Live Founding Cohort open, limited seats remaining Back to main site →

How to read a CSITE inspection observation

The Cyber Security and IT Examination (CSITE) Cell of RBI runs the inspections that turn into enforcement. A CISO who can read a CSITE observation and immediately identify which instrument it cites and what remediation window applies has a defensible programme. One who cannot ends up with a Kotak-shaped restriction. This lesson teaches the reading skill.

Free preview 10 min read Verified
Legal basis
RBI Cybersecurity Framework stack current to 10 August 2026. Core instruments: Cyber Security Framework in Banks (DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016); IT Framework for the NBFC Sector (DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017); Storage of Payment System Data (DPSS.CO.OD No.2785/06.08.005/2017-18 dated 6 April 2018); Comprehensive Cyber Security Framework for UCBs — Graded Approach (DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019); Master Direction on Digital Payment Security Controls (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated 18 February 2021); Master Direction on Outsourcing of IT Services (RBI/2023-24/102 dated 10 April 2023); Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024); Master Directions on Fraud Risk Management (RBI/2024-25/47, /48, /49 dated 15 July 2024); Payment Aggregators Directions (RBI/DPSS/2025-26/141 dated 15 September 2025); Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 dated 31 July 2026; FREE-AI Framework Report dated 13 August 2025; Digital Payment Authentication Framework April 2026; Draft Guidance on Regulatory Expectations for Data Governance dated 15 July 2026. Adjacent instruments: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); Banking Regulation Act 1949 Section 35A; Reserve Bank of India Act 1934 Section 45L; IT Act 2000 Section 70B; Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services (2006); Scale-Based Regulation Framework for NBFCs (22 October 2021).

RBI\'s Cyber Security and IT Examination (CSITE) Cell conducts periodic IT inspections of Regulated Entities. Findings are recorded as "observations" and issued to the entity for response and remediation. Serious or repeated observations flow to enforcement action. Both the 24 April 2024 Kotak Mahindra Bank supervisory restrictions [L4-C1] and the November 2025 HDFC Bank penalty [L4-C2] trace back to CSITE inspection observations that the entity did not close.

A CSITE observation typically has four parts: (a) the factual finding, (b) the specific instrument and paragraph the finding cites, (c) the risk statement, and (d) an implicit remediation window. Reading each part correctly is what allows the CISO to prioritise the response.

Worked example: Kotak Mahindra Bank (2022, 2023 inspections)

The 24 April 2024 RBI Press Release directing Kotak Mahindra Bank to cease onboarding new customers through online / mobile banking channels and to stop issuing fresh credit cards was based on IT inspection observations of 2022 and 2023 that the bank did not close in a comprehensive and timely manner. The Press Release lists the areas of deficiency:

  • IT inventory management
  • Patch and change management
  • User access management
  • Vendor risk management
  • Data security and data leak prevention strategy
  • Business continuity and disaster recovery rigour and drill

The important pattern is: these are not obscure items. They are the operational areas any bank\'s cyber programme has to cover. The Press Release also identifies the mechanism of concern: continued failure on part of the bank to address these concerns in a comprehensive and timely manner. The enforcement action is not about the observation itself. It is about the compounding effect of an unclosed observation.

The two-question reading rule

Every CSITE observation your team receives, ask these two questions in this order:

  1. Which instrument and paragraph does this cite? If the observation says "vendor risk management framework needs strengthening", the underlying obligations are: the 2023 IT Outsourcing MD (RBI/2023-24/102) plus the 2006 Financial Services Outsourcing Guidelines plus (for commercial banks) the 31 July 2026 Directions plus (for applicable REs) the 2023 ITGRCA MD Chapter III on third-party arrangements. Your response must show you have reconciled the observation against every applicable instrument, not just one.
  2. What is the reasonable remediation window? RBI does not always publish an explicit remediation deadline in the observation. The reasonable window is a function of the risk. A patch-management gap on internet-facing systems is measured in days. A CISO independence issue is measured in weeks. A Board-policy bifurcation is measured in the next Board cycle. If you cannot articulate the window internally, you have not read the observation.

Enforcement escalation pattern

Based on the 2022-2026 RBI actions, the escalation pattern is:

  1. Observation issued. RE responds; RBI reviews; if satisfactory, closed.
  2. Observation carried over. Not closed at first review; escalated to a follow-up inspection.
  3. Repeat observation. Same issue appears in a second consecutive inspection. This is the trigger point for enforcement.
  4. Monetary penalty or supervisory action. Penalty for a discrete contravention (HDFC pattern) or business restriction for compounding IT governance failure (Kotak pattern).
  5. Remediation and lifting. Restrictions lifted after RBI is satisfied on remediation (Kotak restrictions lifted 12 February 2025).

The point of the escalation pattern is that observations issued today are enforcement actions tomorrow if not closed. This is why the CISO cannot delegate observation-tracking to a junior analyst without oversight. The IT Strategy Committee should see the open observations register at every meeting, with age and remediation plan against each item.

