By the end of this chapter you'll be able to…

  • 1Distinguish internal audit's broader operational/governance mandate from external statutory audit's narrower financial-statement focus
  • 2Distinguish an ordinary audit's general-purpose, standardised scope from an investigation's specific-purpose, narrowly-tailored scope
  • 3Explain why due diligence surfaces risks a standard financial statement audit would not necessarily identify
  • 4Explain the heightened evidential rigour forensic accounting requires, given its orientation toward actual or anticipated litigation
💡
Why this chapter matters in CA Final
This chapter steps outside the standardised statutory audit framework entirely, covering four engagement types each defined by a genuinely different purpose — ongoing internal improvement, pre-transaction risk discovery, suspicion-driven inquiry, and litigation-ready fact-finding — each demanding its own distinct standard of rigour and evidential preservation.

Internal Audit, Due Diligence, Investigation and Forensic Accounting

Why these four sit in one chapter: all four exist outside the statutory audit

Every engagement examined so far in this paper — the statutory audit itself, reviews, compilations, agreed-upon procedures — shares a common feature: each is performed for, and reports to, parties external to the entity's own management, addressing the reliability of financial information for those external users. This chapter's four topics step outside that frame entirely: internal audit exists inside the organisation, serving management and those charged with governance directly; due diligence exists around a specific transaction, serving a prospective party to that transaction; investigation exists in response to a specific suspicion, serving whoever commissioned the inquiry; and forensic accounting exists specifically because its findings may need to serve a legal proceeding. Recognising this shared "outside the ordinary statutory audit" character is what turns four seemingly disparate topics into one coherent chapter.

Internal audit

Statutory basis and scope in India. The Companies Act, 2013 mandates internal audit for specified classes of companies (based on criteria such as paid-up capital, turnover, borrowings, or deposits), requiring such companies to appoint an internal auditor, who may be an internal employee or an external chartered accountant or firm, to conduct internal audit of the functions and activities of the company. Internal auditing is broader in scope than external statutory audit, extending beyond financial statement assurance to operational efficiency, risk management effectiveness, and governance processes — an internal auditor can, and typically does, examine matters (operational process efficiency, compliance with internal policy, strategic risk management) that fall entirely outside an external statutory auditor's own, narrower financial-statement-focused mandate.

Relationship between internal and external auditors. The relationship is one of potential reliance, not subordination — as SA 610 (covered in an earlier chapter) established, the external auditor may use internal audit's work, and even use internal auditors directly under the external auditor's own direction, but only after evaluating internal audit's objectivity, competence and systematic approach, and never in a way that transfers the external auditor's own ultimate responsibility for the statutory audit opinion; internal audit, correspondingly, is not there to serve the external auditor at all — its primary reporting relationship and accountability runs to management and those charged with governance, addressing a broader mandate than financial statement assurance alone.

Basics of Internal Audit Standards issued by ICAI. ICAI has issued its own Standards on Internal Audit, addressing matters such as the internal auditor's independence and objectivity (itself potentially compromised in specific ways that a genuinely internal, employed auditor's own organisational position can create, distinct from the independence concerns an external auditor faces), the planning and performance of internal audit engagements, and the reporting of internal audit findings — a body of standards distinct from, though conceptually parallel to, the Standards on Auditing governing external statutory audit.

Drafting an internal audit report. An internal audit report is typically structured around specific findings, their risk implications, and actionable recommendations for management, distinguishing it in tone and purpose from an external statutory audit report's narrower, standardised opinion format — internal audit reporting is inherently a management communication tool, aimed at driving specific operational and control improvements, not a standardised assurance opinion addressed to external users.

Audit trail. A specific, increasingly emphasised area of internal audit and internal control assessment: ensuring an entity's accounting software genuinely maintains an audit trail (edit log) of every transaction, recording each change made to accounting records along with the date the change was made, and ensuring this audit trail feature has not been disabled — a specific, technology-driven internal control concern this paper's digital auditing chapter's themes extend directly into internal audit's own scope of examination.

Internal audit as a management function. Internal audit is, at its core, best understood as a management function — a tool management and those charged with governance use to monitor and improve the organisation's own risk management, control, and governance processes from within — distinguishing its fundamental purpose from the external statutory audit's role of providing independent assurance to parties outside the organisation about the reliability of its financial statements.

