CategoriesAudit

Definitive Guide to Modernizing the Risk and Control Matrix | 90-Day Roadmap

SBC | Audit & Assurance | Risk Advisory

Modernizing the Risk and Control Matrix: Transforming an Audit Burden into a Strategic Advantage.

Practical Implementation: A 90-Day Modernization Roadmap

Written By: Sanjeeb Dey | Director – Audits & Assurance | SBC

Blog Metadata

Quick answer: A Risk and Control Matrix should not be treated as a static audit spreadsheet. A modern RCM links business objectives to material risks, maps only the controls that meaningfully mitigate those risks, assigns accountable owners, defines reliable evidence, and uses data and automation where they improve coverage. The objective is not to have fewer controls for its own sake. The objective is to achieve better risk coverage, faster exception visibility and clearer management accountability.

The case for modernization becomes stronger when the RCM is viewed alongside the COSO Internal Control-Integrated Framework, which treats internal control as relevant to operations, reporting and compliance, not merely as a documentation exercise. A good RCM therefore has to answer a management question as clearly as an auditor question: what can materially go wrong, what prevents or detects it, who owns the response, and what evidence tells us the control is actually working?

The need for that shift is also consistent with the wider direction of COSO Enterprise Risk Management Framework guidance, which connects risk with strategy and performance. In practice, this means an RCM should be designed around the business the organization is running today, rather than a collection of controls accumulated over several audit cycles.

1. The Anatomy of a Broken RCM

1.1 When compliance becomes the architecture

Many RCMs begin for good reasons. A company faces a new reporting requirement, a regulator asks for evidence, an auditor raises an observation, or management formalizes a previously informal process. The problem starts when every new requirement becomes another row, another checkbox, another approval, another test script and another evidence request, without anyone stepping back to ask what risk the full structure is actually managing.

Consider procurement. A traditional matrix may record vendor onboarding approval, purchase-order approval, invoice verification, payment authorization and periodic reconciliation. Each activity can be valid. Yet the matrix may say very little about the risks that management actually worries about: vendor concentration, conflicts of interest, unauthorized commitments, duplicate vendors, supply disruption or a change to supplier bank details immediately before a payment. The RCM is full, but the risk view is thin.

That is the first modernization principle: start with the risk, not with the control. The control should exist because a defined risk exists, and the evidence should exist because management needs to know whether the control operated as intended.

1.2 Control bloat: the hidden cost of “just one more control”

Control environments rarely become bloated in one dramatic event. They grow incrementally. One year, a reconciliation is added after an exception. The next year, a second-level review is added after a missed approval. A later system issue leads to a manual spreadsheet check. None of these decisions looks unreasonable on its own. Five years later, the organization may be paying for multiple controls that detect the same failure after it has already happened.

A modern control rationalization exercise therefore asks four simple questions for every control: What risk does it mitigate? Is that risk still material? Does another control already provide equivalent coverage? And can technology reduce the manual burden without weakening the control objective?

The answer may be to retain the control, redesign it, consolidate it, automate it or remove it. That decision should be evidence-based. Rationalization is not a headcount exercise and it should never be presented to management as a promise that every removed control will produce a financial saving. The goal is a stronger control architecture with less unnecessary friction.

1.3 Diffused ownership creates invisible gaps

“Finance owns it” is not a control owner. “IT owns it” is not a control owner. A department can be accountable for a process, but the RCM needs enough precision to tell management who performs the control, who reviews it when review is required, what evidence is retained, and who owns remediation when an exception is found.

This principle is consistent with the IIA Three Lines Model, which distinguishes management responsibilities from independent internal audit assurance. The RCM should make those distinctions visible instead of mixing process ownership, oversight and assurance into a single generic “owner” field.

1.4 Static maintenance produces a moving target

Technology, vendors, organizational structures and regulatory expectations do not wait for the annual audit plan. A company can move to a new ERP, outsource payroll, acquire another business, launch a digital sales channel or introduce an AI-enabled workflow between two risk assessments. If the RCM is updated only when Internal Audit prepares the next annual plan, it may describe a process that no longer exists.

This is one reason the IIA Global Internal Audit Standards emphasize a principle-based internal audit function that responds to organizational context and changing risks. The RCM is not itself the audit plan, but it is one of the most useful structures through which changes in risk and control design can be translated into an auditable record.

2. What a Modern Risk and Control Matrix Should Look Like

A modern RCM is best understood as a structured relationship rather than a spreadsheet. A practical RCM should connect five things: business objective, risk, control, evidence and assurance. The source framework describes this as “Business Objective → Risk → Control → Evidence → Assurance.” That sequence matters because it forces the organization to prove that every control has a business reason and that every assurance conclusion is supported by evidence.

A useful RCM record can therefore contain fields such as: objective affected, risk statement, risk category, inherent risk rating, control objective, control description, preventive/detective/corrective classification, frequency, system or manual nature, owner, reviewer, evidence, testing approach, exception criteria, remediation owner and residual risk.

Not every organization needs every field in the same level of detail. The principle is to include enough structure to support management decisions without turning the RCM into an encyclopedia.

2.1 Anchor risk statements to business objectives

A weak risk statement says: “Invoices may be incorrect.” A stronger risk statement explains what happens to the business if the risk occurs: “Incorrect or duplicate supplier invoices may result in overpayment, misstated expenses and avoidable cash leakage.” The second statement makes it easier to identify meaningful preventive and detective controls.

For strategic objectives, the same logic applies. If a manufacturer is trying to improve production reliability, the RCM should connect equipment failure, maintenance weaknesses, inventory inaccuracy and supply interruptions to that objective. If a technology company is growing through cloud products, identity access, data integrity, third-party risk and change management may become core risks.

This is where enterprise risk management practice adds useful perspective. ISO 31000 Risk Management Guidelines describe a common approach to identifying, analyzing, evaluating, treating, monitoring and communicating risk, and it can be adapted to the organization’s context. The RCM should reflect that same context rather than treating every control as equally important.

2.2 Distinguish preventive, detective and corrective controls

A mature matrix does not treat all control types as interchangeable. Preventive controls aim to stop an undesirable event before it occurs. Detective controls identify a failure after it has occurred. Corrective controls help restore the process, recover assets, or address the root cause.

For example, role-based system access is largely preventive. A review of unusual privileged-user activity is detective. A formal access-remediation workflow after a breach is corrective. The three controls may all be necessary, but their purpose, evidence and testing method are different.

The ICAI Standards on Internal Audit include dedicated standards on internal controls, risk management, governance and compliance. A practical RCM should be able to support that professional conversation by making the linkage between risk, control design and assurance explicit.

