RBI/DOR/2026-27/__ DOR.HGG.GOV.No.__/xx.xx.xxxx/2026-27 June xx, 2026 Reserve Bank of India (Local Area Banks - Governance) Second Amendment Directions, 2026 The Reserve Bank has issued Reserve Bank of India (Local Area Banks - Governance) Directions, 2025 on November 28, 2025. 2. At present, the regulatory instructions with respect to control / assurance functions like compliance and internal audit are contained in various directions / circulars. With a view to strengthening the governance framework for these functions and to ensure greater clarity, consistency and harmonisation in the instructions pertaining to these functions, it has been decided to review them, and consolidate them under these Directions. 3. Accordingly, in exercise of the powers conferred by Section 35A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India in this regard, the Reserve Bank being satisfied that it is necessary and expedient in the public interest so to do, hereby issues the Directions hereinafter specified. (1) These Directions shall be called the Reserve Bank of India (Local Area Banks - Governance) Second Amendment Directions, 2026. (2) These Directions shall come into effect from January 1, 2027. (3) These Directions shall modify the Reserve Bank of India (Local Area Banks - Governance) Directions, 2025 in the manner as specified hereinafter. (1) In Paragraph 4 of 'Chapter I - Preliminary' of the Directions, the following definition shall be deleted: (1) 'Chairperson' means the Part-time Chairman of the Board of Directors of a bank. (2) In Paragraph 4 of 'Chapter I - Preliminary' of the Directions, the following definitions shall be inserted: (1a) 'Assurance' means those activities which provide independent confirmation and confidence to the Board or its committees on the compliance of business functions with the internal control environment, as well as the applicable laws, rules and regulations. (1b) 'Chairperson' means the Part-time Chairman of the Board of Directors of a bank. (3a) 'Compliance' means the state of being in accordance with the applicable laws, regulations, rules, directions issued by the Reserve Bank, self-regulatory organisation standards, codes of conduct applicable to a bank's activities and with the internal control systems laid down to comply with the foregoing. (3b) 'Compliance Culture' means the set of values, attitudes, and behaviours that are promoted and demonstrated throughout the organisation ensuring that adherence to laws, regulations, internal standards, and ethical norms is routinely prioritised and embedded throughout the organisation's operations and decision-making. (3c) 'Compliance Function' means policies, processes, procedures, systems and personnel dedicated for Compliance. (3d) 'Compliance Risk' means the risk of legal or regulatory sanctions, material financial loss, or loss to reputation a bank may suffer as a result of its failure to comply with laws of the land, regulations, rules, directions given by Reserve Bank, related self-regulatory organization standards, and codes of conduct applicable to its activities. (3e) 'Control Functions' mean those functions that have a responsibility independent from business functions to provide objective assessment, reporting and/or assurance. This includes the Risk Management Function, the Compliance Function and the Internal Audit Function. (5a) 'Internal Audit Function' means an activity that provides independent assurance to the Board or its committees on the quality and effectiveness of bank's internal control, risk management and governance systems and processes. (5b) 'Internal Audit Plan' means the document that defines the scope, coverage, areas, frequency, etc. of the internal audit. (5c) 'Internal Controls' means a set of rules and controls governing a bank's organisational/ operational structure, including reporting processes and functions. (3) A new chapter viz. Chapter-VI(A) on 'Control Functions: Compliance and Internal Audit' stands inserted after Chapter (VI), with the following contents: Chapter-VI(A) Control Functions: Compliance and Internal Audit A. General 23A. A bank shall establish Compliance and Internal Audit functions, commensurate with its size, complexity and risk / business profile, headed by a Chief Compliance Officer (CCO) and Head of Internal Audit (HIA), respectively. 23B. The bank shall have policies for Compliance and Internal Audit Functions, clearly articulating the objectives, roles and responsibilities of each function. The said policies shall be approved by the Board and reviewed periodically. 23C. The above functions shall: (1) have the necessary authority and autonomy to discharge their responsibilities effectively. (2) be independent of the business lines, free from conflicts of interest or business targets. Accordingly, they shall neither be involved in revenue generation nor have the remuneration of their staff linked to the business area being overseen. (3) have unrestricted access to all business areas and records. (4) not be outsourced, being core activities. However, external experts may be engaged under the oversight of CCO/HIA for specialised tasks without diluting the accountability of the functions. 