TDS on House Rent Payments: Know the Rates, Rules & Applicability

TDS on House Rent Payments: Know the Rates, Rules & Applicability w.e.f April 1, 2025:

Tax Deducted at Source (TDS) is a mechanism in India where tax is deducted at the source of income, ensuring that the government collects tax on income as it is earned. When it comes to house rent, specific TDS rules apply under the Income Tax Act, particularly for individuals, Hindu Undivided Family (HUF), companies, and firms. In this blog, we’ll break down the TDS rates and criteria for house rent for Financial Year 2025-26, as outlined in the table below, helping you understand your obligations as a tenant or landlord.

TDS on House Rent: The Basics

The table outlines two key scenarios for TDS deduction on house rent, including the criteria, applicable rates, sections of the Income Tax Act, and who it applies to. Let’s dive into the details:
A. TDS on Rent Paid to a Resident Indians:
No. House Rent Criteria TDS Rate Section Tenant Applicability
1 Rent is more than ₹2.40 lacs per annum 10% 194-I – Company

– Firm

– Individual/HUF with business turnover more than ₹1 crore

– Individual/HUF with professional gross receipts more than ₹50 lacs

2 Rent is more than ₹50,000 per month 2% 194-IB – Individual/HUF with business turnover less than ₹1 crore

– Individual/HUF with professional gross receipts less than ₹50 lacs

Scenario 1: Rent Exceeding ₹2.40 Lacs Per Annum
• Criteria: If the annual rent paid exceeds ₹2,40,000, TDS must be deducted.
• TDS Rate: The applicable TDS rate is 10%.
• Section: This falls under Section 194-I of the Income Tax Act, which deals with TDS on rent payments.

• Applicability: This rule applies to:
a) Companies and firms, regardless of their income.
b) Individuals or HUFs who have a business turnover exceeding ₹1 crore in a financial year.
c) Individuals or HUFs with professional gross receipts exceeding ₹50 lacs in a financial year.

• Example: Suppose a company rents office space and pays ₹3,00,000 annually. Since the rent exceeds ₹2.40 lacs, the company must deduct 10% TDS, which amounts to ₹30,000, and pay the remaining ₹2,70,000 to the landlord. The deducted TDS must be deposited to the government, and the landlord can claim credit for this amount while filing their income tax return.

Scenario 2: Rent Exceeding ₹50,000 Per Month
• Criteria: If the monthly rent exceeds ₹50,000, TDS is applicable.
• TDS Rate: The TDS rate in this case is 2%.
• Section: This is covered under Section 194-IB of the Income Tax Act.

• Applicability: This rule applies to:
a) Individuals or HUFs with business turnover less than ₹1 crore.
b) Individuals or HUFs with professional gross receipts less than ₹50 lacs.

• Example: An individual pays ₹60,000 per month as rent for their apartment, totaling ₹7,20,000 annually. Since the monthly rent exceeds ₹50,000, they must deduct 2% TDS, which is ₹1,200 per month (₹14,400 annually). The remaining ₹58,800 is paid to the landlord each month. The tenant must deposit the TDS to the government and issue a TDS certificate (Form 16C) to the landlord.

Key Points to Understand

1) Threshold Limits: The ₹2.40 lacs per annum threshold (Section 194-I) is an annual limit, while the ₹50,000 per month threshold (Section 194-IB) is a monthly limit. Ensure you calculate the rent correctly to determine which section applies.

2) Who Deducts TDS? Under Section 194-I, companies, firms, and high-income individuals/HUFs are responsible for deducting TDS. Under Section 194-IB, individuals/HUFs with lower incomes (below the specified thresholds) are responsible, making it easier for the government to track rent payments by smaller taxpayers.

3) TDS Deposit and Compliance: The deducted TDS must be deposited to the government by the 7th of the following month (or by April 30th for TDS deducted in March). Additionally, tenants must issue TDS certificates to landlords—Form 16A for Section 194-I and Form 16C for Section 194-IB.

