2026-07-31

Added · Updated

Reserve Bank of India (Small Finance Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

These Directions apply to Small Finance Banks and mandate the establishment of a Board-level IT Strategy Committee with specific composition requirements, including a Chairperson with at least seven years of IT expertise. Banks must appoint a Chief Information Security Officer who reports directly to the Executive Director overseeing risk management, ensuring independence from the Head of IT Function. The framework requires distinct Information Security and Cybersecurity policies, quarterly meetings for key committees, and the implementation of robust IT governance, risk management, and service management frameworks. Additionally, banks must maintain technology refresh plans to replace unsupported hardware and software before their End-of-Support dates.

Reserve Bank of India logo

India

Reserve Bank of India

Scan of the document's first page
Share

RBI published 31 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Circular No. DoS.CO.PPG.66/11.0…Circular No. DoS.CO.PPG.66/11.01.005/2026-27 dated 2026-07-31Reserve Bank of India (SmallFinance Banks - Cybersecurity…2026-07-31 · this documentReserve Bank of India (Small Finance Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (2026-07-31)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Reserve Bank of India — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from RBI

RBI published 31 documents in the last 30 days. We email you each new one the day it's published.