The Reserve Bank of India Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices takes effect today for regulated banks and financial entities.
Key points
- Board-level IT governance and a board-approved IT strategy.
- IT and information security risk management.
- Business continuity and disaster recovery.
- Information systems audit and vendor oversight.
UK technology providers serving Indian banks and NBFCs should expect enhanced oversight, audit rights and resilience requirements. The Direction replaces earlier RBI circulars, so a single consolidated set of expectations now applies. Suppliers with ISO/IEC 27001 certification and strong business continuity arrangements will be better placed to respond to customer due diligence.
Source: RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (RBI)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.