Live Founding Cohort open, limited seats remaining Back to main site →

Why you can trust this course

We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.

Legal basis snapshot: RBI Cybersecurity Framework stack current to 10 August 2026. Core instruments: Cyber Security Framework in Banks (DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016); IT Framework for the NBFC Sector (DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017); Storage of Payment System Data (DPSS.CO.OD No.2785/06.08.005/2017-18 dated 6 April 2018); Comprehensive Cyber Security Framework for UCBs — Graded Approach (DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019); Master Direction on Digital Payment Security Controls (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated 18 February 2021); Master Direction on Outsourcing of IT Services (RBI/2023-24/102 dated 10 April 2023); Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024); Master Directions on Fraud Risk Management (RBI/2024-25/47, /48, /49 dated 15 July 2024); Payment Aggregators Directions (RBI/DPSS/2025-26/141 dated 15 September 2025); Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 dated 31 July 2026; FREE-AI Framework Report dated 13 August 2025; Digital Payment Authentication Framework April 2026; Draft Guidance on Regulatory Expectations for Data Governance dated 15 July 2026. Adjacent instruments: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); Banking Regulation Act 1949 Section 35A; Reserve Bank of India Act 1934 Section 45L; IT Act 2000 Section 70B; Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services (2006); Scale-Based Regulation Framework for NBFCs (22 October 2021).

How this RBI Cybersecurity Framework Practitioner Certification register is built

This trust page is the citation register for the RBI Cybersecurity Framework Practitioner Certification course. It cites 25 authorities across 21 statutory instruments, drawn from the legal basis snapshot above (RBI Cybersecurity Framework stack current to 10 August 2026. Core instruments: Cyber Security Framework in Banks (DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016); IT Framework for the NBFC Sector (DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017); Storage of Payment System Data (DPSS.CO.OD No.2785/06.08.005/2017-18 dated 6 April 2018); Comprehensive Cyber Security Framework for UCBs — Graded Approach (DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019); Master Direction on Digital Payment Security Controls (DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated 18 February 2021); Master Direction on Outsourcing of IT Services (RBI/2023-24/102 dated 10 April 2023); Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024); Master Directions on Fraud Risk Management (RBI/2024-25/47, /48, /49 dated 15 July 2024); Payment Aggregators Directions (RBI/DPSS/2025-26/141 dated 15 September 2025); Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 dated 31 July 2026; FREE-AI Framework Report dated 13 August 2025; Digital Payment Authentication Framework April 2026; Draft Guidance on Regulatory Expectations for Data Governance dated 15 July 2026. Adjacent instruments: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); DPDP Act 2023 and DPDP Rules 2025 (Rule 7); Banking Regulation Act 1949 Section 35A; Reserve Bank of India Act 1934 Section 45L; IT Act 2000 Section 70B; Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services (2006); Scale-Based Regulation Framework for NBFCs (22 October 2021).).

Primary sources: RBI Banks Cyber Framework 2016 (3 entries), RBI ITGRCA Master Direction 2023 (3 entries), CERT-In Directions 2022 (1 entry).

Every claim in every RBI Cybersecurity Framework Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below. If a lesson references a specific obligation, click the [Lx-Cy] marker in that lesson to jump to the verbatim text in the register.

Our verification promise

  1. Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the [Lx-Cy] marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013.
  2. Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
  3. Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
  4. Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
9
modules
40
lessons
25
cited authorities
recent
last reviewed

The full citation register

Every authority used in any lesson appears below. Click a row to expand the verbatim text.

CERT-In 6-hour Rule , CERT-In Directions 2022 six-hour incident reporting 28 Apr 2022
Plain summary: CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, effective 27 June 2022. Direction (ii): every service provider, intermediary, data centre, body corporate and Government organisation must mandatorily report cyber incidents of the type specified in Annexure I to CERT-In within six hours of noticing or being brought to notice about such incidents. For an Indian entity handling EU personal data, the 6-hour CERT-In clock runs from detection in parallel with the 72-hour DPDP Rule 7 clock and the 72-hour GDPR Art 33 clock. All three are separate obligations; the incident-response runbook fires all three from a single incident record.
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022. Direction (ii): Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within six hours of noticing such incidents or being brought to notice about such incidents. Direction (iii): Enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days within the Indian jurisdiction.

