An Indian CA firm running reconciliation for 50 or more enterprise clients faces a scoping problem that neither the enterprise-side reconciliation methodology nor the ICAI Standards on Auditing address directly. The firm cannot run 50 disconnected failure mode analyses — each client would end up with its own idiosyncratic Severity anchors, its own idiosyncratic role allocation, and its own idiosyncratic evidence base, and the firm's own peer review under the ICAI Peer Review Board Guidelines 2019 (revised 2019, mandatory once every three years) would fail the design test. The firm also cannot run one flat analysis across the book — a listed-entity client with Ind AS 24 related-party overlays plus SEBI LODR corporate governance obligations plus the ICAI SA 240 fraud-risk assessment carries a materially different Severity ceiling from an SME client whose baseline is the Section 143(3)(i) ICFR opinion under the Companies Act 2013. The firm's role structure — partner, manager, senior, associate — is set by ICAI standard and the reconciliation work must be allocated to each role at the correct Severity band. And the firm's own working papers must survive peer review as evidence of a coherent quality control system, not as a collection of one-off client outputs.
Publish the reconciliation process design programme as a portfolio-scale template. One standard 14-class failure mode taxonomy that is invariant across the client book. One per-client overlay tab that carries the client's industry preset, GST registration footprint, TDS deductor and deductee mix, bank-account inventory, listed-entity or SME classification, and the specific reconciliation streams the engagement scope covers. One role-Severity mapping that is invariant across the book — partner sign-off on Severity 9 or 10, manager review on Severity 6 to 8, senior operator on Severity 3 to 5, associate operator on Severity 1 to 2. One listed-entity Severity+1 overlay on the streams where SEBI LODR, Ind AS 24, and ICAI SA 240 raise the reputational or regulatory-consequence profile. One monthly control plan review by the engagement partner and one quarterly walk by the firm's technical committee. One 3-year peer review cycle mapping the standard tab, the overlay tabs, the role-Severity mapping, the listed-entity overlay, and the audit trail into a coherent peer review file.
Illustrative 60-client mid-tier firm with 8 partners, 24 managers, 60 seniors, and 120 associates. Illustrative Rs 45,000 per client onboarding fee and Rs 12,000 per client monthly recurring retainer. Portfolio-scale control plan template stored in the firm's practice management system alongside the engagement letters. ICAI SA 315 risk-assessment walk executed by the engagement manager at onboarding and re-walked on any material change to the client's operating model. ICAI SA 240 fraud-risk walk executed by the engagement partner on every listed-entity engagement and every non-listed engagement where a fraud indicator is present. Peer review artefact archived per client for the 3-year cycle and made available to the ICAI Peer Review Board panel at the peer review visit. Monthly Section 16(4), Section 200A, and DRC-01B aggregation queues walked at the firm level to surface book-wide exposure ahead of the transition to a white-label reconciliation platform.
A portfolio-scale reconciliation process design programme defensible under the ICAI Peer Review Board Guidelines 2019, with per-client control plans that survive statutory audit peer testing, per-client risk overlays that differentiate listed-entity engagements from SME engagements, and a role-Severity mapping that allocates every reconciliation task to the correct partner, manager, senior, or associate on the anchored SOD scale. Every High Action Priority row on every client's register is signed off at the partner level with a written acceptance rationale for any residual risk. Every listed-entity client carries the additional Severity+1 overlay on the streams where SEBI LODR, Ind AS 24, and ICAI SA 240 apply. Every peer review visit finds a coherent quality control system rather than 60 disconnected client outputs. The white-label reconciliation platform enters the firm's stack as the leverage layer at the point where the book-level aggregation queues on Section 16(4), Section 200A, and DRC-01B exceed the capacity of the senior team to walk within the monthly close cycle.
