Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026

Aug 03, 2026 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe Reserve Bank of India (RBI) has issued the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, effective immediately.

The following has been stated:

• The Directions establish a comprehensive framework for strengthening cybersecurity, technology risk management, cyber resilience, and information systems governance in commercial banks by prescribing Board-level oversight, IT governance structures, information security policies, cybersecurity policies, and clearly defined roles and responsibilities for senior management, the Head of IT Function, and the Chief Information Security Officer (CISO).

• Banks are required to implement robust IT and information security risk management frameworks, maintain secure IT architecture and infrastructure, protect information assets through baseline cybersecurity controls, strengthen customer authentication, access management, application security, vulnerability management, business continuity, disaster recovery, cyber incident response, continuous surveillance, and establish Cyber Security Operations Centres (CSOCs) to enhance cyber resilience.

• The Directions also prescribe comprehensive requirements relating to third-party technology arrangements, audit logging, vulnerability assessments, penetration testing, red teaming, employee awareness, customer education, information systems audit, and governance mechanisms to ensure secure, resilient, and technology-driven banking operations.

Please refer to the document attached below for more details.

[RBI/DoS/2026-27/410]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT