Back to All Posts

Supervision of Commercial Banks in India: RBI’s Supervisory Framework and Risk Management

Supervision of Commercial Banks in India: RBI’s Supervisory Framework and Risk Management

                     Banking supervision refers to the monitoring of the activities of regulated entities to ascertain conformity with applicable laws and regulations as well as to promote sound financial and risk-management practices.

                     The sources indicate that the RBI supervises commercial banks in India as well as the overseas branches of Indian banks in accordance with the relevant provisions of the Banking Regulation Act, 1949. They further identify the Department of Supervision (DoS) as the supervisory authority responsible for regulating entities under the oversight of the Reserve Bank.

Risk-Based Supervision (RBS)

                     August 2011, the RBI established a High Level Steering Committee under the Chairmanship of former Deputy Governor of the RBI, Dr. K.C. Chakrabarty, to examine the supervisory process of commercial banks.

                    The committee suggested moving from the current compliance based approach and transaction testing approach to the risk based supervision (RBS). As per the recommendations of this committee, the RBI started implementation of RBS in a phased manner from the supervisory cycle of 2013.

                    As per risk based supervision, the supervisory focus depends upon the risks, their nature, level and significance faced by the bank. Rather than concentrating on whether each rule has been complied with or not, risk based supervision tries to find out the significant risks, vulnerability and weakness of risk management system of the bank so that the supervisory actions could be undertaken at appropriate time.

                   Risk based supervision replaced the previous CAMELs based supervisory approach for scheduled commercial banks by the RBI. Compliance is very much integral part of the supervisory process, although it does not replace the compliance assessment.



Tools of Supervision

 

On-Site Supervision

                    On-site inspection refers to the inspection of a bank at the bank premises itself to review the activities of the bank, its recordkeeping systems, and the financial condition of the bank. The extent and area of the inspection can vary according to the requirements of supervision.

                    The supervision of the bank entails the review of the bank’s books, controls, risk management activities, and compliance with the regulation. This would help to ascertain the condition of the assets and advances and detect any weaknesses or irregularities in the functioning of the bank.


Off-Site Supervision

                    Off-site supervision enables the regulator to supervise the activities of the bank at a distance based on the financial returns and other regulatory information received periodically from the bank. This process will help the supervisory authority to make an initial assessment of the risk profile of the bank and pinpoint certain critical issues which deserve further investigation. These might include the strategies adopted by the bank, structure of the group, financial results of the bank, compliance record, internal audit plans and reports, and external auditor's comments.

                     The Off-site Monitoring and Surveillance System (OSMOS) is an additional technique to on-site supervision. This will aid in gathering and analyzing the regulatory information received from banks at various frequencies like fortnightly, monthly, quarterly, half yearly and annually.

                     In simple words, off-site supervision can be described as the supervision of banks without visiting their premises through the information provided by the banks.


Para-Supervisory Activities

                     Para-supervision is an essential component of supervisory activities and serves as a tool to supervise the banks and detect any risks. Some of the para-supervision activities include fraud detection, cyber security supervision, early warning indicators, stress testing, RFA and PCA regime.

                    The activities mentioned above assist the supervisor in identifying weak areas, detecting the risks that may occur and taking supervisory action, where required. Para-supervision is an integral part of the core supervision process and assists in identifying risks at an early stage.

Central Fraud Registry (CFR) : 

                    Frauds can lead to monetary loss, weak internal control, and loss of confidence in the banking sector. Early detection assists in containing monetary losses and preventing recurrence of such frauds.

                    The Central Fraud Registry (CFR) was made functional from 20 January 2016 which is a searchable centralized repository of fraud information. It assists the banks in detecting the signs of such frauds and using the information to manage fraud risks and implement necessary preventive actions.

                     the present scenario, the banks are also expected to submit any such fraud cases to RBI through the prescribed reporting system. The RBI has its own Central Payments Fraud Information Registry (CPFIR) for any fraud cases concerning payment systems.

Cybersecurity Framework : 

                     The banking industry relies immensely on information technology in carrying out various transactions and other operations such as customer services, data management, and payments. The vulnerability of the bank to attacks such as cybercrimes, fraud, data breach, and other problems is caused by weaknesses in IT and cybersecurity measures.

