0% found this document useful (0 votes)
16 views19 pages

Process Guidelines

The document is an Internal Audit Process & Risk Reference Compendium that covers eight sectors and over 15 process cycles, detailing key risks, controls, and audit observations. It provides a structured risk-and-control matrix for various business processes, including procurement, order management, human resources, and fixed assets management. The compendium serves as a comprehensive guide for internal audit practices across multiple industries, emphasizing the importance of risk mitigation and compliance.

Uploaded by

prashantpal305
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views19 pages

Process Guidelines

The document is an Internal Audit Process & Risk Reference Compendium that covers eight sectors and over 15 process cycles, detailing key risks, controls, and audit observations. It provides a structured risk-and-control matrix for various business processes, including procurement, order management, human resources, and fixed assets management. The compendium serves as a comprehensive guide for internal audit practices across multiple industries, emphasizing the importance of risk mitigation and compliance.

Uploaded by

prashantpal305
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

INTERNAL AUDIT

PROCESS & RISK REFERENCE COMPENDIUM

Covering 8 Sectors | 15+ Process Cycles | Risks, Controls & Audit Observations
FMCG | Healthcare | Real Estate | Hospitality | Green Energy | IT/ITES | Manufacturing | Education

Prepared for Prashant Pal | CA | Internal Audit & Risk Advisory

CONTENTS
1. Common / Cross-Sector Process Cycles
2. FMCG (Fast Moving Consumer Goods)
3. Healthcare & Pharmaceuticals
4. Real Estate & Construction
5. Hospitality (Hotels & Restaurants)
6. Green / Renewable Energy Generation
7. Information Technology & ITES
8. Manufacturing & Engineering
9. Education & EdTech

HOW TO USE THIS DOCUMENT


Each sector section contains a four-column matrix: Process / Sub-process → Key Risks → Key Controls → Typical Audit
Observations. This is structured to mirror a risk-and-control matrix (RCM), which is the working document used in every internal
audit and IFC engagement.

Process column: The business process or sub-process being audited (e.g. Vendor Onboarding, Revenue Recognition).
Key Risks column: The significant risks that could materialise if controls fail — financial, operational, compliance, or
reputational.
Key Controls column: The controls expected to mitigate the risks — preventive, detective, automated, or manual.
Audit Observations column: Typical findings raised in practice — what auditors commonly discover when controls are absent
or ineffective.
Section 1 — Common / Cross-Sector Process Cycles
The following process cycles exist in virtually every organisation regardless of sector. Mastery of these is the foundation of any
internal audit practice.

1.1 Procure-to-Pay (P2P)

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Vendor • Fictitious or duplicate • Mandatory vendor • Vendor master contains duplicate


Onboarding vendors created registration form with entries with slight name variations
• Vendors related to supporting documents • Related-party vendors not
employees • Background check / KYC disclosed to management
(undisclosed) verification • Vendors onboarded without valid
• Incomplete KYC / • Dual approval for new PAN / GST registration
documentation vendor activation in ERP • No periodic review of inactive
• Blacklisted vendors • Periodic vendor master vendors — zombie vendor risk
onboarded review and deduplication

Purchase • Purchases initiated • Documented purchase • POs raised after goods receipt
Requisition & PO without proper need requisition process with (retroactive POs)
justification budget check • Multiple small POs to same vendor
• DOA bypass — • ERP-enforced DOA on same day to avoid DOA
approvals below hierarchy for PO approval threshold
authorised threshold • System alert for split PO • Purchases made outside approved
• Split purchases to avoid detection vendor list without exception
approval limits • Approved vendor list approval
• Purchases from non- enforced in ERP • No budget availability check before
approved vendor list PO creation

Goods Receipt & • Payments made without • 3-way match: PO + GRN + • 3-way match bypassed by manual
3-Way Match goods receipt Invoice before payment journal override
confirmation • Independent GRN by • GRN raised by the same person
• GRN manipulation — stores / warehouse team who raised the PO — SoD failure
quantity or quality • Quality inspection report • Partial deliveries fully invoiced and
mismatch for material goods paid
• Goods received without • System block on payment • No tolerance limit configured in
inspection if 3-way match fails ERP for quantity variance

Invoice • Duplicate payments on • Invoice uniqueness check • Duplicate invoices paid due to
Processing & same invoice in ERP (vendor + invoice different invoice number formats
Payment • Fraudulent invoices no + amount) • Bank account changed by single
from fictitious vendors • Bank account change user without second approval
• Early payment without requires dual approval + • Advances paid to vendors without
credit period expiry confirmation to vendor utilisation tracking
• Payments to bank • Payment run review by • Payment terms not updated in ERP
accounts not matching finance manager before — early payments reducing working
vendor master release capital
• Cheque/NEFT signatory
limit controls