Due diligence, investigation and forensic accounting

Due diligence review. Conducted typically before a significant transaction (an acquisition, a major investment, a lending decision), a due diligence review is a comprehensive examination of a target's financial, legal, operational and commercial position, undertaken specifically to inform the transacting party's decision — whether to proceed with the transaction at all, at what price, and on what terms — and to identify risks or liabilities that a standard financial statement audit, focused on historical fairness of presentation, would not necessarily surface, such as the quality and sustainability of reported earnings, off-balance-sheet commitments, pending or threatened litigation, and the genuine sustainability of key customer or supplier relationships underlying the target's reported performance.

Audit versus investigation. An ordinary audit is a general-purpose, periodic examination conducted according to a standardised scope defined by professional standards, addressing whether the financial statements as a whole are fairly presented. An investigation is a specific-purpose examination, undertaken in response to a particular suspicion, allegation, or need (suspected fraud, a shareholder dispute, a specific regulatory inquiry), with a scope defined by, and narrowly tailored to, that specific purpose rather than by a general, standardised audit scope — an investigation can be, and often is, considerably more intensive and probing within its specific, narrower scope than an ordinary audit would be, precisely because it is not constrained by the need to cover an entire set of financial statements within the same overall time and cost budget an ordinary audit operates under.

Types of investigation. Common investigation types include investigations on behalf of an incoming partner or shareholder (assessing the genuine value and condition of a business interest being acquired), investigations for a bank or lender considering extending credit, investigations into suspected fraud or misappropriation, and investigations mandated by a regulator or under a statutory provision — each carrying its own specific terms of reference defining precisely what the investigator has been asked to examine and report on.

Procedure, powers and standing of an investigator. An investigator's specific powers depend entirely on the source and terms of the appointment — a statutorily-appointed investigator (under specific Companies Act provisions, for instance) may carry specific legal powers to compel production of documents and information that a purely privately-commissioned investigator, engaged directly by one party with no statutory backing, would not possess, meaning the investigator's actual authority to compel cooperation must be assessed case by case rather than assumed uniform across every investigation engagement.

Types of fraud and indicators. Beyond the fraudulent-financial-reporting-versus-misappropriation-of-assets distinction already established under SA 240, investigation-specific work often focuses on identifying the indicators of fraud — the red flags (unusual, unexplained transactions, employees living conspicuously beyond their apparent means, resistance to segregation of duties, a dominant, unchallenged individual controlling multiple stages of a process) that prompt or focus an investigation's specific lines of inquiry, and the follow-up action once fraud is identified, which can range from internal disciplinary action to civil recovery proceedings to criminal referral, depending on the nature and severity of what is uncovered.

Forensic accounting. Forensic accounting is distinguished from an ordinary statutory audit by its explicit orientation toward matters that may end up before a court or other formal dispute resolution process — the forensic accountant applies accounting, auditing and investigative skills specifically to a matter with actual or anticipated litigation, requiring the forensic accountant to document work with a level of rigour and a preserved chain of evidence sufficient to withstand cross-examination and formal legal scrutiny, a materially higher standard of evidential preservation than an ordinary statutory audit's working papers, prepared for professional peer review rather than adversarial legal challenge, are typically built to withstand.

Difference between statutory audit and forensic accounting/investigation. The single clearest distinguishing feature, worth stating explicitly: a statutory audit's objective is to express an opinion on whether financial statements are fairly presented, a general, standardised objective applied uniformly regardless of whether any specific wrongdoing is suspected; forensic accounting and investigation's objective is to establish specific facts relevant to a specific, already-suspected or already-alleged issue, an objective inherently narrower in scope but typically far more intensive and probing within that narrower scope, and explicitly oriented toward producing findings that can withstand the adversarial scrutiny a legal or disciplinary proceeding will subject them to.

Forensic Accounting and Investigation Standards. ICAI has issued its own Forensic Accounting and Investigation Standards, addressing matters specific to this distinct discipline — engagement acceptance and planning for a forensic engagement, evidence gathering and preservation with the heightened rigour litigation readiness demands, and reporting standards appropriate to findings that may be relied upon in a formal legal or regulatory proceeding, distinguishing this body of standards from both the Standards on Auditing and ICAI's own Standards on Internal Audit.

