CARO 2020 & Internal Financial Controls — What Your Procurement and Asset Records Need
Reviewed by CA Kiren Kumar K · Published April 4, 2026 · Updated July 7, 2026
CARO 2020 Clause 3(i) requires a company to keep proper records of fixed assets with quantitative details and location, to physically verify those assets at reasonable intervals, and to investigate and account for any discrepancies. Where these are missing, the statutory auditor reports the adverse position in the CARO annexure to the audit report (issued under Section 143(11)).
Two of the most common areas where auditors raise observations relate to fixed asset records and procurement controls. CARO 2020 requires the auditor to report on whether the company maintains proper records of its property, plant and equipment. The Companies Act requires the auditor to report on whether the company has adequate internal financial controls. And since April 2023, every company using software to maintain its books must ensure that software has a tamper-proof audit trail.
This article covers what these requirements are, which companies they apply to, what controls auditors look for, and what happens when gaps are found.
Facing these observations in your own audit? Kiren & Co (FRN 031392S) takes CARO 3(i) and internal-financial-controls readiness as a professional engagement — assessing your asset records and procurement controls, designing the gaps closed, and operationalising them using ProcureTrail as the instrument, with continuing involvement. Discuss your requirement →
1. CARO 2020 — Clause 3(i): Fixed Asset Records
The Companies (Auditor's Report) Order, 2020 requires the statutory auditor to report on several matters related to property, plant and equipment (PPE). Clause 3(i) specifically asks:
- Whether the company maintains proper records showing full particulars — including quantitative details and situation (location) — of its PPE
- Whether the PPE has been physically verified by the management at reasonable intervals
- Whether any material discrepancies were noticed during such verification and if so, whether they have been properly dealt with in the books
- Whether title deeds of all immovable properties are held in the name of the company
What "proper records" means in practice
The auditor expects to see, for each asset: a unique identifier, description, classification, cost of acquisition, date of acquisition, location (building, floor, room), department, custodian, depreciation method and rate, accumulated depreciation, and written-down value. An Excel sheet with "Laptop - Rs 50,000 - IT Dept" does not meet this standard. A structured register that tracks all these fields from the point of procurement is what the auditor expects.
Does CARO apply to your company?
CARO 2020 applies to all companies except banking, insurance, and Section 8 companies. Private limited companies are exempt only if they satisfy all three conditions simultaneously:
| Condition | Threshold |
|---|---|
| Paid-up capital + reserves and surplus | Does not exceed Rs 1 crore |
| Borrowings from banks / financial institutions | Does not exceed Rs 1 crore at any point during the FY |
| Total revenue (including discontinued operations) | Does not exceed Rs 10 crore |
If any one of these is breached, CARO applies in full. Small companies (paid-up capital up to Rs 4 crore and turnover up to Rs 40 crore) have a broader exemption.
How auditors judge "reasonable intervals" for verification
Clause 3(i)(b) does not fix a frequency — it requires physical verification at "reasonable intervals" and leaves the interval to management's judgement. In practice auditors assess reasonableness against three factors: the size and spread of the asset base, the mobility and risk of the assets (laptops and tools walk; buildings do not), and whether the programme actually covers the whole register within a defined cycle. For government bodies the benchmark is explicit — Rule 213 of the General Financial Rules (GFR) 2017 requires verification at least once a year.
For a large register, a defensible programme is usually a phased cycle rather than a single annual sweep. Illustratively, a company with a 12,000-line register might verify high-mobility classes (IT equipment, tools, portable instruments) every year and lower-risk classes (plant, furniture, fixtures) on a rolling two-to-three-year cycle — so every asset is physically sighted at least once per cycle, with the high-risk pool sighted annually. What the auditor wants is not a particular number but a documented policy, a schedule that is actually followed, and a reconciliation of what each round found. A programme that exists on paper but produces no dated verification records and no discrepancy reconciliation is treated as no programme at all. See asset verification for the underlying definition, and the physical verification guide for how a campaign is run end to end.