An Indian CA firm running the monthly reconciliation cycle for 60 enterprise clients faces a scoping problem that the enterprise-side reconciliation methodology, on its own, does not answer. The enterprise-side method — one failure mode analysis per stream, one control plan per stream, one anchored Severity, Occurrence, and Detection rating per row — assumes one entity, one CFO, one audit committee, one statutory auditor. The firm has 60. Each client’s reconciliation working papers must survive the client’s own statutory audit. And the firm’s own working papers, taken together, must survive the peer review that the ICAI Peer Review Board Guidelines revised in 2019 mandate once every three years across every practice unit rendering assurance services.
The answer is not to run 60 disconnected failure mode analyses. It is to publish one portfolio-scale reconciliation process design template — one standard tab that is invariant across the book, one per-client overlay tab that captures the engagement’s specifics, one role-Severity mapping that allocates work to the ICAI-standard four-tier structure of partner, manager, senior, and associate, and one listed-entity Severity+1 overlay for engagements where the SEBI LODR corporate governance regime and the Ind AS 24 related-party disclosures apply. This method article publishes the portfolio-scale template a mid-tier CA firm running 50 or more enterprise engagements uses, with the role-Severity mapping, the listed-versus-SME risk overlay, and the peer review readiness that the firm’s own process design produces as a side effect.
Quick reference
| Aspect | Detail |
|---|---|
| Illustrative firm profile | 60-client mid-tier firm with 8 partners, 24 managers, 60 seniors, 120 associates |
| Illustrative engagement economics | Rs 45,000 per client onboarding, Rs 12,000 per client monthly retainer |
| Portfolio template | One standard 14-class failure mode taxonomy plus per-client overlay tab |
| Role-Severity mapping | Partner S9-10, manager S6-8, senior S3-5, associate S1-2 |
| Listed-entity overlay | Severity +1 on SEBI LODR / Ind AS 24 / ICAI SA 240 fraud-risk streams |
| SME baseline | Standard Severity anchored to Section 143(3)(i) ICFR |
| Peer review authority | ICAI Peer Review Board Guidelines (revised 2019), mandatory 3-year cycle |
| Risk assessment authority | ICAI SA 315 (walked at onboarding and on material change) |
| Fraud risk authority | ICAI SA 240 (mandatory on listed-entity engagements) |
| White-label transition triggers | Section 16(4) supplier queue on 15+ engagements; Section 200A aggregation on 20+ engagements; DRC-01B pre-check on 25+ engagements |
The scoping problem — why 60 disconnected analyses fail the peer review
A CA firm at portfolio scale carries three interlocking constraints the enterprise-side reconciliation methodology cannot itself resolve. The first is engagement heterogeneity. A listed-entity client with a Rs 800 crore turnover, three subsidiaries, five GSTIN registrations, 240 vendor deductors, and 60 shipping bills per month is not the same reconciliation engagement as a private-limited SME client with Rs 30 crore turnover, one GSTIN, 45 vendor deductors, and no export footprint. The reconciliation control plan template walks 14 failure classes per stream in either case, but the Severity anchors, the Occurrence ratings, the Detection layer, and the review cadence are materially different.
The second is role allocation. An Indian CA firm operates against an ICAI-standard four-tier structure — partner, manager, senior, associate — with defined sign-off authority. A reconciliation programme that ignores the role structure ends up with associates signing off on Section 16(4) permanent-loss rows because the SOP does not name the sign-off level, and the firm’s peer review under the ICAI Peer Review Board Guidelines revised in 2019 finds a design gap at exactly that seam.
The third is peer review evidence. The Peer Review Board Guidelines require every practice unit rendering assurance services to undergo peer review once every three years. The peer reviewer walks the firm’s quality control policies, its risk-assessment procedures under ICAI SA 315, and a sample of the working paper files. A firm whose reconciliation engagements produce 60 idiosyncratic outputs cannot answer the peer review’s design test — the reviewer sees 60 different Severity anchors, 60 different role allocations, and 60 different audit trails, and the finding lands on quality control system design rather than on any individual engagement.
The portfolio-scale template is the design answer. One standard tab. One per-client overlay. One role-Severity mapping. One listed-versus-SME overlay. One peer review evidence base.
