Skip to main content
How-To · 10 min read

Prevention Controls for Manual Reconciliation: Templates, Cutoffs, Approval Matrices, and Training

A detection control catches a reconciliation failure after it has happened; a prevention control stops the failure from happening in the first place. This method article publishes seven prevention controls Indian finance teams can operate without software — ERP field enforcement, cut-off calendars, sign-off matrices with Rs threshold-based escalation, quarterly training with signed acknowledgement, vendor master data discipline with quarterly re-validation, and a portal-cadence rhythm keyed to TRACES on the 7th, Form 168 quarterly, IMS at day 15, and DRC-01B within 24 hours — each mapped to the failure class it addresses and the statutory anchor that makes it defensible under Section 143(3)(i) ICFR testing.

Terra Insight
Terra Insight Editorial Team Reconciliation Infrastructure

Content authored by practitioners with experience at Amazon India, Intuit QuickBooks, and the Tata Group. Meet the team →

Published 4 August 2026
Domain expertise
TDS Reconciliation GST Input Credit Platform Settlements NACH Batch Matching Bank Reconciliation Form 26AS Matching ERP Integrations Enterprise Finance Ops
Knowledge Card
Problem

Manual reconciliation processes in Indian finance teams typically carry heavy detection controls — monthly tick-and-tie, quarterly peer review, year-end statutory audit — but under-invest in prevention. The result is that every failure mode has to be worked after the fact, the reviewer capacity is spent on catching errors rather than eliminating their causes, and the residual risk on a High Action Priority row keeps re-appearing quarter after quarter because the underlying prevention layer is either absent or informal. A Section 206AA missing-PAN deduction fires because vendor onboarding did not validate PAN; a Rule 36(4) ITC mismatch fires because a supplier's GSTIN status was not re-checked mid-year; a DRC-01B seven-day reply window slips because internal routing burned five of the seven days; a Section 16(4) permanent ITC loss lands because the supplier follow-up cadence was informal. The pattern across all four failures is the same — the prevention layer was undesigned, so the detection layer bore the entire weight of the control, and the detection layer alone cannot carry Severity 9 or 10 exposures.

How It's Resolved

Publish seven prevention controls, each anchored to a failure class it addresses and a statutory consequence it defends against. ERP field-level enforcement — GSTIN, PAN, HSN, SAC, and Section code as mandatory fields with hard validation gates — prevents master-data errors that cascade into Rule 36(4) mismatches, Section 206AA higher-rate deductions, and cross-era Section 393 payment code confusion. Cut-off calendars on a 20-day monthly cadence with named owners and deliverables prevent period-drift errors that trigger DRC-01B intimations. Sign-off matrices tied to Rs threshold bands prevent unauthorised close through the Rs 5 lakh, Rs 25 lakh, and Rs 1 crore approval hierarchy layers, with sign-off evidence retained under Section 128(5) for seven years. Quarterly training with signed acknowledgement prevents knowledge-gap errors as the analyst pool rotates. Vendor master data discipline with quarterly re-validation prevents supplier-state drift on GSTIN, PAN, and Section applicability. Portal cadence discipline — TRACES on the 7th of the month, Form 168 quarterly pull, IMS action within 15 days of GSTR-2B availability, DRC-01B 24-hour internal triage — prevents portal-timing errors that convert reconciliation windows into panic replies. Each control is written, owned, cadenced, and evidenced, so the Section 143(3)(i) ICFR opinion can test both design and operation.

Configuration

One reconciliation prevention control document per stream, sitting alongside the reconciliation control plan template as the design-side pair. ERP field-level rules configured as validation gates in the invoice creation and vendor onboarding workflows; overrides require a written exception log with controller sign-off. Cut-off calendar published on day 25 of the prior month with a named preparer, reviewer, and sign-off authority per sub-cadence. Sign-off matrix published in the reconciliation policy document with the illustrative Rs 5 lakh, Rs 25 lakh, and Rs 1 crore bands calibrated to the enterprise's transaction profile. Quarterly training curriculum reviewed by the controller and the tax head; acknowledgement receipts retained under Section 128(5) for seven years. Vendor master re-validation cycle scripted as a quarterly batch job with GSTN and TRACES lookups; exception list routed to the vendor onboarding owner for correction. Portal cadence discipline enforced through calendar reminders and named owners; SLA breaches escalated to the controller.

