Skip to main content
How-To · 12 min read

The Anchored SOD Rating Scale for Indian Reconciliation: How to Rate Severity, Occurrence, and Detection Without Guessing

Generic 1-to-10 severity tables are the single largest source of noise in a reconciliation risk register — Severity 8 in one team is Severity 5 in another, and both are defensible when the anchors are unwritten. This method article publishes Terra Insight's anchored SOD scale for Indian reconciliation, mapping every Severity rating to a specific statutory consequence, every Occurrence rating to a frequency band per 1,000 transactions, and every Detection rating to an evidence-backed catch-rate — with three worked case studies where a badly-anchored scale mis-prioritised a High Action Priority failure mode into the accept-and-move-on bucket.

Terra Insight
Terra Insight Editorial Team Reconciliation Infrastructure

Content authored by practitioners with experience at Amazon India, Intuit QuickBooks, and the Tata Group. Meet the team →

Published 4 August 2026
Domain expertise
TDS Reconciliation GST Input Credit Platform Settlements NACH Batch Matching Bank Reconciliation Form 26AS Matching ERP Integrations Enterprise Finance Ops
Knowledge Card
Problem

Generic 1-to-10 rating tables are the single largest source of noise in a reconciliation risk register. Severity 8 in one team's register is Severity 5 in another team's register, and both are defensible when the anchors are unwritten. Occurrence 3 to one analyst is Occurrence 6 to another because 'sometimes' and 'occasionally' are not the same word to the same person. Detection ratings drift toward the middle of the scale as analysts hedge, and the resulting Action Priority ranking loses the discriminatory power the framework was designed to produce. A Section 16(4) November 30 permanent-loss risk ends up in the same bucket as a paise-level rounding difference, and the finance team's remediation queue is dictated by whoever shouted loudest rather than by the anchored severity of the exposure.

How It's Resolved

Publish the three SOD scales as anchored tables — Severity anchored to specific Indian statutory consequences (Section 16(4) permanent ITC loss = 10; Section 200A demand notice = 9; DRC-01B seven-day reply window = 8; Section 43B(h) year-end MSME disallowance = 7; CARO 2020 audit-report observation without material weakness = 6; Section 201(1A) TDS interest = 5; Ind AS 21 forex restatement = 4; petty variance below the enterprise's own materiality floor = 3), Occurrence anchored to incidents per one thousand transactions in the prior four quarters (fewer than one per ten thousand = O1; five to twenty-five per one thousand = O5; more than one hundred per one thousand = O10), Detection anchored to catch-rate through the current control layer (system-enforced constraint = D1 at ninety-nine percent plus; manual sampling at year-end = D5 at sixty to seventy-five percent; no control = D10 below thirty percent, effectively pure luck). Prioritise on Severity first — any Severity-9 or Severity-10 row is High Action Priority regardless of Occurrence and Detection. Occurrence and Detection then determine the depth of the required prevention and detection controls, not the fact of the intervention.

Configuration

One-page anchored SOD scale published inside the reconciliation policy document; every risk register row cross-references the specific anchor for its Severity, Occurrence, and Detection rating; the register is reviewed monthly by the controller for Occurrence and Detection re-rating on the basis of actual prior-quarter incidents; Severity is re-rated only when a statute or a portal rule changes — for example, the shift from legacy Section 194x identifiers to the Section 393 four-digit payment codes 1001 to 1092 from 1 April 2026 alters the Severity anchor for cross-era TDS misclassification because the correction-window mechanics themselves change. Audit committee sign-off on the published scale is the design-side evidence that Section 143(3)(i) ICFR testing verifies.

Output

A reconciliation risk register whose Severity, Occurrence, and Detection ratings are independently verifiable against published anchors, whose Action Priority ranking is defensible under statutory audit testing, and whose prevention and detection controls are calibrated to the actual severity of the exposure rather than to the analyst's subjective interpretation. A register configured against the anchored SOD scale routinely surfaces two to three High Action Priority failure modes per reconciliation stream that a generic-scale register had rated Medium or Low, and closes those exposures before they compound into a Section 200A demand notice, a DRC-01B seven-day reply cycle, or a Section 16(4) permanent ITC loss on the November 30 cutoff.

Generic 1-to-10 rating tables are the single largest source of noise in a reconciliation risk register. Severity 8 in one team’s register is Severity 5 in another team’s register, and both are defensible when the anchors are unwritten. Occurrence 3 to one analyst is Occurrence 6 to another because “sometimes” and “occasionally” are not the same word to the same person. Detection ratings drift toward the middle of the scale as analysts hedge on what they cannot measure. The result is a register whose Action Priority ranking loses the discriminatory power the reconciliation process design method was designed to produce — a Section 16(4) November 30 permanent-loss exposure ends up in the same bucket as a paise-level rounding difference, and the finance team’s remediation queue is dictated by whoever shouted loudest rather than by the anchored severity of the exposure.