DPDP Rule 7 , DPDP Rules 2025 Rule 7 breach reporting 13 Nov 2025
Plain summary: DPDP Rule 7 requires a Data Fiduciary to intimate the Data Protection Board of India of a personal data breach without delay and in any event within 72 hours of becoming aware of the breach, and to notify each affected Data Principal in plain-language terms. Runs in parallel with the 6-hour CERT-In clock and, for commercial banks, the 6-hour DAKSH clock under the 31 July 2026 Directions. A single ransomware event at a bank-cum-PA that also handles personal data can trigger four parallel clocks: RBI DAKSH (6h), CERT-In (6h), DPDP Board (72h), and (if the entity is SDF-flagged) SEBI (6h).
DPDP Rules 2025 Rule 7. Intimation of personal data breach. (1) On becoming aware of any personal data breach, a Data Fiduciary shall, without delay, intimate to the Board a description of the breach in the form specified. (2) The Data Fiduciary shall, within 72 hours of becoming aware of the personal data breach, or such longer period as the Board may allow, further intimate to the Board the specified additional information. (3) The Data Fiduciary shall, without delay, intimate every affected Data Principal in a concise, clear and plain manner about the nature of the breach, its likely consequences, mitigation measures, and safety measures the Data Principal may take.

CCMP , Cyber Crisis Management Plan requirement 02 Jun 2016
Plain summary: The 2016 CSF requires every bank to maintain a Cyber Crisis Management Plan (CCMP) that is Board-approved, refreshed periodically, aligned to the National Cyber Crisis Management Plan maintained by CERT-In, and tested through tabletop and technical drills. The CCMP is one of the two mandatory Board-approved cyber artefacts under the 2016 CSF (the other being the Cyber Security Policy).
The Cyber Crisis Management Plan shall be prepared by every bank as part of the Board-approved Cyber Security Policy. The CCMP shall address the following four aspects: (i) Detection; (ii) Response; (iii) Recovery; (iv) Containment. The CCMP shall be aligned to the National Cyber Crisis Management Plan of CERT-In, tested periodically, and reviewed by the Board on a regular basis.
Incident Reporting Template , CSITE incident reporting template and immediacy 02 Jun 2016
Plain summary: Under the 2016 CSF, all unusual cyber security incidents (both successful and attempted) must be reported to RBI CSITE Cell through the specified template. The 2016 language uses "immediately" without specifying an hour count. Supervisory practice through 2024-2026 inherits the CERT-In 6-hour clock. The 31 July 2026 Commercial Banks Cybersecurity Directions have now made the 6-hour reporting via DAKSH explicit for commercial banks.
All unusual cyber security incidents (whether they were successful or were attempted but not successful) should be reported to the Reserve Bank through the format prescribed in Annexure 3. The report should be sent immediately to RBI\'s Cyber Security and IT Examination (CSITE) Cell. Practitioner note: the 2016 language uses "immediately"; the operational clock inherited from the CERT-In Directions 2022 is six hours; the 31 July 2026 Commercial Banks Cybersecurity Directions codify the six-hour DAKSH-based reporting for commercial banks.
Master Circular 2016 , Cyber Security Framework in Banks 02 Jun 2016
Plain summary: RBI Master Circular DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016. First comprehensive RBI cyber circular for commercial banks. Required every bank to have a Board-approved Cyber Security Policy distinct from its IT policy, a Cyber Crisis Management Plan (CCMP) aligned to the National CCMP, cyber risk arrangements with a documented SOC, and CSITE incident reporting through a standard template. Superseded for commercial banks by the 31 July 2026 Commercial Banks Cybersecurity Directions; remains context for non-bank REs until each sub-sector receives its own consolidation.
RBI Master Circular DBS.CO/CSITE/BC.11/33.01.001/2015-16 dated 2 June 2016. Subject: Cyber Security Framework in Banks. Banks shall put in place a Board-approved Cyber Security Policy distinct from the broader IT policy. Banks shall prepare a Cyber Crisis Management Plan (CCMP) as an integral part of their overall Board-approved strategy. All cyber security incidents shall be reported to the Reserve Bank in the prescribed format. The framework applies to all Scheduled Commercial Banks (excluding RRBs).

