Can NBFCs “outsource” internal audit functions to external auditors? 

– Anshika Agarwal (finserv@vinodkothari.com)

The Reserve Bank of India (RBI) has consistently emphasized the significance of robust internal control systems; where gaps are found by the supervisor, it has penalised  regulated entities for non-compliance. Recently, the RBI imposed a penalty on an NBFC for outsourcing one of its core management functions, i.e., internal audit to an external auditor, thereby raising doubts as to whether internal audit for NBFCs can be conducted by external auditors. Does the very fact that internal audit is being conducted not internally but by an external chartered accountancy firm amount to “outsourcing” of core management function?  This article examines outsourcing in the context of internal audit function,  and the conditions subject to which internal audit may be conducted by external agencies. 

Understanding the concept of ‘Outsourcing’

Outsourcing is defined under the Basel 2005 document1 as “a regulated entity’s use of a third party (either an affiliated entity within a corporate group or an entity that is external to the corporate group) to perform activities on a continuing basis that would normally be undertaken by the regulated entity, now or in the future.” Similarly, the IOSCO Consultation Paper2 refers to outsourcing as “a business practice in which a regulated entity uses a service provider to perform tasks, functions, processes, or activities that could otherwise be undertaken by the regulated entity itself.

NBFCs, especially those with asset-light models or limited resources, opt for outsourcing to manage financial as well as non-financial functions. Outsourcing by NBFCs typically involves delegating tasks such as loan application processing, collection of documents, data processing, IT support, customer service, and back-office operations to third-party providers. While outsourcing boosts operational efficiency, they also carry risks, particularly when core management functions are outsourced. Notably, outsourcing is distinct from availing professional services like legal, audit, consulting, or property management, which are ancillary to the NBFC’s core business. In case of outsourcing of financial functions by regulated entities, there are specific guidelines issued by the RBI to regulate the arrangements. Clear regulatory oversight is crucial to strike a balance between leveraging external expertise and maintaining ethical, efficient practices in the financial services sector.

Regulatory Framework: The RBI’s Perspective

The RBI guidelines are specifically aimed at managing risks related to outsourcing of financial services. Master Direction – Reserve Bank of India (Non-Banking Financial Company – Scale Based Regulation) Directions, 2023 (‘SBR Directions’)3, particularly Annexure 13 on Instructions on Managing Risks and Code of Conduct in Outsourcing of Financial Services by NBFCs (‘Outsourcing Guidelines’), Para 2 lays down stringent conditions for outsourcing to ensure compliance, accountability, and effective risk management. While outsourcing can support operational efficiency, core management functions must remain under the direct control of the regulated entity.

Core Management Functions: Non-Negotiable Responsibilities 

The Outsourcing Guidelines explicitly prohibits NBFCs from outsourcing core management functions vital to governance, decision-making, and risk management. The core management functions are those that are vital and crucial for the existence as well as operations of the entity. These have been defined to include:

These functions are critical for ensuring the organization’s stability and operational integrity. For example, internal audit functions identify risks, ensure regulatory compliance, and assess control effectiveness. Entrusting such functions to external entities could compromise decision-making and erode organizational trust.

Contractual Engagement for Internal Audit

While the internal audit function itself is a core management process, the Outsourcing Guidelines in the same lines allows regulated entities to engage internal auditors on a contractual basis. This means external professionals can be brought in to execute internal audits, provided their engagement adheres to regulatory standards, independence is maintained, and the entity retains oversight and control rather than putting all the responsibility on a third party. 

For example, an entity may handle several operational tasks related to an audit, such as preparing documentation, organizing records, or conducting initial reviews. However, the ultimate responsibility for decision-making, oversight, and ensuring compliance with regulations rests with the audit committee or the entity’s senior management. This approach ensures that the internal management retains control over key aspects of the audit process, even while delegating specific tasks or availing expertise support. In contrast, the action of outsourcing shifts the entire responsibility for the audit to a third-party. This means the external firm is accountable for managing and executing all aspects of the audit, from operational tasks to final implementation. Such an outsourcing may reduce the internal workload, however, it also transfers control and accountability to an external entity, which may not align entirely with the entity’s internal objectives and strategic priorities. 

In other words, what is permitted is to avail the expertise services of a third party for carrying out the internal audit function but not the transfer of the entire responsibility of carrying out internal audit to a third party.

ICAI Standards: Expertise and Independence in Internal Audits

The Institute of Chartered Accountants of India (ICAI) Standards on Internal Audit4 states that “Where the Internal Auditor lacks certain expertise, he shall procure the required skills either though in-house experts or through the services of an outside expert, provided independence is not compromised”. 

