The first statutory audit of a company is often the first time a founder sees a chartered accountant sit across the table for more than a filing. There is paperwork, there are questions, and there is a report at the end that goes to the Registrar and the bank. For most owners new to the process, the unfamiliarity is the hardest part — not the audit itself.
This note walks through what a statutory audit actually is, what happens at each stage, and the small handful of things that, if you get them right, make the experience straightforward.
What a statutory audit is (and isn't)
A statutory audit is an independent examination of a company's financial statements by a chartered accountant in practice, leading to a written opinion on whether those statements give a true and fair view. For companies in India, it is mandated by the Companies Act, 2013. The auditor is appointed by the shareholders and reports to them — not to management.
It is not a fraud investigation, a tax assessment, or a management consulting exercise. The auditor's job is to form a reasonable opinion on the financial statements using the standards on auditing issued by the ICAI.
Stage one: the engagement letter
Before any work begins, the auditor sends an engagement letter. This document records the scope of the audit, the reporting framework (in most cases, Schedule III of the Companies Act and Accounting Standards or Ind AS), the responsibilities of management and those charged with governance, and the form of the audit report.
Read it carefully and have it signed by an authorised person. The engagement letter is the one document that defines what the auditor will and will not do, and it sets expectations on access to records, timing, and deliverables.
Stage two: planning and risk assessment
Once the engagement is accepted, the audit team builds an understanding of your business. This includes the nature of operations, the industry you sit in, the regulatory framework you operate under, and the internal controls you have in place. The output of this stage is an audit plan that identifies the areas of higher risk and decides how the team will respond to them.
Expect a request for the prior year's financials, the trial balance, organisation chart, list of bank accounts, sample contracts, and a short discussion with the finance team. The better prepared this conversation is, the smoother the rest of the audit goes.
Stage three: fieldwork
Fieldwork is the substantive part of the audit. The team performs tests of controls and tests of details on the line items in the financial statements. The depth depends on the risk assessment — high-risk areas get more attention; routine areas get less.
Typical procedures include:
- Vouching — tracing entries in the books back to underlying invoices, contracts, or other source documents.
- Sampling — testing a representative selection of transactions rather than every single one. Samples are chosen to give the auditor enough evidence to draw a conclusion about the whole population.
- Confirmations — writing to banks, debtors, and creditors to confirm balances independently.
- Physical verification — observing inventory counts, inspecting fixed assets, checking cash on hand at the year end.
- Analytical review — comparing this year's numbers to last year, to budget, and to industry norms to spot anomalies that warrant a deeper look.
Stage four: reporting
After fieldwork, the auditor summarises the findings, discusses any proposed adjustments with management, and finalises the financial statements. Three deliverables typically come out of this stage:
- The audit report — the auditor's opinion, in the format prescribed by the SAs and the Companies Act.
- The CARO report — additional reporting on matters specified by the Companies (Auditor's Report) Order, where applicable.
- A management letter — observations on internal controls and process weaknesses that the auditor noticed but that do not affect the financial statements.
Common findings worth knowing about
The same handful of issues come up across most first-time audits. Knowing them in advance lets you fix them before the auditor flags them:
- Bank reconciliations that are out of date, or that have old unreconciled items carried forward without explanation.
- Inventory valuation that does not match the policy on the face of the financials — FIFO in the notes, weighted average in practice.
- Related-party transactions that are real but not disclosed, or disclosed without the terms being clear.
- Fixed asset registers that do not reconcile to the general ledger.
- Statutory dues — TDS, GST, PF, ESI — paid late, with the interest exposure not recorded in the books.
Stage five: partner sign-off and filing
Once the financial statements and audit report are finalised, the engagement partner signs the audit report. The audited financials are then placed before the Board, adopted at the AGM, and filed with the Registrar of Companies through the AOC-4 form. The audit report itself is filed alongside.
For most private companies with a March year end, this entire cycle — from engagement letter to ROC filing — runs from April to October. The fieldwork itself usually takes two to four weeks for a small company; longer for groups, listed entities, or businesses with complex operations.
What good looks like
A well-run statutory audit is unremarkable from the inside. Records are ready, questions are answered the day they are asked, adjustments are discussed openly, and the report goes out on time. The value comes not just from the opinion at the end but from the discipline the process builds inside the finance function over the years that the same auditor signs off the books.
This article is for educational purposes and is not professional advice. Consult a qualified professional for advice on your specific situation.
Written by
CA Anil Arora · Founder, Anil Arora & Co.
42 years of practice. Based in Lucknow, Uttar Pradesh.