Why this chapter closes with a genuinely distinct professional register

Each of this chapter's four topics asks you to step outside the standardised, general-purpose statutory audit framework this whole paper has otherwise assumed as its default frame, and to recognise instead an engagement defined by a different purpose entirely — ongoing internal management improvement, pre-transaction risk discovery, targeted suspicion-driven inquiry, or litigation-ready fact-finding — each demanding its own distinct standard of rigour, evidential preservation, and reporting appropriate to that specific, different purpose.

⚠️

Traps CA Final sets — and how to dodge them

These are the exact option-traps and misreads that cost marks under negative marking.

WATCH OUT
Treating internal audit as merely a smaller-scale version of external statutory audit, rather than a broader-mandate management function
WATCH OUT
Assuming every investigator has statutory powers to compel document production regardless of the actual source of their appointment
WATCH OUT
Treating a due diligence review as equivalent in scope and purpose to a financial statement audit
WATCH OUT
Underestimating the heightened documentation and evidence-preservation rigour forensic accounting requires compared to ordinary audit working papers

Exam-pattern practice

PYQ-style questions with full solutions. Work through them as a readiness check — mark yourself honestly and get your gap report at the end.

Readiness check

Are you exam-ready for Internal Audit, Due Diligence, Investigation and Forensic Accounting?

15 problems from this chapter. Try each one, reveal the worked solution, mark yourself honestly — get your gap report at the end.

15 questions~11 min

5-minute revision

The whole chapter, distilled. Read this the night before the exam.

  • Internal audit's mandate is broader than external audit's — operational efficiency, risk management, governance, not just financial statement fairness
  • Internal audit independence concerns are organisational (employment relationship, reporting line) — distinct from external audit's market-based independence concerns
  • Due diligence surfaces forward-looking commercial/sustainability risk (customer concentration, contract expiry) an audit's backward-looking fairness focus doesn't address
  • Audit = general-purpose, standardised scope across all financial statements; Investigation = specific-purpose, narrowly tailored, often more intensive within that narrow scope
  • An investigator's power to compel cooperation depends entirely on the source of appointment — statutory backing vs purely private commission
  • Forensic accounting requires litigation-ready evidence preservation (chain of custody) — materially more rigorous than ordinary audit working papers
  • Fraud indicators combine behavioural (living beyond means) and control-related (resisting segregation of duties) red flags — look for both together
  • Investigation reports have no single standardised format — structure follows the specific terms of reference for that engagement

CA Final question blueprint

How this topic is asked, tier by tier — so you can prep to the pattern.

Typical weightage: 10

Exam-hall strategy

Battle-tested tips from mentors and toppers for this topic under the sectional clock.

  1. For internal audit questions, explicitly state the broader mandate (beyond financial statement fairness) before addressing the specific scenario
  2. For audit-vs-investigation questions, explicitly contrast standardised general-purpose scope against specific-purpose, narrowly-tailored scope
  3. For investigator powers questions, always state the source of the appointment before concluding what powers the investigator actually holds
  4. For forensic accounting questions, explicitly connect the heightened documentation rigour to the anticipated adversarial legal scrutiny the evidence must withstand

Beyond the exam

Where this skill shows up in the job you're competing for — and in life.

M&A due diligence teams routinely uncover exactly the kin…

M&A due diligence teams routinely uncover exactly the kind of customer concentration, contract expiry, and off-balance-sheet risk this chapter describes, directly shaping deal pricing and structuring

Forensic accountants are increasingly engaged by companies

Forensic accountants are increasingly engaged by companies, regulators, and law enforcement in fraud and financial crime cases, with their litigation-ready documentation standards now a distinct, recognised professional specialisation within the CA qualification

Where else this topic is tested

Prepare once, score in every exam that asks it.

CA Intermediate
CMA Final

Questions aspirants ask

Pulled from the Q&A community and mentor sessions.

Yes, under SA 610, but only after the external auditor evaluates internal audit's objectivity, competence and systematic approach — and the external auditor always retains ultimate responsibility for the audit opinion regardless of this reliance.

No — due diligence has a fundamentally different, forward-looking, decision-support purpose (informing whether/how to transact) compared to an audit's backward-looking fairness assurance purpose, even though both may examine some of the same underlying financial records.
Header Logo