2026-07-31

Added · Updated

Reserve Bank of India (All India Financial Institutions – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

These Directions apply to All-India Financial Institutions (AIFIs), specifically EXIM Bank, NABARD, SIDBI, NHB, and NaBFID, and come into force with immediate effect. AIFIs must establish a Board-level IT Strategy Committee with specific composition requirements, including a chairperson with at least seven years of IT expertise, and meet quarterly to oversee IT strategy, risk management, and budgetary allocations. The framework mandates the appointment of a Chief Information Security Officer who reports directly to the executive overseeing risk management, distinct from the Head of IT Function, and requires the implementation of robust IT governance, cybersecurity policies, and risk management frameworks. Additionally, AIFIs are required to maintain specific committees, define clear roles for senior management and IT leadership, and adhere to standards for IT architecture, service management, and technology refresh cycles.

Reserve Bank of India logo

India

Reserve Bank of India

Scan of the document's first page
Share

RBI published 31 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Circular No. DoS.CO.PPG.66/11.0…Circular No. DoS.CO.PPG.66/11.01.005/2026-27 dated 2026-07-31Reserve Bank of India (AllIndia Financial Institutions …2026-07-31 · this documentReserve Bank of India (All India Financial Institutions – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (2026-07-31)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Reserve Bank of India — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from RBI

RBI published 31 documents in the last 30 days. We email you each new one the day it's published.