Commercial Banks Cybersecurity 2026 , Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 31 Jul 2026
Plain summary: RBI Directions dated 31 July 2026 consolidating cyber security obligations for commercial banks into a single instrument. Applies to commercial banks including banking companies, corresponding new banks and the State Bank of India. Excludes Small Finance Banks, Payments Banks, Local Area Banks and Regional Rural Banks. Reporting obligation for cyber security incidents: DAKSH portal within six hours of detection. Security-testing floor: vulnerability assessment every six months, penetration test annually for critical internet-facing systems, half-yearly disaster recovery drills. Board obligations: approve IT policy, cybersecurity policy, information security policy, and business continuity policy; annual review minimum; Board-level IT Strategy Committee. Effectively supersedes the 2016 CSF for commercial banks. Exact RBI reference number to be verified against the rbi.org.in Notifications entry dated 31 July 2026 before quoting in lesson prose.
Reserve Bank of India (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, dated 31 July 2026. Applicability: commercial banks including banking companies as defined under Section 5(c) of the Banking Regulation Act 1949, corresponding new banks as defined under Section 5(da) of the said Act, and the State Bank of India constituted under the State Bank of India Act 1955. Excluded: Small Finance Banks, Payments Banks, Local Area Banks and Regional Rural Banks (governed by separate sector-specific instruments). Incident reporting: any cyber security incident shall be reported through the DAKSH portal within six hours of detection. Security testing: banks shall conduct vulnerability assessment at intervals not exceeding six months, penetration testing at least annually for critical internet-facing systems, and disaster recovery drills at least half-yearly.

DAKSH Portal , DAKSH cyber incident reporting portal 06 Oct 2022
Plain summary: DAKSH (Reserve Bank's Advanced Supervisory Monitoring System) is RBI's web-based end-to-end workflow application launched October 2022. Used by RBI to receive cyber security incident reports from supervised entities and to conduct compliance monitoring. The 31 July 2026 Commercial Banks Cybersecurity Directions codify DAKSH as the reporting channel with a six-hour clock. Earlier references to CIMS in some 2020-2024 material are superseded by DAKSH for cyber incident reporting.
RBI Press Release dated 6 October 2022. Launch of DAKSH — Reserve Bank\'s Advanced Supervisory Monitoring System. DAKSH is a web-based end-to-end workflow application through which RBI shall monitor compliance requirements in a more focused manner with the objective of further improving the compliance culture in Supervised Entities. Supervised Entities shall be able to submit information to RBI in a seamless manner. DAKSH enables the Reserve Bank to have a holistic view of Supervised Entities and enables reporting on cyber security incidents.

Digital Payment Authentication 2026 , RBI Digital Payment Authentication Framework 01 Apr 2026
Plain summary: RBI Digital Payment Authentication Framework notified April 2026. Reinforces the tokenisation-plus-authentication architecture that has been the foundation of Card-on-File Tokenisation live from 1 October 2022. Exact RBI reference number to be pulled from rbi.org.in Notifications for the April 2026 entry before quoting. Interacts with the DPSC Master Direction (2021) and the PA Directions (2025). Course should teach as the current authentication baseline for digital payments.
RBI Digital Payment Authentication Framework, notified April 2026. The Framework builds on the Additional Factor of Authentication regime and the Card-on-File Tokenisation architecture live from 1 October 2022. It sets out risk-based authentication requirements for digital payments, tokenisation-plus-authentication for card transactions at merchants, and Additional Factor of Authentication obligations for non-recurring transactions above prescribed thresholds. Verify exact RBI reference number against the April 2026 entry on rbi.org.in Notifications before printing.