2.3 Make evidence part of the control design

One of the most common design weaknesses is to describe what people should do without describing what proves they did it. “Finance reviews the vendor master monthly” is incomplete. A stronger control says what triggers the review, who performs it, what report is reviewed, what exceptions are investigated, where the evidence is retained and how the review is evidenced.

The ICAI Technical Guide on Risk-Based Internal Audit explains the relationship between risk and internal controls and highlights control activities such as review, approval, physical counts and segregation of duties. That same thinking helps when writing an RCM: the control statement should describe the actual risk-mitigation activity, not just the intended policy outcome.

3. Control Rationalization: Reduce Complexity Without Reducing Coverage

Control rationalization is often misunderstood as “control reduction.” In reality, the stronger approach is coverage optimization. A control can be removed only when the risk remains adequately addressed by another mechanism, when the legal or contractual requirement is not compromised, and when the resulting change is understood by the process owner and assurance teams.

A practical rationalization review can classify controls into five buckets: critical key controls, supporting controls, duplicate controls, obsolete controls and technology candidates. The first group stays central to the RCM. Supporting controls may remain in process documentation rather than the executive risk view. Duplicate and obsolete controls are candidates for consolidation. Technology candidates are controls where data, workflow or analytics can reduce manual effort or increase population coverage.

A useful companion concept is population-based testing. SBC’s current work in audit transformation also emphasizes the move from periodic assurance toward faster risk visibility; the same theme appears in Is Internal Audit Ready for Continuous Risk Intelligence? where the discussion distinguishes continuous monitoring, continuous auditing and the capability changes required to support them.

3.1 Example: procure-to-pay

Suppose a company currently has seven controls around procure-to-pay: vendor onboarding approval, purchase-order approval, invoice three-way match, payment maker-checker, duplicate payment review, monthly vendor-bank master review and quarterly procurement compliance review. The first task is not to cut the seven controls to four. It is to map each control to the underlying risks.

If duplicate-payment analytics already test 100% of transactions, a quarterly sample-based duplicate-payment review may no longer provide meaningful incremental coverage. If bank-detail changes are already blocked by workflow and independently approved, a manual spreadsheet review may be better redesigned than simply retained forever. But if there is no preventive control over conflicted vendor creation, removing a detective control would create a gap.

The output should be a clear rationale for each change. That rationale is as important as the revised RCM itself because it allows Internal Audit, management and the Audit Committee to understand why the control environment is different from the prior year.

4. Ownership and Accountability: From Department Names to Named Roles

A modern RCM should identify the operational owner, the reviewer where required, and the remediation owner for exceptions. Frequency should be defined by the risk, not by habit. A high-risk control may need to operate continuously or daily. Another control may be appropriate monthly or only when a triggering event occurs.

The owner also needs authority and access. A control assigned to someone who cannot access the required system report, cannot approve the exception, or cannot escalate a failure is not a well-designed control. In automated environments, ownership may be shared across process owners, application owners, data teams and information security functions, but the RCM should still make the accountability chain explicit.

This is consistent with the IIA Three Lines Model emphasis on clear roles across management, risk/compliance functions and Internal Audit. The purpose is not to create more governance layers. It is to prevent assurance gaps and duplicated responsibility.

5. Continuous Monitoring: Moving Beyond the Annual Snapshot

Sampling remains appropriate when judgment, qualitative evidence, interviews or complex documentation are required. But high-volume, rules-based transactions are increasingly suitable for automated testing. That is where continuous monitoring becomes practical.

Consider four examples: duplicate payments, vendor master changes, transactions above delegated authority and access rights that remain active after employee exit. These controls can often be expressed as rules and tested against large or complete transaction populations. The result is not “100% assurance.” It is broader detection coverage, faster exception identification and a better use of human review time.

The NIST Cybersecurity Framework 2.0 is a useful illustration of the broader trend toward structured, outcome-based risk management. It provides a taxonomy of cybersecurity outcomes and supports organizations in understanding, assessing, prioritizing and communicating cybersecurity risk. In an RCM context, the same principle can be applied to access, incident response, change management and third-party security controls.

5.1 Continuous monitoring versus continuous auditing

The terms are related but not interchangeable. Continuous monitoring is generally embedded in management processes, with management retaining responsibility for the controls being monitored. Continuous auditing uses ongoing or frequent analytics and testing under the independent mandate of Internal Audit. A mature model can use both: management monitoring helps run the business, while Internal Audit uses independent analysis to assess whether governance, risk management and control arrangements are working as intended.

The distinction is important for independence. Internal Audit should not become the owner of the controls it later needs to assure. The IIA Global Internal Audit Standards provide the professional context for independence, objectivity and value-oriented assurance.

6. The Role of GRC Technology and Data

A GRC platform can help centralize risk registers, control libraries, ownership, testing, exceptions and remediation. But software does not create a mature control environment. If the underlying risk statements are unclear, moving the same problems from Excel into a GRC tool simply creates a more expensive spreadsheet.

The right starting point is a clean control taxonomy. Decide what counts as a key control. Define evidence standards. Define control owners. Define how exceptions are categorized. Then decide which workflows genuinely benefit from technology.

Data quality matters just as much as the user interface. A dashboard that shows zero exceptions is not reassuring if the data feed is incomplete, a business unit is excluded, or the rule is incorrectly configured. Continuous monitoring therefore requires periodic validation of data completeness, rule logic, interfaces and exception handling.

Where asset-heavy operations are involved, the data foundation becomes particularly important. SBC’s 360° Fixed Asset Management work, for example, emphasizes capitalization, tagging, reconciliation, physical verification, audit trails and centralized visibility. Those same data disciplines are useful inputs into a control-monitoring environment for asset existence, disposal approvals, ownership and lifecycle changes.

7. Connecting RCM Modernization to ICFR, SOX and Governance

For organizations operating under Internal Financial Control (IFC), ICFR or SOX expectations, RCM modernization must preserve the controls that support financial reporting while improving how evidence and exceptions are managed. The goal is not to rebuild a separate RCM for every framework. It is to create one coherent control architecture with clear mappings to the relevant obligations.

In India, section 138 of the Companies Act provides for internal audit for prescribed classes of companies, while the related rules provide the operating context. The statutory text is available through the Companies Act, 2013 on India Code. The RCM should not be treated as a statutory form, but it can serve as an important management and assurance structure supporting the company’s broader governance processes.

For listed entities, the Audit Committee and governance framework also matter. Relevant requirements sit within the SEBI LODR Regulations, including provisions concerning Audit Committees and risk-management responsibilities. A modern RCM can help leadership move from reviewing dozens of control descriptions to discussing the exceptions, residual risks and remediation priorities that actually matter.

