What Happened?
On 31 July 2026, the Reserve Bank of India (RBI) issued the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 under Circular RBI/DoS/2026-27/410. These directions apply immediately to all commercial banks (excluding Small Finance Banks, Payments Banks, and Local Area Banks) operating in India. Foreign banks operating through branch mode must follow a 'comply or explain' approach for select provisions. This is a landmark regulation that consolidates IT governance and cybersecurity requirements into a single, comprehensive framework replacing all previous circulars on this subject.
Background & Legal Context
The RBI issued these directions under Section 27 and Section 35-A of the Banking Regulation Act, 1949, and Section 45(U) of the Reserve Bank of India Act, 1934. While these directions are not directly part of the Income Tax Act 2025, they are critical regulatory compliance obligations that banks must meet. Non-compliance can result in RBI penalties, which may have indirect tax implications for banks under Section 36 of the Income Tax Act 2025 (deductibility of fines and penalties is restricted).
Key Legal Framework Involved:
- Banking Regulation Act, 1949 – Parent law for RBI directions
- Reserve Bank of India Act, 1934 – RBI's statutory authority
- Information Technology Act, 2000 – For cybersecurity standards
- Companies Act, 2013 – For Board governance requirements
- Income Tax Act 2025, Section 36 – Regarding deductibility of RBI penalties
These directions supersede all previous RBI guidelines on Cybersecurity Framework and IT Governance (repealed vide Circular DoS.CO.PPG.66/11.01.005/2026-27 dated 31 July 2026).
What Does This Mean for You?
For Commercial Banks:
- Board-Level Oversight: Your Board must approve IT strategy, cybersecurity policy, and business continuity plans annually. The IT Strategy Committee (ITSC) must have minimum three directors with the Chairperson being an independent director with 7+ years IT expertise (Paragraph 17).
- Chief Information Security Officer (CISO) Appointment: You must designate a senior-level executive (General Manager rank or equivalent) as CISO who reports directly to the Executive Director overseeing risk management. Critically, the CISO cannot report to the Head of IT Function and cannot be given business targets (Paragraph 27). This ensures independent oversight of cybersecurity.
- Mandatory Cyber Security Operations Centre (CSOC): You must establish a 24x7 CSOC with Level 1, 2, and 3 personnel. Level 1 monitors continuously, Level 2 provides specialized expertise in network/data security, and Level 3 comprises advanced analysts with forensic knowledge (Paragraphs 212-223).
- Incident Reporting Requirement: You must report any cyber incident within 6 hours of detection on the DAKSH platform (RBI's Advanced Supervisory Monitoring System). Additionally, you must proactively notify CERT-In (Indian Computer Emergency Response Team) (Paragraph 182). Non-compliance can attract penalties under RBI regulations.
- Vulnerability Assessment & Penetration Testing: Critical internet-facing systems require VA every 6 months and PT every 12 months. These must be conducted by CERT-In empanelled auditors (Paragraphs 151-155). This is mandatory—no exceptions.
- Data Protection & Encryption: You must implement strong cryptographic controls using internationally accepted standards (Paragraph 140). All sensitive customer data must be encrypted at rest and in transit. Data migration must maintain audit trails with sign-offs (Paragraph 55).
- Third-Party Risk Management: If you use ATM Switch Application Service Providers (ASPs), you must ensure they comply with 39 baseline cybersecurity controls detailed in Paragraph 136-138. These must be mandated in your contracts.
- Business Continuity & Disaster Recovery: Your DR architecture must achieve minimal Recovery Time Objective (RTO) and near-zero Recovery Point Objective (RPO) for critical systems (Paragraph 171). DR drills must be conducted at least half-yearly for critical systems, involving actual switch-over to DR site for a full working day (Paragraph 167).
For Internal Audit Functions:
- You must establish a separate Information Systems (IS) Audit function with risk-based audit planning (Paragraph 228). The Audit Committee of the Board must oversee this and approve the IS Audit Policy (Paragraph 225).