DPSC Master Direction , Digital Payment Security Controls Master Direction 18 Feb 2021
Plain summary: RBI Master Direction DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated 18 February 2021. Applies to all Scheduled Commercial Banks, Small Finance Banks, Payments Banks and Credit-Card-issuing NBFCs. Sets out common minimum standards of security controls for digital payment products and services including internet banking, mobile banking, card payments, and other digital payment applications. Covers governance, product life-cycle security, authentication, fraud risk management, customer protection, awareness, and incident response. Payment Aggregators that do not issue payment instruments themselves reach DPSC obligations indirectly through their acquirer bank.
RBI Master Direction on Digital Payment Security Controls dated 18 February 2021. Applicable to Scheduled Commercial Banks, Small Finance Banks, Payments Banks and Credit-Card issuing NBFCs. The Direction covers governance and management of security risks; generic and specific security controls for internet banking, mobile applications, and card payment applications; authentication requirements; fraud risk management; customer protection; and reporting requirements. Regulated Entities shall put in place the recommended security controls within six months.

Draft Data Governance , RBI Draft Guidance on Data Governance (consultation) 15 Jul 2026
Plain summary: RBI draft Guidance on Regulatory Expectations for Data Governance issued 15 July 2026. Consultation window closes 17 August 2026. Applies to Regulated Entities including SCBs, SFBs, PBs, and NBFCs. Covers data governance, organisational responsibilities, data lifecycle management, data architecture, data quality, and third-party arrangements. Not binding in Aug 2026; course must teach as draft and flag any final notification after 17 August 2026. Verify status against rbi.org.in Notifications after Sep 2026.
RBI Draft Guidance on Regulatory Expectations for Data Governance dated 15 July 2026. This Guidance is applicable to Regulated Entities including Scheduled Commercial Banks (excluding RRBs), Small Finance Banks, Payments Banks and Non-Banking Financial Companies. The Guidance covers (i) Governance and organisational responsibilities including Board-level oversight and data ownership; (ii) Data lifecycle management from acquisition through retention and disposal; (iii) Data architecture; (iv) Data quality management; and (v) Data governance in third-party arrangements. Consultation closes on 17 August 2026.

FRM MDs Consolidation , Three FRM Master Directions supersede 36 legacy circulars 15 Jul 2024
Plain summary: RBI Master Directions RBI/2024-25/47, /48 and /49 issued 15 July 2024. Three separate Master Directions for (a) Scheduled Commercial Banks, All-India Financial Institutions and Small Finance Banks; (b) Cooperative Banks (UCBs, StCBs, CCBs); (c) NBFCs (including HFCs). Consolidates and supersedes 36 earlier fraud-related circulars and directions. Introduces Early Warning Signal (EWS) framework, Red-Flagged Account (RFA) 7-day reporting, RE Board oversight requirements, and updated fraud reporting formats.
RBI Press Release dated 15 July 2024. RBI has issued three Master Directions on Fraud Risk Management for (i) Scheduled Commercial Banks (excluding RRBs), All-India Financial Institutions, and Small Finance Banks; (ii) Cooperative Banks (Urban, State and Central); and (iii) Non-Banking Financial Companies (including Housing Finance Companies). These Master Directions consolidate 36 earlier fraud-related circulars and directions. Key features include a strengthened Early Warning Signal (EWS) framework, Red-Flagged Account (RFA) reporting inside seven days, principles for penal action, and updated Board oversight and fraud reporting timelines.

FREE-AI Report , Framework for Responsible and Ethical Enablement of AI 13 Aug 2025
Plain summary: Report of the RBI-constituted eight-member Committee on Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Indian Financial Sector, released 13 August 2025. Chaired by Dr Pushpak Bhattacharyya of IIT Bombay. Sets out seven "Sutras", strategic pillars, and specific recommendations for RE-level AI governance. Framework document, not a binding Master Direction. RE-level obligations recommended: Board-approved AI Governance Policy, AI Risk Management aligned with existing RBI guidelines, AI impact assessments before launch, model explainability, disclosure to consumers when they interact with AI, and AI-specific grievance redressal.
RBI FREE-AI Framework Report dated 13 August 2025. The Committee on Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Indian Financial Sector was constituted by the Reserve Bank in December 2024 under the chairpersonship of Dr Pushpak Bhattacharyya. The Report articulates seven Sutras for responsible adoption of AI by financial-sector entities. It recommends that Regulated Entities shall put in place a Board-approved AI Governance Policy, undertake AI Risk Management, conduct AI impact assessments before launch of any AI-based solution having material customer impact, adopt explainability standards proportionate to risk, disclose to consumers when they are interacting with an AI system, and put in place AI-specific grievance redressal mechanisms.