Output

A prevention layer that reduces the Occurrence rating on High Action Priority rows by one to two notches on the anchored SOD scale, freeing detection-layer capacity to work the residual failures the prevention layer misses. A defensible design-side evidence base for the Section 143(3)(i) ICFR opinion and the CARO 2020 audit report. A close cycle where the DRC-01B seven-day reply window carries six clear working days rather than one panic day; a Section 16(4) 30 November cutoff that is walked as a rolling supplier cadence rather than a year-end scramble; a Section 206AA missing-PAN exposure that cannot be created because the ERP will not book the invoice without a validated PAN; and a Section 194Q Rs 50 lakh aggregate trigger that fires automatically the moment cumulative purchases from a vendor cross the threshold, without a manual computation the reviewer would forget.

Every reconciliation risk register carries two kinds of controls — the ones that catch failures after they happen, and the ones that stop failures from happening in the first place. Indian finance teams typically invest heavily in the first kind: the monthly tick-and-tie, the quarterly peer review, the year-end statutory audit checklist. The second kind — the prevention layer — is usually informal, undocumented, or absent, and the pattern shows up on every quarterly walkthrough of the register. A Section 206AA missing-PAN higher-rate deduction fires because vendor onboarding did not validate PAN. A Rule 36(4) input tax credit mismatch fires because a supplier’s GSTIN status was not re-checked mid-year. A DRC-01B seven-day reply window slips because the notice landed in a general inbox and burned five of the seven days on internal routing. A Section 16(4) permanent ITC loss lands on the 30 November cutoff because the supplier follow-up cadence was informal.

The failure pattern in every case is the same. The prevention layer was undesigned, so the detection layer had to carry the entire weight of the control, and the detection layer alone cannot carry a Severity 9 or Severity 10 exposure on the anchored SOD rating scale — it can only catch what it can walk through, and on a reconciliation stream at scale, that ceiling is lower than the enterprise thinks. This method article publishes the seven prevention controls Indian finance teams can operate without software, each anchored to the failure class it addresses and the statutory consequence it defends against.

Why generic prevention controls do not fit Indian reconciliation

Textbook prevention controls — segregation of duties, four-eyes review, standard operating procedures — are designed for a general accounting environment where the failure modes are broad and the consequences are book-side misstatement. Indian reconciliation runs against a specific portal timing calendar, a specific set of statutory consequences with hard deadlines, and a specific pattern of counterparty behaviour that determines whether a reconciliation succeeds or fails. Generic “SOD” does not tell an AR analyst that the Section 194Q Rs 50 lakh aggregate trigger is a running-total computation the ERP has to enforce because no reviewer can carry it manually across two hundred vendors. Generic “four-eyes review” does not tell the indirect tax analyst that the IMS default-accept path fires after 15 days regardless of whether the two eyes actually looked. Generic “SOP with quarterly refresh” does not tell the tax head that the cross-era Section 393 payment code migration on 1 April 2026 requires a training refresh keyed to the FY 2026-27 and FY 2027-28 correction windows.

The prevention layer for Indian reconciliation has to be anchored to the same statutes and portal cadences that the reconciliation control plan template uses on the Severity axis of the register. Each of the seven prevention controls below is anchored that way.

The seven prevention controls

1. ERP field-level enforcement

The invoice creation and vendor onboarding workflows in the ERP carry mandatory fields that cannot be overridden without a written exception log signed by the controller. GSTIN is mandatory on every supplier record and every invoice line. PAN is mandatory on every vendor master — the Section 206AA guide walks through how a missing PAN converts a TDS deduction into the higher of the applicable Section rate or 20 percent, and the ERP validation gate at onboarding is the prevention control that keeps the higher-rate deduction from ever being computed. HSN codes are mandatory on goods lines and SAC codes on services lines, keyed to the Chart of Accounts. The payment code — code 1005 for Section 194J professional fees, code 1031 for Section 194Q buyer’s TDS on aggregate purchases above Rs 50 lakh, code 1057 for Section 195 non-resident payments, and so on across the 1001-1092 Section 393 code range live from 1 April 2026 — is a mandatory field on the deduction transaction, with the code list restricted at posting time to the codes valid for the vendor’s supply type.

Failure class addressed. Master-data errors — the class that cascades into Rule 36(4) mismatches, Section 206AA higher-rate exposures, Section 194Q trigger misses, and cross-era code confusion.

2. Cut-off calendars on a 20-day cadence

The reconciliation cut-off calendar is published on day 25 of the prior month for the coming close. It carries five sub-cadences aligned to the monthly close reconciliation playbook: days 1 to 5 for bank reconciliation, days 6 to 10 for the TDS statement inputs, days 11 to 15 for the GSTR-2B ITC reconciliation once the portal makes the statement available on day 14, days 16 to 20 for the GSTR-1 versus GSTR-3B preparation before the GSTR-3B filing on day 20, day 22, or day 24 depending on the state and turnover band, and day 20 onward for the closing-book journal entries. Every sub-cadence carries a named preparer, a named reviewer, a sign-off authority, and a deliverable artefact.