This method article publishes Terra Insight’s anchored SOD scale for Indian reconciliation — three 1-to-10 tables where every rating is tied to a specific statutory consequence, a specific frequency band, or a specific evidence-backed catch-rate — and then walks through three worked case studies of what happens when a scale is not anchored.

The anchor problem — why generic 1-to-10 tables produce noise

Every reconciliation risk register runs on three axes. Severity measures the consequence of the failure mode if it lands. Occurrence measures how often the failure mode fires under the current prevention control. Detection measures the probability that the current detection control catches the failure before it reaches the counterparty, the tax authority, or the statutory auditor. Together the three axes produce the Action Priority ranking that drives the remediation queue.

The failure of a generic 1-to-10 scale is not in the axes themselves. It is in what “8” means. In a generic table, Severity 8 is described as “high consequence” or “material” — words that mean different things to a controller, a tax head, and an internal auditor sitting in the same room. Occurrence 5 is described as “moderately common” or “happens sometimes” — words whose interpretation swings with the volume base and the reviewer’s own experience. Detection 5 is described as “moderate probability of catch” — a value that most analysts converge on by default because it is the safest rating to defend.

The consequence of this drift is systematic. Severity ratings compress toward the middle of the scale because 10 feels reserved for something that has never happened and 1 feels reserved for something that cannot happen. Occurrence and Detection ratings compress similarly. And when three compressed ratings are multiplied into a Risk Priority Number, or averaged, or otherwise reduced to a single score, the resulting Action Priority ranking is barely more informative than a random sort — every row lands somewhere between 60 and 200, and the threshold for intervention becomes a discussion of which rows the team has capacity to work on this quarter rather than which rows carry the highest exposure to a permanent statutory loss.

The anchored scale eliminates that drift. Every rating on every axis is tied to a specific, named, verifiable state of the world that any two analysts can agree on before they walk the register.

Severity — anchored to Indian statutory consequences

The Severity scale below anchors every rating to a specific Indian consequence — a statute, a notice regime, or an accounting standard. A rating is justified only when the failure mode’s effect maps to the named consequence.

RatingAnchorConsequence in plain terms
10Section 16(4) permanent ITC loss on the 30 November cutoff; Section 40(a)(ia) 30 percent expenditure disallowance; Section 74 fraudulent-ITC recovery with equivalent penaltyPermanent statutory loss with no rectification, no condonation of delay, and no revival path. The Section 16(4) time-bar guide covers the mechanics.
9Section 200A demand notice served on the deductor with interest under Section 201(1A) at 1 percent per month for short-deduction and 1.5 percent per month for short-payment, plus Section 234E late-filing fee at Rs 200 per day capped at the tax deductible amountCash outflow with a recovery mechanism that is slow, expensive, or uncertain. Section 195 mis-tagging on non-resident payments falls here, and so does a Section 143(1) intimation adjustment for a deductee under-credit.
8DRC-01B intimation under Rule 88C with a seven-day reply window; DRC-01C intimation under Rule 88D on the GSTR-2B versus GSTR-3B stream; CARO 2020 material weakness finding on internal financial controls; GSTR-9C three-way mismatch requiring justificationNotice or audit finding that carries a hard deadline and a public reporting consequence. The DRC-01B reply guide walks through the seven-day mechanics.
7Section 43B(h) year-end MSME disallowance for payments beyond 45 days (written agreement) or 15 days (no agreement) not settled by 31 March; Section 194Q buyer’s TDS obligation missed on aggregate purchases above Rs 50 lakh; expenditure recognised in the wrong period; provision not bookedTaxable-income adjustment or misstatement that surfaces at year-end and requires a corrective entry or a book-side re-statement.
6CARO 2020 Clause 3(ii)(b) audit observation on bank/working-capital reconciliation reported in the management letter without escalation to material weakness; Section 39(9) time-barred GST amendment beyond the 30 November window; ledger-level exception that distorts monthly reportingAuditor observation without formal qualification; internal-control weakness that carries reputational cost but no immediate statutory consequence.
5Section 201(1A) TDS interest accrued but not disputed; Section 234B/234C advance-tax interest on the deductee side from an under-credit; monthly close variance investigated after filing; late supplier follow-up on Rule 37A watchlistCash-flow cost or working-capital drag; interest paid or foregone; time lost in the following period’s close.
4Ind AS 21 foreign-exchange restatement on a monetary item at period-end; permitted rounding difference under CBIC clarifications; presentation reclassification between line items on the same statementRequired accounting recognition that is neither a loss nor a mis-statement; the failure mode is a presentation-level adjustment.
3Petty variance below the enterprise’s own materiality floor of Rs 5,000 per invoice; format-level error caught at reviewer stage; column mis-labelled on the working paperImmaterial exception cleared inside the close cycle by the preparer or the reviewer.
2Cosmetic file-naming convention deviation; missing hyperlink on the reconciliation memo; minor formatting on the exception listNuisance-level exception; no financial or reporting consequence.
1Preventable by design; a failure mode the process cannot produce because a system constraint or a policy rule forbids the underlying conditionThe failure cannot occur.

