With NBFCs now operating across co-lending arrangements, digital lending partnerships and embedded finance tie-ups, how has the definition of what needs to be audited expanded beyond a single institution’s own books?
The scope of audit for NBFCs has significantly expanded. In respect of risk based internal audit to which they are subjected to, this assumes greater significance since the risks are now tied not only to the activities but also to the partners and the digital apps used by the NBFC. If the credit decision is outsourced, there is a need to review the decision-making algorithms periodically to ensure that the output is in line with the agreed approach on ongoing basis. Regulators are clear that the decisions are owned by the lender and cannot delegate this to an app. Therefore, there is an additional responsibility to prove to Board and regulator on an ongoing basis, especially in organisation where sanctions are centralised.
Concurrent audit for NBFCs is meant to happen monthly or quarterly, verifying loan disbursements and documentation in near real time. Why has real-time or near-real-time audit become non-negotiable for fast-growing NBFCs in a way it wasn’t a decade ago?
The term concurrent itself means simultaneous and hence real time. The expectation of a concurrent audit is to prevent non compliances in near real time. In the current scenario, the difference between a regular audit and concurrent audit is the frequency and scope. In terms of scope concurrent audit covers 100% of transactions whereas regular audit covers a sample.
In terms of time, concurrent audit verifies either on the next day or next week whereas the regular audit can take much longer time extending up to 12 months. However, both are still verified after the transaction is complete. It is a definite need that concurrent audit verifies on a real time basis. However, the current model of concurrent audit which involves engaging external Chartered Accountants is not fully serving the purpose. I believe that this activity should be insourced by all the organisations to make it effective. This will increase the cost but is good in the long run.
For NBFCs operating in priority sector lending, how does the audit process differ, and what unique verification challenges does that lending mandate create?
The definition of priority sector is clear and there is no ambiguity. However, the nature of evidence to establish that a loan confirms the decision becomes important. Banks are fairly used to this since they have been lending to priority sector for more than five decades. For NBFC, there will be a learning curve and more, so when they lend through partnership. The documentation to be collected from the partners plays a significant role in this.
BaaS SuperWise is built specifically for regulators. What gap did you see in how regulators currently supervise the shadow banking sector that made a dedicated regulator-facing product necessary?
BaaS® SuperWise is meant for regulators/quasi regulators who supervise any regulated entity. Mostly these are annual inspections. Normally an auditor certifies noncompliance and what is not reported is assumed to be compliant. BaaS® SuperWise ensures that the inspector certifies compliance as well. This ensures that the scope is covered to the full extent. The scope can be enlarged based on the evolving regulations.
We believe that every regulator needs to be equipped with a system that helps them to see the performance of a regulated entity across years to understand the trend, repetitive noncompliance, eliminate erroneous compliance.
Where do you see the biggest gap today between how fast shadow banks are scaling their loan books and how fast their audit and compliance infrastructure is maturing?
There is a tendency for all managements to allocate budgets for technology spend towards customer-facing and business-oriented activities. Hence, internet banking, digital lending apps, eKYC get the attention they deserve. However, they are not so eager to spend on technology for Backoffice activities, audit and operational risk. There is a need for a change in the mindset of senior management in defining their priorities so that back-office systems also get priority in their budgets.
The current method of Return on Investment (RoI) approach to assessment of technology proposals outlived its utility. When it comes to systems relating to risks, the benefits are more qualitative than quantitative. If you take Term Insurance, there may not be any return, yet it is needed.
Managements should also acquire skills to assess the value a software brings to the table so that their focus does not get limited to cost.