4) No TAN Requirement for Section 194-IB: Unlike Section 194-I, where a Tax Deduction Account Number (TAN) is required to deduct and deposit TDS, individuals under Section 194-IB can use their PAN to deduct and deposit TDS, simplifying the process for smaller taxpayers.

B. TDS on Rent Paid to Non-Resident Indians (NRIs)

When remitting rental payments to a Non-Resident Indian (NRI), Tax Deducted at Source (TDS) must be withheld at a rate of 30%, in addition to the applicable surcharge and a 4% cess. This TDS deduction is mandatory regardless of the rental amount, as there is no prescribed threshold for rent payments to NRIs. However, an NRI may apply for a certificate of nil or reduced TDS deduction if their taxable income in India falls below the basic exemption limit, subject to the provisions of the Income Tax Act.

What Happens If You Miss TDS?

TDS on house rent ensures that rental income is taxed at the source, reducing tax evasion. For tenants, deducting TDS is a legal obligation, and non-compliance can lead to penalties. For landlords, the TDS deducted can be claimed as a credit when filing their income tax returns, ensuring they aren’t taxed twice on the same income.

• Penalties: Non-deduction or late deduction may attract interest (1% per month) and fines equal to the TDS amount.
• Disallowance of Expenses: The rent paid may not be deductible as a business expense for the tenant.

Practical Tips for Tenants and Landlords

  • Tenants: Always check the rent amount and your income status to determine if TDS applies. Use online tools or consult a tax professional to calculate and deposit TDS correctly. Keep records of rent payments and TDS certificates issued.

  • Landlords: Ensure your tenants are aware of their TDS obligations. Provide your PAN to the tenant for TDS deduction and verify that the TDS amount is credited to your account when filing your returns.

Conclusion

Understanding TDS on house rent is crucial for both tenants and landlords in India. Whether you’re a company paying high rent or an individual renting a modest apartment, knowing the applicable TDS rates and sections can help you stay compliant with tax laws. The table above provides a clear snapshot of the rules, but if you’re unsure about your specific situation, it’s always a good idea to consult a tax expert.

By staying informed and proactive, you can ensure smooth rent transactions while fulfilling your tax responsibilities. Have questions about TDS on rent? Drop them in the comments below, and let’s discuss!

Check out TDS Section 194-I & 194I-B of the Income Tax Act, 1961.

Disclaimer:

This article is for general informational purposes only and should not be considered professional advice. Please consult a qualified expert for advice tailored to your specific situation. The author and website owner are not liable for any errors or actions based on this content.

The Importance of Effective Audit Planning in Internal Audits

The Importance of Effective Audit Planning in Internal Audits

Introduction

Audit planning is a fundamental aspect of the internal audit function. A well-structured audit plan ensures that the internal audit aligns with an organization’s objectives, assesses risks efficiently, and allocates resources optimally. A lack of planning can lead to incomplete audits, overlooked risks, and ineffective compliance measures.

This blog provides an in-depth look at the key components of an internal audit plan, based on the internal audit checklist, covering aspects such as risk assessment, resource allocation, and governance.

Key Components of an Internal Audit Plan

1. Internal Audit Charter and Terms of Engagement

An internal audit charter outlines the scope, objectives, and authority of the internal audit function. It serves as the foundation of the audit process.

• Risk: Without a well-defined audit charter, audits may not align with the organization’s overall objectives.

• Control Measures: A documented audit process should be established, listing step-by-step procedures to develop an annual audit plan.

• Testing Parameters: Ensure that the auditing plan covers all required areas and adheres to the annual audit planning process.

2. Business Knowledge Development

Understanding the business and regulatory environment is essential for auditors to identify key risks.

• Risk: Lack of business knowledge can lead to oversight of crucial risk elements.

• Control Measures: Internal audit teams should engage with internal and external stakeholders to stay updated on industry developments.

• Testing Parameters: Verify interactions and research conducted by the audit team to ensure business knowledge is current.

3. Defining the Audit Universe

An audit universe includes all auditable entities, such as business units, processes, and legal entities.

• Risk: Missing key risk areas in the internal audit plan can result in financial and operational setbacks.

