
The Pension Fund Regulatory and Development Authority (PFRDA) has issued a circular requiring registered Points of Presence (PoPs) to undergo mandatory audits by independent external chartered accountants or audit firms. According to reports from Business Standard, the requirement will apply under the revised framework from April 1, 2026 to March 31, 2027. PoPs serve as the first point of contact for NPS subscribers, handling account opening, contribution processing, service requests, withdrawals and other administrative activities. As reported by The Economic Times, the move is aimed at improving operational controls, protecting subscriber interest and ensuring that contributions, withdrawals and service requests are processed within prescribed timelines.
PFRDA has classified PoPs based on their subscriber base as of the last day of the financial year, determining audit frequency requirements. As reported by Business Standard, PoPs with fewer than 10,000 subscribers will need an audit once in three financial years. PoPs with 10,000 or more subscribers will require audits every financial year. PoPs having fewer than 100 NPS accounts are exempt from submitting audit reports, but once they cross 100 subscribers, they must submit reports for earlier financial years as applicable. For larger PoPs, the first audit report under the revised framework will be due by June 30, 2027, while for smaller eligible PoPs, the due date will depend on whether the audit report for FY26 has already been submitted.
The audit framework extends beyond financial records to examine operational systems and controls. According to Business Standard, the scope includes NPS account opening and subscriber onboarding processes, compliance with KYC, anti-money laundering and counter-terror financing requirements, collection and transfer of subscriber contributions, uploading contribution details into the Central Recordkeeping Agency (CRA) system, maintenance of collection accounts and reconciliation of subscriber funds, handling of subscriber complaints, processing of withdrawals, exits and service requests, and data security practices. As reported by The Economic Times, the audit will examine whether PoPs have proper systems and controls in place for handling subscriber-related activities, including data security and cyber security practices. Auditors will also verify whether PoPs maintain proper books of accounts, electronic records and documents as required under PFRDA regulations.
A major component of the audit framework addresses how subscriber money is handled and processed. As reported by Business Standard, auditors will check whether contributions received from subscribers are deposited and processed within the required timelines and examine whether there are any unreconciled amounts lying in collection accounts. The audit will also verify whether PoPs compensate subscribers in cases where delays occur in activities such as account registration, service requests, contribution processing or withdrawal processing, as prescribed under operational guidelines. For subscribers, this means stronger monitoring around issues such as delayed fund transfers, incorrect processing of requests or unresolved complaints, as reported by The Economic Times.
PFRDA has prescribed specific eligibility conditions for auditors, requiring PoPs to appoint auditors from the list of firms empanelled by financial sector regulators, including PFRDA. According to Business Standard, auditors must be appointed for a three-year tenure, after which the same audit entity will face a two-year cooling-off period before accepting another audit assignment from the same PoP. The appointment must be approved by the Audit Committee or the Board, wherever applicable. The audit report must include confirmation that the auditor has no direct or indirect interest or conflict of interest with the PoP being audited. As reported by The Economic Times, PFRDA has said that audit reports will be reviewed by the regulator, and if reports are incomplete or do not meet the required standards, appropriate action may follow. The regulator may also arrange an audit of PoPs that fail to submit reports within the prescribed timelines.