Outsourcing Guidelines 2006 , Financial services outsourcing guidelines (still enforced) 03 Nov 2006
Plain summary: RBI Circular DBOD.NO.BP.40/21.04.158/2006-07 dated 3 November 2006. The original RBI outsourcing framework. Continues to apply to outsourcing of financial services (as distinct from IT services which sit under the 2023 IT Outsourcing MD). Confirmed still enforced by the November 2025 HDFC Bank penalty of ₹91 lakh, which cited a 2006 Outsourcing Guidelines contravention (along with a KYC Directions contravention).
RBI Circular DBOD.NO.BP.40/21.04.158/2006-07 dated 3 November 2006. Subject: Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services by banks. The Board of Directors of the bank is responsible for approving and reviewing the risk management practices for outsourcing. The bank shall retain ultimate responsibility for outsourced activity. Material outsourcing arrangements require enhanced governance. Cross-border outsourcing requires additional safeguards. The bank shall have a Board-approved policy on outsourcing.

HDFC Nov 2025 , HDFC Bank penalty citing 2006 Outsourcing Guidelines 01 Nov 2025
Plain summary: RBI Press Release November 2025. Monetary penalty of ₹91 lakh imposed on HDFC Bank Limited for contravention of certain provisions of the RBI Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services by banks dated 3 November 2006 and the Master Direction on Know Your Customer. Illustrates that RBI continues to enforce the 20-year-old 2006 Outsourcing Guidelines against banks in parallel with the 2023 IT Outsourcing Master Direction.
RBI Press Release, November 2025. Monetary penalty of Rupees 91 lakh imposed on HDFC Bank Limited under the provisions of Section 47A read with Section 46 of the Banking Regulation Act 1949, for non-compliance with certain provisions of the Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services by banks dated 3 November 2006 and the Master Direction on Know Your Customer. The action is based on deficiencies in regulatory compliance and is not intended to pronounce upon the validity of any transaction or agreement entered into by the bank with its customers.

IIFL and JM Mar 2024 , IIFL Finance and JM Financial supervisory restrictions 01 Mar 2024
Plain summary: RBI directed IIFL Finance Ltd (4 March 2024) to cease and desist from sanctioning or disbursing gold loans or assigning or securitising or selling any of its gold loans, citing material supervisory concerns in gold loan portfolio governance and IT controls. Two days later, RBI directed JM Financial Products Ltd (5 March 2024) to cease and desist from any form of financing against shares and debentures, citing serious deficiencies in loan governance and IT controls in the IPO-financing book. These cases sit alongside Kotak Mahindra as the leading examples of business-restriction-led enforcement in 2024.
RBI Press Release dated 4 March 2024 (IIFL Finance) and 5 March 2024 (JM Financial Products). RBI has, in exercise of its powers under Section 45L(1)(b) of the Reserve Bank of India Act 1934, directed IIFL Finance Ltd to cease and desist, with immediate effect, from sanctioning or disbursing gold loans or assigning or securitising or selling any of its gold loans. Certain material supervisory concerns were observed in the gold loan portfolio of the company. In a separate action, JM Financial Products Ltd has been directed to cease and desist from doing any form of financing against shares and debentures. Deficiencies were observed in the loan governance and IT controls of the company.

