internal control framework. No process documentation. No evidence of governance beyond mandatory filings. The raise was delayed four months. PKC India typically builds the same framework in eight weeks.
Scenario 3: The Family Business That Discovered Vendor Fraud Too Late
A family-owned distribution company had operated comfortably for 20 years. The founders trusted their team and felt close enough to the business to catch problems themselves. When the founder's son joined and reviewed the accounts, he found three vendor relationships with no physical counterpart — each paying out Rs. 6 lakh a month. Twelve months of that totals Rs. 72 lakh. PKC India's vendor audit and process audit work is designed precisely to catch these patterns before they compound.
Common Mistakes Indian Businesses Make With Audit
Treating internal audit and external audit as interchangeable — they check entirely different things
Assuming a clean statutory audit means no hidden risks — it means the risks haven't hit the financial statements yet
Running internal audit only after something goes wrong — by then, the damage is already done
Appointing an internal auditor who reports directly to the CFO — this removes the independence the function needs to work
Producing audit reports that nobody acts on — a finding that isn't tracked to closure is not an audit; it's paperwork
Waiting to hit the mandatory applicability of internal audit thresholds before building the habit — by the time you're legally required, you should already have the practice running
How PKC India Closes the Compliance Gap
Risk-Based Internal Audit Methodology and Coordination Model
PKC India uses a risk-based internal audit approach. That means the audit plan is built around your actual business risks — not a generic annual checklist. Before the first fieldwork cycle begins, PKC's team conducts a full risk assessment: which areas carry the highest financial exposure, operational vulnerability, or regulatory risk? That's where the audit effort concentrates. It's why PKC India's findings are actionable — not a list of things your team already knows.
PKC India is part of PKC Management Consulting's Risk Advisory practice, which covers internal audit, GRC, process audit, financial audit, and outsourced CFO services. The team includes ex-Big Four professionals and sector specialists who've worked across manufacturing, retail, healthcare, real estate, IT, and financial services.
The team doesn't just produce reports. PKC India actively coordinates between internal audit findings and your statutory auditor. Issues get surfaced before the annual audit cycle. Duplication of work drops. Fewer surprises reach the external auditor at year end — which typically makes statutory audit both smoother and less expensive.
Sector-Specific Internal Audit Frameworks
A retail business faces inventory shrinkage risks that a software company doesn't. A healthcare provider carries regulatory and billing risks that a manufacturer doesn't. PKC India builds audit frameworks that match the sector — not a template applied to every client. That's why the findings land with management and drive real action.
What a PKC India Internal Audit Engagement Looks Like
Initial scoping: PKC's team meets with management to understand the business, identify high-risk areas, and set the audit scope.
Risk assessment: A formal risk register is created, ranking areas by likelihood and potential impact.
Fieldwork: The audit team conducts process walkthroughs, samples transactions, reviews controls, and tests compliance.
Draft report: Findings are documented with root cause analysis, risk rating, and specific recommendations.
Management response: Your team responds to each finding — accept, mitigate, or reject — with a committed timeline.
Final report: A clean, action-ready report goes to the audit committee or board.
Follow-up cycle: PKC tracks closure of open findings in the next audit cycle.
7 Questions Every Indian Business Owner Should Ask About Their Audit Setup Today
Do you fall within the mandatory threshold for internal audit under Section 138?
When did your last internal audit cycle take place, and who conducted it?
Is your internal auditor reporting to the audit committee, or only to the CFO or management?
Are your internal audit findings being tracked to closure, or filed away and forgotten?
Does your external auditor have access to your internal audit reports before year-end fieldwork?
Are your highest-risk areas — procurement, inventory, related-party transactions — covered at least quarterly?
Do you have a documented internal audit charter that defines scope, authority, and reporting lines?
Count your 'no' and 'unsure' answers. Three or more means your compliance gap is real — and likely already growing. PKC India offers a no-obligation audit readiness assessment. Book your consultation here.
Frequently Asked Questions
Can the same firm conduct both internal audit and external audit?
No. The Companies Act 2013 prohibits an external auditor from simultaneously providing internal audit services to the same company. The rule protects auditor independence. PKC India serves as an internal audit partner and coordinates separately with your statutory auditor. Both functions stay independent — and work better because of it.
What is the difference between internal audit and statutory audit?
Statutory audit and external audit are the same thing — the legally required annual review of your financial statements by an independent CA. Internal audit covers your operations, risk controls, and processes. Both serve different audiences and answer different questions. The difference between internal audit and external audit is about scope and accountability, not quality.
How often should internal audit be conducted?
High-risk areas need quarterly coverage. Lower-risk processes can run on an annual cycle. PKC India sets internal audit frequency based on your actual risk profile — not a standard calendar. A business with complex procurement and high inventory value needs more frequent review than a service firm with straightforward operations.
What qualifications does an internal auditor need in India?
Rule 13 of the Companies (Accounts) Rules 2014 requires the internal auditor to be a Chartered Accountant, Cost Accountant, or any other professional the Board approves. PKC India's internal audit team is built on qualified CAs and sector specialists who bring hands-on industry experience to every engagement.
Is internal audit applicable to LLPs and partnership firms?
The mandatory applicability of internal audit under Section 138 covers companies under the Companies Act 2013. LLPs and partnerships are outside this provision. But for any LLP or partnership that's growing fast, seeking funding, or operating in a high-risk sector, voluntary internal audit adoption is a practical necessity, not a nice-to-have.
What is a risk-based internal audit approach?
A risk-based internal audit approach builds the audit plan around the most significant risks in your specific business — not a standard process list. PKC India starts every engagement by identifying where your business is most exposed. Audit resources then go to those areas first. The result is findings that management acts on, not a compliance report that sits in a drawer.
The Audit You're Skipping May Be the One That Saves Your Business
Internal audit and external audit are not the same. They are not interchangeable. And skipping one while running the other doesn't mean you're half-protected — it means you have a fully operational blind spot.
The difference between internal audit and external audit matters because fraud doesn't wait for your annual review. Procurement leakage doesn't show up in financial statements. Process failures don't appear in an auditor's report. These are internal audit findings. And the applicability of internal audit under Section 138 means many businesses reading this are legally required to have this function in place already.
But legal compliance is the floor, not the ceiling. Businesses that build serious internal audit practices — whether or not they're legally mandated — catch problems earlier, grow with more confidence, and earn the trust of investors, lenders, and partners faster.
PKC India builds those practices. The team doesn't produce reports for filing cabinets. It tracks findings to closure, coordinates with your statutory auditor, and builds the internal control infrastructure that protects business value for the long term.
Find your compliance gap before it finds your business. Talk to a PKC India specialist today.
Further Reading from PKC India
Internal Audit Services — PKC India (Pillar Page)
Risk Advisory Services — PKC India (Cluster Page)
Expert Insights on Audit, Tax and Business Compliance — PKC India Blog