Failure class addressed. Period-drift errors — the class that produces DRC-01B intimations when GSTR-1 declares a liability in one month but GSTR-3B pays it in the next, and the class that produces cross-era timing confusion when a payment straddles the FY 2025-26 to FY 2026-27 code migration boundary.

3. Sign-off matrix — three-tier threshold-based approval

The sign-off matrix distinguishes preparer, reviewer, and sign-off authority for every reconciliation deliverable, with escalation thresholds tied to Rs bands. The illustrative bands — every enterprise calibrates them to its transaction profile and its statutory audit materiality anchor — sit at Rs 5 lakh, Rs 25 lakh, and Rs 1 crore. A variance up to Rs 5 lakh clears on the reviewer’s sign-off. A variance between Rs 5 lakh and Rs 25 lakh escalates to the controller. A variance between Rs 25 lakh and Rs 1 crore escalates to the CFO. A variance above Rs 1 crore requires audit-committee visibility before it is accepted or cleared. Sign-off evidence — signed working papers, screenshots with URL and timestamp, ERP reports — is retained under Section 128(5) of the Companies Act 2013 for the mandated seven years.

Failure class addressed. Unauthorised close — the class where a material variance is accepted-and-cleared by a preparer alone without independent review, which becomes an ICFR material weakness observation under Section 143(3)(i) testing.

4. Approval hierarchy for statutory filings and payments

Above the sign-off matrix sits the approval hierarchy for the filings and payments themselves. Every GSTR-3B liability payment carries a named payer, a named reviewer, and a sign-off authority above the reviewer. Every Form 26Q or Form 27Q filing carries the same three-tier hierarchy. Every DRC-03 payment on a DRC-01B or DRC-01C reconciliation reply carries the same. The illustrative bands align to the sign-off matrix — a filing below Rs 5 lakh in liability clears on the reviewer’s sign-off, a filing between Rs 5 lakh and Rs 25 lakh clears on the controller’s sign-off, a filing above Rs 25 lakh requires the CFO. The hierarchy is documented in the reconciliation policy and referenced in the statutory audit reconciliation checklist that the auditor works against at year-end.

Failure class addressed. Filing and payment errors that fire because the preparer submitted directly without a review layer.

5. Quarterly training with signed acknowledgement

The reconciliation team runs a quarterly training refresh keyed to the actual regulatory calendar. In Q4 FY 2025-26 the refresh covered the Section 393 payment code migration going live on 1 April 2026. In Q1 FY 2026-27 the refresh will cover Form 168 quarterly filing cadence going live in April 2026 and the cross-era correction window mechanics on the FY 2025-26 residual filings. Every analyst in the reconciliation team signs an acknowledgement receipt at the end of the training session; the receipts are retained under Section 128(5) for the mandated seven years. New analysts run through the refresh within 30 days of joining as an onboarding requirement. The training curriculum itself is reviewed by the controller and the tax head before each session.

Failure class addressed. Knowledge-gap errors that fire when an analyst runs a reconciliation against a stale mental model — most commonly on portal-side rule changes like the Invoice Management System introduced in October 2024 or the Section 393 payment code migration on 1 April 2026.

6. Vendor master data discipline with quarterly re-validation

A vendor master row carries seven fields at onboarding — legal name, PAN, GSTIN, supply type, TDS-applicable Section, TCS-applicable Section, and MSME-registered indicator (for the Section 43B(h) 45-day disallowance check). The onboarding validation runs against the GSTN and TRACES portals to confirm PAN validity, GSTIN active status, and supply type. The quarterly re-validation cycle re-runs the same portal lookups against the entire vendor master, produces an exception list of vendors whose state changed (GSTIN moved from Active to Suspended or Cancelled; PAN moved to inoperative; supply type changed on composition-scheme threshold cross), and routes the exception list to the vendor onboarding owner for correction before the next quarterly reconciliation cycle. The re-validation is a scriptable batch job — VLOOKUPs in Excel against the enterprise’s vendor master with the GSTN and TRACES portal API responses as the reference.

Failure class addressed. Supplier-state drift — the class that produces Rule 37A cascading ITC reversals when a supplier’s GSTIN is cancelled mid-year, and the class that produces Section 194Q trigger misses when a vendor crosses the Rs 50 lakh aggregate purchase threshold and the TDS section indicator was not refreshed.

