CORAA
Resources - NBFC Internal Audit

NBFC internal audit checklist.

NBFC internal audit is not a generic finance checklist. A defensible RBIA file must connect the audit universe to loan origination, KYC, disbursement, collections, NPA classification, ECL/provisioning, ALM, RBI returns, outsourcing, branch controls and ITGC over the loan system.

Build NBFC workbookBuild NBFC RCM
RCM map

Nine areas to test areas

RBIA governance and audit universe

Risk: The internal-audit plan does not reflect the NBFC's risk profile, scale-based regulation layer, products, branches, outsourcing and technology dependence.

Controls
  • Board-approved RBIA policy
  • Risk-ranked audit universe
  • Independent reporting line
  • Coverage and follow-up tracker
Tests
  • Inspect RBIA policy and annual plan approval
  • Check whether high-risk products/branches are covered
  • Review independence and reporting line
  • Trace prior high-risk findings to follow-up status
Evidence

RBIA policy, audit universe, risk assessment, annual plan, board/audit committee minutes, prior reports and ATR register.

Customer onboarding, KYC and loan origination

Risk: Loans are booked for ineligible, unidentified or inadequately assessed borrowers, creating credit, fraud and compliance exposure.

Controls
  • KYC and CKYC completion
  • Credit appraisal checklist
  • Sanction authority matrix
  • Fraud/negative-list checks
Tests
  • Sample new loans for KYC and credit appraisal completeness
  • Match sanction terms to approved authority
  • Review exceptions and overrides
  • Check adverse screening evidence where applicable
Evidence

Loan file, KYC documents, credit note, bureau report, sanction letter, authority matrix, exception approvals and onboarding checklist.

Disbursement and end-use monitoring

Risk: Disbursements are made before conditions are met, to wrong parties, or without evidence that funds were used for the approved purpose.

Controls
  • Pre-disbursement condition checklist
  • Maker-checker bank validation
  • End-use verification
  • Tranche-release approval
Tests
  • Trace disbursement to sanction terms and borrower bank details
  • Review pending pre-disbursement conditions
  • Inspect end-use certificate or supporting utilisation evidence
  • Test tranche releases against milestones
Evidence

Sanction terms, disbursement memo, bank proof, condition checklist, end-use evidence, invoice/supporting documents and tranche approval.

Collections, overdue management and repossession

Risk: Collections are not recorded correctly, overdue accounts are not escalated, or recovery actions breach policy or regulatory expectations.

Controls
  • Daily collection reconciliation
  • Overdue bucket monitoring
  • Collection-agent controls
  • Repossession and settlement approval
Tests
  • Reconcile receipts to loan system and bank
  • Review ageing movement and skipped instalments
  • Test collection-agent cash/UPI controls
  • Inspect repossession, waiver and settlement approvals
Evidence

Collection dump, bank statement, ageing report, collection-agent statement, repossession file, settlement note and approval trail.

NPA / IRACP classification and income recognition

Risk: Accounts are incorrectly classified, interest income continues on impaired accounts, or borrower-level overdue status is not applied consistently.

Controls
  • System-driven DPD computation
  • Borrower-level classification review
  • NPA interest reversal
  • Restructuring and upgradation checks
Tests
  • Recompute DPD/classification for selected accounts
  • Check borrower-level aggregation logic
  • Trace NPA interest reversal
  • Review restructuring and upgradation evidence
Evidence

Loan master, repayment schedule, DPD report, classification report, interest reversal working, restructuring file and reviewer sign-off.

ECL, provisioning and write-offs

Risk: Expected credit loss, prudential provisions or write-offs are unsupported, stale or inconsistent with portfolio risk.

Controls
  • ECL model governance
  • Stage migration review
  • Provisioning reconciliation
  • Write-off and recovery approval
Tests
  • Review ECL input data, assumptions and overlays
  • Test stage migration for sampled accounts
  • Reconcile provisions to GL
  • Inspect write-off approval and post-write-off recovery tracking
Evidence

ECL model, PD/LGD/EAD inputs, stage report, provision working, GL reconciliation, write-off note and recovery register.

Treasury, borrowings, ALM and liquidity

Risk: Borrowing covenants, liquidity mismatches, ALM reporting, bank limits or investments are not monitored in time.

Controls
  • Borrowing covenant tracker
  • ALM gap review
  • Investment approval
  • Bank-limit reconciliation
Tests
  • Inspect covenant compliance and lender reporting
  • Review ALM bucket preparation and approval
  • Test investment purchase/sale approvals
  • Reconcile bank facilities to books and confirmations
Evidence

Loan agreements, covenant tracker, ALM statement, investment register, bank confirmations, board approvals and treasury MIS.