The standard tab and the per-client overlay
The standard tab of the portfolio-scale template carries the 14-class failure mode taxonomy Terra Insight publishes on the reconciliation process design pillar — data extraction, classification, completeness, matching, timing, partner, precision, policy, aging, cutoff, evidence, portal, plus two additional CA-firm-specific classes for engagement-scoping (the risk that the engagement letter’s scope excludes a reconciliation stream the client operationally needs) and cross-client-privilege (the risk that a working paper from Client A becomes visible in the Client B file through file-naming or version-control drift). The standard tab also carries the anchored Severity, Occurrence, and Detection scale from the SOD rating guide, the Action Priority table from the Action Priority method article, and the 6P cause taxonomy of People, Policy, Process, Portal, Period, Partner. The standard tab does not change from client to client. Any firm-wide change to the taxonomy, the SOD scale, the AP table, or the 6P cause categorisation is a change to the standard tab, reviewed by the firm’s technical committee, signed off by the managing partner, and rolled out to every overlay tab in a single release cycle.
The per-client overlay tab carries the engagement’s specifics: the client’s industry preset (steel, pharma, IT services, real estate, jewellery, or one of the other industry presets the firm supports), the GST registration footprint (single-state, multi-state, SEZ, or export-oriented), the TDS deductor and deductee mix (payroll versus vendor versus royalty versus commission versus rent versus professional services), the bank-account inventory, the engagement scope (statutory audit, tax audit, internal audit, monthly compliance, or a combination), the listed-entity or SME classification, and the specific reconciliation streams the engagement covers. Each row on the overlay tab references a row on the standard tab and carries the client-specific Occurrence rating (based on the incident data from the prior four quarters of the engagement), the client-specific Detection rating (based on the client’s current control layer, not the firm’s), and any client-specific prevention or detection control the firm has designed above the standard.
A firm running 60 engagements maintains 1 standard tab and 60 overlay tabs. When a rule changes — the shift from the legacy Section 194x TDS identifiers to the Section 393 four-digit payment codes 1001 to 1092 from 1 April 2026, the DRC-01B threshold change under Rule 88C, the Section 16(4) 30 November cutoff — the change is made on the standard tab, and every overlay tab picks up the change on the next monthly review cycle.
Role allocation — the ICAI four-tier structure mapped to the anchored SOD scale
The firm’s four ICAI-standard roles map directly onto the anchored Severity bands on the reconciliation control plan.
- Partner (Severity 9 or 10). Signs off on every High Action Priority row where the underlying failure mode maps to a Severity 9 or 10 statutory consequence — Section 16(4) permanent ITC loss, Section 200A demand notice with Section 201(1A) interest at 1 percent per month for short-deduction and 1.5 percent per month for short-payment plus Section 234E fee at Rs 200 per day, Section 40(a)(ia) expenditure disallowance for TDS non-deduction, and every ICAI SA 240 fraud-risk-adjacent row on a listed-entity client. The partner’s sign-off is the audit-committee-facing accountability layer and is documented in the working paper file as evidence for the peer review.
- Manager (Severity 6, 7, or 8). Reviews every row rated Severity 6, 7, or 8 — DRC-01B intimation under Rule 88C (seven-day reply window on the GSTR-1 versus GSTR-3B threshold breach), Section 43B(h) MSME year-end disallowance, CARO 2020 Clause 3(ii)(b) material weakness observation on the quarterly stock statements filed with lenders, and Section 143(3)(i) ICFR design observations. The manager also runs the SA 315 risk assessment walk at engagement onboarding and re-walks on any material change to the client’s operating model.
- Senior (Severity 3, 4, or 5). Operates the reconciliation on every row rated Severity 3, 4, or 5 — ledger-level exceptions, timing differences, currency-restatement variances under Ind AS 21, precision-band variances within the enterprise’s materiality floor. The senior’s outputs feed the manager’s review layer.
