✦ Business Set-up & ROC Compliance
internal audit in Gurgaon
Partner-led incorporation that gets your name approved, your SPICe+ filed right the first time, and your post-incorporation deadlines met — before they become penalties.
Gupta Varundeep & Co. (GVC Audit) is a Chartered Accountant firm in Gurgaon handling end-to-end Private Limited Company registration — name reservation, DSC and DIN, MoA and AoA drafting, SPICe+ Part A and Part B, PAN, TAN and TDS set-up, and the INC-20A, ADT-1 and annual ROC filings that follow — for founders, MSMEs and foreign-owned subsidiaries across Gurgaon and Delhi NCR. Every incorporation is reviewed by a qualified CA, not handed to a junior processor.
- ICAI-Registered Chartered Accountants
- 100% On-Time Return Filing Record
- Serving Startups to ₹100+ Crore Enterprises
- Partner-Reviewed Filings, Every Month
20+ Years
200+
Under Section 138 of the Companies Act 2013 and CARO 2020 Clause (xiv), qualifying private and unlisted companies must appoint an independent internal auditor to evaluate Internal Financial Controls (IFCoFR), Risk Control Matrices (RCM), and operating workflows. Beyond statutory compliance, an audit recovers 1% to 3% of top-line revenue lost to billing errors, un-reconciled vendor payouts, inventory shrinkages, and segregation of duties (SoD) breaches. GVC Audit provides partner-led internal audit services across Gurgaon, Manesar, and Delhi NCR.
Internal audit is a continuous risk assessment and governance assurance cycle
A modern internal audit is not an adversarial inspection. It is an independent advisory mechanism structured into two synchronized phases: process mapping and substantive field testing.
Risk Control Matrix & SOP Evaluation
Before testing transactions, we execute process walkthroughs across your operating departments to establish the Risk Control Matrix (RCM) and evaluate Segregation of Duties (SoD).
- Process walkthroughs across Procurement, Sales, Inventory, Payroll, and Finance
- Design of comprehensive Risk Control Matrices (RCM) for operational workflows
- Testing Segregation of Duties (SoD) and user authorization matrices in ERP systems
- Evaluating Entity-Level Controls (ELC) and compliance with Standard Operating Procedures
Field Testing, Analytics & Board Reporting
Executing data analytics across full transaction ledgers, conducting physical inventory counts, and presenting actionable findings to the Audit Committee and Board.
- Automated data analytics testing 100% of vendor payments, credit notes, and payroll ledgers
- Testing operating effectiveness of controls (TOE) across P2P, O2C, and R2R cycles
- Physical inventory verification, scrap yield audits, and warehouse reconciliation
- Quarterly internal audit reports presented directly to the Audit Committee and Board
CA-led risk & process internal audit vs routine checklist audits
Checklist audits simply tick sample vouchers without evaluating operational risk. GVC Audit provides deep, partner-led process forensics, financial leak recovery, and internal control assurance.
Risk-Based Process & Value Assurance
- Partner-led audit oversight by CA Varundeep Gupta with deep process expertise
- Data analytics across full ledger dumps catching duplicate payments and billing gaps
- Comprehensive Risk Control Matrix (RCM) covering design and operating effectiveness
- Audit of MSME 45-day vendor payment rules under Section 43B(h) / Section 37(2)(g)
- Physical inventory count verification, scrap yield analysis, and gate pass audits
- Formal quarterly presentations to the Audit Committee and Board of Directors
Superficial Voucher Ticking
- Clerical vouching of arbitrary samples without understanding operating workflows
- Ignores ERP authorization matrices, leaving Segregation of Duties breaches untouched
- Zero forensic testing of vendor master changes, duplicate bank accounts, or ghost staff
- Fails to catch inventory shrinkage, unrecorded scrap sales, or logistics leakages
- Produces boilerplate PDF reports that gather dust without operational remediation
- No alignment with ICAI Standards on Internal Audit (SIA) or CARO 2020 Clause (xiv)
Who is legally mandated to appoint an Internal Auditor?
Under Section 138 of the Companies Act, 2013 read with Rule 13 of the Companies (Accounts) Rules, 2014, internal audit is mandatory for qualifying entities.
