The Reserve Bank of India (RBI) has issued the Reserve Bank of India (Local Area Banks – Miscellaneous) Supervisory Directions, 2026, with immediate effect under Section 35-A of the Banking Regulation Act, 1949. The Directions apply to all Local Area Banks (LABs) and consolidate the regulatory framework relating to fair lending practices, inoperative accounts, fraud prevention, vigilance, protected disclosures, network management, and cyber security controls. They also prescribe governance requirements for third-party ATM switch service providers.
The Directions require LABs to adopt fair practices in charging interest, strengthen controls over inoperative accounts and unclaimed deposits, implement comprehensive fraud prevention measures, and establish procedures for protected disclosures (whistleblower mechanism) and vigilance administration. They also mandate preventive vigilance measures, staff rotation, complaint handling, and coordination with investigative agencies to strengthen governance and operational integrity.
Further, the Directions introduce a detailed framework for network management and cyber security controls applicable to third-party ATM switch application service providers. They define key cybersecurity concepts, prescribe measures for enhancing cyber resilience, and aim to strengthen the security of banking technology infrastructure while repealing earlier instructions on matters covered under these Directions.
[Notification No. RBI/DoS/2026-27/452]