This governance conversation is also visible in the January 2026 NFRA guidance on audit committee communication, which places emphasis on effective communication between statutory auditors and those charged with governance. While an RCM is an internal management tool, the quality of its risk and control information can materially improve those governance conversations.

7.1 Evidence should be usable outside the RCM

The strongest evidence is not simply evidence that exists; it is evidence that can be retrieved, understood and reconciled by someone who was not involved in creating the control. That means retaining source reports, approvals, exception logs, access records and remediation evidence in a consistent structure.

The same discipline applies to other compliance areas. For example, a reconciliation-based control should be supported by a version of the underlying records that can be tied to the result. SBC’s PAS-6 Reconciliation of Share Capital Audit Report (Half-Yearly) illustrates the broader governance value of structured reconciliation, traceability and review evidence.

8. The 90-Day Modernization Roadmap

Design principle: The 90-day roadmap should be treated as a practical starting framework, not a universal timetable. Organizational size, control maturity, data quality, technology architecture and regulatory complexity will determine how quickly each phase can be completed.

Days 1–30: Rationalization and Pruning

The first month is about understanding what already exists. Do not begin by buying software. Begin by collecting the control inventory across critical business cycles and identifying which controls are actually key to material risks.

Inventory existing RCMs across Finance, Procurement, Sales, HR, IT, Operations and other critical processes.

Map each material control to a clearly worded business risk and objective.

Identify duplicate, overlapping, obsolete and low-value controls.

Identify material risks that currently have no meaningful control coverage.

Check whether process or system changes have made documented controls outdated.

Classify controls as preventive, detective, corrective, manual, automated or hybrid.

The output at Day 30 should be a rationalized control inventory and a prioritized gap list. Management should be able to see where the control environment is overly complex and where the organization is exposed.

Days 31–60: Calibration and Accountability

The second phase is where the surviving control set becomes operationally stronger. Risk ratings should be recalibrated, ownership clarified and evidence requirements standardized. This is also the right stage to test whether controls are designed to prevent the most important risks or merely to document compliance after the fact.

Define the control owner and reviewer for each key control.

Confirm the frequency and triggering events for control execution.

Specify the evidence expected from each control and where it is retained.

Review preventive and detective balance across high-risk processes.

Identify controls suitable for automation or continuous testing.

Define exception severity, escalation and remediation rules.

At the end of Day 60, the organization should have a revised RCM that a process owner can actually operate, an auditor can actually test and management can actually understand.

Days 61–90: Continuous Monitoring Integration

The third phase should begin with a small number of high-volume, rules-based controls. Select areas where reliable data is available and where exception detection can make a visible difference. Good pilot candidates include duplicate payments, purchase-order compliance, vendor master changes and employee-access deprovisioning.

Create read-only, governed data connections where appropriate.

Build and validate monitoring rules using known historical exceptions.

Define thresholds so that alerts are meaningful rather than excessive.

Assign named owners for investigation and remediation of exceptions.

Create a dashboard that shows open exceptions, aging, repeat failures and remediation status.

Periodically revalidate data completeness, rule logic and workflow performance.

A pilot is usually more valuable than a large transformation program launched without learning. Once the organization understands false positives, data limitations, ownership gaps and workflow friction, the monitoring model can be expanded to additional processes.

9. How to Measure Whether the Modernized RCM Is Working

The RCM itself should be measured. Otherwise, modernization becomes another project that produces documents but not better risk management. A small performance scorecard is usually more useful than a large set of activity metrics.

10. Common Mistakes to Avoid During Modernization

Buying a GRC platform before fixing the risk and control taxonomy.

Equating fewer controls with a better control environment.

Assigning ownership to departments instead of accountable roles.

Automating a poorly designed manual control without first validating the risk logic.

Using dashboards that show activity but not risk significance or root cause.

Assuming 100% population testing means 100% assurance.

Allowing Internal Audit to become the operational owner of controls it later needs to assure.

Ignoring mandatory legal, contractual or regulatory controls during rationalization.

Failing to document why controls were removed, consolidated or redesigned.

Updating the RCM once a year while the underlying process changes every month.

11. From RCM to Risk Intelligence

The long-term opportunity is larger than an improved spreadsheet. A modern RCM can become the structured layer that connects risk assessment, control testing, issue management, audit planning and management reporting. When that information is refreshed regularly, the organization gets something closer to risk intelligence: an informed view of where exposure is increasing, where controls are failing, where issues are recurring and where management attention is needed.

This evolution also mirrors changes in the internal audit profession. The ICAI Standards on Internal Audit include explicit standards for internal control, risk management, governance and compliance, while the IIA Global Internal Audit Standards place greater emphasis on strategy, stakeholder relationships and performance. RCM modernization should be part of that broader professional shift, not a separate spreadsheet cleanup exercise.

The distinction between assurance and operational risk ownership remains critical. A good RCM enables management to manage, risk teams to challenge and Internal Audit to provide independent assurance. The technology can be integrated, the data can be shared and the reporting can be coordinated, but accountability should remain clear.

12. The Boardroom Value: Why Management Should Care

A well-designed RCM gives the Audit Committee and senior management a more useful view of risk. Instead of receiving pages of control descriptions, leadership can focus on four questions: Which material risks are increasing? Which key controls are failing? Which exceptions are recurring? And where is remediation getting stuck?

That is a far more meaningful conversation than asking whether the RCM has 400 or 600 rows. The number of controls is not the measure of control maturity. The quality of risk coverage, clarity of ownership, reliability of evidence and speed of exception response are much closer to the real management outcome.

For organizations looking at broader governance and compliance transformation, SBC’s The Complete Guide to Compliance, Documentation, Benchmarking, Advisory and Risk Management (2026) – Part 1 also illustrates the move toward integrated risk, compliance and advisory thinking rather than isolated compliance workstreams.

13. Practical Questions for Leadership

When was the last time we removed a control because the underlying risk had disappeared?

A control that exists only because it has always existed may no longer provide meaningful coverage.

Can every key control be traced to a material business risk?

If not, the matrix may be activity-led rather than risk-led.

Can we identify the individual who owns every key control?

Department-level accountability is not enough when an exception needs immediate action.

Can Internal Audit obtain reliable evidence without chasing multiple teams?

The ease of retrieving evidence is itself a useful indicator of control maturity.

Which controls could be tested across the full population?

High-volume, rules-based activities are natural candidates for automated monitoring.

What changed in the RCM after the last major system or business-model change?

A static RCM can become inaccurate even when its formatting looks perfect.

14. How SBC Approaches RCM Modernization

SBC’s approach starts with the organization’s risk profile and operating model rather than with a technology product. The practical focus is to understand the existing risk and control framework, identify where coverage is duplicated or incomplete, define accountable owners, strengthen evidence and then introduce analytics where the data supports more efficient monitoring.

