0% found this document useful (0 votes)
18 views63 pages

Audit and Inspection Guidelines 2025

The document outlines the guidelines and requirements for credit monitoring, inspection, and audit processes within the organization, including a campaign for reducing Special Mention Accounts (SMA) and renewal requirements for borrowal accounts. It details the auditing procedures, including frequency, exemptions, and responsibilities of auditors, as well as the classification of accounts and compliance measures. Additionally, it covers the consequences for auditors in case of deficiencies and the processes for various types of audits, including statutory, revenue, and forensic audits.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views63 pages

Audit and Inspection Guidelines 2025

The document outlines the guidelines and requirements for credit monitoring, inspection, and audit processes within the organization, including a campaign for reducing Special Mention Accounts (SMA) and renewal requirements for borrowal accounts. It details the auditing procedures, including frequency, exemptions, and responsibilities of auditors, as well as the classification of accounts and compliance measures. Additionally, it covers the consequences for auditors in case of deficiencies and the processes for various types of audits, including statutory, revenue, and forensic audits.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Credit Monitoring ,

Inspection and Audit


Audit and Inspection
IOBOA PROMOTION
CLASSES
( Updated as on 17.07.2025)

DATE 30.11.2025By: STC Mangalore

BY Bikash Kumar Singh


Spot SMA, Stop NPA"- Campaign
"for November 2025"
Campaign for Reduction of SMA to Regional Offices

Campaign Duration: 04/11/2025 to 30/11/2025


Regional Categorization and Qualifying Criteria:

Based on SMA outstanding regions are divided into 4


categories.
Overall minimum reduction is 10% of the base figure as
on 31/10/2025 to qualify the campaign.

There should not be any increase in SMA 2 as compared


to outstanding of 31/10/2025
CAF SUBMISSION TIMELINE
Renewal Requirements and Status
• Mandatory Review: Ensure 100% renewal or review of borrowal
accounts with credit limits ≥ Rs 1 Lakh.

• SRRP (Special Review/Renewal Process): Allowed only once


between 2 regular sanctions.

◦ Regular SRRP: 6-month extension with penal charges.


◦ SRRP “In Process”: Applies if complete renewal papers
submitted before expiry and proposal is under process; no
penalty levied.
• Validity: Both Regular SRRP and In process validity is 180 days
from the renewal due date.
• NPA Classification: If overdue beyond 180 days → NPA.
Processing Charges: If regular renewal completed within 180 days, proportionate
processing charges are refunded, and fresh renewal charges are collected.

• Borrower Notification: Borrowers should be informed through a letter 2 months


before the expiry of the limit.

B. Review Frequency and Exemptions


• Below Hurdle Rate: If credit rating is below the hurdle rate, review/renewal shall
be done in 9 months.
◦ The revamped ICON rating Hurdle Rate is IOB-5 for all types of accounts.

• Home Loans (HL): HL of Rs. 25 lakhs and above (including NPA accounts) will be
reviewed once in 3 years.
• Exemptions from Annual Review:
◦ Secured term loans, DL, NSC/LIC policies, Resurgent India Bonds, IMDs.
◦ All retail term loans below Rs. 25 lakhs.
Frequency of submission Statement
• E R I Statements (Exposure Review & Inspection): Monthly
reports required for irregular advances.

• Continuous Surveillance Statements (CSS): Submitted monthly


from branches for fund based working capital limits ≥ Rs. 1
crore.

• Stock Statements: Must be submitted regularly by Borrower


unless specifically exempted.

CMA Data: Required in all cases where working capital limits are
Rs. 2.00 crore and above, along with audited balance sheets.
Sanction Revalidation: Sanction is valid for 6 months.
◦ Sanctions by MCB (Management Committee of the Board) can be
revalidated by CAC (Credit Approval Committee). Others by the
respective sanctioning authority.

Verification: Physical inspection of securities required before renewal.


• General Valuation: Valuation required every 3 years.
• Property Valuation ≥ Rs. 5 Crores:
◦ Two valuation reports must be obtained from two different Approved
Valuers.
◦ If multiple properties are mortgaged, the second valuation is required
only for the property whose value exceeds Rs. 5 crores.
◦ Comparing Valuations: If the difference between the two valuations is
≤10%, accept the lower value.
◦ If the difference is >10%, engage a third valuer; the lowest value
among the three is the notional fair market value.
Compulsory Audits: Credit Limits of Rs. 25 lakhs and
above must be audited compulsory by the borrower’s
CAs.

