Current · Source: Reserve Bank of India · RBI/2013-14/216 · issued 30 Aug 2013 · ~2 min read
Quick answerRBI issued guidelines for banks to share IT resources for cost optimization, emphasizing strong IT governance, board-level approvals for critical assets, and strict adherence to security, privacy, and audit requirements. Banks must ensure service providers comply with all regulatory and legal norms.
The rule, in the simplest words
Banks must get board-level approval before sharing important IT stuff (like computers or apps) with other banks or companies.
Banks must check that the company they share with follows all Indian laws and lets the RBI (India's bank boss) check their computers anytime.
Banks must map how data (like customer info) moves between them, the sharing partner, and customers to keep it safe and follow rules.
Banks must sign a contract that says the shared computers and apps can be audited (checked) by regulators and must keep data inside India unless allowed.
How it plays out — a real example
An IT-governance officer in Indore wants to share a customer-tracking app with a smaller bank to save money. She first gets her bank's board to approve the sharing, then checks that the smaller bank follows all RBI rules and lets RBI inspect the app. She also draws a map showing how customer data flows from her bank to the smaller bank and back, ensuring no data leaves India without permission.
What changed
RBI issued guidelines in 2013 for banks to share IT resources, providing a structured framework for evaluating assets, mapping data flows, and entering into service contracts covering security, governance, and compliance. Banks must ensure regulatory access to all shared IT resources, even if located off-premises.
What it means for you
Banks can now collaborate to reduce IT costs by sharing infrastructure and applications, but must maintain high governance and security standards. This opens opportunities for smaller banks to access advanced IT capabilities, while all banks must strengthen vendor risk management and audit readiness. Non-compliance with data localization or privacy norms could attract regulatory action.
What you must do
Identify and classify IT assets (data, applications, processes) for potential sharing, with management approval possibly at the board level depending on criticality.
Conduct thorough due diligence on service providers, including other banks, ensuring they meet all legal and regulatory requirements.
Map data flows between your bank, service provider, and customers to assess risks and ensure data movement complies with RBI norms.
Draft comprehensive service contracts covering architecture, governance, security, business continuity, and audit rights for regulators.
Establish ongoing governance processes to monitor provider security maturity and maintain accountability for shared resources.
Who it affects
All Scheduled Commercial Banks (excluding RRBs), IT and IS Governance teams, Risk and compliance departments, Vendor management and procurement teams, Board of Directors (for critical asset approvals)
❓ Common questions
What types of applications can be shared under these guidelines?
Applications related to collaboration, housekeeping, office automation, and business applications are eligible for sharing. Critical infrastructure or applications require management approval, possibly at the board level depending on criticality.
Do we need to allow RBI to audit shared IT resources?
Yes, the service contract must ensure that regulators of the country have access to all information resources consumed by the bank, even if they are not physically located on the bank's premises. The service provider must agree to audit/inspection by regulators.
📜 Read the original circular — full text as issued by RBI
RBI/2013-14/216
DIT.CO (Policy) No.674/09.63.025/2013-14
August 30, 2013
The Chairman/Chief Executive Officers
All Scheduled Commercial Banks
(excluding RRBs)
Dear Sir/Madam
Sharing of Information Technology Resources by Banks - Guidelines
Please refer to paragraph 101 of the Monetary Policy Statement 2013-14 wherein the need for banks to examine the issue of shared IT resources to optimise costs while maintaining the desired levels of efficiency and security has been emphasised.
2. One of the pre-requisites for a bank to consume shared IT resources is the existence of a strong IT and IS Governance in the bank. It is imperative that decisions on IT resource sharing have necessary approvals of the management possibly at the board level depending on the criticality of the infrastructure or application to be shared. The applications that can be considered for sharing IT resources are those related to collaboration, housekeeping, office automation and business applications.
3. As a consumer, banks may ensure that the service provider (including another bank) adheres to all regulatory and legal requirements of the country. Banks may necessarily enter into agreement with the service provider that the infrastructure and applications are made available for audit / inspection by the regulators of the country. Reserve Bank of India should have access to all information resources that are consumed by banks, though the resources are not physically located in the premises of banks. Further, banks have to adhere to the relevant legal and regulatory requirements relating to geographical location of infrastructure and movement of data out of borders.
4. While consuming services provided by other banks or service providers, it may be ensured that all aspects relating to privacy, confidentiality, security and business continuity are fully met.
