No sector in Nepal is audited as continuously, or from as many directions, as banking and finance. A manufacturing company might see its auditor once a year. A bank sees its internal auditors monthly, its external auditor annually, its IT systems reviewed on a recurring cycle, and its financial position reported to the regulator every quarter — all while its loan book is being reclassified in real time against strict provisioning rules. Understanding bank audit requirements in Nepal under BAFIA means understanding that a bank audit is never really "one audit." It's a standing system of overlapping checks, and this post walks through each layer.
Legal Basis: BAFIA 2073 and Nepal Rastra Bank Directives
The Bank and Financial Institutions Act, 2073 (2017) — universally known as BAFIA — is the primary legislation governing all licensed banks and financial institutions in Nepal, from commercial banks down to microfinance institutions. Chapter 9 of BAFIA, covering Sections 58 through 68, is dedicated specifically to accounts, records, and auditing: it establishes the requirement for an audit committee (Section 60), sets out that committee's functions and powers (Section 61), governs the auditing process itself (Section 62), and covers auditor appointment, remuneration, eligibility, and duties (Sections 63–68). BAFIA works alongside the Nepal Rastra Bank Act, 2058, which establishes NRB as the central regulator, and NRB's own Unified Directives, which are reissued periodically and go well beyond BAFIA's baseline requirements — covering capital adequacy, loan classification and provisioning, corporate governance, and reporting in far greater operational detail than the Act itself.
External Statutory Audit — Plus NRB-Specific Disclosures
Every bank and financial institution must undergo an annual external audit, and the auditor must be registered on Nepal Rastra Bank's approved panel — not every ICAN-licensed Chartered Accountant is automatically eligible to audit a licensed BFI. But the audit itself goes well beyond a standard company audit opinion. NRB requires banks to submit a Long Form Audit Report (LFAR) alongside the standard financial statement audit, in which the auditor is required to specifically assess and comment on compliance with the Nepal Rastra Bank Act, BAFIA, and NRB's directives across a detailed checklist — covering matters such as board and CEO remuneration compliance, profit appropriation to statutory reserves, exchange fluctuation reserve treatment, dividend distribution rules, and whether the bank has engaged in any activity prohibited under BAFIA. Commercial banks are generally required to submit their audited financial statements within six months of the fiscal year-end, and larger institutions handling high transaction volumes may also be subject to concurrent audit requirements imposed directly by NRB.
Internal Audit — A Mandatory, Board-Level Function
Unlike most companies, where internal audit is optional or informal, BAFIA and NRB treat internal audit as a mandatory, structural part of a bank's governance. Section 61 of BAFIA sets out the audit committee's functions and powers, which include reviewing internal audit findings and directing follow-up action. In practice, this means a bank's internal audit department conducts ongoing, risk-based reviews — of accounts, budgets, working procedures, compliance with laws and regulations, internal controls, and corporate governance — and reports those findings to the Audit Committee, which in turn escalates significant matters to the full Board of Directors. NRB's own supervisory reports have flagged instances where audit committees fail to give internal audit departments adequate direction or staffing, which the regulator treats as a serious governance weakness given how central this internal function is meant to be to a bank's overall control environment.
IT / Information System Audits — Mandatory for Core Banking Systems
Because banking today runs on core banking systems, mobile banking platforms, and payment infrastructure, NRB treats information system (IS) security as an audit matter in its own right, separate from the financial statement audit. NRB's IT Policy and Guidelines require regular IS audits of licensed banks and financial institutions to verify system security and integrity, with annual risk assessments expected as a baseline and external audits recommended where in-house technical capacity is limited. BAFIA reinforces this obligation for the sector, and in practice, banks are expected to align their IT control environment with recognized international frameworks such as ISO 27001 and, where card payments are involved, PCI-DSS. An IS audit examines access controls, system change management, data backup and recovery, and cybersecurity controls — areas a traditional financial audit typically does not cover in depth.
Quarterly Unaudited Financial Reporting to NRB
Between annual audits, banks and financial institutions are required to prepare and disclose unaudited quarterly financial statements to Nepal Rastra Bank and, for listed banks, to the investing public through NEPSE disclosures. This quarterly cadence gives the regulator a much closer, more frequent view of a bank's financial position than the once-a-year audit cycle alone would allow, and it means that any deterioration in asset quality, profitability, or capital adequacy tends to surface well before the annual audited statements are finalized. While these quarterly figures are unaudited, they are still expected to be prepared on a consistent basis with the bank's accounting policies and are subject to internal audit and management review before submission.
Asset Classification and Loan Loss Provisioning — A Core Audit Focus Area
If there's one area where bank audits diverge most sharply from ordinary company audits, it's loan classification and provisioning. NRB's Unified Directives require banks to classify every loan into one of five categories based on how overdue repayment is, and to hold a minimum loan loss provision against each category:
Pass (up to 1 month overdue) — minimum 1% provision.
Watchlist (1–3 months overdue) — minimum 5% provision.
Substandard (3–6 months overdue) — minimum 25% provision.
Doubtful (6 months to 1 year overdue) — minimum 50% provision.
Loss (more than 1 year overdue) — 100% provision.
Auditors pay close attention to this area for a specific reason: correctly classifying a loan can materially change a bank's reported profit, and NRB has, in recent supervisory reviews, flagged banks for keeping stressed loans in a better classification category than their actual repayment history justifies — a practice that understates provisioning and overstates reported earnings. Both the external auditor and NRB's own supervision teams treat classification accuracy, and the adequacy of the resulting provisions, as one of the highest-risk areas of a bank audit.
Auditor Rotation and NRB Approval of External Auditors
Unlike a typical private company, a bank cannot simply hire any licensed Chartered Accountant as its statutory auditor. The auditor must be registered on Nepal Rastra Bank's approved panel of bank auditors, and under BAFIA, the audit committee is required to recommend a list of three eligible auditors to the Annual General Meeting for shareholder approval, rather than presenting a single name — a practice intended to preserve some separation between management's preferences and the final appointment decision. NRB's own supervisory reports have noted cases where banks recommended only one auditor instead of the required three, treating this as a compliance lapse. Certain individuals are also explicitly ineligible to serve as a bank's auditor under BAFIA, including anyone with a close relationship to the bank's management, reinforcing the same independence principle that runs through the rest of BAFIA's audit provisions.
Conclusion
Bank audit in Nepal isn't a single annual event — it's a year-round system layered across external audit, internal audit, IT security review, quarterly regulatory reporting, and constant loan portfolio monitoring, all anchored in BAFIA and reinforced by NRB's Unified Directives. For directors, audit committee members, and finance teams inside a bank or financial institution, staying ahead of each layer — rather than treating the annual audit as the only checkpoint — is what keeps a BFI genuinely compliant rather than just paper-compliant.
If your institution needs a clearer picture of where its current audit and compliance program has gaps, it's worth reviewing each of these layers individually with your Chartered Accountant or compliance team.
Disclaimer: This article is for general information only and does not constitute legal or tax advice. Tax rules and their application can vary based on individual circumstances. Please consult an ICAN-registered Chartered Accountant before making any decisions related to bank audit or regulatory compliance.
Discussion