- Consider continuous auditing for critical systems (Paragraph 229).
Tax & Compliance Impact:
Under Section 36 of the Income Tax Act 2025, fines and penalties paid to RBI are not deductible. Therefore, if your bank incurs RBI penalties for non-compliance with these cybersecurity directions, such penalties cannot reduce your taxable income. This makes compliance economically essential.
For Foreign Banks (Branch Mode):
You can follow a 'comply or explain' approach for select chapters (II, III, IV, VII) and specific paragraphs in Chapter V. However, you must submit reasonably justifiable explanations to RBI for any deviations, which will be evaluated during supervisory examinations.
What Should You Do Now?
Immediate Actions (August-September 2026):
- Review Compliance Status: Audit your current IT governance structure against the 8 chapters and 233 paragraphs in these directions. Identify gaps in Board committees, CISO authority, and cybersecurity policies.
- Strengthen Board Governance: If your ITSC doesn't meet quarterly or lacks independent director expertise, restructure immediately. Ensure the CISO reports independently to risk management.
- Establish/Upgrade CSOC: If you lack a 24x7 CSOC, establish one with SIEM (Security Information and Event Management) tools. Recruit or engage managed service providers for Level 2 and Level 3 staffing. Budget for this is non-negotiable—it directly impacts cyber resilience.
- Create Incident Response Plan: Document your cyber incident response procedure with clear escalation paths to Board, Senior Management, CERT-In, and customers. Conduct drills quarterly.
- Schedule VA/PT Audits: Identify your critical and internet-facing systems. Engage CERT-In empanelled auditors to begin VA immediately if not done in last 6 months. Schedule PT if not done in last 12 months.
- Update Vendor Contracts: For ATM Switch ASPs and other third-party IT service providers, amend contracts to include the 39 baseline cybersecurity controls from Paragraph 136-138. Conduct due diligence audits of current providers.
- Document All Policies: Ensure written policies exist for Data Migration (Paragraph 55), Patch Management (Paragraph 98), Change Management (Paragraph 98), Teleworking (Paragraph 114), and Removable Media (Paragraph 122).
- Communicate with Auditors: Brief your internal and external auditors about these new RBI directions. Update your audit charter to reflect IS Audit requirements (Paragraphs 224-229).
Medium-Term Actions (October 2026 - March 2027):
- Conduct full Business Continuity and DR testing with documented outcomes.
- Implement multi-factor authentication for all privileged users (Paragraph 110).
- Deploy anti-malware, antivirus, and behavioral detection across all endpoints (Paragraph 145).
- Complete source code audits of critical applications (Paragraph 91).
- Train Board members and Senior Management on cybersecurity risks (Paragraph 204).
Key Takeaways
- Comprehensive Framework: These directions replace all previous RBI cybersecurity circulars and create a unified IT governance and cybersecurity framework for all commercial banks effective immediately.
- Board Accountability: IT strategy and cybersecurity are now Board-level responsibilities. Independent ITSC with technical expertise is mandatory—this is non-negotiable compliance.
- CISO Independence: The CISO must be independent of IT operations and report to risk management. This prevents conflicts of interest and strengthens oversight.
- Incident Reporting is Mandatory: 6-hour reporting to DAKSH and proactive CERT-In notification for all cyber incidents. Non-compliance can attract RBI penalties (non-deductible under Income Tax Act 2025, Section 36).
- Third-Party Accountability: Banks remain liable for cybersecurity lapses at vendor sites. 39 baseline controls for ASPs must be contractually mandated and monitored continuously.
Important Note: These directions create a significant compliance burden but are essential for systemic financial stability. Non-compliance exposes banks to RBI action, customer litigation, reputational damage, and potential income tax implications (e.g., penalty denial under Section 36). The directions align Indian banking cybersecurity standards with global best practices and international frameworks like ISO 27001 and NIST guidelines.
Need expert help with this? EaseValue CAs in Jaipur — WhatsApp 63677 44602
EaseValue