Severity is re-rated only when a statute or a portal rule changes. The shift from the legacy Section 194x identifiers to the Section 393 four-digit payment codes 1001 to 1092 from 1 April 2026 altered the Severity anchor for cross-era TDS misclassification because the correction-window mechanics themselves changed — the correction deadline for FY 2025-26 residual filings closes on 31 March 2027, and the cross-era mapping window itself is a new Severity-9 surface. The TDS reconciliation failure modes guide catalogues the cross-era failure modes in detail.

Occurrence — anchored to incidents per one thousand transactions

Occurrence is measured on the process as it actually operates, not as it would operate under a hypothetical better control. The rating is the observed incident count per one thousand transactions of the same type in the prior four quarters — the same PAN, the same section or payment code, the same portal, the same bank narration structure.

RatingAnchorFrequency band
10More than 100 incidents per 1,000 transactionsHappens on the majority of transactions of this type. No prevention control in place.
950 to 100 incidents per 1,000 transactionsKnown to the team as a routine occurrence; escalated verbally but not systematically prevented.
825 to 50 incidents per 1,000 transactionsOccurs once a month or more frequently on a stream of moderate volume.
710 to 25 incidents per 1,000 transactionsReproducible under known conditions — a specific counterparty, a specific bank format, a specific portal state.
65 to 10 incidents per 1,000 transactionsOccurs once a quarter on a stream of typical volume.
55 to 25 incidents per 1,000 transactions when the underlying condition occursThe base rate is the anchor for a stream where the analyst has personally seen the failure mode.
41 to 5 incidents per 1,000 transactionsOccurs once a year or less, but the analyst has documented at least one instance.
3Under 1 incident per 1,000 transactionsPrevented by a written policy or a documented cadence; the analyst has not seen it in the current cycle.
2Under 1 incident per 10,000 transactionsPrevented by a system-enforced rule — the ERP will not post the failure state; the field is a computed formula.
1Fewer than 1 incident per 10,000 transactions with a hard system constraintEffectively impossible under current process design.

The tightening between rating 5 and rating 2 is not arbitrary — it maps to the difference between a manual policy discipline (10-to-1 gain on Occurrence) and a system-enforced constraint (100-to-1 gain on Occurrence). The Occurrence axis is where the register’s discussion of prevention controls actually happens, because moving a row from Occurrence 8 to Occurrence 3 is the payoff on a policy re-write, and moving it from Occurrence 3 to Occurrence 1 is the payoff on an ERP configuration.

Detection — anchored to catch-rate through the current control layer

Detection measures the probability that the current detection control catches the failure inside the reconciliation cycle, before it reaches the counterparty, the tax authority, or the statutory auditor. The rating is an empirical catch-rate observed on the sample the reconciliation actually walks.

RatingAnchorCatch-rate through the current control
10No detection control. The failure will only surface when a notice arrives or a stakeholder complainsBelow 30 percent — effectively pure luck (a stakeholder happens to spot the invoice; a supplier follows up on a payment they were expecting)
9Manual self-review by the preparer; no second pair of eyes30 to 40 percent — the preparer catches obvious errors but has no framework for finding subtle ones
8Preparer plus a rubber-stamp reviewer with no checklist40 to 55 percent — the reviewer signs off on batches rather than individual items
7Independent peer review sample-based at 10 to 20 percent of the register55 to 65 percent — sampling catches routine failures but misses low-frequency patterns
6Independent peer review sample-based at 30 to 50 percent of the register with a documented checklist65 to 75 percent — the checklist catches structural failure modes
5Manual sample-based tick-and-tie by an independent reviewer at year-end plus a ratio or reasonableness test60 to 75 percent — the ratio test catches aggregate drift that item-level sampling misses
4Multi-layer detection — sample-based peer review plus a ratio test plus a documented aging queue for anything unresolved past a threshold75 to 85 percent — the aging queue closes the gap on failures that persist across cycles
3Multi-layer detection at full population — automated portal-side match plus peer review plus aging queue with escalation trigger85 to 95 percent — the automated match catches high-volume failure modes at population scale
2Continuous detection layer — every incoming document reviewed against every reconciliation dimension at ingestion, with automated escalation95 to 99 percent — the continuous layer catches nearly every failure before the cycle closes
1System-enforced constraint — the ERP cannot post the failure state because the field is a validation gate99 percent-plus — the failure cannot enter the system in the first place