1.2 Order-to-Cash (O2C)

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Customer • Sales to customers • Credit evaluation and • Credit limits set without formal
Onboarding & without credit limit approval process with evaluation — based on relationship
Credit evaluation documented criteria • Credit limit overrides by sales team
• Bad debts from • Credit limit set in ERP; without finance approval
unchecked customers orders blocked beyond • Customer accounts with no
• Fictitious customer limit transactions active for 2+ years
accounts created • Customer KYC verification • No formal process to review and
before activation revise credit limits annually
• Periodic review of credit
limits vs payment history

Order • Orders accepted • Sales order approval • Manual price overrides by sales
Management beyond workflow in ERP executives not subject to approval
production/service • Orders accepted for customers on
capacity credit hold
Process / Sub- Key Risks Key Controls Typical Audit Observations
process

• Pricing errors — • Pricing master maintained • Backdated sales orders raised to


manual discounts not by finance; sales team meet period targets — revenue
authorised cannot override manipulation risk
• Order modifications • Change order process with
post-approval without re-approval requirement
re-approval

Revenue • Revenue recognised • Invoice generation linked • Revenue booked on despatch note,
Recognition & before delivery (cut-off to delivery confirmation / not delivery confirmation
Invoicing risk) milestone • Credit notes issued without
• Fictitious sales — • Revenue recognition supporting reason documentation
invoices without policy aligned with Ind AS • Sales returns not recorded promptly
delivery evidence 115 — inflated revenue
• Under/over-invoicing • Monthly cut-off testing • Consignment stock treated as sold
procedure — premature revenue recognition
• Sales register reconciled
to dispatch records

Collections & • Cash collected not • Collections only to • Collections deposited with delay —
Cash Application deposited in company designated company bank teeming and lading risk
account account • Advances from customers not
• Misapplication of • Cash collection handled by adjusted against invoices on time
payments across cashier, not sales team • Debtors beyond 180 days not
customer invoices (SoD) provisioned as per Ind AS 109
• Old debtors not pursued • Debtors ageing report • No follow-up process for
or provisioned reviewed monthly by outstanding debtors — collections
finance manager ad hoc
• Provision for doubtful
debts policy with defined
ageing buckets

1.3 Human Resources & Payroll

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Recruitment & • Ghost employees • Joiner approval by HR and • Employees added to payroll before
Onboarding added to payroll business head joining date
• Hiring below minimum • Background and reference • Background verification outsourced
qualification standards verification before offer but results not reviewed
• Background verification letter • Salary negotiated by hiring
skipped • New joinee details verified manager without HR involvement
independently before — compensation inconsistency
payroll addition • No formal induction process —
• Employee ID creation only compliance training skipped
after document verification

Payroll • Ghost employees on • Payroll prepared by HR, • Separated employees continue to


Processing payroll approved by Finance receive salary — termination not
• Incorrect salary (SoD) communicated to payroll
calculations — errors or • Salary revision only with • Manual salary adjustments without
manipulation approved increment letter supporting letters
• Unauthorised salary • Monthly payroll • PF deducted but not deposited with
revisions reconciliation vs EPFO — compliance failure
• Payroll tax non- headcount report • Payroll not reconciled to headcount
compliance (TDS, PF, • Automated TDS and PF records monthly
ESI) calculations in
HRMS/payroll software

Attendance & • Buddy punching — • Biometric attendance • Manual attendance override by HR


Leave attendance marked for system with exception without supervisor approval
absent employees report • Leave without pay not deducted in
• Leave encashment • Leave management payroll month
manipulated system with manager • Casual leave and sick leave
• Overtime claimed approval workflow balances not reset at year end
without authorisation • Overtime pre-approval by • Contract staff attendance not
department head verified — payments for non-
• Monthly attendance working days
reconciliation
Process / Sub- Key Risks Key Controls Typical Audit Observations
process

Separation & Exit • Full and final settlement • Exit clearance checklist • System access not revoked within
errors or delays covering IT, admin, 24 hours of separation
• Access not revoked on finance, HR • Company assets (laptop, SIM) not
separation — IT and • Access revocation on last recovered — no tracking register
physical working day (IT policy) • Gratuity and leave encashment
• Assets not recovered • Full and final settlement calculated incorrectly
on exit calculation reviewed by • Exit interview not conducted —
finance flight risk not identified
• Asset recovery
confirmation before
settling dues

1.4 Fixed Assets Management

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Asset • Revenue expenses • Capitalisation policy with • Software maintenance costs