- Associate (Severity 1 or 2). Operates the reconciliation on every row rated Severity 1 or 2 — presentation errors, cosmetic differences within the CBIC-permissible rounding tolerance, formatting variances that do not affect the reconciled amount.
The role-Severity mapping is not a suggestion. It is a design property of the control plan, enforced by the firm’s practice management system’s access control — an associate cannot sign off on a Severity 9 row because the system does not present the sign-off action at that role. The peer reviewer walks the mapping as part of the design-side evidence base, and a firm whose associates have signed off on Severity 9 or 10 rows will face a Peer Review Board finding on quality control system design regardless of whether the underlying reconciliation was technically correct.
The listed-entity Severity+1 overlay
An SME client on the firm’s book uses the standard Severity anchored to the Section 143(3)(i) ICFR baseline under the Companies Act 2013. A listed-entity client carries an additional Severity+1 overlay on the streams where the SEBI (Listing Obligations and Disclosure Requirements) Regulations 2015, the Ind AS 24 related-party disclosures, and the ICAI SA 240 fraud-risk assessment raise the reputational or regulatory-consequence profile.
The Severity+1 overlay is a two-column addition on the standard control plan template. One column carries the SME Severity, one column carries the listed-entity Severity, and the engagement type on the per-client overlay tab determines which column drives the Action Priority lookup. Concretely:
- A CARO 2020 Clause 3(ii)(b) material weakness observation on an SME client anchors at Severity 8 (auditor qualification). The same observation on a listed entity re-anchors at Severity 9 (audit committee scrutiny under SEBI LODR Regulation 18, independent director follow-up, and mandatory SEBI LODR corporate governance disclosure).
- A related-party intercompany reconciliation gap on an SME client anchors at Severity 7 (Ind AS 24 disclosure at the financial statement level). The same gap on a listed entity re-anchors at Severity 9 (SEBI LODR Regulation 23 arm’s-length test failure, related-party transaction disclosure regime, and audit committee’s independent director scrutiny).
- A revenue-recognition timing gap that touches management-estimate boundaries on an SME client anchors at Severity 6 (SA 315 assertion-level risk). The same gap on a listed entity re-anchors at Severity 8 (SA 240 fraud-risk overlay because management estimates are a documented fraud indicator).
The listed-entity engagement partner walks the Severity+1 overlay at onboarding and re-walks at every quarterly board meeting cycle. The overlay is a design property of the firm’s template and is walked by the peer reviewer as part of the design-side evidence base.
Peer review readiness under the ICAI Peer Review Board Guidelines 2019
The Peer Review Board Guidelines revised in 2019 require every practice unit rendering assurance services to undergo peer review once every three years. The peer reviewer examines the firm’s technical, professional, and ethical standards, its quality control policies and procedures, and a sample of working paper files from engagements executed during the review period.
For a firm whose reconciliation programme runs on the portfolio-scale template, the peer review file writes itself. The standard tab is the firm-wide quality control artefact. The overlay tabs are the per-engagement evidence. The role-Severity mapping is the design of the sign-off chain. The listed-entity Severity+1 overlay is the design of the risk-differentiation between engagement types. The monthly Section 16(4), Section 200A, and DRC-01B aggregation queues walked at the firm level are the design of the book-wide risk oversight. The three-year retention of the peer review artefact per client — archived in the practice management system alongside the engagement letters, working papers, and Section 128(5) Companies Act 2013 seven-year retention record — is the operational evidence trail.
The peer reviewer’s walk on this file base finds a coherent quality control system: one standard tab, 60 overlay tabs, one role-Severity mapping, one listed-versus-SME overlay, one book-wide aggregation, and one three-year peer review cycle. The alternative — 60 disconnected Excel-per-client outputs — cannot answer the design test even if every individual engagement is technically competent.
When the white-label reconciliation platform becomes the firm’s leverage layer
A well-run portfolio-scale template does exactly what it was designed to do — it surfaces High Action Priority rows on every client engagement, aggregates the exposure at the firm level, and allocates the sign-off to the correct role. Aggregating the exposure at the firm level also raises the demand on the detection layer.
