Banking

What risk-based internal audit actually changes

Not "audit everything less". A different question about where to look first — and a different argument to have with your board.

2026-08-05

Most cooperative banks already do internal audit. Branches get inspected, findings get raised, reports get filed. So when someone says "move to risk-based internal audit", the reasonable first reaction is that this is a naming exercise.

It isn't. RBIA changes one specific thing, and everything else follows from it.

The old question and the new one

A traditional inspection cycle asks: have we covered every branch this year?

RBIA asks: which branches deserve our attention first, and can we defend that answer?

That sounds like a small shift. It is not, because the second question forces you to hold a written, versioned opinion about every auditable unit — before you visit it. You have to say, in advance and on the record, that Branch A is riskier than Branch B, and be able to show the working.

Where the two risks come from

The rating that matters is a combination of two things that come from completely different places.

Business risk is what the branch does. Deposit and advance mix, NPA movement, exposure concentration, growth rate, the kind of lending it writes. This comes out of the core banking system. Nobody visits a branch to discover it.

Control risk is how well the branch runs itself. Documentation completeness, KYC currency, register maintenance, adherence to sanction terms. This is what the inspection actually produces, and it comes back as marks against a checklist.

Cross the two and you get the rating. A branch with a modest book and terrible controls is a different problem from a branch with a large book and clean controls, and an annual cycle that visits both equally treats them as if they were the same.

The part that catches people out

Higher marks mean higher risk, not better performance.

Almost every checklist people are used to works the other way — score more, do better. In control-risk scoring, a mark is a deficiency found. A branch scoring 26 out of 426 is in better shape than one scoring 180.

We have watched experienced auditors read a scoring screen backwards on first contact. It is worth saying out loud in every training session.

What the bank has to own

This is the part that decides whether an RBIA programme survives its first audit committee meeting.

The weights, the bands, the matrix and the audit frequency table are policy decisions belonging to the bank. They are not vendor defaults and they are not something a system should quietly choose.

If a regulator asks why a branch was rated High, the answer cannot be "that is what the software said". It has to be: here is the policy the risk committee approved, here is the version that was live on the rating date, here is the evidence, and here is the person who confirmed it.

Which means a workable RBIA system needs three things that are easy to overlook:

  • Versioned policy. Every rating binds to the policy version in force on the date it was calculated, not the version in force today.
  • Override with a reason. Head Office must be able to move a rating, and that movement must carry a name, a timestamp and a written justification.
  • Findings that persist. An irregularity that was open at the last visit should arrive at the next one already on the page. A finding that quietly disappears between cycles is worse than one never raised.

Where software genuinely helps, and where it does not

It helps with the mechanical part: pulling business-risk inputs from the core system, scoring a 400-mark checklist without arithmetic errors, carrying findings forward, generating the same report in English and Malayalam, and keeping a trail that survives someone reading it two years later.

It does not help with judgement. Whether a particular control weakness in a particular branch is material is an audit opinion, and it belongs to a person who can be asked to defend it.

That distinction is not modesty. A system that publishes a final risk rating on its own has taken a decision the bank is accountable for and given it to a vendor. No audit committee should accept that, and no vendor should offer it.

The honest summary

RBIA is not a way to do less audit. It is a way to be able to answer the question "why there, and why now?" with something better than "it was their turn."

Everything else — the checklists, the matrix, the dashboards — is machinery in service of being able to answer that one question, in front of people who are entitled to ask it.

All resources