IT Outsourcing MD 2023 , Master Direction on Outsourcing of IT Services 10 Apr 2023
Plain summary: RBI Master Direction RBI/2023-24/102 dated 10 April 2023. Applies to Scheduled Commercial Banks (excluding RRBs), Small Finance Banks, Payments Banks, Local Area Banks, Primary UCBs, non-scheduled Cooperative Banks, All-India Financial Institutions, NBFCs, Credit Information Companies, and EXIM Bank. Introduces a material outsourcing test, mandatory Board-approved Outsourcing Policy, prior approval for material outsourcing arrangements, minimum contract clauses, right of RBI to examine service providers, exit management planning, and specific rules on IT outsourcing to cloud, offshore, and group entities.
RBI Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) dated 10 April 2023. RE shall not outsource core management functions including internal audit, compliance function, and decision-making functions. RE shall have a Board-approved IT and IT-enabled Services Outsourcing Policy. Material outsourcing arrangements shall be subject to enhanced due diligence and prior Board approval. Outsourcing contracts shall include specified minimum clauses covering scope, service levels, security, audit and inspection rights, sub-contracting, business continuity, data protection, exit management, and confidentiality. RE shall retain the right, and shall procure for RBI the right, to inspect the service provider and its records.

IS Audit Cadence , Information Systems Audit annual cadence 07 Nov 2023
Plain summary: ITGRCA Chapter V requires every applicable RE to conduct Information Systems Audit at least once every twelve months. The IS Audit function is independent of the IT function. The IS Audit charter is Board-approved. Auditor competencies must include CISA / CISM / CISSP or equivalent. Findings flow to the Audit Committee of the Board and to the ITSC. Critical findings not closed within stipulated timelines are escalated to the Board.
ITGRCA Master Direction Chapter V. The RE shall conduct an Information Systems (IS) Audit at least once in a year. The IS Audit function shall be independent of the IT function. The Board of Directors shall approve an IS Audit Charter. The IS auditor shall possess required professional certifications such as CISA, CISM, CISSP or equivalent. The IS Audit report shall be placed before the Audit Committee of the Board and the ITSC. Critical observations not closed within the stipulated timeline shall be escalated to the Board.
ITGRCA Applicability , ITGRCA Master Direction applicability perimeter 07 Nov 2023
Plain summary: RBI Master Direction RBI/2023-24/107 dated 7 November 2023, effective 1 April 2024. Applies to Scheduled Commercial Banks (excluding RRBs, LABs, PBs, SFBs, and Cooperative Banks), Non-Banking Financial Companies in Top, Upper and Middle Layer, Credit Information Companies, and All-India Financial Institutions (NABARD, NHB, EXIM Bank, SIDBI, NaBFID). Does NOT apply to Base Layer NBFCs, RRBs, LABs, PBs, SFBs, or Cooperative Banks. Structures IT governance, third-party arrangements, information and cyber security, business continuity, and IS audit and assurance across five chapters.
RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/2023-24/107) dated 7 November 2023, effective from 1 April 2024. Applicability: Scheduled Commercial Banks (excluding Regional Rural Banks, Local Area Banks, Payments Banks, Small Finance Banks and Cooperative Banks), Non-Banking Financial Companies in Top Layer, Upper Layer and Middle Layer, Credit Information Companies, and All-India Financial Institutions.
ITSC and CISO , IT Strategy Committee and CISO independence 07 Nov 2023
Plain summary: ITGRCA Chapter II requires every applicable RE to constitute an IT Strategy Committee (ITSC) of the Board, chaired by an independent director, meeting at least once every quarter. The RE must appoint a full-time Chief Information Security Officer (CISO) of sufficient rank and independence, not reporting through the CTO / CIO or Head of IT. The CISO reports to the RE's risk function or directly to the MD/CEO. The RE must also have an IT Steering Committee (management-level) and an Information Security Committee (management-level, chaired by a senior functionary other than the CTO/CIO).
ITGRCA Master Direction Chapter II. The Board shall constitute an IT Strategy Committee (ITSC), chaired by an independent director with substantial IT expertise, meeting at least once in a quarter. The RE shall appoint a sufficiently senior-level executive with the requisite technical background and expertise as the Chief Information Security Officer (CISO). The CISO shall be responsible for driving the cyber security strategy and shall report to an executive of appropriate rank, not lower than the position of the CRO, or directly to the MD/CEO. The CISO shall not be under the operational hierarchy of the CTO or Head of IT.

