RBI30 Jul 2026master-directionPrepared by Complied AI

Reserve Bank of India (Urban Co-operative Banks - Internal Audit Function) Directions, 2026

RBI/DoS/2026-27/440 DoS.CO.PPG.34/11.01.005/2026-27 July 31, 2026 Reserve Bank of India (Urban Co-operative Banks - Internal Audit Function) Directions, 2026 Table of Contents Introduction Chapter I - Preliminary A. Short Title and Commencement B. Applicability C. Definitions Chapter II - Governance and Oversight A. Ro…

Source details

Source
Reserve Bank of India
Type
master-direction
Published by source
30 Jul 2026
Coverage area
banking

Document text

Prepared for reading; wording retained from the source.

Verify official record

RBI/DoS/2026-27/440 DoS.CO.PPG.34/11.01.005/2026-27 July 31, 2026

Reserve Bank of India (Urban Co-operative Banks - Internal Audit Function) Directions, 2026

Table of Contents

  • Introduction
  • Chapter I - Preliminary
    • A. Short Title and Commencement
    • B. Applicability
    • C. Definitions
  • Chapter II - Governance and Oversight
    • A. Role of the Board
    • B. Role of the Senior Management
  • Chapter III - Risk-Based Internal Audit Framework
    • A. Policy on Internal Audit
    • B. Objectives and Scope
    • C. Authority, Stature, and Independence
    • D. Risk Assessment
    • E. Audit Plan
    • F. Monitoring of Compliance
    • G. Outsourcing
  • Chapter IV - Head of Internal Audit
    • A. Authority, Stature, and Independence
    • B. Tenure
    • C. Reporting Line
  • Chapter V - Inspection and Internal Audit System
    • A. System and Structure
    • B. Periodicity and Coverage
    • C. Special Audits
    • D. Other Instructions
  • Chapter VI - Repeal and Other Provisions
    • A. Repeal and Saving
    • B. Application of Other Laws Not barred
    • C. Interpretations

Introduction

An independent and effective Internal Audit function is integral to sound corporate governance in Urban Co-operative Banks and provides assurance to the Board and senior management on the adequacy and effectiveness of internal controls, risk management, and governance. Given the commonality of risks faced by Urban Co-operative Banks, there is a need for harmonised Internal Audit systems and processes based on uniform guiding principles. Risk-Based Internal Audit (RBIA) framework, as the third line of defence, is intended to strengthen the effectiveness of Internal Audit systems and processes in Urban Co-operative Banks.

In exercise of the powers conferred by Section 35-A read with Section 56 of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues Directions hereinafter specified.

Chapter I - Preliminary

A. Short Title and Commencement

  1. These Directions shall be called the Reserve Bank of India (Urban Co-operative Banks - Internal Audit Function) Directions, 2026.
  2. These Directions shall come into effect immediately upon issuance.

B. Applicability

  1. These Directions shall be applicable to Urban Co-operative Banks (hereinafter collectively referred to as ‘UCBs’ and individually as ‘UCB’).

For the purpose of these Directions, ‘Urban Co-operative Banks’ shall mean Primary Co-operative Banks as defined under Section 5(ccv) as applicable to co-operative societies, read with Section 56 of Banking Regulation Act, 1949.

Provided that Chapter II, III and IV of these Directions shall be applicable to UCBs having asset size of ₹500 crore and above except Salary Earners UCBs, Unit UCBs, and UCBs under All Inclusive Directions.

Provided that Chapter V of these Directions shall be applicable to UCBs having asset size of less than ₹500 crore, all Salary Earners UCBs, Unit UCBs, and UCBs under All Inclusive Directions.

C. Definitions

  1. All expressions used in these Directions, shall have the same meaning as have been assigned to them under the Reserve Bank of India Act, 1934, the Banking Regulation Act, 1949, the Companies Act, 2013, or any statutory modification or re-enactment thereto or other regulations issued by RBI or the Glossary of Terms published by RBI or as used in commercial parlance, as the case may be.

