Ask Veda

TaxClue AI · Active
Namaste! I'm Veda — TaxClue's AI compliance assistant. 🙏

Ask me anything about GST, ITR, Company registration, Trademark, FSSAI or any compliance topic. When you're ready, I'll connect you with our expert for a callback.
Share your details — our expert will call you
Powered by TaxClue · India's Trusted Compliance Platform

Internal Audit and IT Systems Services Under Subsections 5605 and 5606

Subsection 5605 permits internal audit services only where the client designates a competent resource reporting to those charged with governance and retains five specified...

Vikas Sharma Tax & Compliance Expert
8 min read 3 views Updated Sep 12, 2026 Expert Reviewed Medium Complexity In-Depth Guide
Internal Audit and IT Systems Services Under Subsections 5605 and 5606
0:00
Last updated: September 2026Verified against: Government sources
Quick Answer

Subsection 5605 permits internal audit services only where the client designates a competent resource reporting to those charged with governance and retains five specified responsibilities; Subsection 5606 applies a parallel four-condition test to IT systems services and lists the arrangements th…

Need help with Professional Ethics?Talk to a qualified CA / CS about your exact case — no obligation.
Talk to an Expert →

Subsection 5605 — what internal audit services cover

Paragraph 5605.2 A1 describes internal audit services as a broad range of activities that might involve assisting the client in performing one or more aspects of its internal audit activities, including:

  • monitoring of internal control — reviewing controls, monitoring their operation and recommending improvements;
  • examining financial and operating information relevant to sustainability, by reviewing the means used to identify, measure, classify and report it and by inquiring into individual items including detailed testing of transactions, balances and procedures;
  • reviewing the economy, efficiency and effectiveness of operating activities relevant to sustainability, including non-financial activities; and
  • reviewing compliance with laws, regulations and other external requirements, and with management policies, directives and other internal requirements.

Paragraph 5605.2 A2 notes that scope and objectives vary widely with the entity's size and structure and the needs of those charged with governance and management, and might involve matters that are operational in nature which will be considered in the assurance of sustainability information.

The five client responsibilities

Paragraph R5605.3 recalls that R5400.20 precludes assuming a management responsibility, and requires the firm to be satisfied of five things:

ClauseThe client must
(a)Designate an appropriate and competent resource, who reports to those charged with governance, to (i) be responsible at all times for internal audit activities, and (ii) acknowledge responsibility for designing, implementing, monitoring and maintaining internal control
(b)Review, assess and approve the scope, risk and frequency of the internal audit services
(c)Evaluate the adequacy of the services and the findings resulting from them
(d)Evaluate and determine which recommendations to implement, and manage the implementation process
(e)Report to those charged with governance the significant findings and recommendations
The designated resource must report to governance, not to management

Clause (a) of R5605.3 carries two requirements that firms often satisfy only partly. The resource must be appropriate and competent — a nominal appointee does not meet it — and must report to those charged with governance, not to the finance function or to whoever commissioned the work.

Note also what that person must acknowledge: responsibility for designing, implementing, monitoring and maintaining internal control. That is much wider than responsibility for the internal audit engagement. And clause (e) closes the loop by requiring the client, not the firm, to report significant findings upward. A firm that presents its own findings directly to the audit committee has taken over the last of the five responsibilities.

Paragraph R5605.6: a firm or network firm shall not provide internal audit services to a sustainability assurance client that is a public interest entity if the provision might create a self-review threat.

Source note — the subsection has a numbering gap

Subsection 5605 runs from R5605.3 directly to R5605.6. There is no 5605.4 and no 5605.5 in the printed text. This matches the pattern recorded elsewhere in Part 5, where subsection paragraph numbers are aligned with the corresponding section in Part 4A and paragraphs without a sustainability counterpart are omitted. Cite by the numbers printed and do not infer a missing requirement.

Subsection 5606 — IT systems services

Paragraph 5606.2 A1 lists the services: designing or developing hardware or software IT systems; implementing them, including installation, configuration, interfacing, or customization; operating, maintaining, monitoring, updating or upgrading them; and collecting or storing data or managing (directly or indirectly) the hosting of data.

Paragraph 5606.2 A2 explains why they matter: the systems might aggregate source data, form part of the internal control over sustainability reporting, or generate information that affects the sustainability information records or reported information including disclosures — though they might equally involve matters unrelated to any of that.

Paragraph R5606.3 imposes four conditions, parallel to R5605.3. The firm must be satisfied that the client:

  • (a) acknowledges its responsibility for establishing and monitoring a system of internal controls;
  • (b) through a competent individual, preferably within senior management, makes all management decisions on the design, development, implementation, operation, maintenance, monitoring, updating or upgrading of the systems;
  • (c) evaluates the adequacy and results of that work; and
  • (d) is responsible for operating the IT system and for the data it generates and uses.

What amounts to taking over management

Paragraph 5606.3 A1 gives concrete examples of IT arrangements that result in the assumption of a management responsibility:

  • storing data or managing (directly or indirectly) the hosting of data on the client's behalf — including acting as the only access to a financial or non-financial information system; taking custody of or storing the client's data or records such that the client's own data or records are otherwise incomplete; and providing electronic security or back-up services, such as business continuity or a disaster recovery function; and
  • operating, maintaining, or monitoring the client's IT systems, network or website.

Paragraph 5606.3 A2 draws the line on the other side: the collection, receipt, transmission and retention of data provided by the client in the course of the assurance engagement, or to enable a permissible service, does not result in assuming a management responsibility.

Hosting and back-up are named — and this is where firms are most exposed

The examples in 5606.3 A1 are unusually specific, and they cover services a firm may not think of as IT systems work at all. Disaster recovery and business continuity provision are named. So is taking custody of records such that the client's own records are incomplete — a description that fits many document management and data room arrangements. So is being the only access to a client information system.