• Agricultural Borrowers: Rs. 50 lakhs and above

• Auditors’ Certificate: Obtain an annual certificate


from the borrower’s auditor confirming that all statutory
dues, including EPF dues, have been paid; no waiver
allowed.
Stock Audit Eligibility
• Criteria: Borrowal accounts having working capital facilities (Fund
Based & Non-Fund Based) outstanding of Rs. 5 Crores and above as on
31st March every year, and where the prime security is hypothecation of
stock and/or book debts.
• Exclusions:
◦ Cash Credit (Staff, ETF, Miscellaneous, Deposits).
◦ NPA accounts where stocks/receivables are not available as
security.
◦ Consortium accounts where we are only a member and the leader
bank conducts the audit.
◦ Public sector undertakings.
• Multiple Banking: Stock audit conducted by other banks under
multiple banking arrangement is acceptable if the report is not older
than 6 months.
Red Flagged Accounts (RFA) and EWS
• RFA Scope: Applicable to all accounts with exposure ≥ Rs. 3 Crores (Fund-
Based & Non-Fund-Based).
• Multiple/Consortium Banking: Each bank flags the account on CRILC
individually.
◦ Forensic audit conducted by Leader Bank/Largest lender within 3
months.
◦ Decision on Fraud status within 15 days of audit report.
◦ Leader bank lodges CBI complaint for all member banks once declared
fraud.
• EWS (Early Warning System): New system utilizes 143 triggers.
• EWS Review Time Frame:
◦ Branch Level (Advances in charge): 4 working days.
◦ Branch Manager / CrMD Officer (RO): 2 working days.
◦ Central Office (CO): Reviews all EWS monthly and prepares summary
before the 20th of the next month.
IFCOFR (Internal Financial Controls over Financial Reporting)
• Mandate: RBI directed Statutory Central Auditors (SCAs) to
certify IFCOFR adequacy from FY 2020–21.

• Framework: 39 Risk Control Matrices (RCMs) and 1438 control


points approved by the Board.
• Failure Rule: Even a single RCM failure results in IFCOFR for that
controlling office being considered failed.
• RO Responsibility: Ensure compliance of non-complied IFCOFR
points within 60 days of audit completion.

• Testing: Branch control points tested during RBIA by Internal


Auditors. CO department control points tested annually by the
Inspection Department
Critical lapses, serious irregularities, or failure to adhere to procedures
must be reported to the General Manager of the Inspection
Department at the Central Office within 24 hours of detection

Relieving Officer’s Certificate (ROC) (Form F-278): Submitted in Part A


(Outgoing) & Part B (Incoming) within 15 days of charge handover.

Monthly Surprise Cash Verification (circular dated 13.06.2025):


Applies to branch cash, ATM, and BNA cash balances.
◦ Timing: Designated officer must commence verification no later
than 9:45 AM.
◦ RO Submission: RO must submit a consolidated verification
certificate to the Designated Authority on or before the 5th of the
succeeding month.
 INDEPENDENT EXAMINATION OF THE
WHAT IS AUDIT ? FINANCIAL AND NON-FINANCIAL INFORMATION

 MAY BE ONSITE OR OFFSITE

 RESULT OF AUDIT PROCESS MAY BE


ASSURANCE , CERTIFICATION, CONFIRMATION

AUDIT INCLUDES INSPECTION

THE ACT OF LOOKING AT SOMETHING CAREFULLY BY VISITING


INSPECTION : AT SITE
REMUNERATION PAYABLE TO Ref. Circular : Misc./95/2025-26
CONCURRENT AUDITORS Dated : 15.07.2025 Issued by :
Inspection Deptt
CATEGORY FEES ( RS)

SMALL AND MEDIUM 18000 PM

LARGE 24000 PM

VERY LARGE 30000 PM

EXTRA LARGE 36000 PM

In addition to routine Branch Concurrent Audit :

Ccurrency Chest Attached With CA + Rs.3000/- Per Month


Branches
FEMA Audit of AD Branches + Rs.5000/- ( Half Yearly )
 IF PERFORMANCE OF THE CONCURRENT AUDITOR IS
NOT FOUND SATISFACTORY THEN RECOMMENDATION
WILL BE SEND TO GM INSPECTION FOR TERMINATUION/
TERMINATION DE EMPANELMENT OF THE SERVICE OF THE
CONCURRENT AUDITOR.

 IF AUDITORS FAILS IN SUBMISSION OF MONTHLY AUDIT


REPORT FOURTH INSTANCE.

REVIEW OF
THE THE REVIEW OF THE CONCURRENT AUDIT REPORT
CONCURRE WILL BE DONE ON QUARTERLY BASIS IN THE MONTH
NT AUDIT OF SEPT, DEC MAR AND JUNE
REPORT
MONTHLY CONCURRENT AUDIT REPORT SHALL BE REVIEWED AS FOLLOWS

FOR BRANCHES FOR OTHER BRANCHES BRANCHES UNDER


TOP 20 ADVANCES
 ADVANCES >100 CR AS AT
THE END OF THE QUARTER
 AD BRANCH
 ARMB
REVIEW SHALL BE MANDATORILY PARTICIPATED AND CONDUCTED BY

