Current · Source: Reserve Bank of India · RBI/2010-11/340 · issued 27 Dec 2010 · ~1 min read
Quick answerRBI mandates all authorised entities to submit annual system audit reports from a CISA-qualified auditor. For April-March entities, reports due by June 1; for calendar-year entities, by March 1 of the following year.
The rule, in the simplest words
Banks and payment system operators must have their system audits done annually by a CISA-certified professional.
The system audit report must be submitted to RBI within two months after the year-end, depending on the financial year: June 1 for April-March entities and March 1 for calendar-year entities.
Missing the deadlines could invite regulatory scrutiny under the Payment and Settlement Systems Act, 2007.
How it plays out — a real example
Rahul, a branch operations officer in Indore, ensures that their bank's system audit is conducted annually by a CISA-certified auditor. They submit the report to RBI by June 1, meeting the deadline for April-March entities. This helps maintain the bank's IT and payment system security, giving customers peace of mind when using their services.
What changed
This circular reiterates the requirement for annual system audit reports from CISA-qualified auditors, originally introduced in December 2009. It specifies clear submission deadlines based on the entity's financial year: June 1 for April-March entities and March 1 for calendar-year entities.
What it means for you
Banks and payment system operators must ensure their system audits are conducted annually by a CISA-certified professional. Missing the deadlines could invite regulatory scrutiny under the Payment and Settlement Systems Act, 2007. This strengthens oversight of IT and payment system security.
What you must do
Engage a CISA-qualified auditor for your annual system audit immediately if not already done.
Align your audit cycle with your financial year closing to meet the June 1 or March 1 deadline.
Submit the system audit report to RBI within the stipulated two-month window post year-end.
Review your current audit schedule to ensure compliance with this circular.
Who it affects
All scheduled commercial banks, Authorised payment system operators
❓ Common questions
What is the deadline for submitting the system audit report?
For entities following an April-March financial year, the report must be submitted by June 1. For those following a calendar year, the deadline is March 1 of the following year.
Who can conduct the system audit?
The audit must be performed by a CISA-qualified auditor, as specified in the circular.
What is the legal basis for this requirement?
These directions are issued under Section 6(1) of the Payment and Settlement Systems Regulations 2008 read with Section 12 of the Payment and Settlement Systems Act, 2007.
📜 Read the original circular — full text as issued by RBI
RBI/2010-11/340
DPSS.CO.OSD. No. 1444 /06.11.001/2010-2011
December 27, 2010
To
All Scheduled Commercial Banks / Authorised Payment System Operators
Dear Sir,
Directions for submission of system audit reports from CISA qualified Auditor
Please refer to our circular Ref No. DPSS.1206/ 02.27.005/2009-10 dated 7th December 2009 on the captioned subject.
2. All authorised entities are advised to furnish their respective system audit reports from a CISA qualified auditor on an annual basis. Authorised entities which follow an April-March financial year, the system audit report should be submitted within two months i.e. by 1st June of that year. Authorised entities, which follow a calendar year annual closing, are advised to submit their system audit reports by 1st March of the following year.
3. These directions are issued under Section 6(1) of the Payment and Settlement Systems Regulations 2008 read with Section 12 of the Payment and Settlement Systems Act, 2007.
Yours faithfully
G. Srinivas
(General Manager)
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2010-11/340 · issued 27 Dec 2010. The plain-English explanation above is BankPulse’s own independent summary.
Engage a CISA-qualified auditor for your annual system audit immediately if not already done.
Submit the system audit report to RBI within the stipulated two-month window post year-end.
📜 Compliance
Align your audit cycle with your financial year closing to meet the June 1 or March 1 deadline.
Review your current audit schedule to ensure compliance with this circular.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are an IT/Systems lead at a bank this circular applies to (All scheduled commercial banks, Authorised payment system operators), your first concrete step on “Annual System Audit by CISA Auditor Mandated” is: “Engage a CISA-qualified auditor for your annual system audit immediately if not already done.” (RBI issued this 27 Dec 2010).
Circular: RBI/2010-11/340 -- Annual System Audit by CISA Auditor Mandated
Issued: 27 Dec 2010
Action required: Engage a CISA-qualified auditor for your annual system audit immediately if not already done.
Action required: Align your audit cycle with your financial year closing to meet the June 1 or March 1 deadline.
Action required: Submit the system audit report to RBI within the stipulated two-month window post year-end.
Action required: Review your current audit schedule to ensure compliance with this circular.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6177&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.