The Reserve Bank of India sets cyber security and IT governance expectations for the entities it regulates — banks, NBFCs, cooperative banks and payment operators — through a series of directions and master circulars. There isn't one single document; there are several, and which applies depends on your entity type and size. But common threads run through all of them.
Proportionality is the key idea
The RBI applies its expectations proportionately. A large commercial bank faces the most comprehensive requirements; smaller cooperative banks and NBFCs work to a graded baseline. Getting the scope right — knowing which directions apply to your category — is the first and most important step, because it determines everything that follows.
Recurring expectations across the directions
- Governance: a board-approved cyber security policy and clear accountability.
- A baseline of security controls appropriate to the entity's size and risk.
- Continuous security monitoring, with stronger SOC expectations for larger entities.
- Incident detection and reporting to the RBI within prescribed timelines.
- Business continuity, disaster recovery and defined recovery objectives.
- Governance and risk management of outsourced and third-party arrangements.
- Periodic audits, VAPT and independent assurance.
Scope
Applicable directions
Assess
Gap analysis
Remediate
Close gaps
Evidence
Map to controls
Report
Within timelines
Don't rebuild for every mandate
Much of what the RBI expects overlaps with ISO 27001, PCI DSS and SEBI CSCRF. Rather than running each as a separate programme, map your controls once and reuse the evidence across all of them — which is how Pelta handles overlapping Indian and global frameworks, so an inspection becomes a demonstration rather than a scramble.
RBI directions
- Controls mapped
- Evidence collected
- Policies & procedures in place
Adding SEBI CSCRF
~65% carried overAuto-completed from your existing program
Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.
Frequently asked questions
Who do the RBI cyber security guidelines apply to?+
Entities regulated by the Reserve Bank of India — including banks, NBFCs, cooperative banks and payment system operators. The specific directions and depth of requirements vary by entity category and size.
Are RBI cyber requirements the same for all entities?+
No. The RBI applies expectations proportionately, with the most comprehensive requirements for large, systemically important entities and a graded baseline for smaller ones.
What does the RBI expect for incident reporting?+
Regulated entities are generally expected to detect and report cyber incidents to the RBI within prescribed timelines. Confirm the exact requirements in the directions applicable to you.
Do RBI guidelines overlap with SEBI CSCRF?+
Substantially. Both draw on the same security fundamentals, so controls and evidence can be reused across RBI directions, SEBI CSCRF, ISO 27001 and PCI DSS rather than rebuilt.