Internal Financial Controls Explained: What Mid-Sized Indian Companies Actually Need to Build
By BiPivot Team · 21 August 2026

Every year, we meet finance heads at ₹150-400 crore turnover companies who tell us the same thing: "Our auditor didn't flag IFC, so we're fine." That sentence is doing a lot of quiet damage. It conflates two entirely different things — an auditor's reporting exemption and a director's legal responsibility. One is a paperwork relief. The other never goes away.
This article is for CFOs, controllers and finance heads at mid-sized Indian companies who want a straight answer to three questions: does IFC apply to us, what does "adequate" actually mean in practice, and how do we build it without hiring a Big 4 team we can't afford.
What Exactly Are Internal Financial Controls (IFC) Under Indian Law?
Internal Financial Controls (IFC) are defined under Section 134(5)(e) of the Companies Act, 2013 as the policies and procedures a company adopts to ensure orderly and efficient conduct of business, adherence to company policies, safeguarding of assets, prevention and detection of fraud and error, accuracy and completeness of accounting records, and timely preparation of reliable financial information (Startup Movers).
Strip the legal language and it comes down to five practical questions every controller should be able to answer for every material process:
- Can a transaction get approved, executed, and recorded by the same person, with no one else checking?
- If a vendor invoice is fake or inflated, would anyone catch it before payment?
- If a senior employee left tomorrow, would the process still run correctly?
- Do our books reconcile to our GST returns and TDS filings without manual patching every quarter?
- Could we reconstruct, from documentation alone, why a ₹50 lakh journal entry was made six months ago?
If the honest answer to more than two of these is "no," IFC isn't a compliance gap — it's an operational risk sitting on your balance sheet right now.
Who Is Actually Required to Have IFC, and Who Is Exempt From What?
This is where most mid-sized companies get confused, because there are two separate obligations layered on top of each other.
Obligation 1: The Board must establish IFC. This applies to every company incorporated under the Companies Act, 2013 — public, private, listed, unlisted, large or small. There is no turnover threshold, no exemption, no opt-out. Section 134(5)(e) places this responsibility squarely on the Board of Directors as part of the annual Directors' Responsibility Statement (MSNA).
Obligation 2: The statutory auditor must report on IFC. This is different — it's a reporting requirement under Section 143(3)(i), where the auditor opines on the adequacy and operating effectiveness of your Internal Financial Controls over Financial Reporting (ICFR) (SKMC Global). This is the part that has thresholds and exemptions:
- Listed companies: Mandatory auditor reporting on IFC, no exceptions (Startup Movers).
- Unlisted public companies: Mandatory if paid-up capital is ₹25 crore or more at the end of the previous financial year (Startup Movers).
- Private companies: Exempt from auditor reporting only if turnover is below ₹50 crore AND aggregate borrowings from banks, financial institutions, or any body corporate are below ₹25 crore at any point during the year — provided there's no default in statutory filings (MSNA).
Here's the number that should worry you: over 60% of active Indian companies are private companies, many of which qualify for this audit exemption — yet they routinely operate with related-party transactions, cash-heavy operations, and thin segregation of duties, which are precisely the conditions IFC exists to control (MSNA).
Worked example: Take a Pune-based private auto-ancillary company with ₹38 crore turnover and ₹18 crore in working capital loans from two banks. It falls under both thresholds — no mandatory IFC audit report. But its promoter-director's brother runs the raw material supplier, and there is no independent price benchmarking on those purchases. The Board is still legally answerable if that related-party arrangement causes a fraud loss or a misstated P&L — auditor exemption or not. We've seen exactly this pattern trigger an NCLT dispute between shareholders where the absence of a documented approval matrix for related-party transactions became the central evidence gap.
What Does a Practical IFC Framework Look Like – Do We Need the Full COSO Model?
India's IFC framework is built on the globally recognized COSO framework, adapted by ICAI through its Guidance Note on Audit of Internal Financial Controls over Financial Reporting (Mynd Solutions). COSO has five components, and for a listed company with a dedicated internal audit team, implementing all five in full depth makes sense. For a ₹100-300 crore private company with a four-person finance team, doing the same thing verbatim will produce a 200-page document nobody reads and zero behavioral change.

Here's how to right-size each component for a mid-sized business:
1. Control environment — Who sets the tone? In practice: a one-page delegation of authority (DOA) matrix specifying who can approve what amount, reviewed by the Board annually. Not a 40-page policy manual.
2. Risk assessment — What can go wrong, and where? Focus on the top 8-10 processes by rupee value and fraud susceptibility: cash and bank, procurement-to-pay, order-to-cash, payroll, GST/TDS compliance, fixed assets, related-party transactions, and inventory.