Six core operational cycles evaluated in our internal audits
Our internal audit methodology covers the end-to-end operational, commercial, and financial workflows that drive your business.
1. Procure-to-Pay (P2P) Cycle
- Vendor Audit
- 3-Way Match
- MSME 43B(h)
Vendor onboarding due diligence, purchase order (PO) approvals, 3-way matching (PO vs GRN vs Invoice), duplicate payment detection, vendor master change logs, and Section 43B(h) / 37(2)(g) 45-day MSME compliance.
View P2P audit checkpoints ↓2. Order-to-Cash (O2C) Cycle
- Revenue Assurance
- Credit Limits
- e-Invoice Sync
Customer credit limit authorizations, price master controls, sales order to dispatch reconciliations, e-Way bill and e-Invoice matching, trade discount validations, and debtor aging recovery audits.
Review O2C revenue controls ↓3. Inventory & Warehouse Controls
- Physical Count
- Scrap Yield
- SMNM Stock
Perpetual inventory tracking, slow-moving and non-moving (SMNM) stock write-offs, manufacturing yield and scrap loss reconciliation, gate pass security, and warehouse shrinkage prevention in Manesar and Bilaspur.
Explore warehouse audit norms ↓4. Hire-to-Retire (H2R) & Payroll
- Ghost Staff
- EPF/ESIC/LWF
- F&F Settlements
Biometric attendance to payroll register reconciliation, ghost employee audits, statutory compliance verification (EPF, ESIC, Professional Tax, Haryana LWF, Gratuity), and Full & Final (F&F) settlement accuracy.
View payroll audit scope ↓5. Record-to-Report (R2R) & Financials
- Journal Entries
- Inter-Company
- Rule 11(g)
Manual journal entry authorization, inter-company balance reconciliations, bank reconciliation statements (BRS), fixed asset tagging, provision reasonableness, and accounting software audit trail integrity.
Understand R2R accounting audits ↓6. IT General Controls (ITGC) & Security
- User Access
- SoD Matrix
- Backup & DR
ERP user access reviews, Segregation of Duties (SoD) conflict resolution, admin privilege monitoring, password policies, database backup restoration testing, and cybersecurity baseline reviews.
Explore ITGC controls ↓Where un-audited internal workflows bleed cash and invite fraud
Internal control breakdowns rarely appear as dramatic events. They compound quietly over years through minor process deviations and unchecked employee authority.
Vendor collusion and duplicate billing
Unmonitored vendor master edits, shared bank account details between vendors, and lack of automated 3-way matching lead to duplicate payments and inflated procurement costs.
Audit vendor master controls →Inventory shrinkage and unrecorded scrap
Variances between ERP book stock and physical factory inventory, undocumented scrap disposal, and unmonitored sub-contractor job-work lead to massive material losses.
Tighten inventory controls →Uncontrolled customer credit and bad debts
Sales teams overriding customer credit limits in ERP systems without finance approval, leading to uncollected trade receivables aging beyond 90 to 180 days.
Enforce customer credit rules →Segregation of Duties (SoD) conflicts in ERP
Single users holding permissions to create vendors, approve purchase orders, post goods receipts, and initiate bank disbursements, creating direct fraud opportunities.
Resolve SoD conflicts →Comprehensive CA-led internal audit and risk advisory services
From statutory Section 138 compliance and Internal Financial Controls (IFC) testing to operational turnaround reviews and forensic fraud investigations.
Statutory Internal Audit (Section 138 & Rule 13)
Comprehensive corporate internal audit fulfilling Companies Act mandates and CARO requirements.
- Quarterly internal audit execution aligned with ICAI Standards on Internal Audit (SIA)
- Detailed testing of P2P, O2C, H2R, R2R, inventory, and statutory compliance workflows
- Drafting executive observation summaries with root-cause analysis and management action plans
- Formal quarterly presentations to the Audit Committee and Board of Directors
Internal Financial Controls (IFCoFR) & SOX Testing
Testing design and operating effectiveness of internal controls over financial reporting.