The illustrative 60-client firm with 8 partners, 24 managers, 60 seniors, and 120 associates can sustain the manual detection layer up to a specific book-level ceiling. Beyond that ceiling, the aggregation queues that the action priority table demands on High AP rows exceed the capacity of the senior team to walk within the monthly close cycle across the book. The three canonical transition triggers are the Section 16(4) at-risk supplier queue on more than 15 concurrent engagements each with more than 100 GST-eligible vendors; the Section 200A payment-code aggregation queue on more than 20 concurrent engagements each with more than 50 deductors; and the DRC-01B pre-check under Rule 88C on more than 25 concurrent engagements each with more than 3 GSTIN registrations. Beyond these bands, the firm’s role-Severity mapping breaks under aggregate load — not because any individual engagement fails, but because the aggregate senior-team review cadence across the book exceeds what the illustrative 60-senior bench can sustain within the monthly close reconciliation playbook window.
At that point a white-label reconciliation platform enters the firm’s stack as the leverage layer. The firm’s brand carries every client-facing PDF. The firm’s sub-domain carries every client portal login. The firm retains professional responsibility for the reconciliation and the sign-off chain. The white-label reconciliation for CA firms guide covers the operational mechanics of the branding, portal, and email layer, and the reconciliation software for CA firms guide covers the multi-tenant architecture the firm needs. The peer reviewer walks the platform’s audit trail as evidence of the operating detection control — the aging queue, the exception log, the reviewer sign-off timestamp — and the firm’s role-Severity mapping continues to operate above the platform’s detection layer. The companion Phase 4 CLOSER article on manual reconciliation ceilings covers the enterprise-side transition thresholds that the CA firm’s aggregate book-level thresholds mirror at portfolio scale.
Where this fits
- Reconciliation process design — the methodology pillar
- The reconciliation control plan template
- The anchored SOD rating scale
- Action Priority vs materiality
- When manual reconciliation tops out
- Reconciliation software for CA firms
- White-label reconciliation for CA firms
- Monthly close reconciliation playbook
- Reconciliation software India
Frequently Asked Questions
What is the portfolio-scale reconciliation process design template a CA firm running 50 or more enterprise engagements applies?
The portfolio-scale template is one standard control plan document that carries the standard 14-class failure mode taxonomy Terra Insight publishes on the pillar — data extraction, classification, completeness, matching, timing, partner, precision, policy, aging, cutoff, evidence, portal, plus two additional CA-firm-specific classes for engagement-scoping and cross-client-privilege — and a per-client overlay tab that captures the industry-specific failure modes for each engagement. The standard tab does not change from client to client. The overlay carries the client’s industry preset, its GST registration footprint, its TDS deductor and deductee mix, its bank-account inventory, its listed-entity or SME classification, and the specific reconciliation streams the engagement scope covers. A CA firm running 60 client engagements maintains one standard tab and 60 overlay tabs, and the peer reviewer under the ICAI Peer Review Board Guidelines 2019 walks the standard tab once and samples the overlay tabs against the sampled engagements. The template lives in the firm’s practice management system alongside the engagement letters and the working paper files.
How does role allocation on the SOD scale work — partner, manager, senior, associate?
The four ICAI-standard roles in an Indian CA firm — partner, manager, senior, and associate — map directly onto the anchored SOD Severity bands on the reconciliation control plan. The partner signs off on every row rated Severity 9 or 10 — Section 16(4) permanent ITC loss, Section 200A demand notice with Section 201(1A) interest, Section 40(a)(ia) expenditure disallowance, ICAI SA 240 fraud-risk-adjacent items on a listed-entity client. The manager reviews every row rated Severity 6, 7, or 8 — DRC-01B intimation under Rule 88C, Section 43B(h) MSME year-end disallowance, CARO 2020 Clause 3(ii)(b) material weakness observation. The senior operates the reconciliation on every row rated Severity 3, 4, or 5 — ledger-level exceptions, timing differences, currency-restatement variances, precision-band variances. The associate operates the reconciliation on every row rated Severity 1 or 2 — presentation errors, cosmetic differences within the CBIC-permissible rounding tolerance. The role-Severity mapping is a design property of the firm’s control plan and is enforced by access control in the practice management system. The peer reviewer under the Peer Review Board Guidelines 2019 walks the role-Severity mapping as part of the design-side evidence base.