That approach is consistent with SBC’s broader Risk Advisory offering, which includes enterprise risk management, internal audit transformation, co-sourcing, control testing, SOP development, business process improvement and Internal Financial Controls compliance. The objective is not to turn every process into an automated dashboard. It is to create an RCM that is proportionate to risk and useful to the business.

Where the control environment intersects with tax, finance or regulatory processes, the same principle applies: evidence should be organized so a reviewer can follow the trail from transaction to conclusion. For example, SBC’s Transfer Pricing Assessment Procedure shows how a structured review process can link transaction analysis, documentation and assessment activity. The subject matter is different, but the underlying governance discipline is similar.

15. Frequently Asked Questions

What is a Risk and Control Matrix (RCM)?

An RCM is a structured record that links business objectives and risks to the controls designed to mitigate those risks, together with ownership, frequency, evidence and testing or assurance information.

Why should companies modernize their RCM?

Because business processes, systems, regulatory requirements and risk profiles change. A static RCM can become overly complex, outdated or disconnected from material business risks.

Does modernizing the RCM mean removing controls?

Not necessarily. Modernization means improving risk coverage and reducing unnecessary complexity. Some controls will be removed or consolidated, while others will be redesigned or strengthened.

What should be included in a modern RCM?

A practical modern RCM will usually include the risk statement, control objective, control activity, owner, reviewer where applicable, frequency, evidence, exception criteria and remediation responsibility. Organizations may add risk ratings, systems, testing method and residual risk depending on their needs.

What is the difference between continuous monitoring and continuous auditing?

Continuous monitoring is generally a management activity embedded in operations. Continuous auditing is typically performed by Internal Audit using frequent or automated analysis to evaluate controls and transactions and provide independent assurance.

Can every control be automated?

No. Controls involving professional judgment, complex investigations, qualitative assessment or nuanced process walkthroughs may still require human testing and review.

Does 100% population testing provide 100% assurance?

No. Automated testing still depends on complete and reliable data, correct rule configuration, functioning interfaces and effective exception handling.

How long does RCM modernization take?

The source framework proposes a 90-day starting roadmap, but actual duration depends on the organization’s scale, control maturity, systems, data quality and regulatory requirements.

Conclusion: The Future Is a Smarter RCM

A Risk and Control Matrix should help the business understand and manage risk. It should not exist simply because an auditor once requested a spreadsheet. The strongest RCMs make the relationship between business objectives, risks, controls, evidence and accountability visible and usable.

The modernization journey is therefore less about “digitizing the RCM” and more about redesigning the control environment around risk. Rationalize what is redundant. Strengthen what is material. Clarify who owns what. Automate where data and logic are reliable. Monitor exceptions continuously where that adds value. Keep deep-dive audit work where human judgment is essential.

The result is a control framework that can support not only audit readiness, but better governance, faster decision-making and more disciplined allocation of risk-mitigation resources. The organizations that make this transition successfully will not be the ones with the largest RCM. They will be the ones whose RCM tells management, clearly and quickly, what matters, what is changing and where action is required.

A question for leadership: Is your RCM primarily an audit requirement, or has it become an operating tool that management uses to understand risk and protect the business?

Organizations that are also reviewing how exceptions, reconciliations and regulatory workflows are tracked may find SBC’s Implications of Secondary Adjustment u/s 92CE useful as an example of how a control process can be translated into a defined register, review cycle and exception follow-up.

Disclaimer: This article is intended for general information and professional awareness. It is not a substitute for a facts-specific legal, regulatory, accounting or audit assessment. Organizations should consider applicable laws, regulations, contractual requirements, professional standards and the specifics of their own control environment before redesigning controls or changing assurance procedures.

CategoriesAudit

Population Testing vs Audit Sampling: What Changed

Written by Sanjeeb Dey · Statutory references current to the Companies Act, 2013 and applicable IFC requirements.

Quick answer: The deciding difference is residual uncertainty: population testing examines every transaction and leaves no untested portion, while sampling tests a subset and carries sampling risk. Population testing now suits high-volume structured data and Internal Financial Controls testing under section 143(3)(i) of the Companies Act 2013; sampling still suits small, unstructured or judgement-led populations.

For most of my career, sampling has been the backbone of how audit work gets done: you pick a statistically defensible sample size, test it rigorously, extrapolate the results and issue an opinion with an appropriate level of assurance. It is a methodology built on sound statistical theory that has served the profession well for decades.

But something has changed. Fundamentally. Presently, data generated by our clients in the form of millions of transactions recorded over a multitude of interacting systems no longer requires our selective approach but instead allows for full testing of the data. Now we are faced with yet another issue: in case we can test 100% in entirety, should we still stick to sampling as our default practice?

From witnessing this transition play out in our projects, I have learned ten key lessons about what is causing it, what it changes, and what further work needs to be done in the profession.

What is the difference between audit sampling and population testing?

Audit sampling Population testing
Coverage A statistically selected subset Every transaction in the population
Conclusion Extrapolated to the population Observed directly
Residual uncertainty Sampling risk remains No untested portion exists
Effort profile Manual testing of each selected item Automated screening, manual investigation of exceptions
Best suited to Small, unstructured or judgement-heavy populations High-volume structured transactional data
Detects clustered anomalies Only if the cluster happens to be sampled Yes, by design

Why has the business case for sampling flipped?

Sampling exists because testing everything used to be impractical: too expensive, too time-consuming, too manual. That constraint is disappearing.

With modern data-extraction tools and audit data analytics platforms, pulling and testing an entire population of transactions is often no more effortful than pulling a sample, and sometimes faster. When the cost of full-population testing approaches the cost of sampling, the argument for sampling weakens considerably. We are no longer choosing sampling because it is efficient; we are choosing it, in some cases, purely out of habit.

Does 100% testing mean 100% manual effort?

No. This is the single biggest misconception I encounter, even among experienced auditors.

Population testing does not mean assessing each transaction manually, because the workflow is fundamentally different. Automated scripts and analytics tools screen the entire population against defined criteria: duplicate payments, threshold breaches, unusual approval patterns and weekend postings. Only the exceptions are flagged. Human judgement is then applied where it actually matters, investigating the anomalies rather than rubber-stamping the routine.

This is a redistribution of effort. Not a multiplication of it.

How does population testing remove sampling risk?

Every auditor who has had to defend a sample size in the face of questions from a sceptical member of the Audit Committee knows the follow-up question that is bound to come: “But what about those transactions that you never looked at?” This question stems from sampling and is entirely unavoidable and legitimate from the perspective of statistics. Sampling risk, by definition, means there is a chance the sample does not represent the population accurately.

