2026-07-31

Added · Updated

Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

These Directions apply to Commercial Banks, excluding Small Finance Banks, Payments Banks, and Local Area Banks, and come into effect immediately upon issuance. They mandate the establishment of a Board-level IT Strategy Committee with specific composition requirements, including a Chairperson with at least seven years of IT expertise, and require the appointment of a Chief Information Security Officer who reports directly to the Executive Director overseeing risk management. The framework imposes obligations on banks to maintain distinct Information Security and Cybersecurity policies, conduct quarterly reviews of IT governance and cybersecurity risks, and adhere to a 'comply or explain' approach for foreign banks operating in India through branch mode regarding selected chapters.

Reserve Bank of India logo

India

Reserve Bank of India

Scan of the document's first page
Share

RBI published 31 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

DOS Circular No. 66 dated 2026-…DOS Circular No. 66 dated 2026-07-31Reserve Bank of India(Commercial Banks – Cybersecu…2026-07-31 · this documentReserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (2026-07-31)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Reserve Bank of India — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from RBI

RBI published 31 documents in the last 30 days. We email you each new one the day it's published.