CARO 2020 & Internal Financial Controls — What Your Procurement and Asset Records Need

Reviewed by CA Kiren Kumar K · Published April 4, 2026 · Updated July 7, 2026

CARO 2020 Clause 3(i) requires a company to keep proper records of fixed assets with quantitative details and location, to physically verify those assets at reasonable intervals, and to investigate and account for any discrepancies. Where these are missing, the statutory auditor reports the adverse position in the CARO annexure to the audit report (issued under Section 143(11)).

Two of the most common areas where auditors raise observations relate to fixed asset records and procurement controls. CARO 2020 requires the auditor to report on whether the company maintains proper records of its property, plant and equipment. The Companies Act requires the auditor to report on whether the company has adequate internal financial controls. And since April 2023, every company using software to maintain its books must ensure that software has a tamper-proof audit trail.

This article covers what these requirements are, which companies they apply to, what controls auditors look for, and what happens when gaps are found.

Facing these observations in your own audit? Kiren & Co (FRN 031392S) takes CARO 3(i) and internal-financial-controls readiness as a professional engagement — assessing your asset records and procurement controls, designing the gaps closed, and operationalising them using ProcureTrail as the instrument, with continuing involvement. Discuss your requirement →

1. CARO 2020 — Clause 3(i): Fixed Asset Records

The Companies (Auditor's Report) Order, 2020 requires the statutory auditor to report on several matters related to property, plant and equipment (PPE). Clause 3(i) specifically asks:

What "proper records" means in practice

The auditor expects to see, for each asset: a unique identifier, description, classification, cost of acquisition, date of acquisition, location (building, floor, room), department, custodian, depreciation method and rate, accumulated depreciation, and written-down value. An Excel sheet with "Laptop - Rs 50,000 - IT Dept" does not meet this standard. A structured register that tracks all these fields from the point of procurement is what the auditor expects.

Does CARO apply to your company?

CARO 2020 applies to all companies except banking, insurance, and Section 8 companies. Private limited companies are exempt only if they satisfy all three conditions simultaneously:

ConditionThreshold
Paid-up capital + reserves and surplusDoes not exceed Rs 1 crore
Borrowings from banks / financial institutionsDoes not exceed Rs 1 crore at any point during the FY
Total revenue (including discontinued operations)Does not exceed Rs 10 crore

If any one of these is breached, CARO applies in full. Small companies (paid-up capital up to Rs 4 crore and turnover up to Rs 40 crore) have a broader exemption.

How auditors judge "reasonable intervals" for verification

Clause 3(i)(b) does not fix a frequency — it requires physical verification at "reasonable intervals" and leaves the interval to management's judgement. In practice auditors assess reasonableness against three factors: the size and spread of the asset base, the mobility and risk of the assets (laptops and tools walk; buildings do not), and whether the programme actually covers the whole register within a defined cycle. For government bodies the benchmark is explicit — Rule 213 of the General Financial Rules (GFR) 2017 requires verification at least once a year.

For a large register, a defensible programme is usually a phased cycle rather than a single annual sweep. Illustratively, a company with a 12,000-line register might verify high-mobility classes (IT equipment, tools, portable instruments) every year and lower-risk classes (plant, furniture, fixtures) on a rolling two-to-three-year cycle — so every asset is physically sighted at least once per cycle, with the high-risk pool sighted annually. What the auditor wants is not a particular number but a documented policy, a schedule that is actually followed, and a reconciliation of what each round found. A programme that exists on paper but produces no dated verification records and no discrepancy reconciliation is treated as no programme at all. See asset verification for the underlying definition, and the physical verification guide for how a campaign is run end to end.

The five limbs of Clause 3(i) — and what changed in 2020

CARO is issued under Section 143(11) of the Companies Act 2013 (the order itself is S.O. 849(E), applying from FY 2021-22). Clause 3(i) is reported on in five limbs, three of which were new or expanded in CARO 2020 — a clean record has to satisfy each:

LimbWhat the auditor reports on
3(i)(a)(A)Proper records of property, plant and equipment — full particulars, including quantitative details and situation.
3(i)(a)(B)Proper records of intangible assetsnew in CARO 2020.
3(i)(b)PPE physically verified at reasonable intervals; material discrepancies dealt with in the books.
3(i)(c)Title deeds of immovable property held in the company's name (else a tabular disclosure).
3(i)(d)Revaluation of PPE/intangibles — whether it is based on a registered valuer; and the amount of change specified where that change is 10% or more of the net carrying value of a class — new in CARO 2020.
3(i)(e)Whether any Benami proceedings are initiated or pending — new in CARO 2020.

