AUDITMIND / REGULATORY LEARNING LAB

Understand the NBFC framework through an audit lens.

We have converted the supplied regulatory reference material into an original educational view: classify the entity, determine applicability, map prudential and governance requirements, and then design evidence-led audit checks.

4-layer viewBase · Middle · Upper · Targeted
6+control domains
3audit questions
01 / Regulatory architecture

Layering changes the control intensity.

The reference describes four supervisory layers. Most smaller NBFCs generally sit in the Base Layer, while scale, systemic significance and functional classification can lead to stronger supervision.

01 / BL

Base Layer

Foundation-level supervision for smaller or lower-complexity entities, subject to the applicable category.

Baseline controls
02 / ML

Middle Layer

Enhanced prudential, governance and risk-management expectations for entities in this layer.

Enhanced oversight
03 / UL

Upper Layer

More intensive supervision for entities with greater systemic significance.

Heightened supervision
04 / TL

Targeted Layer

A risk-driven layer for specific entities where systemic risk may materially increase.

Risk escalation
02 / Applicability

Before testing a rule, determine whether it applies.

The reference material uses factors such as customer interface, public funds, functional category and supervisory layer to shape applicability. For audit, the classification itself becomes a control point.

Control domainBase / no PFBase / with PFMiddleAudit question
KYCContext-basedDoes the business model support the stated applicability?
Capital adequacyContext-basedIs the capital calculation aligned to the applicable layer?
ProvisioningContext-basedDoes classification flow correctly into provisioning?
Asset classificationContext-basedDoes system logic match the required status at day-end?
GovernanceContext-basedDo committees and compliance ownership work in practice?
Information reportingContext-basedIs the reporting population complete and timely?
03 / Audit analytics

Six domains where regulation becomes data-backed testing.

01 / PRUDENTIAL

Exposure & concentration

Compare actual aggregate exposures with internal and regulatory concentration limits.

  • single borrower / party
  • single group
  • consumer-credit segments
02 / IRAC

SMA / NPA logic

Trace due dates, day-end processing and upgrade logic through system and account data.

  • due-date population
  • day-end snapshot
  • arrears and upgrade trail
03 / GOVERNANCE

Compliance function

Assess independence, seniority, reporting lines and evidence of escalation for relevant layers.

  • CCO structure
  • committee minutes
  • risk escalation
04 / REPORTING

Regulatory submissions

Build completeness and timeliness tests around major reporting obligations described in the reference.

  • FIU-IND / CKYC
  • credit information
  • periodic and event reporting
05 / DISCLOSURE

Risk signals in disclosures

Use disclosures as a second source of audit evidence rather than treating them as presentation-only.

  • related parties
  • complaints
  • covenant / classification signals
06 / RISK

Risk committee evidence

Evaluate whether risk identification, measurement, monitoring and board reporting are demonstrable.

  • risk profile
  • measurement systems
  • liquidity risk

Turn regulation into better audit questions.

The analytical approach is: classify → determine applicability → map the control → identify evidence → test the population → assess exceptions → conclude.

ClassifyApplicabilityControl mapData testEvidenceFinding
Reference basis

This educational module is an original analytical interpretation of the user-provided Crash Course on NBFCs — Overview of Regulatory Framework. It reorganises concepts for learning and audit use rather than reproducing the source presentation. Always check the current applicable regulatory text before relying on a requirement.