Current · Source: Reserve Bank of India · RBI/2012-13/547 · issued 26 Jun 2013 · ~2 min read
Quick answerRBI mandates banks to implement robust Business Continuity Plans (BCP) and conduct periodic Vulnerability Assessment and Penetration Testing (VAPT) to secure information systems, with board-level approval and quarterly reporting.
The rule, in the simplest words
Banks must have a Business Continuity Plan (a plan to keep working even after a disaster) that covers people, processes, and technology.
Banks must run Disaster Recovery drills (practice tests to see if systems can be fixed after a crash) and Vulnerability Assessment and Penetration Testing (VAPT, which is like a security check to find weak spots) regularly.
The bank's board (top leaders) must approve the information security policies (rules to protect data) and update them when needed.
Banks must send a certificate to RBI saying the board approved the policies, and keep reporting every three months on DR drills and VAPT.
Any problems found during VAPT or DR drills must be fixed quickly as part of the bank's security work.
How it plays out — a real example
An IT-governance officer in Indore, Priya, receives an email from her IT team saying the bank's quarterly VAPT found a weak spot in the loan application system. She works with the tech team to patch it within a week, and her manager notes the fix in the compliance report sent to RBI. This keeps customer data safe and the bank running smoothly.
What changed
RBI reinforced the need for banks to have consolidated BCP documents covering people, process, and technology, and to conduct regular Disaster Recovery drills and VAPT. It also requires board-level approval of information security policies and continued quarterly reporting on these activities.
What it means for you
Banks must strengthen their IT resilience by formalizing BCPs and testing them regularly to minimize operational, financial, and reputational risks from disruptions. VAPT becomes a non-negotiable periodic exercise to guard against cyber threats, with gaps needing timely closure. Board oversight and quarterly compliance reporting are now mandatory, making information security a governance priority.
What you must do
Formulate or update consolidated BCP documents covering critical aspects of people, process, and technology.
Conduct Disaster Recovery drills and VAPT on a regular basis and document the results.
Ensure board-level discussion and approval of information security policies, with updates as needed.
Submit a certificate to RBI confirming board approval of policies and continue quarterly reporting on DR drills and VAPT.
Plug identified gaps from VAPT and DR drills in a timely manner as part of the information security assurance function.
Who it affects
All Scheduled Commercial Banks (excluding RRBs), Board of Directors and senior management, IT and information security teams, Risk management and compliance departments
❓ Common questions
What is the frequency of VAPT required by RBI?
RBI mandates periodic VAPT but does not specify an exact frequency in this circular; banks should determine a schedule based on risk assessment and ensure regular testing.
Do we need board approval for information security policies?
Yes, the circular states that policies governing security of information systems should be discussed and approved at the board level and updated from time to time.
What should be included in the BCP document?
The BCP document should cover policies, standards, and procedures to ensure continuity, resumption, and recovery of critical business processes, limiting impact on people, processes, and infrastructure.
📜 Read the original circular — full text as issued by RBI
RBI/2012-13/547
DIT.CO(Policy)No. 2636/09.63.025/2012-13
June 26, 2013
The Chairmen/Chief Executive Officers,
All Scheduled Commercial Banks (excluding RRBs)
Dear Sir/Madam,
Business Continuity Planning (BCP), Vulnerability Assessment and Penetration Tests (VAPT) and Information Security
Please refer paragraph 102 of the Monetary Policy Statement 2013-14 wherein we have emphasised the importance of securing the Information Systems (IS) of banks. In order for banks to secure their ISs, ensure their continuity, and check their robustness, it is expected that banks put in place appropriate business continuity plans (BCPs) and test them periodically. These ISs should also be subjected to vulnerability assessment and penetration testing (VAPT).
2. Formulation of consolidated BCP documents by banks covering critical aspects of people, process and technology is important in view of the increased contribution of 24x7 electronic banking channels. The documents should cover policies, standards and procedures to ensure continuity, resumption and recovery of critical business processes, at an agreed level and limit the impact of the any disaster on people, processes and infrastructure (including IT); or to minimise the operational, financial, legal, reputational and other material consequences arising from such a disaster. In order to test their internal IT systems to handle unforeseen disruptions, it is important for the banks to conduct Disaster Recovery (DR) Drills on a regular basis. It is also important that these arrangements are subject to periodic testing.
3. Further, considering that cyber attacks could threaten the confidentiality, integrity and availability of data and the systems, it is imperative for the banks to conduct VAPT periodically to prevent any such attacks. There is a need to prepare documents detailing these activities, update the same regularly and ensure that gaps identified from the tests are plugged in a timely manner. This should form part of the Information Security assurance function undertaken by banks.
4. Reserve Bank has been emphasising to banks on the importance of putting appropriate IT and IS governance structures to enable, interalia, better control and security. The policies governing security of ISs may be discussed and approved at the Board level and updated from time-to-time. A certificate confirming the same may be forwarded to us for our record. This aspect may be subjected to scrutiny at a later date during the Annual Financial Inspection of banks.
5. The information regarding the conduct of DR drills and VAPT is received by the Reserve Bank on a quarterly basis and this may be continued.
6. The critical components of Business Continuity Management Framework as enunciated in the report of Working Group on information security, electronic banking, technology risk management, and cyber frauds (Chairman: Shri G Gopalakrishna) can serve as reference material for banks while finalising their policies.
7. Please acknowledge the receipt of the letter.
Yours faithfully
(A. S. Ramasastri)
CGM-in-charge
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2012-13/547 · issued 26 Jun 2013. The plain-English explanation above is BankPulse’s own independent summary.
Example: if you are a Compliance officer at a bank this circular applies to (All Scheduled Commercial Banks (excluding RRBs), Board of Directors and senior management, IT and information security teams, Risk management and compliance departments), your first concrete step on “BCP, VAPT and Information Security for Banks” is: “Formulate or update consolidated BCP documents covering critical aspects of people, process, and technology.” (RBI issued this 26 Jun 2013).
Circular: RBI/2012-13/547 -- BCP, VAPT and Information Security for Banks
Issued: 26 Jun 2013
Action required: Formulate or update consolidated BCP documents covering critical aspects of people, process, and technology.
Action required: Conduct Disaster Recovery drills and VAPT on a regular basis and document the results.
Action required: Ensure board-level discussion and approval of information security policies, with updates as needed.
Action required: Submit a certificate to RBI confirming board approval of policies and continue quarterly reporting on DR drills and VAPT.
Action required: Plug identified gaps from VAPT and DR drills in a timely manner as part of the information security assurance function.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8061&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.