What Happened?
On July 31, 2026, the Reserve Bank of India (RBI) issued comprehensive new directions on the Internal Audit Function for Commercial Banks. These directions, issued under Section 35-A of the Banking Regulation Act, 1949, replace all previous internal audit guidelines and are effective immediately. The new framework emphasizes Risk-Based Internal Audit (RBIA) rather than transaction-centric auditing, bringing Indian banking standards in line with international best practices and evolving governance requirements.
Background & Legal Context
Why Did RBI Issue These Directions?
The RBI recognized that traditional transaction-centric audit approaches have limitations in identifying systemic risks and control weaknesses. Modern banking operations are complex, involve diverse business lines, and face evolving regulatory challenges. Therefore, the RBI mandated a shift to Risk-Based Internal Audit (RBIA), which focuses on:
- Assessment of risk management systems and internal controls
- Evaluation of control effectiveness across all business activities
- Identification and prioritization of audit areas based on risk levels
- Selective transaction testing aligned with risk profiles
Applicability
These directions apply to all Commercial Banks, defined as:
- Banking companies (excluding Small Finance Banks, Payments Banks, and Local Area Banks)
- Corresponding new banks
- State Bank of India
- Foreign banks operating as branches in India
The directions do NOT apply to NBFCs, insurance companies, or non-banking financial institutions.
Legal Framework
These directions are issued under the Banking Regulation Act, 1949, making them binding on all applicable banks. They supersede all previous RBI circulars, instructions, and guidelines on internal audit, communicated vide circular DoS.CO.PPG.66/11.01.005/2026-27 dated July 31, 2026.
What Does This Mean for You?
For Bank Management & Board Members:
Your Board and Audit Committee must now:
- Approve RBIA Policy: The Board must formally approve the bank's Risk-Based Internal Audit policy, including the risk assessment methodology
- Approve Annual Audit Plan (AAP): The Board must approve the schedule and rationale for all planned audit work
- Approve Risk Assessment Methodology: Customized to the bank's size, complexity, and business model
- Oversee Performance: The Audit Committee must periodically assess RBIA system reliability, accuracy, and objectivity
- Set Service Period Standards: Establish minimum service periods for internal audit staff (except for specialized audit-focused institutions)
For Internal Audit Department (IAD):
The IAD must implement the new risk-based framework:
- Functional Independence: The IAD must be completely independent from internal control processes and not assigned other accounting or operational functions
- Risk Assessment: Conduct annual risk assessments identifying inherent business risks and control risks at corporate, branch, portfolio, and transaction levels
- Risk Matrix Approach: Use a 3×3 risk matrix combining inherent business risks and control risks to classify areas as Low, Medium, High, Very High, or Extremely High Risk
- Transaction Testing: Determine extent of testing (up to 100% for extremely high-risk areas) based on risk classification
- Comprehensive Scope: Review risk identification processes, control environment, fraud-prone areas, data integrity, regulatory compliance, budgetary controls, and money laundering controls
For Head of Internal Audit (HIA):
The HIA's role is significantly strengthened:
- Tenure: Must be appointed for a minimum of 3 years (except in specialized audit-focused institutions) to ensure continuity
- Reporting Line: Reports directly to the Audit Committee, MD & CEO, or Whole Time Director—NOT to business verticals
- No Business Targets: Cannot be assigned any business targets or KPIs linked to profitability
- Direct Access: Has authority to communicate with any staff and access all records necessary for audit work
- Quarterly Meetings: The Audit Committee must meet the HIA at least quarterly without senior management present
For Staffing & Professional Development:
- Banks must provide adequate resources and staffing to IAD
- Staff must receive training on banking operations, accounting, IT, data analytics, and forensic investigation
- Remuneration of audit staff cannot be linked to financial performance of business lines they audit
- Banks may engage retired personnel on contractual basis for up to 3 years in specialized areas (subject to Audit Committee approval)
For Outsourcing Arrangements:
While the IAD itself cannot be outsourced, banks may hire external experts subject to:
- Audit Committee assurance that internal expertise is unavailable
- Written contracts specifying scope, frequency, reporting, cost accountability, and data security
- Work papers remain bank property with employee access rights
- Contingency plans for sudden vendor termination
What Should You Do Now?
Immediate Actions (Next 30 Days):
- Review Current Framework: Audit all existing internal audit policies against the new RBIA requirements
- Board Approval: If not already done, obtain formal Board approval for RBIA policy, risk assessment methodology, and AAP
- HIA Reporting Structure: Verify that the HIA reports to the Audit Committee or appropriate authority as specified
- Policy Documentation: Ensure all RBIA policies are properly documented and communicated to staff
Medium-Term Actions (30-90 Days):
- Risk Assessment Methodology: Develop or refine risk assessment methodology covering inherent business risks and control risks
- Risk Mapping: Prepare risk matrices for all business activities and locations using the 3×3 framework
- Annual Audit Plan: Formulate AAP based on risk assessment, prioritizing high, very high, and extremely high-risk areas
- Staff Competency Assessment: Evaluate IAD staff skills and arrange training in data analytics, IT audit, and forensics
- Independence Review: Ensure IAD has no operational responsibilities that could compromise independence
Long-Term Compliance (Ongoing):
- Annual Risk Assessment: Conduct risk assessments at least annually, more frequently if business changes occur
- Performance Reviews: IAD must conduct periodic reviews of RBIA effectiveness versus approved AAP
- Audit Committee Meetings: Ensure Audit Committee meets HIA quarterly without senior management
- Communication Protocol: Establish channels for reporting serious deficiencies immediately to appropriate management levels
- Regulatory Updates: Monitor RBI clarifications and interpretations issued under Section 41 of the directions
Key Takeaways
- Risk-Based Approach is Mandatory: All commercial banks must transition from transaction-centric to risk-based internal audit frameworks by December 31, 2026 (reasonable implementation timeline)
- Board Accountability Increased: Boards must actively approve, oversee, and assess the effectiveness of the RBIA system—this is no longer an operational-level function
- IAD Independence is Critical: Internal audit departments must operate completely independently from business functions, with separate reporting lines and no performance linkage to profitability
- HIA Role Strengthened: Head of Internal Audit now has enhanced authority, longer tenure, direct access to all records, and quarterly one-on-one meetings with the Audit Committee
- Regulatory Scrutiny Expected: RBI will examine compliance during supervisory audits; non-compliance could result in regulatory action under Section 35-A of the Banking Regulation Act
Practical Compliance Example: If a bank identifies a high-magnitude, high-frequency lending activity as "Very High Risk" based on recent control failures, the RBIA framework requires 100% transaction testing and immediate allocation of maximum audit resources. This differs from the old approach where such testing might have been deferred or sampled.
Important Note for Taxpayers: While these RBI directions apply to banks (not individual taxpayers), they impact banks' internal control environments. Better internal controls mean more accurate financial reporting, which benefits depositors and reduces systemic financial risk. If you are a bank official or audit staff, ensure your institution complies fully.
Need expert help with this? EaseValue CAs in Jaipur — WhatsApp 63677 44602
EaseValue