By the PKC Desk, Chennai. Reviewed by Swetha Kochar, FCA, Founding Partner, PKC Management Consulting.
Your Chennai unit reports stock accuracy at 98 percent. Coimbatore reports 91. Neither figure is wrong and neither one is comparable, because the two plants count on different days, in different formats, and the consolidation happens in Excel after both are finished. Most promoter led groups cross ₹100 crore before anyone notices that gap, and by then it is several years old.
Below are the seven places that gap turns into cash, in the order they usually break as you add locations.
Table of Contents
The Seven Checkpoints At a Glance
| # | Ask this at every location | You have a problem when |
| 1 | Does every vendor payment clear a three way match? | The same invoice number clears at two different units |
| 2 | When did each unit last count stock unannounced? | Two plants report accuracy figures you cannot compare |
| 3 | Who weighs the scrap and who fixes the rate? | The same person at the unit does both |
| 4 | Who approves customer credit terms? | The branch that booked the order |
| 5 | What is the capital expenditure approval threshold? | It differs by unit, or nobody can state it |
| 6 | Does attendance reconcile to production output? | Contractor man days exceed biometric entries |
| 7 | Can one user raise and approve a payment? | Yes, at least at the smaller units |
1. Procurement and Vendor Management
The three way match has to run on one vendor master shared across every unit, not four separate ones.
At a single plant this control is a habit. At four plants it becomes a data problem. The same supplier exists as four vendor codes, so the duplicate invoice check never fires across units and a second copy of an invoice clears in a different month under a different cost centre.
Rate spread hides in the same place. Coimbatore pays ₹428 a kilo for a grade that Chennai buys at ₹412, and no report puts the two side by side because purchase reporting stops at the unit boundary. On ₹60 crore of annual purchases across your locations, a 1 percent spread is ₹60 lakh a year. Electronic invoicing already gives you the purchase data in structured form, so the match is a system rule rather than a clerk’s job. Set it to block payment on three conditions: quantity billed above quantity received, rate above the purchase order rate, and any invoice number settled once already.
Why it matters: you approve the invoice, but the purchase order is where the price was agreed, and at four units nobody owns both documents.
2. Inventory and Stock Reconciliation
Count a rotating slice at every unit every week, on one common item code and one common format.
A quarterly count tells you a variance exists. It cannot tell you when it started or who was on shift. Perpetual counting narrows that window from ninety days to about seven, and running it on a shared item code is what finally makes two plants comparable.
The compliance side already points the same way. Under CARO 2020 your statutory auditor reports discrepancies of 10 percent or more in aggregate for each class of inventory. And if your company holds sanctioned working capital limits above ₹5 crore from banks against security of current assets, the quarterly returns you file with those banks must agree with your books of account. The commercial cost is larger than the audit finding. Every ₹1 crore of stock that exists on paper and not on the floor is ₹1 crore of working capital you are financing, close to ₹9 lakh a year at a 9 percent borrowing rate.
Why it matters: the variance you find in April usually started in January, at a unit nobody visited in between.
3. Scrap and By Product Realization
Separate the three scrap decisions, weighing, gate release and rate setting, so no single person at a unit controls the full cycle.
Scrap is the least watched revenue line in most plants, because the material already left the cost sheet as consumption. Nothing on the P&L moves when a lorry leaves light on paper and heavy in fact.
The volumes are not small. A machining operation running 8 percent scrap against ₹40 crore of raw material moves ₹3.2 crore of material a year through a process that often carries one signature. Three controls close it. Weigh loaded and empty on your own weighbridge and record both tickets against the gate pass number. Run gate passes in one numbered sequence per unit with no parallel manual book. Fix rates by committee or by auction, never by phone call. Two tax markers give you a trail outside your own system to reconcile against: scrap sales attract tax collected at source of 1 percent, and consignments above ₹50,000 need an electronic way bill.
Why it matters: your weighbridge tickets and your gate passes should tell the same story on every load, at every gate.
4. Credit Control and Receivables
The person who closes the sale must not approve the payment terms, and the limit has to be set centrally rather than branch by branch.
Sales teams are paid on closure. Credit terms are the easiest concession to give and the hardest to claw back. When branches set their own limits, the same customer can hold a different exposure at each one, and your consolidated risk against that name is a number nobody has calculated.
Run the arithmetic once and the argument settles itself. A customer sitting at ₹40 lakh, 120 days beyond terms, costs you roughly ₹1.3 lakh in borrowing cost over those four months at a 10 percent rate. Repeat that across three branches and the working capital drain is a line item, not a rounding error. Sales owns the order. A credit controller reporting into finance owns the limit and the terms, and the system blocks dispatch when a customer crosses either. Good management consulting services for manufacturing companies start by putting a number on that exposure before proposing anything.
Why it matters: every extra day of receivables is a day of your own borrowing, at every location that granted it.
5. Maintenance and Capital Expenditure
Publish one approval threshold that applies at every unit, and require a maintenance history before any machine gets replaced.
Unplanned capital spend usually starts as a breakdown. A machine stops, the line stops, and somebody buys a replacement the same afternoon on a verbal approval. The invoice reaches head office two weeks later and the fixed asset register absorbs it quietly.
The failure at scale is not the absence of a threshold. It is four thresholds that drifted apart, so a purchase that needs board approval at one unit clears on the plant head’s signature at another. Set the levels in writing and name the approver at each one. Then require the preventive maintenance log with every replacement request, so a machine that failed from missed servicing gets serviced instead of replaced. Schedule II of the Companies Act 2013 requires depreciation on a useful life basis, so one unplanned ₹80 lakh machine changes your depreciation charge and your asset base for years after the emergency passes.