Capitalisation capitalised to inflate threshold (e.g. items capitalised as intangible assets
asset base above ₹5,000 capitalised) • Capital work-in-progress (CWIP)
• Assets capitalised • Commissioning certificate not transferred to fixed assets on
without commissioning before capitalisation in commissioning — understates
• Incorrect asset ERP depreciation
classification affecting • Asset category matrix with • Assets impaired but not written
depreciation useful life and depreciation down
rate • Useful life not reviewed periodically
• Finance review of capital as required by Ind AS 16
vs revenue treatment

Physical • Assets on books but not • Annual physical • Last physical verification done 3+
Verification physically present verification of all fixed years ago
(ghost assets) assets • Large number of 'not found' assets
• Assets present but not • Unique asset tagging not written off — inflated asset base
on books (unrecorded (barcodes/RFID) • Laptops and mobile phones
assets) • Reconciliation of physical assigned to ex-employees still
• Assets mislocated — at count with asset register active in asset register
employee homes or • Surprise verification for • No tagging for land and buildings —
unauthorised locations high-value portable assets verification not possible

1.5 Treasury & Cash Management

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Bank • Unidentified reconciling • Monthly bank • Bank reconciliation prepared but


Reconciliation items concealing fraud reconciliation by person not reviewed or signed off
• Timing differences used independent of cash • Old uncleared cheques not
to manipulate cash handling investigated — concealing
balance • Reconciliation reviewed payments
• Stale cheques not and approved by CFO / • Multiple bank accounts with no
reversed Finance Head centralised visibility
• Stale cheque reversal • Cash book maintained manually —
policy (typically 3 months) no ERP integration
• Direct bank confirmation
for material accounts

Petty Cash • Petty cash • Petty cash float limit with • Petty cash expenses approved by
misappropriation imprest system custodian themselves — SoD
• Duplicate • All petty cash expenses failure
reimbursements supported by original bills • Same bills submitted multiple times
• Expenses without • Petty cash custodian across different periods
supporting vouchers different from approver • Cash balances not counted and
• Surprise cash count by reconciled regularly
finance team • Petty cash used for personal
expenses of employees
Section 2 — FMCG (Fast Moving Consumer Goods)
FMCG organisations are characterised by high-volume, low-margin transactions, complex distribution networks, trade promotions,
and significant inventory and logistics operations. Key audit focus areas: distribution channel controls, trade spend, and inventory
management.

2.1 Supply Chain & Distribution

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Distributor / • Fictitious distributors • Distributor onboarding with • Primary sales booked without
Channel Partner receiving stock and KYC, trade licence, GST secondary (retailer) sales data —
Management margin verification channel stuffing
• Distributor claims • Primary and secondary • Distributors returning outdated
without physical stock sales reconciliation stock not accounted for
movement • GPS-tracked delivery • Distributor claims for promotional
• Channel conflict — confirmation material not verified with physical
parallel imports, grey • Periodic distributor evidence
market performance review • No reconciliation of stock at
distributor level with company
records

Trade Promotions • Scheme payments • Scheme design • Trade promotion spend 8-12% of
& Schemes made for non-qualifying documented and approved revenue but with minimal
transactions before launch documentation
• Duplicate or inflated • Claims verified against • Same scheme claim submitted by
claims from distributors primary sales data in multiple distributors for same event
• Promotional goods (free system • Return on scheme spend never
goods) not accounted • Free goods issued through calculated — no effectiveness
for ERP with separate measurement
accounting • Free goods issued manually
• Scheme audit by sales outside ERP — not tracked
finance team

Logistics & • Freight overbilling by • Freight rate master • Freight charged per actual distance
Freight transport vendors approved by procurement; but GPS data shows shorter route
• Fuel pilferage in payable only per approved • Multiple freight invoices for same
company-owned fleet rate trip with different reference
• Route deviation • GPS tracking for all numbers
increasing logistics cost vehicles • No competitive tendering for freight
• Route optimisation contracts above threshold
software with deviation • Demurrage charges paid without
alerts investigation of root cause
• Freight bill audit before
payment

2.2 Manufacturing & Quality (FMCG)

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Raw Material • Adulterated or • Approved vendor list with • Purchases from non-approved
Procurement substandard inputs quality certification vendors during shortage without
affecting product quality requirements documented approval
• Vendor concentration • Incoming quality • Quality inspection reports signed
risk — single source inspection with sampling without actual testing
dependency standards • Significant price variance between
• Price variance — • 3-way match for raw purchase rate and approved rate
purchases above material purchases with no explanation
approved rate • Price variance report • Raw material shelf life not
reviewed monthly monitored — expired materials
used in production