Detection is where a manual reconciliation control tops out. The rating gain from moving from D5 (manual sample-based tick-and-tie) to D3 (multi-layer detection at full population) is 20 to 25 percentage points of catch-rate — the difference between catching two-thirds of the failure modes and catching nine-tenths of them. On a Severity-10 row, that gain is the difference between a Section 16(4) permanent loss that lands and a Section 16(4) permanent loss that is caught inside the reconciliation cycle.

Case study 1 — the materiality-cutoff trap

A mid-market Indian manufacturer with a ₹40 crore annual GST-eligible purchase base runs a Rs 5,000-per-invoice materiality floor on variance investigation. Any invoice with a GSTR-2B versus purchase-register variance below Rs 5,000 in ITC is auto-cleared without investigation and rolled into the accepted-variance bucket at close. The controller has anchored the materiality-floor rule to Severity 3 on the register — “petty variance below the enterprise’s own materiality floor” — and the risk register categorises it as Low Action Priority.

In FY 2025-26, one supplier with an aggregate annual spend of Rs 8 lakh files no GSTR-1 for four months. The supplier’s monthly invoice runs at Rs 47,236 in ITC. Each individual invoice sits below the enterprise’s materiality floor and is auto-cleared. On 30 November 2026, the Section 16(4) cutoff fires. Four months of ITC — cumulatively Rs 1.89 lakh — is permanently lost. The register’s Severity-3 rating was wrong. The failure mode was not “petty variance below materiality floor” — it was “Section 16(4) permanent ITC loss on the November 30 cutoff”, and the anchor for that failure mode is Severity 10.

The badly-anchored scale had collapsed two different failure modes into a single rating because both produced sub-materiality variance in the current period. The anchored scale distinguishes them at the Severity axis — a Rs 4,900 variance from a paise-level rounding difference is Severity 3 (Ind AS-permissible rounding), but a Rs 4,900 variance from a supplier GSTR-1 non-filing is Severity 10, because the sub-materiality current-period value compounds into a Section 16(4) permanent-loss cumulative value across the ageing window. Materiality is not a Severity anchor. The consequence is.

The re-rating. The failure mode is split into two rows on the register — “paise-level rounding difference within CBIC-permissible tolerance” (S3, O10, D2, Low AP) and “sub-materiality supplier GSTR-1 non-filing compounding across ageing window” (S10, O5, D8, High AP). The prevention control is a per-supplier ageing queue keyed to earliest-Section 16(4)-deadline, not a per-invoice materiality filter.

Case study 2 — the multiplicative-RPN trap on a rare foreign-remittance mis-tag

A ₹800 crore IT services enterprise runs a Section 195 foreign-remittance ledger with roughly 40 non-resident vendor payments per year — an average of one every ten working days. The risk register uses a multiplicative Risk Priority Number with an intervention threshold at RPN 100. The failure mode “Section 195 non-resident payment mis-tagged to a resident payment code” is rated Severity 9 (Section 200A demand analogue with cross-border withholding exposure), Occurrence 2 (happens on fewer than 1 in 40 non-resident payments), Detection 4 (peer review catches most mistakes at end-of-quarter close). RPN = 72. Below threshold. Not in the High Action Priority queue.

In Q3 FY 2026-27, a single ₹1.4 crore payment to a non-resident consulting firm is mis-tagged to code 1027 (Section 194J domestic professional fees) instead of code 1057 (Section 195 non-resident payment). The Form 26Q filing under Rule 31A reports it as a domestic deduction. The Form 27Q filing does not report it at all. Six months later, the deductee’s own income-tax processing under Section 143(1) at the non-resident’s CBDT circle surfaces the missing withholding. The demand on the deductor lands at Rs 4.7 lakh in Section 201(1A) interest plus a disallowance exposure under the Income-tax Act 2025 for the underlying expenditure.

The multiplicative RPN had systematically under-prioritised the row because it multiplied a high Severity (9) by a low Occurrence (2) and produced a middle-of-the-pack score. The TDS reconciliation failure modes analysis documents Section 195 mis-tagging as a High Action Priority failure mode precisely because a low occurrence on a low-volume stream does not lower the Severity of the consequence when it does land.

