Now partnering with TechDefence to deliver stronger cyber security outcomes — Learn more

Cyber News
All news →
Compliance · RBI

RBI cyber security and IT governance compliance

The Reserve Bank of India expects regulated entities to run cyber security as a board-level responsibility, not just an IT task. Its directions cover governance, risk management, technical controls, outsourcing, digital payment security and incident reporting.

Overview

In plain English

Which instruments apply to you depends on your licence and category — a scheduled commercial bank, a co-operative bank, an NBFC in a particular layer, or a payment system operator will each have a different set of obligations.

Instruments covered

  • Cyber Security Framework in Banks (2 June 2016)
  • Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (7 November 2023, effective 1 April 2024)
  • Master Direction on Outsourcing of Information Technology Services (10 April 2023)
  • Master Direction on Digital Payment Security Controls (18 February 2021)
  • Cyber resilience and digital payment security controls for non-bank payment system operators (2024)
  • Digital Lending Directions

Last reviewed:

Key requirements

What RBI expects

  1. Board-approved policies

    IT strategy, information security and cyber security policies approved and overseen by the board or its committees.

  2. IT and information security governance

    Defined roles such as a senior official responsible for information security, with committees overseeing IT and cyber risk.

  3. Risk assessment and controls

    Periodic risk assessments and controls covering access, change management, vulnerability management and data protection.

  4. Vulnerability assessment and penetration testing

    Regular VAPT of critical and internet-facing systems, with findings tracked to closure.

  5. Outsourcing and third-party risk

    Due diligence, contracts and ongoing monitoring of IT service providers, with the regulated entity remaining accountable.

  6. Digital payment security

    Security controls for internet banking, mobile banking and payment channels, including fraud monitoring and customer protection.

  7. Incident reporting and crisis management

    A Cyber Crisis Management Plan and timely reporting of cyber incidents to RBI and CERT-In as applicable.

  8. IS audit

    Periodic information systems audit covering the areas the directions require.

How TrustNet helps

From gap to evidence

  • Gap assessment against the RBI directions that apply to your entity
  • VAPT of banking, payment and lending channels
  • Board-approved policy suite and IT governance documentation
  • IT audit support and evidence preparation
  • Incident reporting playbooks and Cyber Crisis Management Plan
  • Outsourcing and vendor risk assessments

Official sources

Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.

Services mapped to RBI

FAQ

RBI FAQ

Does the IT Governance Master Direction apply to NBFCs?

It applies to specified categories of regulated entities, including NBFCs in certain regulatory layers. We help you confirm the exact applicability for your entity.

Do we need a Cyber Crisis Management Plan?

RBI expects regulated entities to be prepared to respond to cyber incidents. A tested Cyber Crisis Management Plan is the standard way to show this.

Can TrustNet sign our RBI-mandated audit?

Some audits must be signed by auditors meeting specific qualifications. We will tell you clearly which parts we deliver and where a qualified partner signs.

Book a consultation

Get RBI-ready

We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.

support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438

Under attack right now? Go to emergency help →

Today in Cyber

What's happening in cyber security

See all news →

Source: The Hacker News — headlines only, each linking to the original article.

Chat with us