- Design and update of enterprise-wide Risk Control Matrices (RCM) across all business processes
- Test of Design (TOD) and Test of Operating Effectiveness (TOE) under Section 134(5)(e) and 143(3)(i)
- SOX 404 compliance testing for US/overseas multinational subsidiaries in Gurgaon
- Remediation support for control deficiencies prior to statutory audit sign-off
Standard Operating Procedure (SOP) Drafting & Audit
Designing, benchmarking, and auditing corporate operational processes.
- Drafting comprehensive, flowchart-based Standard Operating Procedures (SOPs) across departments
- Gap analysis benchmarking existing operating practices against industry best practices
- Audit of SOP compliance to identify operational deviations and bottlenecks
- Designing delegation of authority (DOA) matrices and approval workflows
Special Investigative & Forensic Fraud Audits
Targeted forensic investigations into suspected fraud, leakages, and whistle-blower complaints.
- Forensic data analytics across ledger dumps, bank records, and email communication trails
- Investigation of procurement fraud, inventory pilferage, kickbacks, and employee embezzlement
- Quantification of financial loss and evidence documentation for legal proceedings
- Strengthening anti-fraud controls and whistleblower governance frameworks
IFC
How Risk Control Matrices (RCM) protect board directors from liability
Under Section 134(5)(e) of the Companies Act 2013, the Board of Directors of an unlisted company must confirm in their Director Responsibility Statement that adequate Internal Financial Controls (IFC) were in place and operated effectively. Under Section 143(3)(i), the statutory auditor must issue an independent opinion on these controls.
GVC Audit constructs enterprise-wide Risk Control Matrices (RCM) that map every operational risk to specific preventative and detective controls, proving design effectiveness (Test of Design - TOD) and operating effectiveness (Test of Operating Effectiveness - TOE).
- Risk Identification: Mapping financial reporting, operational, and compliance risks across all business cycles
- Control Classification: Segregating controls into Manual, Automated (ERP-configured), Preventative, and Detective
- Test of Design (TOD): Verifying whether the control, if operated properly, prevents or detects material misstatements
- Test of Operating Effectiveness (TOE): Sampling transaction evidence across the year to prove consistent control execution
- Entity-Level Controls (ELC): Evaluating tone at the top, code of conduct, whistleblower mechanisms, and HR hiring policies
- Remediation Tracking: Documenting time-bound management remediation plans for identified control deficiencies
The quarterly internal audit execution roadmap
A structured quarterly audit calendar ensuring exhaustive process coverage, timely remediation, and structured Audit Committee presentations.
Pre-Audit Internal Controls Health Checklist
Five critical checks to evaluate whether your organization holds adequate internal controls to prevent fraud and satisfy Section 138 mandates.
Audit my internal controls ↗- Purchase orders, goods receipts, and vendor invoices are 3-way matchedEnsure no vendor invoice is processed for payment without automated matching against approved PO and store GRN.
- ERP user permissions enforce strict Segregation of Duties (SoD)Verify that no single employee can create vendors, approve purchase orders, and execute banking disbursements.
- All registered MSME vendors are tracked with 45-day payment agingMaintain automated ERP alerts for micro/small vendor dues to prevent tax disallowances under Section 43B(h).
- Physical inventory counts are conducted and reconciled quarterlyEnsure physical warehouse stock in Manesar/Gurgaon is reconciled with book balances, logging scrap and slow-moving items.
- Accounting software maintains an untampered audit trail under Rule 11(g)Confirm that Tally, Zoho, or SAP edit-log functionality has operated continuously without being disabled.
Chartered Accountants delivering actionable operational assurance
Partner-Led CA Oversight
CA Varundeep Gupta personally oversees your internal audit planning, fieldwork execution, and Audit Committee presentations, ensuring institutional-grade rigor.
Deep Industrial & Corporate Depth
Extensive experience auditing manufacturing plants in IMT Manesar, tech startups and D2C brands in Udyog Vihar, and foreign corporate shared services in Cyber City.
Commercial Value Addition
We do not just find audit defects. We quantify financial leakages, optimize operational working capital, recover duplicate payments, and help management tighten profitability.