7. Portal cadence discipline

The portal cadence carries four hard rhythms. The TRACES portal pull for TDS credits runs on the 7th of every month, timed to the day after the deductor’s TDS payment deadline, and produces the deductor’s own credit-side view for reconciliation against Form 26AS on the deductee side. The Form 168 quarterly pull runs 15 days after each quarter-end, timed to the CPC-TDS processing window for the new quarterly statement structure that goes live in April 2026. The IMS action window runs within 15 days of the GSTR-2B statement becoming available on the 14th of the month, keyed to the default-accept path that fires if the reviewer does not act; the calendar reminder fires on day 21 with a hard stop on day 28. The DRC-01B triage SLA runs within 24 hours of the notice landing on the GSTN portal — the notice itself carries a 7-day reply window under Rule 88C, and a 24-hour internal SLA compresses the routing time so the preparer has six clear working days to do the reconciliation and reply work.

Failure class addressed. Portal-timing errors — the class that converts a reconciliation window into a panic reply, and the class that converts a 15-day IMS action window into a default-accept exposure the Section 74 fraud recovery framework can then act on.

Worked case 1 — the missing PAN that would not have been created

A mid-market Indian manufacturer onboards 47 new vendors in Q2 FY 2026-27 as part of a supplier diversification programme. The onboarding workflow runs through the ERP with the field-level enforcement layer switched on — PAN mandatory, GSTIN mandatory, supply type mandatory, applicable Section indicator mandatory. Three vendors submit incomplete onboarding forms without PAN. The ERP validation gate blocks the vendor master creation, the onboarding owner escalates to the procurement head, and the three vendors are asked to submit PAN before their purchase orders can be raised.

Under the prevention layer, no invoice is booked, no purchase order is raised, and no TDS deduction is computed. Under a hypothetical no-prevention baseline, the three vendors would have been onboarded with the PAN field left blank, the first invoice from each would have been booked, and Section 206AA would have fired at the higher of the applicable Section rate or 20 percent on the TDS deduction. On aggregate Rs 18 lakh of first-quarter deductions across the three vendors, the higher-rate deduction produces an over-withholding of approximately Rs 3.6 lakh, plus the compliance overhead of Form 26Q correction filings once the PAN is subsequently supplied. The prevention control paid for itself on the first invoice that would have been booked without a PAN.

Worked case 2 — the DRC-01B that had time to be worked

A pharmaceutical distributor’s GSTR-1 filing for month M reports a liability of Rs 47.3 lakh; the GSTR-3B filing for the same month pays a liability of Rs 44.9 lakh, a difference of Rs 2.4 lakh driven by a credit note that was issued in GSTR-1 in month M but should have been reflected in GSTR-3B in month M+1 under the credit note timing rule. The DRC-01B intimation lands on day 3 of month M+2 with a 7-day reply window under Rule 88C.

Under the 24-hour triage SLA, the notice is acknowledged in the indirect tax analyst’s queue within 3 hours of landing on the GSTN portal, the working paper is opened on day 3 itself, the specific credit note driving the flagged difference is isolated on day 4, and the reply is routed through the sign-off matrix on day 5 with the controller’s sign-off on the DRC-03 payment for the differential and the interest under Section 50. The reply is filed on day 6, one clear working day inside the 7-day statutory window. Under a hypothetical no-triage baseline where the notice sits in a general inbox until day 5, the same work is compressed into two panic days and the reply either goes in late (with Section 79 recovery risk) or goes in incomplete (with a follow-up DRC-01B on the same period).

Worked case 3 — the Section 16(4) supplier who was chased in time

A ₹300 crore GST-eligible purchase base runs against a supplier base of 240 vendors. The portal cadence discipline pulls GSTR-2B on the 14th of every month, runs the vendor master re-validation on the last day of each quarter, and maintains a per-vendor filing-status log against GSTR-1. In September 2026, the log flags four vendors whose GSTR-1 filings for July and August have not yet been made. The prevention control fires the vendor follow-up cadence — the vendor key account managers are notified on 15 September, the vendors are contacted with a reminder on 22 September and 5 October, and three of the four vendors file GSTR-1 for the two months by 25 October. The fourth vendor’s aggregate exposure of Rs 3.4 lakh is escalated to the controller on 5 November and routed to the audit committee as a High Action Priority residual risk before the 30 November Section 16(4) cutoff.

Under a hypothetical no-prevention baseline where the supplier follow-up cadence is informal, the same four vendors are noticed for the first time in mid-November when the year-end reconciliation begins. The three cooperative vendors do not have time to file the two months of GSTR-1 before 30 November — CPC-GST processing and vendor-side accountant availability during the year-end window make a two-week turnaround unrealistic. Rs 12 lakh in aggregate ITC across the four vendors is permanently lost on 1 December.

