Why Should CFOs Review Internal Audit Reports Every Quarter?
Most internal audit reports in Indian companies follow the same journey.
The internal auditor submits the report. Someone forwards it to the CFO’s office. It sits in an inbox until the audit committee meeting is two days away. Then it gets skimmed, tabled, and filed.
Six months later, the same finding shows up again. Vendor master data still has duplicate entries. Petty cash reconciliations are still delayed. The three-way match between purchase order, GRN, and invoice is still being done manually in one plant. The statutory auditor flags it at year-end, and now it looks like a control failure instead of a known issue that was never closed.
If your business has an internal audit function under Section 138 of the Companies Act, 2013, this pattern is avoidable. CFOs who read internal audit reports every quarter, not just before the audit committee meeting, catch control weaknesses while they are still small and cheap to fix.
This blog explains why quarterly review matters, what a CFO should actually look for, and how to build a review habit that survives a busy close calendar.
Why Do internal Audit Reports quietly Become a Filing Exercise?
There is a simple reason this happens.
Internal audit reports are written in audit language: observations, risk ratings, root causes, recommendations. A CFO reading it for the first time right before a board meeting has neither the time nor the context to challenge anything in it. The path of least resistance is to accept it as presented and move on.
This turns internal audit reports into a compliance artifact rather than what they were designed to be: a live governance tool.
The Companies Act does not treat internal audit as a paperwork requirement. Section 138 requires certain classes of companies to appoint an internal auditor. Also, the rule 13 of the Companies (Accounts) Rules, 2014 gives the Audit Committee or the Board the responsibility to set the scope, periodicity, and methodology of internal audit in consultation with the internal auditor. That responsibility does not end once the report is issued. It continues through how the findings are reviewed, challenged, and closed.
For listed companies, SEBI’s LODR Regulations go further. Internal audit reports are among the documents the audit committee is legally required to review under Schedule II, Part C, alongside management discussion and analysis and statutory auditor communications. Regulation 18(2)(a) also requires audit committees to meet at least four times a year, and in most companies that translates into a quarterly review of audit findings.
What Does Quarterly Review Add That Annual Review Misses?
The difference is not just frequency. It is what becomes visible in time to act on it.
Annual review (at year-end) | Quarterly review | |
When issues surface | After the full year has closed | Within the quarter they occurred |
Ability to fix before statutory audit | Limited, often reactive | High, control gaps are closed before external scrutiny |
Repeat findings | Common, since the gap between audits is long | Rare, because closure is tracked every quarter |
CFO’s role | Approver of a finished report | Active reviewer shaping the next quarter’s focus areas |
Audit committee discussion | Dominated by explaining old findings | Focused on new risks and emerging trends |
Cost of remediation | Higher, issues have compounded over months | Lower, caught while limited in scope |
A control gap caught in Q1 usually needs a policy tweak or a training session. The same gap left unaddressed until Q4 can mean a qualified statutory audit opinion, a restatement, or a difficult conversation with investors who read the financials closely.
What Should a CFO look For In an Internal Audit Report?
Reading an internal audit report is different from reading a financial statement. A useful review routine looks for four things every quarter, in this order:
1. New findings and their risk rating
Is anything rated high risk for the first time? Does the risk rating match the actual financial exposure, not just the auditor’s checklist?
2. Status of prior quarter’s findings
Has the management action plan been executed, partially executed, or not started? A finding marked “in progress” for three quarters running is really an unresolved finding.
3. Patterns across functions
Are similar issues appearing in procurement, inventory, and fixed assets in the same quarter? That usually points to a system or process gap rather than three unrelated lapses.
4. Auditor’s commentary on scope changes
Did the auditor have full access to data and systems this quarter? Restricted access itself is a governance red flag worth raising.
Why Do repeat Findings keep Showing Up at year-end?
Repeat findings are one of the most reliable early indicators of a governance problem, and they rarely get the attention they deserve. A finding repeats for one of three reasons:
- The management action plan was written to close the report, not the risk. A generic response like “process will be strengthened” satisfies the audit committee minutes but fixes nothing.
- Ownership was never assigned to a person, only to a department. When everyone owns a finding, nobody does.
- The next quarter’s audit did not specifically re-test the closed items. Without re-testing, a finding marked closed on paper can still be open in practice.
Bonus tip:
An audit observation tracker is a useful tool. It’s a simple log kept outside the quarterly report. It lists every finding and shows the risk rating, the owner, and the target closure date. It also shows the re-test result.
