2026-07-31
Added · Updated
These Directions prescribe the governance, structure, and operational requirements for the Compliance function of Local Area Banks. They mandate the establishment of an independent Compliance Department headed by a Chief Compliance Officer, with specific reporting lines to the Board and Audit Committee. The regulations require annual compliance risk assessments, quarterly Board reviews, and the implementation of a comprehensive Compliance programme to manage regulatory and statutory adherence.
RBI published 33 documents in the last 30 days — get each new one by email the day it lands.
Search the Website
( 968 kb ) Reserve Bank of India (Local Area Banks - Compliance Function) Directions, 2026
RBI/DoS/2026-27/444 DoS.CO.PPG.38/11.01.005/2026-27
July 31, 2026 Reserve Bank of India (Local Area Banks - Compliance Function) Directions, 2026 Introduction Compliance function is a key element of a bank’s corporate governance framework and an integral part of assurance, alongside internal audit and risk management processes. The principles governing the Compliance function are aligned with the Basel Committee on Banking Supervision framework, adapted to the Indian operating environment, and extend to bank-led Financial Conglomerates for managing group-wide compliance risk. While minimum standards are prescribed, the bank shall organise its Compliance function and prioritise compliance risk management in a manner commensurate with its size, complexity, risk profile, and organisational structure. In exercise of the powers conferred by Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues Directions hereinafter specified. Chapter I - Preliminary A. Short Title and Commencement 1. These Directions shall be called the Reserve Bank of India (Local Area Banks - Compliance Function) Directions, 2026. 2. These Directions shall come into effect immediately upon issuance. B. Applicability 3. These Directions shall be applicable to Local Area Banks (hereinafter collectively referred to as 'banks' and individually as 'bank'). C. Definitions 4. In these Directions, unless the context states otherwise, the terms herein shall bear the meaning assigned to them below: (1) ‘Compliance Risk’ shall mean the risk of legal or regulatory sanctions, material financial loss, or loss to reputation a bank may suffer as a result of its failure to comply with laws, regulations, rules, related self-regulatory organisation standards, and codes of conduct applicable to its banking activities (together, ‘compliance laws, rules, and standards’). 5. All other expressions unless defined herein shall have the same meaning as have been assigned to them under the Reserve Bank of India Act, 1934, the Banking Regulation Act, 1949, the Companies Act, 2013, or any statutory modification or re-enactment thereto or other regulations issued by RBI or the Glossary of Terms published by RBI or as used in commercial parlance, as the case may be. Chapter II - Governance and Oversight A. Role of the Board 6. The Board shall have an overall responsible for the effective oversight and management of the bank’s Compliance function and compliance risk. 7. The Board shall ensure that the bank has an appropriate Compliance Policy in place and shall oversee its effective implementation. The Board shall review the policy at least annually. 8. The Board shall ensure that compliance issues are resolved effectively and expeditiously by senior management with the assistance of compliance staff. If necessary, the Board may delegate these tasks to the Audit Committee of the
Board (ACB). 9. The Board or ACB shall review the Compliance function on a quarterly basis. A detailed annual review should also be placed before the Board / ACB. The Chief Compliance Officer (CCO) should be an invitee to such meetings. 10. The Board shall ensure that the Compliance function and the Internal Audit function of the bank are kept separate. B. Role of the Senior Management 11. The Managing Director and Chief Executive Officer (MD & CEO) shall ensure the presence of an independent Compliance function and adherence to the compliance policy of the bank. 12. The senior management shall establish a written Compliance policy which should contain the basic principles to be followed by the management and staff and explain the process by which compliance risk shall be identified and managed through all levels of the bank. 13. The senior management shall ensure that appropriate remedial or disciplinary action is taken if breaches are identified. 14. Senior management shall, with the assistance of the Compliance Function: (1) identify and assess, at least annually, the main compliance risks facing the bank and formulate the plans to manage them; (2) submit to the Board / ACB, as the case may be, quarterly and annual reviews as prescribed at paragraph 9, in such a manner as to assist the Board members to make an informed judgment on whether the bank is managing its compliance risk effectively; and (3) report promptly any material compliance failure (e.g., failure that may attract a significant risk of legal or regulatory sanctions, material financial loss, or loss to reputation) to the Board / ACB and take appropriate remedial measures. C. Compliance Policy 15. The Board-approved Compliance policy of the bank should clearly spell out its compliance philosophy, expectations on compliance culture covering tone from the top, accountability, incentive structure, effective communication and challenges thereof, structure and role of the Compliance function, authority, and role of the CCO, processes for identifying, assessing, monitoring, managing, and reporting on compliance risk throughout the bank. 16. The Compliance policy shall, inter alia, adequately consider the size, complexity, and compliance risk profile of the bank, expectations on ensuring compliance to all applicable statutory provisions, rules, and regulations, various codes of conduct (including the voluntary ones) and the bank’s own internal rules, policies and procedures, and a disincentive structure for compliance breaches. The policy should emphasise building up compliance culture, vetting of the quality of reports provided to RBI by the bank. 17. The policy should cover the following aspects: (1) Establishment of an independent Compliance Department at the Head Office headed by the CCO with adequate support staff and its role and responsibilities specified. (2) Compliance units in controlling offices and branches specifying the role and responsibility of each functionary within such
