RBI Act, 1934 Audit Checklist |
Sr. No. |
Requirement |
Category |
Provision |
Consequences |
Mitigation Measures |
Status |
1 |
Maintain authorized capital ₹5 crore |
Governance & Structure |
Sec 4 |
Legal breach |
Annual capital review by finance |
✅/❌ |
2 |
RBI Central Board formed properly |
Governance & Structure |
Sec 8 |
Governance lapses |
Legal vetting of appointment orders |
✅/❌ |
3 |
Governor, Dy Governors appointed as per law |
Governance & Structure |
Sec 8(1) |
Appointment can be invalid |
Appointment policy and documentation |
✅/❌ |
4 |
Meetings of Central Board held regularly |
Governance & Structure |
Sec 13 |
Operational inefficiency |
Calendarized schedule with alerts |
✅/❌ |
5 |
Maintain CRR |
Monetary & Note Issue |
Sec 42 |
Monetary penalties |
Automated CRR reporting system |
✅/❌ |
6 |
Report CRR to RBI |
Monetary & Note Issue |
Sec 42(1) |
Penal interest |
Daily liquidity monitoring |
✅/❌ |
7 |
Weekly balance sheet to Govt. |
Monetary & Note Issue |
Sec 53 |
Data compliance lapse |
Internal compliance team tracking |
✅/❌ |
8 |
Segregation: Issue vs. Banking Dept |
Monetary & Note Issue |
Sec 23 |
Conflict of operations |
SOP enforcement and segregation audit |
✅/❌ |
9 |
Currency issued only by Issue Dept |
Monetary & Note Issue |
Sec 22 |
Illegal note issuance |
SOP and internal control checks |
✅/❌ |
10 |
Currency chest compliance |
Monetary & Note Issue |
Sec 33 |
Currency shortfall |
Vault audit + central reconciliation |
✅/❌ |
11 |
Backing currency with assets |
Financial Reporting |
Sec 33 |
Market distrust |
Quarterly FX/gold reserve review |
✅/❌ |
12 |
No trading activity by RBI |
Financial Reporting |
Sec 21(2) |
Legal violation |
Staff training, internal audit |
✅/❌ |
13 |
Only permitted lending |
Financial Reporting |
Sec 17 |
Regulatory breach |
Lending policy mapped to RBI limits |
✅/❌ |
14 |
Advance to Govt. per limits |
Monetary & Note Issue |
Sec 17(5) |
Fiscal indiscipline |
MOUs & statutory reporting |
✅/❌ |
15 |
Note design approval by RBI |
Monetary & Note Issue |
Sec 25 |
Forgery risk |
RBI vetting of currency design |
✅/❌ |
16 |
Separate reserve fund maintained |
Monetary & Note Issue |
Sec 46 |
Balance sheet errors |
Year-end reconciliation |
✅/❌ |
17 |
Surplus transferred to GoI |
NBFC Regulation |
Sec 47 |
Fiscal anomaly |
Review of audited P&L |
✅/❌ |
18 |
Adherence to Note Issue Limit |
NBFC Regulation |
Sec 22(1) |
Legal violation |
Note issuance audit |
✅/❌ |
19 |
Follow denominations specified by RBI |
NBFC Regulation |
Sec 24 |
Circulation confusion |
SOP + currency strategy doc |
✅/❌ |
20 |
No issuance of bearer instruments |
NBFC Regulation |
Sec 31 |
Criminal action |
Compliance memo in board minutes |
✅/❌ |
21 |
NBFC registered with RBI |
NBFC Regulation |
Sec 45-IA |
Ban from operation |
Check CoR status quarterly |
✅/❌ |
22 |
Fit & proper directors (NBFC) |
NBFC Regulation |
RBI Circular |
Disqualification |
KYC & conflict checks |
✅/❌ |
23 |
Capital adequacy met |
NBFC Regulation |
RBI Norms |
Risk of insolvency |
Regular CAR monitoring |
✅/❌ |
24 |
Fair practices for lending |
NBFC Regulation |
RBI FPC |
Consumer lawsuits |
Internal compliance training |
✅/❌ |
25 |
Risk classification accuracy |
NBFC Regulation |
RBI Norms |
NPA misreporting |
Automated risk scoring |
✅/❌ |
26 |
Quarterly RBI returns |
NBFC Regulation |
