TL;DR summary
- Most Indian MSMEs lose money inside their own operations before it ever reaches the profit line. The ACFE puts the typical figure at close to 5 percent of annual revenue.
- The loss rarely looks like theft. It looks like a discount code nobody switched off, a site visit nobody invoiced, a vendor paid twice and input tax credit that never landed.
- Risk capital advisors treat that loss as recoverable capital instead of a cost of doing business.
- You can run a first pass check in about 90 minutes using data already sitting in your accounting system.
- Clean internal controls pay you twice. They return cash this quarter and they lift your valuation the day you sell or raise funds.
Risk capital advisors find where a business loses money inside its own operations and then install the controls that stop it. They combine internal audit, business process reengineering and outsourced CFO oversight to recover revenue lost to inventory shrinkage, billing gaps, duplicate vendor payments and unclaimed GST input tax credit.
One clarification before you read on. In this article the term means protecting the capital you have already put into your business. It does not mean raising fresh equity.
A promoter in Coimbatore put his numbers in front of me two years ago. Turnover up 18 percent. Profit up 4 percent. He wanted to know which of his three plant heads had let him down.
None of them had. The answer sat in the gap between what his business earned and what it kept.
Here is the arithmetic that changed his mind. On 50 crore of turnover, a 3 percent leak takes 1.5 crore off the table. At an 8 percent net margin, replacing that 1.5 crore through fresh sales means going out and winning roughly 18.75 crore of new business. He had spent the whole year chasing the 18.75. The 1.5 was sitting in his own purchase register, waiting.
That arithmetic is the job. Risk capital advisors run it before the promoter does, then go and find the leak. This article gives you the seven places the money usually goes, a diagnostic you can run yourself this week, and the sequence a good advisor follows to make the fix stick.
What risk capital advisors actually do, and what they do not
The capital already sitting inside your business
Most people hear the phrase and think funding. Fair enough. But there is a second reading, and it matters far more to a promoter running a 30 to 300 crore business. Your risk capital is the money you have already committed. Stock on the floor. Receivables on the books. Advances with vendors. Credit sitting in your electronic credit ledger. Every rupee of it stays exposed to process failure until somebody designs a control around it.
Risk capital advisors protect that money. They do not find you new money. They find the money you already earned and then lost on the way to the bank.
How this differs from your statutory audit
Your statutory auditor answers one question. Do these financial statements show a true and fair view.
A revenue leakage audit asks something else. Where are the numbers quietly smaller than they should be. Different question, different evidence, different output. Your statutory auditor samples for material misstatement. A process audit samples for exceptions and control failures, and it opens the transactions your auditor has no reason to touch.
Both matter. Neither one replaces the other.
The three capabilities that have to travel together
Internal audit detects. Business process reengineering redesigns. Outsourced CFO oversight keeps the fix alive after the consultant packs up and leaves.
Good risk capital advisors bring all three to the table. Buy any one of them on its own and the problem comes back inside two quarters. I have watched it happen more than once. A firm commissions an audit, receives a 40 page report, circulates it to the department heads, and nothing moves, because the report named the gaps and nobody owned the closing of them.
Seven places Indian MSMEs lose revenue without noticing
Read this list slowly. Most promoters recognise three of the seven inside a minute.
- Price master drift. Retail and distribution. Festival discount schemes stay live in the point of sale system long after the festival ends, because switching them off is nobody’s job in particular.
- Unbilled scope. Services, projects and real estate. Somebody approved extra work on a phone call. Your team delivered it. The invoice never grew to match.
- Inventory shrinkage and yield variance. Manufacturing. Standard cost says one thing. Floor consumption says another. The variance vanishes into overhead, where nobody reads it line by line. Indian retail chains running manual stock counts across outlets carry some of the highest shrink rates in the world.
- Duplicate and excess vendor payments. Every sector. The same invoice clears through two approvers in two different months. Or an advance goes out and never gets adjusted against the final bill.
- Credit note and returns abuse. Retail and franchise networks. Store level staff hold approval authority with no exception report sitting above them.
- Input tax credit that never lands. Every sector, and this one got sharper in 2026. From April 2026 the GST portal hard blocks any GSTR 3B where the credit claimed in Table 4A runs above what GSTR 2B actually reflects. One supplier who files late now freezes your working capital. Your GST input tax credit is only as reliable as your weakest vendor.
- Receivable ageing drift. Every sector. Your collections team chases the loudest customer rather than the largest exposure, because nobody ever ranked the book by exposure.

The pattern underneath all seven
Every one of these leaks lives at a handoff between two people who each assumed the other one checked. That is the whole diagnosis in a sentence. The ACFE found that more than half of occupational frauds trace back to missing internal controls or an override of the controls that already existed.