compliance units. (3) Measures to ensure independence of the Compliance function. (4) Focus of the Compliance function on ensuring compliance with regulatory and statutory requirements, fair practice codes, and other codes prescribed / suggested by self-regulatory organisations, government policies, bank's internal policies, and requirements relating to the prevention of money laundering and funding of illegal activities. (5) Monitoring mechanism for the compliance testing procedure. (6) Reporting requirements including inter alia reporting of monitoring results, compliance risk assessment and change in the compliance risk profile, by the Compliance function to the senior management and the Board / ACB, as the case may be. (7) Right of the Compliance function to have access to information necessary to carry out its responsibilities and for pointing out / looking into possible breaches of Compliance policy. (8) Relationship between CCO and heads of other functional departments. (9) Independence of the Compliance function from Internal Audit function and clarity on their respective roles. (10) Mechanism for dissemination of information on regulatory directions and guidelines among operational staff and periodic updating of operational manuals to incorporate changes in regulatory, legal and other applicable requirements. (11) Approval process for all new processes and products by the Compliance Department prior to their introduction. (12) Right of the Compliance function to freely disclose its findings and views to senior management, Board / ACB, as the case may be. Chapter III - Scope, Structure and Responsibilities A. Scope 18. The Compliance function shall ensure adherence with applicable statutory and regulatory requirements as well as applicable codes, of Self-Regulatory Organisations. B. Group-wide Compliance 19. A group or enterprise-wide compliance programme shall assist senior management and the Board in understanding the concentration, level, and evolution of legal and reputational risks and in identifying control processes requiring enhancement. The Compliance function shall ensure that controls and procedures capture the appropriate information to allow senior management and the Board to better perform their Risk Management functions on a group-wide basis. Explanation: A Group is defined as parent and its subsidiaries (as defined in AS-21). However, the bank is also encouraged to promote a similar compliance culture across its associates and joint ventures (as defined in AS-23 and AS-27 respectively). C. Structure 20. Depending on its branch network, size and complexity of the business operations, and sophistication of products and services offered, the bank shall decide on the organisational structure and composition of its Compliance unit. The bank may, however, lay down the structure within the overall framework of these Directions and should avoid all potential conflicts of interest. Regardless of how the Compliance function is
organized within the bank, it should be independent and sufficiently resourced, its responsibilities should be clearly specified, and its activities should be subject to periodic and independent review. 21. The bank shall set up a Compliance Department at the Head Office of the bank. The CCO shall head the Compliance Department, with the overall responsibility of coordinating the identification and management of the bank's compliance risk and supervising the activities of other Compliance function staff. 22. In case of large banks, Compliance function staff may be located within operating business lines. 23. Each Department in the Head Office, controlling offices, the branches, and / or Strategic Business Units shall have distinct Compliance function, and the functions should be undertaken by specifically identified / designated compliance official/s who would report to the CCO. 24. The staff in the Compliance Department at the Head Office, controlling offices, and branches / Strategic Business Units shall primarily focus on compliance functions. However, in small sized banks with limited branch network, the compliance staff may be assigned other duties while ensuring that there is no conflict of interest. Under no circumstances, the compliance staff should be assigned audit / inspection duty to avoid conflict of interest in view of the fact that all products and processes are expected to be cleared by the Compliance Department, and its audit needs to be carried out independently by a separate set of staff. 25. Depending on the business model, size, structure of the bank, entire compliance responsibilities may not be carried out by the Compliance Department and may be vested in different departments. For Compliance function staff in independent support units (e.g., legal, financial control, risk management), a separate reporting line from staff in these units to the CCO may not be necessary. However, these units / departments shall co-operate closely with the CCO and there should invariably be an appropriate mechanism for co-ordination among these departments to enable the CCO to perform the assigned responsibilities effectively. 26. Compliance function staff in operating business units or in local subsidiaries may have a reporting line to operating business unit management or local management, but they should also have a reporting line through to the CCO for their compliance responsibilities. 27. The remuneration of the Compliance functionaries shall not be related to the business line for which they exercise Compliance responsibilities though it could generally be related to the financial performance of the bank as a whole. D. Staffing 28. The bank shall provide adequate staff to the Compliance Department to ensure that the compliance units discharge their functions without human resource constraints. The bank shall put in place appropriate succession planning to ensure that the post of compliance officer(s) does not remain vacant. 29. Apart
