{"url_path":"/sec/infy/10-k/2026/item-15","section_key":"item-15","section_title":"Item 15 Controls and Procedures","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-06-15","source_url":"https://www.sec.gov/Archives/edgar/data/1067491/0001193125-26-270520-index.html","accession_number":"0001193125-26-270520","cik":"0001067491","ticker":"INFY","issuer_name":"Infosys Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1067491/0001193125-26-270520-index.html","primary_entity_key":"0001067491","primary_entity_name":"Infosys Ltd"},"word_count":1318,"has_tables":true,"body_markdown":"Item 15. Controls and Procedures\n\nDISCLOSURE CONTROLS AND PROCEDURES\n\nAs of the end of the period covered by this Annual Report on Form 20-F, our management, with the participation of our CEO and CFO, has carried out an evaluation of the effectiveness of our disclosure controls and procedures, as defined in Rules 13a-15(e) or 15d-15(e) promulgated under the Securities Exchange Act of 1934, as amended (the “Exchange Act”), at March 31, 2026. The term “disclosure controls and procedures” means controls and other procedures that are designed to ensure that information required to be disclosed in the reports we file or submit under the Exchange Act is recorded, processed, summarized and reported, within the time periods specified in the rules and forms of the SEC. Disclosure controls and procedures include, without limitation, controls and procedures designed to ensure that information required to be disclosed by us in our reports that we file or submit under the Exchange Act is accumulated and communicated to management, including our CEO and CFO, as appropriate to allow timely decisions regarding our required disclosure. In designing and evaluating our disclosure controls and procedures, management recognizes that any controls and procedures, no matter how well conceived and operated, can only provide reasonable assurance that the objectives of the disclosure controls and procedures are met.\n\nBased on their evaluation as of the end of the period covered by this Annual Report on Form 20-F, our CEO and CFO have concluded that our disclosure controls and procedures were effective to provide reasonable assurance that the information required to be disclosed in filings and submissions under the Exchange Act, is recorded, processed, summarized, and reported within the time periods specified by the SEC’s rules and forms, and that material information related to us and our consolidated subsidiaries is accumulated and communicated to management, including the Chief Executive Officer and Chief Financial Officer, as appropriate to allow timely decisions about required disclosure.\n\nManagement’s Annual Report on Internal Control over Financial Reporting\n\nOur management is responsible for establishing and maintaining adequate internal control over financial reporting as defined in Rules 13a-15(f) and 15d-15(f) under the Exchange Act. Our internal control over financial reporting is a process to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with International Financial Reporting Standards (IFRS), as issued by the International Accounting Standards Board (IASB). Our internal control over financial reporting includes those policies and procedures that:\n\n•\npertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of our assets;\n\n•\nprovide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with IFRS as issued by the IASB, and that our receipts and expenditures are being made only in accordance with authorizations of our management and directors; and\n\n•\nprovide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of our assets that could have a material effect on the financial statements.\n\nBecause of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.\n\nManagement assessed the effectiveness of our internal control over financial reporting as of March 31, 2026. In conducting its assessment of internal control over financial reporting, management based its evaluation on the Internal Control - Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Based on the assessment, management has concluded that our internal control over financial reporting was effective as of March 31, 2026.\n\nOur independent registered public accounting firm, Deloitte Haskins & Sells LLP, has audited the consolidated financial statements included in this Annual Report on Form 20-F, and as part of their audit, has issued their report, included herein, on the effectiveness of our internal control over financial reporting as of March 31, 2026.\n\nREPORT OF INDEPENDENT REGISTERED PUBLIC ACCOUNTING FIRM\n\nTo the Shareholders and the Board of Directors of Infosys Limited\n\nOpinion on Internal Control over Financial Reporting\n\nWe have audited the internal control over financial reporting of Infosys Limited (the “Company”) and subsidiaries (the “Group”) as of March 31, 2026, based on criteria established in Internal Control — Integrated Framework (2013) issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). In our opinion, the Group maintained, in all material respects, effective internal control over financial reporting as of March 31, 2026, based on criteria established in Internal Control — Integrated Framework (2013) issued by COSO.\n\nWe have also audited, in accordance with the standards of the Public Company Accounting Oversight Board (United States) (PCAOB), the consolidated financial statements as of and for the year ended March 31, 2026, of the Group and our report dated June 15, 2026, expressed an unqualified opinion on those consolidated financial statements.\n\nBasis for Opinion\n\nThe Group’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of internal control over financial reporting, included in the accompanying Management’s Annual Report on Internal Control over Financial Reporting. Our responsibility is to express an opinion on the Group’s internal control over financial reporting based on our audit. We are a public accounting firm registered with the PCAOB and are required to be independent with respect to the Group in accordance with the U.S. federal securities laws and the applicable rules and regulations of the Securities and Exchange Commission and the PCAOB.\n\nWe conducted our audit in accordance with the standards of the PCAOB. Those standards require that we plan and perform the audit to obtain reasonable assurance about whether effective internal control over financial reporting was maintained in all material respects. Our audit included obtaining an understanding of internal control over financial reporting, assessing the risk that a material weakness exists, testing and evaluating the design and operating effectiveness of internal control based on the assessed risk, and performing such other procedures as we considered necessary in the circumstances. We believe that our audit provides a reasonable basis for our opinion.\n\nDefinition and Limitations of Internal Control over Financial Reporting\n\nA company’s internal control over financial reporting is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. A company’s internal control over financial reporting includes those policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of the company; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the company are being made only in accordance with authorizations of management and directors of the company; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use, or disposition of the company’s assets that could have a material effect on the financial statements.\n\nBecause of its inherent limitations, internal control over financial reporting may not prevent or detect misstatements. Also, projections of any evaluation of effectiveness to future periods are subject to the risk that controls may become inadequate because of changes in conditions, or that the degree of compliance with the policies or procedures may deteriorate.\n\n \n\n/s/ Deloitte Haskins & Sells LLP\n\nBengaluru, India\n\nJune 15, 2026\n\nCHANGES IN INTERNAL CONTROL OVER FINANCIAL REPORTING\n\nDuring the period covered by this Annual Report on Form 20-F, there were no changes in our internal control over financial reporting that have materially affected or are reasonably likely to materially affect our internal control over financial reporting."}