Cybersecurity, Technology Risk, Resilience and Assurance Framework, July 31, 2026
RBI issued separate entity-specific Directions on the Cybersecurity, Technology: Risk, Resilience and Assurance Framework. The Directions consolidate and update requirements relating to IT governance, information security, cybersecurity, technology risk management, operational resilience and information-systems audit.
Scope and Purpose of the Directions
The Directions apply to a wide range of regulated entities, each covered by its own entity-specific framework:
- Commercial Banks
- Small Finance Banks
- Payments Banks
- Urban Co-operative Banks
- Non-Banking Financial Companies (“NBFCs”)
- All India Financial Institutions (“AIFIs”)
Board and Senior Management Responsibilities
The Directions place greater responsibility on Boards and senior management for technology and cybersecurity governance. Depending on the regulated entity and applicable framework, requirements include:
- Board-approved IT and information-security policies
- Appropriate IT/security committees
- Defined responsibilities for senior technology and security personnel, including the Chief Information Security Officer (“CISO”)
- Systematic identification and assessment of technology and cybersecurity risks
Key Areas Covered by the Framework
The framework addresses a broad set of technology and security domains, including:
- Information-asset protection and classification
- Access controls
- Application and network security
- Vulnerability management
- Audit logs
- Incident response
- Business continuity and disaster recovery
- Third-party technology arrangements
- Information-systems audit
Differentiated Requirements for NBFCs
For NBFCs, the requirements are differentiated based on the applicable regulatory layer and asset size. Enhanced governance and technology-risk requirements apply to larger and higher-layer entities.
Effective Date
The Directions came into effect immediately upon issuance.
Key Takeaway
Regulated entities and their technology-service providers will need to review the following areas against the applicable 2026 framework:
- Governance structures
- Cybersecurity controls
- Incident-response arrangements
- Outsourcing arrangements
- Technology-risk documentation
Last Updated on 21 August, 2026
By entering the email address you agree to our Privacy Policy.
