Cybersecurity

RBI Cybersecurity Requirements for NBFCs

Affix Center · · 6 min read

RBI Cybersecurity Requirements for NBFCs - Affix Center

NBFCs now run most of their business on digital systems: loan origination apps, collection platforms, core lending software and partner APIs. That makes them attractive targets for fraud, ransomware and data theft. The Reserve Bank of India has responded with detailed directions, and understanding the RBI cybersecurity requirements for NBFCs is no longer just a task for the IT head. Boards, risk teams and business heads are all accountable.

The practical challenge is that the requirements sit across several documents, and many NBFCs rely heavily on vendors for technology. Compliance often turns into a last-minute scramble before inspection. This guide summarises the key expectations in plain English and suggests how to organise the work so it becomes routine rather than a yearly rush. Always read the original RBI texts and take professional advice for your specific category.

RBI Cybersecurity Requirements for NBFCs: The Main Directions

IT Governance, Risk, Controls and Assurance Practices

RBI issued the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices on 7 November 2023, effective from 1 April 2024. For NBFCs, it applies to entities in the Top, Upper and Middle Layers under the scale-based regulation framework. It covers governance, IT and information security risk management, business continuity and disaster recovery, and information systems audit.

Outsourcing of Information Technology Services

The Master Direction on Outsourcing of IT Services was issued on 10 April 2023 and came into effect on 1 October 2023. It applies to NBFCs along with banks and other regulated entities, and sets rules for selecting, contracting with and monitoring technology vendors.

CERT-In directions

Beyond RBI, the CERT-In directions of April 2022 require organisations in India to report specified cyber incidents to CERT-In within six hours of noticing them, and to keep system logs for a defined period. These apply to NBFCs as well.

Base Layer NBFCs fall outside the scope of the 2023 IT governance direction, but they are still expected to manage IT and cyber risk sensibly. Check the instructions that apply to your category.

Governance: What the Board Must Own

RBI places clear responsibility on the board and senior management. Key expectations under the IT governance direction include:

  • IT Strategy Committee: A board-level committee that meets at least once a quarter and oversees IT strategy, resources and risk.
  • Senior CISO: A senior executive designated as Chief Information Security Officer. The CISO should not report directly to the head of IT and should not carry business targets.
  • Board-approved policies: Information security, cyber security, IT risk, business continuity and IT outsourcing policies, reviewed periodically.
  • Risk oversight: The Risk Management Committee should review IT and cyber risks at least once a year.

A common gap is having the right committees on paper but no meaningful reporting to them. Give the board a short, regular dashboard: open high-risk vulnerabilities, incidents, audit findings, vendor risks and DR test results.

Security Controls and Testing

The direction expects a structured control environment, not just antivirus and a firewall. Priority areas include:

  1. Asset inventory: Keep an up-to-date list of hardware, software, data and interfaces, classified by criticality.
  2. Access control: Least privilege, multi-factor authentication for privileged and remote access, and regular access reviews.
  3. Patch and vulnerability management: For critical information systems, vulnerability assessment at least once every six months and penetration testing at least once every twelve months.
  4. Logging and monitoring: Applications that handle sensitive data need audit and system logs, with alerts reviewed by a security operations function.
  5. Secure development and change management: Security testing before new apps or major changes go live, and controlled data migration with sign-offs and audit trails.
  6. Encryption: Use accepted, non-deprecated cryptographic standards for data at rest and in transit.

Our cybersecurity services can support testing, monitoring and control reviews so your team has evidence ready for supervisors.

Business Continuity and Disaster Recovery

An NBFC that cannot disburse or collect for a few days faces real financial and reputational damage. The direction asks for a documented BCP and DR framework, with defined recovery time and recovery point objectives for critical systems. DR drills for critical information systems should be carried out at least every six months.

Make drills realistic. Switch actual workloads to the DR site, measure how long recovery really takes and record data loss against your targets. Include key vendors, such as your loan management software provider, in the test. A plan that has never been tested is not a plan.

Managing IT Outsourcing and Vendor Risk

Most NBFCs depend on external providers for core lending systems, cloud hosting, collections apps and customer support. Under the outsourcing direction, the NBFC stays fully responsible for outsourced activities. Practical steps include:

  • Maintain a board-approved IT outsourcing policy and a register of all IT service providers, including key entities in their supply chain.
  • Do risk-based due diligence before signing, covering financial strength, security practices and past performance.
  • Include audit and inspection rights for both the NBFC and RBI in contracts.
  • Define security obligations, incident reporting duties, data location and handling, and service levels.
  • Agree on exit and termination plans, including safe return or destruction of data.
  • Review material vendors periodically, not only at renewal time.

Common Gaps Found in NBFC Reviews

Across mid-sized lenders, the same weaknesses appear again and again. Checking for them early saves effort later:

  • Shared or generic admin accounts on servers, databases and cloud consoles, which make it impossible to trace who did what.
  • Field and collection apps that store customer data on staff phones without encryption or remote wipe.
  • Partner and fintech APIs exposed without rate limits, strong authentication or monitoring.
  • Old test environments containing copies of live customer data with weaker controls.
  • Vendor reports accepted without review, so audit observations stay open for years.

Each of these can be fixed with clear ownership and modest investment, and each reduces both regulatory and real-world risk.

A Practical Compliance Roadmap

If you are starting or restructuring your programme, work in this order:

  1. Gap assessment: Compare current policies, controls and evidence against each applicable direction.
  2. Prioritise: Fix governance gaps and high-risk technical issues first, such as unpatched internet-facing systems or shared admin accounts.
  3. Assign owners: Give every control a named owner and a review date.
  4. Build evidence: Store policies, minutes, test reports and closure proof in one organised repository.
  5. Test and report: Run VA/PT, DR drills and IS audits on schedule, and report results to the board committee.

For help structuring governance and policy work, our enterprise advisory services team can work alongside your compliance and risk functions.

Frequently Asked Questions

Which NBFCs must follow RBI's IT governance direction?

NBFCs in the Top, Upper and Middle Layers under scale-based regulation. It took effect from 1 April 2024.

How often must NBFCs run VA/PT?

For critical information systems, vulnerability assessment at least every six months and penetration testing at least every twelve months.

Who should an NBFC's CISO report to?

The CISO should be a senior executive who does not report directly to the head of IT and has no business targets, so security decisions stay independent.

How quickly must a cyber incident be reported?

Under CERT-In directions, specified incidents must be reported to CERT-In within six hours of noticing them. NBFCs should also follow RBI's own reporting instructions.

How Affix Center Can Help

We support NBFCs with gap assessments, policy drafting support, VA/PT coordination, security monitoring, DR planning and vendor risk reviews. Our aim is to make RBI cybersecurity requirements for NBFCs part of daily operations, with evidence ready when supervisors ask.

To discuss your compliance position, contact our team.