RBI returns, outsourcing and branch controls

Risk: Regulatory returns, outsourced activities, field branches or digital-lending partners are not controlled or evidenced.

Controls
  • Return-preparation checklist
  • Outsourcing due diligence
  • Branch surprise review
  • Partner reconciliation and exception review
Tests
  • Tie selected RBI returns to source reports
  • Review outsourcing agreements and monitoring evidence
  • Inspect branch cash/document controls
  • Reconcile partner/customer data with the loan system
Evidence

RBI return working, source reports, outsourcing agreement, SLA reports, branch visit report, partner reconciliation and exception tracker.

ITGC and loan-system controls

Risk: Loan-system access, product configuration, interest logic or interface controls can change without approval or audit trail.

Controls
  • Role-based access
  • Product/interest configuration approval
  • Change management
  • Interface reconciliation
Tests
  • Review privileged access and leaver removal
  • Test product master and interest-rate changes
  • Sample loan-system changes for UAT/approval
  • Compare source and GL interface totals
Evidence

User list, role matrix, access review, product master change log, UAT sign-off, interface logs and reconciliation file.

Continuous monitoring

Rules worth automating rules

RuleException logic
DPD driftLoan account DPD changes materially after period close or differs between loan system and reporting extract.
Interest on impaired accountInterest income continues or is not reversed for accounts classified as non-performing under the entity’s applicable policy/regulation.
KYC gapLoan is active or disbursed while mandatory KYC/CKYC, sanction or appraisal fields are blank.
Collection mismatchCustomer receipt exists in bank/collection file but is not posted or is posted to the wrong loan account.
Restructure watchRestructured account is upgraded without evidence of sustained performance under the applicable framework.
Covenant/ALM exceptionLiquidity, borrowing covenant or lender-reporting metric breaches internal threshold without documented escalation.
Check NPA classificationOpen monitoring repository
Downloads

Templates and linked tools workpapers

NBFC Internal Audit Workbook

Generate an Excel/PDF workbook for RBIA, loan files, NPA/IRACP, collections, ECL, ALM, RBI returns and ITGC.

Open ->
NBFC Audit Checklist Template

Editable NBFC checklist covering RBI, IRACP, ECL and audit documentation areas.

Open ->
NPA / IRAC Classification Calculator

Classify accounts and compute provisioning support for RBI/IRACP-style testing.

Open ->
ECL Ind AS 109 Calculator

Expected credit loss support for Ind AS reporting entities and credit portfolios.

Open ->
Restructured Advance Checker

Check classification impact, monitoring-period performance and upgradation evidence.

Open ->
Internal Audit RCM Builder

Turn NBFC cycle checks into a risk-control-test-evidence matrix.

Open ->
ITGC Internal Audit Checklist

Loan systems, access, changes, interfaces, backups and audit logs.

Open ->
Authority

Regulatory references to verify sources

Use this page as a working checklist, not as a substitute for the current RBI directions applicable to the entity. Before issuing an NBFC internal-audit or RBIA report, verify the NBFC category, layer, products, deposit status, asset size and applicable directions for the period under review.

RBI circular on Risk-Based Internal Audit for select NBFCs and UCBs ->RBI Master Direction: NBFC Scale Based Regulation Directions, 2023 ->NBFC statutory audit guide on CORAA ->
FAQ

NBFC internal audit FAQs questions

Which NBFCs need Risk-Based Internal Audit?

RBI's February 2021 RBIA circular applies to all deposit-taking NBFCs, irrespective of size, and all non-deposit-taking NBFCs, including Core Investment Companies, with asset size of Rs 5,000 crore and above. Smaller NBFCs may still use the same risk-based structure as good governance, but the exact regulatory trigger should be verified for the entity.

What should an NBFC internal audit cover?

An NBFC internal audit should cover governance/RBIA, customer onboarding and KYC, credit appraisal, disbursement, collections, overdue monitoring, NPA/IRACP classification, income recognition, ECL/provisioning, write-offs, treasury and ALM, RBI returns, outsourcing, branch controls and ITGC over the loan system.

How is NBFC internal audit different from statutory audit?

Statutory audit concludes on financial statements and prescribed reporting. Internal audit/RBIA is a recurring assurance function that assesses risk management, internal controls, governance, compliance and follow-up. The evidence can overlap, but the timing, reporting line and purpose are different.

Can NBFC internal audit be monitored continuously?

Yes. DPD movement, KYC gaps, collection mismatches, delayed interest reversal, restructuring watch accounts, covenant exceptions, branch cash issues and loan-system access changes can be monitored periodically. Each exception still needs auditor review and documented closure.