Internal Audit, Due Diligence, Investigation and Forensic Accounting
Why these four sit in one chapter: all four exist outside the statutory audit
Every engagement examined so far in this paper — the statutory audit itself, reviews, compilations, agreed-upon procedures — shares a common feature: each is performed for, and reports to, parties external to the entity's own management, addressing the reliability of financial information for those external users. This chapter's four topics step outside that frame entirely: internal audit exists inside the organisation, serving management and those charged with governance directly; due diligence exists around a specific transaction, serving a prospective party to that transaction; investigation exists in response to a specific suspicion, serving whoever commissioned the inquiry; and forensic accounting exists specifically because its findings may need to serve a legal proceeding. Recognising this shared "outside the ordinary statutory audit" character is what turns four seemingly disparate topics into one coherent chapter.
Internal audit
Statutory basis and scope in India. The Companies Act, 2013 mandates internal audit for specified classes of companies (based on criteria such as paid-up capital, turnover, borrowings, or deposits), requiring such companies to appoint an internal auditor, who may be an internal employee or an external chartered accountant or firm, to conduct internal audit of the functions and activities of the company. Internal auditing is broader in scope than external statutory audit, extending beyond financial statement assurance to operational efficiency, risk management effectiveness, and governance processes — an internal auditor can, and typically does, examine matters (operational process efficiency, compliance with internal policy, strategic risk management) that fall entirely outside an external statutory auditor's own, narrower financial-statement-focused mandate.
Relationship between internal and external auditors. The relationship is one of potential reliance, not subordination — as SA 610 (covered in an earlier chapter) established, the external auditor may use internal audit's work, and even use internal auditors directly under the external auditor's own direction, but only after evaluating internal audit's objectivity, competence and systematic approach, and never in a way that transfers the external auditor's own ultimate responsibility for the statutory audit opinion; internal audit, correspondingly, is not there to serve the external auditor at all — its primary reporting relationship and accountability runs to management and those charged with governance, addressing a broader mandate than financial statement assurance alone.
Basics of Internal Audit Standards issued by ICAI. ICAI has issued its own Standards on Internal Audit, addressing matters such as the internal auditor's independence and objectivity (itself potentially compromised in specific ways that a genuinely internal, employed auditor's own organisational position can create, distinct from the independence concerns an external auditor faces), the planning and performance of internal audit engagements, and the reporting of internal audit findings — a body of standards distinct from, though conceptually parallel to, the Standards on Auditing governing external statutory audit.
Drafting an internal audit report. An internal audit report is typically structured around specific findings, their risk implications, and actionable recommendations for management, distinguishing it in tone and purpose from an external statutory audit report's narrower, standardised opinion format — internal audit reporting is inherently a management communication tool, aimed at driving specific operational and control improvements, not a standardised assurance opinion addressed to external users.
Audit trail. A specific, increasingly emphasised area of internal audit and internal control assessment: ensuring an entity's accounting software genuinely maintains an audit trail (edit log) of every transaction, recording each change made to accounting records along with the date the change was made, and ensuring this audit trail feature has not been disabled — a specific, technology-driven internal control concern this paper's digital auditing chapter's themes extend directly into internal audit's own scope of examination.
Internal audit as a management function. Internal audit is, at its core, best understood as a management function — a tool management and those charged with governance use to monitor and improve the organisation's own risk management, control, and governance processes from within — distinguishing its fundamental purpose from the external statutory audit's role of providing independent assurance to parties outside the organisation about the reliability of its financial statements.
Due diligence, investigation and forensic accounting
Due diligence review. Conducted typically before a significant transaction (an acquisition, a major investment, a lending decision), a due diligence review is a comprehensive examination of a target's financial, legal, operational and commercial position, undertaken specifically to inform the transacting party's decision — whether to proceed with the transaction at all, at what price, and on what terms — and to identify risks or liabilities that a standard financial statement audit, focused on historical fairness of presentation, would not necessarily surface, such as the quality and sustainability of reported earnings, off-balance-sheet commitments, pending or threatened litigation, and the genuine sustainability of key customer or supplier relationships underlying the target's reported performance.
