HomeCirculars › RBI/2013-14/216

RBI Guidelines on Sharing IT Resources by Banks

Current · Source: Reserve Bank of India · RBI/2013-14/216 · issued 30 Aug 2013 · ~2 min read
Quick answerRBI issued guidelines for banks to share IT resources for cost optimization, emphasizing strong IT governance, board-level approvals for critical assets, and strict adherence to security, privacy, and audit requirements. Banks must ensure service providers comply with all regulatory and legal norms.
The rule, in the simplest words
How it plays out — a real example

An IT-governance officer in Indore wants to share a customer-tracking app with a smaller bank to save money. She first gets her bank's board to approve the sharing, then checks that the smaller bank follows all RBI rules and lets RBI inspect the app. She also draws a map showing how customer data flows from her bank to the smaller bank and back, ensuring no data leaves India without permission.

What changed

RBI issued guidelines in 2013 for banks to share IT resources, providing a structured framework for evaluating assets, mapping data flows, and entering into service contracts covering security, governance, and compliance. Banks must ensure regulatory access to all shared IT resources, even if located off-premises.

What it means for you

Banks can now collaborate to reduce IT costs by sharing infrastructure and applications, but must maintain high governance and security standards. This opens opportunities for smaller banks to access advanced IT capabilities, while all banks must strengthen vendor risk management and audit readiness. Non-compliance with data localization or privacy norms could attract regulatory action.

What you must do

Who it affects

All Scheduled Commercial Banks (excluding RRBs), IT and IS Governance teams, Risk and compliance departments, Vendor management and procurement teams, Board of Directors (for critical asset approvals)

❓ Common questions

What types of applications can be shared under these guidelines?

Applications related to collaboration, housekeeping, office automation, and business applications are eligible for sharing. Critical infrastructure or applications require management approval, possibly at the board level depending on criticality.

Do we need to allow RBI to audit shared IT resources?

Yes, the service contract must ensure that regulators of the country have access to all information resources consumed by the bank, even if they are not physically located on the bank's premises. The service provider must agree to audit/inspection by regulators.