The re-rating. Severity-first prioritisation puts the row at High Action Priority regardless of the Occurrence 2 rating. The prevention control is a resident-versus-non-resident scan at vendor master onboarding with a hard validation gate at PO issue time. The detection control is a monthly Section 195 register walk against the deductor’s Form 27Q filing, with every payment to a non-resident PAN cross-checked against the payment code applied.

Case study 3 — the un-anchored occurrence rating that hid an IMS default-accept path

A pharmaceutical distributor with a ₹300 crore annual GST-eligible purchase base uses the Invoice Management System introduced on the GST portal in October 2024. Roughly 4,000 inbound documents flow through IMS every month across 220 suppliers. The controller’s risk register carries the row “IMS action defaulted to Accept on a wrongly-issued invoice” at Severity 9 (Section 74 fraud recovery with interest and penalty), Occurrence 3 (“we haven’t seen it in nine months of IMS”), Detection 6 (weekly IMS dashboard review with a two-eyes sign-off). Medium Action Priority.

The Occurrence rating was not anchored to a frequency band. It was anchored to the analyst’s personal recollection — “we haven’t seen it”. In the same nine-month window, the industry base rate for IMS Default-Accept exposure on a supplier base of 200-plus at 4,000 documents per month is measured across published industry data at 5 to 25 incidents per 1,000 documents — an anchored Occurrence 5. The register’s Occurrence 3 was a two-notch under-rating.

In month ten, a compromised supplier submits three duplicate invoices totalling Rs 2.8 lakh in ITC. The weekly IMS review misses them because the reviewer is on leave and the two-eyes sign-off is skipped for one cycle. Default-Accept fires. The invoices flow into GSTR-2B. The ITC is availed in GSTR-3B. Ninety days later, the fraud is surfaced by the supplier’s own investor complaint, and the enterprise faces a Section 74 recovery notice for the Rs 2.8 lakh plus 18 percent Section 50 interest plus a penalty at CBIC’s discretion.

The anchored Occurrence 5 would have put the row at High Action Priority — S9, O5, D6 — and the prevention control would have been a mandatory two-reviewer whitelist rather than an optional two-eyes sign-off, plus a monthly IMS-Accept audit against the vendor master. The GSTR-2B ITC reconciliation failure modes analysis treats IMS Default-Accept as a High Action Priority row on any purchase base above roughly 200 suppliers precisely because the industry base rate cannot be defeated by nine months of personal recollection.

The re-rating. Occurrence is re-anchored to 5 on the industry base rate. Action Priority becomes High. The prevention control becomes a whitelist-gated Accept action with mandatory two-reviewer approval on documents above a threshold PO value.

Where a well-anchored SOD scale meets the manual capacity ceiling

An anchored SOD scale sharpens the register — it surfaces the High Action Priority rows that a badly-anchored scale had systematically hidden. But sharpening the register also raises the demand on the detection layer. A register that surfaces the Section 16(4) permanent-loss queue on every quarter’s close needs a detection control that walks every at-risk invoice through an ageing band and an escalation state on a rolling basis. A register that surfaces the Section 195 non-resident mis-tag queue needs a monthly cross-check against Form 27Q at the payment-code level. A register that surfaces the IMS Default-Accept queue needs a whitelist-gated Accept flow refreshed daily.

Below a certain volume, the manual detection layer sustains this discipline. Above roughly 200 vendors, or above roughly 3,000 purchase invoices per month, or on a multi-GSTIN structure with more than three GSTINs, the manual detection layer stops being economically viable — the reviewer capacity required to walk every High Action Priority row through its prevention and detection controls exceeds what a finance team member can sustain across a close cycle that compresses the Rule 37 ageing walk, the Rule 37A annual walk, and the Section 16(4) November lockdown walk into the same September-to-November window. The anchored scale has done its job — it has named the exposure. The next question is whether a manual layer can close it.

Terra Insight’s reconciliation software surface carries the continuously-refreshed detection layer that the anchored SOD scale demands on High Action Priority rows — the GST reconciliation software closes the Section 16(4) queue, the TDS reconciliation software closes the cross-era Section 393 queue, and the monthly close reconciliation playbook sequences the manual closes that a finance team runs alongside those layers on a common cadence.

Where this fits

Frequently Asked Questions

Why does a multiplied Risk Priority Number — Severity times Occurrence times Detection — fail on Indian reconciliation risks?