Testing the population sidesteps the problem altogether. Once each and every transaction has been tested, there is no question what the untested segment could be made up of because there is no untested segment left.

What issues does sampling miss that population testing catches?

This is, in my view, the most compelling argument for the shift.

Control failures and fraud are rarely distributed evenly in populations but tend to cluster together purposely to avoid detection, and a sample of 30 or 60 transactions, however statistically sound, can miss a pattern that only becomes visible when you look at all 50,000.

We have seen this firsthand. Anomalies that would never have surfaced in a traditional sample-based approach became immediately apparent once the full population was run through an analytics script: a handful of unusual entries, invisible in isolation, but glaring once compared against the whole.

The same principle applies in terms of physical verification. By sampling a fixed asset register, you assess whether or not the sampled assets exist; physical verification and tagging of the full asset base aids in identifying the non-existent ones.

How does population testing affect IFC testing in India?

For Indian companies, this is where the shift bites: in internal financial controls over financial reporting, or ICFR.

Under section 143(3)(i) of the Companies Act 2013, the statutory auditor must report on whether the company has appropriate internal financial controls in relation to its financial statements, and whether these controls are operating effectively. The ICAI Guidance Note on Audit of Internal Financial Controls Over Financial Reporting provides guidelines on how this testing is carried out.

Operating effectiveness is an evidential question, and where a control applies to a high-volume, structured transaction stream, testing the full population produces direct evidence of every instance in which the control did or did not operate, whereas a sample produces only an inference about everything it did not touch. As management and auditors converge on analytics-based testing of the same control populations, a documented Risk and Control Matrix supported by full-population results is materially stronger evidence than the same matrix supported by an extrapolation.

What skills does an auditor need for population testing?

Traditional sampling required a solid grounding in statistical theory, including confidence levels, tolerable error rates and sample size calculations. Population testing requires something different: comfort with data extraction, scripting, query languages and visualisation tools.

This does not make statistical knowledge irrelevant, but it does mean the day-to-day skillset of an auditor is shifting, and increasingly our teams need people who can write a SQL query or build a Python script for anomaly detection, just as much as they need people who understand internal controls frameworks. The ICAI Internal Audit Standards Board, which issues the Standards on Internal Audit, is the body Indian functions should watch as this expectation formalises.

Why do data access and data quality become the new bottleneck?

Once the testing itself is no longer the constraint, the constraint moves upstream, to data access and data quality.

Full-population testing is only as good as the completeness and accuracy of the underlying dataset. If a client’s ERP system exports incomplete records, or if access negotiations with IT take three weeks, that becomes the actual bottleneck in the engagement, not the analysis itself. A growing share of our engagement planning now goes into data scoping and access logistics rather than sample design. The principle is the same as for fixed asset register: the results of the analysis depend on the quality of the data being analysed.

How does population testing change what assurance means?

There is a meaningful difference between telling an Audit Committee “we tested a representative sample and found no material exceptions” and telling them “we tested every single transaction in the population and found no material exceptions.”

The latter is a categorically stronger assurance statement, and clients and regulators increasingly recognise the difference. As population testing becomes more common, the bar for what counts as sufficient assurance is quietly rising, and firms that stick exclusively to sampling may find themselves needing to justify that choice, rather than the other way around.

How does population testing lead to continuous auditing?

Once you have built the scripts and analytics needed to test 100% of a population for a point-in-time audit, you are most of the way toward being able to run that same testing on a rolling, continuous basis.

This is where population testing and continuous risk intelligence intersect, because the infrastructure built for one supports the other, so that a control testing script built for an annual audit can, with modest adaptation, become a monthly or even daily monitoring routine, turning a static engagement into an ongoing assurance capability that the client did not have to build twice.

Does population testing replace professional judgement?

No. I want to be careful not to overstate this shift.

Population testing tells you what happened across every transaction, but it does not automatically tell you why, or whether a flagged anomaly represents a genuine control failure, a one-off exception, or perfectly legitimate business activity. Judgement-intensive areas, including complex estimates, related-party transactions and areas requiring interviews and process walkthroughs, still depend heavily on experienced auditors applying professional scepticism.

Population testing is a far more powerful tool for surfacing what deserves attention, but it does not replace the judgement needed to interpret what is found.

What does the transition actually require?

You cannot simply resolve to do more analytics. You need to take the necessary steps to invest in technology, build the data access infrastructure, train existing staff and, in some cases, hire people with different skills from those of traditional auditors.

Firms that treat this as a checkbox, running one analytics script on one engagement and calling it a transformation, will see limited results. The firms that genuinely benefit are the ones building the capability systematically:

  • Standardised scripts that can be reused across engagements
  • A data access playbook that speeds up negotiations with client IT functions
  • A training pipeline that builds these skills into every new hire, rather than relegating them to a small specialist team

Where does that leave sample-based auditing?

To be clear, I do not think sampling is going away entirely, nor should it. There are still engagements where the underlying population is genuinely too small or too unstructured for full-population testing to add meaningful value, and there are judgement-based audit areas where sampling was never really the constraint to begin with.

But for high-volume, structured, transactional data, which is the bread and butter of so much control testing work, the default is shifting, and shifting quickly.

The question every audit and risk advisory function should be asking is not whether to ever use population testing, because that question has largely been answered. The real question, for each engagement, each control and each population of data, is whether sampling is still the right default, or whether it is simply the default we have never gotten around to reconsidering.

What is the path forward?

As a firm, we have started treating population testing as the starting assumption for structured transactional testing, with sampling as the deliberate exception rather than the automatic default. That is a meaningful reversal of how most of us were trained. It requires new tools, new skills and, admittedly, some discomfort in retiring methodologies that have served the profession reliably for a long time.

But the payoff is real: stronger assurance, fewer blind spots, and testing capabilities that lay the groundwork for the kind of continuous, forward-looking risk intelligence our clients are increasingly asking us to deliver.

The transition from sample auditing to population testing is not just a technical advancement of the method but is an important step towards the kind of assurance that the clients, Audit Committees and regulators will begin to expect as the norm instead of an exception. The firms and functions that start developing this competence now will be the ones defining the standard that the rest will have to catch up to.

How SBC applies population testing

Steadfast Business Consulting (SBC) believes that the function performed by internal audit and governance should be transformed from mere compliance exercise to a useful source of risk and control intelligence. SBC’s Financial and Risk Advisory practice applies data analytics across the internal audit process, control testing, Internal Financial Controls compliance under the Companies Act 2013 and forensic audit and investigations, coupled with standard operating procedure development and business process improvement. Rule 13 of the Companies (Accounts) Rules 2014 enables the internal auditor to be external to the company, which is what allows this work to be delivered on a co-sourced basis.