 RM 2ND LINE OF RO RM
 ZAO BM ZAO
 BM PARTNER OF THE FIRM BM
 PARTNER OF THE AUDIT MINUTES SHALL BE PLACED AND APPROVED PARTNER OF THE
FIRM BY RM WITHIN 2 DAYS OF THE MEETING FIRM

IN CASE OF NON AVALIABILITY OF THE MANDATORY PARTICIPANTS THE MEETING


SHALL BE POSTPONDED TO ANOTHER DAY BUT TO BE COMPLETED WITHIN 30 DAYS ( IN
ALL CASES) OF THE END OF THE QUARTER
Statutory Audit:
 Statutory Audit of Branches are being done on
quarterly as well as annual basis.
 For the purpose of quarterly audit of 20 branches
plus branches under concurrent audit to be audited
by SCA which should at least cover 50% of the
advances and 50% of the NPA.
 For the purpose of Annual Audit of Branches, all
Branches having advance of Rs.20 Cr and above are
selected along with 20% of remaining branches
representing all category of Branches so that at least
90% of advances are covered under the Audit.
 The deficiencies are reported in LFAR for
compliance.
 Compliance is to be submitted to RBI within 60 days
from the date of report.
Revenue Audit:
 Revenue audit is conducted to ensure that :
1. To check the proper interest rate are applied.
2. Eligible service charges are collected.
3. Revenue and capital charges are authorized by authorities.
4. Arithmetically accuracy in computation of revenue.
 It is done for the period Jan – Dec.
 Branches where total Advances is 5 crore and above as on 31st Dec.
 If the leakage detected and found that it occurred due to user negligence ,
suitable staff accountability may be conducted and in such cases disciplinary
action may be initiated against erring official
 If the leakage detected and found that it occurred due to concurrent Auditors or
Revenue Auditors, suitable disciplinary action may be initiated against erring
official for such omission
 Branch is having time of 2 days for recovery or reason of non-recovery to RO
Accountability for Revenue Leakage:
 Concurrent Auditor:

First amount not more than 100000 or entire amount is Concurrent Auditor will be
Occasion recovered by branch within same day of detection – cautioned

Second amount not more than 100000 or First occasion with Penalty of 10000
Occasion aggregate amount 100000 and above but below 1000000

Third Aggregate amount not more than 100000 or second Termination of auditor & de-
Occasion occasion, aggregate amount 100000 & above and below empanelled
1000000 or aggregate amount 1000000 and above

 Revenue Auditor:
1. If the aggregate amount 100000 and above –auditor shall be de-empaneled.
FEMA & Management Audit
FEMA:
 It is conducted by concurrent auditor of AD branches.
 It is done half yearly basis
 Compliance of FEMA guidelines at AD branches are
checked.
Management Audit:
 CO departments, Regional Offices and specialized
departments.
 Review of policies in force
 How effective functioning
 It is conducted Yearly
Forensic Audit:
 Forensic Audit is the examination of financial statements to extract
evidences that can be used in a court of law or in a legal proceedings.

 It is done to find facts that are admissible in court of law to prove financial
crime like diversion and siphoning of fund as well as fraud.

 Forensic audit needs expert in Audit and Accounting as well as expert of


the legal implications of such audit reports.

 To maintain the quality of reporting under Forensic Audit results, the panel
of professionals having expertise and training in relevant field are
appointed as forensic Auditors.

 The empanelment shall be in force for 2 years i.e. during 2 calendar years.
Credit Compliance Audit :
Allotment & Review:

For exposure < Rs. Accounts shall be allotted and reviewed by Credit
5.00 Cr Monitoring Department of respective Regional Offices
For exposure Rs. Accounts shall be allotted and reviewed by the LRMD,
5.00 Cr and above CO

2% of the accounts having exposure below Rs. 50.00 lakhs to be


randomly selected and shall be allotted by the respective
Regional Offices.
Overseas Branches
Eligibility for the CCA Audit Accounts having exposure Rs.1 .00 Crore &
above shall be eligible

Authority to conduct CCA Audit shall be conducted by the internal


Audit auditor of Overseas Centers

Reviewing authority for CCA Review to be done by the LRMD, CO.


audit
Coverage under Credit Compliance Audit

All standard borrowal accounts with exposure of Rs 50 lakhs &


above will be covered.

Exemptions 1. Loan against Deposits/ Government securities/


from liquid securities such as JL/ AJL etc.
coverage of 2. All NPA accounts
Credit 3. Loans granted to staff members under staff
Compliance schemes. However, loans granted to staff under retail
Audit ( schemes are eligible for audit.
Point 4 to 6 4. TreDs Accounts sanctioned through TreDs
are new Platforms.
additions) 5. Pool buyout accounts.
6. Bank Guarantee secured by guarantee of other
Public Sector Banks.
Credit Compliance Audit format Two formats for Credit
and Risk Classification Compliance Audit

First format is for reporting of other than


retail loans and contains total 44 points
having total scores of 165.

