Skip to content
BankPulseBETARegulatory intelligence for Indian banking
Directions · Reserve Bank of India

Reserve Bank of India (Non-Banking Financial Companies - Internal Audit Function) Directions, 2026

UR

The four dates on this rule

At a glanceThe board or its audit committee is first responsible for internal audit. These rules apply to every non-banking financial company named below. The rules start the moment RBI issues them.

Official RBI page

What it says

Chapter I. Preliminary

1. Starts at once

The rules start the moment RBI issues them.

2. Who must follow this

These rules apply to every non-banking financial company named below.

3. Every deposit taking company

Every deposit-taking finance company registered with RBI is covered.

4. Others at 5,000 crore

A company that takes no deposits is covered at 5,000 crore of assets.

BankPulse example. A finance company takes no deposits and holds 4,200 crore of assets. These rules do not reach it, because RBI's line for a company like it is 5,000 crore. Grow to 5,100 crore and the same company is inside.

5. Housing finance too

Every deposit-taking housing finance company is covered as well.

Chapter II. Governance and Oversight

Must know

1. The board owns the audit

The board or its audit committee is first responsible for internal audit.

2. New audit tools

New tools and technology should cut down manual checking.

Do it

3. It approves the plan

It approves an audit plan built on the level and direction of risk.

4. A quality programme is required

A quality assurance and improvement programme must cover the whole function.

5. A quality check yearly

The audit function itself is assessed at least once a year.

6. A minimum posting period

The board sets how long staff must serve in the audit function.

7. Senior staff follow the policy

Senior management must see the board's audit policy is actually followed.

8. Act on findings in time

Audit findings must be acted on within the time given.

9. Build the function properly

Senior management must build a full and independent audit function.

10. Staff it and train it

It must be staffed with skilled people who are trained regularly.

11. One risk picture a year

Senior management puts the whole risk picture to the board at least yearly.

Chapter III. Risk-Based Internal Audit Framework

Must know

1. Nothing escapes for ever

The policy must fix the longest time even a low risk area can go unaudited.

2. Give it standing

The function needs enough authority, standing, independence and resources.

3. Pay not tied to sales

Audit pay must not depend on how the audited business lines perform.

4. What auditors should know

Accounts, technology, data work and fraud investigation among others.

5. Nothing is left out

Every activity and location is assessed, risk and compliance staff included.

6. Risk decides the order

The risk assessment decides which material areas are audited first.

7. Count the time since

How long it has been since the last audit is one of the tests.

8. The report rests on evidence

The audit report must rest on proper analysis and evaluation.

9. Audit cannot be outsourced

The internal audit function must not be handed to an outside firm.

10. The reports stay inside

Ownership of every audit report stays with the regular audit staff.

Do it

11. Write the policy down

The board's policy must set out the purpose, authority and responsibility.

12. Review it and share it

The policy is reviewed from time to time and made known widely.

13. Tell audit about changes

New products, new reporting lines and accounting changes must reach audit.

14. A risk look every year

The risk assessment must be done at least once a year.

15. A matrix of two risks

The business risk and the control risk are put together in one matrix.

16. Look at the last report

The risk method starts from earlier audit reports and their compliance.

17. Fix the job before starting

Plan, scope, aims, timing and people are settled before the work begins.

18. Enough scope and people

The scope and the people put on it must be enough to meet the aims.

19. Follow the findings up

There must be a system to track compliance with audit observations.

20. Old high risk items up

Pending high and medium risk items go to the board with the old ones.

21. Sound data behind it

The audit needs a proper reporting system and clean data.

Background

22. Banking knowledge counts

Knowing how a lender actually operates is part of the skill needed.

Chapter IV. Head of Internal Audit

1. The audit head is senior

The head of internal audit is senior and can judge on his own.

2. Three years in the chair

He should be appointed for a long period, preferably three years at least.

3. No business targets

He has no reporting line to business.

4. And no sales to chase

He is given no business targets of any kind.

5. Meet him every quarter

The board or its audit committee meets the audit head alone each quarter.

Chapter V. Repeal and Other Provisions

1. Old rules stand repealed

The earlier internal audit rules for these are repealed.

2. Old actions still stand

Anything done under the old rules stays governed by those old rules.

3. Old approvals still count

Approvals given under the repealed rules now come under these rules.

The same subject for other kinds of institution

The same subject for other kinds of institution.

Other RBI rules for NBFCs

Every rule page on BankPulse  ·  Questions bankers ask, answered