The five limbs of Clause 3(i) — and what changed in 2020
CARO is issued under Section 143(11) of the Companies Act 2013 (the order itself is S.O. 849(E), applying from FY 2021-22). Clause 3(i) is reported on in five limbs, three of which were new or expanded in CARO 2020 — a clean record has to satisfy each:
| Limb | What the auditor reports on |
|---|---|
| 3(i)(a)(A) | Proper records of property, plant and equipment — full particulars, including quantitative details and situation. |
| 3(i)(a)(B) | Proper records of intangible assets — new in CARO 2020. |
| 3(i)(b) | PPE physically verified at reasonable intervals; material discrepancies dealt with in the books. |
| 3(i)(c) | Title deeds of immovable property held in the company's name (else a tabular disclosure). |
| 3(i)(d) | Revaluation of PPE/intangibles — whether it is based on a registered valuer; and the amount of change specified where that change is 10% or more of the net carrying value of a class — new in CARO 2020. |
| 3(i)(e) | Whether any Benami proceedings are initiated or pending — new in CARO 2020. |
The records that satisfy these limbs are the same ones the accounting standards require: recognition, cost, depreciation and derecognition of property, plant and equipment are governed by AS 10 for entities on Indian GAAP and Ind AS 16 for Ind AS entities. The auditor's procedures for the clause follow the ICAI Guidance Note on CARO 2020 (revised 2022), which sets out, limb by limb, the verification and reporting expectations — including that "reasonable intervals" is judged on the size, nature and risk of the asset base, not a fixed frequency.
Does an ERP or accounting fixed-asset module satisfy Clause 3(i)?
A common assumption is that because the accounting or ERP system carries a fixed-asset module, Clause 3(i) is already met. The module records the financial life of an asset — its cost, its depreciation, its written-down value, its disposal — and posts these to the general ledger. What it does not do is confirm the asset still physically exists. It will keep depreciating a machine every month whether or not that machine was scrapped two years ago; that is how "ghost assets" — fully carried in the books, physically long gone — accumulate.
Clause 3(i)(a) can largely be met inside such a module if its per-unit quantitative and location fields are actually maintained. But Clause 3(i)(b) is a separate limb, and it asks for something an accounting record cannot supply on its own: evidence that the assets were physically verified — the count, the date, who checked, the discrepancies noticed and how they were dealt with in the books. Where the module is used only for the accounting entries and physical verification happens on spreadsheets, or not at all, the 3(i)(b) limb is left unmet.
This is why organisations already running SAP, Oracle or Tally still keep a dedicated register and a physical-verification routine alongside the accounting system — SAP itself treats physical inventory of assets as a separate process. The register-and-verification layer captures the physical facts and feeds them back to the accounting system as structured entries; the two reconcile, and that reconciliation — physical count against register, register against written-down value — is the evidence Clause 3(i)(b) looks for.
Download: CARO 3(i) readiness checklist (PDF, one page) — a tick-box self-assessment covering clauses 3(i)(a) to 3(i)(e), reviewed by CA Kiren Kumar K, FCA.
2. Internal Financial Controls — Section 143(3)(i)
Section 143(3)(i) of the Companies Act 2013 requires the auditor to state whether the company has adequate internal financial controls (IFC) with reference to financial statements, and whether those controls are operating effectively.
Internal financial controls are defined under Section 134(5)(e) as the policies and procedures adopted by a company for:
- Orderly and efficient conduct of business
- Adherence to company policies
- Safeguarding of assets
- Prevention and detection of fraud and errors
- Accuracy and completeness of accounting records
- Timely preparation of reliable financial information
Does IFC audit apply to your company?
