Reserve Bank of India (Commercial Banks - Compliance Function) Directions, 2026
RBI/DoS/2026-27/408 DoS.CO.PPG.2/11.01.005/2026-27 July 31, 2026 Reserve Bank of India (Commercial Banks - Compliance Function) Directions, 2026 Table of Contents Introduction Chapter I - Preliminary A. Short Title and Commencement B. Applicability C. Definitions Chapter II - Governance and Oversight A. Role of the Boa…
Source details
- Source
- Reserve Bank of India
- Type
- notification
- Published by source
- 30 Jul 2026
- Coverage area
- banking
Document text
RBI/DoS/2026-27/408 DoS.CO.PPG.2/11.01.005/2026-27 July 31, 2026
Reserve Bank of India (Commercial Banks - Compliance Function) Directions, 2026
Table of Contents
- Introduction
- Chapter I - Preliminary
- Chapter II - Governance and Oversight
- Chapter III - Scope, Structure and Responsibilities
- Chapter IV - Chief Compliance Officer
- Chapter V - Use of Technology for Monitoring
- Chapter VI - Repeal and Other Provisions
Introduction
Compliance function is a key element of a bank’s corporate governance framework and an integral part of assurance, alongside internal audit and risk management processes. The principles governing the Compliance function are aligned with the Basel Committee on Banking Supervision framework, adapted to the Indian operating environment, and extend to bank-led Financial Conglomerates for managing group-wide compliance risk. While minimum standards are prescribed, the bank shall organise its Compliance function and prioritise compliance risk management in a manner commensurate with its size, complexity, risk profile, and organisational structure.
In exercise of the powers conferred by Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues Directions hereinafter specified.
Chapter I - Preliminary
A. Short Title and Commencement
- These Directions shall be called the Reserve Bank of India (Commercial Banks - Compliance Function) Directions, 2026.
- These Directions shall come into effect immediately upon issuance.
B. Applicability
- These Directions shall be applicable to Commercial Banks (hereinafter collectively referred to as 'banks' and individually as 'bank').
For the purpose of these Directions, ‘Commercial Banks’ means banking companies (other than Small Finance Banks, Payments Banks, and Local Area Banks), corresponding new banks, and the State Bank of India, as defined respectively under clauses (c), (da), and (nc) of Section 5 of the Banking Regulation Act, 1949.
C. Definitions
-
In these Directions, unless the context states otherwise, the terms herein shall bear the meaning assigned to them below: (1) ‘Compliance Risk’ shall mean the risk of legal or regulatory sanctions, material financial loss, or loss to reputation a bank may suffer as a result of its failure to comply with laws, regulations, rules, related self-regulatory organisation standards, and codes of conduct applicable to its banking activities (together, ‘compliance laws, rules, and standards’).
-
All other expressions unless defined herein shall have the same meaning as have been assigned to them under the Reserve Bank of India Act, 1934, the Banking Regulation Act, 1949, the Companies Act, 2013, or any statutory modification or re-enactment thereto or other regulations issued by RBI or the Glossary of Terms published by RBI or as used in commercial parlance, as the case may be.
Chapter II - Governance and Oversight
A. Role of the Board
- The Board shall have an overall responsibility for the effective oversight and management of the bank’s Compliance function and compliance risk.
- The Board shall ensure that the bank has an appropriate Compliance Policy in place and shall oversee its effective implementation. The Board shall review the policy at least annually.
- The Board shall ensure that compliance issues are resolved effectively and expeditiously by senior management with the assistance of compliance staff. If necessary, the Board may delegate these tasks to the Audit Committee of the Board (ACB).
- The Board or ACB shall review the Compliance function on a quarterly basis. A detailed annual review should also be placed before the Board / ACB. The Chief Compliance Officer (CCO) should be an invitee to such meetings.
- The Board shall ensure that the Compliance function and the Internal Audit function of the bank are kept separate.
B. Role of the Senior Management
- The Managing Director and Chief Executive Officer (MD & CEO) shall ensure the presence of an independent Compliance function and adherence to the compliance policy of the bank.
- The senior management shall establish a written Compliance policy which should contain the basic principles to be followed by the management and staff and explain the process by which compliance risk shall be identified and managed through all levels of the bank.
- The senior management shall ensure that appropriate remedial or disciplinary action is taken if breaches are identified.
- Senior management shall, with the assistance of the Compliance Function: (1) identify and assess, at least annually, the main compliance risks facing the bank and formulate the plans to manage them; (2) submit to the Board / ACB, as the case may be, quarterly and annual reviews as prescribed at paragraph 9, in such a manner as to assist the Board members to make an informed judgment on whether the bank is managing its compliance risk effectively; and (3) report promptly any material compliance failure (e.g., failure that may attract a significant risk of legal or regulatory sanctions, material financial loss, or loss to reputation) to the Board / ACB and take appropriate remedial measures.
C. Compliance Policy
- The Board-approved Compliance policy of the bank should clearly spell out its compliance philosophy, expectations on compliance culture covering tone from the top, accountability, incentive structure, effective communication and challenges thereof, structure and role of the Compliance function, authority, and role of the CCO, processes for identifying, assessing, monitoring, managing, and reporting on compliance risk throughout the bank.
- The Compliance policy shall, inter alia, adequately consider the size, complexity, and compliance risk profile of the bank, expectations on ensuring compliance to all applicable statutory provisions, rules, and regulations, various codes of conduct (including the voluntary ones) and the bank’s own internal rules, policies and procedures, and a disincentive structure for compliance breaches. The policy should emphasise building up compliance culture, vetting of the quality of reports provided to RBI by the bank.
- The policy should cover the following aspects: (1) Establishment of an independent Compliance Department at the Head Office headed by the CCO with adequate support staff and its role and responsibilities specified. (2) Compliance units in controlling offices and branches specifying the role and responsibility of each functionary within such compliance units. (3) Measures to ensure independence of the Compliance function. (4) Focus of the Compliance function on ensuring compliance with regulatory and statutory requirements, fair practice codes, and other codes prescribed / suggested by self-regulatory organisations, government policies, bank's internal policies, and requirements relating to the prevention of money laundering and funding of illegal activities. (5) Monitoring mechanism for the compliance testing procedure. (6) Reporting requirements including inter alia reporting of monitoring results, compliance risk assessment and change in the compliance risk profile, by the Compliance function to the senior management and the Board / ACB, as the case may be. (7) Right of the Compliance function to have access to information necessary to carry out its responsibilities and for pointing out / looking into possible breaches of Compliance policy. (8) Relationship between CCO and heads of other functional departments. (9) Independence of the Compliance function from Internal Audit function and clarity on their respective roles. (10) Mechanism for dissemination of information on regulatory directions and guidelines among operational staff and periodic updating of operational manuals to incorporate changes in regulatory, legal and other applicable requirements. (11) Approval process for all new processes and products by the Compliance Department prior to their introduction. (12) Right of the Compliance function to freely disclose its findings and views to senior management, Board / ACB, as the case may be.
Research the source law
Find the provision behind this update.
No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source laws