Production & • Batch formula • Batch manufacturing • Batch records incomplete or filled
Batch Control tampering — under- records (BMR) for each post-production
filling or ingredient production run • Excess wastage written off without
substitution • Yield monitoring — actual investigation
• Production wastage not vs standard yield variance • No investigation of yield variance
recorded accurately investigation beyond 2% — significant loss
• Counterfeit product risk potential
Process / Sub- Key Risks Key Controls Typical Audit Observations
process

• Tamper-evident packaging • Finished goods produced but not


and product authentication entered into ERP until day end —
features gap period risk
• Production supervisor
sign-off on each batch

Inventory • Inventory theft or • FIFO / FEFO (First • FEFO not followed in dispatch —
Management pilferage at warehouse Expired First Out) policy near-expiry goods returned from
• Expired/near-expiry enforced in WMS market
stock not identified • Monthly cycle counts with • Shrinkage above industry norm not
• Inventory valuation annual physical verification investigated
errors • Expiry date tracking in • Slow-moving and obsolete
WMS inventory not provisioned quarterly
• Separate storage for near- • Batch-level inventory tracking not
expiry stock done — FIFO not verifiable

2.3 Sales & Marketing

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Sales Target & • Sales incentives • Incentive payout • Incentive paid on gross invoicing —
Incentive manipulated — calculated on net sales returns in next month inflate payout
bookings reversed after (after returns) • No clawback mechanism —
payout • Clawback provision for executives reverse orders after
• Returns spike post- reversals within 60 days of incentive collection
period to meet targets payout • Incentive scheme not documented
(channel stuffing) • Sales incentive calculation — verbal commitments causing
• Incentive calculation reviewed by finance disputes
errors • Monthly sales return • Regional manager approving their
analysis by product and own incentive calculation
region
Section 3 — Healthcare & Pharmaceuticals
Healthcare organisations face unique risks around drug inventory, regulatory compliance (CDSCO, MCI, PCPNDT, NABH), patient
billing, and insurance claims. Pharmaceutical companies have additional risks around clinical trials, batch recall, and narcotic
controls.

3.1 Hospital Operations

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Patient • Inflated billing — • Patient billing generated • Manual service entries in billing not
Registration & services not rendered from clinical system (not linked to clinical notes
Billing charged to patient manual) • TPA (insurance) claims for services
• Insurance fraud — • Discharge summary not supported by medical records
claims for non- reviewed by billing team vs • Day care procedures billed as
performed procedures clinical records inpatient to claim higher insurance
• Revenue leakage — • Insurance pre- package
services rendered but authorisation obtained • Billing team incentivised on
not billed before planned procedures collections — conflict of interest
• Daily revenue
reconciliation: clinical
system vs billing system
vs cash

Drug & • Drug pilferage from • Indent-based dispensing • Drugs dispensed without valid
Consumable pharmacy linked to prescription and prescription entry in HMS
Management • Expired drugs patient record • Narcotic register not maintained
dispensed to patients • FEFO followed in daily — count reconciliation gaps
• Narcotic drugs pharmacy inventory • Returned drugs from patients re-
mismanaged — management entered into stock without quality
regulatory risk • Narcotic register check
maintained as per Narcotic • High-value drugs (oncology,
Drugs and Psychotropic anaesthesia) not under perpetual
Substances Act inventory
• Perpetual inventory with
daily reconciliation for
high-value drugs

OT / Procedure • Surgical kits misused or • OT checklist linking • Implants used in surgery not
Scheduling under-reported implant usage to patient entered in implant register
• Implants used but not billing • Surgical kits opened and items
charged to patient • Surgeon and consumed but not recorded
• Ghost procedures — anaesthesiologist sign-off • Difference between OT utilisation
billing for surgeries not on procedure record log and billing record — unbilled
performed • Implant serial number procedures
recorded in patient file and • High-value implants procured from
billing system vendor recommended by surgeon
• Video recording of OT (in — kickback risk
select facilities for
compliance)

3.2 Pharmaceutical Manufacturing

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

GMP Compliance • Non-GMP production • Batch Manufacturing • BMR not completed


& Quality leading to CDSCO Record (BMR) and Batch contemporaneously — filled
action or product recall Packing Record (BPR) for retrospectively
• Batch failure due to each batch • Out-of-specification (OOS) results
inadequate testing • QC testing of every batch investigated informally — no written
• Data integrity risk — lab before release investigation
results manipulated • 21 CFR Part 11 compliant • Audit trail disabled in LIMS — data
electronic records (for integrity failure
export-oriented units) • Stability samples not retained for
• Deviation management required period
and CAPA process

Narcotic & • Diversion of controlled • Restricted access to • Controlled substance balance not
Controlled substances for illegal controlled substance tallying with register
Substances use storage
Process / Sub- Key Risks Key Controls Typical Audit Observations
process

• Regulatory penalties for • Double-lock system with • Access to controlled substance


record gaps dual custodians store not limited to authorised
• Theft from production or • Daily reconciliation of personnel
warehouse controlled substance • Destructions of rejected controlled
register substance batches not witnessed
• Annual government by regulatory officer
inspection readiness • Controlled substance register not
maintained in prescribed format
Section 4 — Real Estate & Construction
Real estate companies face risks across project execution, revenue recognition (Ind AS 115 / POC method), RERA compliance,
subcontractor management, and land acquisition. Construction companies additionally face material procurement, contractor
billing, and safety compliance risks.

