RBI issues Risk Based Internal Audit (RBIA) requirements for NBFCs.

Author: Irm India Affiliate

RBI has issued Risk Based Internal Audit (RBIA) requirements for NBFCs. As SCBs, NBFCs and UCBs grow in size and face risks similar to larger banks by virtue of being engaged in similar financial intermediation activities, their internal audit systems also need to broadly align while keeping in mind the principle of proportionality. Considering these aspects, the RBI Guidelines prescribe the broad principles that should be followed by NBFCs and UCBs to enable them to gradually move towards a RBIA system where by identifying its risk environment, the company establishes its risk management processes which highlights the importance for enterprise risk management.

  • Banks would eventually have to switch to the IA risk-based approach

Greater focus on the role of internal auditors in Risk Management will ensure that the demand for risk qualified professionals will go up.

  • Deposits taken by non-banking finance companies (NBFCs)

Non-deposit taking NBFCs with an asset size of ~5,000 crore and above (including Core Investment Companies). Main (Urban) cooperative banks with an asset size of about 500 crores (UCBs). Requirements for high levels include establishment a committee of senior executives with the task of formulating an appropriate plan of action.

The audit plan is advised to cover business risks resulting from an activity/location that are inherent. Effectiveness of control systems to detect inherent hazards of this type. A holistic approach towards risk management will be adopted to ensure all business verticals are accounted for. This committee should discuss transitional and change management concerns and should report to the Board and senior management annually on development. For the internal audit feature, the committee should formulate and retain quality assurance. Quality assurance should provide an evaluation, at least once a year, of the internal audit feature. Require the following selective transaction checking over and above, which is the existing status for most internal NBFC audits. Assessment of risk management processes and monitoring protocols in different operating areas will need to be done for which it is key that the employees have immense knowledge and possess the key skills to predict areas of potential threats and mitigate these risks. To arrive at a risk-based audit strategy, RBIA should conduct an independent risk evaluation. As the Head of Internal Audit (HIA) should be a senior executive with the capacity to exercise independent judgement, the basic criteria for the Internal Audit Committee have already been stated. Internal audit should have the power to connect with any workers and access the necessary records. Ideally, internal audit professionals may have expertise in the following sectors, such as activities of banking/financial companies, accounting, information technology, computer analytics, criminal analysis. The Board has recommended a minimum length of work for personnel in the internal audit role for non-full-time/permanent internal auditors. Whether the Board/ MD & CEO or the Full-Time Director should report directly to the HIA (WTD). Compensation plans should be designed in a manner that prevents conflicts of interest and compromises the transparency and objectivity of the audit.

For example, some criteria were also stated for independent risk assessment. The internal audit committee is suggested to carry out an independent risk assessment. This risk assessment can be used to concentrate on areas of material risk and prioritize audit plans. The basis for assessing the degree of risk (high, medium, low) and the pattern (increasing, steady, decreasing) should be set out explicitly. The strategy, scope, priorities, schedules, and resource distribution of the task should be explicitly defined before the relevant internal audit assignment is taken up. The internal audit should include a framework to track compliance with internal audit findings. An important part of reporting to the Board should be the state of enforcement. You should not outsource the internal audit feature. However, specialists, including former employees, may be employed on a temporary basis if necessary. To ensure that all business verticals are functioning the key is to ensure that people possess the key skills of risk management and are qualified so they can not only identify but mitigate risks too.