RBI\'s Cyber Security and IT Examination (CSITE) Cell conducts periodic IT inspections of Regulated Entities. Findings are recorded as "observations" and issued to the entity for response and remediation. Serious or repeated observations flow to enforcement action. Both the 24 April 2024 Kotak Mahindra Bank supervisory restrictions [L4-C1] and the November 2025 HDFC Bank penalty [L4-C2] trace back to CSITE inspection observations that the entity did not close.
A CSITE observation typically has four parts: (a) the factual finding, (b) the specific instrument and paragraph the finding cites, (c) the risk statement, and (d) an implicit remediation window. Reading each part correctly is what allows the CISO to prioritise the response.
Worked example: Kotak Mahindra Bank (2022, 2023 inspections)
The 24 April 2024 RBI Press Release directing Kotak Mahindra Bank to cease onboarding new customers through online / mobile banking channels and to stop issuing fresh credit cards was based on IT inspection observations of 2022 and 2023 that the bank did not close in a comprehensive and timely manner. The Press Release lists the areas of deficiency:
- IT inventory management
- Patch and change management
- User access management
- Vendor risk management
- Data security and data leak prevention strategy
- Business continuity and disaster recovery rigour and drill
The important pattern is: these are not obscure items. They are the operational areas any bank\'s cyber programme has to cover. The Press Release also identifies the mechanism of concern: continued failure on part of the bank to address these concerns in a comprehensive and timely manner. The enforcement action is not about the observation itself. It is about the compounding effect of an unclosed observation.
The two-question reading rule
Every CSITE observation your team receives, ask these two questions in this order:
- Which instrument and paragraph does this cite? If the observation says "vendor risk management framework needs strengthening", the underlying obligations are: the 2023 IT Outsourcing MD (RBI/2023-24/102) plus the 2006 Financial Services Outsourcing Guidelines plus (for commercial banks) the 31 July 2026 Directions plus (for applicable REs) the 2023 ITGRCA MD Chapter III on third-party arrangements. Your response must show you have reconciled the observation against every applicable instrument, not just one.
- What is the reasonable remediation window? RBI does not always publish an explicit remediation deadline in the observation. The reasonable window is a function of the risk. A patch-management gap on internet-facing systems is measured in days. A CISO independence issue is measured in weeks. A Board-policy bifurcation is measured in the next Board cycle. If you cannot articulate the window internally, you have not read the observation.
Enforcement escalation pattern
Based on the 2022-2026 RBI actions, the escalation pattern is:
- Observation issued. RE responds; RBI reviews; if satisfactory, closed.
- Observation carried over. Not closed at first review; escalated to a follow-up inspection.
- Repeat observation. Same issue appears in a second consecutive inspection. This is the trigger point for enforcement.
- Monetary penalty or supervisory action. Penalty for a discrete contravention (HDFC pattern) or business restriction for compounding IT governance failure (Kotak pattern).
- Remediation and lifting. Restrictions lifted after RBI is satisfied on remediation (Kotak restrictions lifted 12 February 2025).
The point of the escalation pattern is that observations issued today are enforcement actions tomorrow if not closed. This is why the CISO cannot delegate observation-tracking to a junior analyst without oversight. The IT Strategy Committee should see the open observations register at every meeting, with age and remediation plan against each item.
What a defensible response looks like
Response to a CSITE observation is not a compliance form-fill. It is a document that will be read by supervisors and by future inspectors. A defensible response has:
- Acknowledgement of the observation without minimising it
- Citation of the specific instrument(s) and paragraphs the observation touches
- Root-cause analysis of why the gap exists
- Concrete remediation actions with owners and dates
- Compensating controls in place until remediation completes
- Board / ITSC visibility route for the remediation
- Independent-assurance route (Internal Audit or an external CERT-In empanelled auditor) to confirm closure
If the response cannot show all seven, the observation is likely to recur. And recurrence is what triggers the escalation pattern above.