Private companies are exempt from IFC auditor reporting if both conditions are met:
| Condition | Threshold |
|---|---|
| Turnover (per latest audited financial statement) | Less than Rs 50 crore |
| Aggregate borrowings from banks / FIs / corporates | Less than Rs 25 crore at any point during the FY |
OPC and small companies are fully exempt. However, two important qualifications:
- The exemption is lost if the company has defaulted in filing financial statements under Section 137 or annual return under Section 92.
- Directors remain responsible regardless. Even if the auditor's IFC report is exempted, Section 134(5)(e) requires directors to state in the annual report that IFCs are adequate and operating effectively. There is no exemption from this directors' responsibility.
What IFC controls do auditors check on procurement and assets?
| Control area | What the auditor looks for |
|---|---|
| Purchase authorisation | Are purchases approved by authorised personnel before commitment to a vendor? |
| Segregation of duties | Are the people who request, approve, and receive goods different individuals? |
| GRN verification | Is physical receipt verified against the purchase order before payment is processed? |
| Invoice matching | Are vendor invoices matched to PO and GRN before payment — quantity, price, and tax? |
| Asset capitalisation | Are assets recorded in the register when acquired, with correct cost and classification? |
| Asset safeguarding | Are assets physically verified at reasonable intervals? Are discrepancies investigated? |
| Disposal controls | Are asset disposals authorised, recorded, and proceeds accounted for? |
These controls are not assessed in a vacuum. The auditor's reporting on internal financial controls under Section 143(3)(i) follows the ICAI Guidance Note on Audit of Internal Financial Controls over Financial Reporting, and draws on the Standards on Auditing — SA 315 (understanding the entity and its internal control, including the authorisation and segregation-of-duties controls over procurement) and SA 500 (audit evidence). It is also worth keeping the distinction clear: IFC under Section 134 is the broad framework the board is responsible for, while ICFR (internal financial controls over financial reporting) under Section 143(3)(i) is the narrower set the auditor actually reports on. A procurement and asset trail that enforces approval, segregation of duties, and a tamper-evident record is what lets the auditor conclude those controls are not only designed but operating.
3. The Audit Trail Requirement — Rule 3 of Companies (Accounts) Rules 2014
This is a requirement many organisations are still catching up with. Effective 1 April 2023, Rule 3(1) of the Companies (Accounts) Rules 2014 requires:
Every company which uses accounting software for maintaining its books of account shall use only such accounting software which has a feature of recording audit trail of each and every transaction, creating an edit log of each change made in books of account along with the date when such changes were made and ensuring that the audit trail cannot be disabled.
Key points:
- Applies to ALL companies — including OPC, small, dormant, and Section 8 companies. No exemption.
- "Books of account" under Section 2(13) includes records of all assets and liabilities. The fixed asset register is within scope.
- The audit trail must be preserved for 8 years (Section 128(5)).
- The auditor must separately report on audit trail compliance under Rule 11(g) of the Companies (Audit and Auditors) Rules 2014 — whether the feature was operational throughout the year, whether it was tampered with, and whether it was preserved.
What this means for Excel-based records
Excel does not have a built-in, tamper-proof audit trail. A cell can be edited, a row deleted, a formula changed — with no automatic record of who did it, when, or what the previous value was. Any company maintaining asset records, procurement records, or financial data in Excel spreadsheets does not satisfy this requirement.
This is not a technical interpretation — it is the plain reading of the rule. The software must record the trail. Excel does not.
4. Consequences for the Company and Its Directors
| Provision | What it covers | Penalty |
|---|---|---|
| Section 128(6) | Failure to maintain proper books of account | No company penalty. MD / WTD in charge of finance / CFO / person charged by the Board: fine Rs 50,000–5 lakh |
| Section 129(7) | Financial statements not giving true and fair view | Officer-only (no company penalty): MD / WTD in charge of finance / CFO — or, in their absence, all directors — imprisonment up to 1 year, or fine Rs 50,000–5 lakh, or both |
| Section 134(8) | False directors' responsibility statement (including IFC adequacy) | Company: Rs 50,000-25 lakh. Officers: imprisonment up to 3 years or fine Rs 50,000-5 lakh or both |
| Section 447 | Fraud (including fraudulent records) | Imprisonment 6 months to 10 years + fine 1x to 3x the fraud amount |
| Section 448 | False statement in any return, report, or financial statement | Imprisonment up to 2 years + fine Rs 50,000-5 lakh |
Beyond statutory penalties, the practical consequences matter more for most companies: a qualified audit report affects bank loan processing, investor due diligence, and vendor relationships. Banks review the CARO report and IFC opinion before sanctioning or renewing credit facilities.