23D. As part of the overall corporate governance framework, the Board is responsible for overseeing the control functions. The Board must set the 'tone at the top' and ensure that these functions are adequately resourced and maintain their independence. Further, the Board or ACB, shall review control functions on an ongoing basis to ensure their continued relevance and effectiveness. 23E. The Compliance Function shall be subject to regular internal audit. B. Terms of appointment of the CCO / HIA 23F. The terms of appointment of the CCO / HIA would be as follows: (1) Appointing Authority and Rank: A bank shall appoint / designate suitably senior employees, not more than three levels below the MD&CEO, as CCO and HIA with the approval of the Board. (2) Knowledge / Experience: CCO and HIA shall possess adequate domain knowledge and relevant experience in the respective fields, commensurate with the size, complexity, and risk profile of the bank. (3) Age: The age limits for CCO and HIA to hold office may be prescribed by a bank as part of its internal policy. (4) Tenure: CCO and HIA shall ordinarily be appointed for a fixed tenure of not less than three years. (5) Premature transfer / removal: Any transfer or removal of CCO and HIA prior to the completion of the stipulated tenure shall be subject to the approval of the Board. (6) External Hiring: If considered necessary, suitably experienced and competent external candidates may be hired as CCO or HIA. However, consultants, advisors, part time auditors or individuals who are neither on the rolls of the bank nor have any contractual employer-employee relationship with the bank shall not be appointed/designated as CCO or HIA. C. Independence of the CCO and HIA 23G. CCO and HIA shall function with independence, objectivity and free from conflict of interest. In particular, CCO and HIA shall: (1) functionally report to the Board or ACB and administratively report to MD&CEO. (2) not be assigned business targets or have their remuneration linked to the performance of any business line. (3) meet the Board or ACB at least once in a quarter, without the presence of the Senior Management (including the MD&CEO / WTD). Even otherwise, they shall have direct and unrestricted access to the Board or ACB to enable them to communicate concerns without any management interference. (4) have their final performance review carried out by the Board or ACB. D. Compliance Function 23H. The Board shall ensure an effective oversight over the bank's compliance risk. 23I. The Senior Management shall be responsible for effective management of the bank's compliance risk, including communication of the compliance policy throughout the bank and ensuring that it is observed in letter and spirit. Further, Senior Management shall be responsible for embedding compliance in the business strategy while ensuring risk of non-compliance are identified and mitigated, and for promoting compliance culture. Reviews and reporting should be regular and meaningful, with frequency based on the risk profile of the bank. 23J. A bank shall maintain a compliance programme supported by an annual compliance risk assessment placed before the Board or ACB. The Compliance Function shall monitor and test compliance by inter-alia performing sufficient and representative compliance testing. 23K. The Compliance Function shall: (1) ensure adherence to statutory and regulatory requirements, fair customer treatment, and sound market conduct. The CCO shall be the nodal point of contact between the bank and RBI. (2) proactively identify, assess, and manage compliance risks, and provide independent assurance to the Board or ACB on the effectiveness of compliance policies, controls, and remediation of breaches, to be in state of compliance and for the improvement in compliance culture. (3) vet internal policies and communications, act as a reference point for regulatory interpretation, and coordinate with other control / assurance functions such as Internal Audit, while maintaining its independence. E. Internal Audit Function 23L. The Board shall ensure an effective internal audit framework, proportionate to the bank's risk profile with adequate resources and independence. Staff posted to the Internal Audit Function should ordinarily have a tenure of at least three years. 23M. The Senior Management shall be responsible for ensuring effectiveness of the Internal Audit Function. It must facilitate the independence of audit, provide full access and act promptly on audit findings. The Senior Management shall ensure that internal auditors have sufficient knowledge and training appropriate to the entity's risks. 23N. The Internal Audit Function shall provide independent evaluation of governance, risk management, compliance, internal controls, business lines, support functions, outsourced activities, etc., ensuring assurance across the entire organisation. All significant activities shall be audited over a defined cycle (ordinarily not exceeding three years), with high-risk areas reviewed more frequently. 23O. The Internal Audit Function shall: (1) follow systematic methodologies aligned with professional standards, using tools such as data analytics, thematic reviews, and automated monitoring, with proper documentation. (2) coordinate with risk management, compliance, and external auditors while retaining independent judgment, ensuring clear distinction of responsibilities. (Scenta Joy) Chief General Manager |