Corporate Governance • ICFR, DoFP & Enterprise Policy Architecture

Internal Financial Controls, Delegation of Powers & Corporate Policy Architecture

Strategic institutional governance, operational hierarchy engineering, and risk control design across Delhi NCR and Indian enterprises: aligning board oversight, C-Suite KMPs, functional controllership, and frontline Maker-Checker execution with the IIA Three Lines Model (2020), COSO 2013, and statutory mandates under the Companies Act, 2013.

Operational Level 1

Governance & Board

Fiduciary stewardship, strategic guidance, and statutory committee oversight: Audit Committee (§ 177), NRC (§ 178), CSR (§ 135), Independent Directors, and Woman Director mandates.

Operational Level 2

C-Suite & KMPs

Key Managerial Personnel (§ 203): Managing Director / CEO operational execution, CFO financial stewardship & ICFR certification, CS governance reporting, and CISO cyber defense.

Operational Level 3

Functional Controllership

Supervisory 2nd & 3rd Line controls: Financial Controller general ledger discipline, Head Internal Audit (§ 138), Procurement 3-way matching, Legal CLM, and Quality QA/HSE monitoring.

Operational Level 4

Frontline Execution

Day-to-day transactional custody: Accounts Payable Maker-Checker dual authorization, Storekeeper GRN physical checks, Cashier § 40A(3) imprest limits, and POSH IC (§ 4) protection.

1. Internal Financial Controls over Financial Reporting (ICFR)

Companies Act 2013 §§ 134(5)(e) & 143(3)(i) • COSO 2013 • IIA Three Lines Model

Under Section 134(5)(e) of the Companies Act, 2013, the Directors' Responsibility Statement must affirm that the company has laid down internal financial controls that are adequate and operating effectively. Furthermore, Section 143(3)(i) mandates statutory auditors to issue an independent attestation on ICFR design and operating effectiveness, benchmarked against ICAI guidance and the COSO Internal Control - Integrated Framework.

1st Line (Operations): Business unit managers and frontline process owners directly managing process risks, transactional approvals, and physical custody.
2nd Line (Controllership): Financial controllership, legal counsel, risk management, CISO, and compliance teams designing policies and monitoring controls.
3rd Line (Internal Audit): Independent internal audit function under Section 138 providing objective assurance directly to the Board Audit Committee.

2. Delegation of Financial Powers (DoFP) & Authority Matrices

Companies Act 2013 § 179(3) • Enterprise Governance • Anti-Collusion Controls

Operational efficiency collapses when decision thresholds are ambiguous or bottlenecks accumulate at the promoter desk. We architect institutional 5-tier Delegation of Financial Powers (DoFP) schedules defining explicit monetary ceilings, escalation hierarchies, and dual-authorization matrices for Capital Expenditures (Capex), Operational Commitments (Opex), Vendor Contract Execution, Bank Payment Releases, and Bad Debt Write-Offs.

Authority Tier Designated Roles Operational Capex / Opex Limit Contract & Banking Mandate
Tier 1: Operational Plant Managers, Project Leads ≤ ₹1 Lakh (Budgeted) Routine stores replenishment, minor PO verification
Tier 2: Functional Head VPs, General Managers, Financial Controller ₹1 Lakh – ₹10 Lakhs Vendor PO approvals, departmental operating contracts
Tier 3: Executive KMP Chief Financial Officer (CFO), COO ₹10 Lakhs – ₹50 Lakhs Major procurement contracts, credit line drawdowns
Tier 4: Managing Director Managing Director / Chief Executive Officer ₹50 Lakhs – ₹2 Crores Strategic contracts, M&A commitments, Capex expansion
Tier 5: Board / Audit Comm. Board of Directors (§ 179) > ₹2 Crores / Unbudgeted Borrowings (§ 180(1)(c)), RPTs (§ 188), major asset sales

3. Institutional Enterprise Policy Compendium

Statutory & Operational Governance Codes across 6 Functional Categories

Governance & Fiduciary Policies

Whistleblower & Vigil Mechanism (§ 177(9)): Confidential reporting channel with direct escalation to Audit Committee Chair and absolute victimisation immunity.

Related Party Transactions (§ 188 / SEBI LODR 23): Prior Audit Committee approvals, arm's length benchmarks, and shareholder approval matrices.

Anti-Bribery & Anti-Corruption (ABAC): Section 9 Prevention of Corruption Act compliance, commercial bribery defense, and zero facilitation payments.

Financial & Operational Policies

Procure-to-Pay & 3-Way Match: Automated matching of Purchase Orders, GRNs, and Vendor Tax Invoices prior to booking, enforcing § 43B(h) MSME & § 16(2) GST.

Document Retention (§ 128(5)): 8-year statutory retention of books and vouchers vs permanent retention of corporate charter, title deeds, and meeting minutes.

IT Security & DPDP 2023: ISO 27001 InfoSec, BCP-DR (ISO 22301) failover drills, and CERT-In 6-hour cybersecurity incident reporting compliance.

Internal Financial Controls & Governance Practice

Institutionalize Your Enterprise Operating Architecture

Consult with Senior Practice Partners to design robust ICFR Risk & Control Matrices (RCM), establish tailored Delegation of Financial Powers (DoFP), and draft statutory corporate policies compliant with Companies Act 2013 and SEBI LODR.

Schedule Governance Review
ICAI Code of Ethics Pull-Model Statutory Notice This practice overview provides statutory governance and internal control reference information in compliance with ICAI regulations.