A multiplicative Risk Priority Number treats a Severity-10 permanent loss with low occurrence the same as a Severity-3 nuisance with high occurrence — both can produce identical scores of, say, 60. For a Section 16(4) November 30 permanent Input Tax Credit loss, that arithmetic hides the failure mode behind the intervention threshold precisely when it matters most, because Section 16(4) exposures are always low-occurrence by design — they emerge on a small number of laggard suppliers each quarter. A team using an RPN of 100 as the escalation threshold will typically skip every Section 16(4) risk in the register, because its typical RPN of 10 (Severity 10, Occurrence 1, Detection 1) sits below the threshold. The Terra Insight framework rejects the RPN entirely and prioritises on Severity first — any Severity-9 or Severity-10 row is High Action Priority regardless of Occurrence and Detection. Occurrence and Detection then determine the depth of the required control, not whether the row deserves attention at all.

What makes a scale “anchored” rather than generic?

An anchored scale ties every rating on the 1-to-10 axis to a specific, named, verifiable consequence that any two analysts in the same room would agree on. Severity 10 is not “catastrophic” — it is “Section 16(4) permanent ITC loss on the November 30 cutoff, with no rectification path”. Severity 8 is not “material” — it is “DRC-01B intimation served with a seven-day reply window under Rule 88C”. Occurrence 5 is not “sometimes” — it is “five to twenty-five incidents per one thousand transactions of this type in the prior four quarters”. Detection 5 is not “moderate” — it is “sixty to seventy-five percent catch-rate through manual sample-based tick-and-tie”. Anchored ratings eliminate the noise that generic tables produce, and they make the register defensible in a statutory audit under Section 143(3)(i) of the Companies Act, because the auditor can independently verify every rating against a documented anchor rather than an analyst’s personal interpretation.

Should Occurrence be rated on the current process, or on a best-practice process?

On the current process. Occurrence is a measurement of what has actually happened in the prior four quarters, not what would happen under a hypothetical better control. Rating Occurrence on best-practice systematically under-estimates the failure rate and mis-prioritises the register — a Rule 37A supplier non-filing risk rated Occurrence 2 because “we would spot that on a well-run supplier watchlist” is a wrong rating when the actual watchlist is refreshed once a quarter and the supplier base has doubled since the last refresh. The correct posture is to rate Occurrence on the process as it operates today, hold Severity at its anchored value, and let the resulting High Action Priority ranking drive the case for either strengthening the prevention control (which lowers Occurrence) or the detection control (which lowers Detection) in the next quarter. Re-rating happens quarterly with actual incident data as the input.

How does the Detection scale map to the “who catches it first” question?

The Detection scale is anchored to the probability that a failure is caught inside the reconciliation process, before it reaches the counterparty, the tax authority, or the statutory auditor. Detection 1 is an automated system-enforced constraint — the ERP simply will not post an invoice without a valid PAN-and-payment-code combination, so the failure mode cannot occur. Detection 3 is a two-layer control — an automated portal-side match plus an independent peer review plus an ageing queue that escalates on threshold breach. Detection 5 is a manual sample-based tick-and-tie at the end of the cycle, catching roughly sixty to seventy-five percent of failures. Detection 8 is a self-review by the preparer with no independent second pair of eyes. Detection 10 is no control at all — the failure only surfaces when a notice arrives from CPC-TDS, a DRC-01B lands on the GSTN portal, or the statutory auditor asks for the reconciliation evidence. A Severity-10 row with Detection 8 is the most dangerous combination on the register, because the consequence is permanent and the process has no capacity to see it coming.

When does a badly-anchored SOD scale become a defensible audit finding rather than an internal process weakness?

When the statutory auditor’s testing under Section 143(3)(i) of the Companies Act — the Internal Financial Controls over Financial Reporting opinion — uncovers a High Action Priority failure mode that the enterprise’s own risk register had rated as Low or Medium because the SOD anchors were undocumented or inconsistent. At that point the auditor’s finding is not that the reconciliation failed — that is a testing outcome that can happen even to a well-designed control — but that the enterprise’s risk-assessment methodology itself is unreliable. That is a finding on control design, not control operation, and it typically produces a material weakness observation in ICFR because the failure mode that drove the underlying loss was foreseeable and was foreseen but was mis-prioritised. The remedy is to publish the anchored SOD scale in the reconciliation policy document, walk every existing High Action Priority failure mode through the anchors, and route the re-rated register through the audit committee for adoption. The reconciliation control plan template carries the anchored scale as the default configuration.