The aforesaid guidance from the ICAI emphasizes maintaining expertise and independence. While not explicitly addressing outsourcing, these standards recognize that internal auditors may lack certain specialized skills. In such scenarios, they encourage engaging in-house or external experts while safeguarding independence.

The standards indirectly allow for outsourcing when:

  • Specific expertise is unavailable in-house,
  • Independence remains uncompromised

By availing the services of experts ensures that internal audit teams possess the necessary skills to perform effective reviews, while the entity retains oversight and accountability.

Companies Act, 2013: Flexibility in Internal Audit Assignments

Section 138 of the Companies Act, 2013 (‘CA 2013’)5, specifies the requirement for internal audits for certain classes of companies. It allows the appointment of internal auditors, which may include chartered accountants, cost accountants, or other professionals, as decided by the Board. Explanation of Rule 13 of the Companies (Accounts) Rules, 2014, states that “the internal auditor may or may not be an employee of the company”.

The aforesaid provision also enables companies to engage external auditors to perform internal audits, even if they are not part of the organization. While the CA 2013 does not explicitly prohibit outsourcing of internal audit functions, it places the ultimate responsibility for conducting and reporting on internal audits with the Board. This also clarifies that companies may utilize external expertise while maintaining oversight and control of the audit process.

Conclusion

In conclusion, the RBI’s recent penalties underscore the importance for regulated entities to maintain strict compliance with outsourcing regulations, particularly regarding core management functions. While the Outsourcing Guidelines as well as the provisions of CA 2013 permit engaging external auditors on a contractual basis to perform operational tasks related to audits, accountability and strategic control such as having audit plan approved by the audit committee, regular reporting to the audit committee, discussion of the board and audit committee on the conduct of audit,implementing remedial measure on the oversight of the audit committee or senior management must remain firmly within the organization. Adherence to these principles will help maintain the fine distinction between outsourcing the internal audit function and appointing external auditors as internal auditors, specifically in the context of internal audits.

Read our other related resources –

  1. UNDERSTANDING THE CONCEPT OF OUTSOURCING- ENVISAGING A TOUGH ROAD AHEAD FOR THE SERVICE PROVIDERS
  2. Draft framework for Financial Services Outsourcing

  1.   https://www.bis.org/publ/joint12.pdf (last accessed in November 2024) ↩︎
  2.   https://www.iosco.org/library/pubdocs/pdf/IOSCOPD654.pdf (last accessed in November 2024) ↩︎
  3.  Reserve Bank of India, Master Direction – Scale Based Regulation (SBR): A Revised Regulatory Framework for NBFCs, October 22, 2021. Available at: https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12550 ↩︎
  4.  Institute of Chartered Accountants of India, Standard on Internal Audit (SIA) 2: Basic Principles Governing Internal Audit. Available at: https://resource.cdn.icai.org/52727iasb-basicprinciples-3.pdf ↩︎
  5.  The Companies Act, 2013, Ministry of Corporate Affairs, Government of India. Available at: https://www.mca.gov.in/. ↩︎

Shastrartha 13 – DPDP Rules for Lenders

In this edition of Shastrath, we address key concerns and considerations for lenders in light of the Draft DPDP Rules published on January 03, 2025, and discuss steps to take in order to ensure readiness and compliance. 


Register your interest here: https://docs.google.com/forms/d/e/1FAIpQLSf0uZidJDf8oqK0GfGygo0BmuCKRg9wMo2bXRtwRMIra7Zx5Q/viewform

Credit Information Reporting: Actionables under the New Directions

– Anshika Agarwal (finserv@vinodkothari.com)

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download as PDF [170.48 KB]

Disclosures in Financial Statements: Role of CS

Read our other resources:

Disclosure in financial statements: Relationship with struck off companies

Changes in Auditors’ Report and Financial Statements to reveal camouflaged financial transactions

MCA introduces a cartload of additional disclosures in the Financial Statements

Secretarial auditors for listed entities: FAQs on disqualifications and prohibited services

Team Corplaw | Corplaw@vinodkothari.com

Updated as on 25th April, 2025

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download as PDF [435.76 KB]


Refer our related resources

Secretarial auditors for listed entities: FAQs on disqualifications and prohibited services

SEBI’s Implementation Circular for several LODR Amendments

Read our other resources:

  1. Presentation on LODR 3rd Amendment Regulations, 2024
  2. The Load of LODR: Listing regulations become more prescriptive
  3. Webinar: Online workshop on SEBI LODR 3rd Amendment Regulations 2024
  4. Youtube video: Position of Compliance Officer: Analysing ‘one level below the board’
  5. Perched at the Peak: Compliance Officer as CXO

LODR Resource Centre

Presentation on Small Companies

Read our other resources:

  1. Definition of Small Company
  2. Do NBFCs qualify as Small Companies?
  3. Abridged Annual Return for Small Companies

SEBI approves cartload of amendments 

– Team Corplaw | corplaw@vinodkothari.com

SEBI in its Board meeting dated December 18, 2024, has approved amendments pertaining to BRSR, HVDLEs, DTs, SMEs, Intermediaries, etc.  This article gives a brief overview of the approved amendments.

