August 24, 2026

NFRA Audit Quality: Why India Needs Better Metrics Before More Powers

0
NFRA held a review meeting with key officials in New Delhi recently.

NFRA held a review meeting with key officials in New Delhi recently. (Image NFRA on X)

Spread love

By P. SESH KUMAR

NFRA has strengthened remediation and boardroom oversight, but its small inspection samples and lack of an aggregate quality series make it difficult to tell whether audit quality is actually improving.

New Delhi, August 20, 2026 — India’s National Financial Reporting Authority (NFRA) is becoming a more powerful audit regulator, but a fundamental question remains unanswered: is audit quality in India actually improving? Unlike the US Public Company Accounting Oversight Board (PCAOB), NFRA does not yet publish a consistent aggregate series that allows audit quality to be tracked across firms and inspection cycles. Its reports provide detailed findings, but the small number of engagements reviewed makes meaningful deficiency rates difficult to calculate. At the same time, NFRA’s procedures remain under judicial scrutiny even as Parliament considers giving the regulator wider rule-making, enforcement and quasi-judicial powers. The result is an institutional paradox: India is strengthening the regulator before fully resolving how its performance should be measured and how its powers should be exercised.

The National Financial Reporting Authority (NFRA) has been running audit quality inspections at least since 2022, and its findings, read chronologically, tell a different story from the PCAOB’s. The first cycle, published in December 2023, covered BSR & Co, Deloitte Haskins & Sells, S R B C & Co and Price Waterhouse Chartered Accountants. Its most striking observations were not about evidence at all.

NFRA found BSR’s claim to be independent of KPMG India entities unacceptable and noted that the firm had not furnished details of its leadership structure, network entities, or non-audit services provided by those entities to the firm’s audit clients. It found that PwC’s own voluntary restriction on non-audit services did not extend to overseas member firms serving overseas holding companies of Indian audit clients. It found that Deloitte Haskins & Sells had, on one engagement, provided a non-audit service amounting to a self-review threat, and that a board contemplated by a networking agreement did not exist.

The March 2026 cycle continued in the same register: findings against two PwC network firms, four KPMG affiliates, one EY affiliate and a BDO network firm, concentrated on independence, internal governance and the scrutiny of related-party transactions, with concerns raised about the independence of six PwC-network partners, gaps in recruitment policy, and irregularities in audit work on investments held for sale and on impairment.

Read alongside those findings, however, the same cycle records movement in the other direction, and fairness requires recording it: the BSR & Affiliates network was assessed as generally compliant with independence requirements and as having implemented corrective action from earlier inspections, and BSR & Co’s non-compliance rates on personnel independence had fallen substantially after a revised non-assurance services policy took effect in January 2024.

The 2022 findings quoted above are three years old and should not be read in the present tense. An inspection report on Walker Chandiok & Co followed on 27 March 2026.  Independent commentary on the cumulative record identifies the recurring Indian themes as related-party transactions, impairment, going concern and documentation–and observes, correctly, that these are not new risks anywhere.

The divergence is the point. The PCAOB’s findings are overwhelmingly about the sufficiency of evidence on individual engagements. NFRA’s are disproportionately about independence, network architecture and the flow of non-audit services through affiliates– which is to say, about structure rather than execution. That is not because Indian auditors test estimates better than American ones.

It is because India’s unresolved question is the one America addressed in form in 2002 with the Sarbanes-Oxley prohibitions and the creation of the PCAOB itself: what exactly is the relationship between an Indian audit firm bearing an Indian name and the global network whose brand, methodology, technology and consultancy revenue stand behind it? Until that is settled, an Indian inspector (NFRA) who goes looking for the biggest threat to audit quality will keep finding it in the network agreement rather than in the sampling.

SA 600 Reform: Why MCA Must Act on NFRA’s Audit Standard Proposal

But there is a second divergence, and it needs stating with more care than the comparison usually receives, because the easy version of it is false. It is not the case that NFRA inspects in the dark. It names the firms, publishes reports carrying firm registration and report numbers, states how many engagements it reviewed, states which areas it reviewed within each, and states how many were found wanting–three of five selected audits deficient on impairment of investment at BSR & Co in one cycle, deficiencies in one engagement on related-party transactions in another. The denominator is on the page.

The difficulty is what that denominator is. NFRA reviews three to five engagements per firm; the PCAOB reviewed sixty-four at each of the Big Four. At a sample of five, a single deficiency moves the rate by twenty percentage points, which means no rate worth computing can be computed–and that is a resourcing constraint, not a disclosure choice.

The scope compounds it: NFRA fixes two standard focus areas, revenue recognition and loans and advances, and adds one engagement-specific high-risk area, so what is examined is a theme within an audit rather than the audit. A deficiency rate built on that base would not mean what a Part I.A rate means, and publishing one as though it did would mislead rather than inform.

What genuinely does not exist is the series. The PCAOB, for all the criticisms above, produces a number that can be tracked over four years, across firms and across tiers, argued about in public, and quoted in a senator’s letter.

