2026-07-31
Added · Updated
These Directions apply to Commercial Banks, excluding Small Finance Banks, Payments Banks, and Local Area Banks, and come into effect immediately upon issuance. They mandate the establishment of a Board-level IT Strategy Committee with specific composition requirements, including a Chairperson with at least seven years of IT expertise, and require the appointment of a Chief Information Security Officer who reports directly to the Executive Director overseeing risk management. The framework imposes obligations on banks to maintain distinct Information Security and Cybersecurity policies, conduct quarterly reviews of IT governance and cybersecurity risks, and adhere to a 'comply or explain' approach for foreign banks operating in India through branch mode regarding selected chapters.