What a defensible response looks like

Response to a CSITE observation is not a compliance form-fill. It is a document that will be read by supervisors and by future inspectors. A defensible response has:

  • Acknowledgement of the observation without minimising it
  • Citation of the specific instrument(s) and paragraphs the observation touches
  • Root-cause analysis of why the gap exists
  • Concrete remediation actions with owners and dates
  • Compensating controls in place until remediation completes
  • Board / ITSC visibility route for the remediation
  • Independent-assurance route (Internal Audit or an external CERT-In empanelled auditor) to confirm closure

If the response cannot show all seven, the observation is likely to recur. And recurrence is what triggers the escalation pattern above.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of RBI Cybersecurity Framework Practitioner Certification?

  • All 8 paid modules (36 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹24,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
RBI Kotak Mahindra Enforcement 2024, Kotak Mahindra 24 Apr 2024 (Kotak Mahindra Bank supervisory business restrictions) L4-C1
RBI Press Release dated 24 April 2024. Directed Kotak Mahindra Bank Limited under Section 35A of the Banking Regulation Act 1949 to cease and desist, with immediate effect, from onboarding new customers through its online and mobile banking channels and from issuing fresh credit cards. Cited serious deficiencies observed in RBI IT inspections of 2022 and 2023 across IT inventory management, patch and change management, user access management, vendor risk management, data security and data leak prevention. Restrictions lifted on 12 February 2025 after remediation. Verbatim order paragraphs must be pulled from the 24 April 2024 press release on rbi.org.in before printing.
RBI HDFC Bank Penalty 2025, HDFC Nov 2025 (HDFC Bank penalty citing 2006 Outsourcing Guidelines) L4-C2
RBI Press Release November 2025. Monetary penalty of ₹91 lakh imposed on HDFC Bank Limited for contravention of certain provisions of the RBI Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services by banks dated 3 November 2006 and the Master Direction on Know Your Customer. Illustrates that RBI continues to enforce the 20-year-old 2006 Outsourcing Guidelines against banks in parallel with the 2023 IT Outsourcing Master Direction.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The RBI Cyber Stack in 2026
Module 2: IT Governance under the 2023 ITGRCA Master Direction
  • ITGRCA applicability perimeter in detail
  • IT Strategy Committee: composition, cadence, chair independence
  • CISO independence: the reporting line that actually works
  • IS Audit: cadence, charter, and auditor competencies
  • Three management committees that do the actual work
Module 3: The 2026 Commercial Banks Cybersecurity Directions and the 2016 CSF Baseline
  • Reading the 2026 Directions chapter by chapter
  • The 2016 CSF as continuing baseline for non-commercial-bank REs
  • UCB Graded Framework: picking the right level and staying in it
  • The Cyber Security Policy vs the IT Policy: two documents, one Board
  • The security-testing floor: VA every six months, PT annually, DR half-yearly
Module 4: NBFC IT Framework and the ITGRCA Overlay by SBR Layer
  • The 2017 NBFC IT Framework: what it still does
  • SBR layer mapping and the NBFC IT overlay
  • Reconciling apparent conflicts between the 2017 IT Framework and the 2023 ITGRCA MD
  • NBFC-specific enforcement: IIFL Finance and JM Financial Products
  • Proportionality for sub-₹500 crore NBFCs: a documented risk statement, not a licence
Module 5: Payments: DPSC, PA Directions 2025, Payment Data Storage, Digital Payment Authentication 2026
  • The DPSC Master Direction: scope and application
  • The 2025 Payment Aggregators Directions: three sub-categories and one repeal list
  • Payment data storage 2018: end-to-end in India, foreign leg permitted
  • The April 2026 Digital Payment Authentication Framework
  • The payments compliance stack for a non-bank PA: the eight-instrument register
Module 6: IT Outsourcing, Cloud, and Third-Party Risk
  • The 2023 IT Outsourcing Master Direction in one page
  • The 2006 Financial Services Outsourcing Guidelines that HDFC was penalised under
  • Cloud without a standalone cloud framework
  • Vendor-risk playbook: due diligence to exit management
  • Pooled audits of common third-party providers
Module 7: Incident Response, Fraud Reporting, and the Multi-Regulator Parallel Clocks
  • The DAKSH portal: six-hour clock for commercial banks
  • The CERT-In Directions 2022 obligation in practice
  • DPDP Rule 7: the 72-hour clock for personal data breaches
  • The 2024 Fraud Risk Management Master Directions: EWS, RFA, and seven-day reporting
  • The single incident record that satisfies four parallel regulator clocks
  • A worked example: ransomware at a bank-cum-PA that is also NCIIPC-designated
Module 8: FREE-AI, Draft Data Governance, Enforcement Pattern, and Crosswalk Capstone
  • The FREE-AI Framework and Board-level AI governance
  • The 15 July 2026 Draft Data Governance Guidance: reading the direction of travel
  • Reading the 2022-2026 RBI enforcement pattern
  • Crosswalk: RBI stack with SEBI CSCRF, IRDAI 2026 Guidelines, NCIIPC and CERT-In
  • Capstone: end-to-end compliance programme for a multi-regulated RE
Module 9: Final Exam and Certificate