4.1 Project Management & Construction

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Contractor • Fictitious work orders • Independent measurement • Running account bills passed
Management raised for contractor by PMC (Project without independent measurement
payments Management Consultant) • BOQ quantities revised upward
• Inflated BOQ (Bill of • Work order backed by without change order approval
Quantities) approved BOQ and design • Same person verifying
measurements drawings measurement and approving
• Subcontractor collusion • Joint measurement payment — SoD failure
with site engineer certificate with contractor • Contractor not registered under
• Labour law non- and company QS CLRA for contract labour above
compliance by • Periodic labour threshold
contractors compliance audit of
contractors

Material • Purchases above • Rate approval by • Purchases from related-party


Procurement approved rates procurement committee for vendors without disclosure
(Construction) • Substandard material high-value materials • Material test reports not obtained or
leading to quality and • Third-party quality testing not reviewed
safety risk for cement, steel, • Site stock register not maintained
• Material diversion from aggregates — material theft undetected
site • Material reconciliation: • Material issued to contractor
quantity received vs without consumption tracking
quantity used vs closing
stock
• Site store with restricted
access

RERA Compliance • Customer funds used • Separate designated • RERA account funds withdrawn for
for non-project RERA account for each purposes other than land and
purposes project (mandatory) construction costs
• Project completion • 70% of customer • RERA registration obtained but
delayed beyond RERA collections deposited to portal not updated quarterly
commitment RERA account • Structural changes made to plan
• Undisclosed changes to • RERA portal updated with without RERA amendment filing
approved plan construction progress • OC (Occupancy Certificate)
regularly obtained late — possession
• Legal team review of sale delayed beyond RERA commitment
agreements for RERA
alignment

4.2 Revenue Recognition & Sales

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Revenue • Revenue recognised • Revenue recognition • POC calculated by project team


Recognition (Ind before performance policy aligned with Ind AS without independent engineering
AS 115) obligation satisfied 115 certification
• Percentage of • POC based on certified • Revenue recognised on agreement
completion engineer valuation, not date regardless of completion stage
manipulation management estimate • Pre-launch bookings recognised as
• Brokerage and • Brokerage recognised as revenue before RERA registration
incentives distorting deduction from revenue • Customer cancellations and
revenue with documentation forfeitures not accounted for in
• CFO review of quarterly revenue recognition
revenue recognition
workings

Customer • Collections • All customer payments • Demand raised before milestone


Collections & misappropriated before only to registered achieved — customer disputes
RERA Account bank deposit company bank accounts • Collections deposited in general
account instead of RERA account
Process / Sub- Key Risks Key Controls Typical Audit Observations
process

• Demand letters issued • Demand schedule tied to • PDC not deposited on due dates —
not aligned with construction milestone working capital impact
construction milestones certificates • Customer payment receipts not
• Post-dated cheques • PDC register maintained issued promptly
mismanaged and reviewed monthly
• Collections reconciled to
booking records daily
Section 5 — Hospitality (Hotels & Restaurants)
Hospitality businesses face unique risks in revenue management (rooms, F&B, banquets), cash-heavy operations, perishable
inventory, channel management (OTA commissions), and guest experience-linked compliance (FSSAI, fire safety, PCIDSS for card
payments).

5.1 Front Office & Revenue

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Room Revenue & • Reservation • Rate plan master • Front office team overriding rate
Reservations manipulation — maintained by revenue without authorisation — discounts
blocking rooms for manager, not front office to known guests
personal use • OTA commission • Complimentary rooms given at
• OTA commission reconciliation against operational level without GM
overbilled channel-wise booking approval
• Rate below approved report • OTA commission invoices not
rack rate without • Complimentary room matched against actual bookings
authorisation authorisation by GM only before payment
• Walk-in revenue not • Night audit report • Night audit not performed daily —
captured — cash reconciling occupancy vs revenue discrepancies not detected
pilferage revenue promptly