The starting point is not technology but an honest reading of where your risk intelligence currently stands and where it must be headed. If your organisation is questioning whether sampling is still the right default, the SBC internal audit team would be glad to discuss the opportunity.

Frequently Asked Questions

What is full-population testing in audit?

Full-population testing studies all transactions in a specified dataset against predetermined criteria instead of testing a representative sample and extrapolating findings. Automated scripts review the full population and reveal discrepancies, so auditors can focus on identifying anomalies instead of testing regular transactions.

Is population testing better than sampling?

Population testing is generally more advantageous when it comes to high-volume structured transaction data because it removes sampling risk and captures irregularities in clusters. The practicality of sampling is presumed to hold true when the population is small or unstructured, or if the audit inquiry of interest turns on professional judgement rather than the transaction features.

Does population testing satisfy IFC testing requirements?

Section 143(3)(i) of the Companies Act 2013 requires reporting on whether internal financial controls operate effectively. Population testing produces direct evidence of every instance in which a control operated, which is stronger evidence of operating effectiveness than an extrapolation from a sample.

What is sampling risk?

Sampling risk is the possibility that a selected sample does not accurately represent the population from which it was drawn, so that the auditor’s conclusion differs from the conclusion that testing the entire population would have produced. Population testing eliminates it, because no untested portion remains.

What skills do auditors need for data-driven testing?

In order to be successful, auditors must master data extraction skills, possess knowledge of query languages, be able to script for detecting discrepancies as well as use visualisation tools, plus know standard internal control concepts. Statistical theory remains relevant, but the practical bottleneck has moved from sample design to data access and data quality.


Disclaimer: This article is intended for general information and does not constitute professional advice. Statutory positions are stated as at 3 September 2026 and readers should confirm current requirements before acting.

CategoriesAudit

Is Internal Audit Ready for Continuous Risk Intelligence?

Written by Sanjeeb Dey · Statutory references current to the Companies Act, 2013 and applicable IFC requirements.

Quick answer: No, internal audit is not yet ready, and the obstacle is capability rather than law. Section 138 of the Companies Act 2013 prescribes no interval for internal audit, and Rule 13(2) of the Companies (Accounts) Rules 2014 leaves periodicity and methodology to the Audit Committee or the Board. The annual plan is a convention, not a statutory requirement.

The annual audit plan was designed for a world where risks changed slowly. That world no longer exists. For decades internal audit has followed a familiar rhythm: build a risk-based annual plan, present it to the Audit Committee, execute it quarter by quarter and report findings after the fact. It is a model that served organisations well, until the risk landscape stopped waiting for the planning cycle. Cyber threats now emerge overnight, regulatory changes land with little warning and supply chains buckle in days rather than quarters. By the time a traditional audit is scoped, fielded and reported, the risk it was designed to catch may already have evolved into something else entirely.

Having watched the tension between the level of assurance stakeholders want and the speed at which risk actually moves, I set out below ten realities that each audit function must accept in order to shift from the current model of annual planning to a continuous risk intelligence model.

Does Indian law require the internal audit plan to be annual?

No. Most discussions of continuous auditing miss this point. It matters more in India than the global commentary suggests.

According to Section 138(1) of the Companies Act 2013, certain types of companies must appoint an internal auditor who can either be a chartered accountant or cost accountant or any other professional as per the decision of the Board. Section 138(2) empowers the government to specify how the internal audit should be done, but the by-laws drafted by it are silent about the frequency of internal audits.

In contrast, Rule 13(2) of the Companies (Accounts) Rules 2014 states that the internal audit scope, operation, periodicity, and methodology will be decided along with the internal auditor by the Audit Committee or Board.

Periodicity is therefore a governance decision taken by your Audit Committee rather than a constraint imposed by statute. A function that moves to continuous risk intelligence is not straining against the Companies Act but exercising a discretion the Act deliberately left open.

Which companies must appoint an internal auditor?

Rule 13(1) sets the thresholds, all tested against the preceding financial year:

Company type Trigger for mandatory internal audit
Listed company Every listed company, with no threshold
Unlisted public company Paid-up share capital of ₹50 crore or more; or turnover of ₹200 crore or more; or outstanding loans or borrowings from banks or public financial institutions exceeding ₹100 crore at any point; or outstanding deposits of ₹25 crore or more at any point
Private company Turnover of ₹200 crore or more; or outstanding loans or borrowings from banks or public financial institutions exceeding ₹100 crore at any point

The Explanation to Rule 13 also confirms that the internal auditor may or may not be an employee of the company, which is what makes outsourced and co-sourced internal audit models available to Indian companies.

Why is the annual audit plan becoming a historical document?

By design, a risk-based internal audit plan is a snapshot: a best guess at what risks matter, frozen at a single point in time and usually built months before execution even begins. The problem is that risk does not freeze. Thus, a plan that is approved in December might have become obsolete by March when regulations change, a merger occurs, or a system migration takes place.

This does not mean annual planning is obsolete; it means annual planning can no longer be the only mechanism for prioritising audit work. It must instead become a living document, revisited continuously rather than dusted off once a year.

Should risk assessment move from periodic to perpetual?

Yes. The shift is one of supplementation, not replacement.

Most functions still run their formal risk assessment once or twice a year, as a structured exercise involving interviews, surveys and workshops that is thorough but slow. Continuous risk intelligence flips the model: risk data is captured constantly, from operational metrics, control failures, incident logs and external signals, so that risk scores update in near real time rather than annually. The point is not to abandon structured risk assessments but to surround them with an always-on pulse of the organisation’s risk environment.

Why is data analytics no longer optional in internal audit?

Internal audit teams that still rely primarily on sampling and manual testing are structurally incapable of achieving continuous assurance, because there are simply not enough hours in the year.

Analytics changes the equation: instead of testing 30 transactions out of 30,000, audit teams can test all 30,000, flag anomalies automatically and redirect human judgement toward the exceptions that actually matter. This requires investment in tools, in data access and in skills, but the payoff is a level of coverage and speed that manual testing cannot match. The same logic already applies in asset-heavy environments, where a structured approach to fixed asset management produces the transaction-level data that continuous testing depends on.

What is the difference between continuous auditing and continuous monitoring?

These terms get used interchangeably. They should not be. They serve different purposes, sit with different owners and produce different kinds of evidence.

