RBI NBFC Internal Audit Function Directions 2026: RBIA Checklist for Audit Teams
RBI's NBFC Internal Audit Function Directions 2026 are a governance upgrade for specified NBFCs and HFCs. They move internal audit from periodic transaction checking toward a Board-overseen, risk-based internal audit function with independence, annual risk assessment, technology use, quality assurance and follow-up discipline.
For internal audit teams, the practical question is not "what does the notification say?" It is: what should change in the audit universe, RBIA policy, annual plan, RCM, evidence file, monitoring rules and audit committee pack?
What changed on 31 July 2026
According to the reproduced RBI notification dated 31 July 2026, the Reserve Bank of India issued the Reserve Bank of India (Non-Banking Financial Companies - Internal Audit Function) Directions, 2026 with immediate effect. The directions apply to:
| Entity type | Applicability stated in the 2026 directions |
|---|---|
| Deposit-taking NBFCs | All deposit-taking NBFCs registered with RBI |
| Large non-deposit-taking NBFCs | Non-deposit-taking NBFCs registered with RBI with asset size of Rs 5,000 crore and above |
| Deposit-taking HFCs | All deposit-taking Housing Finance Companies |
| Large non-deposit-taking HFCs | Non-deposit-taking HFCs registered with RBI with asset size of Rs 5,000 crore and above |
The 2021 RBI RBIA circular already applied to all deposit-taking NBFCs and non-deposit-taking NBFCs, including Core Investment Companies, with asset size of Rs 5,000 crore and above. The 2026 directions are important because they consolidate the operating expectations for the internal audit function itself.
Before relying on any summary, verify the current RBI notification, the entity's registration category, deposit status, asset size, scale-based layer and any sector-specific directions applicable to the period under review.
The short answer for NBFC audit committees
An NBFC or HFC covered by the 2026 directions should be able to show six things: a Board-approved internal audit policy, an independent and adequately staffed internal audit function, an annual risk assessment, a risk-based audit plan approved by the Board or Audit Committee, a quality assurance and improvement programme, and a disciplined closure process for internal audit findings.
That means the audit file should not stop at loan-file sampling. It should show how the audit universe was risk-ranked, why high-risk products and locations were selected, which controls were tested, what source data supported the conclusions and how open issues moved into management action tracking.
RBIA implementation checklist
| Area | What internal audit should document | Useful CORAA resource |
|---|---|---|
| Board oversight | Board or Audit Committee approval of internal audit policy, RBIA plan and risk assessment method | Audit committee reporting pack |
| Internal audit policy | Purpose, authority, responsibility, independence, ethics, accountability and review cycle | Internal audit charter and mandate |
| Audit universe | Products, branches, channels, outsourced activities, systems, compliance functions and risk areas | Audit universe and risk taxonomy |
| Risk assessment | Inherent risk, control risk, direction of risk, prior findings, regulatory reports, external audit inputs and time since last audit | Internal audit risk scorer |
| Annual plan | Coverage, frequency, scope, objectives, timelines, resource allocation and low-risk maximum deferral period | Annual plan generator |
| Independence | HIA authority, reporting line, no business targets, access to records and quarterly private access where applicable | Three lines assurance map |
| Staffing | Competence in NBFC operations, accounting, IT, data analytics, forensic review and regulatory compliance | Resource capacity planner |
| Technology use | Data analytics, audit tools, continuous monitoring and reduced manual transaction checking where practical | Monitoring rules repository |
| Quality assurance | Annual QAIP-style review of internal audit policy adherence, expected outcomes and file quality | Quality review checklist |
| Follow-up | Timely action on findings, closure evidence, repeat findings and Board/Audit Committee reporting | ATR tracker |
What changes in the NBFC audit universe
The audit universe should explicitly include more than finance and loan operations. For a covered NBFC or HFC, include at least:
- Loan origination, underwriting and sanction
- KYC, CKYC, customer due diligence and fraud screening
- Disbursement and end-use monitoring
- Collections, settlements, repossession and recovery agents
- DPD, NPA/IRACP, restructuring, upgradation and write-off
- ECL, prudential provisioning and GL reconciliation
- ALM, liquidity, borrowings, covenants, investments and treasury
- Outsourcing, digital-lending partners, DSAs and service providers
- RBI returns, compliance function and regulatory reporting
- Branches, field offices and cash/document controls
- Loan-management system, interfaces, access, changes and audit logs
- Cybersecurity, data privacy, grievance redress and internal ombudsman controls where applicable
The most common weak file is one where the loan samples are tested well, but the audit universe never explains why the selected products, branches, partners or system controls were in scope.
