04 Aug 2026 · 6 min read · Companies Act · CA Dheeraj Somani

What audit committees are asking internal auditors in 2026.

Audit committees have moved from receiving internal audit reports to interrogating them. A short note on why that happened, where the questions come from in the Companies Act and the LODR, and the six questions internal audit should walk in ready to answer.

1. The committee has changed.

A decade ago the internal auditor's appearance before the audit committee was brief. The report was tabled, the high-rated observations were read out, management responded, and the committee moved on.

That is no longer the norm in listed companies, and it is fading in large promoter-led unlisted ones too. Three things changed.

Independent directors' exposure became visible. Enforcement actions and disqualifications over the last few years made clear that "the report was tabled" is not a defence. Directors now read the internal audit report as a document they may one day have to explain.

Regulators wrote the committee's job down in more detail. SEBI's LODR amendments and the MCA's rules on internal financial controls turned general oversight into a list of specific matters the committee must review and record.

Internal audit itself got better at data. Once full-population analytics became normal, findings arrived with numbers attached, and committees learned to ask for them.

The result is a committee that treats the internal auditor as a witness to be questioned rather than a presenter to be heard.

The committee is no longer asking whether the internal auditor did the work. It is asking whether it was the right work, and whether anything changed because of it.

2. Where the questions come from.

Each question the committee asks has a statutory source, and the internal auditor who knows the source answers better.

Section 177 of the Companies Act, 2013 requires the audit committee to evaluate internal financial controls and risk management systems, review the findings of internal investigations, and oversee the vigil mechanism. Section 134(5)(e) makes the board responsible for adequate internal financial controls, and section 143(3)(i) requires the statutory auditor to report on their operating effectiveness. Somebody has to test them first; the committee expects that to be internal audit.

For listed entities, Regulation 18 of the SEBI LODR Regulations, read with Part C of Schedule II, adds specific duties: reviewing the adequacy of the internal audit function including its structure, staffing, reporting line and frequency; discussing significant findings and management's follow-up; reviewing the appointment and remuneration of the internal auditor; and reviewing related party transactions and the whistle-blower mechanism. Regulation 23 governs related party transactions in detail. For the top one thousand listed entities, Regulation 21 requires a separate risk management committee, and the boundary between the two committees is itself a recurring question.

The SEBI Prohibition of Insider Trading Regulations require a structured digital database and controls over unpublished price-sensitive information. Audit committees increasingly ask internal audit to test those controls rather than take the compliance officer's word.

Put together, the committee has a written reason for every question below.

3. The six questions to walk in ready for.

Did we audit the right things? Show the risk universe, the scoring, and why this quarter's scope was chosen. One page.

What has not been fixed, and for how long? An open-findings register with owner, original target date, number of times the date moved, and quarter-on-quarter closure rate.

Are related party transactions actually at arm's length? Evidence of pricing tested against third-party comparables, not the approval minute.

Do the internal financial controls still hold? What was tested, what failed, and whether any failure could reach the financial statements.

What are you seeing in technology? ERP access, cyber incidents, AI tools in use, and readiness under the Digital Personal Data Protection Act, 2023. The committee wants to know internal audit has looked, not a technical briefing.

Are you independent and adequately resourced? Any restriction on scope or access, whether the reporting line runs to the committee, and whether the team has the skills the plan requires. An honest gap builds more credibility than a reassuring answer.

4. Preparing for the meeting.

Send a short pack a week ahead: one-page executive summary, findings register, risk map, plan status. Meet the committee chair privately beforehand on anything sensitive. Leave time for the session without management present; the LODR contemplates it and the better committees use it.

When internal audit takes the questions seriously, the report gets shorter, findings get owners and dates that are tracked, and closure rates rise because the committee asks about them every quarter. That is the mechanism by which internal audit produces change rather than paper.

This article is general in nature and does not constitute professional advice. Readers should seek specific advice before acting on any matter described here.

This website is meant for information purposes only. The contents are made available on a pull basis and are not intended to solicit work or advertise.

Frequently asked

Do these questions apply to unlisted companies?

Section 177 of the Companies Act, 2013 requires an audit committee for listed companies and prescribed classes of public companies, and section 138 mandates internal audit for a wider group including certain private companies. Boards of large family-owned businesses increasingly adopt the same practices voluntarily, often because lenders, investors or a planned listing expect them.

Should the internal auditor report to the audit committee or to the CFO?

Functionally to the audit committee, administratively to management. The LODR's requirement that the committee review the internal auditor's appointment, remuneration and performance only works if the reporting line runs to the committee.

CA Dheeraj Somani
CA Dheeraj Somani
Founder & Proprietor · D Somani & Associates · More about the firm →

Related notes