Second format is for reporting of all the


retail loans and contains total 17 points
having total score of 51
Appointment of Auditors:

Retail Loans Audited by our own staff members of the respective


Regions
Other than Audited by the external auditor's i.e. Concurrent
Retail Loans auditors of the Bank or Empanelled Retired Officers
(EROs) or RBI panel auditors

Closure Mechanism Audit will be closed after l00% rectification of


of Audit Report zero tolerance deficiencies &
80% rectification in other deficiencies
Authority to close Audit may be closed by CRMD, RO or
the Audit Findings CCA GMs' Committee at Central Office as the
case may be
Periodicity for conducting CCA
Retail loans  Audit shall be conducted only once within 2 months
of the first disbursement.
 However in case of partially disbursed accounts,
Reviewing Authority at RO/CO shall decide conduct
of subsequent Credit Compliance Audit after full
disbursement and/or completion of project.

Other than  Audit shall be conducted once in a year for all


Retail Loans eligible accounts. Further, Periodicity of review of
accounts is to be based on Risk Category of the
Account i.e. High Risk – 6 Months , Moderate Risk –
9 Months and Low Risk – 12 Months
 Within 2 months from the first disbursement in case
of new accounts or enhancement of exposure
 Within 2 months from the expiry of earlier CCA
report for existing accounts
Stipulated time for Compliance/Rectification
Zero tolerance level to be rectified within 30 days from the
deficiencies completion of audit.
Other than zero tolerance to be rectified within 45 days from the
deficiencies completion of audit.
In case where branch is should be reported to reviewing authority
not in position to rectify within above specified timelines along
the deficiencies with the reasons for the same.

Reviewing authority has the discretion to


close the report.

Credit Compliance Audit report closure time is 60 Days.


Legal Audit
 Eligibility Criteria for Legal Audit : All credit exposures of Rs.5 crore and above
to periodic legal audit and re-verification of title deeds with relevant
authorities as part of regular audit exercise till the loan stands fully repaid.
 Periodicity for Legal Audit

In respect of standard asset accounts In respect of non-performing Asset


of RS.5Crore and above, Legal Audit (NPA) accounts with RS.5.00Cr. and
exercise is to be done by above outstanding, Legal Audit is to
RO/Branches once in twenty seven be conducted once in twelve months
months until such time the Bank's till such time Recovery Satisfied in
dues therein are fully repaid respect of such NPA accounts
Short Inspection
 The Short inspection is an internal control tools
Objective of Short Inspection : To find shortcomings and ensure
compliance of very near transaction event.
 Periodicity of Short Inspection : The audit is to be conducted on
half year basis for the period Apr - Sep and Oct - Mar every
financial year.
 Exemption from Short Inspection : Short Inspection is exempted
for Concurrent Audit, ERO Branches and where Branches were
subjected to RBIA during the month of Jan-Mar for March half
year and Jul-Sep for Sep half year.
 Auditor must not be less than Scale III who has completed
multiphase credit /intensive credit program or Certified Credit
officer from IIBF or who has served as 1st Line for least 3 Years.
 Each Auditor shall not be given more than 5 branches to conduct
short inspection for each half year.
Short Inspection
 The maximum man-days is 2 days and no extension is permitted.
 The Auditor shall be liable for not checking, if any deficiencies are found
during RBIA or any other audit / Investigations subsequent to Branch Short
Audit.
 Regional Manager shall record steps or corrective action to ensure
rectification of observations.

The Audit Points are grouped into Cash/Advances/ Audit/


KYC and MISC.
There are totally 70 audit points available in the report (
increased from 68 to 70) Ref : Misc / 382/ 2022-23 dated
28.10.2022 Issuing Deptt: Inspection
Jewel Inspection
 Digitalization of Jewel Loan Inspection wef 01.11.2021.

 Periodicity of Jewel Inspection ( Misc/78/2020-21 dated 05.11.2020 )


 Jewel Loan Inspection is to be conducted for every quarter in respect of all Jewel loans disbursed
during previous quarter and outstanding as on date of inspection, subject to jewel loan disbursal
during the quarter being 200 or more in number. And if less than 200 in number, jewel loan
inspection is to be conducted for 2 quarters combined together.
 As per fresh guidelines ( Ref. Circular MISC/ 33/2025-26 Dated 02.05.2025 ) all auditors visiting the
Branches for Quarterly Jewel Inspection are required to check Jewels disbursed/outstanding as
on date of start of the Jewel Inspection.

