2026-07-31

Added · Updated

Reserve Bank of India (Payments Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

These Directions apply to Payments Banks and require the Board of Directors to approve and annually review strategies and policies for Information Technology, Information Assets, Business Continuity, Information Security, and Cybersecurity. Banks must establish a Board-level IT Strategy Committee with specific composition requirements, including a chairperson with substantial IT expertise, and meet quarterly to oversee IT governance, risk management, and budgetary allocations. The framework mandates the appointment of a Chief Information Security Officer who reports directly to the Executive Director overseeing risk management, ensuring the CISO has no direct reporting line to the Head of IT Function and holds no business targets. Additionally, banks are required to implement robust IT Governance, Information Security, and Cybersecurity policies, maintain an IT Steering Committee, and ensure effective management of IT risks, architecture, and service delivery.

Reserve Bank of India logo

India

Reserve Bank of India

Scan of the document's first page
Share

RBI published 31 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Circular No. DoS.CO.PPG.66/11.0…Circular No. DoS.CO.PPG.66/11.01.005/2026-27 dated 2026-07-31Reserve Bank of India(Payments Banks - Cybersecuri…2026-07-31 · this documentReserve Bank of India (Payments Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (2026-07-31)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Reserve Bank of India — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from RBI

RBI published 31 documents in the last 30 days. We email you each new one the day it's published.