Audit

Concurrent Audit of Banks: Objectives, Scope and Practical Approach

Concurrent audit of banks is a near real-time control review that helps detect irregularities early, strengthen branch discipline, and improve follow-up on risk-sensitive transactions. This guide explains the RBI framework, practical scope, reporting approach, ICAI ethics points, and examples relevant to Indian CA and finance professionals.

Concurrent Audit of Banks: Objectives, Scope and Practical Approach

Concurrent audit of banks is not a year-end exercise. In the RBI’s framework for scheduled commercial banks, it is a near-contemporaneous examination of transactions and controls so that irregularities are identified quickly, corrected early, and escalated before they become larger operational or fraud issues.

For scheduled commercial banks other than regional rural banks, an important RBI source is its July 16, 2015 circular revising the concurrent audit system in commercial banks. RBI describes concurrent audit as an examination carried out at the time of the transaction or as close to it as possible, with more emphasis on substantive checking in key areas than on sample-based post-facto review. RBI also makes an important boundary clear: the concurrent auditor is not expected to second-guess a branch manager’s commercial decision, but to examine whether the transaction stays within delegated authority, internal policy, and regulatory instructions.

Why concurrent audit matters in banking

Banking errors become expensive very quickly. A documentation gap in a working capital account, a control failure in treasury, a dormant account activated without proper review, or an exception in foreign exchange processing can create immediate financial, compliance, or fraud risk. Concurrent audit matters because it shortens the time between transaction execution and independent examination.

That is why RBI treats the system as part of a bank’s early-warning framework. The practical value is not only detection. A well-run concurrent audit also improves branch discipline, exception handling, escalation quality, and follow-up by controlling offices.

Where banks typically apply concurrent audit

Under the RBI’s 2015 revised guidelines, branch selection is risk-based. High-risk branches are to be subjected to concurrent audit irrespective of business size. RBI also indicates coverage for specialised and operationally sensitive units such as large corporate and SME branches, centralised processing units, treasury and foreign exchange units, data centres, critical head office departments, and other areas that the bank considers suitable for concurrent audit.

A change-sensitive point that was verified from the RBI circular: for branch coverage, concurrent audit should cover at least 50% of a bank’s advances and 50% of its deposits. The same circular also allows banks to exclude some lower-risk areas where risk has reduced because of computerisation or core banking controls.

What a concurrent auditor is expected to examine

RBI’s minimum programme in Annex II is broad. In practice, the engagement usually combines transaction checking, control validation, exception review, and immediate reporting in the following areas:

  • Cash and ATM operations: cash verification, custody, unusual receipts and payments, and related control discipline.
  • Clearing and remittances: reconciliations, uncleared effects, and operational exceptions in movement of funds.
  • Deposits and customer operations: account opening controls, KYC or AML process adherence, inoperative or dormant accounts, quick account closures, and unusual patterns.
  • Loans and advances: sanction compliance, documentation, charge creation, post-disbursement monitoring, stock statement based controls, renewal and review discipline, and prudential classification issues.
  • LCs, guarantees, and contingent liabilities: approved formats, margins, commission, and deviations from sanction terms.
  • Treasury and forex: deal controls, confirmations, reconciliations, cancellations, limits, and regulatory compliance in specialised operations.
  • Housekeeping and exception control: suspense entries, unreconciled balances, value-dated entries, unusual vouchers, and ageing open items.

The exact checklist should still be bank-specific. RBI says the detailed scope should be determined uniformly by the bank’s inspection and audit department in consultation with the Audit Committee of the Board.

How the process works in practice

1. Risk-based coverage is approved by the bank

The bank decides which branches, units, and activities come under concurrent audit. In a mature setup, that decision is linked to risk-based internal audit results, fraud-prone operations, business concentration, and operational centralisation.

2. The auditor checks transactions close to occurrence

The work is designed to be contemporaneous. The objective is to identify breaches while the transaction trail is fresh and corrective action is still meaningful.

3. Minor issues are corrected quickly; serious issues are escalated

RBI’s reporting design is practical. Minor irregularities are meant to be rectified on the spot. Serious irregularities should be reported immediately to controlling or head office. Where fraudulent transactions are detected, the RBI circular requires immediate reporting to the inspection and audit department at head office and to the chief vigilance officer, apart from the concerned branch manager unless the branch manager is involved.

4. Reporting does not end with the branch note

RBI expects structured reporting, prompt follow-up, a quarterly review of important features before the Audit Committee of the Board, and an annual review of the effectiveness of the concurrent audit system.