RBI Returns |
Fines |
Regulatory calendar tracking |
✅/❌ |
27 |
KYC norms followed |
NBFC Regulation |
RBI KYC Master |
PMLA penalty |
Real-time customer verification |
✅/❌ |
28 |
AML systems in place |
NBFC Regulation |
PMLA/RBI |
Criminal action |
STR filing system |
✅/❌ |
29 |
RBI audits conducted timely |
NBFC Regulation |
Sec 35 |
Audit objections |
Calendarized external/internal audits |
✅/❌ |
30 |
RBI inspection queries addressed |
NBFC Regulation |
Sec 35 |
Blacklisting |
Central compliance cell |
✅/❌ |
31 |
Disclosure of interest rates |
KYC/AML & Consumer Protection |
RBI FPC |
Customer dissatisfaction |
Rate publishing via mail/website |
✅/❌ |
32 |
Transparent lending agreements |
KYC/AML & Consumer Protection |
RBI Norms |
Civil cases |
Legal vetting |
✅/❌ |
33 |
Grievance redressal system |
KYC/AML & Consumer Protection |
RBI Ombudsman Scheme |
Customer complaints |
48-hour TAT policy |
✅/❌ |
34 |
Data protection for clients |
KYC/AML & Consumer Protection |
RBI Circular |
Data theft lawsuits |
Encryption and DLP controls |
✅/❌ |
35 |
Loan provisioning norms met |
KYC/AML & Consumer Protection |
RBI IRACP |
Penalty |
Monthly NPA report |
✅/❌ |
36 |
No unauthorized deposit collection |
KYC/AML & Consumer Protection |
Sec 45S |
Imprisonment |
Client on-boarding checks |
✅/❌ |
37 |
Customer identity properly verified |
Digital Compliance & Cybersecurity |
RBI KYC |
Legal action |
Aadhaar + PAN mandate |
✅/❌ |
38 |
RBI instructions for digital lending |
Digital Compliance & Cybersecurity |
2022 Guidelines |
Suspension |
App vetting & RBI checklist |
✅/❌ |
39 |
Cybersecurity norms |
Digital Compliance & Cybersecurity |
RBI Cybersecurity Circular |
Data compromise |
ISO 27001 & audit trails |
✅/❌ |
40 |
Controlled outsourcing practices |
Digital Compliance & Cybersecurity |
Outsourcing Master Direction |
Regulatory breach |
SLA with vendors |
✅/❌ |
41 |
Internal audit of NBFCs |
Risk Management & Basel Norms |
Sec 45MA |
Financial risks |
Quarterly IA review |
✅/❌ |
42 |
Board risk oversight documented |
Risk Management & Basel Norms |
RBI Expectations |
Board audit remarks |
Annual board workshops |
✅/❌ |
43 |
Related party transactions monitored |
Risk Management & Basel Norms |
Governance Code |
Conflict of interest |
Disclosures + audit |
✅/❌ |
44 |
Dividend declaration norms followed |
Risk Management & Basel Norms |
RBI Circular |
Capital risk |
RBI permission obtained |
✅/❌ |
45 |
Liquidity coverage ratio maintained |
Risk Management & Basel Norms |
RBI Basel Norms |
Shortage |
Daily LCR dashboard |
✅/❌ |
46 |
Follow moratorium guidelines |
Regulatory Filings |
Sec 45 |
Lawsuit risk |
RBI circular compliance |
✅/❌ |
47 |
Avoid misleading advertisement |
Regulatory Filings |
Sec 58B |
Penalty ₹1L |
Legal content team review |
✅/❌ |
48 |
Proper record retention |
Regulatory Filings |
RBI Direction |
Non-traceability |
DMS + archival SOP |
✅/❌ |
49 |
All returns filed with RBI |
Regulatory Filings |
Sec 45IB |
Monetary fines |
Calendarized filing alerts |
✅/❌ |
50 |
Proper calculation of Net Owned Funds |
KYC/AML & Consumer Protection |
Sec 45-IA |
Rejection of registration |
Chartered accountant certification |
✅/❌ |
51 |
Timely response to RBI notices |
NBFC Regulation |
Sec 45L |
Blacklisting |
Compliance team SOP |
✅/❌ |
52 |
Internal capital adequacy assessment process |
