Capex & Fixed Asset Risk Audit in India: Capital Approvals, Vendor Sourcing, CWIP, Asset Register, Disposal & Physical Verification 2026
A CFO, project and audit-committee framework for protecting capital expenditure from weak business cases, procurement leakage, incomplete commissioning records, missing assets and disposal abuse.
Capital expenditure creates concentrated financial exposure because large amounts may be committed before the company can verify whether the asset or project will deliver expected benefits. Risk can arise through inflated specifications, non-competitive procurement, scope creep, unsupported variation orders, delayed commissioning, assets recorded but not physically present and disposals lacking transparent value.
A corporate-standard review therefore connects the original business case to approval, procurement, project execution, accounting, asset custody and final disposal.
1. Capex universe and project register
Maintain a register covering project name, sponsor, business case, approved budget, approval date, expected completion, vendor, actual spend, current stage, capital work-in-progress, commissioning status and responsible custodian. Split projects should be aggregated where they form one economic investment.
Authority should align with the Delegation of Authority & Approval-Control Audit.
2. Business case and budget approval
Review need, expected benefit, alternatives, estimated cost, implementation timeline, operating impact, vendor assumptions and approval. Projects should not be approved through artificially divided budgets designed to remain below higher authority thresholds.
3. Vendor sourcing and conflict risk
Test competitive bids where policy requires, technical evaluation, commercial negotiation, vendor ownership, conflict declarations and award approval. Repeated single-source awards, narrow technical specifications favouring one vendor and late inclusion of additional scope should be analysed.
For deeper sourcing risks, see Vendor & Procurement Fraud Risk in India.
4. Purchase orders, milestones and variation orders
Capital POs should define scope, specification, payment milestones, acceptance, delay consequences, warranty and change control. Review variation orders that increase project value after award, especially where they avoid renewed competition or higher approval.
5. Project payment controls
Link advances and milestone payments to contractual evidence, engineer/user certification, invoice, security where applicable and approved budget. Old advances and retention balances should be aged and reconciled.
6. Capital work-in-progress
Long-running CWIP can conceal abandoned or delayed projects. Review ageing, physical status, reason for delay, expected completion, impairment considerations and whether costs classified as capital genuinely relate to the project. Accounting treatment should be evaluated with finance specialists under applicable standards.
7. Asset commissioning and capitalisation
Capitalisation should be supported by completion or commissioning evidence, location, custodian, serial number where available, invoice and date placed in use. Assets should not remain in CWIP after operational use, nor be capitalised before they are available for intended use merely to meet reporting objectives.
8. Fixed asset register and tagging
The register should identify asset class, cost, date, location, custodian, unique tag or serial number, depreciation data and disposal status. High-value movable assets require stronger custody and transfer controls than immovable equipment.
9. Physical verification
Physical checks should compare asset register to actual existence and actual assets back to the register. Exceptions include missing assets, unrecorded assets, incorrect locations, idle equipment and assets held by former employees or closed branches.
10. Disposal, scrap and write-off controls
Disposal should document reason, condition, valuation or market comparison where appropriate, buyer, approval, payment receipt, data sanitisation for IT assets and removal from the asset register. The same person should not control classification as scrap, buyer selection and final approval without independent review.
11. Capex analytics
- projects split below approval thresholds;
- repeated single-source awards;
- variation orders materially increasing original value;
- old CWIP without completion plan;
- assets capitalised with no physical verification;
- duplicate serial numbers or locations;
- frequent transfers immediately after purchase;
- write-offs soon after acquisition;
- scrap sales to recurring related buyers; and
- payments beyond approved budget without authority.
12. Risk matrix
| Risk | Indicator | Control response |
|---|---|---|
| Approval | Split project or unapproved overrun | Aggregate value and reapproval |
| Execution | Unsupported milestone/variation | Independent certification |
| Custody | Asset missing or wrong location | Physical verification and accountability |
| Disposal | Opaque scrap sale or write-off | Valuation, approval and receipt control |
13. Evidence and deliverables
Business cases, capex approvals, budgets, bids, POs, contracts, variation orders, milestone certifications, payment records, CWIP schedules, fixed asset register, physical verification reports, transfer records, disposals and user-access logs form the evidence set.
- capex approval exception report;
- project overrun and variation analysis;
- old-CWIP schedule;
- asset-register exception report;
- physical-verification variance;
- disposal/scrap review;
- estimated financial exposure; and
- 30/60/90-day remediation plan.
14. 30/60/90-day remediation
0–30 days: verify high-value assets, review old CWIP, freeze unsupported disposals and identify capex above approved limits.
31–60 days: clean fixed asset register, strengthen change-order controls and close old advances or incomplete documentation.
61–90 days: implement recurring physical verification, capex dashboards and independent review of major variations and disposals.
15. Frequently asked questions
Does a cost overrun prove procurement fraud?
No. It can result from scope change, inflation, design error, delay or vendor issues. Evidence is required.
How often should assets be physically verified?
Frequency should reflect value, mobility, risk and applicable accounting/control requirements.
Should all disposals use auction?
The appropriate disposal method depends on asset type, value, policy and market. Transparency and authority are the key controls.
Why is old CWIP risky?
It may indicate stalled projects, incomplete records, inappropriate capitalisation or assets that are already in use but not correctly accounted for.
Authoritative references
Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.