RBI Cyber Security
& IS Audit Compliance
We help banks and NBFCs meet the RBI IT Governance, Risk, Controls and Assurance Directions: gap assessment, VA/PT and control remediation, BCP-DR, and IS-audit readiness.
The RBI IT Governance, Risk, Controls and Assurance Practices Directions require banks and larger NBFCs to put formal IT governance, cyber-security controls, vulnerability assessment and penetration testing (VA/PT), an independent Information Systems (IS) audit, and business-continuity / disaster-recovery capability in place, and to keep them running on an ongoing cycle. They apply to scheduled commercial banks, small finance banks, payments banks, NBFCs in the Top, Upper and Middle layers, credit information companies and all-India financial institutions (base-layer NBFCs are outside scope). Separate RBI directions on the outsourcing of IT services add vendor due-diligence, audit-rights and exit/BCP requirements. These obligations are in force and the IS-audit and VA/PT cycles recur rather than being one-time.
Banks and larger NBFCs
The depth of what you need scales with your entity layer. Base-layer NBFCs are outside the IT-governance direction, but the outsourcing and cyber-security expectations still reach most regulated lenders.
- Scheduled commercial banks
- Small finance banks and payments banks
- NBFCs in the Top, Upper and Middle layers
- Credit Information Companies (CICs)
- All-India Financial Institutions (AIFIs)
- Entities that outsource IT or run on cloud (RBI IT-outsourcing directions)
What RBI compliance requires
These are the control areas a bank or NBFC programme has to build and keep running under the RBI directions.
IT governance
A Board-level IT strategy committee, an IT governance framework, and clear roles and accountability for technology risk.
VA/PT
Vulnerability assessment and penetration testing of critical applications and infrastructure, with tracked remediation.
IS audit
An independent Information Systems audit with defined scope and cadence, conducted by an appointed auditor.
Cyber security controls
Access control, logging, encryption, network security and secure configuration across critical systems.
BCP & DR
Business-continuity and disaster-recovery capability with periodic drills that prove recovery objectives.
Incident response
Detection, response and reporting processes for cyber incidents, within the required timelines.
IT outsourcing governance
Vendor due-diligence, audit rights, exit and BCP clauses, and cloud controls under the RBI IT-outsourcing directions.
Risk & assurance
IT risk management and assurance practices embedded in day-to-day operations, not just at audit time.
From gap assessment to IS-audit ready
Gap assessment
We map your controls against the RBI directions for your bank or NBFC layer and produce a prioritized remediation plan.
VA/PT, engineering & remediation
We run our own vulnerability assessment and penetration testing to surface issues, then build and fix the controls: access, logging and SIEM, encryption, secure SDLC and network segmentation.
BCP-DR & monitoring
We design and build the business-continuity / DR architecture and the monitoring, alerting and incident-response plumbing.
IS-audit readiness
We assemble the evidence, policies and documentation so the independent IS audit your entity commissions passes cleanly.
A repeatable RBI compliance programme
Discovery & scoping
We confirm your entity layer and inventory the systems and data in scope.
Gap assessment
A control-by-control review against the RBI directions, with a prioritized roadmap.
Remediation & build
Engineering the missing controls, running VA/PT, and fixing issues in reviewable sprints.
IS audit & ongoing cycle
Evidence for the IS audit, plus a plan for the recurring VA/PT and audit cadence.
We build banking-grade systems every day
Fintech and banking is a core industry for us, so RBI control work is not a side project. We run our own VA/PT, remediate the actual systems, and build the BCP-DR and monitoring the directions expect, then hand your IS auditor a clean, well-documented environment instead of a pile of open findings.
Frequently asked questions
What do the RBI IT governance directions require?
They require banks and larger NBFCs to establish IT governance, cyber-security controls, vulnerability assessment and penetration testing, an independent Information Systems (IS) audit, and business-continuity / disaster-recovery capability, and to keep them running on an ongoing basis rather than as a one-time project.
Who has to comply?
Scheduled commercial banks, small finance banks, payments banks, NBFCs in the Top, Upper and Middle layers, credit information companies, and all-India financial institutions. Base-layer NBFCs are outside the IT-governance direction’s scope. If you outsource IT or run on cloud, the RBI IT-outsourcing directions also apply.
Is this a one-time exercise?
No. The VA/PT and IS-audit obligations recur, so you need a repeatable programme with monitoring and periodic testing, not a single audit before a deadline.
Does Levitation conduct the IS audit?
Our role is the engineering side: gap assessment, our own VA/PT to find and fix issues, control remediation, BCP/DR, and preparing the evidence so your audit passes. The statutory independent IS audit itself is conducted by the auditor your entity appoints — we get you audit-ready for it.
How does IT outsourcing and cloud fit in?
If you rely on IT vendors or cloud, RBI’s outsourcing directions require vendor due-diligence, audit rights, and exit / BCP terms. We put the technical controls and the documentation side of that in place so your outsourcing arrangements are compliant and auditable.
Get an RBI compliance gap assessment
Tell us your entity type and systems, and we will map exactly what the RBI directions need from you and what it takes to get IS-audit ready.
Talk to our team