NBFC Regulation |
RBI Guidelines |
Capital mismatch |
ICAAP policy review |
✅/❌ |
53 |
Compliance with Basel III norms |
NBFC Regulation |
RBI Basel III |
Capital inadequacy |
Quarterly compliance certification |
✅/❌ |
54 |
ALM policy implementation |
NBFC Regulation |
RBI ALM Guidelines |
Liquidity risk |
Monthly ALM committee meeting |
✅/❌ |
55 |
Stress testing framework |
NBFC Regulation |
RBI Risk Management Guidelines |
Capital shocks |
Scenario-based simulations |
✅/❌ |
56 |
Market risk monitoring |
NBFC Regulation |
RBI Risk Guidelines |
Trading loss |
VaR & sensitivity analysis |
✅/❌ |
57 |
Operational risk loss database |
NBFC Regulation |
RBI ORM Norms |
Inaccurate risk profiling |
Loss event data collection |
✅/❌ |
58 |
Outsourced activity risk assessment |
NBFC Regulation |
RBI Outsourcing Guidelines |
Vendor breach |
Risk-based vendor selection |
✅/❌ |
59 |
Staff awareness on RBI compliance |
NBFC Regulation |
RBI Norms |
Operational lapses |
Regular training calendar |
✅/❌ |
60 |
Customer consent on data sharing |
Digital Compliance & Cybersecurity |
RBI Digital Lending Guidelines |
Data misuse |
Consent-based digital flow |
✅/❌ |
61 |
Audit of digital lending apps |
Digital Compliance & Cybersecurity |
RBI Norms |
Non-compliance |
App compliance checklist |
✅/❌ |
62 |
Disclosure of bank/NBFC promoter holdings |
NBFC Regulation |
RBI Guidelines |
Corporate governance issue |
Annual disclosure to RBI |
✅/❌ |
63 |
Filing of FDI/FII data |
NBFC Regulation |
FEMA + RBI |
Penalty |
Regular submission via FIRMS portal |
✅/❌ |
64 |
Proper classification of investments |
NBFC Regulation |
RBI AFS/HFT Norms |
Investment loss |
Mark-to-market controls |
✅/❌ |
65 |
Adherence to SLR maintenance |
NBFC Regulation |
Banking Regulation Act & RBI |
Monetary penalty |
Daily SLR tracker |
✅/❌ |
66 |
Correct accounting of forward contracts |
NBFC Regulation |
RBI Forex Guidelines |
FX losses |
Treasury policy enforcement |
✅/❌ |
67 |
Monitoring ECB limits |
NBFC Regulation |
FEMA/RBI |
Regulatory violation |
ECB tracker & approval system |
✅/❌ |
68 |
Repatriation reporting of foreign remittances |
NBFC Regulation |
FEMA/RBI |
Penalty |
Form A2 and FIRC validation |
✅/❌ |
69 |
Reporting of wilful defaulters |
NBFC Regulation |
RBI Master Circular |
Reputational damage |
Quarterly board review |
✅/❌ |
70 |
Reporting frauds to RBI within 3 days |
NBFC Regulation |
RBI Fraud Reporting Circular |
Regulatory censure |
Automated fraud escalation |
✅/❌ |
71 |
Verification of PAN/Aadhaar linkage |
Risk Management & Basel Norms |
RBI Directions |
Account freezing |
eKYC automation |
✅/❌ |
72 |
Reporting of Non-Performing Investments |
Risk Management & Basel Norms |
RBI Prudential Norms |
Misinformation |
Periodic asset quality review |
✅/❌ |
73 |
Sanction screening against watchlists |
Risk Management & Basel Norms |
RBI AML/UNSCR Guidelines |
Legal & reputational risk |
Name screening tool |
✅/❌ |
74 |
Adherence to NBFC governance code |
Risk Management & Basel Norms |
RBI NBFC Guidelines |
Board censure |
Annual governance audit |
✅/❌ |
75 |
Due diligence before loan disbursement |
Risk Management & Basel Norms |
RBI Lending Norms |
Credit loss |
Pre-sanction checklist |
✅/❌ |
76 |
Non-coercive recovery practices |
Risk Management & Basel Norms |
RBI Guidelines |