Continuous monitoring Continuous auditing
Owner Typically management Internal audit
Position Embedded into business processes Independent of the process
Purpose Flag control breakdowns as they happen Ongoing independent testing of controls and transactions
Typical method Process-embedded alerts and dashboards Automated audit scripts and audit-owned dashboards

A mature internal audit function does not simply rely on management’s monitoring; it builds its own independent continuous auditing capability, while also learning to treat management’s monitoring data as a risk signal in its own right.

What does the Audit Committee actually want from internal audit?

Expectations from Boards and Audit Committees are changing: though a report on the failures of the past quarter does provide some value, it is ultimately focused on history, whilst Committees now prefer a more forward-thinking perspective to understand better what risks are on the rise, where the controls show signs of weakness, and which additional areas need attention in future.

This is a fundamental repositioning of internal audit’s value proposition, from a rearview mirror to something closer to a radar system. It is also, under Rule 13(2), a conversation the Audit Committee is statutorily entitled to have with you about methodology and periodicity. The expectations placed on that dialogue are already visible in NFRA communication between auditors and Audit Committees, where the regulator has pressed for substantive rather than procedural exchange.

Why does technology risk break the traditional audit cycle?

Cloud migrations, artificial intelligence adoption, third-party integrations and cybersecurity threats evolve on a timeline measured in weeks, not the twelve to eighteen month cycle typical of a traditional IT audit rotation, which means that a system touched once every year or two is effectively audited as a version of itself that may no longer exist when the report is issued. Technology risk, more than almost any other risk category, demands continuous visibility rather than periodic deep dives.

How are talent requirements changing for internal auditors?

Continuous risk intelligence is not merely a technology upgrade. It is a talent transformation. Auditors need to be comfortable with data querying, with visualisation tools and, increasingly, with understanding how artificial intelligence and machine learning models work well enough to audit them, because the traditional profile of an auditor skilled primarily in controls testing and documentation review, however valuable it remains, is no longer sufficient on its own.

Forward-thinking functions now hire data scientists, engineers and analytics specialists alongside traditional auditors, and cross-train existing staff to bridge the gap. The ICAI Internal Audit Standards Board, which issues the Standards on Internal Audit, is the reference point Indian functions should be tracking as this expectation formalises.

Why do data silos block continuous risk intelligence?

Continuous risk intelligence depends on access to live data from ERP systems, GRC platforms, incident management tools, HR systems and external threat intelligence feeds. Yet in many organisations this data lives in disconnected silos, each with its own owner, format and access restrictions, and each requiring a separate negotiation before internal audit can see it.

Building the capability is as much an organisational and political challenge as a technical one. It requires data access agreements, data governance standards, and often the persuasion of other functions that sharing data with internal audit benefits everyone. Our guide to compliance, documentation and risk management sets out how that documentation layer is usually built.

Can third-party risk still be reviewed once a year?

No. Annual vendor risk assessments have become insufficient because of the speed with which third-party risks can emerge, as various incidents such as data breaches at a vendor, geopolitical disruptions and financial distress on the part of a key supplier can occur within a matter of weeks.

Continuous risk intelligence extends monitoring beyond the four walls of the organisation, incorporating real-time signals about vendor financial health, news events and even social sentiment. Many audit functions still lag here, treating third-party risk as a compliance exercise rather than a live risk category demanding ongoing attention.

Is continuous risk intelligence a replacement for traditional audits?

No. This is perhaps the most important point of all. Continuous risk intelligence does not mean abandoning traditional audit engagements. Deep-dive audits, control testing and independent assurance work still matter, especially for risks that require nuanced professional judgement, complex fraud investigation or detailed process walkthroughs that automation cannot fully replicate.

The future is not continuous risk intelligence instead of annual audit plans but a hybrid model. Continuous monitoring and analytics feed a dynamic, frequently updated risk register, which in turn informs a more agile audit plan, one that can pivot mid-year when new information demands it rather than waiting for the next annual cycle.

How mature is your internal audit function?

A simple maturity test for the internal audit process, against which most Indian functions we encounter sit at Level 1 or Level 2.

Level Stage What it looks like
1 Periodic audit Annual risk assessment, sample-based testing, periodic reporting
2 Data-enabled audit Analytics-supported testing, exception reporting, improved audit coverage
3 Continuous assurance Continuous monitoring, automated control testing, risk-based alerts
4 Dynamic risk intelligence Real-time risk sensing, predictive analytics, integrated governance intelligence
5 Strategic risk intelligence Assurance supported by artificial intelligence, continuous risk intelligence, predictive control insights, board-level risk foresight

The dilemma facing the Chief Audit Executives, Chief Financial Officers, and Audit Committees is not if internal audit employs artificial intelligence but how rapidly it can notice a significant swing in risk, how quickly that signal can reach those who can implement change, and how quickly managers will react. Auditors who can answer the question will not necessarily be the auditors who perform the most audits. Rather, those auditors are the ones who combine business acumen with risk knowledge, technological skills, data analytics expertise, and professional judgement to indicate what the control is, how the data determines whether the control works, what signals indicate the risk situation is shifting, and what the management team must do before the risk crystallises. That is the transition from internal audit as an assurance function to internal audit as a risk intelligence partner.

So, is internal audit ready?

Honestly? Not yet. Not universally. Many functions are still investing heavily in traditional planning cycles, manual testing and annual risk assessments, while continuous risk intelligence remains a conference-session aspiration rather than daily practice. But the direction of travel is unmistakable, because organisations generate risk-relevant data faster than ever, stakeholders expect faster insight, and the tools for continuous assurance have never been more accessible.

The functions that will thrive are the ones that start now, by building analytics capabilities, breaking down data silos, upskilling their people, and reshaping their relationship with the Audit Committee from “here is what happened” to “here is what is coming.” The annual audit plan is not disappearing. But it can no longer stand alone. When risks move in real time, assurance cannot remain static. The next generation of internal audit will be defined not by how many audits it completes but by how early it helps the organisation see what is coming.

How SBC works with internal audit functions

Steadfast Business Consulting (SBC) views internal audit and governance not as a mere periodic compliance process but as the development of a dynamic risk and control intelligence function. SBC’s Financial and Risk Advisory practice serves listed and unlisted companies in the areas of internal audit, ongoing internal audit transformation, co-sourcing, control testing, enterprise risk management, SOP development and Internal Financial Controls compliance under the Companies Act 2013. The starting point is not technology but an honest assessment of the current status of the risk intelligence capability of the organisation. If the organisation is now thinking of moving to continuous risk intelligence, the SBC internal audit team would be glad to discuss the opportunity.

Frequently Asked Questions

Is an annual internal audit plan legally required in India?

No. Section 138 of the Companies Act 2013 prescribes no interval for internal audit. Rule 13(2) of the Companies (Accounts) Rules 2014 assigns the scope, functioning, periodicity and methodology to the Audit Committee or the Board, in consultation with the internal auditor. An annual cycle is a professional convention.