Audit versus investigation. An ordinary audit is a general-purpose, periodic examination conducted according to a standardised scope defined by professional standards, addressing whether the financial statements as a whole are fairly presented. An investigation is a specific-purpose examination, undertaken in response to a particular suspicion, allegation, or need (suspected fraud, a shareholder dispute, a specific regulatory inquiry), with a scope defined by, and narrowly tailored to, that specific purpose rather than by a general, standardised audit scope — an investigation can be, and often is, considerably more intensive and probing within its specific, narrower scope than an ordinary audit would be, precisely because it is not constrained by the need to cover an entire set of financial statements within the same overall time and cost budget an ordinary audit operates under.
Types of investigation. Common investigation types include investigations on behalf of an incoming partner or shareholder (assessing the genuine value and condition of a business interest being acquired), investigations for a bank or lender considering extending credit, investigations into suspected fraud or misappropriation, and investigations mandated by a regulator or under a statutory provision — each carrying its own specific terms of reference defining precisely what the investigator has been asked to examine and report on.
Procedure, powers and standing of an investigator. An investigator's specific powers depend entirely on the source and terms of the appointment — a statutorily-appointed investigator (under specific Companies Act provisions, for instance) may carry specific legal powers to compel production of documents and information that a purely privately-commissioned investigator, engaged directly by one party with no statutory backing, would not possess, meaning the investigator's actual authority to compel cooperation must be assessed case by case rather than assumed uniform across every investigation engagement.
Types of fraud and indicators. Beyond the fraudulent-financial-reporting-versus-misappropriation-of-assets distinction already established under SA 240, investigation-specific work often focuses on identifying the indicators of fraud — the red flags (unusual, unexplained transactions, employees living conspicuously beyond their apparent means, resistance to segregation of duties, a dominant, unchallenged individual controlling multiple stages of a process) that prompt or focus an investigation's specific lines of inquiry, and the follow-up action once fraud is identified, which can range from internal disciplinary action to civil recovery proceedings to criminal referral, depending on the nature and severity of what is uncovered.
Forensic accounting. Forensic accounting is distinguished from an ordinary statutory audit by its explicit orientation toward matters that may end up before a court or other formal dispute resolution process — the forensic accountant applies accounting, auditing and investigative skills specifically to a matter with actual or anticipated litigation, requiring the forensic accountant to document work with a level of rigour and a preserved chain of evidence sufficient to withstand cross-examination and formal legal scrutiny, a materially higher standard of evidential preservation than an ordinary statutory audit's working papers, prepared for professional peer review rather than adversarial legal challenge, are typically built to withstand.
Difference between statutory audit and forensic accounting/investigation. The single clearest distinguishing feature, worth stating explicitly: a statutory audit's objective is to express an opinion on whether financial statements are fairly presented, a general, standardised objective applied uniformly regardless of whether any specific wrongdoing is suspected; forensic accounting and investigation's objective is to establish specific facts relevant to a specific, already-suspected or already-alleged issue, an objective inherently narrower in scope but typically far more intensive and probing within that narrower scope, and explicitly oriented toward producing findings that can withstand the adversarial scrutiny a legal or disciplinary proceeding will subject them to.
Forensic Accounting and Investigation Standards. ICAI has issued its own Forensic Accounting and Investigation Standards, addressing matters specific to this distinct discipline — engagement acceptance and planning for a forensic engagement, evidence gathering and preservation with the heightened rigour litigation readiness demands, and reporting standards appropriate to findings that may be relied upon in a formal legal or regulatory proceeding, distinguishing this body of standards from both the Standards on Auditing and ICAI's own Standards on Internal Audit.
Why this chapter closes with a genuinely distinct professional register
Each of this chapter's four topics asks you to step outside the standardised, general-purpose statutory audit framework this whole paper has otherwise assumed as its default frame, and to recognise instead an engagement defined by a different purpose entirely — ongoing internal management improvement, pre-transaction risk discovery, targeted suspicion-driven inquiry, or litigation-ready fact-finding — each demanding its own distinct standard of rigour, evidential preservation, and reporting appropriate to that specific, different purpose.
