The Reserve Bank of India (RBI) on July 31, 2026, issued the Reserve Bank of India (Small Finance Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.
The following has been stated: -
•The Reserve Bank of India (RBI) issued the Reserve Bank of India (Small Finance Banks - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 under the Banking Regulation Act, 1949, taking immediate effect for all Small Finance Banks.
•The guidelines establish a comprehensive governance framework requiring Board-approved policies and a dedicated Board-level IT Strategy Committee to oversee technological risks, resource allocations, and business continuity.
•To ensure robust risk management, banks are mandated to set up an IT Steering Committee, an Information Security Committee, and appoint a qualified Chief Information Security Officer (CISO) who operates independently of the IT Head.
•Additionally, the directions mandate baseline cybersecurity controls including asset management, continuous surveillance, data protection, and incident response mechanisms to maintain operational resilience.
•Finally, the framework requires regular Information Systems (IS) audits overseen by the Audit Committee of the Board to ensure strict regulatory compliance and safeguard banking operations.
These Directions shall come into effect immediately upon issuance.
The detailed directions are given in the document below.
[Notification No.: RBI/DoS/2026-27/419 DoS.CO.CSITEG.13/31.01.015/2026-27]