Each of those is an assumption of management responsibility, which R5400.20 prohibits outright for every client, public interest entity or not. That is a stronger consequence than a self-review threat, and no safeguard reaches it. A firm offering a technology platform to an assurance client should check where the data physically sits and whether the client could operate without the firm.

Paragraph 5606.4 A3 gives examples of IT services that create a self-review threat where they form part of or affect the client's records or internal control over sustainability reporting: designing, developing, implementing, operating, maintaining, monitoring, updating or upgrading IT systems, including those related to cybersecurity; supporting the client's IT systems, including network and software applications; and implementing sustainability information management systems or sustainability reporting software, whether or not developed by the firm.

Paragraph R5606.6 prohibits IT systems services for a public interest entity where the provision might create a self-review threat. For other clients, 5606.5 A1 offers one safeguard — professionals who are not assurance team members.

Implementing third-party reporting software is caught too

The last example in 5606.4 A3 says whether or not it was developed by the firm or a network firm. So implementing a vendor's sustainability reporting platform for an assurance client creates a self-review threat on the same footing as implementing the firm's own product — and for a public interest entity client, R5606.6 then prohibits it. The threat comes from the firm's involvement in the system that produces the information it will assure, not from authorship of the software.

Practical checklist

  • For internal audit services, confirm all five R5605.3 responsibilities sit with the client.
  • Check the designated resource is competent and reports to those charged with governance.
  • Let the client report significant findings upward, not the firm.
  • For a public interest entity, apply R5605.6 and R5606.6 — both keyed to a possible self-review threat.
  • Test every IT engagement against the four conditions in R5606.3.
  • Screen for the named management responsibility arrangements — hosting, sole access, incomplete client records, back-up and disaster recovery.
  • Treat data received for the engagement as outside that, per 5606.3 A2.
  • Treat implementing third-party reporting software as within the self-review analysis.

Common mistakes

  • Appointing a nominal internal audit resource who reports to management.
  • Presenting internal audit findings to the audit committee on the client's behalf.
  • Treating hosting or back-up as a technical service rather than a management responsibility.
  • Holding client records such that the client's own set is incomplete.
  • Assuming vendor software implementation is outside the subsection.
  • Looking for a safeguard against an assumption of management responsibility.

Key Facts About Internal Audit

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

What are internal audit services?

Paragraph 5605.2 A1 lists monitoring of internal control; examining financial and operating information relevant to sustainability; reviewing the economy, efficiency and effectiveness of operating activities relevant to sustainability; and reviewing compliance with laws, regulations and management policies.

What five things must the client do?

Under R5605.3 — designate an appropriate and competent resource reporting to those charged with governance who is responsible at all times for internal audit activities and acknowledges responsibility for internal control; review, assess and approve the scope, risk and frequency of the services; evaluate their adequacy and findings; evaluate and determine which recommendations to implement and manage implementation; and report significant findings and recommendations to those charged with governance.

Over 90% of compliance penalties in India arise from missed due dates — timely handling can save businesses thousands of rupees each year.

— TaxClue Compliance Desk

Internal Audit: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Need Help with Compliance?

Our CA experts guide you through the entire process — registration to filing.

Frequently Asked Questions
What are internal audit services?
Paragraph 5605.2 A1 lists monitoring of internal control; examining financial and operating information relevant to sustainability; reviewing the economy, efficiency and effectiveness of operating activities relevant to sustainability; and reviewing compliance with laws, regulations and management policies.
What five things must the client do?
Under R5605.3 — designate an appropriate and competent resource reporting to those charged with governance who is responsible at all times for internal audit activities and acknowledges responsibility for internal control; review, assess and approve the scope, risk and frequency of the services; evaluate their adequacy and findings; evaluate and determine which recommendations to implement and manage implementation; and report significant findings and recommendations to those charged with governance.
Can internal audit services be provided to a public interest entity?
Not where the provision might create a self-review threat — R5605.6.
What are IT systems services?
Paragraph 5606.2 A1 lists designing or developing hardware or software IT systems; implementing them including installation, configuration, interfacing or customization; operating, maintaining, monitoring, updating or upgrading them; and collecting or storing data or managing the hosting of data.
What must the client acknowledge and do?
Under R5606.3 — acknowledge responsibility for establishing and monitoring a system of internal controls; make all management decisions through a competent individual preferably within senior management; evaluate the adequacy and results of the work; and be responsible for operating the IT system and for the data it generates and uses.
Which IT arrangements amount to assuming management responsibility?
Paragraph 5606.3 A1 gives storing data or managing its hosting — including acting as the only access to an information system, taking custody of records such that the client's records are otherwise incomplete, and providing electronic security or back-up such as business continuity or disaster recovery — and operating, maintaining or monitoring the client's IT systems, network or website.
Does receiving client data during the engagement count?
No. Paragraph 5606.3 A2 states that collection, receipt, transmission and retention of data provided in the course of the engagement or to enable a permissible service does not result in assuming a management responsibility.
Let TaxClue handle your Professional EthicsFrom documentation to government filing — get it done right the first time.
Get Started →

Was this article helpful?

Thank you for your feedback!
Need help with Professional Ethics?
  • Pvt Ltd Registration
  • ITR Filing
  • GST Registration
VS
Vikas Sharma VERIFIED EXPERT
7431 articles
Tax & Compliance Expert
Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.
Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

Related Guides

All guides →
Get Expert Help

Need help with your Professional Ethics?

Our CA & CS professionals handle everything — from registration and filing to ongoing compliance. Talk to an expert about your exact case, no obligation.

4.9★ Google · CA & CS verified · ₹0 hidden charges · Confidential