When reviewed alongside the risk register, it turns quarterly review into a habit. Most companies that avoid repeat findings do this already. They may not call it a “tracker.” Often it’s just a shared spreadsheet. The CFO’s office and the internal auditor both update it. They review it for ten minutes at the start of each quarter.
How Can CFOs Build a Quarterly Internal Audit Review Rhythm?
A workable rhythm does not need a new tool or a large time commitment. It needs a fixed sequence that repeats every quarter.
1. Set a fixed review window.
Block two to three hours within a week of receiving the report, before the audit committee meeting, not the day before it.
2. Read the report against the prior quarter’s action plan first.
This immediately shows what moved and what stalled.
3. Update the risk register with any new or escalated risks from the report.
This only works if the risk register reflects the current audit cycle, not the one from two quarters ago.
Reviewing relevant Top 15 Internal Audit KPIs to Improve Audit Quality alongside these findings can help CFOs assess audit performance and follow-up effectiveness.
4. Walk into the audit committee meeting with a point of view.
This is what shifts the audit committee meeting from a formality to genuine oversight.
5. Flag questions for the internal auditor directly, rather than waiting for the audit committee meeting to raise them for the first time
What Should a CFO ask in the Internal Audit Review Meeting?
A short, consistent set of questions improves audit quality more than a long one that changes every quarter. Useful starting points:
- Which findings from last quarter are still open, and why?
- Did the scope of this audit change from what the audit committee approved?
- Are any findings connected to a control that directly affects financial reporting?
- Is there a finding here that the statutory auditor is likely to ask about separately?
- What would the internal auditor flag as the single biggest risk if this were a one-line summary?
That last question is worth asking every quarter. It forces a prioritisation that a full report, with everything rated on the same page, does not naturally provide.
Common Mistakes CFOs Make when Reviewing Internal Audit Reports
Even CFOs who do review internal audit reports every quarter can undercut the exercise with a few recurring habits.
- Treating the report as the auditor’s job to defend, not the CFO’s job to interrogate.
- Reviewing only the executive summary. Risk ratings and headline numbers rarely capture root cause. The detailed observations usually do.
- Waiting for the audit committee meeting to read the report for the first time. By then, there is no time to ask the internal auditor a clarifying question before the discussion.
- Not distinguishing between a process observation and a control failure. Both get logged as findings, but they carry very different levels of urgency.
When Does Quarterly Review Matter Less?
Quarterly internal audit review matters most for companies where internal audit is already an active function:
- PE-backed or VC-funded businesses preparing for a future listing or Series C and beyond
- Any listed entity governed by SEBI LODR
For an early-stage private company below the Section 138 thresholds, internal audit is voluntary. In that case:
- A half-yearly review cycle can be reasonable
- The right frequency depends on the company’s risk profile and pace of growth
Whatever the frequency, the underlying principle stays the same: internal audit reports are only useful if someone with authority reviews them soon after the issues are found, not months later. This is the rhythm that SGGK’s internal audit support engagements are built to help finance teams sustain.
Final thoughts About Internal Audit Reports
Reviewing internal audit reports every quarter is not about adding another task to a CFO’s calendar. It is about catching a control gap when it costs a policy update, not a qualified audit opinion. At SGGK, our audit support engagements follow a clear rhythm, helping finance teams track, address, and close internal audit findings before they come up again at year-end.
If your audit committee wants help setting up a quarterly review rhythm, SSK’s audit support team can walk through your current tracker.
Strengthen Your Internal Audit Process
Frequently Asked Questions About Internal Audit Reports
Is quarterly internal audit review mandatory in India?
In case of listed companies, SEBI’s LODR Regulations specify that the audit committee shall review internal audit reports, with at least four meetings per year. In case of unlisted companies, as per Section 138 of the Companies Act, there is no specified frequency; only quarterly is the usual practice.
Which companies are obliged to appoint an internal auditor as per the Companies Act?
All listed companies, all unlisted public companies having turnover of more than ₹200 crore, or ₹50 crore paid-up capital, ₹100 crore borrowings or ₹25 crore deposits, and all private companies having turnover of more than ₹200 crore or ₹100 crore borrowings in the previous financial year.
What is the difference between an internal audit finding and management action plan?
The finding is the observation of auditor about gap/risk. A management action plan is the plan of the process owner as a reaction to the finding, including the corrective action, owner, and target date.
Does reviewing internal audit reports quarterly replace the statutory audit?
No. Internal audit is a continuous, management-facing review of controls, while a statutory audit is an independent year-end opinion on the financial statements, and quarterly review only reduces surprises; it doesn't substitute for the statutory audit