RBI Issues Final Guidelines on IT Security and Cyber Fraud for Banks
No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2010-11/494 · issued 29 Apr 2011 · ~2 min read
Quick answerRBI has issued final guidelines from the Gopalakrishna Working Group on IT security, cyber fraud, and technology risk management. Banks must conduct gap analysis and implement risk-based measures commensurate with their technology use, with a time-bound action plan.
The rule, in the simplest words
Banks must check their current computer safety rules against the new RBI rules and make a plan to fix any missing parts.
The rules are not the same for every bank; banks that use more technology must follow more rules, while smaller banks may follow fewer.
If a new rule says something different from an old rule, banks must follow the new rule; otherwise, the old rules still help.
Banks must write down a plan with deadlines to fix any gaps in their computer safety, and the bank's top leaders must watch over this work.
How it plays out — a real example
An IT-governance officer in Indore, Priya, is updating her bank's IT security checklist. She finds that her bank, which only offers basic internet banking without transactions, does not need to add extra security for online money transfers. She notes this in her gap analysis report and sets a deadline to review the bank's backup plans instead, making sure her team knows the new rules are risk-based and not one-size-fits-all.
What changed
RBI released final guidelines based on the Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds, covering nine areas including IT governance, information security, IS audit, IT operations, outsourcing, cyber fraud, BCP, customer awareness, and legal aspects. The guidelines are risk-based and not one-size-fits-all; banks must perform a formal gap analysis and create a time-bound action plan for compliance. New guidelines supersede earlier ones in case of direct conflict, but earlier guidelines remain adjunct where no conflict exists.
What it means for you
Banks must now systematically assess their current IT security posture against these new RBI stipulations and address gaps within a defined timeline. The risk-based approach means smaller banks with limited technology use may not need to implement all measures, while tech-heavy banks must comply fully. This will likely increase compliance costs and require dedicated project management for IT security upgrades.
Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.
What banks were required to do at the time
Conduct a formal gap analysis comparing your bank's current IT security, audit, and cyber fraud measures against the new guidelines.
Develop a time-bound action plan to address identified gaps and ensure compliance with all applicable stipulations.
Implement risk-based measures commensurate with your bank's technology leverage and business scope, focusing on areas like IT governance, information security, and BCP.
Review and update existing policies on outsourcing, IS audit, and customer awareness to align with the new guidelines.
Engage with RBI for clarifications if needed, and ensure board-level oversight of the implementation process.
Who it affects
All scheduled commercial banks (excluding RRBs), IT and information security teams, Internal audit and compliance departments, Senior management and board of directors, Vendors providing IT services to banks
❓ Common questions
Regulatory timeline
Decoded by BankPulse2026-06-19 01:47 IST
repealed_by — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
Do these guidelines apply to all banks uniformly?
No, the guidelines are risk-based and not one-size-fits-all. Banks with extensive technology use must implement all stipulations, while those with limited tech leverage may only need relevant measures. For example, banks without transactional internet banking need not implement specific measures for that facility.
What should we do if we have already implemented some of these measures?
You must still conduct a formal gap analysis comparing your current status with the new guidelines. If there is a direct conflict with an earlier RBI guideline, the new guideline takes precedence. Otherwise, earlier guidelines remain adjunct.
Are we allowed to use alternative technologies not mentioned in the guidelines?
Yes, the guidelines are technology neutral except where a specific technology is legally required or suggested for enhanced security. Banks may adopt equivalent or better technologies after a diligent evaluation.
📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Repealed byRBI/2025-26/100 — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
RBI’s words: “Official withdrawal register entry #124: DBS.CO.ITC.BC.No.6/31.02.008/2010-11 — "Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds - Implementation”
📜 Read the original circular — full text as issued by RBI
RBI/2010-11/494
DBS.CO.ITC.BC.No. 6/31.02.008/2010-11
April 29, 2011
The Chairman / Chief Executives of
All Scheduled Commercial Banks (excluding RRBs)
Dear Sir / Madam,
Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds- Implementation of recommendations
As you are aware, following the announcement in the April 2010 Monetary Policy Statement, the Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds was constituted, under the Chairmanship of Shri G. Gopalakrishna, Executive Director, RBI. The Group examined various issues arising out of the use of Information Technology in banks and made its recommendations in nine broad areas. These areas are IT Governance, Information Security, IS Audit, IT Operations, IT Services Outsourcing, Cyber Fraud, Business Continuity Planning, Customer Awareness programmes and Legal aspects . The report was placed on the RBI website on January 21, 2011. Subsequently, on February 1, 2011, views/ comments of all stake-holders and the public at large on the Report were invited. After taking into account various responses, final guidelines in the respective areas as mentioned above are now being issued to banks for implementation. The guidelines are enclosed herewith for implementation by banks.