Kotak Mahindra 24 Apr 2024 , Kotak Mahindra Bank supervisory business restrictions 24 Apr 2024
Plain summary: RBI Press Release dated 24 April 2024. Directed Kotak Mahindra Bank Limited under Section 35A of the Banking Regulation Act 1949 to cease and desist, with immediate effect, from onboarding new customers through its online and mobile banking channels and from issuing fresh credit cards. Cited serious deficiencies observed in RBI IT inspections of 2022 and 2023 across IT inventory management, patch and change management, user access management, vendor risk management, data security and data leak prevention. Restrictions lifted on 12 February 2025 after remediation. Verbatim order paragraphs must be pulled from the 24 April 2024 press release on rbi.org.in before printing.
RBI Press Release dated 24 April 2024. The Reserve Bank of India has today, in exercise of its powers under Section 35A of the Banking Regulation Act 1949, directed Kotak Mahindra Bank Limited to cease and desist, with immediate effect, from (i) onboarding of new customers through its online and mobile banking channels and (ii) issuing fresh credit cards. This action is necessitated based on significant concerns arising out of the Reserve Bank\'s IT Examination of the bank for the years 2022 and 2023 and the continued failure on part of the bank to address these concerns in a comprehensive and timely manner. Serious deficiencies and non-compliances were observed in the areas of IT inventory management, patch and change management, user access management, vendor risk management, data security and data leak prevention strategy, business continuity and disaster recovery rigour and drill, etc.

NBFC IT Framework 2017 , IT Framework for the NBFC Sector 08 Jun 2017
Plain summary: RBI Master Direction DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017. Applies to NBFCs with asset size of ₹500 crore or above. Covers IT Governance, IT Policy, Information and Cyber Security, IT Operations, IT Audit, BCP, DR, Outsourcing and Fraud Risk Management. Graded provisions inside the framework distinguish NBFCs above ₹500 crore from those below. Still live in Aug 2026 as the standalone NBFC IT baseline, with the 2023 ITGRCA Master Direction layered on top for Top, Upper and Middle Layer NBFCs under the Scale-Based Regulation framework.
RBI Master Direction DNBS.PPD.No.04/66.15.001/2016-17 dated 8 June 2017. Subject: Master Direction - Information Technology Framework for the NBFC Sector. NBFCs with asset size of Rupees 500 crore and above shall put in place an IT Framework covering IT Governance, IT Policy, Information Security, IT Operations, IT Audit, Business Continuity Planning, Disaster Recovery, Outsourcing and Fraud Risk Management. NBFCs with asset size below Rupees 500 crore shall adopt appropriate controls proportionate to their size, complexity and risk exposure.

PA Directions 2025 , Consolidated Payment Aggregators Directions 15 Sep 2025
Plain summary: RBI Directions RBI/DPSS/2025-26/141 dated 15 September 2025. Repeals the 17 March 2020 PA-PG Guidelines, the 31 March 2021 clarifications, and the October 2023 PA-Cross Border Directions. Creates three PA sub-categories: PA-Physical (offline), PA-Online, and PA-Cross Border. Sets minimum net-worth thresholds, KYC obligations, escrow account maintenance, settlement timelines, and data-storage obligations for each sub-category. Non-bank PAs remain outside the direct applicability of the DPSC Master Direction but reach DPSC obligations indirectly through their acquirer bank arrangements.
RBI Directions RBI/DPSS/2025-26/141 dated 15 September 2025. Subject: Payment Aggregators. These Directions apply to non-bank entities providing payment aggregation services either through the physical / offline mode (PA-P), the online / digital mode (PA-O), or the cross-border payment aggregation mode (PA-CB). Minimum net-worth: Rupees 15 crore at the time of application and Rupees 25 crore by end of third financial year of authorisation. Escrow account: all funds received by a PA from a customer shall be maintained in an escrow account with a Scheduled Commercial Bank. Settlement to merchants: T+1 for PA-Online. Data storage: PA shall not store customer card credentials (CoF) within their database or servers.

