RBI
RBI Master Direction — IT Governance, Risk, Controls and Assurance Practices
The Reserve Bank's IT governance and security standard for banks, NBFCs and payment players.
Issuer
Reserve Bank of India
Region
India
In force
Since April 2024
Applies to
Banks, NBFCs, CICs
Overview
What is RBI?
The RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023, effective April 2024) consolidates the Reserve Bank's expectations for how regulated entities govern and secure their technology. It spans IT governance, infrastructure and service management, IT and information-security risk, business continuity, and independent assurance.
It is a board-level obligation: entities must put in place an IT governance framework, an IT Strategy Committee, a CIO and a CISO, and a risk-based information-security programme — and prove it through Information Systems audit. Applicability is graded by entity type and size.
Who needs it: RBI-regulated entities — scheduled commercial banks, small finance and payments banks, NBFCs (per the regulatory tiering), credit information companies and other supervised entities.
Inside the framework
What it covers
IT governance
Board-approved framework, IT Strategy Committee, and designated CIO and CISO with clear roles.
IT infrastructure & services
Change, patch, capacity, cryptography and service management.
IT & information-security risk
A risk framework, risk register, and third-party / outsourcing risk management.
Information & cyber security
Access control, network and application security, monitoring, VAPT and incident response.
Continuity & assurance
Business continuity and DR, plus independent Information Systems audit.
With RegShield
Get RBI-ready in a fraction of the time
AI evidence mapping
Upload a policy, screenshot, or config and RegShield maps it to the right RBI controls in seconds — with confidence scores you can defend in front of an auditor.
Reuse across frameworks
Evidence you collect for RBI is automatically reused across every other framework you've activated — so the work compounds instead of repeating.
Gaps & audit-ready reports
See your RBI readiness score, the exact gaps that remain, and concrete remediation steps — then export an audit-ready report.
FAQ
Common questions
Who does this apply to?
RBI-regulated entities — banks, NBFCs (by tier), payments and small finance banks, credit information companies and similar. The exact requirements are graded by entity type and size.
How does it relate to ISO 27001?
It shares the same security backbone — governance, risk, access control, monitoring, BCP — so ISO 27001 or SOC 2 work carries over substantially. RegShield reuses that evidence and maps it to the RBI Direction.
Does RegShield make us RBI-compliant?
RegShield gets you ready and assembles the evidence and gaps. Compliance and any required IS audit are determined by your auditor and the RBI — RegShield is a readiness tool, not an audit.