We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · BFSI

Third-party risk assessment for banks and NBFCs

RBI’s outsourcing directions and IT-governance framework hold banks and NBFCs accountable for the security of their vendors, cloud providers and digital-lending partners. CyberSigma runs third-party risk assessments (TPRM) for BFSI: vendor tiering, security questionnaires, evidence review, on-site or remote assessment of critical suppliers, and a scored, prioritised report your risk committee and RBI inspection can rely on. We turn a sprawling vendor estate into a defensible, monitored programme.

Get a free TPRM scoping call →Book a 20-minute call
Who needs it

Who this is for

Banks, cooperative banks, NBFCs and payment firms accountable under RBI outsourcing and IT-governance directions for the security of material service providers, cloud vendors and digital-lending partners (LSPs).

Scope

What the assessment covers

Vendor tiering
Classify suppliers by criticality and data access to focus effort where risk is highest.
Assessment
Security questionnaire, evidence review and deep-dive assessment of critical vendors.
Ongoing monitoring
Cadence, re-assessment triggers and contract-clause recommendations.
Regulation

Applicable RBI expectations

RBI outsourcing directions, the Master Direction on IT Governance, Risk, Controls and Assurance Practices, and the Digital Lending guidelines for LSP oversight.

Deliverables

What you receive

Scored vendor register
Risk-scored inventory with tiering and gaps per vendor.
Remediation & monitoring plan
Prioritised actions, contract clauses and re-assessment cadence.
Common failures

Where TPRM programmes fail

  • No tiering — everyone assessed the same, so critical vendors under-scrutinised
  • Questionnaires collected but evidence never verified
  • Cloud and digital-lending partners left out of scope
  • No re-assessment cadence or contractual right to audit
Proof

See how we’ve done it before

Relevant case study
How a lender built a scored, monitored vendor programme aligned to RBI outsourcing norms. Read case studies →
Redacted sample deliverable
Inspect a redacted TPRM report first. Request a redacted sample →

Worried about a supplier becoming your breach?

Get a free third-party risk scoping call — share your work email and we frame your vendor tiers, gaps and next steps.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • IT Governance, Risk, Controls and Assurance Practices Directions (2023)Effective 1 April 2024

    The Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023 (RBI/2023-24/107), effective 1 April 2024, is a Master Direction that consolidates and supersedes earlier RBI IT-governance and cyber-risk instructions. It applies to regulated entities including scheduled commercial banks (excluding RRBs), small finance banks, payments banks, NBFCs in the specified layers, credit information companies, and all-India financial institutions (NABARD, EXIM Bank, NHB, SIDBI, NaBFID). It requires a board-level IT governance framework covering strategic alignment, risk management, resource and performance management, and business continuity and disaster recovery, plus an IT and information-security risk management framework and periodic information systems audits.

  • Cyber Security Framework in Banks (2016)Effective 2 June 2016

    The RBI circular Cyber Security Framework in Banks (RBI/2015-16/418, DBS.CO/CSITE/BC.11/33.01.001/2015-16), dated 2 June 2016, requires scheduled commercial banks to put in place a board-approved cyber-security policy distinct from their IT or IS-security policy, to implement a baseline cyber-security and resilience framework, and to arrange continuous surveillance (for example through a Security Operations Centre). Issued and supervised by the RBI CSITE Cell, it also requires banks to maintain a Cyber Crisis Management Plan and to report all cyber-security incidents, whether successful or attempted, to the RBI.

  • Master Direction on Digital Payment Security Controls (2021)Effective 18 February 2021

    The RBI Master Direction on Digital Payment Security Controls (RBI/2020-21/74, DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21), dated 18 February 2021, sets out a robust governance structure and common minimum standards of security controls for digital payment products and services. It covers areas such as internet banking, mobile banking and card payments, along with customer protection and grievance redressal. It applies to Scheduled Commercial Banks (excluding Regional Rural Banks), Small Finance Banks, Payments Banks and credit-card-issuing NBFCs, and took effect within six months of being placed on the RBI website.

  • Storage of Payment System Data (data localisation)Effective 6 April 2018

    The RBI circular on Storage of Payment System Data (RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-2018), dated 6 April 2018, requires all system providers to ensure that the entire data relating to the payment systems they operate is stored in a system only in India. This includes the full end-to-end transaction details and any information collected, carried or processed as part of the payment message or instruction. Providers were given six months to comply and to submit a System Audit Report conducted by a CERT-In empanelled auditor. It applies to all Payment System Providers authorised under the Payment and Settlement Systems Act, 2007.

  • Regulation of Payment Aggregators Directions, 2025Effective 31 December 2025

    The Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025 (RBI/DPSS/2025-26/141), issued 15 September 2025 and in force from 31 December 2025, consolidate the earlier 2020, 2021 and 2023 payment-aggregator guidelines into a single framework covering online and face-to-face (proximity) payment aggregators. A non-bank entity carrying on payment-aggregator business must obtain RBI authorisation, and must have a minimum net worth of INR 15 crore at the time of application, rising to a minimum net worth of INR 25 crore by the end of the third financial year after authorisation, maintained thereafter. The directions also cover governance, KYC of merchants, escrow-account operation, security and reporting.

  • Payment system data storage in IndiaEffective 6 October 2018

    RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.

    Circular number cited for retrieval via RBI's notification search; we deliberately avoid deep-linking RBI's session-bound URLs.

  • IT Governance Master DirectionEffective 1 April 2024

    Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.

    Direction number cited for retrieval via RBI notification search; RBI deep links are session-bound.

  • IT Outsourcing Master DirectionEffective 1 October 2023

    Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.

    Direction number cited for retrieval via RBI notification search.

  • Digital Payment Security Controls Master DirectionEffective 18 February 2021

    Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.

    Direction cited by title and date for retrieval via RBI notification search.

  • Cyber Security Framework in BanksEffective 2 June 2016

    RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.

Related in this cluster

TPRM for banks — FAQs

Does RBI hold us responsible for vendor security?

Yes. Under RBI outsourcing and IT-governance directions, accountability for a material service provider’s security remains with the regulated entity. TPRM evidences that oversight.

Do you cover cloud and digital-lending partners?

Yes. Cloud providers and Lending Service Providers are commonly the highest-risk relationships; we assess them against RBI outsourcing and Digital Lending expectations.

Talk to our BFSI risk practice

We tier your vendors, assess the critical ones and leave you with a monitored programme. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your Third-party risk assessment for banks requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.