Payment Data Localisation , RBI Payment Data Storage Direction 2018 06 Apr 2018
Plain summary: RBI Circular DPSS.CO.OD No.2785/06.08.005/2017-2018 dated 6 April 2018 requires all system providers and their service providers, intermediaries, third-party vendors and other entities in the payment ecosystem to store the entire data relating to payment systems operated by them in a system only in India. Data may be processed abroad but must be brought back to India within one business day or 24 hours of processing, whichever is earlier. For an Indian payment-service provider processing EU cardholder data, GDPR Chapter V transfer rules and RBI Payment Data Storage rules both apply; comply with both by design (typically Indian primary storage plus EU-region processing for the EU leg, both with SCCs where cross-border transfer under GDPR applies).
RBI Circular DPSS.CO.OD No.2785/06.08.005/2017-18 dated 6 April 2018. Subject: Storage of Payment System Data. All system providers shall ensure that the entire data relating to payment systems operated by them are stored in a system only in India. For the foreign leg of the transaction, if any, the data can also be stored in the foreign country, if required. In case the processing is done abroad, the data should be deleted from the systems abroad and brought back to India not later than the one business day or 24 hours from payment processing, whichever is earlier.

SBR Layer Mapping , Scale-Based Regulation four-layer NBFC classification 22 Oct 2021
Plain summary: RBI Scale-Based Regulation Framework of 22 October 2021 classifies NBFCs into four layers: Base Layer (BL) for NBFCs with asset size under ₹1,000 crore; Middle Layer (ML) for NBFCs with asset size between ₹1,000 crore and ₹10,000 crore; Upper Layer (UL) for NBFCs identified by RBI as systemically important (typically top 10-15 by scoring methodology); and Top Layer (TL) reserved for NBFCs identified as posing extreme systemic risk. The layer determines which additional RBI instruments apply on top of the 2017 NBFC IT Framework. Base Layer NBFCs sit under the 2017 IT Framework only. Middle, Upper and Top Layer NBFCs sit under both the 2017 IT Framework and the 2023 ITGRCA Master Direction.
RBI Scale-Based Regulation for NBFCs, dated 22 October 2021. NBFCs are classified into four layers: Base Layer, Middle Layer, Upper Layer and Top Layer. Base Layer: NBFCs (i) not accepting public funds and not having customer interface, (ii) NBFC-P2P Lending Platforms, (iii) NBFC-Account Aggregators, (iv) NOFHC, and (v) NBFCs with asset size below Rs 1,000 crore. Middle Layer: NBFCs with asset size of Rs 1,000 crore and above but below Rs 10,000 crore. Upper Layer: NBFCs specifically identified by RBI as warranting enhanced regulatory requirements based on parameters set out in Appendix I. Top Layer: shall ideally remain empty unless RBI identifies specific NBFCs.

UCB Graded Framework , Four-level graded cyber framework for UCBs 31 Dec 2019
Plain summary: RBI Circular DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019. Introduces a graded four-level framework for Urban Cooperative Banks. Level I: basic controls applicable to all UCBs regardless of size. Level II: additional controls for UCBs offering digital banking services. Level III: further controls for larger UCBs / those on centralised banking solutions. Level IV: highest control set for UCBs of systemic significance. Each level embeds baseline controls, endpoint protection, network security, application security, VAPT, incident response, and BCP. Live and unamended as of Aug 2026.
RBI Circular DoS.CO.CSITE.BC.4083/31.01.052/2019-20 dated 31 December 2019. Subject: Comprehensive Cyber Security Framework for Primary (Urban) Cooperative Banks (UCBs) — a Graded Approach. Four levels of controls, with progressively stronger requirements as UCB size, digital banking exposure, and systemic importance increase. Level I applies to all UCBs; Level IV applies to systemically important UCBs.

Found an error? We pay for it.

If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.

  • ₹1,000 credit for the first report of any verifiable factual error.
  • ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
  • Credit on your dcomply Academy account usable against any future course.

We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.

On this page
  • 🟢 Our verification promise
  • 📊 Course statistics
  • 📚 Full citation register
  • 🐛 Bug bounty for errors

Maintained by the dcomply Academy editorial team. Last reviewed recently.