Ease of Doing Business for BRSR

  • Scope of BRSR Core for Value Chain Partners shrunk
    • Value chain partners now consist of individuals comprising 2% or more of the listed entity’s purchases and sales (by value) instead of 75% of listed entity’s purchases/sales (by value).
    • Further, the listed entity may limit disclosure of value chain to cover 75% of its purchases and sales (by value), respectively.
  • Deferred applicability of ESG disclosures for the value chain partners & its limited assurance by one financial year
    • Applicability of ESG disclosures for the value chain deferred from FY 24-25 to FY 25-26.
    • Applicability of limited assurance deferred from FY 25-26 to FY 26-27.
  • Voluntary disclosure of ESG disclosures for the value chain partners & its limited assurance instead of comply-or-explain
    • Top 250 listed entities by market cap can now comply with the ESG disclosures for the value chain partners & its limited assurance on a voluntary basis in place of  comply-or-explain.
  • Term ‘Assurance’ replaced with ‘assessment or assurance’ to prevent unwarranted association with a particular profession (specifically audit profession).
    • Assessment defined as third-party assessment undertaken as per standards to be developed by the Industry Standards Forum (ISF) in consultation with SEBI. 
  • Reporting of previous year numbers voluntary in case of first year of reporting of ESG disclosures for value chain.
  • Addition of disclosure pertaining to green credits as a leadership indicator under Principle 6 – Businesses should respect and make efforts to protect and restore the environment of BRSR

Immediate actionables for Listed entities:

  • Entity to re-assess its value chain partners as per the revised definition.
  • Entity forming part of top 250 listed entities by market cap to undertake third party assessment of its BRSR Core disclosure for FY 24-25 as per the standards to be developed by ISF.
  • To disclose about the green credits procured/generated by the entity during FY 24-25.

Debenture Trustee (‘DT’) Regulations:

  • Introduction of provisions relating to ‘Rights of DTs exercisable to aid in the performance of their duties, obligations, roles and responsibilities’, which broadly indicates (as proposed in the CP):
    • Calling information/ documents from issuer w.r.t. the issuance;
    • Calling documents from various intermediaries;
    • Calling of and utilization of Recovery Expense Fund, with consent of holders.
  • Corresponding obligations on the issuers to submit necessary information/documents to DTs.

VKCo comments: In addition to the corresponding obligations on the issuer, CP also proposed to mandate Depositories and Stock exchanges to provide requisite information to DTs, which is yet to be approved. The right to call information from issuers and market participants including corresponding obligations on them will enable DTs to perform their functions efficiently.

  • Introduction of standardized format of the Debenture Trust Deed (‘DTD’)
    • To be issued by Industry Standards Forum with SEBI consultation;
    • In case of deviation from the format of DTD, disclosure is to be made for investor review. (CP proposed to disclose deviation as insertion of a key summary sheet of deviation in GID/KID)

VKCo comments: While the introduction of model DTD is appreciated, the draft model DTD proposed in the CP was not aligned with the general market practices followed by the DTs as well as the applicable laws such as SEBI Listing Regulations, NCS Regulations, Indian Trust Act, etc.

  • Activity-based Regulation for DTs:
    • DTs are to undertake only such activities regulated by other financial sector regulators/ authorities (as SEBI specifies);
    • Hive off non-regulated activities to a separate entity – within 2 years;
    • Sharing of resources between DT and hived-off entity is allowed, subject to segregation of legal liabilities;
    • Hived-off entity can use DT’s brand/logo – only for a period of 2 years (CP suggested 1 year); Both DT and hived-off entity to abide by SEBI’s code of conduct during such period.

Applicability of CG norms on HVDLEs 

Under this segment of changes discussed by SEBI, most of the proposals are in alignment with the Consultation Paper dated 31st October, 2024, except for few changes in relation with PSUs coming together with public enterprises under Public Private Partnership.