5. Consequences for the Auditor
Auditors face their own consequences for inadequate reporting. These provisions are relevant because they explain why your statutory auditor is increasingly insistent on seeing proper records and controls.
| Provision | What it covers | Penalty |
|---|---|---|
| Section 147(1) | Contravention of audit provisions | Fine Rs 25,000 to Rs 5 lakh |
| Section 147(2) | Knowingly/wilfully with intent to deceive | Imprisonment up to 1 year + fine Rs 1-25 lakh |
| Section 143(12) | Failure to report fraud discovered during audit | Fine Rs 1 lakh to Rs 25 lakh |
| NFRA | Inadequate audit quality | Penalty up to 5x audit fees + debarment up to 10 years |
| ICAI | Professional misconduct | Removal from register up to 5 years + fine up to Rs 5 lakh |
NFRA has debarred 85 chartered accountants as of 2025 for audit failures — including cases involving inadequate control testing, failure to verify asset records, and baseless reports on internal financial controls. ICAI penalised 241 members in a single year — a record high. These are not theoretical risks.
6. What Good Records and Controls Look Like
When an auditor tests your procurement and asset records, they are looking for a system — not a collection of documents. The difference:
| What auditors ask | Without a system | With a governed system |
|---|---|---|
| "Show me the approval for this purchase" | Email thread, verbal confirmation | Approval matrix with frozen snapshot showing who approved, when, at what level |
| "Show me receipt was verified before payment" | Signed delivery challan in a file | GRN matched to PO with quantity, price, and condition recorded |
| "Show me your asset records" | Excel with asset name and cost | Register with 40+ fields — ID, location, custodian, classification, depreciation, acquisition trail |
| "Show me assets physically exist" | "We did a check last year" | Verification campaign report — who scanned, when, what condition, what was missing |
| "Show me disposals were authorised" | Board resolution | Disposal requisition with approval chain, asset value at disposal, proceeds recorded |
| "Show me the audit trail" | "We don't delete anything" | System-generated log of every change with user, timestamp, and before/after values |
7. Implementing These Controls
The requirements described in this article — CARO-compliant asset records, internal financial controls over procurement, and tamper-proof audit trails — are not about installing software. They are about putting a structured process in place:
- Define your approval structure: Who can request purchases? Who approves, and at what thresholds? Map this to an approval matrix with clear levels and dimensions.
- Govern the procurement chain: Every purchase follows PR → PO → GRN with each step requiring completion before the next. No ad-hoc purchases, no retroactive documentation.
- Maintain a structured asset register: Every asset has a complete record — identity, location, financial details, lifecycle status. Depreciation runs on defined schedules with year-end snapshots that cannot be modified.
- Verify physically: Tag assets with QR codes, run periodic verification campaigns, record what was found and what was missing. This directly satisfies CARO Clause 3(i).
- Match invoices: Before payment, the vendor's invoice is matched to the PO and GRN — quantity, price, and GST. Mismatches are resolved through a defined workflow, not ignored.
- Ensure the audit trail: Every action in the system — creation, approval, rejection, edit, posting, reversal — is logged with user, timestamp, and before/after values. The trail cannot be disabled or tampered with.
ProcureTrail supports this complete workflow. But the principle applies regardless of the tool — the statutory requirement is for controls and records, not for any specific software.