[Link] Quarter Audit Plan Logic Account Checking/downloading


1 Q1 Branches where Jewel Loan disbursal >= 200 01st April to Audit start date
(April to June) packets.
2 Q2 100% branches All the outstanding Jewel loan accounts as on
(July to September) Audit start date
3 Q3 Branches where Jewel Loan disbursal >= 200 1st October to Audit start date
(October to December) packets.
4 Q4 a. Branches where Jewel Loan disbursal >= 1st January to Audit start date
(January to March) 200 packets.
1st October to Audit start date
b. Branches which were not audited in Q3
SACC- Self Assessment Compliance Certificate
 Objective : SACC is one of the internal strengthening and preventive vigilance
tool
 Who Conducts SACC : to be done by compliance officer of the Branch
 Periodicity of SACC : for Half Year ending June and December.
 This should cover the preceding half year and sample to be selected from the
entire 6 months.
 Minimum 5 samples to be taken for checking the compliance and directive in
the related aspect.
 Out of the selected samples Even if one sample fails conclusion should be No.
 In case of no testing done. NA should be mentioned.
 While doing SACC , compliance officer should go through earlier inspection
report to know the real position.
 Any fraud during the audit period must be reported.
PVRO- Physical Verification of Compliance by RO
 Objective : It is one of the internal strengthening and preventive vigilance tool
 Who Conducts : to be done by officer nominated by Regional Office
 Periodicity of Audit : for Half Year ending March and September.
 This should cover the preceding half year and sample to be selected from the entire 6
months.
 Minimum 5 samples to be taken for checking the compliance and directive in the related
aspect.
 Even if one sample fails conclusion should be No.
 In case of no testing done. NA should be mentioned.
 While doing PVRO , the officer should go through earlier inspection report to know the
real position.
 Any fraud during the audit period must be reported
OCAS- Offsite Control Audit System
 OCAS works through a system of “Alerts”.
 Alert is a notification of deviation which has been occurred in a transaction.
 After day end transaction data for the day is processed in Ethic server, with
reference to laid down procedures and guidelines.
 Alert is generated for any deviation noticed and is made available to the
branches for rectification or reply. Branches have 15 days time for closure
of alerts.
 After processing of Alert by Branch it moves to Regional office and
Inspectorate, for further processing and closure.
 Low risk alerts pending more than 15 days at branches will be reassigned
as Medium Risk and escalated to Regional Office for closure of alert.
 Medium risk alerts are attended and closed by RO after
rectification or justification from the Branches.
REVAMPING OF OCAS ( Ref Cir. Misc/364/2022-23 DATED 22.09.2022)
Introduction of New OCAS Alerts for Branch and Regional Office
S Description of Alert Frequency Risk Alert Alert Closed
N of Alert Category Generated at
at

1 When Loan/CC/SB/CD accounts closed to the debit of Office Account Daily Medium Branch Regional
Office
2 When Assets/Expense heads are in Credit Balance and Liability/Income Monthly Medium Branch Regional
heads in Debit Balance Office
3 When the Balance in the Utility payment account in Non Zero at EOD Daily Medium Branch Regional
Office
4 When There is Credit of Interest in Loan/ CC Account instead of Debit Monthly Medium Branch Regional
Office
5 When Manual Transaction are initiated in Dormant/ Inoperative Account Daily Medium Branch Regional
Office
6 Overdue deposit closed and credited to other than depositor account Daily Medium Branch Regional
Office
7 Loan Sanctioned in a month Monthly Regional Regional
Greater then equal to 3 Krishi Samridhhi > 3 Lakh High Office Office
Greater then equal to 5 Mudra / Agri Dairy / Subhgruha/SME300
Greater then equal to 10 KCC/SHG
Greater then 50 loan in a month excluding Jewel Loan and Demand Loan
against Deposit
Offsite Monitoring Unit (OMU)
 PROBE – Perpetual Remote Offsite Audit for Branch
Excellence.
 Offsite Monitoring Unit ( OMU ) is a fundamental tool in monitoring the
conduct of branch business activities. It involves reviewing and
analyzing of reports generated from CBS. This tool enables
identification of deviations and their rectification, thus mitigating
some of the operational risk.
 Compliance Matrix:
Other Audits
KYC AUDIT:

 Second line of the branch has to submit the KYC compliance Every week to
the branch manager

 1st line of the branch has to submit KYC compliance certificate to regional
office within 5th of the succeeding month.

 Regional Office to submit the consolidated report to CO by 10th of succeeding


month.
Other Audits
Self Audit of Income & Expenditure:
 Checking of applicable of correct interest rate
 Correctness of income and expenditure
 Second line has to submit before 4th of every month.
 Branch to recover the income leakage and report to RO before 7th of every
month.
 RO to send consolidated data to CO before 15th of every month.
IS AUDIT (Information System)
 Checking of systems and IT infrastructures, Procedures to mitigate the associated
technological risk.
 Quarterly
 Questionary to be filled up by second line of the branch and Report has to be submitted by 7th
of succeeding month.
Quarterly Dynamic Risk Assessment RBIA-Risk Based Internal Audit

 The New Framework adopts Dynamic Risk Assessment Model effective


from 31.10.2021 on three parameters:
 Business Risk
 Automated Control Risk
 Control Risk
Dynamic Risk Assessment Model
 The Risk Mitigation plan ( RMP) by RBI has mandated review of existing Internal audit
System and directed for adoption of
Forward looking approach ,
adequate coverage of business area ,
Efficient audit process ,
realistic risk assessment with Back testing for deficiency and system level,
modifications for effectiveness in risk based internal audit system.

