






















Mumbai: Reserve Bank of India (RBI) logo at its headquarters, in Mumbai, Maharashtra, Friday, June 5, 2026. The Reserve Bank on Friday expectedly kept interest rates unchanged for the second time in a row as it weighed the impact of rising energy prices and supply disruptions caused by the West Asia crisis. (PTI Photo/Shashank Parade)(PTI06_05_2026_000103A) | Photo Credit: SHASHANK PARADE
The RBI may ask banks to adopt a Risk-based Internal Audit (RBIA) approach, focusing on areas of higher risk, materiality, systemic relevance and supervisory concerns. This is aimed at providing the Board or its committees with reasonable assurance on the adequacy and effectiveness of the bank’s risk management and internal control framework.
RBIA is an audit methodology that focuses on identifying, assessing and prioritising the most significant risks faced by an organisation, and allocating audit resources accordingly.
In fulfilling this role, RBIA should assess whether risks are being properly identified, monitored and reported, and whether significant exceptions or excesses are duly recorded and addressed, per the Reserve Bank of India (Commercial Banks - Governance) Second Amendment Directions, 2026 (Draft). The RBI has asked regulated entities and members of public/other stakeholders to submit their comments on the draft directions on or before July 9, 2026.
The RBI noted that while transaction testing continues to have relevance, its extent should be driven by the outcome of risk assessments — high-risk areas may warrant comprehensive testing, whereas low-risk areas can be covered selectively and at longer intervals, supplemented by surprise checks to ensure vigilance. At a minimum, RBIA should evaluate the adequacy of risk management processes, the robustness of the control environment, the reliability of information and reporting systems, and the institution’s adherence to internal and regulatory requirements.
Unlike traditional compliance-oriented audits, RBIA aligns audit activities with the regulated entities’ risk management framework and strategic objectives.
The aim is to provide independent assurance on whether material risks are being managed effectively and in line with the entity’s risk appetite.
The RBI said the risk management and compliance functions shall be subject to regular internal audit. Further, banks shall develop and maintain a Quality Assurance and Improvement Program (QAIP) covering all aspects of the Compliance and Internal Audit Functions.
A bank shall establish risk management, compliance and internal audit functions, commensurate with its size, complexity and risk / business profile, headed by a Chief Risk Officer (CRO), Chief Compliance Officer (CCO) and Head of Internal Audit (HIA), respectively. In banks that are part of a group comprising more than one financial entity, there may be a Group Chief Risk Officer (GCRO) and a Group Chief Compliance Officer (GCCO), responsible for group-level risk oversight / compliance, and for coordination.
The bank shall have policies for each of the three control functions, viz., Risk Management, Compliance and Internal Audit, clearly articulating the objectives, roles and responsibilities of each function.
As part of the overall corporate governance framework, the Board is responsible for overseeing the control functions. The Board must set the ‘tone at the top’, ensure that these functions are adequately resourced, and maintain their independence.
Published on June 10, 2026
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。