Terra Insight
Terra Insight Editorial Team Reconciliation Infrastructure

Content authored by practitioners with experience at Amazon India, Intuit QuickBooks, and the Tata Group. Meet the team →

Published 4 August 2026
Domain expertise
TDS Reconciliation GST Input Credit Platform Settlements NACH Batch Matching Bank Reconciliation Form 26AS Matching ERP Integrations Enterprise Finance Ops
Primary reference: CBIC GST portal — for Section 16(4) time bar, DRC-01B mismatch notice framework under Rule 88C, DRC-01C ITC mismatch under Rule 88D, and Section 74 fraud-recovery provisions that anchor the Severity scale in this article..
Primary sources cited
Last reviewed against sources on 4 August 2026
  • Section 16(4), Central Goods and Services Tax Act 2017 — Time limit for availing Input Tax Credit. A registered person shall not be entitled to take ITC in respect of any invoice or debit note after the 30th day of November following the end of the financial year to which such invoice pertains, or furnishing of the relevant annual return, whichever is earlier. The Finance Act 2022 shifted the deadline from 30 September to 30 November and applied the extension retrospectively from 1 July 2017. There is no rectification, no condonation of delay, and no recovery mechanism. This is the Severity-10 anchor on the anchored SOD scale — permanent statutory loss with no revival path.
  • Section 200A read with Section 201(1A) and Section 234E, Income-tax Act 1961 (retained in Income-tax Act 2025) — Processing of the deductor's TDS statement by the Central Processing Centre. Any short-deduction or short-payment identified in that processing becomes a demand notice, with interest under Section 201(1A) accruing at 1 percent per month for short-deduction and 1.5 percent per month for short-payment from the date the tax was deductible until the date of deposit, and Section 234E late-filing fee at Rs 200 per day of delay capped at the tax deductible amount. This is the Severity-9 anchor on the SOD scale.
  • Rule 88C and Form DRC-01B, Central Goods and Services Tax Rules 2017 — Where the tax liability declared in GSTR-1 for a tax period exceeds the tax paid in GSTR-3B for the same period by an amount and percentage as specified, an intimation in Form GST DRC-01B is auto-generated to the registered person. The recipient shall either pay the differential amount with applicable interest under Section 50 through Form GST DRC-03 or furnish a reply within seven days of receipt, failing which recovery proceedings under Section 79 may be initiated. The seven-day reply window is the Severity-8 anchor for the GSTR-1 vs GSTR-3B stream.
  • Section 43B(h), Income-tax Act 1961 (retained in Income-tax Act 2025) — Effective 1 April 2024, any sum payable by an assessee to a micro or small enterprise beyond the time limit specified in Section 15 of the Micro, Small and Medium Enterprises Development Act 2006 — 45 days where there is a written agreement, 15 days where there is none — is disallowed as an expense in the year of accrual and allowed only in the year of actual payment. Non-payment by 31 March of the relevant financial year converts a routine payables balance into a year-end taxable-income adjustment. This is the Severity-7 anchor on the SOD scale — a tax-cost consequence that is time-limited to the financial-year boundary.
  • Companies (Auditor's Report) Order 2020, Clause 3(ii)(b) — The auditor is required to report on whether the company has been sanctioned working capital limits in excess of five crore rupees, in aggregate, from banks or financial institutions on the basis of security of current assets, and whether the quarterly returns or statements filed by the company with such banks or financial institutions are in agreement with the books of account. A reportable observation without material weakness — the auditor notes a reconciliation control gap in the management letter without escalating it in the main audit report — is the Severity-6 anchor. A material weakness finding is the Severity-8 anchor.
  • Rule 88D and Form DRC-01C, Central Goods and Services Tax Rules 2017 — Where the Input Tax Credit availed in GSTR-3B for a tax period exceeds the ITC available in GSTR-2B for the same period by the prescribed amount and percentage, an auto-generated intimation in Form GST DRC-01C is served. The recipient shall either pay the differential through Form GST DRC-03 with interest under Section 50 or furnish a reply within the prescribed period. Recovery under Section 79 follows non-compliance. DRC-01C is the Severity-8 anchor on the GSTR-2B stream.
  • Ind AS 21, The Effects of Changes in Foreign Exchange Rates — Foreign currency monetary items shall be translated using the closing exchange rate at each reporting date, and exchange differences arising on settlement or on translation of monetary items shall be recognised in profit or loss in the period in which they arise. Reconciliation of foreign-currency receivables and payables against a bank remittance or a settlement advice produces a routine translation variance at each period-end. This variance is neither a loss nor a mis-statement — it is a required accounting recognition. Its correct rating on the SOD scale is Severity 4, because the effect is a presentation adjustment rather than a statutory or audit consequence.