How the seven prevention controls plug into the wider methodology

The seven controls sit alongside the reconciliation control plan template as the design-side pair of the register. Every High Action Priority row on the register carries at least one prevention control (from this list) plus at least one detection control (from the manual detection techniques article in this same wave). The prevention control lowers the Occurrence rating on the anchored SOD scale; the detection control lowers the Detection rating. Together they drive the Action Priority ranking through the severity-first framework that Terra Insight’s methodology adopts over multiplicative Risk Priority Numbers.

The cause of every failure mode traces to one of the 6P cause taxonomy branches — People, Policy, Process, Portal, Period, Partner — and every prevention control in this list is calibrated to reduce the failure rate on the branches it maps to. The training control (Control 5) addresses People-cause failures. The ERP field enforcement (Control 1), the cut-off calendar (Control 2), and the sign-off matrix (Control 3) address Policy and Process causes. The portal cadence discipline (Control 7) addresses Portal causes. The cut-off calendar again addresses Period causes on cross-era and quarter-boundary drift. The vendor master data discipline (Control 6) addresses Partner causes on supplier-state drift.

On the operational side, the seven prevention controls run against the same close-cycle calendar that the monthly close reconciliation playbook sequences, the TDS runbook on monthly and quarterly cadence operates on the TRACES cadence, the GSTR-2B ITC runbook on days 11 to 15 operates against the day-14 portal availability, and the three-way ITC reconciliation Excel workbook provides the working paper the sign-off matrix routes for review.

When manual prevention controls stop scaling

Below a certain volume, the manual prevention layer sustains the discipline. The ERP field enforcement scales indefinitely because the ERP is doing the enforcement. The cut-off calendar scales indefinitely because the calendar is a written artefact. The sign-off matrix scales with the number of sign-off events, which is a linear function of variance count. The training programme scales with the analyst count.

The four controls that break at scale are the portal cadence discipline, the vendor master re-validation cycle, the supplier follow-up cadence for the Section 16(4) queue, and the IMS action window. Each of these is a rolling operational rhythm that has to fire on a specific day against a specific portal state — the TRACES pull on the 7th, the IMS action by day 28, the vendor follow-up cadence throughout October and November, the DRC-01B triage within 24 hours. Above roughly 200 vendors, or above roughly 3,000 purchase invoices per month, or on a multi-GSTIN structure with more than three GSTINs, the reviewer capacity required to run all four cadences in parallel across the close window exceeds what a finance team member can sustain — and the prevention layer starts to slip on precisely the controls that have the highest Severity anchors on the reconciliation control plan.

Terra Insight’s reconciliation software surface carries the continuously-refreshed prevention and detection layers that the anchored register demands on High Action Priority rows — the GST reconciliation software closes the Section 16(4) supplier queue on a daily-refreshed cadence, the TDS reconciliation software runs the vendor master re-validation and the cross-era Section 393 payment code queue as a machine-enforced layer, and the monthly close reconciliation playbook sequences the manual close cycle that a finance team runs alongside those layers on the same 20-day cadence.

Where this fits

Frequently Asked Questions

What is the difference between a prevention control and a detection control in a reconciliation risk register?

A prevention control reduces the likelihood that a failure mode fires at all — a mandatory GSTIN field on invoice creation in the ERP prevents an unregistered supplier’s invoice from being booked, so the downstream Rule 36(4) mismatch never occurs. A detection control catches a failure that has already happened but before it reaches the counterparty, the tax authority, or the statutory auditor — a monthly tick-and-tie of the purchase register against GSTR-2B catches the mismatch after the invoice was booked without a GSTIN. On the anchored SOD scale, prevention controls lower the Occurrence rating, while detection controls lower the Detection rating. The two are complementary — a High Action Priority row on the register almost always requires both a prevention layer that keeps the failure rate down and a detection layer that catches the residual failures the prevention layer misses. A row with only a prevention control is fragile because the prevention control can be circumvented; a row with only a detection control is expensive because every failure has to be worked after the fact.

How does a Rs 5 lakh / Rs 25 lakh / Rs 1 crore approval hierarchy defend against reconciliation risk under Section 143(3)(i)?

The approval hierarchy is the design-side evidence that no single individual can close a material variance without independent review. A Rs 5 lakh threshold sign-off by the controller, a Rs 25 lakh threshold sign-off by the CFO, and a Rs 1 crore threshold sign-off by the audit committee (illustrative bands — every enterprise calibrates its own thresholds to its transaction profile and materiality anchor) mean that any reconciliation variance above the smallest band cannot be accepted-and-cleared by the preparer alone. The Section 143(3)(i) ICFR opinion tests the design of the control by asking whether the hierarchy is written, whether the thresholds are calibrated to the enterprise’s transaction profile, and whether the sign-off evidence is retained under Section 128(5) of the Companies Act for the mandated seven-year period. The opinion tests the operation of the control by sampling variances against the sign-off log — a Rs 27 lakh variance cleared without a CFO signature is an operating-effectiveness failure that becomes an ICFR material weakness observation.

