Levitation Logo
RBI Compliance

RBI Cyber Security
& IS Audit Compliance

We help banks and NBFCs meet the RBI IT Governance, Risk, Controls and Assurance Directions: gap assessment, VA/PT and control remediation, BCP-DR, and IS-audit readiness.

What do the RBI directions require?

The RBI IT Governance, Risk, Controls and Assurance Practices Directions require banks and larger NBFCs to put formal IT governance, cyber-security controls, vulnerability assessment and penetration testing (VA/PT), an independent Information Systems (IS) audit, and business-continuity / disaster-recovery capability in place, and to keep them running on an ongoing cycle. They apply to scheduled commercial banks, small finance banks, payments banks, NBFCs in the Top, Upper and Middle layers, credit information companies and all-India financial institutions (base-layer NBFCs are outside scope). Separate RBI directions on the outsourcing of IT services add vendor due-diligence, audit-rights and exit/BCP requirements. These obligations are in force and the IS-audit and VA/PT cycles recur rather than being one-time.

Who must comply

Banks and larger NBFCs

The depth of what you need scales with your entity layer. Base-layer NBFCs are outside the IT-governance direction, but the outsourcing and cyber-security expectations still reach most regulated lenders.

  • Scheduled commercial banks
  • Small finance banks and payments banks
  • NBFCs in the Top, Upper and Middle layers
  • Credit Information Companies (CICs)
  • All-India Financial Institutions (AIFIs)
  • Entities that outsource IT or run on cloud (RBI IT-outsourcing directions)
The directions

What RBI compliance requires

These are the control areas a bank or NBFC programme has to build and keep running under the RBI directions.

IT governance

A Board-level IT strategy committee, an IT governance framework, and clear roles and accountability for technology risk.

VA/PT

Vulnerability assessment and penetration testing of critical applications and infrastructure, with tracked remediation.

IS audit

An independent Information Systems audit with defined scope and cadence, conducted by an appointed auditor.

Cyber security controls

Access control, logging, encryption, network security and secure configuration across critical systems.

BCP & DR

Business-continuity and disaster-recovery capability with periodic drills that prove recovery objectives.

Incident response

Detection, response and reporting processes for cyber incidents, within the required timelines.

IT outsourcing governance

Vendor due-diligence, audit rights, exit and BCP clauses, and cloud controls under the RBI IT-outsourcing directions.

Risk & assurance

IT risk management and assurance practices embedded in day-to-day operations, not just at audit time.

How we help

From gap assessment to IS-audit ready

Gap assessment

We map your controls against the RBI directions for your bank or NBFC layer and produce a prioritized remediation plan.

VA/PT, engineering & remediation

We run our own vulnerability assessment and penetration testing to surface issues, then build and fix the controls: access, logging and SIEM, encryption, secure SDLC and network segmentation.

BCP-DR & monitoring

We design and build the business-continuity / DR architecture and the monitoring, alerting and incident-response plumbing.

IS-audit readiness

We assemble the evidence, policies and documentation so the independent IS audit your entity commissions passes cleanly.

How we work

A repeatable RBI compliance programme

01

Discovery & scoping

We confirm your entity layer and inventory the systems and data in scope.

02

Gap assessment

A control-by-control review against the RBI directions, with a prioritized roadmap.

03

Remediation & build

Engineering the missing controls, running VA/PT, and fixing issues in reviewable sprints.

04

IS audit & ongoing cycle

Evidence for the IS audit, plus a plan for the recurring VA/PT and audit cadence.

Why Levitation

We build banking-grade systems every day

Fintech and banking is a core industry for us, so RBI control work is not a side project. We run our own VA/PT, remediate the actual systems, and build the BCP-DR and monitoring the directions expect, then hand your IS auditor a clean, well-documented environment instead of a pile of open findings.

Fintech & banking focusIn-house VA/PTBCP-DR & monitoringIS-audit readiness
8+
years building for regulated industries
300+
projects delivered
100%
client retention
FAQ

Frequently asked questions

What do the RBI IT governance directions require?

They require banks and larger NBFCs to establish IT governance, cyber-security controls, vulnerability assessment and penetration testing, an independent Information Systems (IS) audit, and business-continuity / disaster-recovery capability, and to keep them running on an ongoing basis rather than as a one-time project.

Who has to comply?

Scheduled commercial banks, small finance banks, payments banks, NBFCs in the Top, Upper and Middle layers, credit information companies, and all-India financial institutions. Base-layer NBFCs are outside the IT-governance direction’s scope. If you outsource IT or run on cloud, the RBI IT-outsourcing directions also apply.

Is this a one-time exercise?

No. The VA/PT and IS-audit obligations recur, so you need a repeatable programme with monitoring and periodic testing, not a single audit before a deadline.

Does Levitation conduct the IS audit?

Our role is the engineering side: gap assessment, our own VA/PT to find and fix issues, control remediation, BCP/DR, and preparing the evidence so your audit passes. The statutory independent IS audit itself is conducted by the auditor your entity appoints — we get you audit-ready for it.

How does IT outsourcing and cloud fit in?

If you rely on IT vendors or cloud, RBI’s outsourcing directions require vendor due-diligence, audit rights, and exit / BCP terms. We put the technical controls and the documentation side of that in place so your outsourcing arrangements are compliant and auditable.

Get an RBI compliance gap assessment

Tell us your entity type and systems, and we will map exactly what the RBI directions need from you and what it takes to get IS-audit ready.

Talk to our team
Related