Revised PFRDA Audit Framework for NPS Points of Presence: Complete Compliance Guide
The Pension Fund Regulatory and Development Authority has overhauled the audit requirements applicable to Points of Presence handling National Pension System operations, including NPS Vatsalya. Vide Circular No. PFRDA/2026/36/SUP-POP/05 dated 17th June 2026, a structured, risk-based audit framework has been introduced, significantly changing the manner and frequency in which PoPs must undergo external audit.
This note explains the revised framework in a practical, compliance-oriented manner for PoPs, their management teams, compliance officers and auditors.
1. Background and Regulatory Context
Points of Presence registered under Regulation 3(1)(a) of the Pension Fund Regulatory and Development Authority (Points of Presence) Regulations, 2018 (as amended) are the primary service interface for NPS subscribers. With the expansion of NPS and the introduction of NPS Vatsalya, PFRDA has sought to strengthen oversight of:
- subscriber onboarding and account handling
- KYC/AML/CFT compliance
- fund collection, transmission and reconciliation
- grievance redressal
- data and cyber security
- fraud risk management
The circular dated 17th June 2026 aligns the audit framework with the Operational Guidelines issued on 27th February 2026 under the PFRDA (PoP) Regulations, 2018. It prescribes:
- audit periodicity based on subscriber base
- eligibility criteria for auditors
- tenure and cooling-off norms
- detailed audit scope and report format
- consequences for non-submission or delayed submission of reports
2. Applicability and Broad Requirement
All PoPs registered under Regulation 3(1)(a) and carrying out NPS (including NPS Vatsalya) activities must ensure that their NPS-related accounts, processes and controls are subjected to an independent external audit in accordance with:
Pension Fund Regulatory and Development Authority Act, 2013Pension Fund Regulatory and Development Authority (Points of Presence) Regulations, 2018and amendments- Operational Guidelines dated 27th February 2026
- Circulars/Guidelines/Notifications issued by PFRDA from time to time
- KYC/AML requirements under PML Act/Rules
The audit is to be carried out by an external chartered accountant or audit firm fulfilling the eligibility norms specified by PFRDA (detailed later).
3. Risk-Based Audit Frequency Linked to Subscriber Base
The revised framework classifies PoPs into categories based on the number of associated subscribers as on the last day of the financial year. The categorisation is effective for the period from 1st April 2026 to 31st March 2027.
3.1 Categorisation and Audit Periodicity
| Category | Subscriber base (as on last day of FY) | Audit frequency | Due date of first report under new regime |
|---|---|---|---|
| I | Less than 10,000 | Once in three financial years (covering all three years) | 30.06.2029 (where audit report for FY 2025-26 is already submitted) |
| II | 10,000 and above | Every financial year | 30.06.2027 |
Important
PoPs with a relatively lower subscriber base (below 10,000) are subject to a reduced frequency of audit, whereas larger PoPs must be audited annually, reflecting a risk-based approach.
3.2 Exemption for Very Small PoPs
- PoPs having less than 100 NPS accounts are presently exempt from the obligation to submit an audit report.
- Once such PoPs cross the threshold of 100 or more subscribers, they become liable to submit audit reports for all prior financial years during which they were performing NPS-related activities.
This is a deferred but retrospective compliance requirement, and PoPs that are currently below the 100-account threshold should maintain complete records from inception to ensure smooth audit when the threshold is breached.
4. Eligibility Norms and Tenure for Auditors (Annexure 1)
PFRDA has prescribed specific eligibility conditions for selection and appointment of auditors to ensure independence, competence and consistency across PoPs.
4.1 Source of Auditor Empanelment
PoPs generally
- Must appoint external auditors from the panel of auditors empanelled by any Financial Sector Regulator (FSR), including PFRDA.
- The audit will be restricted to activities related to NPS.
Central/State Government departments/entities
- May conduct the audit through:
- their internal audit department, or
- an external auditor drawn from the panel of auditors empanelled by any FSR including PFRDA.
- May conduct the audit through: