Current · Source: Reserve Bank of India · RBI/2011-12/600 · issued 13 Jun 2012 · ~1 min read
Quick answerRBI directs all scheduled commercial banks (excluding RRBs) to adopt IT and IS governance frameworks, referencing IDRBT's manual, and to implement automated data flow for returns by March 2013.
The rule, in the simplest words
All big banks (except rural banks) must set up a special plan for how they use computers and keep information safe, using a guide from IDRBT (a banking tech institute).
The bank's top leaders (the Board) must pay close attention to computer safety, keeping information secret, and having a backup plan if things go wrong.
By March 2013, banks must build automatic computer systems that send reports to RBI (the central bank) without people typing them in.
Banks must tell RBI they got this rule by sending a reply.
How it plays out — a real example
A payments & clearing officer in Indore, Priya, sees her bank's IT team working late to build a new automated system that will send loan reports to RBI by March 2013. She knows this means no more manual data entry errors, and her branch's board will now review computer security every quarter, making her feel safer about customer data.
What changed
RBI reiterated its Monetary Policy Statement 2012-13, emphasizing that banks must implement IT and IS governance structures. It also set a deadline of March 2013 for banks to fully deploy automated data flow systems for submitting returns to RBI.
What it means for you
Banks must prioritize board-level attention on IT governance, information security, and business continuity. This move aims to align IT with business, reduce operational risks, and ensure timely, error-free regulatory reporting. Non-compliance could impact financial stability and regulatory standing.
What you must do
Adopt IT and IS governance frameworks as per IDRBT's reference manual.
Ensure board-level oversight of IT governance, information security, and business continuity.
Develop and deploy automated data flow systems to generate all RBI returns by March 2013.
Acknowledge receipt of this circular to RBI.
Who it affects
All scheduled commercial banks (excluding RRBs), Board of Directors and senior management, IT and information security teams, Regulatory reporting departments
❓ Common questions
What is the deadline for implementing automated data flow?
Banks must implement suitable solutions to generate all returns to RBI without manual intervention by end-March 2013.
Which document can serve as a reference for IT governance?
The IDRBT document on 'Organizational Structure for IT in the Indian Banking Sector' is recommended as a reference manual.
Does this apply to Regional Rural Banks (RRBs)?
No, this circular is addressed to all scheduled commercial banks excluding RRBs.
📜 Read the original circular — full text as issued by RBI
RBI/2011-12/600
DIT Cir. No.2833/09.63.025/2011-12
June 13, 2012
The Chairmen/Chief Executive Officers,
All Scheduled Commercial Banks (excluding RRBs)
Madam / Dear Sir,
Monetary Policy Statement 2012-13 - IT and IS Governance structures
Please refer to the paragraphs 121 - 123 of the Monetary Policy Statement 2012-13, wherein we have emphasized the importance of implementing IT and IS Governance structure in banks. It is expected that all banks adopt appropriate frameworks for both IT and IS Governance and put in place the proper structure and systems. Accordingly, we request you to take up suitable steps at your end in this regard and ensure that the issues relating to governance, information security and business continuity get adequate attention at the Board level. In this regard, the document prepared by IDRBT on the ‘Organizational Structure for IT in the Indian Banking Sector’ can serve as a reference manual.
2. We also draw your attention to Para 124 on automated data flow and request you to develop and deploy suitable systems to meet the deadline of March 2013 for its total implementation.
3. Please acknowledge receipt.
Yours faithfully
(G Padmanabhan)
Executive Director
Extracts of the Annual Policy Statement for the year 2012-13
IT and IS Governance
121. Information Technology Vision Document 2011-2017, which was released in February 2011, also sets priorities for commercial banks to move forward from usage of CBS for front-end customer service to areas such as management information system (MIS), regulatory reporting, overall risk management, financial inclusion and customer relationship management. Recognising that possible operational risks arising out of adopting technology in the banking sector could have some impact on financial stability, the document has emphasised the need for internal controls, risk mitigation systems and BCPs. Towards this, banks may work in improving their IT governance structures; and evolve well defined information technology policies as well as information security (IS) frameworks.
122. Adoption of well-structured IT governance models will assist banks in enabling better alignment between IT and business, create efficiencies, enhance conformity to internationally accepted best practices and improve overall IT performance, as also enable better control and security. IT governance objectives may be translated effectively and efficiently into improved performance. In order to achieve the above, banks need to move towards adoption of well-structured IT governance models. At its own level, the Reserve Bank has set up an IT Sub-Committee of the Central Board, chaired by an external director, in order to strengthen its IT governance mechanism.
123. Banks are increasingly relying on various IT based channels to operate their businesses and market interactions. Ability of banks to take advantage of new opportunities would largely depend on their capability to provide accessible and secure service channels. However, this would also increase their exposure to technology and operational risks, which have potential implications for individual banks as also for the entire financial sector. Adoption of comprehensive IS frameworks suiting the prevalent banking environment, business goals, processes, people and technology will be imperative to meet these challenges
Automated Data Flow from Banks
124. Following the announcement in the Monetary Policy Statement of May 2011, banks have undertaken to bring returns to be submitted to the Reserve Bank under Automated Data Flow (ADF). A working group comprising representations from banks and the Reserve Bank has been constituted for guiding and monitoring the implementation of the ADF project. Banks are adopting different strategies for putting in place systems and processes required for achieving automation of internal data flow to generate returns without manual intervention. Banks are required to implement suitable solutions to generate all the returns to be submitted to the Reserve Bank by end-March 2013. The Reserve Bank has been closely monitoring the progress of implementation.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2011-12/600 · issued 13 Jun 2012. The plain-English explanation above is BankPulse’s own independent summary.
Develop and deploy automated data flow systems to generate all RBI returns by March 2013.
📜 Compliance
Adopt IT and IS governance frameworks as per IDRBT's reference manual.
Ensure board-level oversight of IT governance, information security, and business continuity.
Acknowledge receipt of this circular to RBI.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are a Compliance officer at a bank this circular applies to (All scheduled commercial banks (excluding RRBs), Board of Directors and senior management, IT and information security teams, Regulatory reporting departments), your first concrete step on “RBI Mandates IT and IS Governance for Banks” is: “Adopt IT and IS governance frameworks as per IDRBT's reference manual.” (RBI issued this 13 Jun 2012).
Circular: RBI/2011-12/600 -- RBI Mandates IT and IS Governance for Banks
Issued: 13 Jun 2012
Action required: Adopt IT and IS governance frameworks as per IDRBT's reference manual.
Action required: Ensure board-level oversight of IT governance, information security, and business continuity.
Action required: Develop and deploy automated data flow systems to generate all RBI returns by March 2013.
Action required: Acknowledge receipt of this circular to RBI.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=7269&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.