Is Internal Audit Ready for Continuous Risk Intelligence?
CategoriesAudit

Last updated 3 September 2026 · Statutory references current to the Companies Act 2013 and the Companies (Accounts) Rules 2014.

Quick answer: No, internal audit is not yet ready, and the obstacle is capability rather than law. Section 138 of the Companies Act 2013 prescribes no interval for internal audit, and Rule 13(2) of the Companies (Accounts) Rules 2014 leaves periodicity and methodology to the Audit Committee or the Board. The annual plan is a convention, not a statutory requirement.

The annual audit plan was designed for a world where risks changed slowly. That world no longer exists. For decades internal audit has followed a familiar rhythm: build a risk-based annual plan, present it to the Audit Committee, execute it quarter by quarter and report findings after the fact. It is a model that served organisations well, until the risk landscape stopped waiting for the planning cycle. Cyber threats now emerge overnight, regulatory changes land with little warning and supply chains buckle in days rather than quarters. By the time a traditional audit is scoped, fielded and reported, the risk it was designed to catch may already have evolved into something else entirely.

Having watched the tension between the level of assurance stakeholders want and the speed at which risk actually moves, I set out below ten realities that each audit function must accept in order to shift from the current model of annual planning to a continuous risk intelligence model.

Does Indian law require the internal audit plan to be annual?

No. Most discussions of continuous auditing miss this point. It matters more in India than the global commentary suggests.

According to Section 138(1) of the Companies Act 2013, certain types of companies must appoint an internal auditor who can either be a chartered accountant or cost accountant or any other professional as per the decision of the Board. Section 138(2) empowers the government to specify how the internal audit should be done, but the by-laws drafted by it are silent about the frequency of internal audits.

In contrast, Rule 13(2) of the Companies (Accounts) Rules 2014 states that the internal audit scope, operation, periodicity, and methodology will be decided along with the internal auditor by the Audit Committee or Board.

Periodicity is therefore a governance decision taken by your Audit Committee rather than a constraint imposed by statute. A function that moves to continuous risk intelligence is not straining against the Companies Act but exercising a discretion the Act deliberately left open.

Which companies must appoint an internal auditor?

Rule 13(1) sets the thresholds, all tested against the preceding financial year:

Company type Trigger for mandatory internal audit
Listed company Every listed company, with no threshold
Unlisted public company Paid-up share capital of ₹50 crore or more; or turnover of ₹200 crore or more; or outstanding loans or borrowings from banks or public financial institutions exceeding ₹100 crore at any point; or outstanding deposits of ₹25 crore or more at any point
Private company Turnover of ₹200 crore or more; or outstanding loans or borrowings from banks or public financial institutions exceeding ₹100 crore at any point

The Explanation to Rule 13 also confirms that the internal auditor may or may not be an employee of the company, which is what makes outsourced and co-sourced internal audit models available to Indian companies.

Why is the annual audit plan becoming a historical document?

By design, a risk-based internal audit plan is a snapshot: a best guess at what risks matter, frozen at a single point in time and usually built months before execution even begins. The problem is that risk does not freeze. Thus, a plan that is approved in December might have become obsolete by March when regulations change, a merger occurs, or a system migration takes place.

This does not mean annual planning is obsolete; it means annual planning can no longer be the only mechanism for prioritising audit work. It must instead become a living document, revisited continuously rather than dusted off once a year.

Should risk assessment move from periodic to perpetual?

Yes. The shift is one of supplementation, not replacement.

Most functions still run their formal risk assessment once or twice a year, as a structured exercise involving interviews, surveys and workshops that is thorough but slow. Continuous risk intelligence flips the model: risk data is captured constantly, from operational metrics, control failures, incident logs and external signals, so that risk scores update in near real time rather than annually. The point is not to abandon structured risk assessments but to surround them with an always-on pulse of the organisation’s risk environment.

Why is data analytics no longer optional in internal audit?

Internal audit teams that still rely primarily on sampling and manual testing are structurally incapable of achieving continuous assurance, because there are simply not enough hours in the year.

Analytics changes the equation: instead of testing 30 transactions out of 30,000, audit teams can test all 30,000, flag anomalies automatically and redirect human judgement toward the exceptions that actually matter. This requires investment in tools, in data access and in skills, but the payoff is a level of coverage and speed that manual testing cannot match. The same logic already applies in asset-heavy environments, where a structured approach to fixed asset management produces the transaction-level data that continuous testing depends on.