3. Control activities — The actual checks. For each risk identified above, one specific control: three-way match on purchase orders above ₹1 lakh, dual authorization on bank transfers above ₹5 lakh, monthly vendor ledger reconciliation before payment runs.
4. Information and communication — Does the person who needs to know, know in time? A monthly MIS pack that flags exceptions (overdue reconciliations, GST mismatches, TDS short-deductions) rather than just reporting revenue and expenses.
5. Monitoring — Someone independent checks that controls are actually operating, not just documented. A quarterly internal control self-assessment by the CFO, reviewed by an independent director or audit committee, is sufficient for most mid-sized structures.
A full cycle from scoping to final testing of an IFC framework for a mid-sized Indian enterprise typically takes 4 to 6 months (Mynd Solutions). Budget for that timeline rather than trying to compress it into a pre-audit sprint — rushed IFC documentation is the single most common reason auditors issue qualified opinions on ICFR.
How Should GST and TDS Compliance Sit Inside Your IFC Framework, Not Beside It?
The mistake we see most often: GST reconciliation sits with the tax team, TDS compliance sits with payroll/accounts, and IFC documentation sits in a folder prepared once a year for the auditor. These are treated as three separate exercises when they're the same exercise viewed from different angles.
GST as an IFC control point. Input Tax Credit (ITC) management, allocation of common costs across GSTINs, and 2A/2B reconciliation are core IFC concerns for any company with turnover exceeding ₹5 crore (PKC India). A company claiming ITC on invoices that later turn out to be from non-compliant vendors isn't just facing a GST notice — it's evidence of a broken control over vendor onboarding and purchase recording, which is exactly what Section 134(5)(e) requires the Board to prevent.
Worked example: A Coimbatore textile exporter with ₹80 crore turnover was claiming ITC monthly based on purchase register entries, without matching against GSTR-2B. Over one financial year, ₹34 lakh of ITC was later disallowed because 22 vendors had failed to file their GSTR-1 or had mismatched invoice values. That ₹34 lakh wasn't a tax problem — it was a control failure: no monthly 2B reconciliation, no vendor compliance monitoring before onboarding. Once they built a control requiring 2B reconciliation before every GSTR-3B filing, disallowances dropped to near zero within two quarters. We've covered the automation side of this in detail in GST Return Automation: A CFO's Playbook for Turning Compliance Into Control — worth reading if 2A/2B mismatch is a recurring line item in your ITC reversal register.
TDS as an IFC control point. Correct rate application, timely deposit, and accurate quarterly reporting are strengthened significantly by robust internal financial controls, with regular internal audits playing a key role in catching discrepancies before they become notices (IndiaFilings). Provisions like Section 206AB (higher TDS for non-filers of returns) mean your vendor master data itself is now a control point — if your system doesn't flag non-filer vendors before payment, you're deducting at the wrong rate and generating a default that surfaces months later as interest and penalty.
Worked example: A Gurugram IT services company with 340 active vendors discovered during a statutory audit that 11 vendors classified as "professional services" under Section 194J were actually contract labour suppliers who should have been under Section 194C — a rate difference of 10% vs 1-2%. The shortfall came to ₹9.2 lakh in TDS plus interest. The root cause wasn't tax knowledge — it was that vendor category was set once at onboarding and never reviewed as an internal control. We go deeper into fixing this class of problem in TDS Compliance Automation: Why Mid-Sized Indian CFOs Can't Wait for the New Income Tax Act 2026, which is a natural next read if TDS reconciliation is still a manual, quarter-end scramble in your team.
The practical takeaway: your IFC risk register should have GST and TDS as named line items with named control owners, not as a footnote under "statutory compliance."
Where Does Technology Fit in IFC, and Where Does It Not Solve the Problem?
A recurring pain point among mid-sized Indian companies is treating technology adoption as the IFC solution itself, rather than as an enabler of controls that are already well-defined. Buying an ERP module doesn't create segregation of duties — it just automates whatever process (good or bad) you configure into it.

Where technology genuinely strengthens IFC:
- System-enforced approval hierarchies replacing email-based or verbal sign-offs — removes the "I forgot to get approval" excuse entirely.
- Automated three-way matching (PO, GRN, invoice) before payment release — catches quantity and rate mismatches that manual review misses under volume.
- Exception dashboards that flag GST mismatches, TDS rate anomalies, and duplicate vendor payments in real time rather than at month-end close.
- Immutable audit trails on journal entries — who posted, who approved, when, with what supporting document attached.