NFRA has thirty-odd individual reports and no aggregation–nothing that lets a citizen, an audit committee or a Joint Parliamentary Committee ask whether Indian audit quality is better in 2026 than it was in 2022, or where one firm stands against another on a stable definition.

And here NFRA has a defence, which deserves to be put at its strongest. Its own inspection guidelines state that inspections are not investigations, that they provide neither absolute assurance nor conclusive findings of misconduct, and that engagement selection is risk-based with no role for the auditor.

A published league table of firms would therefore operate as a sanction imposed without adjudication–reputational punishment on the strength of a process the regulator itself says is not adjudicative. Given that the adequacy of NFRA’s adjudicative procedure is the precise question now before the Supreme Court, declining to publish such a table is arguably principled rather than evasive.

The counter to the defence is narrower but survives it: an aggregate count of engagements reviewed and deficiencies found, published across firms without ranking them, sanctions nobody and would settle the trend question in a single table.

To NFRA’s credit, its June 2026 inspection guidelines are a serious advance and in one respect braver than the PCAOB model. Firms must now submit a remediation plan within 90 days of an inspection finding and implement it within 180 days, against the PCAOB’s twelve months; and–the single most under-appreciated reform in either jurisdiction– auditors must place the inspection report before the audit committees of the public interest entities (PIE) they audit.

That last requirement puts the finding in front of the only body with the power to change the fee, the scope, the timetable and the engagement partner. It converts inspection from a conversation between regulator and firm into a fact in the boardroom. NFRA has also been careful to record that inspection findings are not the product of an adjudicative process and do not constitute conclusive findings for the purpose of sanctions–a caveat that will matter a great deal in the litigation described next.

Can NFRA Restore Credibility After Its Neutrality Questioned?

The judicial overhang, and a sequencing error

NFRA’s problem is not its findings. It is its procedure, and the procedure is in court.

On 7 February 2025 a division bench of the Delhi High Court comprising Justices Yashwant Varma and Dharmesh Sharma upheld the validity of section 132 of the Companies Act and the NFRA Rules–and then quashed 11 show-cause notices, mostly arising from the IL&FS audits, on the ground that the procedure followed lacked neutrality and dispassionate appraisal.

The absence of a bifurcation of functions, the bench held, exposes the regulator to allegations of bias, to a tendency to dismiss challenges to pre-formed opinions, and to disregard for arguments aimed at review and reappraisal. The division that conducts an audit quality review cannot be the division that adjudicates on it. The court expressly left it open to NFRA to begin afresh, from fresh notices, on the basis of the findings recorded in the audit quality review report.

NFRA appealed to SupremeCourt. On 17 February 2025 a bench of then Chief Justice Sanjiv Khanna and Justice Sanjay Kumar admitted the special leave petition, declined to stay the High Court’s judgment, permitted proceedings to continue on the High Court’s terms–including in cases where no audit quality review report had yet been prepared–and directed that final orders not be enforced for the time being.

The Solicitor General’s argument is worth recording because it is the crux of the institutional problem: NFRA, he submitted, is a composite body with only three full-time members (since augmented) and cannot realistically function in separate divisions.

Separately, in March 2025, the Supreme Court restored NFRA’s reach over engagement quality control review partners, holding that a recipient of a show-cause notice must first raise objections within the regulatory process before running to court–a reading I take from secondary commentary rather than the judgment itself, and flag accordingly.

NFRA’s administrative answer arrived in April 2026, when it separated oversight, investigation, referral for disciplinary action, and adjudication into four divisions, each led by a different member.  It is a sensible firewall, and it concedes in practice what the Solicitor General resisted in argument. NFRA has also relied, in its Supreme Court petition, on an earlier ruling of the National Company Law Appellate Tribunal (NCLAT) finding it compliant on division of functions, and on subsequent Supreme Court orders upholding that tribunal ruling–a line of authority reinforced by a further NCLAT decision in July 2026 upholding NFRA penalties.

Against that unsettled backdrop, Parliament is preparing to make NFRA far more powerful. The Corporate Laws (Amendment) Bill, 2026, introduced on 23 March 2026 and referred to a Joint Parliamentary Committee, would restructure the authority as a quasi-judicial regulator with corporate status, independent rule-making power and the ability to levy fees; require auditors of prescribed classes of companies to intimate their ICAI registration details and file periodic returns, with penalties for default; give it direct jurisdiction over contraventions within its remit without dependence on ICAI referral; restrict non-audit services for three years after an audit tenure ends; exclude civil court jurisdiction, with challenges lying only to the appellate tribunal; and provide imprisonment of up to six months and fines up to Rs 25 lakh for non-compliance with its orders.

Much of that is desirable. We need a strong audit regulator, and one with rule-making power and its own funding is more likely to be effective than one dependent on annual grants and referrals. But the sequencing is wrong, and an auditor’s eye cannot miss it.

A regulator whose procedure has been found by a High Court to lack neutrality, whose appeal on that precise point is pending before the Supreme Court, and whose divisional firewall is four months old, is about to be given the power to imprison and the insulation of an ouster clause.

