The Reserve Bank of India (RBI) on July 31, 2026, issued the Reserve Bank of India (Local Area Banks – Internal Audit Function) Directions, 2026, in exercise of powers under Section 35-A of the Banking Regulation Act, 1949. Applicable to all Local Area Banks and effective immediately, the Directions mandate adoption of Risk-Based Internal Audit (RBIA), moving beyond a purely transaction-centric approach to emphasise assessment of risk management systems and internal controls, in line with evolving governance standards. Undefined terms take their meaning from the RBI Act, 1934, the Banking Regulation Act, 1949, the Companies Act, 2013, or RBI's Glossary of Terms.
Chapter II assigns the Board responsibility for approving the RBIA policy, the risk assessment methodology, the Annual Audit Plan (AAP), and a policy for engaging retired personnel (capped at three years) in areas lacking expertise, while also periodically assessing RBIA's reliability and objectivity, and prescribing minimum tenure for internal audit staff. Senior Management must ensure the importance of RBIA is understood bank-wide and that audit staff act with objectivity. Chapter III establishes the core RBIA framework: the Internal Audit Department (IAD) must remain functionally independent from internal control processes and distinct from the Risk Management Department, with remuneration delinked from the performance of business lines audited, and adequately skilled, trained staff covering banking operations, IT, data analytics, and forensic investigation.
The risk assessment methodology must combine inherent business risk and control risk into a risk matrix (ranging from Low Risk to Extremely High Risk), with extent of transaction testing—including potential 100% testing for extremely high or increasing very-high-risk areas—determined accordingly; assessments must be updated at least annually considering factors like prior audit findings, business changes, management turnover, and regulatory examination results. The Board-approved AAP must prioritise audit frequency and resource allocation using this risk assessment, illustratively via a Risk Audit Matrix weighing magnitude and frequency of risk. Subsequent chapters (not excerpted in full) address audit scope, communication, performance evaluation, outsourcing, the Head of Internal Audit's authority, tenure, and reporting line, and repeal of prior applicable instructions with standard interpretive provisions.
[Notification No. RBI/DoS/2026-27/447, DoS.CO.PPG.41/11.01.005/2026-27]