The Reserve Bank of India (RBI) on November 28, 2025, issued the Reserve Bank of India (Small Finance Banks – Managing Risks in Outsourcing) Directions, 2025 for public comments. The aims to provide a uniform regulatory framework for managing risks arising from outsourcing of both financial and information technology (IT) services by Small Finance Banks (SFBs). It emphasizes that outsourcing does not diminish the responsibilities of the Board and Senior Management, who retain ultimate accountability for the outsourced activities. Existing IT outsourcing agreements must comply with these Directions by April 10, 2026, while new agreements must conform from the date of effect.
The mandates that each bank adopt Board-approved policies for outsourcing of financial and IT services, outlining processes for due diligence, risk evaluation, monitoring, and contingency planning. Core management functions — such as internal audit, compliance, and credit sanctioning — cannot be outsourced. Detailed governance requirements include due diligence of service providers, confidentiality and data security obligations, clear contractual terms covering audit rights, RBI’s access to information, and termination clauses. Special emphasis is placed on managing material outsourcing arrangements that could impact a bank’s operations, profitability, or reputation if disrupted.
Additionally, the introduces detailed provisions for IT outsourcing, including requirements for data protection, business continuity planning, inventory of outsourced services, and controls for cloud computing and offshore outsourcing. Banks must ensure service providers maintain high standards of integrity, security, and operational resilience. The framework seeks to strengthen SFBs’ ability to manage third-party risks effectively, maintain regulatory compliance, and safeguard customer interests.
These Directions shall come into force with immediate effect.
[Notification No. RBI/DOR/2025-26/202 DOR.ORG.REC.No.121/21-04-158/2025-26]