If the Supreme Court affirms the High Court, every order passed in the interim inherits the defect. If it reverses, the firewall stands as good practice regardless. Either way, the honest order of operations is to settle the procedure, then hand over the powers–not to legislate capacity in the hope that litigation resolves conveniently. Legislating power before curing procedure is how a regulator wins the argument and loses the case, and then loses the argument too, because every future respondent litigates process instead of substance.

There is a further irony worth naming. PCAOB is being softened by the body that oversees it –its chair removed, its board reconstituted with practitioners, its enforcement all but suspended, its abolition twice attempted–while its published quality numbers improve. NFRA is being hardened by its legislature while its due process is contested and its published quality metric does not exist. Two mirror-image failures of the same function. In Washington the measurement survives and the enforcement has gone; in Delhi the enforcement is being armed and the measurement was never built.

ICAI vs NFRA: India’s Audit Regulator War Thaws amid Fog

Diagnosis and remedy

If we pull the threads together, the diagnosis is threefold: the failings are executional and economic rather than intellectual; the mechanisms designed to correct them operate on engagements while the causes live in systems; and the metrics by which we judge the whole enterprise are chosen and produced by the party whose performance they describe.

The remedies follow from that, and they are unglamorous.

At the firm level, root cause analysis has to reach the things firms do not enjoy examining: how many hours the engagement had against how many it needed, who reviewed the estimate memorandum and when, whether the person who signed off on the completeness of a system-generated report had ever seen the system. NFRA’s repeated criticism of root cause analysis frameworks is aimed at exactly this, and firms should stop treating it as a documentation complaint.

At the regulator level, three things. First, NFRA should widen the engagement sample and publish an aggregate–engagements reviewed and deficiencies found, by cycle and by focus area, across all firms inspected, on a stable definition. It already discloses these figures firm by firm; what is missing is the addition. Three to five engagements per firm will not support a rate however it is presented, so the sample is the first constraint to lift, and it is a question of inspection capacity rather than of policy.

Second, both regulators should publish the basis of engagement selection in enough detail that an outsider can tell whether a change in the rate reflects a change in audit quality or a change in inspection posture; the PCAOB’s forthcoming shift to system-level inspection makes this urgent, and a two-cycle bridge between old and new bases is the minimum.

Third, remediation should be verified publicly. A quality control criticism that becomes public only if the firm fails to remediate creates an incentive to satisfy the regulator rather than to fix the system, and the difference between those two things is the entire subject of this article.

At the governance level, NFRA’s audit committee requirement should be copied, not admired. And the audit committee that receives an inspection report should be required to record in the annual report what it did about it–which converts a regulatory finding into a governance fact with a name attached to it.

Lessons, and the way forward

Five lessons, then, and they travel.

The first is that improvement in a regulator’s headline metric is not the same as improvement in the thing measured, and the gap widens precisely when the regulator’s leadership changes. The 8 per cent is probably real. It is also unauditable from outside, and that combination–probably right, structurally unverifiable–is exactly what a serious accountability system should be designed to eliminate.

The second is that recurring deficiencies recur because they are cheap to commit, invisible to everyone but an inspector, and expensive to prevent. Nothing changes that except raising the probability and consequence of detection, which is why the collapse of American audit enforcement in 2025 and the improvement in American audit quality in 2025 sit so awkwardly on the same page. The improvement was bought by the previous administration’s severity. Whether it survives the current administration’s collegiality is the question the 2027 reports will answer, and it is the only question about these numbers that genuinely matters.

The third is that the mid-tier gap–34 and 33 per cent against 5–is now a structural feature of a market in which audit quality has become capital-intensive. Censure alone will drive concentration. Some combination of shared methodology infrastructure, proportionate scoping for less complex entities, and honest acknowledgment that not every firm can audit every company is the harder and better answer.

The fourth is that India’s inspection regime is well designed on remediation and boardroom transparency, admirably specific in its individual reports, and yet incapable of answering the only question the public will eventually ask, which is whether things are getting better. The reports disclose their samples; the samples are too small to carry a rate; and nobody adds them up. Widen the sample, publish the aggregate, resist the league table, and let the profession argue about the trend in public–because the argument is the mechanism.

The fifth is about sequencing, and it is the one I would press hardest on the Joint Parliamentary Committee. Do not hand a regulator the power of imprisonment, an ouster clause and independent rule-making while the Supreme Court is still deciding whether the way it initiates proceedings satisfies natural justice. Settle the procedure first. A regulator that is feared but procedurally vulnerable will spend the next decade litigating its own legitimacy instead of improving audit quality–which is, after all, what both of these institutions exist to do, and what neither can currently prove it has done.

Big Four Audit Deficiencies Fall Sharply in US — But Should Regulators Celebrate Yet?

(This is the second of the two-part series. Link of the first article is above. Views expressed in the article are author’s own.)

Follow The Raisina Hills on WhatsApp, Instagram, YouTube, Facebook, and LinkedIn

About The Author

Leave a Reply

Your email address will not be published. Required fields are marked *

Discover more from The Raisina Hills

Subscribe now to keep reading and get access to the full archive.

Continue reading