Lawsuits & complaints |
Training of recovery agents |
✅/❌ |
77 |
Reporting to Credit Bureaus |
Risk Management & Basel Norms |
CICRA + RBI |
Consumer disputes |
Automated monthly upload |
✅/❌ |
78 |
Approval for overseas investments |
Regulatory Filings |
RBI ODI Norms |
FEMA breach |
Legal and compliance validation |
✅/❌ |
79 |
Renewal of NBFC license timely |
Regulatory Filings |
Sec 45IA |
Cancellation of license |
Annual calendar monitoring |
✅/❌ |
80 |
Monthly return NBS-1 filed |
Regulatory Filings |
RBI NBFC Returns |
Monetary penalty |
MIS-based reporting process |
✅/❌ |
81 |
Quarterly return NBS-2 filed |
Regulatory Filings |
RBI NBFC Returns |
Non-compliance penalty |
Quarterly compliance calendar |
✅/❌ |
82 |
Half-yearly ALM return submitted |
Regulatory Filings |
RBI NBFC Guidelines |
Liquidity risk penalty |
Dedicated ALM MIS |
✅/❌ |
83 |
Exposure norms followed |
Forex & Overseas Transactions |
RBI Exposure Norms |
Capital at risk |
Exposure limit checks |
✅/❌ |
84 |
Avoid conflict in lending to group entities |
Forex & Overseas Transactions |
RBI Corporate Governance |
Conflict of interest |
Board-level oversight |
✅/❌ |
85 |
KYC updates for long-standing accounts |
Forex & Overseas Transactions |
RBI KYC |
Account freeze |
Periodic KYC triggers |
✅/❌ |
86 |
Central KYC registry compliance |
Forex & Overseas Transactions |
CKYCR + RBI |
Reporting failure |
API-based upload |
✅/❌ |
87 |
Audit trail of digital transactions |
Forex & Overseas Transactions |
RBI Cybersecurity |
Fraud risk |
DMS + transaction logging |
✅/❌ |
88 |
Monitoring of co-lending arrangements |
Audit, Disclosure & Policy Update |
RBI Co-Lending Guidelines |
Operational confusion |
Partner MoUs + MIS review |
✅/❌ |
89 |
Monitoring of FLDG arrangements |
Audit, Disclosure & Policy Update |
RBI Digital Lending Guidelines |
Contingent liability |
Risk assessment framework |
✅/❌ |
90 |
Compliance with Loan Securitization norms |
Audit, Disclosure & Policy Update |
RBI Guidelines |
Accounting issues |
Transaction-level checklist |
✅/❌ |
91 |
Classification of off-balance sheet exposures |
Audit, Disclosure & Policy Update |
RBI Norms |
Risk concealment |
OBS disclosures in financials |
✅/❌ |
92 |
Reporting of Capital to Risk-weighted Assets Ratio |
Audit, Disclosure & Policy Update |
RBI Basel Norms |
Capital adequacy concerns |
Monthly CAR review |
✅/❌ |
93 |
Ensure RBI prior approval for change in control |
Audit, Disclosure & Policy Update |
RBI NBFC Norms |
Invalid transaction |
M&A legal opinion |
✅/❌ |
94 |
Reconciliation of Nostro accounts |
Uncategorized |
RBI Forex Control |
Reputational loss |
Monthly reconciliation process |
✅/❌ |
95 |
Audit of suspense accounts |
Uncategorized |
RBI Circular |
Fraud risk |
Quarterly suspense audit |
✅/❌ |
96 |
Review of unclaimed deposits |
Uncategorized |
RBI Circular |
Consumer dissatisfaction |
Annual dormant account reconciliation |
✅/❌ |
97 |
Timely update of policies with RBI directions |
Uncategorized |
RBI Master Circulars |
Policy non-alignment |
Annual policy calendar |
✅/❌ |
98 |
Ensure compliance with Inspection Reports |
Uncategorized |
RBI Inspection |
Repeat audit flags |
Inspection tracking register |
✅/❌ |
99 |
No delayed implementation of regulatory instructions |
Uncategorized |
RBI Act Sec 45L |
Penalties |
Internal compliance reminders |
✅/❌ |