There is a category error that many compliance teams make when preparing for reviews: they assume that the documentation sufficient to satisfy an internal audit committee will also satisfy an RBI inspection team. The two audiences have different objectives, different authority, and fundamentally different relationships to the institution. Preparing one kind of evidence pack and presenting it to both creates unnecessary risk during inspections.
Having spent years in compliance departments at regional banks, preparing documentation for both types of scrutiny, the patterns become clear. Internal auditors are ultimately accountable to the board. RBI inspection teams are accountable to the Reserve Bank, and their findings have legal and regulatory consequences that no internal audit can produce. The evidence required to satisfy each reflects that difference.
What Internal Audit Committees Want
An internal audit committee is reviewing your compliance program to assess whether the institution has adequate controls in place and whether those controls are operating effectively. Their question is essentially: are we doing what we said we would do, and does what we said we would do actually address the regulatory requirements?
For this audience, the most persuasive evidence format is a closed-loop record: a regulatory requirement identified, a control mapped to it, evidence that the control was tested or operated during the review period, and a conclusion about its effectiveness. Internal auditors like to see completeness. If you have thirty-five active circulars affecting your operations, they want to see thirty-five items in the compliance register, each with a status. Gaps in the register are more troubling to this audience than gaps in a specific piece of evidence, because gaps in the register suggest that something might have been overlooked entirely.
Internal audit is also more comfortable with management assertions that are supported by process evidence. A statement like "loan disbursement documentation was verified for all accounts opened in Q3" supported by a sample test result and a sign-off from the operations head is acceptable to an internal auditor. They understand that testing all accounts is impractical and they are evaluating whether the sampling methodology is defensible.
What RBI Inspection Teams Look For
RBI's Annual Financial Inspection (AFI) is not a compliance review in the same sense. The examination team is assessing the safety and soundness of the institution and verifying that the bank is conducting its operations in compliance with applicable regulations. The relationship is supervisory, and the inspection team has authority to impose directives, restrictions, and penalties based on their findings.
RBI inspectors are trained to look past process documentation to ask whether the process actually produced correct outcomes. A compliant-looking process record that covers a period where actual errors were occurring will be noticed, because inspectors triangulate: they compare your policy documentation against transaction-level data, against exception reports, and against your own internal audit findings. If your internal audit found a problem and you corrected it, showing the inspector both the problem record and the correction record is generally better than presenting a clean policy document and hoping the underlying data does not surface an anomaly.
RBI inspection teams are particularly attentive to the temporal consistency of evidence. If you produce a policy document dated after the period under review, it does not establish compliance during that period. Timestamped evidence of contemporaneous action is what they need. A policy approved by your board in January 2025 demonstrates your commitment to compliance from January 2025 forward. It says nothing about December 2024.
The Five Components of an Evidence Pack That Works for Both
While the two audiences have different orientations, the underlying structure of credible compliance evidence is similar enough that one well-organized pack can serve both, with appropriate sections for each audience's specific concerns.
The first component is the regulatory citation: the exact circular reference, including the date, circular number (using the RBI notation such as RBI/2025-26/47 or the SEBI notation), and the specific provision being addressed. Vague references to "RBI guidelines on KYC" do not establish which provision you are addressing or which version of the requirement you complied with.
The second component is the change record: what the provision required before this circular and what it requires after. For circulars that amended existing Master Directions, this means showing the previous paragraph text alongside the amended text. This establishes that your compliance team actually identified what changed, not just that a circular arrived.
The third component is the control or policy response: what your institution specifically did to address the changed requirement. This should include any policy document updated, the section that was changed, and the approval record showing when it was approved by the appropriate authority. For operational changes, this component should include the system or process change, the testing record, and the implementation date.
The fourth component is the implementation evidence: transaction-level or operational evidence that the new requirement is being met in practice. For an RBI inspection, this component carries the most weight. A policy document and a process change record without implementation evidence is an incomplete compliance case. Inspectors will pull samples and compare them against the stated requirements. Having your own sample data ready, showing the same comparison, positions your institution as one that has already done the verification.
The fifth component is the audit trail: the timestamp record showing when each step occurred. When was the circular first identified? When was the impact assessment completed? When was the policy updated? When was the operational change made? When was implementation evidence collected? This sequence of timestamps is what allows both internal and external reviewers to assess whether the compliance response was timely and orderly, or whether it was rushed together shortly before a review date.
What Breaks Down in Practice
The most common weakness we see in compliance evidence packs is that they are assembled in preparation for a review rather than built as a natural output of the compliance process. Assembling evidence after the fact produces several structural weaknesses that experienced auditors recognize: gaps in the temporal sequence, inconsistencies between documents prepared at different times by different people, and missing components that would have been automatic if the process had been documented contemporaneously.
A second common weakness is that the regulatory citations are out of date. A bank that updated its KYC policy in response to a 2023 circular and then did not update it again when a 2025 circular made further changes may have a policy that cites a superseded provision number. The policy intent may still be substantially correct, but the citation gap creates an appearance of incomplete monitoring that draws audit scrutiny to the KYC area specifically.
A third weakness is that the evidence components exist in different systems and are not organized into a single retrievable document. The circular is in a shared folder, the policy update is in the document management system, the approval email is in a compliance officer's mailbox, and the sample testing results are in a spreadsheet on someone's desktop. Each piece of evidence exists. Assembling it for presentation during an inspection requires hours that would not be necessary if the pack had been maintained as a unified document from the beginning.
Building the Pack Before You Need It
The principle that makes evidence pack preparation tractable is that the pack should be built during the compliance process, not assembled after it. Every time a circular triggers a compliance response, that response should produce a structured record containing all five components listed above. By the time an inspection is scheduled, the work is already done. The pack exists. The preparation task is to retrieve it, not to rebuild it.
This is a workflow change rather than a technology change, although tooling that structures the workflow helps. The practice is to treat every compliance response as the first step in building an audit record, not as a task to be completed and filed. The difference in effort is modest. The difference in inspection readiness is substantial.
One practical note on the RBI inspection context specifically: inspection teams arrive with a list of regulatory areas they intend to examine, typically shared with the bank in advance. Having evidence packs organized by circular and by regulatory topic, rather than by internal policy area, makes retrieval during the inspection considerably faster. An inspector who asks for evidence of compliance with RBI/2024-25/103 should be able to receive it within minutes, not hours. The organizational structure of your evidence archives is itself an indicator of compliance program maturity.