• Control Measures: Organizations must maintain an up-to-date audit universe and review it periodically.

• Testing Parameters: Assess the availability, risk rating, and periodic updates of the audit universe.

4. Linkage with Enterprise Risk Management (ERM)

Integrating the audit plan with the ERM framework ensures that key business risks are effectively monitored.

• Risk: If the audit planning process is not aligned with ERM, critical risks may not be addressed.

• Control Measures: Input from the ERM team should be factored into the audit planning process.

• Testing Parameters: Verify whether ERM inputs are utilized in formulating the overall audit plan.

5. Independent Risk Assessment for Auditable Units

Each business unit or process should undergo an independent risk assessment to prioritize high-risk areas.

• Risk: Failure to conduct a risk assessment can result in inadequate audit coverage.

• Control Measures: Conduct independent risk assessments of each unit and allocate resources accordingly.

• Testing Parameters: Review methodologies used for risk assessments and verify coverage scope.

6. Resource and Time Allocation

Audit efficiency depends on proper allocation of skilled auditors and sufficient time for review.

• Risk: Inadequate resource allocation can lead to ineffective audits.

• Control Measures: Allocate resources based on the complexity and risk profile of each auditable unit.

• Testing Parameters: Assess the adequacy of time and resource allocation in covering all high-risk areas.

7. Audit Plan Approval Process

The audit plan should be approved by the Audit Committee and the Board to ensure alignment with organizational priorities.

• Risk: Lack of governance approval can lead to misalignment with business strategies.

• Control Measures: Audit plans should be reviewed and approved at multiple levels.

• Testing Parameters: Examine minutes of Audit Committee meetings to verify audit plan discussions and approvals.

8. Periodic Review of the Audit Plan

A periodic review of the audit plan ensures that it remains relevant and adaptable to emerging risks.

• Risk: An outdated audit plan can derail audit objectives.

• Control Measures: The Chief Audit Executive should conduct regular reviews to align the plan with business changes.

• Testing Parameters: Evaluate periodic reviews to confirm alignment with the company’s strategic objectives.

Conclusion

A comprehensive audit planning process is vital for ensuring effective risk management, regulatory compliance, and operational efficiency. By incorporating structured risk assessment, stakeholder engagement, and robust governance measures, organizations can enhance their internal audit effectiveness.

For Chartered Accountants, following a detailed audit checklist and ensuring periodic reviews of the audit plan can significantly improve the quality and reliability of internal audits. By implementing these best practices, businesses can strengthen their financial and operational resilience while maintaining transparency and accountability.

Would you like additional insights on implementing this checklist in your organization? Share your thoughts in the comments! 🚀

Disclaimer:

This article is for general informational purposes only and should not be considered professional advice. Please consult a qualified expert for advice tailored to your specific situation. The author and website owner are not liable for any errors or actions based on this content.

The Role of Artificial Intelligence (AI) in Internal Auditing: Transforming Risk and Compliance

Last updated: 09 October 2026 · Written and reviewed by CA Meet Dhrangadhariya, CSM & Co LLP

Quick summary

  • AI is best used for the repetitive, data heavy parts of an internal audit: extraction, matching, full population testing and anomaly flags
  • The auditor still owns the scope, the judgment and the conclusion; an AI flag is a lead to examine, not an audit finding
  • Key risks are wrong or biased output, poor data quality, confidential data leaving the company and weak documentation of how a result was reached
  • Start small: one process, clean data, a written human review step and a record of what the tool did
  • Check whether the company is required to have an internal audit under section 138 of the Companies Act, 2013 before planning the scope

A safe way to introduce AI in an internal audit

1. Pick one process with clean, repeatable data
↓
2. Define the risk and the test in plain words
↓
3. Run the AI tool on the full population
↓
4. Auditor reviews every flag and samples what was not flagged
↓
5. Document the tool, data, settings and reviewer
↓
6. Report findings and agree actions with management

Introduction

Internal auditing has always been about one question: are the company’s controls working, and are the risks that matter being managed? What has changed is the volume of data an auditor must look at. A mid sized company can post lakhs of entries in a year, and testing a sample of 25 or 60 of them leaves most of the population unexamined.