(b) The guidelines are not “one-size-fits-all” and the implementation of these recommendations need to be risk based and commensurate with the nature and scope of activities engaged by banks and the technology environment prevalent in the bank and the support rendered by technology to the business processes. Banks with extensive leverage of technology to support business processes would be expected to implement all the stipulations outlined in the circular. For example, banks which do not offer transactional facilities in internet banking would not be required to implement specific measures for transactional internet banking facility outlined in the guidelines. Further, various instructions in “IT operations” chapter like detailed configuration management practices may not be necessary for banks that do not develop or maintain critical applications internally, though such practices may be expected from the external vendor providing such services.
(c) The Group had endeavored to generate self-contained and comprehensive guidelines. This has resulted in reiteration of certain guidelines already prescribed by RBI, for example, in certain areas relating to information security, outsourcing, BCP and IS Audit. However, there are certain guidelines like the checklist for computer audit prescribed in the year 2002 which on the whole cannot be ignored since the nature of coverage is different. In the event of a direct conflict with an earlier guideline, the new guideline would be the basis for implementation by banks. Else, the relevant guidelines prescribed earlier would be an adjunct to the present guidelines issued herewith. It would be the endeavor of RBI to develop the enclosed guidelines as a Master Circular incorporating relevant old and new circulars on related subject areas in due course. In the event of any further clarifications in the matter, banks may approach RBI for further guidance.
(d) The Group’s report was largely technology neutral except in exceptional circumstances where a specific technology/methodology may be suggested due to legal reasons or for enhanced security or for illustrative purpose. It is clarified that except where legally required, banks may consider any other equivalent/better and robust technology/methodology based on new developments after carrying out a diligent evaluation exercise.
(e) Banks may have already implemented or implementing some or many of the requirements indicated in the circular. In order to provide focused project oriented approach towards implementation of guidelines, banks would be required to conduct a formal gap analysis between their current status and stipulations as laid out in the circular and put in place a time-bound action plan to address the gap and comply with the guidelines. However, banks need to ensure implementation of basic organizational framework and put in place policies and procedures which do not require extensive budgetary support, infrastructural or technology changes, by October 31, 2011. The rest of the guidelines need to be implemented within period of one year unless a longer time-frame is indicated in the circular. There are also a few provisions which are recommendatory in nature, implementations of which are left to the discretion of banks.
(f) Given the fact the guidelines are fundamentally expected to enhance safety, security, efficiency in banking processes leading to benefits for banks and their customers, the progress in implementation of recommendations may be monitored by the top management on an ongoing basis and a review of the implementation status may be put up to the Board at quarterly intervals. Banks may also incorporate in their Annual Report from 2011-12 onwards broadly the measures taken in respect of various subject areas indicated in these guidelines.
(g) The measures suggested for implementation cannot be static. Banks need to pro-actively create/fine-tune/modify their policies, procedures and technologies based on new developments and emerging concerns.
(h) Reserve Bank of India would review the progress in implementation of the guidelines in its Quarterly Discussions with banks and would examine comprehensively the efficacy of implementation of the guidelines commensurate with nature and scope of operations of individual banks from the next AFI cycle (for the period 2011-12) onwards.
(i) Please acknowledge receipt.
Yours faithfully,
(G. Jagan Mohan Rao)
Chief General Manager-in-charge
Encl : Guidelines on Information security, Electronic Banking, Technology risk management and Cyber frauds
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2010-11/494 · issued 29 Apr 2011. The plain-English explanation above is BankPulse’s own independent summary.
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6366&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.