How the RBI frames cyber and IT expectations
Rather than a single document, the RBI's expectations are set out across directions and master circulars that differ by entity type and size — with proportionately deeper requirements for larger and more systemically important entities. Common threads run through all of them: board-level governance, a baseline of security controls, continuous monitoring, prompt incident reporting, and disciplined management of outsourcing and third-party risk.
Recurring expectations
- Board-approved cyber security policy and a clearly accountable governance structure.
- A baseline of security controls appropriate to the entity's size and risk.
- Continuous security monitoring, with stronger SOC expectations for larger entities.
- Incident detection and reporting to the RBI within prescribed timelines.
- Business continuity, disaster recovery and defined recovery objectives.
- Governance and risk management of outsourced and third-party arrangements.
- Periodic audits, VAPT and independent assurance.
Scope
Applicable directions
Assess
Gap analysis
Remediate
Close gaps
Evidence
Map to controls
Report
Within timelines
Proportionality matters
The RBI applies its expectations proportionately: a large commercial bank faces the most comprehensive requirements, while smaller cooperative banks and NBFCs work to a graded baseline. Getting the scope right — knowing which directions apply to your category — is the first and most important step.
Common pitfalls to avoid
- Assuming one set of requirements applies uniformly, rather than by entity category and size.
- Under-investing in incident reporting readiness and the associated timelines.
- Overlooking outsourcing and third-party risk, which the RBI scrutinises closely.
- Keeping evidence in scattered systems, so supervisory reviews become a scramble.