Monitoring rules NBFCs should prioritise
Continuous monitoring is not a separate dashboard project. It is RBIA discipline applied to repeatable data signals.
| Monitoring rule | Exception to review |
|---|---|
| DPD drift | DPD changes after period close or differs between loan-system extract and reporting extract |
| KYC gap | Active or disbursed loan has mandatory borrower, CKYC, sanction or appraisal fields blank |
| Collection mismatch | Bank receipt, collection-agent file or payment gateway record does not reconcile to the loan account |
| Interest on impaired account | Interest continues or reversal is incomplete after NPA classification under applicable policy |
| Restructuring watch | Upgradation or stage movement is unsupported by sustained performance evidence |
| Write-off recovery | Recoveries after write-off are not tracked, approved or posted consistently |
| ALM and covenant exception | Liquidity, borrowing covenant or lender reporting threshold breach lacks escalation |
| Outsourcing SLA breach | Critical partner misses agreed turnaround time, reconciliation, complaint or incident metric |
| Leaver and privileged access | Former employees, field users or vendor users retain loan-system access |
| RBI return tie-out | Return value does not reconcile to source system, GL, board MIS or compliance working |
Each rule needs source report, fields used, exception threshold, owner, cadence, reviewer conclusion and follow-up status. Without those fields, the rule is only an analytics idea, not audit evidence.
How CA firms should use this for NBFC clients
For CA firms delivering internal audit, the 2026 directions change the conversation with covered NBFC and HFC clients.
Do not sell only a checklist. Sell a governed RBIA operating cadence:
- Confirm whether the client is covered by the 2026 directions.
- Review the Board-approved internal audit policy and independence of the HIA or outsourced/assisted model.
- Rebuild the audit universe by product, branch, system, partner and compliance function.
- Risk-rank the universe and show why high-risk areas are audited more frequently.
- Convert the plan into cycle RCMs, data requests, sampling plans and monitoring rules.
- Report observations with owner, due date, root cause and closure evidence.
- Give the Board or Audit Committee a quarterly view of coverage, high findings, delays and overdue actions.
The strongest retainers are not generic quarterly visits. They are recurring monitoring reviews over loan quality, collections, NPA/IRACP, KYC, ALM, outsourcing, RBI returns, ITGC and open ATR items.
Internal audit evidence that should survive review
An NBFC RBIA file should preserve:
- The approved internal audit policy and latest review date
- The risk assessment methodology and scoring basis
- The audit universe with products, branches, systems, partners and compliance functions
- Annual plan approval and change log
- Scope, objectives, timelines and resource allocation for each assignment
- RCM rows linking risk, control, test, source data, evidence and conclusion
- Population completeness and source-data reliability checks
- Sampling basis or full-population test logic
- Exceptions, false-positive clearance and reviewer sign-off
- Observation rating, criteria, cause, effect, recommendation and owner
- Management response, due date, revised date and closure evidence
- QA review checklist and file review notes
This is where software matters. A folder of spreadsheets can hold the evidence, but it rarely proves the path from risk assessment to plan to RCM to observation to ATR without manual reconstruction.
FAQ
What are the RBI NBFC Internal Audit Function Directions 2026?
They are RBI directions issued on 31 July 2026 for the internal audit function of specified NBFCs and HFCs. They set expectations for Board oversight, internal audit policy, RBIA framework, independence, audit planning, quality assurance, technology use, staffing and follow-up.
Which NBFCs are covered by the 2026 internal audit directions?
The reproduced notification states coverage for all deposit-taking NBFCs, non-deposit-taking NBFCs with asset size of Rs 5,000 crore and above, all deposit-taking HFCs, and non-deposit-taking HFCs with asset size of Rs 5,000 crore and above. Verify the current RBI record and entity-specific facts before concluding applicability.
Are the 2026 directions different from the 2021 RBIA circular?
Yes. The 2021 circular mandated RBIA for select NBFCs and UCBs. The 2026 directions consolidate expectations around the NBFC/HFC internal audit function itself: Board/Audit Committee oversight, policy, RBIA framework, independence, staffing, quality assurance, technology use and follow-up.
Can an NBFC outsource internal audit under the 2026 directions?
The reproduced 2026 text says the internal audit function cannot be outsourced, while experts may be engaged under specified conditions. Treat this as a governance and independence issue, not just procurement. Covered NBFCs should verify the final RBI text and document how any external expert supports, rather than replaces, the internal audit function.
What should an NBFC internal audit dashboard show?
It should show audit-universe coverage, high-risk products and branches, overdue evidence, open observations, repeat findings, unresolved management actions, monitoring exceptions, compliance-function coverage, outsourcing issues, ITGC exceptions and Board/Audit Committee reporting status.
Related CORAA resources
- NBFC internal audit checklist
- NBFC internal audit workbook
- Internal audit risk scorer
- Internal audit annual plan generator
- Internal audit control repository
- Internal audit monitoring rules repository
- Internal audit dashboard KPI dictionary
- CORAA Internal Audit product