How the RBI frames cyber and IT expectations
Rather than a single document, the RBI's expectations are set out across directions and master circulars that differ by entity type and size, with proportionately deeper requirements for larger and more systemically important entities. Common threads run through all of them: board-level governance, a baseline of security controls, continuous monitoring, prompt incident reporting, and disciplined management of outsourcing and third-party risk.
Recurring expectations
- Board-approved cyber security policy and a clearly accountable governance structure.
- A baseline of security controls appropriate to the entity's size and risk.
- Continuous security monitoring, with stronger SOC expectations for larger entities.
- Incident detection and reporting to the RBI within prescribed timelines.
- Business continuity, disaster recovery and defined recovery objectives.
- Governance and risk management of outsourced and third-party arrangements.
- Periodic audits, VAPT and independent assurance.
Scope
Applicable directions
Assess
Gap analysis
Remediate
Close gaps
Evidence
Map to controls
Report
Within timelines
Proportionality matters
The RBI applies its expectations proportionately: a large commercial bank faces the most comprehensive requirements, while smaller cooperative banks and NBFCs work to a graded baseline. Getting the scope right (knowing which directions apply to your category) is the first and most important step.
Common pitfalls to avoid
- Assuming one set of requirements applies uniformly, rather than by entity category and size.
- Under-investing in incident reporting readiness and the associated timelines.
- Overlooking outsourcing and third-party risk, which the RBI scrutinises closely.
- Keeping evidence in scattered systems, so supervisory reviews become a scramble.