The records that satisfy these limbs are the same ones the accounting standards require: recognition, cost, depreciation and derecognition of property, plant and equipment are governed by AS 10 for entities on Indian GAAP and Ind AS 16 for Ind AS entities. The auditor's procedures for the clause follow the ICAI Guidance Note on CARO 2020 (revised 2022), which sets out, limb by limb, the verification and reporting expectations — including that "reasonable intervals" is judged on the size, nature and risk of the asset base, not a fixed frequency.

Does an ERP or accounting fixed-asset module satisfy Clause 3(i)?

A common assumption is that because the accounting or ERP system carries a fixed-asset module, Clause 3(i) is already met. The module records the financial life of an asset — its cost, its depreciation, its written-down value, its disposal — and posts these to the general ledger. What it does not do is confirm the asset still physically exists. It will keep depreciating a machine every month whether or not that machine was scrapped two years ago; that is how "ghost assets" — fully carried in the books, physically long gone — accumulate.

Clause 3(i)(a) can largely be met inside such a module if its per-unit quantitative and location fields are actually maintained. But Clause 3(i)(b) is a separate limb, and it asks for something an accounting record cannot supply on its own: evidence that the assets were physically verified — the count, the date, who checked, the discrepancies noticed and how they were dealt with in the books. Where the module is used only for the accounting entries and physical verification happens on spreadsheets, or not at all, the 3(i)(b) limb is left unmet.

This is why organisations already running SAP, Oracle or Tally still keep a dedicated register and a physical-verification routine alongside the accounting system — SAP itself treats physical inventory of assets as a separate process. The register-and-verification layer captures the physical facts and feeds them back to the accounting system as structured entries; the two reconcile, and that reconciliation — physical count against register, register against written-down value — is the evidence Clause 3(i)(b) looks for.

Download: CARO 3(i) readiness checklist (PDF, one page) — a tick-box self-assessment covering clauses 3(i)(a) to 3(i)(e), reviewed by CA Kiren Kumar K, FCA.

2. Internal Financial Controls — Section 143(3)(i)

Section 143(3)(i) of the Companies Act 2013 requires the auditor to state whether the company has adequate internal financial controls (IFC) with reference to financial statements, and whether those controls are operating effectively.

Internal financial controls are defined under Section 134(5)(e) as the policies and procedures adopted by a company for:

Does IFC audit apply to your company?

Private companies are exempt from IFC auditor reporting if both conditions are met:

ConditionThreshold
Turnover (per latest audited financial statement)Less than Rs 50 crore
Aggregate borrowings from banks / FIs / corporatesLess than Rs 25 crore at any point during the FY

OPC and small companies are fully exempt. However, two important qualifications:

  1. The exemption is lost if the company has defaulted in filing financial statements under Section 137 or annual return under Section 92.
  2. Directors remain responsible regardless. Even if the auditor's IFC report is exempted, Section 134(5)(e) requires directors to state in the annual report that IFCs are adequate and operating effectively. There is no exemption from this directors' responsibility.

What IFC controls do auditors check on procurement and assets?

Control areaWhat the auditor looks for
Purchase authorisationAre purchases approved by authorised personnel before commitment to a vendor?
Segregation of dutiesAre the people who request, approve, and receive goods different individuals?
GRN verificationIs physical receipt verified against the purchase order before payment is processed?
Invoice matchingAre vendor invoices matched to PO and GRN before payment — quantity, price, and tax?
Asset capitalisationAre assets recorded in the register when acquired, with correct cost and classification?
Asset safeguardingAre assets physically verified at reasonable intervals? Are discrepancies investigated?
Disposal controlsAre asset disposals authorised, recorded, and proceeds accounted for?