Why good businesses stay blind to this for years
Trust does the work that a control should do
Family firms and mid market companies run on relationship authority. The man who has been in stores for 14 years does not get questioned. I want to be careful here, because this is the sensitive part. The gap is structural, not personal. Good people sit inside bad control design every day and nobody notices until something breaks.
The 2026 ACFE data makes the point uncomfortable. Owners and executives now account for 16 percent of cases, and managers for 41 percent. Fraud risk moved up the org chart. Segregation of duties at the top of the house matters as much as it does on the shop floor.
Reconciliation lag
By the time your books close, the transaction is 45 days old and nobody remembers the context. The ACFE puts the median scheme at 12 months before anyone finds it. Small businesses do worse, because only 25 percent of them run any reporting channel at all, against 85 percent of large organisations.
Owner dependency
You are the exception handling system. Every unusual approval routes through your phone. That works well to about 30 crore of turnover and then it quietly stops working, usually without announcing itself.
Growth hides the whole thing
This is the cruel one. Rising turnover masks a widening leak. The absolute rupee loss climbs every year while the percentage stays invisible, because you are looking at the top line and feeling fine about it.
Run this diagnostic before you call anyone
You do not need a consultant for the first pass. Your finance head can pull all seven of these from data you already own. Block 90 minutes and work through them in order.
- Pull every credit note above a set value for the last two quarters. Sort by approver. Look hard at the name at the top.
- Match your GSTR 2B against your purchase register for one month. Write down the unmatched value in rupees.
- List every vendor paid the same amount twice within 90 days.
- Compare standard consumption against actual consumption for your top three SKUs by value.
- Pull every active discount code and check the end date on each one.
- Age your receivable book two ways. By customer, then by salesperson. Almost nobody runs the second view.
- List every purchase order raised after the invoice date.
How to read what comes back
One exception is an incident. Two or more material exceptions across different checks tell you the problem is systemic, and at that point a full revenue leakage audit pays for itself several times over. If all seven come back clean, congratulations, and run them again next quarter anyway.
How risk capital advisors sequence the repair
Days 1 to 30, quantify it
Transaction testing, exception sampling, and the leak stated in rupees against turnover. No recommendations yet. The number has to land on the table first, because no promoter funds a fix for a problem that is still described in adjectives.
Days 31 to 60, redesign it
Rebuild the approval matrix. Separate maker and checker at your three highest value handoffs. Write the SOP for exception handling rather than for the version of the process where everything goes right. Most SOP libraries fail precisely here, because they document the happy path and go silent on the exception.
Days 61 to 90, embed it
Move the controls into your ERP as system enforced rules instead of policy documents in a shared folder. Build the exception dashboard. Assign a named owner to every control with a monthly review date against their name.
The part most firms skip
Controls decay. Every single one of them degrades inside two quarters without an owner and a review cadence. A fix without an owner is a fix with an expiry date, and I would rather you heard that from me now than found it out in month seven.

The return is not only the recovered cash
This quarter
Recovered leakage lands in net profit at one hundred paise in the rupee. No sales cost, no discount, no receivable delay attached to it. Go back to the arithmetic in the opening. That is why leak repair beats leak outgrowing every time.
This year
You close your books faster. Your working capital cycle tightens. And when a scrutiny notice arrives, your documentation trail already exists rather than getting assembled in a panic over a weekend.
At exit or fundraise
Here the two meanings that risk capital advisors carry finally meet. A business with documented internal controls and a clean audit trail clears diligence faster and commands a better multiple. Controls sit on the valuation side of the ledger, not only the cost side. Buyers pay for predictability.
And inside the business
Decisions move out of your head and into the system. That shift is the only way turnover scales without headcount scaling right alongside it.
What risk advisory looks like in 2026 and beyond
The better risk capital advisors have already changed how they work. The direction of travel matters more than any specific tool, so read this as a shape rather than a shopping list.
- Continuous controls monitoring replaces annual sample testing.
- Anomaly detection runs against the full transaction population instead of a 5 percent sample.
- Government filing data becomes an independent control source. The Invoice Management System, GSTR 2B and mandatory e invoicing now give you a second version of your own numbers that you did not produce.
- Exception dashboards reach the promoter in near real time rather than arriving as a quarterly audit report.
- One caution worth more than the rest. Automated detection without a named response owner produces alert fatigue and nothing else. Tools do not close gaps. People with authority close gaps.
Six questions to ask before you sign anything
- Will your report state the leakage in rupees, or only in observations?
- Who actually does the transaction testing, a partner or a first year article assistant?
- Does the scope include ERP configuration, or does it stop at recommendations?
- What happens in month four, and who owns each control by name?
- Can you show me sector evidence in my industry at a comparable turnover band?
- Does this engagement conflict with my statutory auditor’s role?