 A detailed review of our internal Audit system was undertaken by M/S Deloitte and
 The risk advisory has recommended for Dynamic Risk Assessment mitigation plan
directed by RBI.
 The recommended Dynamic Risk assessment model has been accepted and approved
by the Audit committee of Board for immediate implementation w.e.f. 31 Oct 2021.

54
Risk Parameters and Weightages

The Risk Assessment of Branches during Internal Audit shall have evaluation of
following Parameters with appropriate weightages :
A. Business Risk ( BR ) :
The Business Risk parameters shall be system driven and picked up from
CBS Ware house and evaluated on QUARTELY basis for risk scoring as
follows :
1. Deposit , Position and Trend
2. Credit Quality and Concentration , position and Trend
3. Performance of the Branch , Position and trend
4. NPA Management , Position and Trend

55
B. Automated Control Risk ( ACR ) :

The Automated Control Risk parameters shall be sourced and supplied by Co


Departments on QUARTELY basis and evaluated for its position and trend with
appropriate weightages for Risk scoring. The various ACR Parameters are as
follows :
1. OCAS / OMU
2. KYC
3. AML
4. EWS
5. RFA
6. Compliance Audit SACC/PVRO
7. Operational Loss ( Customer Compensation / Penalties imposed )
8. Frauds reporting during the period 56
C. Control Risk :

The Control Risk shall be evaluated by Internal Auditor during the Audit
as per Branch Audit Schedule and commencement based on Revised
Check list mapped as per classification of branches (AD, General, Large
Corporate) covering wide business areas with appropriate weightages
under the following categories :

1. General Branch Management


2. Operational Risk Management
3. Credit Risk Management
4. Internal Control
5. Systems Management
6. Compliance Management
57
Dynamic Risk Assessment

 Quarterly Risk Assessment :


Irrespective of the Audit schedule on any branches, the system facilitates an Automated Quarterly Risk
Assessment that needs to be initiated and run every Quarter (on successful import of Business risk and
Automated Control Risk. On Initiation by NAO, the system shall carry out a risk assessment
and arrive at a dynamic risk.

 Risk Assignment and Score :


The risk assignment score is as follows :
Risk Score Business Risk Control Risk

High Below 30% Below 40%

Medium 30% to 60% 40% to 70%

Low Above 60% Above 70%


58
 Negative Scores :
Zero Tolerance Area , Special Report and leakage of income shall have negative scoring.

ZERO TOLERANCE AREAS 10

SPECIAL REPORT 10

LEAKAGE OF INCOME

UPTO RS 10000 05

ABOVE RS 10000 10

DYANIMIC UPDATE AND QUARTERLY RISK ASSESSMENT


(The quarterly Risk Assessment under schedule is called as QUADRAS )
59
 The Automated Control Risk parameters of all Branches shall be served
by Central Office Department on Quarterly Basis.

 The quarter ending data as per the format will reach to Inspection
Department by 3rd Working day in the month of April, July, Oct and Jan
of every Year .

 The received data shall be authorized and updated in to the ethic


system by the 6th working day of the Months of April, July, Oct and Jan

 System Administrator ethic shall supervise and ensure completion and


submit a status report to Head Internal Audit on the 7th of every first
month of the quarter.
Sampling Methodology :
The sampling method shall be system driven and will auto populate on Audit
Commencement. The system driven samples are mandatory for review by
Internal Auditor.
AUDIT PERIOD PREVIOUS TO AUDIT PERIOD

Review of 100 % If overall rating of the branch in previous inspection is


Disbursement made

Review of 10% of OCAS and High and Above 20 % of Sampling


OMU observations

Medium and Increasing 10 % of sampling

Medium and decreasing and 8% of sampling


stable

Low 5 % of Sampling
Escalation Mechanism : An automated Escalation mail of overdue ZTA