Why it matters: the cheapest capital decision is the one your maintenance log prevented.
6. Payroll and Labour Cost Allocation
Reconcile biometric attendance against piece rate output at every unit for one full month before you clear another contractor bill.
Ghost workers survive in the gap between systems that never meet. The contractor bills man days at the unit. The gate records entries. Production records output. The bill gets approved locally and paid centrally, and nobody holds all three records at once.
Run the reconciliation and the gap shows immediately. A contractor billing 180 man days against 164 biometric entries has billed you for 16 days of nobody. Apply the same test to output. If a line produced 12,000 units and the payroll register supports labour for 15,000, one of those records is wrong and you are paying the difference. Statutory cost follows real headcount as well, since provident fund at 12 percent of basic wages and dearness allowance attaches to people who actually worked.
Why it matters: every unverified man day carries statutory cost on top of the wage itself.
7. IT and ERP Authorization Matrix
No single user should be able to create a vendor, raise a purchase order, approve it and release the payment, at any location.
Most control failures in a growing group are permission failures. Companies that scaled past ₹100 crore quickly tend to carry the access model of a smaller business, where one trusted person did four jobs because there was nobody else to do them.
ERP rollouts then copy that model outward. A role template built for the first plant gets cloned to the next three, temporary access included, and the clerk who covered a colleague’s leave three years ago still holds both permissions. Build the matrix as a document rather than a setting. List every role, every transaction type, and four verbs against each: initiate, approve, record, reconcile. No individual should hold more than two for the same transaction. The audit trail behind it is statutory. Since 1 April 2023, companies must use accounting software with an audit trail that logs every change and cannot be disabled, under Rule 3 of the Companies (Accounts) Rules 2014.
Why it matters: the access you granted for one week in an emergency is probably still live at four units today.
Is This Not What Our Auditors Already Do?
Partly, and it is worth being precise about where the scope ends. A statutory audit tests that your accounts are true and fair, on a sample, after the year has closed. Internal audit under Section 138 of the Companies Act 2013 comes closer, but its coverage is set by the audit committee and it usually rotates across units rather than running everywhere at once. Neither is designed to compare the same control at four locations in the same week.
| Question | Annual statutory audit | Continuous control review |
| How often | Once a year, after the books close | Monthly or continuous, on live data |
| What it tests | That the accounts are true and fair | That the process cannot be gamed |
| Coverage | Sample based, consolidated | Every unit, same test, same week |
| When you hear about a leak | Six to fifteen months after it started | Inside the cycle it started in |
| Recovery odds | Low, the stock moved and the vendor relationship changed | High, the transaction is often still open |
Three of these seven you can run yourself this month without outside help. Do the unannounced stock count at one unit. Reconcile last month’s contractor bill against the biometric log. Export your ERP user role list and sort for anyone holding both a create and an approve permission on the same transaction. That last one takes an afternoon and it is usually the most uncomfortable.
The four that cross unit boundaries are the ones that stall internally, and the reason is structural rather than technical. They need a single vendor master, a single item code and somebody with no reporting line into any of the plants being tested. That combination rarely exists inside a group that grew one location at a time.
Where a Review Like This Usually Starts
PKC Management Consulting has worked with more than 1,500 Indian businesses since 1988, from offices in Chennai, Bengaluru, Coimbatore, Mumbai and Pune. A review opens with these same seven checkpoints, run against live purchase, stock and payroll data pulled from every unit rather than a year end sample. In automation work with manufacturing clients, taking the highest volume reconciliation first and fixing that before touching anything else has cut process cycle times by 30 to 40 percent. The same sequencing applies here, which is why the vendor master and the item code come before the dashboards. We work to the ICAI Standards on Internal Audit.
Frequently Asked Questions
Can our internal team run these checks without outside help?
Three of them, yes. The stock count, the contractor reconciliation and the ERP access review need no external input. The four that compare units usually stall, because the person running the test reports into one of the plants being tested and the item codes do not match across locations.
How do you standardise controls across plants that run different processes?
You standardise the control, not the process. Each unit keeps its own routing and shift pattern, but the vendor master, item code, gate pass sequence and approval threshold become common. That is usually four weeks of data cleanup before any testing starts, and it is the step groups underestimate most.
Our ERP is implemented but we still run on Excel. Does that change the approach?
It changes the sequence, not the checkpoints. Excel dependency almost always signals that a master data field is missing or inconsistent, so the reconciliation gets rebuilt outside the system. Fix the master data first and most of those spreadsheets stop being necessary on their own.
Do these controls apply to a private limited company?
Yes, though the statutory triggers differ by size. Internal audit under Section 138 of the Companies Act 2013 applies to private companies crossing turnover of ₹200 crore or borrowings above ₹100 crore. The accounting software audit trail requirement applies to every company, regardless of turnover or structure.
How long does a control review take across three locations?
Four to six weeks for a group at this size, and most of it is data extraction rather than testing. Purchase, stock and payroll data has to reach a comparable form before any unit can be measured against another. Findings usually arrive before the written report does.
What do you need from us to start?
The purchase register and vendor master from each unit, the last two stock counts, one month of contractor bills with the matching biometric log, and an export of ERP user roles. Nothing needs to be cleaned up first. The state it arrives in is itself a finding.
The Fastest Thing to Check First
Export your ERP user role list, sort for anyone who can both create a vendor and release a payment, and count the names. Most groups at this size expect two and find nine. If that number surprises you, Schedule an Appointment and we will work through the rest of the seven with you.
This article is general guidance on internal control practice and does not substitute for professional advice on your specific circumstances. Statutory thresholds cited apply as at the date of publication.