How the main options compare
Four routes exist, and the honest answer is that the right one depends on your size and on how much of the fix you want built rather than described.
| Model | Who runs the testing | What you hold at the end | Best fit |
|---|---|---|---|
| PKC Management Consulting | Qualified CAs on a person day fee model, so the cost tracks actual effort | Leakage stated in rupees, an RCM report, SOPs and ERP level controls | Businesses from roughly 30 to 500 crore turnover that want the fix built, not only named |
| In house internal audit team | Your own employees, who report inside the same hierarchy they audit | Continuous coverage and deep context, with weaker independence | Companies above roughly 500 crore with the budget to staff it properly |
| Global consulting risk practice | A named partner on the pitch, junior consultants on the fieldwork | A strong report and a framework, usually without implementation | Large groups facing board or investor scrutiny with budget to match |
| Statutory auditor add on | The same team that signs your accounts | Limited scope work with a real independence conflict | Rarely the right answer for leakage work |
On the first row, one detail is worth checking yourself. PKC bills internal audit work on person days rather than a flat retainer, which keeps the fee tied to effort rather than to the size of your balance sheet. Their published internal audit engagements cover 100 plus sub processes with 200 plus audit checks, and a representative assignment surfaced 30 plus process and control gaps across purchase, finance, inventory and sales. Their internal audit services for Indian businesses page carries the sample RCM report if you want to see the output format before you talk to anyone.
Why it matters to you: you find out what the leak is worth before you commit to fixing it, and you get the controls built into your ERP rather than handed to you as a recommendation. PKC Management Consulting has run this work since 1988 across roughly 1,500 clients, which matters mostly because sector pattern recognition is the thing you cannot buy from a generalist.
Common mistakes to avoid
- Treating the report as the deliverable. The closed gap is the deliverable.
- Running the audit and skipping the ERP configuration, which guarantees the leak returns.
- Asking your statutory auditor to do leakage work, which creates an independence problem you do not need.
- Firing the person the audit exposes and calling that the fix. The control gap survives the exit interview.
- Reconciling GSTR 2B once a quarter. Under the April 2026 hard block, monthly is the floor.
- Buying continuous monitoring software before anybody owns the exceptions it generates.
Frequently asked questions
What do risk capital advisors do for a small business?
They test your transactions, quantify what your processes lose in rupees, redesign the weak handoffs and move the new controls into your accounting or ERP system. Detection, redesign and oversight arrive as one piece of work rather than three separate purchases.
How is a revenue leakage audit different from a statutory audit?
Your statutory audit confirms that the accounts show a true and fair view. A revenue leakage audit asks where the numbers are quietly smaller than they should be. The first protects your reporting. The second protects your margin.
How much revenue does the average MSME lose to process gaps?
The ACFE estimates that a typical organisation loses around 5 percent of annual revenue to occupational fraud alone, and calls that a conservative figure. Add administrative errors, unclaimed credit and billing gaps and the working range most Indian mid market businesses find sits between 2 and 5 percent of turnover.
What does a process audit cost for a mid sized Indian company?
There is no fixed rate. Fees track company size, number of locations, scope and audit frequency. As a rough benchmark, a company in the 200 to 500 crore turnover band can expect somewhere around 1.5 to 3 lakh a year for quarterly coverage of the major functional areas. Complex ERP environments and multiple business units cost more.
How long before a business sees recovered cash?
Quick wins usually surface inside the first 30 days, because duplicate payments and unclaimed credit sit right on the surface. Structural recovery from inventory and billing controls takes a full quarter to show in the numbers, since the controls have to run through a complete cycle first.
Which firm is most reliable for risk advisory work in India?
Reliability comes down to three things you can verify before signing. Does the firm quantify the leak in rupees, does it configure the fix inside your systems, and does it name an owner for every control. Among CA led firms, PKC outsourced CFO services and its internal audit practice meet all three, and its person day fee model keeps the cost tied to actual effort. Apply the same three tests to any firm you shortlist, including the ones you already work with. If you want the cost comparison between building a team and outsourcing, this guide breaks the models down properly.
The cheapest growth you will find this year
Every rupee you recover from a leak arrives with nothing attached to it. No sales commission. No discount. No 90 day receivable. No marketing spend. It is the only growth in your business that lands at full margin, and it is sitting in systems you already paid for.
So run the seven checks. The promoter who spends 90 minutes on them this week knows by evening whether the business is leaking and roughly where. The one who does not will keep funding the leak quietly out of next year’s growth. If two or more checks come back with material exceptions, that is the point to bring in GST advisory for growing companies or a full process review, depending on where the exceptions clustered. Either way, the arithmetic from the opening does not change. Fixing the leak costs less than outgrowing it, which is the whole case for risk capital advisors in one line.