If your finance stack is still Tally with Excel bolted on for MIS, this doesn't mean IFC is out of reach — it means your controls need to be more manually enforced and more frequently reviewed to compensate. We've written a practical path for moving from spreadsheet-dependent reporting to system-driven controls in Tally to Power BI Guide: Turning Tally Data Into Real-Time Financial Intelligence, and for companies running SAP, the equivalent playbook is in Integrating SAP with Power BI: A CFO's Guide to Real-Time Financial Intelligence in India. Both are about visibility, which is the "information and communication" leg of your IFC framework — but visibility without underlying control design just gives you a faster view of a broken process.
Is IFC Worth the Effort If We're Not Required to Have It Audited?
Yes, and the evidence is now empirical, not just anecdotal. A July 2026 study of 150 publicly listed firms across the NSE and BSE found that both internal controls and audit committee effectiveness significantly reduce financial risk (ResearchGate). While that study covers listed entities, the mechanism it identifies — controls reducing the probability and magnitude of financial risk events — applies with equal force to unlisted and private companies, arguably with higher stakes given thinner capital buffers.
The business case beyond audit exemption:
- Fundraising readiness. Every PE or strategic investor doing due diligence on a mid-sized target runs an internal controls assessment. Weak IFC either kills the deal or gets baked into a valuation discount of 10-15% as a "governance risk adjustment" — we've seen this figure explicitly in term sheets.
- Fraud prevention economics. A single unsegregated cash-and-bank function at a ₹200 crore manufacturing company we advised had a ₹1.2 crore embezzlement running for 14 months before detection, purely because the person who reconciled the bank statement was the same person who initiated payments. The fix cost nothing — reassign the reconciliation to someone else. The loss was 100% preventable.
- Bank and lender confidence. Working capital lenders increasingly ask for internal control certifications as part of renewal, especially for limits above ₹15-20 crore. Companies without documented IFC face longer TAT and occasionally tighter covenants.
If you're scaling your finance function to support this level of control discipline, the organizational design questions — who owns reconciliation, who owns approvals, where shared services fit — are covered in Building a Finance Shared Services Center: A Mid-Sized Indian CFO's Playbook, which is a logical companion piece once you've mapped your control gaps and need to decide how to staff the fix.
How Do Resource-Constrained Finance Teams Actually Build IFC Without a Big 4 Retainer?
Here is a phased, six-month approach we use with mid-sized clients who have 3-6 people in finance and no dedicated internal audit function:
Month 1 — Risk-based scoping. Identify your top 8 processes by rupee exposure and fraud susceptibility (typically: cash/bank, P2P, O2C, payroll, GST/TDS, fixed assets, related-party transactions, inventory). Don't try to control everything on day one.
Month 2 — Gap mapping. For each process, document the current flow and mark every point where one person has both custody and recording authority, or where approval happens without documentation. This alone typically surfaces 15-25 control gaps in a company that has never done this exercise.
Month 3-4 — Design and implement fixes. Prioritize by cost-to-fix vs. risk-reduced. Segregation-of-duty fixes (reassigning who does what) are usually free and should go first. System-enforced approval limits come next. Policy documentation comes last — it should describe what you're actually doing, not an aspirational ideal.
Month 5 — Test operating effectiveness. Pick a sample of transactions from the last quarter and verify the new controls actually operated — not just that they exist on paper. This is what separates "designed" controls from "operating effectively" controls, the exact distinction your auditor (if applicable) will test.
Month 6 — Board sign-off and monitoring cadence. Present the framework to the Board, get it minuted as part of the Directors' Responsibility Statement process, and establish a quarterly self-assessment cadence going forward.
If you genuinely lack in-house expertise for the design phase, a virtual CFO or fractional controller engagement for months 1-3 is far cheaper than a Big 4 IFC engagement and gets you 80% of the value — the remaining 20% (formal documentation for audit purposes, if you cross the exemption thresholds) can be brought in later, closer to year-end. For a broader view of which parts of your finance stack to fix first when resources are tight, The Modern Finance Tech Stack: A CFO's Guide for Mid-Sized Indian Companies is a useful sequencing reference.

What should be on your desk this quarter?
If you take one action item from this article, make it this: pull your Directors' Responsibility Statement from last year's annual report and check whether the IFC declaration was made based on an actual assessment or copy-pasted from the previous year's boilerplate. If it's the latter, your Board has an exposure it doesn't know about — regardless of whether your auditor was required to report on it.
How BiPivot helps
BiPivot works with mid-sized Indian finance teams to translate IFC requirements into practical, risk-based control frameworks that fit real headcount and real systems — not textbook COSO deployments. If you're mapping GST, TDS, and process-level controls into a single Board-ready IFC framework, talk to us at bipivot.com.