📜 Read the original circular — full text as issued by RBI
RBI/2013-14/216 DIT.CO (Policy) No.674/09.63.025/2013-14 August 30, 2013 The Chairman/Chief Executive Officers All Scheduled Commercial Banks (excluding RRBs) Dear Sir/Madam Sharing of Information Technology Resources by Banks - Guidelines Please refer to paragraph 101 of the Monetary Policy Statement 2013-14 wherein the need for banks to examine the issue of shared IT resources to optimise costs while maintaining the desired levels of efficiency and security has been emphasised. 2. One of the pre-requisites for a bank to consume shared IT resources is the existence of a strong IT and IS Governance in the bank. It is imperative that decisions on IT resource sharing have necessary approvals of the management possibly at the board level depending on the criticality of the infrastructure or application to be shared. The applications that can be considered for sharing IT resources are those related to collaboration, housekeeping, office automation and business applications. 3. As a consumer, banks may ensure that the service provider (including another bank) adheres to all regulatory and legal requirements of the country. Banks may necessarily enter into agreement with the service provider that the infrastructure and applications are made available for audit / inspection by the regulators of the country. Reserve Bank of India should have access to all information resources that are consumed by banks, though the resources are not physically located in the premises of banks. Further, banks have to adhere to the relevant legal and regulatory requirements relating to geographical location of infrastructure and movement of data out of borders. 4. While consuming services provided by other banks or service providers, it may be ensured that all aspects relating to privacy, confidentiality, security and business continuity are fully met. 5. A document which may serve as guidance in this regard is enclosed . 6. Please acknowledge receipt of the letter. Yours faithfully (A S Ramasastri) CGM-in-C Encl: as stated Sharing of Information Technology Resources by Banks - Steps 1. Identify the asset(s) to be included: Data Applications/Functions/Process 2. Evaluate the asset on the following factors- Determine how important the data or function is to the bank Analyse the impact of the scenarios The asset becoming widely public & widely distributed An employee of the service provider accessing the asset The process or function being manipulated by an outsider The process or function failing to provide expected results The info/data being unexpectedly changed The asset being unavailable for a period of time 3. Choose the external organisation carefully: A bank An IT Company Any other organization 4. Map Data Flow Map the data flow between bank, service provider, customers, other nodes Essential to understand whether and data can move in/out of the shared infrastructure provided by others Sketch it for each of the models Know risk tolerance 5. Assess requirements Infrastructure Applications 6. Analyse the Security Concerns Issues in applications - Service levels, security, governance, compliance, liability expectations of the service  & provider are contractually defined Issues in infrastructure - service provider handling Infrastructure security 7. Prepare a service contract addressing the following domains: Architectural Framework Governance, Enterprise Risk Management Legal, e-Discovery Compliance & Audit Information Lifecycle Management Portability & Interoperability Security, Business Continuity, Disaster Recovery Data Center Operations Incident Response Issues Application Security Encryption & Key Management Identity & Access Management Virtualization 8. Understand the issues in security pitfalls Geographical location of Infrastructure Scope network security issues Control Mechanism 9. Comprehend the overall security concerns a. Handing over operational control to service provider while maintaining accountability 10. General Governance issues Identify, implement process, controls to maintain effective governance, risk management, compliance Provider security governance should be assessed for sufficiency, maturity, consistency with user ITSEC proces 11. 3rd Party Governance issues Request for clear documentation on how facility & services are assessed Requirement of definition of what provider considers critical services, information Perform full contract, terms of use due diligence to determine roles, accountability 12. Analyse legal issues Functional: functions & services which have legal implications for both parties Jurisdictional: which governments administer laws and regulations impacting services, stakeholders, data assets Contractual: terms & conditions Clarity on provider and consumer's roles Litigation hold e-Discovery searches Expert testimony Provider must save primary and secondary (logs) data location of storage data   Plan for unexpected contract termination and orderly return or secure disposal of assets ensuring to retaining ownership of data in its original form 13. Examine compliance & audit function Right to Audit clause Analyze compliance scope Regulatory impact on data security Evidence requirements are met Appropriate certification such as SAS 70 Type II, ISO 27001/2 audit statements 14. Study Information Lifecycle Management especially in the context of Data security Data Location All copies, backups stored only at location allowed by contract, SLA and/or regulation 15. Analyse portability and interoperability Factors necessitating switching service providers Negotiate Contract price increase Factor in service provider bankruptcy and service shutdown Decrease in service quality Business dispute 16. Understand security, business continuity, disaster recovery related issues Centralization of data means greater insider threat from within the provider Requirement of onsite inspections of provider facilities Disaster recovery, Business continuity, of service provider etc. 17. Formulate appropriate Incident Response systems Applications may not always be designed with data integrity, security in mind Necessity to store keep application, firewall, IDS etc. logs Management of snapshots of virtual environment 18. Plan application security Different trust boundaries for various types of shared resources Ensure web application security Secure inter-host communication channel 19. Devise encryption, key management procedures Encrypt data in transit, at rest, backup media Secure key store Protect encryption keys Ensure encryption is based on industry/government standards Limit access to key stores Key backup & recoverability Test these procedures 20. Manage ID, access control Determine how service provider handles provisioning, de-provisioning Authentication Federation Authorization User profile management 21. Plan virtualization Type of virtualization 3rd party security technology augmenting virtual OS controls that protect admin interfaces
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2013-14/216 · issued 30 Aug 2013. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
💻 IT / Systems
  • Identify and classify IT assets (data, applications, processes) for potential sharing, with management approval possibly at the board level depending on criticality.
📜 Compliance
  • Conduct thorough due diligence on service providers, including other banks, ensuring they meet all legal and regulatory requirements.
  • Map data flows between your bank, service provider, and customers to assess risks and ensure data movement complies with RBI norms.
  • Draft comprehensive service contracts covering architecture, governance, security, business continuity, and audit rights for regulators.
  • Establish ongoing governance processes to monitor provider security maturity and maintain accountability for shared resources.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are an IT/Systems lead at a bank this circular applies to (All Scheduled Commercial Banks (excluding RRBs), IT and IS Governance teams, Risk and compliance departments, Vendor management and procurement teams, Board of Directors (for critical asset approvals)), your first concrete step on “RBI Guidelines on Sharing IT Resources by Banks” is: “Identify and classify IT assets (data, applications, processes) for potential sharing, with management approval possibly at the board level depending on criticality.” (RBI issued this 30 Aug 2013).

  1. Circular: RBI/2013-14/216 -- RBI Guidelines on Sharing IT Resources by Banks
  2. Issued: 30 Aug 2013
  3. Action required: Identify and classify IT assets (data, applications, processes) for potential sharing, with management approval possibly at the board level depending on criticality.
  4. Action required: Conduct thorough due diligence on service providers, including other banks, ensuring they meet all legal and regulatory requirements.
  5. Action required: Map data flows between your bank, service provider, and customers to assess risks and ensure data movement complies with RBI norms.
  6. Action required: Draft comprehensive service contracts covering architecture, governance, security, business continuity, and audit rights for regulators.
  7. Action required: Establish ongoing governance processes to monitor provider security maturity and maintain accountability for shared resources.
  8. Owner: ____________ Target date: ____________
  9. Board/committee approval needed? Y / N
  10. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8365&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