Complete corporate assurance, tax, and regulatory advisory.
Protect your enterprise from leakages, fraud, and control failures.
Schedule a 30-minute consultation with CA Varundeep Gupta to plan your company's internal audit scope, Risk Control Matrix design, and Section 138 compliance.
Internal Audit in Gurgaon: CA-Led Risk Advisory & Process Assurance
Under Section 138 of the Companies Act, 2013, qualifying companies in India are legally mandated to conduct an internal audit of their functions and activities by an independent Chartered Accountant, Cost Accountant, or designated internal professional. While statutory audit focuses on the historical accuracy of annual financial statements for external stakeholders, an internal audit is an ongoing, operational evaluation designed to evaluate internal controls, improve operational efficiency, prevent corporate fraud, and protect enterprise profitability.
Gurgaon stands as the industrial and corporate nerve center of North India, hosting corporate headquarters, tech unicorns in Cyber City, automotive manufacturing plants in IMT Manesar, and export garment factories in Udyog Vihar. In this complex operating environment, unmonitored workflows lead to severe operational leakages: duplicate vendor disbursements, inventory shrinkage, uncollected receivables, and non-compliance with statutory mandates such as Section 43B(h) / Section 37(2)(g) 45-day MSME supplier rules.
GVC Audit (Gupta Varundeep & Co.) is a premier Chartered Accountant firm located in Sushant Lok-1, Sector 43, Gurugram. We provide comprehensive, partner-led internal audit services, Internal Financial Controls (IFCoFR) design, Risk Control Matrix (RCM) drafting, SOX testing, and process turnaround advisory across Delhi NCR.
Section 138 Applicability & Statutory Mandates
Under Rule 13 of the Companies (Accounts) Rules, 2014, the following classes of companies must mandatorily appoint an internal auditor:
| Company Classification | Turnover Threshold (Preceding FY) | Outstanding Loans/Borrowings (Preceding FY) | Paid-Up Capital / Deposits Threshold |
|---|---|---|---|
| Private Limited Companies | ₹200 Crore or more | Exceeding ₹100 Crore from banks or public financial institutions at any point | Not applicable for private companies |
| Unlisted Public Companies | ₹200 Crore or more | Exceeding ₹100 Crore from banks or public financial institutions at any point | Paid-up capital ≥ ₹50 Crore OR Outstanding deposits ≥ ₹25 Crore |
| Listed Companies | Mandatory for all listed entities regardless of turnover, capital, or debt levels | Mandatory for all listed entities | Mandatory for all listed entities |
Procure-to-Pay (P2P) Internal Audit Methodology
The procurement cycle represents the largest cash outflow in any organization and is the most vulnerable to employee-vendor collusion, inflated pricing, and duplicate payments. Our P2P internal audit tests:
- Vendor Master Controls: Testing vendor onboarding documentation, verifying GSTIN active status on the GST portal, auditing changes to vendor bank account numbers in ERP, and detecting shared bank accounts across multiple vendor codes.
- 3-Way Matching: Ensuring ERP controls automatically enforce matching between the Purchase Order (PO), Goods Receipt Note (GRN), and Vendor Tax Invoice before approving payments.
- Section 43B(h) / Section 37(2)(g) MSME Compliance: Auditing payment release dates to registered micro and small suppliers to ensure settlement within 45 days, preventing corporate income tax disallowances.
- Job-Work & Subcontracting Reconciliation: Reconciling raw material sent for job-work under Section 143 of the CGST Act with finished goods received, verifying processing loss norms in Manesar manufacturing plants.
Order-to-Cash (O2C) & Revenue Assurance
The sales and collection cycle directly determines operational working capital health. Our O2C audit evaluates:
- Customer Credit Governance: Verifying whether customer credit limits in ERP systems are enforced or routinely overridden by sales managers without finance approval.
- Price Master Authorization: Auditing special pricing discounts, volume rebates, and post-sale credit notes to ensure they carry proper authorized sign-offs.
- e-Way Bill & e-Invoice Synchronization: Reconciling sales invoices with real-time e-Way bills and e-Invoice IRN portal records to eliminate indirect tax compliance penalties.
