RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices

RBI BFSI Direction Active 1 Apr 2024

Applies to: Scheduled commercial banks, urban cooperative banks, NBFCs, payment system operators

Consolidates and updates earlier RBI IT and cyber circulars into a single governance-led direction. Board-level IT governance is mandatory via a dedicated IT Strategy Committee; the IT Risk Framework requires board (not just senior-management) approval. A Cyber Crisis Management Plan is now mandatory for all covered entities, not only large banks. Third-party risk management is tightened — exit clauses, concentration-risk monitoring and annual audits of critical vendors. Payment-data localisation requirements remain with stricter monitoring. Significant incidents must be reported within tightened timelines. The CISO is expected to report outside the IT function, and VAPT — manual penetration testing, not just scanning — is expected at least annually and after significant change, with findings remediated and re-tested.
Why it matters
This is the spine the April 2026 data advisory hangs off — read them together, not in isolation. The structural shift examiners now enforce is board ownership: a Cyber Crisis Management Plan that exists on paper but has never been exercised under pressure is the most common finding. Note the supervisory expectation has moved from "did you scan" to "did you manually pen-test, remediate and re-test" — a scan report alone no longer satisfies. CISO reporting line outside IT is a hard structural control; if yours still reports to the CIO, that is an audit flag waiting to be raised.