  • Threshold for being identified as HVDLE increased from 500 Crores to 1,000 Crores to align with the criteria of Large Corporates

VKCo Comments: The proposal to enhance the extant threshold is encouraging in terms of governing the maximum value of outstanding debt while at the same time achieving the same without bearing the burden of compliance by an increased number of purely debt listed entities. Subsequently, effective implementation of such a proposal aligns it with the identification criteria of Large Corporates. 

  • Introduction of a separate chapter for entities having only debt listed, and sunset clause for applicability of CG norms

VKCO Comments: While this proposal is noteworthy, however, instead of rolling out a new chapter, there could have been certain modifications in the existing regulations by way of a proviso to align with the needs of an HVDLE. Further, one also needs to wait to see the fine print -of the provisions once the same is issued.

VKCo Comments: The proposal is welcome since it clearly sets the HVDLEs free from the barrier of once an HVDLE so always an HVDLE. This proposal sets a clear nexus between the compliance and the size of the debt outstanding, for the protection of which in the very first place, the compliance triggered.

  • Optional constitution of RMC, NRC, and SRC and delegation of their functions to the AC and Board respectively.

VKCo Comments: Given the close construct of debt listed entities, it is often observed that the constitution of such committees becomes more of a hardship than in smoothing compliance and discussing specific matters. Accordingly, it looks appropriate to redirect the functions of NRC and RMC to the Audit Committee and that of the SRC to the Board.

  • HVDLEs to be included in the counting of maximum no. of directorships, memberships and chairmanships of committees. However, this shall exclude directorships arising out of ex-officio position by virtue of statute or applicable contractual framework in case of PSUs and entities set up under the Public Private Partnership (PPP) mode respectively, in the count. The said exclusion was not in the CP.

VKCo Comments: The rationale completely aligns with the proposal made and seems to be justified. Further, as far as the exclusion is concerned, this seems more from excluding those members who are part of the board not on the basis of their appointment but their current tenure being served in a particular position in the company.

  • RPT Approval by way of NOC from DT (who obtains it from holders), before going for shareholders’ approval [w.e.f. 1st April, 2025]

VKCo Comments – While the CP suggested two ways of seeking approval for material RPTs of an HVDLE. The Board has only considered the alternative mode of first seeking NOC of DT and thereafter approaching the shareholders. Further, as discussed in our related write up on the CP, there does not seem to be any incentive to first approach the DT and thereafter the DT to approach the NCD holders. Instead the approval of the NCD holders can be taken up directly by the HVDLE. 

  • Submission of BRSR on a voluntary basis

VKCo Comments: The inclusion of a voluntary provision in the legislation with respect to a comprehensive report like BRSR is not likely to be submitted given the huge details under the BRSR. However, an opportunity to submit BRSR can be a game changer for an HVDLE from the perspective of being able to raise funds based on its reporting standards in this regard. 

One of the changes discussed by the Board is relaxation to HVDLEs set up under the PPP mode from composition requirements of directors. While this was not a part of the CP, however, even if we have to understand that change proposed, this looks like relaxing the composition requirement of the Board of Directors. 

CHANGES NOT APPROVED: 

  • Compulsory filing of CG compliance report in XBRL format

VKCo Comments: This proposal was with an objective to align and standardize the filing of quarterly CG compliance report for bringing parity as in the case of equity listed entities 

  • Exemption to entities not being a Company

VKCo Comments: While SEBI refers to the introduction of similar exclusion for equity listed entities, however, it has also mentioned the subsequent amendment wherein the same was omitted. The proposal not being notified is in alignment with the position of equity listed entities, however, the same would have been a welcome change since it would have helped such entities to give preference to their principal statutes and not an ancillary one like LODR. 

Our detailed write up on the CP can be accessed here.

Amendments in the definition of UPSI – making the law more prescriptive

  • Inclusion of 17 items in definition of UPSI: The illustrative list of USPI in reg. 2 (1) (n) of the PIT Regulations has been expanded to include 17 items from the list of material events laid out in Part A of Schedule III of the Listing Regulations [Originally proposed in the CP – 13 items] 
  • Threshold limits under reg. 30 made applicable: materiality thresholds specified in reg. 30 (4) (i) (c) of the Listing Regulations have been made applicable for identification of events as UPSI 
    • As per the current practice, any event that is likely to materially affect the price of the securities can be identified as UPSI 
  • Extended timelines for making entries in SDD: for an event of UPSI that emanates outside the company, entries can be made in the SDD within 2 days of occurrence. Further closure of the trading window will not be mandatory in such cases. 
    • This has been introduced as a part of EODB
    • As per the current practice entries in the SDD have to be made promptly

Refer to our discussion on CP in: Laundry List: SEBI’s proposal to elongate list of deemed UPSIs