F&B Revenue • KOT (Kitchen Order • KOT void and cancellation • High void/cancellation rate on cash
(Restaurant & Bar) Ticket) manipulation — requires manager override transactions — pilferage signal
voids and cancellations with reason • Manual KOTs raised for select
• Cash sales not rung • All orders mandatory tables — revenue bypassing POS
through POS through POS before • Bar stock physical count not
• Bartender pilferage — preparation matched against consumption and
under-pouring or theft of • Bottle-for-bottle exchange opening stock
spirits policy for spirits • Recipe-based cost of goods not
• Surprise cash count benchmarked — actual
against POS Z-report daily consumption much higher

Banquet & Events • Event overbooking • Banquet booking system • Banquet advances received in cash
leading to customer with confirmed booking — not deposited or recorded
dissatisfaction and deposit policy • Additional services consumed
• Advance deposits for • Event BEO (Banquet during event not billed
events not accounted Event Order) signed by • BEO signed but not updated when
for client with full scope event scope changes — under-
• Banquet revenue • Post-event billing reviewed billing
leakage — additional against BEO before • Cancellation forfeitures not
services not billed invoice dispatch enforced per contract terms
• Deposit receipts issued
and tracked in system

5.2 Food & Beverage Operations

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Kitchen & • Perishable wastage • Daily food cost report • Food cost % consistently above
Perishable above norm — theft or against revenue (cost %) industry benchmark (28–32%)
Inventory poor planning • Receiving inspection with without explanation
• Purchases inflated by quantity and quality check • Perishable purchases made by
kitchen team • FEFO in cold storage with kitchen in-charge from preferred
• FSSAI compliance daily temperature logs vendors without procurement
failure involvement
• FSSAI records (food logs,
pest control, hygiene) • Cold storage temperature records
maintained not maintained — food safety risk
• Pest control contract active but visit
records not maintained

Recipe Costing & • Menu prices not • Standardised recipe cards • No standardised recipes — food
Menu Pricing covering cost — margin for all menu items cost varies widely by shift
erosion • Quarterly menu • Menu prices not reviewed for 2+
• Recipe not followed — engineering review — cost years despite input cost inflation
inconsistent quality and vs sales mix • Portion control not enforced — high
cost • Actual vs standard food variability in cost per cover
cost variance analysis
Process / Sub- Key Risks Key Controls Typical Audit Observations
process

• Wastage not segregated from


actual consumption — inaccurate
food cost
Section 6 — Green / Renewable Energy Generation
Renewable energy companies (solar, wind, hydro, biomass) face risks in project commissioning, energy generation and offtake
(PPA compliance), O&M performance, regulatory compliance (CERC/SERC), and ESG data integrity. This is a rapidly growing
sector with significant audit complexity.

6.1 Project Development & EPC

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

EPC Contract • EPC contractor delay • Milestone-based EPC • Milestone payments released
Management leading to COD payment schedule tied to without independent engineer
(Commercial Operation independent engineer certification
Date) miss certification • Variation orders approved by
• Variation orders • Variation order approval project team without commercial
inflating EPC cost process with financial review
• Substandard equipment threshold and technical • Equipment specifications changed
or installation justification post-LOI to lower-cost alternatives
• Third-party quality • Performance guarantee not invoked
inspection during despite EPC delay — commercial
installation (panels, lapse
inverters, cabling)
• Performance bank
guarantee from EPC
contractor

Land & Regulatory • Land acquisition • Legal due diligence on • Land documents not verified for
Compliance disputes delaying land titles before encumbrances
project acquisition • Forest land used without Stage II
• Environmental • Environmental Impact clearance
clearance not obtained Assessment for projects • Grid evacuation line commissioned
or lapsed above threshold late — generation loss not
• Grid connectivity • Pre-COD regulatory quantified
approvals delayed checklist reviewed by legal • DISCOM interconnection
team agreement not executed before
COD

6.2 Operations & Maintenance

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Energy • Generation shortfall vs • SCADA monitoring with • Generation data from SCADA not
Generation & PPA PPA commitment — real-time generation reconciled with DISCOM meter
Compliance penalty risk visibility reading
• Meter tampering or • Independent third-party • Grid curtailment hours not
metering inaccuracy meter testing annually documented — force majeure claim
• Grid unavailability • Grid curtailment logs not possible
losses not documented maintained and reported to • CUF (Capacity Utilisation Factor)
for force majeure claim DISCOM/RLDC below P90 projections for 2+ years
• Monthly PPA compliance — O&M performance issue
report reviewed by • Meter calibration records not
commercial team maintained

O&M Performance • Preventive maintenance • Preventive maintenance • Preventive maintenance schedule


skipped — increased schedule in CMMS exists but actual adherence not
breakdowns (Computerised tracked
• Spare parts Maintenance Management • Spare parts procured from O&M
procurement inflated or System) contractor at inflated prices without
fictitious • Spare parts procurement market comparison
• O&M contractor through approved vendor • SLA penalties never invoked
performance not process despite repeated performance
monitored against SLA • Monthly O&M SLA review shortfalls
with penalty / bonus • Inverter availability below 98% SLA
calculation without formal non-conformance
• String-level and inverter- raised
level monitoring for solar