Frequently Asked Questions

Why does a multiplied Risk Priority Number — Severity times Occurrence times Detection — fail on Indian reconciliation risks?
A multiplicative Risk Priority Number treats a Severity-10 permanent loss with low occurrence the same as a Severity-3 nuisance with high occurrence — both can produce identical scores of, say, 60. For a Section 16(4) November 30 permanent Input Tax Credit loss, that arithmetic hides the failure mode behind the intervention threshold precisely when it matters most, because Section 16(4) exposures are always low-occurrence by design — they emerge on a small number of laggard suppliers each quarter. A team using an RPN of 100 as the escalation threshold will typically skip every Section 16(4) risk in the register, because its typical RPN of 10 (Severity 10, Occurrence 1, Detection 1) sits below the threshold. The Terra Insight framework rejects the RPN entirely and prioritises on Severity first — any Severity-9 or Severity-10 row is High Action Priority regardless of Occurrence and Detection. Occurrence and Detection then determine the depth of the required control, not whether the row deserves attention at all.
What makes a scale 'anchored' rather than generic?
An anchored scale ties every rating on the 1-to-10 axis to a specific, named, verifiable consequence that any two analysts in the same room would agree on. Severity 10 is not 'catastrophic' — it is 'Section 16(4) permanent ITC loss on the November 30 cutoff, with no rectification path'. Severity 8 is not 'material' — it is 'DRC-01B intimation served with a seven-day reply window under Rule 88C'. Occurrence 5 is not 'sometimes' — it is 'five to twenty-five incidents per one thousand transactions of this type in the prior four quarters'. Detection 5 is not 'moderate' — it is 'sixty to seventy-five percent catch-rate through manual sample-based tick-and-tie'. Anchored ratings eliminate the noise that generic tables produce, and they make the register defensible in a statutory audit under Section 143(3)(i) of the Companies Act, because the auditor can independently verify every rating against a documented anchor rather than an analyst's personal interpretation.
Should Occurrence be rated on the current process, or on a best-practice process?
On the current process. Occurrence is a measurement of what has actually happened in the prior four quarters, not what would happen under a hypothetical better control. Rating Occurrence on best-practice systematically under-estimates the failure rate and mis-prioritises the register — a Rule 37A supplier non-filing risk rated Occurrence 2 because 'we would spot that on a well-run supplier watchlist' is a wrong rating when the actual watchlist is refreshed once a quarter and the supplier base has doubled since the last refresh. The correct posture is to rate Occurrence on the process as it operates today, hold Severity at its anchored value, and let the resulting High Action Priority ranking drive the case for either strengthening the prevention control (which lowers Occurrence) or the detection control (which lowers Detection) in the next quarter. Re-rating happens quarterly with actual incident data as the input.
How does the Detection scale map to the 'who catches it first' question?
The Detection scale is anchored to the probability that a failure is caught inside the reconciliation process, before it reaches the counterparty, the tax authority, or the statutory auditor. Detection 1 is an automated system-enforced constraint — the ERP simply will not post an invoice without a valid PAN-and-payment-code combination, so the failure mode cannot occur. Detection 3 is a two-layer control — an automated portal-side match plus an independent peer review plus an ageing queue that escalates on threshold breach. Detection 5 is a manual sample-based tick-and-tie at the end of the cycle, catching roughly sixty to seventy-five percent of failures. Detection 8 is a self-review by the preparer with no independent second pair of eyes. Detection 10 is no control at all — the failure only surfaces when a notice arrives from CPC-TDS, a DRC-01B lands on the GSTN portal, or the statutory auditor asks for the reconciliation evidence. A Severity-10 row with Detection 8 is the most dangerous combination on the register, because the consequence is permanent and the process has no capacity to see it coming.
When does a badly-anchored SOD scale become a defensible audit finding rather than an internal process weakness?
When the statutory auditor's testing under Section 143(3)(i) of the Companies Act — the Internal Financial Controls over Financial Reporting opinion — uncovers a High Action Priority failure mode that the enterprise's own risk register had rated as Low or Medium because the SOD anchors were undocumented or inconsistent. At that point the auditor's finding is not that the reconciliation failed — that is a testing outcome that can happen even to a well-designed control — but that the enterprise's risk-assessment methodology itself is unreliable. That is a finding on control design, not control operation, and it typically produces a material weakness observation in ICFR because the failure mode that drove the underlying loss was foreseeable and was foreseen but was mis-prioritised. The remedy is to publish the anchored SOD scale in the reconciliation policy document, walk every existing High Action Priority failure mode through the anchors, and route the re-rated register through the audit committee for adoption. The [reconciliation control plan template](/insights/reconciliation-control-plan-template-india/) carries the anchored scale as the default configuration.

See how TransactIG handles reconciliation for your industry

Configuration takes 2–4 weeks. No code development required. ISO 27001:2022 certified.