How does the risk overlay differ between a listed-entity client and an SME client on the CA firm’s book?
The SME client’s reconciliation control plan uses the standard Severity anchored to the Section 143(3)(i) ICFR baseline — Severity 10 for Section 16(4) permanent ITC loss, Severity 9 for Section 200A demand, Severity 8 for CARO 2020 or DRC-01B. The listed-entity client’s control plan carries an additional Severity+1 overlay on the streams where the SEBI LODR corporate governance obligations, the Ind AS 24 related-party disclosure regime, and the ICAI SA 240 fraud-risk assessment raise the reputational or regulatory-consequence profile. A Severity 8 CARO 2020 material weakness observation on an SME client re-anchors as Severity 9 on a listed-entity client because the material weakness on a listed entity feeds the SEBI LODR corporate governance disclosure regime and the audit committee’s independent director scrutiny. Related-party intercompany reconciliation on a listed entity carries a Severity anchor of 9 (Ind AS 24 disclosure gap under SEBI LODR Regulation 23) versus a Severity anchor of 7 on an SME. The overlay is a two-column addition on the standard control plan template — one column captures the SME Severity, one column captures the listed-entity Severity, and the engagement type determines which column drives the Action Priority lookup.
How does the firm’s own reconciliation process design feed peer review readiness under the ICAI Peer Review Board Guidelines 2019?
The Peer Review Board Guidelines revised in 2019 require every practice unit rendering assurance services to undergo peer review once every three years. The peer reviewer examines the firm’s quality control policies, its risk-assessment procedures under SA 315, and a sample of the working paper files from the engagements executed during the review period. Where the firm’s reconciliation engagements form part of a statutory audit, tax audit, or assurance-adjacent workpaper file, the peer reviewer walks the firm’s own reconciliation process design methodology, the anchored SOD rating scale, the Action Priority table, the 6P cause taxonomy, and the per-client control plan overlay. A firm whose reconciliation programme is engineered against a documented failure mode analysis — one standard tab, per-client overlays, role-Severity mapping, listed-entity Severity+1 overlay, monthly control plan review, quarterly audit committee walk — carries the design-side evidence base that a peer reviewer tests as a coherent quality control system. A firm running Excel-per-client with no standard tab and no role-Severity mapping cannot answer the peer review’s design test even if the individual client engagements are technically competent.
When does a CA firm move from Excel-per-client to a white-label reconciliation platform as the leverage layer?
The transition point is not a specific client count or a specific transaction volume. It is the point at which the firm’s own control plan template surfaces a High Action Priority row on multiple client engagements simultaneously and the manual layer cannot economically produce the detection control the control plan demands across the book. The three canonical transition triggers are: the Section 16(4) at-risk supplier queue on more than 15 concurrent enterprise engagements each with more than 100 GST-eligible vendors; the Section 200A payment-code aggregation queue on more than 20 concurrent engagements each with more than 50 deductors; and the DRC-01B pre-check under Rule 88C on more than 25 concurrent engagements each with more than 3 GSTIN registrations. Beyond these thresholds the firm’s role-Severity mapping breaks — the senior team cannot manually walk the aggregation queues within the monthly close cycle across the book. A white-label reconciliation platform — the firm’s brand on the client-facing PDF, the vendor’s brand invisible, the firm’s sub-domain on the client portal — becomes the leverage layer at that point. The firm retains professional responsibility, the peer reviewer walks the platform’s audit trail as evidence of the operating detection control, and the client sees only the firm’s letterhead. Read the Terra Insight guide on white-label reconciliation for CA firms for the operational mechanics of the transition.