Concurrent audit is not the same as internal audit or statutory branch audit

AspectConcurrent auditInternal auditStatutory branch audit
TimingDuring or soon after transactionsPeriodic, risk-basedTypically linked to year-end financial reporting
Main purposeEarly detection of irregularities and control failuresEvaluate controls, risk management, and processesSupport audit opinion on financial statements and branch reporting
Testing styleFocused, transaction-near, exception-sensitiveBroader process and control reviewFinancial statement and audit-report oriented
Immediate corrective valueHighModerate to highUsually lower for day-to-day operations because it is later in time

If you want a broader refresher on how internal audit differs in objective and process, this explanation of internal audit objectives and practical value is the closest related CA Samaaj resource.

Two examples that remove common confusion

Example 1: Working capital account with delayed stock statements

Assumptions: A branch has sanctioned a cash credit limit of Rs. 2 crore to a trading borrower. Drawing power is supposed to be updated monthly from stock statements. For two months, the system limit continues without updated drawing power support.

What concurrent audit does: It checks whether the branch updated drawing power from current borrower data, whether excess drawings were allowed, whether post-disbursement monitoring conditions were followed, and whether the irregularity was escalated in time.

What concurrent audit does not do: It does not decide whether the borrower deserved the facility in the first place. That commercial judgement belongs to sanctioning authority and credit process. The auditor tests compliance with sanction terms, monitoring discipline, and delegated authority.

Example 2: Dormant account reactivated and high-value outward transfer processed

Assumptions: A savings account with no meaningful activity for a long period is reactivated. Within two days, a high-value transfer is processed after a customer instruction is recorded.

What concurrent audit looks for: whether reactivation controls were followed, whether supporting records and maker-checker steps were complete, whether the transaction pattern was unusual, and whether the branch followed the bank’s KYC or AML monitoring process.

Why this matters: This is exactly the kind of near-real-time exception where a delayed audit can miss the opportunity for immediate containment.

Professional points for CAs accepting bank concurrent audit work

ICAI has a change-sensitive clarification that is directly relevant to practice. In its April 9, 2023 announcement on acceptance of certain assignments by the concurrent auditor of bank branches, ICAI clarified three points:

  • A concurrent auditor of a bank branch may undertake the LFAR assignment only for branches that are not subject to statutory audit. If the branch is subject to statutory audit, LFAR is to be undertaken by the statutory auditor.
  • A concurrent auditor or internal auditor may issue certifications for a bank branch only when those certificates are addressed to the bank’s management, and not to the statutory auditor, a regulator, or nobody in particular.
  • A concurrent auditor or internal auditor cannot perform the statutory audit of that branch’s financial statements or certify them as audited financial statements.

For practice support, ICAI’s Guidance Note on Audit of Banks (2026 Edition) remains a useful professional reference alongside the RBI framework.

What makes a concurrent audit report useful

The strongest concurrent audit reports do not merely list exceptions. They help the bank act. That usually means each observation identifies the transaction or control point, the breached instruction or condition, the operational or regulatory risk, the immediate corrective step, and whether the issue needs escalation beyond the branch.

A weak report says documentation is incomplete. A useful report says the sanction required insurance renewal before drawdown, the policy exception was not approved, the account remained operative, and the lapse exposes the bank to unsecured risk for the specified period.

Practical checklist for engagement planning

  • Identify whether the unit is branch-based, centralised, treasury, forex, or another specialised operation.
  • Obtain the bank’s current scope note, reporting format, escalation matrix, and product-specific circulars.
  • Map high-risk transactions first instead of spreading time evenly across low-value items.
  • Check whether system controls and manual controls both operate as designed.
  • Separate spot rectification points from matters requiring immediate escalation.
  • Document unresolved exceptions, repeat observations, and ageing action points clearly.
  • Confirm engagement boundaries before accepting overlapping assignments such as LFAR or certifications.

Bottom line

Concurrent audit of banks is best understood as a control mechanism that sits close to live operations. Its value lies in timing as much as in technical accuracy. For Indian banks, the RBI framework makes it risk-based, broad enough to cover specialised units and centralised operations, and closely tied to reporting and follow-up. For CAs, the real skill is not only spotting exceptions but understanding which exceptions matter immediately, how they should be framed, and where professional independence ends.

Related Articles

Subscribe To Our Newsletter

Subscribe us to get updates on latest Jobs Openings, News, Articles, Notices/ Circulars

Submit

© 2026 CA Samaaj. All rights reserved.

Join Whatsapp Group of CA Samaaj