India

IN · IND · Asia-Pacific · Last verified 2 Sep 2026

14 regulators · 26 instruments · 36 enforcement actions · 9 upcoming deadlines

India — hero image

Direction 2023

RBI Master Direction Information Technology Governance, Risk, Controls and Assurance Practices, 2023

Issued by Reserve Bank of India

Effective: 1 Apr 2024

Plain-English summary

RBI’s Master Direction on IT Governance, Risk, Controls and Assurance Practices 2023 that came into full effect from 1 April 2024, lays out a singular regulatory model for cybersecurity and management of IT infrastructure in Indian banks, major NBFCs, and financial institutions. It makes sure that technical responsibility is directly assigned to the Board of Directors through the creation of IT strategy committees, vendor risk controls, and cybersecurity resilience plans. Through this mandate, it overrides previous circulars and legalizes the operational controls by mandating standardized practices like continuous vulnerability assessments, thorough migration data testing, and disaster recovery plans to ensure no operational hitches and safeguard the banking system from technological risks.

Who it applies to

Banking · NBFC / Non-bank Lending

Topics

Cybersecurity & IT Risk

Official source

Latest news