RBI30 Jul 2026master-directionPrepared by Complied AI

Reserve Bank of India (Commercial Banks - Internal Audit Function) Directions, 2026

RBI/DoS/2026-27/413 DoS.CO.PPG.7/11.01.005/2026-27 July 31, 2026 Reserve Bank of India (Commercial Banks - Internal Audit Function) Directions, 2026 Table of Contents Introduction Chapter I - Preliminary A. Short Title and Commencement B. Applicability Chapter II - Governance and Oversight A. Role of the Board B. Role…

Source details

Source
Reserve Bank of India
Type
master-direction
Published by source
30 Jul 2026
Coverage area
banking

Document text

Prepared for reading; wording retained from the source.

Verify official record

RBI/DoS/2026-27/413 DoS.CO.PPG.7/11.01.005/2026-27 July 31, 2026

Reserve Bank of India (Commercial Banks - Internal Audit Function) Directions, 2026

Table of Contents

  • Introduction
  • Chapter I - Preliminary
    • A. Short Title and Commencement
    • B. Applicability
  • Chapter II - Governance and Oversight
    • A. Role of the Board
    • B. Role of the Senior Management
  • Chapter III - Risk-Based Internal Audit Framework
    • A. Policy on Internal Audit
    • B. Functional Independence
    • C. Risk Assessment
    • D. Scope
    • E. Communication
    • F. Performance Evaluation
    • G. Outsourcing
  • Chapter IV - Head of Internal Audit
    • A. Authority, Stature, and Independence
    • B. Tenure
    • C. Reporting Line
  • Chapter V - Repeal and Other Provisions
    • A. Repeal and Saving
    • B. Application of Other Laws Not barred
    • C. Interpretations

Introduction

A sound Internal Audit function is an integral component of a bank’s internal control and risk management framework. In view of the limitations of a transaction-centric audit approach, the banks are required to adopt Risk Based Internal Audit (RBIA), which places emphasis on the assessment of risk management systems and internal controls, in addition to selective transaction testing, in alignment with evolving governance standards and international best practices.

In exercise of the powers conferred by Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues the Directions hereinafter specified.

Chapter I - Preliminary

A. Short Title and Commencement

  1. These Directions shall be called the Reserve Bank of India (Commercial Banks - Internal Audit Function) Directions, 2026.
  2. These Directions shall come into effect immediately upon issuance.

B. Applicability

  1. These Directions shall be applicable to Commercial Banks (hereinafter collectively referred to as ‘banks’ and individually as a ‘bank’).

For the purpose of these Directions, ‘Commercial Banks’ means banking companies (other than Small Finance Banks, Payments Banks, and Local Area Banks), corresponding new banks, and the State Bank of India, as defined respectively under clauses (c), (da), and (nc) of Section 5 of the Banking Regulation Act, 1949.

Chapter II - Governance and Oversight

A. Role of the Board

  1. The Board of the bank / Local Advisory Board (LAB) (in case of a foreign bank) shall approve the following: (1) A well-defined policy for undertaking RBIA. (2) A risk assessment methodology devised by the Internal Audit Department (IAD) of the bank, keeping in view the size and complexity of the business undertaken by the bank. (3) An Annual Audit Plan (AAP) which should include the schedule and the rationale for audit work planned. (4) A policy to engage the services of the bank’s retired personnel for a maximum tenure not exceeding three years in areas where it does not have enough expertise which shall, inter alia, include the terms of engagement, review of performance, termination of services.
  2. The Board / LAB shall be responsible for ensuring that an effective RBIA system is in place, and its importance is understood throughout the bank.
  3. The Board / Audit Committee of the Board (ACB) / LAB shall periodically assess the performance of the RBIA for reliability, accuracy, and objectivity.
  4. The Board / LAB shall prescribe a minimum period of service for staff in the Internal Audit function, except for banks where the Internal Audit function is a specialised function and managed by career internal auditors. The Board / LAB may also examine the feasibility of prescribing at least one stint of service in the Internal Audit function for those staff possessing specialised knowledge useful for the audit function, but who are posted in other departments, so as to have adequate skills for the staff in the Internal Audit function.

B. Role of the Senior Management

  1. The Senior Management shall ensure that the importance of an effective RBIA system is understood throughout the bank, and the Internal Audit staff perform their duties with objectivity and impartiality.

Chapter III - Risk-Based Internal Audit Framework

A. Policy on Internal Audit

  1. The primary focus of Risk-Based Internal Audit (RBIA) shall be to provide reasonable assurance to the Board and senior management about the adequacy and effectiveness of the risk management and control framework in the bank’s operations. While examining the effectiveness of control framework, the RBIA shall report on proper recording as well as reporting of major exceptions and excesses.
  2. The RBIA should focus on risk identification, prioritisation of audit areas, and allocation of audit resources in accordance with the risk assessment. The policy shall include the risk assessment methodology for identifying the risk areas based on which the audit plan would be formulated. It shall also lay down the maximum time period beyond which even the low-risk business activities / locations shall not remain unaudited.
  3. The bank shall ensure and demonstrate through proper documentation that its RBIA framework captures all the significant criteria / principles suited for its organisational structure, business model and risks. The Information Systems Audit should also be carried out using the risk-based approach.

B. Functional Independence

  1. The IAD of the bank shall be independent from the internal control process in order to avoid any conflict of interest and should be given an appropriate standing within a bank to carry out its assignments. It shall not be assigned the responsibility of performing other accounting or operational functions.
  2. The bank shall distinguish between the functions of the Risk Management Department and the role of RBIA. While the Risk Management Department focuses on areas such as identification, monitoring and measurement of risks, development of policies and procedures, and use of risk management models, RBIA shall undertake an independent risk assessment solely for the purpose of formulating the risk-based audit plan keeping in view the inherent business risks of an activity / location and the effectiveness of the control systems for monitoring the inherent risks of the business activity. While formulating the audit plan, every activity / location of the bank, including the Risk Management function, shall be subjected to risk assessment by the RBIA.
  3. The bank shall provide appropriate resources and staff to the IAD to achieve its objectives under the RBIA system. Requisite professional competence, knowledge, and experience of each internal auditor are essential for the effectiveness of a bank's Internal Audit function. They should also be trained periodically to enable them to understand the bank’s business activities, operating procedures, risk management and control systems, and Management Information System (MIS). The desired areas of knowledge and experience may include banking operations, accounting, information technology, data analytics, and forensic investigation, among others. The bank shall ensure that its Internal Audit function has the requisite skills to audit all areas of the bank.
  4. The bank shall not link the remuneration of Internal Audit staff to the financial performance of the business lines for which they exercise audit responsibilities. The bank shall structure the remuneration policy in a way that it avoids creating conflict of interest and compromising audit’s independence and objectivity.

C. Risk Assessment

  1. The risk assessment should, as an independent activity, cover risks at various levels (corporate and branch; the portfolio and individual transactions, etc.) as also the processes in place to identify, measure, monitor, and control the risks.
  2. The Board - approved risk assessment methodology shall, inter alia, include the following: (1) Identification of inherent business risks in various activities undertaken by the bank. (2) Evaluation of the effectiveness of the control systems for monitoring the inherent risks of the business activities (‘Control risk’). (3) Drawing up a risk-matrix for considering both the factors viz., inherent business risks and control risks. An illustrative risk-matrix and guidance are given as a box item below:

Showing 1,262 of 3,445 words

Research the source law

Find the provision behind this update.

No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.

Browse source laws