Base Layer
Foundation-level supervision for smaller or lower-complexity entities, subject to the applicable category.
Baseline controlsWe have converted the supplied regulatory reference material into an original educational view: classify the entity, determine applicability, map prudential and governance requirements, and then design evidence-led audit checks.
The reference describes four supervisory layers. Most smaller NBFCs generally sit in the Base Layer, while scale, systemic significance and functional classification can lead to stronger supervision.
Foundation-level supervision for smaller or lower-complexity entities, subject to the applicable category.
Baseline controlsEnhanced prudential, governance and risk-management expectations for entities in this layer.
Enhanced oversightMore intensive supervision for entities with greater systemic significance.
Heightened supervisionA risk-driven layer for specific entities where systemic risk may materially increase.
Risk escalationThe reference material uses factors such as customer interface, public funds, functional category and supervisory layer to shape applicability. For audit, the classification itself becomes a control point.
| Control domain | Base / no PF | Base / with PF | Middle | Audit question |
|---|---|---|---|---|
| KYC | Context-based | ✓ | ✓ | Does the business model support the stated applicability? |
| Capital adequacy | Context-based | ✓ | ✓ | Is the capital calculation aligned to the applicable layer? |
| Provisioning | Context-based | ✓ | ✓ | Does classification flow correctly into provisioning? |
| Asset classification | Context-based | ✓ | ✓ | Does system logic match the required status at day-end? |
| Governance | Context-based | ✓ | ✓ | Do committees and compliance ownership work in practice? |
| Information reporting | Context-based | ✓ | ✓ | Is the reporting population complete and timely? |
Compare actual aggregate exposures with internal and regulatory concentration limits.
Trace due dates, day-end processing and upgrade logic through system and account data.
Assess independence, seniority, reporting lines and evidence of escalation for relevant layers.
Build completeness and timeliness tests around major reporting obligations described in the reference.
Use disclosures as a second source of audit evidence rather than treating them as presentation-only.
Evaluate whether risk identification, measurement, monitoring and board reporting are demonstrable.
The analytical approach is: classify → determine applicability → map the control → identify evidence → test the population → assess exceptions → conclude.
This educational module is an original analytical interpretation of the user-provided Crash Course on NBFCs — Overview of Regulatory Framework. It reorganises concepts for learning and audit use rather than reproducing the source presentation. Always check the current applicable regulatory text before relying on a requirement.