These controls are not assessed in a vacuum. The auditor's reporting on internal financial controls under Section 143(3)(i) follows the ICAI Guidance Note on Audit of Internal Financial Controls over Financial Reporting, and draws on the Standards on Auditing — SA 315 (understanding the entity and its internal control, including the authorisation and segregation-of-duties controls over procurement) and SA 500 (audit evidence). It is also worth keeping the distinction clear: IFC under Section 134 is the broad framework the board is responsible for, while ICFR (internal financial controls over financial reporting) under Section 143(3)(i) is the narrower set the auditor actually reports on. A procurement and asset trail that enforces approval, segregation of duties, and a tamper-evident record is what lets the auditor conclude those controls are not only designed but operating.

3. The Audit Trail Requirement — Rule 3 of Companies (Accounts) Rules 2014

This is a requirement many organisations are still catching up with. Effective 1 April 2023, Rule 3(1) of the Companies (Accounts) Rules 2014 requires:

Every company which uses accounting software for maintaining its books of account shall use only such accounting software which has a feature of recording audit trail of each and every transaction, creating an edit log of each change made in books of account along with the date when such changes were made and ensuring that the audit trail cannot be disabled.

Key points:

What this means for Excel-based records

Excel does not have a built-in, tamper-proof audit trail. A cell can be edited, a row deleted, a formula changed — with no automatic record of who did it, when, or what the previous value was. Any company maintaining asset records, procurement records, or financial data in Excel spreadsheets does not satisfy this requirement.

This is not a technical interpretation — it is the plain reading of the rule. The software must record the trail. Excel does not.

4. Consequences for the Company and Its Directors

ProvisionWhat it coversPenalty
Section 128(6)Failure to maintain proper books of accountNo company penalty. MD / WTD in charge of finance / CFO / person charged by the Board: fine Rs 50,000–5 lakh
Section 129(7)Financial statements not giving true and fair viewOfficer-only (no company penalty): MD / WTD in charge of finance / CFO — or, in their absence, all directors — imprisonment up to 1 year, or fine Rs 50,000–5 lakh, or both
Section 134(8)False directors' responsibility statement (including IFC adequacy)Company: Rs 50,000-25 lakh. Officers: imprisonment up to 3 years or fine Rs 50,000-5 lakh or both
Section 447Fraud (including fraudulent records)Imprisonment 6 months to 10 years + fine 1x to 3x the fraud amount
Section 448False statement in any return, report, or financial statementImprisonment up to 2 years + fine Rs 50,000-5 lakh

Beyond statutory penalties, the practical consequences matter more for most companies: a qualified audit report affects bank loan processing, investor due diligence, and vendor relationships. Banks review the CARO report and IFC opinion before sanctioning or renewing credit facilities.

5. Consequences for the Auditor

Auditors face their own consequences for inadequate reporting. These provisions are relevant because they explain why your statutory auditor is increasingly insistent on seeing proper records and controls.

ProvisionWhat it coversPenalty
Section 147(1)Contravention of audit provisionsFine Rs 25,000 to Rs 5 lakh
Section 147(2)Knowingly/wilfully with intent to deceiveImprisonment up to 1 year + fine Rs 1-25 lakh
Section 143(12)Failure to report fraud discovered during auditFine Rs 1 lakh to Rs 25 lakh
NFRAInadequate audit qualityPenalty up to 5x audit fees + debarment up to 10 years
ICAIProfessional misconductRemoval from register up to 5 years + fine up to Rs 5 lakh

NFRA has debarred 85 chartered accountants as of 2025 for audit failures — including cases involving inadequate control testing, failure to verify asset records, and baseless reports on internal financial controls. ICAI penalised 241 members in a single year — a record high. These are not theoretical risks.

6. What Good Records and Controls Look Like

When an auditor tests your procurement and asset records, they are looking for a system — not a collection of documents. The difference:

What auditors askWithout a systemWith a governed system
"Show me the approval for this purchase"Email thread, verbal confirmationApproval matrix with frozen snapshot showing who approved, when, at what level
"Show me receipt was verified before payment"Signed delivery challan in a fileGRN matched to PO with quantity, price, and condition recorded
"Show me your asset records"Excel with asset name and costRegister with 40+ fields — ID, location, custodian, classification, depreciation, acquisition trail
"Show me assets physically exist""We did a check last year"Verification campaign report — who scanned, when, what condition, what was missing
"Show me disposals were authorised"Board resolutionDisposal requisition with approval chain, asset value at disposal, proceeds recorded
"Show me the audit trail""We don't delete anything"System-generated log of every change with user, timestamp, and before/after values