What is the difference between continuous auditing and continuous monitoring?

These terms get used interchangeably. They should not be. They serve different purposes, sit with different owners and produce different kinds of evidence.

Continuous monitoring Continuous auditing
Owner Typically management Internal audit
Position Embedded into business processes Independent of the process
Purpose Flag control breakdowns as they happen Ongoing independent testing of controls and transactions
Typical method Process-embedded alerts and dashboards Automated audit scripts and audit-owned dashboards

A mature internal audit function does not simply rely on management’s monitoring; it builds its own independent continuous auditing capability, while also learning to treat management’s monitoring data as a risk signal in its own right.

What does the Audit Committee actually want from internal audit?

Expectations from Boards and Audit Committees are changing: though a report on the failures of the past quarter does provide some value, it is ultimately focused on history, whilst Committees now prefer a more forward-thinking perspective to understand better what risks are on the rise, where the controls show signs of weakness, and which additional areas need attention in future.

This is a fundamental repositioning of internal audit’s value proposition, from a rearview mirror to something closer to a radar system. It is also, under Rule 13(2), a conversation the Audit Committee is statutorily entitled to have with you about methodology and periodicity. The expectations placed on that dialogue are already visible in NFRA communication between auditors and Audit Committees, where the regulator has pressed for substantive rather than procedural exchange.

Why does technology risk break the traditional audit cycle?

Cloud migrations, artificial intelligence adoption, third-party integrations and cybersecurity threats evolve on a timeline measured in weeks, not the twelve to eighteen month cycle typical of a traditional IT audit rotation, which means that a system touched once every year or two is effectively audited as a version of itself that may no longer exist when the report is issued. Technology risk, more than almost any other risk category, demands continuous visibility rather than periodic deep dives.

How are talent requirements changing for internal auditors?

Continuous risk intelligence is not merely a technology upgrade. It is a talent transformation. Auditors need to be comfortable with data querying, with visualisation tools and, increasingly, with understanding how artificial intelligence and machine learning models work well enough to audit them, because the traditional profile of an auditor skilled primarily in controls testing and documentation review, however valuable it remains, is no longer sufficient on its own.

Forward-thinking functions now hire data scientists, engineers and analytics specialists alongside traditional auditors, and cross-train existing staff to bridge the gap. The ICAI Internal Audit Standards Board, which issues the Standards on Internal Audit, is the reference point Indian functions should be tracking as this expectation formalises.

Why do data silos block continuous risk intelligence?

Continuous risk intelligence depends on access to live data from ERP systems, GRC platforms, incident management tools, HR systems and external threat intelligence feeds. Yet in many organisations this data lives in disconnected silos, each with its own owner, format and access restrictions, and each requiring a separate negotiation before internal audit can see it.

Building the capability is as much an organisational and political challenge as a technical one. It requires data access agreements, data governance standards, and often the persuasion of other functions that sharing data with internal audit benefits everyone. Our guide to compliance, documentation and risk management sets out how that documentation layer is usually built.

Can third-party risk still be reviewed once a year?

No. Annual vendor risk assessments have become insufficient because of the speed with which third-party risks can emerge, as various incidents such as data breaches at a vendor, geopolitical disruptions and financial distress on the part of a key supplier can occur within a matter of weeks.

Continuous risk intelligence extends monitoring beyond the four walls of the organisation, incorporating real-time signals about vendor financial health, news events and even social sentiment. Many audit functions still lag here, treating third-party risk as a compliance exercise rather than a live risk category demanding ongoing attention.

Is continuous risk intelligence a replacement for traditional audits?

No. This is perhaps the most important point of all. Continuous risk intelligence does not mean abandoning traditional audit engagements. Deep-dive audits, control testing and independent assurance work still matter, especially for risks that require nuanced professional judgement, complex fraud investigation or detailed process walkthroughs that automation cannot fully replicate.

The future is not continuous risk intelligence instead of annual audit plans but a hybrid model. Continuous monitoring and analytics feed a dynamic, frequently updated risk register, which in turn informs a more agile audit plan, one that can pivot mid-year when new information demands it rather than waiting for the next annual cycle.

How mature is your internal audit function?