from the basic qualifications, the compliance staff should preferably have fair knowledge of law, accountancy, and information technology and also adequate practical experience in various business lines and audit / inspection functions to enable them to carry out their duties effectively. In order to keep the compliance staff up-to-date with developments in the areas of banking laws, rules, and standards, regular and systematic education and training in new products and services introduced in the banking industry as well as in the areas of corporate governance, risk management, and supervisory practices may be considered. E. Roles and Responsibilities 30. The Compliance Department at the Head Office shall play the central role in identifying the level of compliance risk in each business line, product, and process, issue instructions to operational functionaries and formulate proposals for mitigation of such risk. It shall periodically circulate the instances of compliance failures among staff along with preventive instructions. 31. The responsibilities of the Compliance function shall be carried out under a Compliance programme that sets out its planned activities. The Compliance programme shall be risk-based and subject to oversight by the CCO to ensure appropriate coverage across businesses and co-ordination among Risk Management functions. The bank shall implement a comprehensive Compliance plan replete with Compliance testing and review structures. 32. Inspection / audit findings should serve as a feedback mechanism for the Compliance Department for assessing the areas of compliance breaches / failures. A checklist on the compliance aspect may be made part of the inspection report for the inspectors / concurrent auditors to verify the level of compliance. 33. Compliance function shall vet the guidelines / circulars issued by the bank, for compliance with regulatory guidelines before these are disseminated amongst the operational units. It shall also incorporate a robust mechanism to ensure that regulatory guidelines / instructions are promptly issued / disseminated within the bank and also monitor compliance with them. 34. The Compliance Department shall serve as a reference point for the bank's staff from operational departments for seeking clarifications / interpretations of various regulatory and statutory guidelines. 35. The Compliance function shall on a pro-active basis identify, document, assess the compliance risks associated with the bank's business activities and products. The compliance risks in all new products and processes should be thoroughly analysed and appropriate risk mitigants by way of necessary checks and balances should be put in place before launching. The bank shall subject all new products to intensive monitoring for the first six months of introduction to ensure that the indicative parameters of compliance risk are adequately monitored. 36. The bank shall develop function-wise compliance manuals duly approved by the
CCO if their operating manuals do not already contain specific sections or chapters on compliance and provide these to the staff associated with the respective functions. 37. The Compliance Department shall, at frequent intervals, interact with Legal Department, Operational Risk Management Department, Taxation Department, and Audit / Inspection Department of the bank to take stock of the latest developments. The bank should provide Compliance officers with access to all information they require and the right to conduct investigation and report the findings to the CCO. 38. The bank shall ensure should be close co-ordination and partnership between Compliance and Business Operations functions. The interaction may be formalised by making the CCO a member of the various inter-departmental committees in the bank. 39. The Compliance function shall monitor and test compliance by performing sufficient and representative compliance testing, and the results of such compliance testing shall be placed before the Board / ACB / MD & CEO. 40. The Compliance function shall also consider ways to measure compliance risk (e.g., by using performance indicators) and use such measurements to enhance compliance risk assessment. 41. The Compliance function shall empower the Compliance staff to conduct compliance reviews / investigations, whenever required. The authority to use external experts for the purpose of investigation, if required, should be left to the discretion of the CCO. 42. The bank shall ensure that the Compliance function is free to report to senior management on any irregularities without fear of disfavour from management or other staff members. The Compliance function should also have the right of direct access to the Board or the ACB, as the case may be, bypassing normal reporting lines. 43. Non-compliance with any regulatory guidelines and administrative actions initiated against the bank and / or corrective steps taken to avoid recurrence of the lapses should be disclosed in the annual report of the bank. 44. The code of conduct for employees should envisage working towards earning the trust of the society by dealing with customers in a fair manner and conducting business operations consistent with rules and regulations. Due weightage may be given to record of compliance during performance appraisal of staff at various levels. The bank shall examine staff accountability for all compliance failures. 45. Compliance function shall ensure full compliance with all specified guidelines enlisted in the templates oriented towards Compliance assessment under the Risk-Based Supervision (RBS) framework. Since the regulatory guidelines forming part of such template are neither exhaustive nor static and are expected to be updated on an annual basis, the bank shall, therefore, strive to put in place an exhaustive Compliance framework encompassing all guidelines emanating from RBI, identify potential breaches and remedy them up-front. 46. Compliance units shall