7. Implementing These Controls

The requirements described in this article — CARO-compliant asset records, internal financial controls over procurement, and tamper-proof audit trails — are not about installing software. They are about putting a structured process in place:

  1. Define your approval structure: Who can request purchases? Who approves, and at what thresholds? Map this to an approval matrix with clear levels and dimensions.
  2. Govern the procurement chain: Every purchase follows PR → PO → GRN with each step requiring completion before the next. No ad-hoc purchases, no retroactive documentation.
  3. Maintain a structured asset register: Every asset has a complete record — identity, location, financial details, lifecycle status. Depreciation runs on defined schedules with year-end snapshots that cannot be modified.
  4. Verify physically: Tag assets with QR codes, run periodic verification campaigns, record what was found and what was missing. This directly satisfies CARO Clause 3(i).
  5. Match invoices: Before payment, the vendor's invoice is matched to the PO and GRN — quantity, price, and GST. Mismatches are resolved through a defined workflow, not ignored.
  6. Ensure the audit trail: Every action in the system — creation, approval, rejection, edit, posting, reversal — is logged with user, timestamp, and before/after values. The trail cannot be disabled or tampered with.

ProcureTrail supports this complete workflow. But the principle applies regardless of the tool — the statutory requirement is for controls and records, not for any specific software.

Frequently Asked Questions

What does CARO 2020 require for fixed asset records?

CARO 2020 Clause 3(i) requires the statutory auditor to report on whether the company maintains proper records of its property, plant and equipment — with full particulars including quantitative details and location, whether PPE has been physically verified at reasonable intervals, and whether title deeds of immovable property are held in the company's name.

How are fixed assets classified under the Companies Act?

Under Schedule II of the Companies Act 2013, fixed assets are classified by asset class — buildings, plant and machinery, furniture and fixtures, office equipment, vehicles, computers, and intangibles — each with a prescribed useful life for straight-line or written-down depreciation. The classification drives the asset register structure and the depreciation schedule.

Does CARO 2020 apply to private limited companies?

Yes, unless the company meets all three exemption conditions simultaneously: paid-up capital plus reserves not exceeding Rs 1 crore, borrowings from banks or financial institutions not exceeding Rs 1 crore at any point during the year, and revenue not exceeding Rs 10 crore. If any one threshold is breached, CARO 2020 applies in full.

Is internal financial controls (IFC) audit mandatory for all private companies?

No. Private companies with turnover below Rs 50 crore and borrowings below Rs 25 crore are exempt from IFC auditor reporting under Section 143(3)(i). However, directors of all companies — regardless of size — must state in the annual report that IFCs are adequate and operating effectively under Section 134(5)(e).

Does the audit trail requirement apply to asset registers maintained in Excel?

Rule 3 of the Companies (Accounts) Rules 2014 requires accounting software to have a built-in audit trail that records every transaction change with date and user, and that cannot be disabled. Excel does not have this capability. Asset records maintained in Excel do not satisfy this requirement, which applies to all companies from 1 April 2023.

What are the penalties for not maintaining proper books of account?

Under Section 128(6) of the Companies Act 2013, the managing director, the whole-time director in charge of finance, the Chief Financial Officer, or any other person charged by the Board with the duty of compliance faces a fine of Rs 50,000 to Rs 5 lakh. The company itself is not penalised under this section and there is no per-day continuing penalty. Under Section 134(8), for false statements in the directors' responsibility statement, officers face imprisonment up to 3 years or fine up to Rs 5 lakh or both.

Does an ERP fixed-asset module satisfy CARO 2020 on its own?

Usually not on its own. Clause 3(i)(a) can be met inside the module if its per-unit quantitative and location details are maintained. But Clause 3(i)(b) is a separate limb requiring evidence that assets were physically verified at reasonable intervals, that discrepancies were noticed, and that they were dealt with in the books — field evidence an accounting module does not capture. Where the module is used only for depreciation and general-ledger entries, the physical-verification limb is left unmet, which is why companies on SAP, Oracle or Tally keep a dedicated register and verification routine alongside it.

Assess How This Applies to Your Organisation

Share a brief overview of your current procurement and asset record-keeping setup and we will evaluate where the gaps are.

Book a Consultation