- ▸ ICAI Peer Review Board Guidelines (Revised 2019) — The Peer Review Board Guidelines, revised in 2019, mandate a mandatory peer review of every practice unit rendering assurance services once every three years. The peer reviewer examines the firm's technical, professional, and ethical standards, its quality control policies and procedures, and the working papers of a sample of the engagements executed during the review period. Where the firm renders reconciliation services under an assurance-adjacent engagement or where reconciliation working papers form part of a statutory audit or tax audit workpaper file, the peer reviewer walks the firm's own reconciliation process design methodology, its risk-assessment procedures under SA 315, and the working paper evidence trail. A firm whose reconciliation engagements are executed against a documented failure mode analysis with anchored Severity ratings and a written control plan per client carries the design-side evidence the peer reviewer tests.
- ▸ ICAI Standard on Auditing SA 315, Identifying and Assessing the Risks of Material Misstatement — The auditor shall perform risk assessment procedures to obtain an understanding of the entity and its environment, including the entity's internal control, sufficient to identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels. SA 315 requires the firm to walk each client's reconciliation function's design and operating effectiveness at engagement onboarding and re-walk on any material change. The CA firm's portfolio-scale reconciliation process design methodology is the direct evidence base for the SA 315 walk on every engagement in the book.
- ▸ ICAI Standard on Auditing SA 240, The Auditor's Responsibilities Relating to Fraud in an Audit of Financial Statements — The auditor shall maintain professional scepticism throughout the audit, recognising the possibility that a material misstatement due to fraud could exist, notwithstanding the auditor's past experience of the honesty and integrity of the entity's management and those charged with governance. SA 240 requires the auditor to identify and assess the risks of material misstatement due to fraud at the financial statement level and at the assertion level for classes of transactions, account balances, and disclosures. For a listed-entity client the fraud-risk overlay raises the Severity ceiling on every reconciliation stream by one band on the anchored SOD scale, and the CA firm's control plan template carries the listed-entity SA 240 overlay as a distinct column.
- ▸ Section 143(3)(i), Companies Act 2013 — The auditor's report shall state whether the company has adequate internal financial controls with reference to financial statements in place and the operating effectiveness of such controls. The Section 143(3)(i) ICFR opinion is the baseline evidence requirement for every SME client on the firm's book. The reconciliation process design methodology — one control plan per stream, one Severity anchored to Indian statutory consequences, one Action Priority table, one 6P cause taxonomy — is the design-side documentation the Section 143(3)(i) test evaluates when the firm's engagement is a statutory audit.
- ▸ SEBI (Listing Obligations and Disclosure Requirements) Regulations 2015 — Every listed entity shall comply with the corporate governance provisions, related-party transaction disclosure regime under Regulation 23, and the audit committee constitution and reporting obligations under Regulation 18. For a listed-entity client on the CA firm's book, the SEBI LODR obligations sit alongside the Ind AS 24 related-party disclosures and the ICAI SA 240 fraud-risk overlay to raise the Severity anchor on the intercompany, related-party, and disclosure-adjacent reconciliation streams by one band on the anchored SOD scale. The listed-entity Severity ceiling overlay is a design property of the firm's portfolio-scale control plan template.
- ▸ Ind AS 24, Related Party Disclosures — An entity's financial statements shall contain the disclosures necessary to draw attention to the possibility that its financial position and profit or loss may have been affected by the existence of related parties and by transactions and outstanding balances, including commitments, with such parties. Ind AS 24 requires the disclosure of related-party transactions and balances at the financial statement level. For every listed-entity client, the CA firm's reconciliation process design must include a related-party overlay on the intercompany reconciliation stream that identifies the related-party population, walks the pricing and terms against the SEBI LODR Regulation 23 arm's-length test, and reconciles the disclosed balances back to the underlying ledger.