ESG Data & • Incorrect generation or • Generation data from • GHG savings calculated using
Sustainability emissions data in SCADA as primary source; incorrect emission factor (outdated
Reporting sustainability report reconciled with DISCOM grid emission factor used)
meter
Process / Sub- Key Risks Key Controls Typical Audit Observations
process

• GHG savings • GHG calculation per GHG • RECs generated but not registered
overstated Protocol Scope 2 on RRAS within validity period —
• RECs (Renewable methodology expired unclaimed
Energy Certificates) not • REC registration and • ESG report boundary inconsistent
claimed or incorrectly issuance tracked in RRAS — some assets excluded without
reported / I-REC system disclosure
• ESG data reviewed by • Water consumption at project sites
independent assurance not tracked — BRSR P6 gap
provider (BRSR / GRESB)
Section 7 — Information Technology & ITES
IT and ITES companies face risks around revenue recognition (milestone vs time-and-material), data security, employee cost
management (their primary cost), client contract compliance, and offshore delivery controls.

7.1 Revenue & Contract Management

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Project Revenue • Revenue recognised on • Revenue recognition • Revenue booked on invoice date
Recognition billing, not on policy per contract type irrespective of delivery stage
percentage completion (T&M, fixed price, • Project EAC not reviewed —
• Fixed-price project cost milestone) margin erosion discovered only at
overruns eroding • Monthly EAC (Estimate at project close
margin Completion) review for • Change requests executed verbally
• Change request fixed-price projects without written SOW amendment
revenue not captured • Change request (CR) • Unbilled revenue (accrued) not
formal approval before tracked and cleared systematically
work commencement
• Billing milestones defined
in SOW and tracked in
project system

Client Contract • SLA breach — uptime, • SLA monitoring dashboard • SLA credits claimed by client not
Compliance response time, delivery with automated alerting contested even when data shows
milestones • Data classification and compliance
• IP and data security DLP (Data Loss • Confidential client data processed
obligations not met Prevention) tools on non-approved infrastructure
• Subcontracting without • Subcontractor approval • Subcontractors used without client
client approval clause tracked during notification — contract breach risk
contract review • Contract renewals not tracked —
• Monthly SLA compliance auto-renewal clauses triggered
report shared with client without commercial review

7.2 IT General Controls (ITGC)

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Access • Excessive user access • Role-based access control • Users with conflicting access (e.g.
Management leading to SoD conflicts (RBAC) with least privilege can raise and approve PO)
• Terminated user principle • Terminated employees' accounts
accounts active • Automated active 30+ days after separation
• Shared or generic IDs provisioning/deprovisioning • Shared service accounts with
linked to HRMS multiple users — no individual
• Quarterly user access accountability
review (UAR) • Privileged access (admin IDs) not
• MFA for all critical systems logged or monitored
and remote access

Change • Unauthorised or • Formal change request • Developers have direct access to


Management untested changes with testing evidence production environment
deployed to production before production • Emergency changes deployed
• Emergency changes deployment without any documentation
without post- • Separation of development • No change freeze period around
implementation review and production month-end / year-end close
• Version control gaps environments
• Test results not documented —
• Change Advisory Board verbal sign-off only
(CAB) approval for
significant changes
• Rollback plan documented
for every major change

Backup & • Data loss from failed or • Automated daily backup • Backup taken but restoration never
Business untested backups with offsite / cloud tested — false assurance
Continuity • System downtime replication • BCP document last updated 3+
beyond RTO/RPO in • Annual BCP drill with years ago — technology landscape
disaster documented results changed
• BCP not tested — only • RTO/RPO defined per • RTO/RPO not defined for critical
documented system criticality and systems
tested
Process / Sub- Key Risks Key Controls Typical Audit Observations
process

• Backup restoration tested • No offsite backup — single point of


quarterly failure
Section 8 — Manufacturing & Engineering
Manufacturing companies face risks across production planning, quality control, scrap management, safety compliance (Factories
Act), and energy/utility efficiency. Heavy engineering adds project-based revenue recognition and long-cycle contract risks.