Does a listed company need to cross a threshold before internal audit applies?

No. Rule 13(1) of the Companies (Accounts) Rules 2014 applies to every listed company with no threshold at all. The turnover, borrowing, paid-up capital and deposit tests apply only to unlisted public companies and private companies, and each of those tests is measured against the preceding financial year.

Can internal audit rely on management’s monitoring data?

Not as a substitute for its own testing. Continuous monitoring is owned by management and embedded in the process, so it is not independent evidence. A mature function builds its own continuous auditing capability and treats management’s monitoring data as a risk signal in its own right, rather than as assurance.

Can an internal auditor be an employee of the company?

Yes. The Explanation to Rule 13 of the Companies (Accounts) Rules 2014 states expressly that the internal auditor may or may not be an employee of the company. This is what permits outsourced and co-sourced internal audit arrangements in India.

Does continuous risk intelligence replace deep-dive audits?

No. Deep-dive audits remain necessary for risks requiring nuanced professional judgement, complex fraud investigation and detailed process walkthroughs. The realistic model is hybrid, in which continuous analytics feed a dynamic risk register that informs a more agile audit plan.


Disclaimer: This article is intended for general information and does not constitute professional advice. Statutory positions are stated as at 3 September 2026 and readers should confirm current requirements before acting.

CategoriesAudit SBC

PAS-6 Reconciliation of Share Capital Audit Report (Half-Yearly)

PAS-6 Reconciliation of Share Capital Audit Report (Half-Yearly)

Home > PAS-6 Reconciliation of Share Capital Audit Report (Half-Yearly)

PAS-6 Reconciliation of Share Capital Audit Report (Half-Yearly)

Introduction to Form PAS-6

What is Form PAS-6?

A half-yearly audit report filed with the Registrar of Companies (ROC).

Introduced under Rule 9A(8) of Companies (Prospectus and Allotment of Securities) Rules, 2014 in 10th September 2018.

Certified by a practicing Company Secretary (CS) or Chartered Accountant (CA).

Purpose

Verify issued capital against shares in Demat (NSDL/CDSL) and physical form.

Report discrepancies and changes in share capital (e.g., bonus issues, ESOPs, buybacks).

Ensure compliance with mandatory dematerialization for applicable companies.

Ensures transparency in share capital by reconciling issued capital with Demat and physical shares.

Applicability Non-Applicability
Unlisted Public Limited Companies w.e.f. 02nd October 2018. Notification (MCA vide General Circular G.S.R. 376(E). dated 22nd May 2019)
• Nidhi Company
• Government Company
• Wholly Owned Subsidiary Company of Public Company
• Small Private Limited Companies

Timelines for Filing

Companies having ISIN Period for which Form PAS-6 is to be filed Due Date
Before 31st March 2025
April 1 – September 30
29th November
Before 31st March 2025
October 1 – March 31
30th May
After 1st April 2025 and before 30th June 2025
Private Limited Companies (other than small companies) not having ISIN & dematerialize their shares on or before 30th June 2025 must file for the half-year within 60 days ending 30th September 2025.
29th November 2025

Penalties for Non-Compliance

As per Section 450 of the Companies Act, 2013: Company and every officer in default:

₹10,000 and

₹1,000 per day for continuing default (Maximum: ₹2,00,000 for company and ₹50,000 for officer)

What is Dematerialization of Shares?

Dematerialization of shares is the process of converting physical share certificates into electronic form, stored in a digital account with a depository, such as the National Securities Depository Limited (NSDL) or Central Depository Services Limited (CDSL) in India

Aspect Listed Public Companies Unlisted Public Companies Private Companies
Applicability
Mandatory for all listed public companies under SEBI guidelines.
Mandatory for Unlisted public companies under MCA notification G.S.R. 853(E)
Mandatory for certain classes of private companies under MCA notification G.S.R. 802(E).
Regulatory Authority
Securities and Exchange Board of India (SEBI)
Ministry of Corporate Affairs (MCA)
Ministry of Corporate Affairs (MCA)
Threshold Criteria
Not applicable
Not applicable
Private companies (excluding small companies) with: • Share capital ≥ ₹4 crore and
• Turnover ≥ ₹40 crore
Applicability of PAS-6
Mandatory to file PAS-6
Mandatory to file PAS-6
Mandatory to file PAS-6 refer timelines for filing table
Verification & Process Oversight
Done by RTA (Registrar and Transfer Agent) under SEBI supervision
Done by RTA, but under MCA oversight if demat is mandated
Done by RTA, but under MCA oversight if demat is mandated

Important Note:

The deadline for dematerialization of shares by non-small private limited companies has been extended i.e., 30 June 2025. As per MCA General Circular G.S.R. 131(E) dated 12th February 2025, it is now mandatory for all non-small private limited companies to convert their physical share certificates into dematerialized form.

FAQ’s

Q1. What is the ISIN code?

ISIN (International Securities Identification Number) is a unique 12-digit alphanumeric code used to identify securities. Each country’s National Numbering Agency (NNA) issues ISINs. In India,

NSDL issues ISINs for most securities, under SEBI’s direction.

RBI handles ISIN allotment for government securities.

Q2. What is a Small Company?

A Small Company in India, as per the Companies Act, 2013 (Section 2(85)), is a private company with a

Paid-up Share Capital of up to ₹4 crore and Turnover of up to ₹40 crore,

Q3. What is a not a Small Company?

1. A public company.

2. A holding or subsidiary company.

3. A Section 8 (charitable) company.

4, A company governed by a special Act (e.g., banking or insurance).

Q4. Is PAS-6 now applicable to private limited companies?

Yes, w.e.f. 1st July 2025, Non-Small Private Companies are required to file Form PAS-6. Therefore, they need to file for the half year ending September 2025 first time. i.e., before November 2025

Q5. Can a company file PAS-6 without having dematerialized its shares?

Obtaining an ISIN is mandatory as you must mention the ISIN number in the Form PAS-6,but shares can be in physical form.

Q6. Should a company file form PAS-6 for various securities separately?

Yes, as only one ISIN can be inserted in the form PAS-6. Thus, for various types and classes of securities different forms are needed to be furnished. A company must furnish the form PAS-6 for every ISIN issued to it.

Q7. Should PAS-6 be filed if there is no change in shareholding?

Yes, it must be filed for every applicable half-year regardless of changes.

Q8. Can a company issue shares in physical form?

No. As per Rule 9A(1)(a) of the Companies (Prospectus and Allotment of Securities) Rules, 2014, a company is under obligation to issue fresh securities only in the Demat form.