Escalation Matrix on Non Compliance of ZTA


TO BRANCH TO RO TO NAO TO CO
> 30 DAYS > 45 DAYS > 60 DAYS > 90 DAYS

FRC PROACTIVE ESCALATION ALERT


A PROACTIVE ESCALATION MAIL ON DUE FRC

FRC ESCALATION MATRIX ON DUE DATE

TO BRANCH TO RO TO NAO TO CO
> 30 DAYS > 60 DAYS > 90 DAYS > 120 DAYS
RBIA-Risk Based Internal Audit
 Over Frequency of Inspection :
 Low Risk Branches to be audited once in 15-18 months.
 Medium Risk Branches to be audited once in 12 to15 months.
 Business Risk-High and Control Risk is low or medium - once in 12 months.
 Extremely High, Very High and where control risk is high risk rated branch
shall be audited in the interval of 9 Months.
RBIA-Risk Based Internal Audit
 High Risk Branches need Special attention:
1. RM visit within 3 working days and Change in Branch Management if required
2. Quarterly progress report till branch upgraded to Medium or low category
3. Introduction of concurrent Audit System if required.
 Timeline to reply to the irregularity and filing FRC is 2 months from the date of
inspection report which can be relaxed by RM up to one additional month
 and if further time is required GM- inspection can give one additional month if he is
satisfied with the reason furnished.
(Branch Point war Reply time period - within 45 days)
 If there is no relaxation provided the timeline of two months to be followed.
 The reply should not contain any pending compliance under Zero tolerance areas.
 Any non compliance under Zero Tolerance areas will attract 50 negative marks under
control risk
RBIA-Risk Based Internal Audit
SPECIAL FOCUS AREA [SFA] ( Refer Circular Misc/138/2023-24 Issuing Deptt
Inspection Dated 07.11.2023 )
 A new category namely Special Focus Area ( SFA) has been introduced w.e.f. 01st
October 2023 to have Risk Focus on the control areas that has propensity of High
Risk. Non –Compliance reported in SFA mandates mitigation of risk with appropriate
remedial measures, strictly within 30 Days.
 A total of 08 Risk Areas are classified under Special Focus Areas :
I. Sanction Exceeding Branch Manager’s discretionary powers
II. Broken Period Encumbrance Certificate( BPEC)
III. Review / Renewal of limits pending more than 90 Days
IV. Registration of Memorandum of Deposit of Title Deeds ( MoDT)
V. Obtention of RC book with Banks Clause.
VI. Registration of Charges
VII. Revenue Leakage
[Link] Coverage ( CGTMSE / CGSSI / ECGC Etc. )
RBIA-Risk Based Internal Audit
As per Board approved Internal Audit Policy 03 Control Areas are classified as
Zero Tolerance Areas which shall be effective from 01st October 2023.
Following are the Zero Tolerance Areas and its control objectives :
[Link]. Zero Tolerance Control Objective
Area
1. 2nd Line 2nd Line Certificate is held for documents
Certificate ( Including Single Man Branches from RO )

2. Documental Prescribed Document are obtained in the standard format for all facilities,
Irregularities & with all covenants duly incorporated and ensured it is complete , valid ,
Missing Documents enforceable and adequately stamped. Such obtained documents are signed
by all parties in proper capacity and has adequate power to execute /
mortgage.
All documents are in proper custody and available for verification. No
Documents are missing.
3. No Objection from No Objection Certificate ( NOC ) is obtained from concerned authorities for
Society / creation of charge or for mortgaging lease hold rights viz. State financial
Government entity institutions , Societies , Housing Boards , industrial boards , control boards.
STANDARD OPERATING PROCEDURE : SPECIAL REPORTS – REPORTING AND
CLOSURE ( Refer : Circular Misc/139/2024-25, Issuing Deptt : Inspection Dated
16.12.2024 )
STANDARD OPERATING PROCEDURE : SPECIAL REPORTS – REPORTING AND
CLOSURE ( Refer : Circular Misc/139/2024-25, Issuing Deptt : Inspection Dated
16.12.2024 )

 Single Special Report may be issued by Internal Auditor when Similar irregularities on Multiple
accounts under each type of loan.

 Any irregularities that is already existing or identified during the course of inspection and found to
be reported as Vigilance Overtone, the matter shall be reported in Vigilance page report in Ethics
Package (CAAM).

 The matter which is identified during course of RBIA with Vigilance overtone should be brought to
the notice of Top Management through Special Report.

 Internal Auditor shall discuss on significant findings with Nodal Audit Head (In absence, then
AGM/DGM of Inspection Department, CO), before issuing Special Report or submission of Special
Letter.
STANDARD OPERATING PROCEDURE : SPECIAL REPORTS – REPORTING AND
CLOSURE ( Refer : Circular Misc/139/2024-25, Issuing Deptt : Inspection Dated
16.12.2024 )
 The Special Report is issued by Internal Auditor in Ethic Package (CAAM). The Ethic Package (CAAM) is
enabled to send the Special Report by Email to Branch, respective Regional Manager, Nodal Audit
Head, and General Manager Inspection.

 On receipt of Special Report, Branch shall immediately take necessary steps to ensure rectification
under the guidance of RO.

 Regional Offices : On receipt of Special Report by the Regional Office, the Inspection Department shall
obtain status report within 10 days.

 The department should place status note on special report to RM within 15 days from the report date.

 In the ensuing Regional Audit Committee of Executives (RACE) meeting an agenda on the pending
Special Report is to be included and status is to be incorporated.

