Reserve Bank of India (Non-Banking Financial Companies - Internal Audit Function) Directions, 2026
UR
- Applies toFinance companies
- StatusIn force
- ImportanceMUST READ
- IssuedJul 31, 2026
- Amendmentsnone tracked
- Length46 points in 5 sections · 4 min read
The four dates on this rule
- PublishedJul 31, 2026The day RBI put this document out.
- Starts to applyNot statedNot stated separately in this document. Read the rule itself before you assume a start date.
- Time to get readyNot statedCannot be worked out until the day it starts to apply is known.
- Last date to actNot statedNo date to act by was found in this document. Other dates may sit inside single paragraphs.
Kept in your browser only. Your desk
Show me the points for
Nothing is removed from the page.
Show me the points about
45 of the 46 points name no product and bind every product. All products.
What it says
Chapter I. Preliminary
1. Starts at once
The rules start the moment RBI issues them.
2. Who must follow this
These rules apply to every non-banking financial company named below.
3. Every deposit taking company
Every deposit-taking finance company registered with RBI is covered.
4. Others at 5,000 crore
A company that takes no deposits is covered at 5,000 crore of assets.
BankPulse example. A finance company takes no deposits and holds 4,200 crore of assets. These rules do not reach it, because RBI's line for a company like it is 5,000 crore. Grow to 5,100 crore and the same company is inside.
5. Housing finance too
Every deposit-taking housing finance company is covered as well.
Chapter II. Governance and Oversight
Must know
1. The board owns the audit
The board or its audit committee is first responsible for internal audit.
2. New audit tools
New tools and technology should cut down manual checking.
Do it
3. It approves the plan
It approves an audit plan built on the level and direction of risk.
4. A quality programme is required
A quality assurance and improvement programme must cover the whole function.
5. A quality check yearly
The audit function itself is assessed at least once a year.
6. A minimum posting period
The board sets how long staff must serve in the audit function.
7. Senior staff follow the policy
Senior management must see the board's audit policy is actually followed.
8. Act on findings in time
Audit findings must be acted on within the time given.
9. Build the function properly
Senior management must build a full and independent audit function.
10. Staff it and train it
It must be staffed with skilled people who are trained regularly.
11. One risk picture a year
Senior management puts the whole risk picture to the board at least yearly.
Chapter III. Risk-Based Internal Audit Framework
Must know
1. Nothing escapes for ever
The policy must fix the longest time even a low risk area can go unaudited.
2. Give it standing
The function needs enough authority, standing, independence and resources.
3. Pay not tied to sales
Audit pay must not depend on how the audited business lines perform.
4. What auditors should know
Accounts, technology, data work and fraud investigation among others.
5. Nothing is left out
Every activity and location is assessed, risk and compliance staff included.
6. Risk decides the order
The risk assessment decides which material areas are audited first.
7. Count the time since
How long it has been since the last audit is one of the tests.
8. The report rests on evidence
The audit report must rest on proper analysis and evaluation.
9. Audit cannot be outsourced
The internal audit function must not be handed to an outside firm.
10. The reports stay inside
Ownership of every audit report stays with the regular audit staff.
Do it
11. Write the policy down
The board's policy must set out the purpose, authority and responsibility.
12. Review it and share it
The policy is reviewed from time to time and made known widely.
13. Tell audit about changes
New products, new reporting lines and accounting changes must reach audit.
14. A risk look every year
The risk assessment must be done at least once a year.
15. A matrix of two risks
The business risk and the control risk are put together in one matrix.
16. Look at the last report
The risk method starts from earlier audit reports and their compliance.
17. Fix the job before starting
Plan, scope, aims, timing and people are settled before the work begins.
18. Enough scope and people
The scope and the people put on it must be enough to meet the aims.
19. Follow the findings up
There must be a system to track compliance with audit observations.
20. Old high risk items up
Pending high and medium risk items go to the board with the old ones.
21. Sound data behind it
The audit needs a proper reporting system and clean data.
Background
22. Banking knowledge counts
Knowing how a lender actually operates is part of the skill needed.
Chapter IV. Head of Internal Audit
1. The audit head is senior
The head of internal audit is senior and can judge on his own.
2. Three years in the chair
He should be appointed for a long period, preferably three years at least.
3. No business targets
He has no reporting line to business.
4. And no sales to chase
He is given no business targets of any kind.
5. Meet him every quarter
The board or its audit committee meets the audit head alone each quarter.
Chapter V. Repeal and Other Provisions
1. Old rules stand repealed
The earlier internal audit rules for these are repealed.
2. Old actions still stand
Anything done under the old rules stays governed by those old rules.
3. Old approvals still count
Approvals given under the repealed rules now come under these rules.
The same subject for other kinds of institution
The same subject for other kinds of institution.
Other RBI rules for NBFCs
Every rule page on BankPulse · Questions bankers ask, answered