Chapter II - Governance and Oversight

A. Role of the Board

  1. The Board / Audit Committee of Board (ACB) of the UCB shall be primarily responsible for overseeing the Internal Audit function. It shall approve a RBIA plan to determine the priorities of the Internal Audit function based on the level and direction of risk, consistent with the UCB’s goals.
  2. The Board / ACB shall review the performance of RBIA. The Board / ACB should formulate and maintain a quality assurance and improvement program that covers all aspects of the Internal Audit function. The quality assurance program may include assessment of the Internal Audit function at least once a year for adherence to the Internal Audit policy, objectives, and expected outcomes.
  3. The Board / ACB shall promote the use of new audit tools / new technologies for reducing the extent of manual monitoring / transaction testing / compliance monitoring.
  4. The Board should prescribe a minimum period of service for staff in the Internal Audit function except for those UCBs where the Internal Audit function is a specialised function and managed by career internal auditors. The Board may also examine the feasibility of prescribing at least one stint of service in the Internal Audit function for those staff possessing specialised knowledge useful for the audit function, but who are posted in other areas, so as to have adequate skills for the staff in the Internal Audit function.

B. Role of the Senior Management

  1. The senior management is responsible for ensuring adherence to the Internal Audit Policy as approved by the Board and development of an effective internal control function that identifies, measures, monitors, and reports all risks faced. It shall ensure that appropriate action is taken on the Internal Audit findings within given timelines and status on closure of audit reports is placed before the Board / ACB.
  2. The senior management shall be responsible for establishing a comprehensive and independent Internal Audit function which should promote accountability and transparency. It shall ensure that the Internal Audit function is adequately staffed with skilled personnel of right aptitude and attitude who are periodically trained to update their knowledge, skill, and competencies.
  3. The senior management shall, based on inputs from all forms of audit, present a consolidated position of major risks faced by the UCB at least annually to the Board / ACB.

Chapter III - Risk-Based Internal Audit Framework

A. Policy on Internal Audit

  1. The Risk-Based Internal Audit (RBIA) Framework relies broadly on a well-defined policy for Internal Audit, functional independence with sufficient standing, effective channels of communication and adequate audit resources with sufficient professional competence.
  2. The Board approved policy shall clearly document the purpose, authority, and responsibility of the internal audit activity, with a clear demarcation of the role and expectations from Risk Management function and Risk Based Internal Audit function. The policy should be consistent with the size and nature of the business undertaken, the complexity of operations and should factor in the key attributes of Internal Audit function relating to independence, objectivity, professional ethics, and accountability.
  3. The policy should also lay down the maximum time period beyond which even the low-risk business activities / locations would not remain excluded for audit.
  4. The policy should be reviewed periodically and disseminated widely within the organisation.

B. Objectives and Scope

  1. RBIA as an effective audit methodology should link the UCB's overall risk management framework and provide assurance to the Board and the senior management on the quality and effectiveness of the UCB’s internal controls, risk management, and governance related systems and processes.
  2. The Internal Audit function should assess and contribute to the overall improvement of the UCB’s governance, risk management, and control processes using a systematic and disciplined approach. It should work on the basis of established policies and procedures as approved by the Board / ACB.
  3. RBIA, in addition to selective transaction testing, shall include an evaluation of the risk management systems and control procedures in various areas of operations, which will also help in anticipating areas of potential risks and mitigating such risks.
  4. While the Risk Management function should focus on identification, measurement, monitoring, and management of risks, development of risk policies and procedures, and use of risk management models, RBIA should undertake an independent risk assessment for the purpose of formulating a risk-based audit plan which considers the inherent business risks emanating from an activity / location and the effectiveness of the control systems for monitoring such inherent risks.
  5. The Internal Audit function should assess and make appropriate recommendations to improve the governance processes on business decision making, risk management and control; promote appropriate ethics and values within the UCB; and ensure effective performance management and staff accountability.

Showing 1,298 of 3,408 words

Research the source law

Find the provision behind this update.

No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.

Browse source laws