 The stipulated Turn Around Time (TAT) for Regional Office to monitor and recommend Closure of special
report is 60 days from the date of Special Reports/Letter issued.
“Discover & Recover” Incentive Scheme for Internal Auditors
Detection of Leakage of Income & Timely Recovery (FY2025-26)
REF NO: MISC/ 83 /25-26 Dated : 07.07.2025 Issued By : Inspection Deptt
 Leakage of income directly affects the profitability of the bank.
 Internal Auditors plays a crucial role in detection of Leakage of Income during Risk Based
Internal Audit (RBIA) of a branch. Bank has decided to roll out an incentive scheme for the
internal auditors for FY 2025-26 for detecting Leakage of Income (detected and subsequently
recovered within 90 Days) to motivate auditors.
 Auditors are required to check for Leakage of Income broadly pertaining to below areas:
 Non-Charging of additional interest for SRRP accounts.
 Non-Charging of additional interest for account where audited balance sheet is not
submitted with in time.
 Non-application of correct interest rate in loan/CC/OD accounts
 Non-charging of additional interest for delayed period for delayed submission of stock
statement.
 Non-recovery of Godown / Unit Inspection Charges and documentation charges.
 Short charging of commission on Non-Fund Based facilities.
 Processing charges ( for broken period )/Commitment Charges/ Mortgage Charges not
collected. .
 Any other charges not collected as applicable from time to time.
“Discover & Recover” Incentive Scheme for Internal Auditors
Detection of Leakage of Income & Timely Recovery (FY2025-26)
REF NO: MISC/ 83 /25-26 Dated : 07.07.2025 Issued By : Inspection Deptt
Incentive Scheme:
Bank has decided to roll out an incentive scheme for the internal auditors to continue their efforts for augmenting
income/profitability of the bank for FY 2025-26 (Timely detection of Leakage of Income during RBIA and rec
Eligibility and other criteria:
 Leakage of Income identified/detected and recovered subsequently during Financial Year 2025-26 between 01st
April 2025 to 31st March 2026 will be eligible for consideration.
 Recovered Leakage of Income amount should be >=Rs.25 lacs for considering an auditor for receipt of Incentives
under the scheme.
 Leakage of Income recovered with in a span of 90 Days will be reckoned.
Rewards & Appreciation:
 GROUP I: Recovered Leakage of Income >=Rs.50 Lacs
 Reimbursement for purchase of items (Books/Bags/Stationary items/watches) costing up to Rs.10,000/-
 Appreciation letter signed by Respected ED’s/MD & CEO.
 GROUP II: Recovered Leakage of Income >=Rs.25 Lacs and < Rs.50 lacs
 Reimbursement for purchase of items (Books/Bags/Stationary items/watches) costing up to Rs.5,000/-
 Appreciation letter signed by GM (Inspection).
The Names & Photos of eligible Auditors will be displayed in IOB online for one month.
RBI INSPECTION

RBI inspection is conducted at any Branch or currency chest.

The Branch Head must inform about commencement of RBI Inspection to Inspection
Department, CO on the same day.

In case of penalty levied by RBI( with permission from RM ) investigation to be


ordered and report to be submitted to CO within 10 days

Currency Chest Inspection


Regional Office shall conduct Currency Chest Inspection of all the Currency Chest in
the region bi Monthly basis for test checking and half Yearly (during October & April)
for full ( 100%) checking of Currency
The auditor shall conduct audit and submit report on or before 10th of said month of
audit
RACE
 Regional Audit Committee of Executives just like ACE at CO
 Members – Regional Manager, Zonal Audit Head & Other Executives at
regional office.
 Chairman of committee – RM or ZAH whoever is senior.

 Quorum- Min 2 members RM & ZAH


 Convenor – Inspection Department In charge at Regional Office

 RACE shall have oversight and supervision of all audit matters within
jurisdiction and Regional office
 Meeting Schedule – Monthly Once before 15th

 Minutes of meeting to be submitted to Audit Committee of Executive (ACE)


at Central Office within a week of meeting or 25th of the month.
Agenda of RACE Meeting
 Agenda 1 : Description and follow up of last month minutes of RACE meeting s
 Agenda 2 :Compliance level of the latest CO Instructions by Branches and
Regional Office either send by email or letter.
Agenda 3
 FRC pending > 2 months
 ROC submission status and major observation in the ROC
 Short Inspection
 Jewel Inspection
 ATM Cash verification
 IFCOFR Compliance
 Agenda 4 : Revenue Leakage
 Agenda 5 ,6, and 7 : Audit Return , special report, CAF, Currency Chest Audit
etc.
Income Leakage Pendency ( Ref: Inspection Deptt Circular MISC/02/2024-25
Dated 05.04.2024 )

 In case of waiver requests from the borrower, it should be


taken up with concerned verticals immediately and bring to
logical conclusion whether to be waived or to be recovered
within a period of 6 months from the date of detection. In
no case, the recovery or waiver should go beyond 6 months.
THANK YOU

You might also like