2026-07-31

Added · Updated

Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

These Directions apply to Commercial Banks, excluding Small Finance Banks, Payments Banks, and Local Area Banks, and come into effect immediately upon issuance. They mandate the establishment of a Board-level IT Strategy Committee with specific composition requirements, including a Chairperson with at least seven years of IT expertise, and require the appointment of a Chief Information Security Officer who reports directly to the Executive Director overseeing risk management. The framework imposes obligations on banks to maintain distinct Information Security and Cybersecurity policies, conduct quarterly reviews of IT governance and cybersecurity risks, and adhere to a 'comply or explain' approach for foreign banks operating in India through branch mode regarding selected chapters.

Reserve Bank of India logo

India

Reserve Bank of India

Click to view full text