Table of Contents

RTI Compliance Audit Checklist for Public Authorities

RTI Compliance Audit Checklist for Public Authorities — RTI Wiki

Quick Reply: Annual RTI compliance audit checklist for public authorities. Twelve audit areas, scoring template, evidence required, and how to close audit observations from the CAG or Information Commission. Free 2026 audit…

Direct answer. Every public authority should run an internal RTI compliance audit at least once a year, ideally aligned with the financial-year close. The audit should cover twelve areas: PIO designation, FAA designation, Section 4 disclosure, record management, RTI receipt and disposal SLAs, fees, appeals, third-party procedure, Section 25 returns, training, citizen feedback, and Information Commission directions outstanding. A scoring template is below — eighty per cent or above is the working benchmark; below sixty per cent is a red flag for the head of office and external audit.

CAG audits and Information Commission compliance reviews routinely flag the same patterns: outdated PIO pages, untracked appeal disposals, missing Section 25 returns, no Section 4 update log. An internal audit catches all of these before the external audit does. This checklist is designed for adoption by the public authority's vigilance / records committee.

When to run the audit

Twelve audit areas with scoring

Each area is scored out of ten. The total is out of 120; convert to percentage.

Area 1 — PIO designation (10)

Area 2 — FAA designation (10)

Area 3 — Section 4 disclosure (10)

Area 4 — Record management (10)

Area 5 — RTI receipt and disposal SLA (10)

Area 6 — Fees (5)

Area 7 — Appeals (10)

Area 8 — Third-party procedure (10)

Area 9 — Section 25 annual return (10)

Area 10 — Training (10)

Area 11 — Citizen feedback (10)

Area 12 — Outstanding Commission directions (15)

Step by step

  1. Step 1. Constitute an audit team — nodal RTI officer, internal audit officer, IT, vigilance.
  2. Step 2. Agree the score-sheet using the twelve areas above.
  3. Step 3. Sample 5% of applications and 10% of appeals for evidence.
  4. Step 4. Cross-verify with public-facing data (website, portal, Commission's records).
  5. Step 5. Score each area with documentary evidence.
  6. Step 6. Compile a draft report with scores, findings, recommendations.
  7. Step 7. Discuss with the head of office; finalise.
  8. Step 8. Place the report on the office's RTI page (with redactions for any sensitive personnel content).
  9. Step 9. Track corrective actions to closure.

Evidence the audit team should gather

Scoring benchmarks

Score % Rating Action
90+ Excellent Sustain
80 to 89 Good Minor improvements
70 to 79 Average Targeted improvements
60 to 69 Weak Action plan within 30 days
Below 60 Critical Head of office to convene review

Common public authority mistakes

Frequently asked questions

Is the audit mandatory by law?

The Act does not name an “audit” but the Section 25 return, Section 4 sign-off, and CAG performance audit collectively make internal audit a practical necessity.

Who pays for an external audit?

External audit (CAG, peer-review by another department, civil-society audit) is funded by the audit authority's budget. Internal audit is by the public authority's own staff.

How long does an audit take?

Two to three weeks in a small office; six weeks in a large ministry.

Can a third-party agency audit us?

Yes — many ministries engage civil-society partners (e.g. CHRI, RAAG) for independent scoring.

What if we score below 60%?

The head of office must convene a review and produce a 30-day action plan.

Do we publish the audit report?

Yes, with redactions for sensitive personnel matters.

Does the Commission accept our audit as evidence?

Yes. Commissions look favourably on public authorities that maintain internal audit and produce findings.

Sources

See also

Last reviewed: 9 May 2026.

RTI compliance audit: How to assess whether a public authority is meeting RTI obligations?