- DSO & Debtor Aging Analysis: Evaluating recovery velocity across trade receivables, identifying sticky debts exceeding 90 to 180 days, and verifying bank Drawing Power reporting accuracy.
Inventory, Warehouse & Manufacturing Yield Audits
In the industrial belts of IMT Manesar, Khandsa, and Sector 37 Pace City, inventory represents a massive portion of total current assets. Our inventory audit methodology includes:
| Inventory Dimension | Internal Audit Verification Procedure | Operational Risk Mitigated |
|---|---|---|
| Perpetual Inventory Physical Count | Conducting regular physical sample counts across raw materials, WIP, and finished goods, comparing physical counts against ERP book balances. | Prevents inventory shrinkage, unrecorded stock write-offs, and stock statement misreporting to commercial banks. |
| Slow-Moving / Non-Moving (SMNM) Stock | Aging inventory by holding period (identifying stock lying idle for > 180 to 360 days) and evaluating provision for obsolescence. | Prevents capital lockup in dead inventory and ensures accurate balance sheet inventory valuation under AS-2 / Ind AS 2. |
| Scrap & Production Yield Reconciliation | Benchmarking actual manufacturing scrap generation against standard technical BOM (Bill of Materials) yield parameters. | Uncovers unrecorded scrap sales, unauthorized raw material diversions, and machine calibration inefficiencies. |
| Gate Pass & Material Movement Security | Auditing returnable vs non-returnable gate passes (RGP / NRGP) and tracking material sent outside factory premises for testing or rework. | Eliminates physical theft and unreturned third-party material leakage across warehouse hubs. |
Hire-to-Retire (H2R) & Statutory Labor Compliance
Payroll represents one of the largest operating expenses. Our H2R audit tests:
- Ghost Employee Detection: Reconciling biometric gate attendance logs with monthly payroll master registers to detect inactive or fictitious employees.
- Statutory Labor Compliance: Auditing employee and employer contribution deductions for Employees' Provident Fund (EPF), Employees' State Insurance (ESIC), Haryana State Professional Tax, and Labor Welfare Fund (LWF).
- Full & Final (F&F) Settlements: Verifying leave encashment calculations, gratuity eligibility under the Payment of Gratuity Act, and recovery of company assets/loans upon employee exit.
IT General Controls (ITGC) & Rule 11(g) Edit-Log Verification
With modern businesses running on enterprise ERP systems (SAP, Oracle, Tally Prime, Zoho), IT controls are the foundation of all financial reporting:
- Segregation of Duties (SoD) Conflict Testing: Ensuring ERP user authorization roles prevent toxic combinations (such as a single user having permission to create a vendor master and initiate payment).
- Audit Trail (Rule 11(g)) Verification: Testing accounting software system logs to confirm that the audit trail feature operated continuously without being disabled during the year.
- User Access Reviews: Ensuring system access for terminated employees is revoked immediately upon exit.
How GVC Audit Executes Your Internal Audit
1. Risk Assessment & Annual Audit Plan Design
We evaluate your organizational workflows, construct comprehensive Risk Control Matrices (RCM), and present an annual risk-based audit plan to the Audit Committee.
2. Substantive Fieldwork & Forensic Analytics
Our team executes detailed transaction testing across P2P, O2C, H2R, R2R, and warehouse cycles, using data analytics on full ledger dumps to identify control exceptions.
3. Actionable Root-Cause Reporting
We issue structured internal audit reports detailing root-cause analysis, quantified financial impact, and clear management action plans with implementation timelines.
4. Audit Committee Presentation & Remediation Tracking
We present quarterly internal audit summaries directly to the Board of Directors and Audit Committee, tracking management remediation status across subsequent audit cycles.
Frequently Asked Questions: Internal Audit in Gurgaon
What is an internal audit and is it mandatory for private limited companies?
An internal audit is an independent, objective assurance function that evaluates internal financial controls, operational efficiency, and risk management. Under Section 138 of the Companies Act 2013, it is mandatory for private companies if annual turnover is ₹200 Crore or more in the preceding FY, OR if outstanding loans/borrowings from banks/PFIs exceed ₹100 Crore at any point during the preceding FY.