A simple maturity test for the internal audit process, against which most Indian functions we encounter sit at Level 1 or Level 2.

Level Stage What it looks like
1 Periodic audit Annual risk assessment, sample-based testing, periodic reporting
2 Data-enabled audit Analytics-supported testing, exception reporting, improved audit coverage
3 Continuous assurance Continuous monitoring, automated control testing, risk-based alerts
4 Dynamic risk intelligence Real-time risk sensing, predictive analytics, integrated governance intelligence
5 Strategic risk intelligence Assurance supported by artificial intelligence, continuous risk intelligence, predictive control insights, board-level risk foresight

The dilemma facing the Chief Audit Executives, Chief Financial Officers, and Audit Committees is not if internal audit employs artificial intelligence but how rapidly it can notice a significant swing in risk, how quickly that signal can reach those who can implement change, and how quickly managers will react. Auditors who can answer the question will not necessarily be the auditors who perform the most audits. Rather, those auditors are the ones who combine business acumen with risk knowledge, technological skills, data analytics expertise, and professional judgement to indicate what the control is, how the data determines whether the control works, what signals indicate the risk situation is shifting, and what the management team must do before the risk crystallises. That is the transition from internal audit as an assurance function to internal audit as a risk intelligence partner.

So, is internal audit ready?

Honestly? Not yet. Not universally. Many functions are still investing heavily in traditional planning cycles, manual testing and annual risk assessments, while continuous risk intelligence remains a conference-session aspiration rather than daily practice. But the direction of travel is unmistakable, because organisations generate risk-relevant data faster than ever, stakeholders expect faster insight, and the tools for continuous assurance have never been more accessible.

The functions that will thrive are the ones that start now, by building analytics capabilities, breaking down data silos, upskilling their people, and reshaping their relationship with the Audit Committee from “here is what happened” to “here is what is coming.” The annual audit plan is not disappearing. But it can no longer stand alone. When risks move in real time, assurance cannot remain static. The next generation of internal audit will be defined not by how many audits it completes but by how early it helps the organisation see what is coming.

How SBC works with internal audit functions

Steadfast Business Consulting (SBC) views internal audit and governance not as a mere periodic compliance process but as the development of a dynamic risk and control intelligence function. SBC’s Financial and Risk Advisory practice serves listed and unlisted companies in the areas of internal audit, ongoing internal audit transformation, co-sourcing, control testing, enterprise risk management, SOP development and Internal Financial Controls compliance under the Companies Act 2013. The starting point is not technology but an honest assessment of the current status of the risk intelligence capability of the organisation. If the organisation is now thinking of moving to continuous risk intelligence, the SBC internal audit team would be glad to discuss the opportunity.

Frequently Asked Questions

Is an annual internal audit plan legally required in India?

No. Section 138 of the Companies Act 2013 prescribes no interval for internal audit. Rule 13(2) of the Companies (Accounts) Rules 2014 assigns the scope, functioning, periodicity and methodology to the Audit Committee or the Board, in consultation with the internal auditor. An annual cycle is a professional convention.

Which private companies must appoint an internal auditor?

Under Rule 13(1)(c), a private company must appoint an internal auditor if, during the preceding financial year, its turnover was ₹200 crore or more, or its outstanding loans or borrowings from banks or public financial institutions exceeded ₹100 crore at any point during that year.

What is the difference between continuous auditing and continuous monitoring?

Continuous monitoring is owned by management and embedded into business processes to flag control breakdowns as they occur. Continuous auditing is internal audit’s own independent, ongoing testing of controls and transactions using automated scripts and dashboards. A mature function operates both.

Can an internal auditor be an employee of the company?

Yes. The Explanation to Rule 13 of the Companies (Accounts) Rules 2014 states expressly that the internal auditor may or may not be an employee of the company. This is what permits outsourced and co-sourced internal audit arrangements in India.

Does continuous risk intelligence replace deep-dive audits?

No. Deep-dive audits remain necessary for risks requiring nuanced professional judgement, complex fraud investigation and detailed process walkthroughs. The realistic model is hybrid, in which continuous analytics feed a dynamic risk register that informs a more agile audit plan.


Disclaimer: This article is intended for general information and does not constitute professional advice. Statutory positions are stated as at 3 September 2026 and readers should confirm current requirements before acting.

Leave a Reply

Your email address will not be published. Required fields are marked *