8.1 Production & Quality

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Production • Overproduction — • MRP (Material • Production plan based on ad hoc


Planning & excess inventory tied up Requirements Planning) in inputs, not system-generated MRP
Scheduling in working capital ERP linked to sales • No feedback loop between actual
• Underproduction — forecast production and plan — deviations
supply shortfalls and • Weekly production not investigated
customer penalties planning meeting with • Safety stock levels not reviewed for
• Material shortage sales, procurement, and 12+ months — stockouts risk
causing line stoppage production
• Machine downtime not tracked
• Safety stock levels defined against production loss
and monitored in ERP
• Daily production report vs
plan reviewed by plant
head

Quality Control & • Substandard finished • In-process quality • Final inspection done by production
Rejection goods shipped to inspection at each team — not independent QC
customers — returns production stage • Rejection rate consistently above
and warranty claims • Final inspection certificate standard — root cause never
• Rejection manipulated before dispatch investigated
to hide production • Rejection analysis report • Rework treated as normal
inefficiency with root cause and CAPA production cost — distorting
• Rework costs not • Customer rejection standard cost
tracked register tracked vs internal • Customer complaints not linked
rejection back to internal rejection/rework
data

Scrap • Scrap theft — saleable • Scrap weighment at gate • Scrap sold below market rate to
Management scrap removed from site with security witness related vendor
• Scrap proceeds not • Scrap sale through • Scrap generation not reconciled
accounted for fully competitive tendering or with production records —
• Scrap classification rate contract significant gap
manipulation • Scrap sale proceeds • No competitive process for scrap
deposited directly to buyer selection
company account • Security not present at scrap
• Scrap generation weighment — under-weighing
reconciled to material possible
consumption and
production output

8.2 Environment, Health & Safety (EHS)

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Statutory Safety • Factories Act non- • Annual Factories Act • Factories Act licence not renewed
Compliance compliance — penalties returns filed on time — operating without valid licence
and closure risk • HIRA (Hazard • HIRA conducted as a one-time
• Industrial accident Identification and Risk exercise — not reviewed after
liability Assessment) for each job process changes
• Contractor workforce type • Permit-to-work system exists but
safety gaps • Permit-to-work system for not enforced for routine high-risk
high-risk activities tasks
• Contractor safety induction • Accident near-misses not reported
and PPE compliance — no leading indicator tracking
monitoring
Section 9 — Education & EdTech
Educational institutions face risks in fee collection, scholarship management, examination integrity, and regulatory compliance
(UGC, AICTE, state board approvals). EdTech companies additionally face subscriber revenue recognition, content IP risks, and
high customer acquisition cost management.

9.1 Fee Management & Collections

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Fee Collection & • Fee collected in cash • ERP-generated fee • Manual fee receipts still in use
Receipts not deposited receipts only — no manual alongside ERP — reconciliation
• Duplicate receipts for receipts gaps
same fee • Cashier and accounts • Cash collections delayed in deposit
• Waivers and team different persons — teeming and lading risk
concessions without (SoD) • Fee waivers granted verbally by
authorisation • Concession and waiver management without system entry
approval by principal / • No reconciliation between
finance head with admission register and fee
documentation collection records
• Daily collection
reconciliation: receipts
issued vs bank deposit

Scholarship • Ghost scholarship • Scholarship list from • Scholarship received from


Management beneficiaries government/institution government but fully credited to
• Scholarship funds verified against student institution, not passed to students
diverted records • Student bank account details
• Eligibility criteria not • Scholarship payments changed without verification —
verified made directly to verified diversion risk
student bank accounts • Scholarship beneficiary list not
• Eligibility documentation reconciled against enrolled student
checked by independent database
team • Utilisation certificate submitted
• Scholarship utilisation without actual disbursement proof
report submitted to funding
authority

9.2 EdTech — Subscription & Content

Process / Sub- Key Risks Key Controls Typical Audit Observations


process

Subscription • Revenue recognised • Revenue recognition • Annual subscription fee fully


Revenue upfront for multi-year policy: ratable over recognised in month of sale
Recognition subscriptions subscription period (Ind • Deferred revenue balance declining
• Deferred revenue AS 115) faster than revenue recognition —
understated • Deferred revenue accounting error
• Churn not reflected in schedule reviewed • Free trial conversions not tracked
revenue monthly — revenue pipeline inaccurate
• Churn rate tracked and • Refund policy not consistently
used in revenue forecast applied — customer disputes
• Subscription management
system reconciled to
accounting system

Content & IP • Course content copied • Content creation • Content contracts silent on IP
Management from third-party sources agreements with IP ownership — ambiguity risk
— IP infringement ownership clause • Third-party images and videos used
• Instructor content favouring company without licensing
ownership disputes • Plagiarism check before • Course content not updated for 2+
• Content not updated — content publishing years — outdated material
quality deterioration • Content review cycle — • Instructor agreements executed
annual update schedule after content delivery — no IP
• Instructor agreements assignment
reviewed by legal before
contract execution
End of Document | Prashant Pal | Internal Audit & Risk Advisory Reference Compendium

You might also like