What is the difference between a Statutory Auditor and an Internal Auditor?
A Statutory Auditor is appointed by shareholders under Section 139 to independently report whether annual financial statements show a true and fair view for external stakeholders. An Internal Auditor is appointed by the Board under Section 138 to evaluate internal controls, prevent fraud, improve operational processes, and report directly to management and the Audit Committee throughout the year. The same CA firm cannot serve as both statutory and internal auditor for the same company.
What are Internal Financial Controls (IFCoFR) under the Companies Act 2013?
Internal Financial Controls over Financial Reporting (IFCoFR) represent policies and procedures adopted by a company to ensure orderly business conduct, adherence to company policies, asset safeguarding, fraud prevention, and timely preparation of reliable financial information. Under Section 134(5)(e), directors must confirm their operational effectiveness.
What is a Risk Control Matrix (RCM)?
A Risk Control Matrix (RCM) is an operational governance document that maps every identified business risk (in procurement, sales, inventory, payroll, accounting) to specific preventative or detective controls, defining control frequency, ownership, and testing procedures (Test of Design and Test of Operating Effectiveness).
How often should an internal audit be conducted?
Internal audits are typically conducted on a quarterly basis, with the internal audit team reviewing designated operational cycles each quarter and presenting formal quarterly internal audit reports to the Audit Committee and Board of Directors before the adoption of quarterly/annual accounts.
What is tested during a Procure-to-Pay (P2P) internal audit?
A P2P audit tests vendor onboarding due diligence, purchase order approvals, 3-way matching (PO vs GRN vs Invoice), duplicate payment detection, vendor master change logs, Section 43B(h) / Section 37(2)(g) 45-day MSME supplier compliance, and job-work reconciliation.
Can an internal audit help recover lost profits?
Yes. In practice, a thorough CA-led internal audit frequently recovers 1% to 3% of top-line revenue by uncovering duplicate vendor payments, un-billed customer dispatches, uncollected trade rebates, excess scrap generation, unauthorized transport charges, and ghost payroll entries.
What is CARO 2020 Clause (xiv) regarding internal audit?
Under Clause (xiv) of CARO 2020, statutory auditors must formally report whether the company has an internal audit system commensurate with the size and nature of its business, and whether the statutory auditor reviewed the internal auditor's reports during the annual audit.
What is Segregation of Duties (SoD) in ERP systems?
Segregation of Duties ensures that critical tasks are divided among multiple employees to prevent fraud. For example, the employee who creates vendor master codes in ERP should not have permission to approve purchase orders or authorize bank disbursements.
How does internal audit verify Audit Trail / Edit-Log under Rule 11(g)?
The internal auditor tests accounting software system logs (in Tally, Zoho, SAP) to verify that the automated edit-log operated continuously throughout the year for every transaction, confirming that admin users did not disable or purge audit trail history.
How does GVC Audit report internal audit findings to the Board?
We issue structured quarterly internal audit reports containing an executive dashboard, risk-rated observations (High, Medium, Low), quantified financial leakages, root-cause analysis, and management action plans with assigned responsibilities and implementation deadlines.
Do you provide internal audit services outside Gurgaon?
Yes. GVC Audit is based in Sushant Lok-1, Sector 43, Gurugram, and we deliver internal audit, IFC testing, and process advisory for manufacturing, retail, and corporate clients across IMT Manesar, Faridabad, Delhi NCR, and nationwide through on-site fieldwork and secure digital analytics.
Chartered Accountants & Internal Audit Specialists in Gurgaon
Visit our Sushant Lok office for a confidential review of your internal controls, SOP compliance, and risk governance framework.
Gupta Varundeep & Co.
ICAI Certified Chartered Accountants
- AddressH-312, Sushant Shopping Arcade, near Huda Metro Station, Sushant Lok Phase I, Sector 43, Gurugram, Haryana 122009
- Phone+91 97173 55517
- Emailvarun@gvcaudit.com
- Office HoursMonday to Saturday, 10:00 AM to 7:00 PM