                     To counter these growing cyber threats, the Board for Financial Supervision (BFS) has asked the RBI to have an extensive supervisory knowledge of the IT systems of the banks. This led to the formation of an Expert Panel on Cyber Security and IT Examination along with the Cyber Security and IT Examination Cell (CSITE Cell) at the RBI in June 2015 and On the basis of the recommendations of this panel, the RBI came up with the “Cyber Security Framework in Banks” on 2 June 2016.

Early Warning Systems and Indicators : 

                      Early warning indicators assist in recognizing financial risks before they evolve into more serious issues. From a systemic perspective, some indicators include credit-to-GDP ratios and economy-wide debt service indicators that assist in recognizing the accumulation of systemic risk. Individually, supervision functions such as stress testing, capital planning, asset quality review, and liquidity management assist in recognizing the financial and risk status of an individual bank. This early recognition allows banks and supervisors to evaluate and rectify any identified weaknesses before they evolve into serious financial problems.

 Prompt Corrective Action Framework

                      The Prompt Corrective Action (PCA) framework is designed so as to enable prompt supervisory intervention in response to significant weaknesses in a bank’s key financial or supervisory parameters. Thresholds of risk are specified which signal the need for specific supervisory actions to address the problem. These actions are expected to restore the Bank’s financial position to a satisfactory level, and require it to take corrective steps.

                      The framework addresses capital, asset quality and profitability closely and other financial or supervisory indicators may also be considered in taking supervisory action. In accordance with the nature of the weakness, the RBI may impose mandatory or discretionary corrective actions.

                      These actions can take the form of special supervisory meetings, strengthening of business and risk-management practices, engagement with the bank’s board, conservation of capital, enhancement of loan-review processes, restriction of selected risk-taking activities, reviews of staff-training needs, and restrictions on certain capital expenditures and expansion of branches.

                      The PCA framework does not preclude the RBI from taking other supervisory actions in its regulatory powers. The framework aims at addressing financial weaknesses at an early stage and ensuring that corrective measures are taken before the situation deteriorates further.

Stress Testing : 

                      Stress testing is a tool for evaluating the impact of financial and economic shocks on a bank or portfolio of investments. The crisis that erupted in the global financial system in 2007-09 has demonstrated the significance of stress testing as a risk management tool and a supervisory function.

                      The RBI issued guidelines on stress testing in December 2013 specifying that stress testing by banks using the shocks as a minimum was mandatory. The banks were also required to evolve stress-testing programs commensurate with the complexity and sophistication of their operations.

                       It can help bankers evaluate the impact of a downturn in the economy, impaired assets, liquidity crunch, interest rates, and other factors. They can also aid in identifying the weakness, estimating the losses, and preparing for future financial strains.

Red Flagged Accounts : 

                      The concept of RFA was brought out in 2015 as part of an early-warning mechanism framework for early detection and prevention of financial fraud. A Red Flagged Account refers to the account where one or more Early Warning Signals (EWS) are detected which make the bank suspicious about the fraud being committed on the account. It is through these signals that the bank becomes aware of its investigation and preventive action needs to be taken regarding the same.

                      In the earlier framework, detection and red flagging of accounts with exposures of ₹50 crore and above was mentioned. It was the past criterion and should not be taken as the present requirement. As per the RBI Fraud Risk Management Directions presently, there is a need for the appropriate framework of EWS and Red Flagging of Accounts for early detection and prevention of frauds.



In Short 

                       Banking supervision not only ensures that banks are fit and proper to operate as per laid down rules, but also a continuing process of risk identification, evaluation of the business and financial soundness of banks and taking corrective measures in a timely manner. By using risk based supervision, on-site and off-site supervision and para supervisory tools like fraud vigilance, cyber security, early warning indicators, stress testing, RFA and PCA, the RBI tries to detect emerging vulnerabilities at an early stage and take remedial action. The combined effect of these supervisory measures helps individual banks as well as the banking system as a whole to build resilience.