RBI IT GRC · Banking & NBFC Compliance · 12 min read

RBI Master Directions for IT GRC: Governance, Risk, Controls and Assurance Checklist for Indian Banks and NBFCs

A structured, proof-first governance, risk, and control checklist for Indian banks and NBFCs complying with RBI Master Directions.

RBI IT GRCBanking GRCNBFC ComplianceAudit ReadinessGovernanceRisk Management
✍️ CISOGenie Team📅 August 2026🕐 12 min read🏷️ RBI IT GRC · Banking & NBFC Compliance
RBI IT GRC Three-Tier Governance Structure for Banks & NBFCs

Master Direction on Information Technology Governance, Risk, Control and Assurance Practices

If you are a bank or NBFC covered by RBI's IT GRC Master Direction, the main job is simple: show proof that controls worked from 01-04-2024 onward. A policy alone is not enough. You need clear owners, dated reviews, action trackers, test records, audit trails, and one place where your team can pull evidence fast.

Here's the short version of what I'd check first:

  • Board approvals: IS Policy, IT Policy, Cyber Security Strategy, CCMP, Vendor/Outsourcing Policy, BCP/DR Policy, and IT Risk Appetite Statement
  • Governance setup: Board, Board-level IT Strategy Committee, and management IT Steering Committee
  • Role clarity: CISO kept separate from CIO/CTO, with a clear reporting line and committee presence
  • Risk tracking: IT risk register with owner, rating, review date, action due date, and closure proof
  • Third-party checks: vendor inventory, due diligence, contract clauses, retention/deletion terms, and review records
  • Control proof: access approvals, access reviews, privileged access checks, patch and test records, backup restore results, and incident logs
  • Resilience proof: DR and BCP test results, follow-up actions, and sign-offs
  • Audit readiness: annual IT/IS audit coverage, issue closure files, and a central evidence repository
  • Inspection readiness: every file linked to source, date, owner, and status such as Extracted or Inferred

In plain terms, RBI wants steady control proof, not one-time paperwork. That means your team should be able to answer basic questions fast: Who owns this control? When was it last reviewed? What is the proof? Is the issue closed? If any of those answers are missing, inspection prep gets harder.

A few facts stand out:

  • The direction became effective on 01-04-2024
  • The article points to quarterly Board-level risk review and monthly/quarterly management review
  • The IT Strategy Committee should include at least 3 directors
  • Its Chairperson should be an independent director with 7+ years of IT experience
  • Annual policy review and annual IT/IS audit records should be easy to trace

What I like about this checklist is that it keeps the focus on what RBI teams usually ask for first: approval, ownership, dates, and evidence. Not long policy files. Not slide decks. Just proof that the control ran, was checked, and any gap was closed.

This makes the article useful for CISOs, CIOs, compliance teams, risk teams, and internal audit. Each group can take one control set, assign one owner, log the last review date in DD-MM-YYYY format, and keep the matching file ready.

That is the whole game: less theory, more proof.

Governance checklist: Board oversight, accountability, and policy approvals

RBI IT GRC Three-Tier Governance Structure for Banks & NBFCs
RBI IT GRC Three-Tier Governance Structure for Banks & NBFCs

Once governance ownership is set, the next step is simple: check whether the Board has approved the main IT and cyber policies. RBI places accountability for IT and cyber governance on the Board, and each core policy must be Board-approved and easy to trace back to the approved version in the minutes. If a policy was approved only by a management committee, it won't meet RBI's governance test.

Confirm that Board approval exists for each of these:

  • IS Policy
  • IT Policy
  • Cyber Security Strategy
  • Cyber Crisis Management Plan (CCMP)
  • Vendor and Outsourcing Policy
  • BCP/DR Policy
  • IT Risk Appetite Statement

Evidence required: Board minutes with the policy version reference for each item listed above.

Board and committee structure for IT governance and cyber risk oversight

After approvals are checked, look at the governance chain that reviews risk and follows up on actions. RBI expects a three-tier structure: the Board, a Board-level IT Strategy Committee (ITSC), and a Management-level IT Steering Committee. The ITSC should include at least three directors, and its Chairperson should be an independent director with 7+ years of IT experience.

The minutes matter here. They should show that risks were reviewed, decisions were documented, and actions were assigned. A meeting record that only says something was "noted" or "recorded" won't do the job. RBI expects review, challenge, and clear action ownership.

Committee / RoleLevelMeeting FrequencyKey Evidence Required
IT Strategy CommitteeBoardQuarterlyMinutes showing substantive IT and cyber risk review
IT Steering CommitteeManagementMonthly / QuarterlyAction tracker, risk updates, project status

CISO, senior management, and policy ownership responsibilities

The CISO's reporting line needs to be documented clearly. The CISO should report to the Executive Director overseeing Risk Management, not to the CIO or CTO, and should be a standing invitee to both the ITSC and the IT Steering Committee. This should be visible in the organisation chart and in the Board-approved committee charters.

Each IT and cyber policy should also have a named owner, version history, change log, and an annual review record. On top of that, the version being circulated inside the organisation should match the Board-approved version. That way, inspection teams can verify approval and ownership without digging around.

