| 54 Annual Report | 2025-2026 for detailed compliance across Information technology practise & control and cyber security preparedness, cyber crisis management & mitigation plans. In line with one of the key directives in the said circular is the definition & scope of the role of a Chief Information Security Officer (CISO) with reporting lines to the Chief Risk Officer. In compliance to the said circular, a General Manager cadre officer has been appointed as a CISO in Arohan with effect from April 1, 2024 to bring in the desired focus & actionable regarding information technology and cyber security risk management. An independent vCISO consulting team has been delivering robust performance in terms of monitoring & reporting of information security aspects. Arohan has deployed a monitoring tool named, Secveil, which monitors & reports exceptions of all end points. The vCISO also undertakes monitoring the identified cyber-attacks & potential exploits from Web Application Firewall (WAF) attack reports, Security Operations Center (SOC) raised incidents on SIEM tool indicators and AWS Guard Duty services findings. Arohan put together a robust oversight structure under the CISO to ensure better Information Security preparedness at Arohan. INTERNAL AUDIT MANAGEMENT At Arohan, the Internal Audit function serves as a cornerstone of organisational integrity, playing a vital role in protecting customer interests through the promotion of transparency, accountability, and robust governance. By providing an independent assessment of internal controls, governance systems, and risk management practices, the team upholds the reliability of the entire organisation. This systematic and disciplined approach is designed not only to enhance operational efficiency but also to fortify the trust that customers place in the company. To ensure a completely unbiased and thorough review process, the Internal Audit department operates with full independence, reporting directly to the Audit Committee of the Board. The Audit Committee maintains active oversight by regularly evaluating the department’s staffing, audit plans, and overall structure, thereby reinforcing Arohan’s commitment to safeguarding customer confidence. Strategic Role and Regulatory Compliance The Internal Audit function acts as a strategic partner to Arohan’s management, offering insights that strengthen internal defences and enhance governance practices. A key component of this strategic alignment is the department’s adherence to the Reserve Bank of India’s (RBI) Risk-Based Supervision (RBS) framework. Specifically, Arohan follows the guidelines outlined in the RBI’s February 3, 2021, circular regarding “Risk-Based Internal Audit (RBIA)” for large non-deposit-taking NBFCs. In addition to these sector-specific regulations, the function ensures compliance with the broader governance requirements of the Companies Act, 2013, and adheres to the professional Standards and Guidelines prescribed by the Institute of Chartered Accountants of India (ICAI). These collective efforts support high levels of regulatory compliance while promoting the transparency and resilience necessary for long-term organisational integrity. Professional Expertise and Multidisciplinary Strength Arohan’s Internal Audit team is characterized by deep expertise and a multidisciplinary skill set, which allows for high-quality assessments across various operational areas. The professional composition of the team includes: ● 2 Chartered Accountants (CA). ● 2 Certified Information System Auditors (CISA). ● 1 Certified Internal Auditor (CIA). ● 10+ MBAs who operate across both headquarters and field operations. ● 2 Lead Auditors certified in ISO 9001:2015 and ISO 27001. This robust mix of technical precision and strategic perspective enables the team to navigate complex audit challenges effectively. Furthermore, Arohan actively champions diversity and inclusion within this critical function. Currently, the team includes seven women professionals, with ongoing initiatives to further increase female representation. This commitment is part of a broader vision to foster gender equity and build a forwardthinking audit environment where women leaders are empowered. Commitment to Quality Certification Quality and operational excellence are fundamental to Arohan’s audit practices, as evidenced by its history of ISO certifications. In FY 2020, the Internal Audit function was awarded the ISO 9001:2015 certification by the British Standards Institution (BSI). This certification recognizes the department’s adherence to internationally accepted quality management standards. The validity of this certification was extended for another three years in February 2023 following a successful surveillance audit, demonstrating a dedication to continuous improvement. Building on the success of the audit-specific certification, Arohan achieved a significant milestone in FY 2025 by securing the ISO 9001:2015 Certificate of Registration Management Discussion & Analysis
RkJQdWJsaXNoZXIy NTE5NzY=