Cybersecurity, Technology Risk, Resilience and Assurance Framework, July 31, 2026

Posted On - 20 August, 2026 • By - King Stubb & Kasiva

RBI issued separate entity-specific Directions on the Cybersecurity, Technology: Risk, Resilience and Assurance Framework. The Directions consolidate and update requirements relating to IT governance, information security, cybersecurity, technology risk management, operational resilience and information-systems audit.

Scope and Purpose of the Directions

The Directions apply to a wide range of regulated entities, each covered by its own entity-specific framework:

  • Commercial Banks
  • Small Finance Banks
  • Payments Banks
  • Urban Co-operative Banks
  • Non-Banking Financial Companies (“NBFCs”)
  • All India Financial Institutions (“AIFIs”)

Board and Senior Management Responsibilities

The Directions place greater responsibility on Boards and senior management for technology and cybersecurity governance. Depending on the regulated entity and applicable framework, requirements include:

  • Board-approved IT and information-security policies
  • Appropriate IT/security committees
  • Defined responsibilities for senior technology and security personnel, including the Chief Information Security Officer (“CISO”)
  • Systematic identification and assessment of technology and cybersecurity risks

Key Areas Covered by the Framework

The framework addresses a broad set of technology and security domains, including:

  • Information-asset protection and classification
  • Access controls
  • Application and network security
  • Vulnerability management
  • Audit logs
  • Incident response
  • Business continuity and disaster recovery
  • Third-party technology arrangements
  • Information-systems audit

Differentiated Requirements for NBFCs

For NBFCs, the requirements are differentiated based on the applicable regulatory layer and asset size. Enhanced governance and technology-risk requirements apply to larger and higher-layer entities.

Effective Date

The Directions came into effect immediately upon issuance.

Key Takeaway

Regulated entities and their technology-service providers will need to review the following areas against the applicable 2026 framework:

  • Governance structures
  • Cybersecurity controls
  • Incident-response arrangements
  • Outsourcing arrangements
  • Technology-risk documentation

Last Updated on 21 August, 2026

Get King Stubb & Kasiva’s legal updates in your Google feedAdd King Stubb & Kasiva as a preferred source on Google