Why does vendor master data discipline require quarterly re-validation rather than a one-time onboarding check?

A vendor’s GSTIN status, PAN status, supply type, and applicable withholding section are not static properties. A supplier’s GSTIN can move from Active to Suspended if the supplier fails to file GSTR-3B for two consecutive periods, and from Suspended to Cancelled if the default persists. A supplier’s PAN can become inoperative if it is not linked to Aadhaar under the applicable notification. A supplier’s supply type can change if the supplier crosses the composition-scheme turnover threshold. A one-time onboarding check captures the state on the day the vendor was added; a quarterly re-validation cycle refreshes the state before the vendor’s next quarterly ITC or TDS reconciliation runs, so a supplier whose GSTIN was cancelled in Q1 does not cause a Rule 37A cascading ITC reversal in Q2. The re-validation itself is a bulk portal lookup on the GSTN and the TDS TRACES portal, scriptable in Excel VLOOKUPs against the enterprise’s vendor master, and the output feeds directly into the exception list the reviewer works next quarter.

What is the case for a 24-hour DRC-01B triage window when the statutory reply period is seven days?

The seven-day DRC-01B reply window under Rule 88C is the outer statutory boundary. Every day of it that the enterprise burns on internal routing — the notice landing in a general inbox, waiting for the indirect tax analyst to notice, waiting for the analyst to route it to the preparer, waiting for the preparer to open the working paper — is a day removed from the reconciliation and reply work itself. A 24-hour triage SLA compresses the routing time so the preparer has six clear working days to do the actual work: pull the GSTR-1 versus GSTR-3B variance schedule, isolate the specific invoices driving the flagged difference, decide whether to pay through DRC-03 or reply with reconciliation, and route the response through the sign-off matrix. The DRC-01B reply guide documents the seven-day mechanics; the 24-hour triage is the internal SLA that keeps the seven days workable. Enterprises without the triage discipline routinely reply on day seven at 4pm and pay penalties for reconciliation errors they could have found on day two.

How does a 20-day cut-off calendar cadence relate to the Playbook operational close rhythm?

The 20-day cadence is not a single cut-off event — it is a rolling operational rhythm across the close window. Days 1 to 5 close the bank reconciliation on the previous month’s transactions; days 6 to 10 close the TDS statement inputs for the deductions made that month; days 11 to 15 close the GSTR-2B ITC reconciliation once the portal makes the statement available on the 14th; days 16 to 20 close the GSTR-1 preparation and the GSTR-3B liability workbook before the GSTR-3B filing on day 20 or day 22 or day 24 depending on the state and turnover band. The prevention-side calendar publishes each of these sub-cadences with a named owner and a named deliverable, and the monthly close reconciliation playbook sequences the runbooks that operate against each cadence. The prevention control is the published calendar itself with signed analyst acknowledgement; the operational execution is what the Playbook cluster’s five stream runbooks then walk through step by step.

Terra Insight
Terra Insight Editorial Team Reconciliation Infrastructure

Content authored by practitioners with experience at Amazon India, Intuit QuickBooks, and the Tata Group. Meet the team →

