Reserve Bank of India (Small Finance Banks - Internal Audit Function) Directions, 2026
RBI/DoS/2026-27/422 DoS.CO.PPG.16/11.01.005/2026-27 July 31, 2026 Reserve Bank of India (Small Finance Banks - Internal Audit Function) Directions, 2026 Table of Contents Introduction Chapter I - Preliminary A. Short Title and Commencement B. Applicability C. Definitions Chapter II - Governance and Oversight A. Role of…
Source details
- Source
- Reserve Bank of India
- Type
- master-direction
- Published by source
- 30 Jul 2026
- Coverage area
- banking
Document text
RBI/DoS/2026-27/422 DoS.CO.PPG.16/11.01.005/2026-27 July 31, 2026
Reserve Bank of India (Small Finance Banks - Internal Audit Function) Directions, 2026
Table of Contents
- Introduction
- Chapter I - Preliminary
- A. Short Title and Commencement
- B. Applicability
- C. Definitions
- Chapter II - Governance and Oversight
- A. Role of the Board
- B. Role of the Senior Management
- Chapter III - Risk-Based Internal Audit Framework
- A. Policy on Internal Audit
- B. Functional Independence
- C. Risk Assessment
- D. Scope
- E. Communication
- F. Performance Evaluation
- G. Outsourcing
- Chapter IV - Head of Internal Audit
- A. Authority, Stature, and Independence
- B. Tenure
- C. Reporting Line
- Chapter V - Repeal and Other Provisions
- A. Repeal and Saving
- B. Application of Other Laws Not barred
- C. Interpretations
Introduction
A sound Internal Audit function is an integral component of a bank’s internal control and risk management framework. In view of the limitations of a transaction-centric audit approach, the bank is required to adopt Risk Based Internal Audit (RBIA), which places emphasis on the assessment of risk management systems and internal controls, in addition to selective transaction testing, in alignment with evolving governance standards and international best practices.
In exercise of the powers conferred by Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues the Directions hereinafter specified.
Chapter I - Preliminary
A. Short Title and Commencement
- These Directions shall be called the Reserve Bank of India (Small Finance Banks - Internal Audit Function) Directions, 2026.
- These Directions shall come into effect immediately upon issuance.
B. Applicability
- These Directions shall be applicable to Small Finance Banks (hereinafter collectively referred to as ‘banks’ and individually as a ‘bank’).
C. Definitions
- All expressions used in these Directions, shall have the same meaning as have been assigned to them under the Reserve Bank of India Act, 1934, the Banking Regulation Act, 1949, the Companies Act, 2013, or any statutory modification or re-enactment thereto or other regulations issued by RBI or the Glossary of Terms published by RBI or as used in commercial parlance, as the case may be.
Chapter II - Governance and Oversight
A. Role of the Board
- The Board of the bank shall approve the following: (1) A well-defined policy for undertaking RBIA. (2) A risk assessment methodology devised by the Internal Audit Department (IAD) of the bank, keeping in view the size and complexity of the business undertaken by the bank. (3) An Annual Audit Plan (AAP) which should include the schedule and the rationale for audit work planned. (4) A policy to engage the services of the bank’s retired personnel for a maximum tenure not exceeding three years in areas where it does not have enough expertise which shall, inter alia, include the terms of engagement, review of performance, termination of services.
- The Board shall be responsible for ensuring that an effective RBIA system is in place, and its importance is understood throughout the bank.
- The Board / Audit Committee of the Board (ACB) shall periodically assess the performance of the RBIA for reliability, accuracy, and objectivity.
- The Board shall prescribe a minimum period of service for staff in the Internal Audit function, except for banks where the Internal Audit function is a specialised function and managed by career internal auditors. The Board may also examine the feasibility of prescribing at least one stint of service in the Internal Audit function for those staff possessing specialised knowledge useful for the audit function, but who are posted in other departments, so as to have adequate skills for the staff in the Internal Audit function.
B. Role of the Senior Management
- The Senior Management shall ensure that the importance of an effective RBIA system is understood throughout the bank, and the Internal Audit staff perform their duties with objectivity and impartiality.
Chapter III - Risk-Based Internal Audit Framework
A. Policy on Internal Audit
- The primary focus of Risk-Based Internal Audit (RBIA) shall be to provide reasonable assurance to the Board and senior management about the adequacy and effectiveness of the risk management and control framework in the bank’s operations. While examining the effectiveness of control framework, the RBIA shall report on proper recording as well as reporting of major exceptions and excesses.
- The RBIA should focus on risk identification, prioritisation of audit areas, and allocation of audit resources in accordance with the risk assessment. The policy shall include the risk assessment methodology for identifying the risk areas based on which the audit plan would be formulated. It shall also lay down the maximum time period beyond which even the low-risk business activities / locations shall not remain unaudited.
- The bank shall ensure and demonstrate through proper documentation that its RBIA framework captures all the significant criteria / principles suited for its organisational structure, business model and risks. The Information Systems Audit should also be carried out using the risk-based approach.
B. Functional Independence
- The IAD of the bank shall be independent from the internal control process in order to avoid any conflict of interest and should be given an appropriate standing within a bank to carry out its assignments. It shall not be assigned the responsibility of performing other accounting or operational functions.
- The bank shall distinguish between the functions of the Risk Management Department and the role of RBIA. While the Risk Management Department focuses on areas such as identification, monitoring and measurement of risks, development of policies and procedures, and use of risk management models, RBIA shall undertake an independent risk assessment solely for the purpose of formulating the risk-based audit plan keeping in view the inherent business risks of an activity / location and the effectiveness of the control systems for monitoring the inherent risks of the business activity. While formulating the audit plan, every activity / location of the bank, including the Risk Management function, shall be subjected to risk assessment by the RBIA.
- The bank shall provide appropriate resources and staff to the IAD to achieve its objectives under the RBIA system. Requisite professional competence, knowledge, and experience of each internal auditor are essential for the effectiveness of a bank's Internal Audit function. They should also be trained periodically to enable them to understand the bank’s business activities, operating procedures, risk management and control systems, and Management Information System (MIS). The desired areas of knowledge and experience may include banking operations, accounting, information technology, data analytics, and forensic investigation, among others. The bank shall ensure that its Internal Audit function has the requisite skills to audit all areas of the bank.
- The bank shall not link the remuneration of Internal Audit staff to the financial performance of the business lines for which they exercise audit responsibilities. The bank shall structure the remuneration policy in a way that it avoids creating conflict of interest and compromising audit’s independence and objectivity.
C. Risk Assessment
- The risk assessment should, as an independent activity, cover risks at various levels (corporate and branch; the portfolio and individual transactions, etc.) as also the processes in place to identify, measure, monitor, and control the risks.
- The Board - approved risk assessment methodology shall, inter alia, include the following: (1) Identification of inherent business risks in various activities undertaken by the bank. (2) Evaluation of the effectiveness of the control systems for monitoring the inherent risks of the business activities (‘Control risk’). (3) Drawing up a risk-matrix for considering both the factors viz., inherent business risks and control risks. An illustrative risk-matrix and guidance are given as a box item below:
Research the source law
Find the provision behind this update.
No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source lawsRelated RBI updates
- Governor’s Statement: August 5, 2026
- Monetary Policy Statement, 2026-27 Resolution of the Monetary Policy Committee August 3 to 5, 2026
- Money Market Operations as on August 4, 2026
- Statement on Developmental and Regulatory Policies
- Directions under Section 35A read with Section 56 of the Banking Regulation Act, 1949 – The Pusad Urban Co-operative Bank Ltd., Pusad, Dist. Yavatmal, Maharashtra – Extension of Period