specifically devise a time-bound strategy to ensure that compliance with Monitorable Action Plan (MAP) / Risk Mitigation Plan (RMP) prescribed pursuant to the Annual Financial Inspection / Risk Based Supervision process is achieved within the time frame. The bank shall comply with all MAP / RMP points well before the commencement of the subsequent supervisory cycle and / or within the periods prescribed for fulfilling the requirements of MAP / RMP. 47. The Compliance function may have specific statutory responsibilities (e.g., fulfilling the role of anti-money laundering officer). The bank shall carry out an annual compliance risk assessment in order to identify and assess major compliance risks faced by it and prepare a plan to manage the risks. The Annual Review shall cover the following aspects: (1) Compliance failures, if any, during the preceding year and consequential losses and regulatory action as also steps taken to avoid recurrence of the same. (2) List of all major regulatory guidelines issued during the preceding year, and steps taken by the bank to ensure compliance. (3) Independence of Compliance function. (4) Scope of compliance procedures and processes. (5) System of internal control to minimise compliance risk. (6) Compliance with fair practices codes and adherence to standards set by self-regulatory organisations and accounting standards. (7) Progress in rectification of significant deficiencies pointed out by the Internal audit, Statutory audit, and RBI inspection reports and position of implementation of recommendations made therein. (8) Strategy for the next year including restructuring of Compliance Department, if necessary, and posting / transfer / training of staff. 48. Apart from the exhaustive annual review, a monthly report on the position of compliance risk may be put up to the senior management / MD & CEO. 49. The Compliance function shall advise and assist the senior management on compliance laws, rules, and standards, including keeping them informed on developments by establishing written guidance to staff on the appropriate implementation of compliance laws, rules, and standards through policies and procedures and other documents such as compliance manuals, internal codes of conduct, and practice guidelines. 50. The Compliance function shall also attend to the compliance of directions from other regulators (including Insurance Regulatory & Development Authority of India and Securities and Exchange Board of India) in those cases where the activities of the bank are not limited to the banking sector. For example, a bank which is acting as a corporate agent for distribution of other companies’ insurance products may receive direction from Insurance Regulatory & Development Authority of India, which should be a part of the Compliance function. The Compliance function shall bring to the notice of RBI, any discomfort conveyed to the bank on any issue by other regulators. 51. A bank with business across various
jurisdictions shall ensure that it complies with applicable laws and regulations in all such jurisdictions and that the bank, its Compliance function structure, and its responsibilities are consistent with local legal and regulatory requirements. It is for local business units to ensure that compliance responsibilities specific to each jurisdiction are carried out by the individuals with appropriate local knowledge and expertise, with oversight from the CCO in co-operation with the bank’s other risk management functions. F. Compliance Culture 52. For the Compliance function to be effective, it must be supported by a healthy Compliance culture within the bank. It is important that the need to comply with instructions meticulously is periodically re-iterated to all the staff in the bank through continuous and mandatory training on compliance aspects, and appropriate disciplinary measures through staff accountability framework / policies for non-compliance. Compliance should not be viewed as a responsibility of the Compliance Department alone but as a culture that should pervade across the bank. G. Quality Assurance and Internal Audit 53. The bank shall develop and maintain a quality assurance and improvement program covering all aspects of the Compliance function. The quality assurance and improvement program shall be subject to independent external review periodically (at least once in three years). 54. The Compliance function shall be subject to Internal Audit. The Internal audit function should keep the CCO informed of audit findings related to Compliance. Compliance risk shall be included in the risk assessment methodology of the Internal Audit function, and the audit programme shall cover the adequacy and effectiveness of the bank's Compliance function including testing of controls commensurate with the perceived level of risk. Chapter IV - Chief Compliance Officer
Top
Back to previous page
Read the rest free
Source: Reserve Bank of India — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from RBI
RBI published 33 documents in the last 30 days. We email you each new one the day it's published.