Published 4 August 2026
Domain expertise
TDS Reconciliation GST Input Credit Platform Settlements NACH Batch Matching Bank Reconciliation Form 26AS Matching ERP Integrations Enterprise Finance Ops
Primary reference: Ministry of Corporate Affairs — for the Companies Act 2013 auditor's report requirements under Section 143(3)(i) on Internal Financial Controls over Financial Reporting and the CARO 2020 clauses that read directly against the prevention controls in this article..
Primary sources cited
Last reviewed against sources on 4 August 2026
  • Section 143(3)(i), Companies Act 2013 — The auditor's report shall state whether the company has adequate internal financial controls with reference to financial statements in place and the operating effectiveness of such controls. Prevention controls — the ERP field constraints, the sign-off matrix, the cut-off calendar, the training programme — are the design-side evidence the statutory auditor tests for adequacy. A reconciliation prevention control without a documented anchor to a statutory consequence is a control the auditor cannot rate for adequacy, and an ICFR opinion on design effectiveness is what a Section 143(3)(i) report ultimately turns on.
  • Section 206AA, Income-tax Act 1961 (retained in Income-tax Act 2025) — Notwithstanding anything contained in any other provision of this Act, any person entitled to receive any sum or income on which tax is deductible at source shall furnish his Permanent Account Number to the person responsible for deducting such tax, failing which tax shall be deducted at the higher of the rate specified in the relevant provision of this Act, the rate or rates in force, or twenty percent. Section 206AA converts a missing-PAN failure at vendor onboarding into a deduction at the higher of the applicable Section rate or twenty percent, which is why vendor master PAN validation is a prevention control the ERP field-level enforcement layer must operate before any invoice is booked, not a downstream reconciliation catch.
  • Section 194Q, Income-tax Act 1961 (retained in Income-tax Act 2025) — Any person, being a buyer who is responsible for paying any sum to any resident for purchase of any goods of the value or aggregate of such value exceeding fifty lakh rupees in any previous year, shall, at the time of credit of such sum to the account of the seller or at the time of payment thereof by any mode, whichever is earlier, deduct an amount equal to 0.1 percent of such sum exceeding fifty lakh rupees as income tax. The Rs 50 lakh aggregate threshold is a running-total trigger — the ERP field enforcement layer must track cumulative purchase value per vendor PAN across the financial year, and switch on TDS deduction the moment the aggregate crosses fifty lakh, which is a computation no reviewer can do manually across a supplier base of two hundred plus vendors.
  • Rule 36(4), Central Goods and Services Tax Rules 2017 — Input tax credit to be availed by a registered person in respect of invoices or debit notes, the details of which are required to be furnished under sub-section (1) of section 37, shall be restricted to the invoices or debit notes uploaded by the suppliers in FORM GSTR-1 or through the Invoice Furnishing Facility and communicated to the recipient in FORM GSTR-2B. A vendor master with a discipline of PAN, GSTIN, supply type, and Section-code capture at onboarding plus quarterly re-validation is the prevention control that keeps Rule 36(4) matching tractable — a supplier whose GSTIN status changes from Active to Cancelled mid-year without a re-validation cycle will cascade into a mismatched-vendor ITC exposure that the [Rule 36(4) framework](/insights/rule-37-37a-itc-reversal-supplier-default-india/) then converts into a reversal obligation.
  • Section 16(4), Central Goods and Services Tax Act 2017 — A registered person shall not be entitled to take input tax credit in respect of any invoice or debit note for supply of goods or services or both after the thirtieth day of November following the end of the financial year to which such invoice or debit note pertains. The 30 November time bar is why the portal-cadence prevention control has the tightest calendar of any control in this article — a TRACES pull on the 7th and an IMS action within 15 days of GSTR-2B availability are cadences the finance team can drift on for a month, but a supplier follow-up cadence that lets a laggard supplier's GSTR-1 filing slip past 30 November is a Severity-10 permanent loss the [Section 16(4) time-bar guide](/insights/section-16-4-itc-time-bar-india/) walks through in detail.
  • Rule 88C and Form DRC-01B, Central Goods and Services Tax Rules 2017 — Where the tax liability declared in GSTR-1 for a tax period exceeds the tax paid in GSTR-3B for the same period by the prescribed amount and percentage, an intimation in Form GST DRC-01B is auto-generated to the registered person. The recipient shall either pay the differential with applicable interest or furnish a reply within seven days of receipt. The 24-hour triage window is a prevention-control design decision — the DRC-01B notice itself carries a seven-day statutory clock, but a finance team's own internal SLA to acknowledge the notice, assign the row to a named preparer, and open the reconciliation working paper within 24 hours of the intimation landing is the prevention control that keeps the 7-day reply window from becoming a 6-day reply cycle plus a 1-day panic.
  • Companies (Auditor's Report) Order 2020, Clause 3(vi) — Whether maintenance of cost records has been specified by the Central Government under sub-section (1) of section 148 of the Companies Act 2013, and whether such accounts and records have been so made and maintained. Read together with Clause 3(ii)(b) on quarterly stock and receivables statements filed with lenders, CARO 2020 requires an auditor's report on the reliability of the underlying records and reconciliations. Prevention controls — the cut-off calendar, the sign-off matrix, the ERP field enforcement layer — are the design-side artefacts that make the maintained records reliable and the auditor's report on their sufficiency defensible.