Artificial Intelligence (AI) helps close that gap. Tools can read documents, match transactions, score risk and flag anomalies across the whole population. This article explains where AI genuinely helps in an internal audit, where it does not, the risks to control, and a practical way to start.

Where AI helps an internal audit

1. Routine tasks: extraction, matching and reconciliation

Much of audit time goes into collecting and tidying data. AI can:

  • Read invoices, receipts, challans and contracts and pull out dates, amounts, GSTINs and terms
  • Match bank statements with the books, or purchase orders with invoices and goods receipts
  • Check whether an entry follows the company’s policy or a standard format

Illustrative example: A manufacturing company has 18,000 bank lines a month. A matching tool pairs most of them automatically and leaves a short list of unmatched or part matched items. The auditor spends time on the exceptions, such as a payment that cleared twice, instead of ticking the matches.

2. Risk assessment and full population testing

Instead of a small random sample, analytics can test every entry against a rule or look for entries that behave differently from the rest. Typical tests:

  • Entries posted on holidays, at odd hours or just below an approval limit
  • Round amounts, repeated amounts and out of sequence documents
  • Vendors with the same bank account or address as an employee
  • Sudden changes in a ledger’s pattern compared with earlier months

Illustrative example: A finance company ranks its loan accounts by early warning signals such as delayed instalments and frequent restructuring requests. The audit team then picks the highest ranked branches for field work instead of choosing by rotation.

3. Fraud detection

Fraud rarely announces itself; it shows up as small oddities repeated many times. AI can help to:

  • Flag duplicate or split invoices
  • Spot unusual refund, discount or credit note patterns by location or user
  • Compare expense claims with travel, attendance and policy limits

Illustrative example: A retail chain’s refund data shows one store with far more refunds than stores of similar size, mostly at closing time and mostly approved by the same user. The flag leads to a review of the bills and CCTV, which is how the actual explanation, genuine or not, is found. The tool pointed to the place; the auditor found the facts.

4. Compliance and regulatory monitoring

AI can help keep checklists current and test them:

  • Tracking changes in GST, TDS, labour and company law and mapping them to the company’s checklists
  • Comparing GSTR-2B with the purchase register and flagging mismatches
  • Alerting the team when a due date or a threshold is approaching

Treat the output as a prompt to check the law, not as the law. Tools can be out of date, and a wrong rate or section carried into a report is the auditor’s error.

5. Document review with natural language processing (NLP)

NLP lets a tool read long documents and find what matters:

  • Missing or unusual clauses in vendor and customer contracts
  • Terms that differ from the approved template, such as payment terms or indemnity
  • Policy documents that do not match what is actually followed

Illustrative example: An audit team asks a tool to list every vendor contract without a confidentiality or termination clause. The team then reads the short list in full, instead of reading hundreds of contracts to find a few.

What AI does not do

  • It does not decide the audit scope or what is material
  • It does not understand the business reason behind an unusual entry
  • It can give a confident answer that is wrong, and it cannot always explain how it got there
  • It cannot take responsibility for the conclusion. That stays with the auditor and the firm

Auditing the AI itself: a growing part of the internal auditor’s role

AI is not only a tool for the auditor. Companies now use it in fraud detection, credit scoring, expense approval and customer screening, and internal audit is increasingly asked to give assurance over those systems too. This moves the role from reviewing outcomes to also reviewing the process behind them. A useful review covers:

  • Governance: who owns the model, who approved it, and who can change it
  • Data inputs: whether the data is complete, accurate, current and lawfully used
  • Training and validation: how the model was built and tested, and whether it is re-tested when the business or data changes
  • Bias and fairness: whether results differ unreasonably across groups, branches or customer types
  • Transparency: whether the company can explain, in plain words, why the system flagged or rejected an item
  • Human oversight: which decisions a person must review, and whether that review actually happens
  • Monitoring and incidents: logs, error tracking, and what happens when the model is wrong

Internal auditors do not need to build models, but they do need to work with IT, compliance and data teams and to ask for evidence on each of these points.