RTI compliance audit of public authorities — complete guide on assessment and enforcement:

  1. Step 1: What is RTI compliance? (a) under Section 4(1)(a) of the RTI Act: every public authority must maintain all records duly indexed and in a form that facilitates the right to information, (b) under Section 4(1)(b): every public authority must publish 17 categories of information suo moto (on its website — including organisation structure, powers and duties, decision-making process, rules and regulations, budget, subsidy programmes, information about PIOs, etc.), © under Section 5(1): every public authority must designate a Central/State Public Information Officer (CPIO/SPIO) and a First Appellate Authority (FAA), (d) under Section 26: the appropriate government must organise training programmes and create awareness about the RTI Act.
  2. Step 2: Key compliance indicators. (a) Section 4(1)(b) disclosure: is the 17-point mandatory disclosure published on the website — and is it current (updated within the year), (b) PIO/FAA designation: are the PIO and FAA designated — and are their names, designations, and contact details published, © RTI fee mechanism: is the RTI fee collection mechanism in place (online payment, IPO, court-fee stamp — as per the state/central rules), (d) response rate: what percentage of RTI applications are responded to within 30 days (the statutory timeline), (e) rejection rate: what percentage of RTI applications are rejected — and are the rejections with valid reasons (citing the specific exemption), (f) first appeal disposal: what percentage of first appeals are disposed of within 30 days (the statutory timeline for FAA), (g) penalty and compliance: has the Information Commission imposed penalties — and has the public authority complied.
  3. Step 3: How to audit. (a) visit the public authority's website (check Section 4(1)(b) disclosure — is it present, is it current, are all 17 categories covered), (b) file test RTI applications (file 3-5 RTI applications on different topics — and track the response time, the quality of response, and the rejection rate), © file RTI on compliance (ask the public authority for: (i) the number of RTI applications received per year, (ii) the number responded to within 30 days, (iii) the number rejected — with reasons, (iv) the number of first appeals — and the disposal rate, (v) the number of second appeals to the Information Commission — and the penalties imposed), (d) check the Information Commission's website (for orders against the public authority — and the compliance status), (e) check the Annual Return (the public authority must file an annual return with the Information Commission — with compliance statistics).
  4. Step 4: File RTI for audit. File RTI with the public authority asking for: (a) the Section 4(1)(b) disclosure (the date of last update — and the URL where it is published), (b) the PIO and FAA designated (the names, designations, phone numbers, and email addresses — and whether the posts are currently filled), © the number of RTI applications received from [date] to [date] (and the number responded to within 30 days — and the number rejected — with the reasons for rejection), (d) the number of first appeals received and disposed of (within 30 days — and the number pending — and the reasons for pendency), (e) the number of second appeals to the Information Commission (and the number of penalties imposed — and the amount — and whether the penalties have been paid), (f) the annual return filed with the Information Commission (for the year [year] — a copy of the return).
  5. Step 5: Common non-compliance. (a) Section 4(1)(b) not published (the public authority has not published the 17-point disclosure — or it is years old — or it is incomplete), (b) PIO not designated (the PIO post is vacant — or the PIO is additional charge — or the contact details are not published), © RTI applications not responded to (the PIO does not respond — or responds after 30 days — or gives incomplete information), (d) rejections without valid reasons (the PIO rejects without citing the specific exemption — or cites “general” reasons like “not in public interest”), (e) first appeals not disposed of (the FAA does not respond — or responds after 30 days — or upholds the PIO's rejection without reasoning), (f) penalties not paid (the Information Commission imposes a penalty — but the public authority does not pay — or recovers it from the PIO).
  6. Step 6: Enforcement. (a) file a complaint with the Information Commission (under Section 18 — for non-compliance with Section 4 — or non-response by the PIO), (b) the Commission can: (i) direct the public authority to comply (publish Section 4(1)(b) — designate PIO — respond to RTI applications), (ii) impose a penalty on the PIO (Rs 250 per day — up to Rs 25,000 — under Section 20(1)), (iii) recommend disciplinary action (against the PIO — under Section 20(2)), © file a writ petition (in the High Court — under Article 226 — for systemic non-compliance — the court can order the public authority to comply with the RTI Act), (d) use the audit findings for advocacy (publish the audit report — approach the media — and the parliament/legislature — to highlight non-compliance).
  7. Step 7: Best practices. (a) proactive disclosure (the public authority should publish all 17 categories — on the website — updated annually), (b) online RTI portal (the public authority should accept RTI applications online — with online payment — and online response), © training (the public authority should train the PIO and FAA — on the RTI Act, the exemptions, and the response format), (d) monitoring (the public authority should monitor the RTI compliance — monthly — with statistics on response rate, rejection rate, and appeal disposal), (e) the CIC has issued guidelines (on Section 4(1)(b) compliance — and on the PIO's duties — and the public authority should follow these guidelines).

See RTI Compliance Audit and Find PIO.