Frequently Asked Questions

What is the difference between a prevention control and a detection control in a reconciliation risk register?
A prevention control reduces the likelihood that a failure mode fires at all — a mandatory GSTIN field on invoice creation in the ERP prevents an unregistered supplier's invoice from being booked, so the downstream Rule 36(4) mismatch never occurs. A detection control catches a failure that has already happened but before it reaches the counterparty, the tax authority, or the statutory auditor — a monthly tick-and-tie of the purchase register against GSTR-2B catches the mismatch after the invoice was booked without a GSTIN. On the anchored SOD scale, prevention controls lower the Occurrence rating, while detection controls lower the Detection rating. The two are complementary — a High Action Priority row on the register almost always requires both a prevention layer that keeps the failure rate down and a detection layer that catches the residual failures the prevention layer misses. A row with only a prevention control is fragile because the prevention control can be circumvented; a row with only a detection control is expensive because every failure has to be worked after the fact.
How does a Rs 5 lakh / Rs 25 lakh / Rs 1 crore approval hierarchy defend against reconciliation risk under Section 143(3)(i)?
The approval hierarchy is the design-side evidence that no single individual can close a material variance without independent review. A Rs 5 lakh threshold sign-off by the controller, a Rs 25 lakh threshold sign-off by the CFO, and a Rs 1 crore threshold sign-off by the audit committee (illustrative bands — every enterprise calibrates its own thresholds to its transaction profile and materiality anchor) mean that any reconciliation variance above the smallest band cannot be accepted-and-cleared by the preparer alone. The Section 143(3)(i) ICFR opinion tests the design of the control by asking whether the hierarchy is written, whether the thresholds are calibrated to the enterprise's transaction profile, and whether the sign-off evidence is retained under Section 128(5) of the Companies Act for the mandated seven-year period. The opinion tests the operation of the control by sampling variances against the sign-off log — a Rs 27 lakh variance cleared without a CFO signature is an operating-effectiveness failure that becomes an ICFR material weakness observation.
Why does vendor master data discipline require quarterly re-validation rather than a one-time onboarding check?
A vendor's GSTIN status, PAN status, supply type, and applicable withholding section are not static properties. A supplier's GSTIN can move from Active to Suspended if the supplier fails to file GSTR-3B for two consecutive periods, and from Suspended to Cancelled if the default persists. A supplier's PAN can become inoperative if it is not linked to Aadhaar under the applicable notification. A supplier's supply type can change if the supplier crosses the composition-scheme turnover threshold. A one-time onboarding check captures the state on the day the vendor was added; a quarterly re-validation cycle refreshes the state before the vendor's next quarterly ITC or TDS reconciliation runs, so a supplier whose GSTIN was cancelled in Q1 does not cause a Rule 37A cascading ITC reversal in Q2. The re-validation itself is a bulk portal lookup on the GSTN and the [TDS TRACES portal](/insights/tds-traces-portal-reconciliation-india/), scriptable in Excel VLOOKUPs against the enterprise's vendor master, and the output feeds directly into the exception list the reviewer works next quarter.
What is the case for a 24-hour DRC-01B triage window when the statutory reply period is seven days?
The seven-day DRC-01B reply window under Rule 88C is the outer statutory boundary. Every day of it that the enterprise burns on internal routing — the notice landing in a general inbox, waiting for the indirect tax analyst to notice, waiting for the analyst to route it to the preparer, waiting for the preparer to open the working paper — is a day removed from the reconciliation and reply work itself. A 24-hour triage SLA compresses the routing time so the preparer has six clear working days to do the actual work: pull the GSTR-1 versus GSTR-3B variance schedule, isolate the specific invoices driving the flagged difference, decide whether to pay through DRC-03 or reply with reconciliation, and route the response through the sign-off matrix. The [DRC-01B reply guide](/insights/drc-01b-reconciliation-reply/) documents the seven-day mechanics; the 24-hour triage is the internal SLA that keeps the seven days workable. Enterprises without the triage discipline routinely reply on day seven at 4pm and pay penalties for reconciliation errors they could have found on day two.
How does a 20-day cut-off calendar cadence relate to the Playbook operational close rhythm?
The 20-day cadence is not a single cut-off event — it is a rolling operational rhythm across the close window. Days 1 to 5 close the bank reconciliation on the previous month's transactions; days 6 to 10 close the TDS statement inputs for the deductions made that month; days 11 to 15 close the GSTR-2B ITC reconciliation once the portal makes the statement available on the 14th; days 16 to 20 close the GSTR-1 preparation and the GSTR-3B liability workbook before the GSTR-3B filing on day 20 or day 22 or day 24 depending on the state and turnover band. The prevention-side calendar publishes each of these sub-cadences with a named owner and a named deliverable, and the [monthly close reconciliation playbook](/insights/reconciliation-playbook-monthly-close-india/) sequences the runbooks that operate against each cadence. The prevention control is the published calendar itself with signed analyst acknowledgement; the operational execution is what the Playbook cluster's five stream runbooks then walk through step by step.

See how TransactIG handles reconciliation for your industry

Configuration takes 2–4 weeks. No code development required. ISO 27001:2022 certified.