RegWatch · RBI · NBFCs

RBI’s new cybersecurity and IT directions for NBFCs: what changes for operations, tier by tier

On 31 July 2026 the RBI pulled its IT, cybersecurity and IT governance instructions for NBFCs into one set of Directions, effective the same day. Most of the coverage reads like a security checklist. But a lot of it lands on operations: maker-checker inside systems, audit trails someone actually reviews, and documented approval for changing an interest rate or a user’s permissions. Which parts apply depends on your layer and size, so start there.

Updated 1 October 2026

What changed

One framework, three tiers

Chapter III covers base layer NBFCs with assets below ₹500 crore and Core Investment Companies. Chapter IV covers base layer NBFCs with assets of ₹500 crore and above. Chapter V covers middle, upper and top layer NBFCs, excluding CICs. For every NBFC, the Board approves the technology and cybersecurity strategies and policies and reviews them at least once a year.

Smaller NBFCs: a baseline IT/IS policy

Base layer NBFCs under ₹500 crore and CICs need a Board-approved IT/IS policy whose systems have access controls and a password policy, defined user roles, the maker-checker concept, cybersecurity controls, system-generated reports for senior management, the ability to file RBI returns, a Board-approved BCP and tested data backups. They are expected to scale their IT up as they grow.

Base layer ₹500 crore+: governance, controls and MIS

An IT Strategy Committee chaired by an independent director, with the CIO and CTO as members, meeting at least every six months. An information security policy covering an asset inventory, segregation of duties, role-based access with documented delegation for changing user permissions and key business parameters such as interest rates, maker-checker requiring approval by at least two individuals, and audit trails that record unauthorised user activity. The MIS should identify Special Mention Accounts and NPAs in the system, regulatory returns should be system-driven, and RBI supervisors get read-only access to the MIS.

Base layer ₹500 crore+: incidents, audit, continuity, outsourcing

Cyber incidents are reported to RBI on the DAKSH platform within six hours of detection. IT risk assessment at least annually. Tracked security training. An IS audit framework approved by the Audit Committee, ideally run before the statutory audit, with audit-mode access for auditors and regulators. BCP tested at least annually. Outsourcing contracts must give the NBFC access to records, including audit trails and admin logs held by technology providers, and the right to audit.

Middle layer and above: committees and a CISO

A Board-level IT Strategy Committee of at least three directors, chaired by an independent director with at least seven years of IT experience, meeting at least quarterly. A quarterly IT Steering Committee. An Information Security Committee headed by someone from risk. A senior CISO who does not report to the Head of IT, has no business targets, reports to the executive director overseeing risk, and reviews cyber preparedness with the Board, risk committee or ITSC at least quarterly.

Middle layer and above: data, change and access controls

A data migration policy with audit trails and sign-offs from business users and application owners at each stage. Audit logging in every application that can access or affect critical or sensitive information, with regular monitoring of those logs. Documented change and patch management with approvals. Access only where there is a valid business need, logged supervision of privileged users, and, based on risk assessment, multi-factor authentication for privileged users of critical systems and critical activities. No manual intervention or modification of data as it moves between critical applications ("straight through processing").

Middle layer and above: testing, recovery and vendors

Vulnerability assessment at least every six months and penetration testing at least every 12 months for critical and customer-facing DMZ systems. DR drills at least half-yearly for critical systems, running a full working day from the DR site. Near-zero RPO for critical systems. Source code for critical applications, or an escrow arrangement, and a written confirmation from vendors that applications are free of known vulnerabilities and malware, renewed on material changes. Cyber incidents go to RBI on DAKSH within six hours and CERT-In is notified proactively; housing finance companies continue to report to NHB.

What it means for operations

Security teams will own most of this. But several requirements are about how business processes run, and those land on credit, operations and finance.

Maker-checker has to live in the system

For base layer NBFCs, the directions put maker-checker inside the IT/IS policy, and for those above ₹500 crore they spell out approval by at least two individuals before a transaction completes. An approval given on email and keyed in later by one person is hard to defend.