Evidence required: Org chart, committee charters, policy version register, annual review log.

Risk management checklist: IT risk assessments, third-party risk, and control tracking

Risk management has to move beyond policy documents and into tracked risks, actions, and proof of closure. RBI expects structured registers, periodic reviews, and documented remediation.

IT risk register, periodic assessments, and vulnerability testing

Your IT risk register should cover more than the obvious buckets. RBI expects risk identification across confidentiality, integrity, and availability. Cyber and operational-resilience threats need to be tracked clearly, and availability should be treated as a primary risk, not a footnote.

Each risk entry should include an owner, current and residual ratings, appetite mapping, and a dated remediation action. At a glance, the register should show who owns the risk, when it was last reviewed, and what action is still open.

Vulnerability assessments and penetration tests need the same level of discipline. Schedule them, track them, and link each finding to an owner, due date, and closure evidence. That's what makes the register useful for both management review and internal audit.

Evidence required: Current IT risk register with owner and rating fields, risk appetite alignment documentation, vulnerability testing tracker with remediation status, and closure evidence for open findings.

Outsourcing and vendor risk management under RBI expectations

RBI Outsourcing and Vendor Risk Management Workflow

Check that third-party due diligence records include SOC 2 Type II status and ZDR capability where required. Contracts should spell out retention, deletion, and exception timelines. You'll also need to monitor vendor compliance with retention and security obligations, then close exceptions through a dated action log.

Evidence required: Vendor inventory, due diligence records, executed contracts with SOC 2 Type II and ZDR clauses, and ongoing vendor monitoring reports.

Controls checklist: IT operations, cybersecurity, resilience, and payment environment safeguards

Controls are what turn policy into proof. RBI expects banks and NBFCs to show that access, monitoring, resilience, and data-protection checks worked as intended, with dated records to back them up. This is where governance and risk decisions move from paper into day-to-day controls that RBI can inspect.

Core IT and security controls that should be working effectively

A policy matters only when its execution, approval, and evidence are easy to see.

Use Single Sign-On (SSO) for controlled access, and make sure approvals, periodic reviews, and revocations are logged. If Zero Data Retention (ZDR) applies, keep configuration records and exception evidence ready for audit.

Evidence required: Access approvals, access review sign-offs, privileged access review records, and data retention or deletion evidence.

Business continuity, disaster recovery, and critical service resilience

For resilience, keep backup restore test results and exception closure trackers so you can show that testing happened and that follow-up actions were completed. Dated records for backup tests, incident closure, and exception sign-off should be easy to pull during a review.

Evidence required: Backup restore test results, incident records, and exception closure sign-offs.

Digital banking and payment system control checks

Payment and digital banking controls need the same discipline as core IT controls. Keep access, configuration, and retention evidence for digital banking and payment systems in one audit-ready repository.

Evidence required: ZDR configuration evidence and access review records.

Assurance and readiness checklist: Audit evidence, RBI inspection preparation, and continuous compliance

Once controls are in place, the next question is simple: can your evidence pack prove it? For RBI readiness, the assurance layer should make it easy to show what was tested, what was found, and how each issue was closed.

Internal audit, IS audit, and issue closure evidence

Your annual IT and IS audit coverage should map back to governance, cyber, incident handling, BCP/DR, vendor risk, and issue closure evidence.

For each audit or control review, keep the scope, test results, artefacts, and exception closure evidence in one place. The main goal here is packaging and traceability. If AI helps assemble the pack, tag each item as Extracted or Inferred so auditors can track the source without guesswork.

RBI inspection readiness and evidence repository checklist

RBI inspections are much easier when evidence lives in one central repository instead of being scattered across shared drives and spreadsheets. A linked repository ties together policies, controls, implementation artefacts, and remediation records, so teams don't have to hunt things down by hand.

At a minimum, your repository should be able to produce the following on demand:

Evidence CategoryWhat to Include
GovernanceIT and cybersecurity policies, governance records
Risk ManagementIT risk register, risk assessments, control tracking
Vendor RiskThird-party assessments, contract clauses, monitoring records
ResilienceDR drill results, BCP test reports, closure sign-offs
IncidentsIncident logs, post-incident review notes
AuditIS audit reports, action trackers, closure evidence

Traceability is non-negotiable. Every item should show whether it was directly observed, extracted from source material, or inferred, so inspectors can follow the logic without extra follow-up.

Moving to continuous compliance with CISOGenie

CISOGenie Continuous Compliance Platform

Continuous compliance keeps the repository up to date between audit cycles.

Manual audit prep often leads to stale evidence and drift in risk registers. CISOGenie automates evidence collection, risk assessments, policy updates, and third-party workflows, so the evidence base stays current. That gives CISOs and audit teams a more current view of evidence and cuts manual effort at inspection time. For sensitive inspection data, ZDR supports purge requirements, and SOC 2 Type II remains a useful benchmark.

Audit Management with CISOGenie

Frequently Asked Questions

Ready to streamline your RBI IT GRC compliance?

See how CISOGenie automates evidence collection, IT risk tracking, and audit-ready reporting across RBI Master Directions and 40+ frameworks.