Risks and the controls to put in place

Risk What can go wrong Control
Wrong or invented output A tool states a figure, section or clause that does not exist Trace every flag to source documents before reporting
Poor data quality Duplicate masters, missing fields and wrong mapping give false flags and miss real ones Clean and reconcile the data first; record completeness checks
Confidential data Client data sent to a public tool or stored outside India without approval Use approved tools under a written agreement; remove personal data where possible
Personal data Employee and customer data processed without a lawful basis Follow the Digital Personal Data Protection Act, 2023 and the client’s data policy
Bias and blind spots Models trained on past data repeat past patterns Also test a sample of items the tool did not flag
Weak documentation Nobody can later explain what the tool did Keep the tool name and version, settings, data period, output and reviewer in the working papers
Over reliance Staff stop questioning the result Define the reviewer’s role and sign off every automated test

How to start: a practical approach

  1. Choose one process with repeatable data, such as bank reconciliation, payables or expense claims
  2. Write the test in plain words first (for example, “payments to the same bank account under two vendor names”) and only then build or buy the tool
  3. Run it on the full population and also keep a small manual sample to compare
  4. Review every flag and record the conclusion, including the false alarms; the false alarm rate tells you how useful the test is
  5. Document the work so a reviewer or another team can repeat it
  6. Agree actions with management and follow up, like any other internal audit finding
  7. Train the team on the basics of data, prompts and the limits of the tools before widening the use

Is an internal audit required for your company?

Section 138 of the Companies Act, 2013 read with Rule 13 of the Companies (Accounts) Rules, 2014 requires an internal auditor for listed companies and for prescribed unlisted public and private companies, based on paid up capital, turnover, borrowings and deposits in the preceding financial year. Check the current thresholds for your company, and re-check them every year as the company grows. Even where it is not mandatory, many owners choose an internal audit for control and fraud prevention.

How CSM & Co LLP can help

Our internal audit team can help you:

  • Design a risk based internal audit plan and decide where analytics adds value
  • Run full population tests on payables, receivables, payroll, expenses and GST data
  • Review contracts and policies against your approved templates
  • Set up documentation and review steps so that tool based audit work stands up to scrutiny

Please reach out to our team and we will be happy to assist.

Frequently asked questions

Will AI replace internal auditors?

No. AI can read, match and flag very large volumes of data, but scoping the audit, judging whether a flag is a real control failure, talking to management and giving a conclusion remain the auditor’s work. The skill that grows in value is knowing how to question the tool’s output.

Is an internal audit mandatory for every company?

No. Section 138 of the Companies Act, 2013 read with Rule 13 of the Companies (Accounts) Rules, 2014 makes it mandatory for listed companies and for prescribed unlisted public and private companies based on paid up capital, turnover, borrowings and deposits. Please check the current thresholds for your company before deciding scope.

Can an AI flag be reported as an audit finding?

Not by itself. A flag is a lead. The auditor should trace it to the source documents, understand the business reason and confirm the control gap before it goes into a report.

Is it safe to upload company data to a public AI chatbot?

Usually not. Invoices, contracts, payroll and customer data are confidential, and the Digital Personal Data Protection Act, 2023 also applies to personal data. Use tools approved by the client, under a written agreement, or run them inside the client’s own environment.

Do small and mid sized companies benefit from AI in internal audit?

Yes, often for simple things first: matching bank statements to books, finding duplicate invoices, checking expense claims against policy and testing every entry instead of a sample. These need good spreadsheets and clean data more than expensive software.

Official sources

Related reading

Cited in

This article is cited in the reference list of "The Role of AI in Fraud Detection: Are Financial Institutions Using the Most Effective Systems?" (Hoje Jo, Hien Bui and Damon Moreland), Journal of Finance Issues, Vol. 23, No. 2 (2025). View the journal article.

Disclaimer

This article is for general informational purposes only and should not be considered professional advice. Please consult a qualified expert for advice tailored to your specific situation. The author and website owner are not liable for any errors or actions based on this content.