Parameter and permission changes need their own trail

Changing an interest rate, a limit or a user’s access needs documented delegation and a record of who changed what. Many NBFCs control loans tightly but let rate tables and role changes happen informally.

Audit trails are expected to be read, not just kept

The directions want audit trails that support audits, forensics and dispute resolution, record unauthorised activity, and, for the middle layer and above, are monitored regularly. A log nobody looks at does not meet that bar.

Spreadsheet hops between systems become a finding

For middle layer and above, data moving between critical applications should not be touched by hand. Exporting from the LOS to Excel and re-uploading to the LMS is exactly the pattern to retire. Data migrations need stage-wise sign-offs and an audit trail too.

MIS and returns should come from the system

Base layer NBFCs above ₹500 crore need system-identified SMA and NPA, system-driven regulatory returns and read-only MIS access for RBI. If your SMA report is assembled by hand each month, that is a gap.

Expect your vendors to be asked harder questions

Access to audit trails and admin logs, the right to audit and, for the middle layer and above, source code or escrow and written vulnerability confirmations. Put these in vendor due diligence now rather than at renewal.

Checklist for this week

  • ✓Confirm which chapter applies to you: base layer below ₹500 crore (and CICs), base layer ₹500 crore and above, or middle layer and above.
  • ✓List every critical approval that still happens by email or spreadsheet and plan to move it into a system with maker-checker.
  • ✓Document who can change interest rates, limits, product parameters and user roles, and make sure every change is logged.
  • ✓Check that audit trails capture unauthorised activity, and decide who reviews them and how often.
  • ✓Write a six-hour cyber incident reporting runbook for DAKSH (and CERT-In if you are middle layer or above; NHB for housing finance companies).
  • ✓Review technology vendor contracts for audit-trail and log access, audit rights and, where applicable, source code escrow and vulnerability confirmations.
  • ✓Put the recurring items in one calendar: Board policy review, committee meetings, IT risk assessment, IS audit, BCP/DR tests and, for the middle layer and above, VA every six months and PT every year.

This is a plain-English summary for operations teams, not legal or regulatory advice, and it is not endorsed by RBI. Read the circular itself and take advice on how it applies to your fund or company.

DG
· Sales Director, Averoic

Works with alternative lenders, AIFs, NBFCs and insurers in India on approvals, maker-checker controls and audit readiness.

Averoic can run reviews, sign-offs and filing trackers like these as configured workflows, with a record of who did what and when.

Frequently asked questions

What are the RBI NBFC cybersecurity directions 2026?

They are the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, reference RBI/DoS/2026-27/461, issued and in force from 31 July 2026. They consolidate IT governance, information security, cybersecurity, IS audit, business continuity and IT outsourcing requirements for NBFCs.

Which NBFCs do the directions apply to?

All NBFCs registered with RBI, including those under the Factoring Regulation Act and the NHB Act, but by tier: Chapter III for base layer NBFCs under ₹500 crore and Core Investment Companies, Chapter IV for base layer NBFCs of ₹500 crore and above, and Chapter V for middle, upper and top layer NBFCs excluding CICs.

How quickly must an NBFC report a cyber incident to RBI?

Within six hours of detection, on RBI’s DAKSH platform, for base layer NBFCs of ₹500 crore and above and for middle layer and above. Middle layer and above NBFCs must also proactively notify CERT-In. The directions note that housing finance companies continue to report cyber incidents to NHB.

Do the RBI directions require maker-checker for NBFCs?

Yes for the base layer. NBFCs below ₹500 crore and CICs must build the maker-checker concept into their IT systems under the IT/IS policy, and base layer NBFCs of ₹500 crore and above must implement maker-checker so transactions complete only after independent verification and approval by at least two individuals.

Who should the CISO of an NBFC report to?

For middle layer and above NBFCs, the CISO must not report directly to the Head of IT, must not have business targets, and reports directly to the executive director or equivalent executive overseeing risk management.

Start building on your process.

Spin up a free workspace in minutes — no card. Or book a 30-minute walkthrough on your real workflow.