5. A document which may serve as guidance in this regard is enclosed .
6. Please acknowledge receipt of the letter.
Yours faithfully
(A S Ramasastri)
CGM-in-C
Encl: as stated
Sharing of Information Technology Resources by Banks - Steps
1. Identify the asset(s) to be included:
Data
Applications/Functions/Process
2. Evaluate the asset on the following factors-
Determine how important the data or function is to the bank
Analyse the impact of the scenarios
The asset becoming widely public & widely distributed
An employee of the service provider accessing the asset
The process or function being manipulated by an outsider
The process or function failing to provide expected results
The info/data being unexpectedly changed
The asset being unavailable for a period of time
3. Choose the external organisation carefully:
A bank
An IT Company
Any other organization
4. Map Data Flow
Map the data flow between bank, service provider, customers, other nodes
Essential to understand whether and data can move in/out of the shared infrastructure provided by others
Sketch it for each of the models
Know risk tolerance
5. Assess requirements
Infrastructure
Applications
6. Analyse the Security Concerns
Issues in applications - Service levels, security, governance, compliance, liability expectations of the service & provider are contractually defined
Issues in infrastructure - service provider handling Infrastructure security
7. Prepare a service contract addressing the following domains:
Architectural Framework
Governance, Enterprise Risk Management
Legal, e-Discovery
Compliance & Audit
Information Lifecycle Management
Portability & Interoperability
Security, Business Continuity, Disaster Recovery
Data Center Operations
Incident Response Issues
Application Security
Encryption & Key Management
Identity & Access Management
Virtualization
8. Understand the issues in security pitfalls
Geographical location of Infrastructure
Scope network security issues
Control Mechanism
9. Comprehend the overall security concerns
a. Handing over operational control to service provider while maintaining accountability
10. General Governance issues
Identify, implement process, controls to maintain effective governance, risk management, compliance
Provider security governance should be assessed for sufficiency, maturity, consistency with user ITSEC proces
11. 3rd Party Governance issues
Request for clear documentation on how facility & services are assessed
Requirement of definition of what provider considers critical services, information
Perform full contract, terms of use due diligence to determine roles, accountability
12. Analyse legal issues
Functional: functions & services which have legal implications for both parties
Jurisdictional: which governments administer laws and regulations impacting services, stakeholders, data assets
Contractual: terms & conditions
Clarity on provider and consumer's roles
Litigation hold
e-Discovery searches
Expert testimony
Provider must save primary and secondary (logs) data
location of storage data
Plan for unexpected contract termination and orderly return or secure disposal of assets
ensuring to retaining ownership of data in its original form
13. Examine compliance & audit function
Right to Audit clause
Analyze compliance scope
Regulatory impact on data security
Evidence requirements are met
Appropriate certification such as SAS 70 Type II, ISO 27001/2 audit statements
14. Study Information Lifecycle Management especially in the context of
Data security
Data Location
All copies, backups stored only at location allowed by contract, SLA and/or regulation
15. Analyse portability and interoperability
Factors necessitating switching service providers
Negotiate Contract price increase
Factor in service provider bankruptcy and service shutdown
Decrease in service quality
Business dispute
16. Understand security, business continuity, disaster recovery related issues
Centralization of data means greater insider threat from within the provider
Requirement of onsite inspections of provider facilities
Disaster recovery, Business continuity, of service provider etc.
17. Formulate appropriate Incident Response systems
Applications may not always be designed with data integrity, security in mind
Necessity to store keep application, firewall, IDS etc. logs
Management of snapshots of virtual environment
18. Plan application security
Different trust boundaries for various types of shared resources
Ensure web application security
Secure inter-host communication channel
19. Devise encryption, key management procedures
Encrypt data in transit, at rest, backup media
Secure key store
Protect encryption keys
Ensure encryption is based on industry/government standards
Limit access to key stores
Key backup & recoverability
Test these procedures
20. Manage ID, access control
Determine how service provider handles provisioning, de-provisioning
Authentication
Federation
Authorization
User profile management
21. Plan virtualization
Type of virtualization
3rd party security technology augmenting virtual OS controls that protect admin interfaces
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2013-14/216 · issued 30 Aug 2013. The plain-English explanation above is BankPulse’s own independent summary.
Identify and classify IT assets (data, applications, processes) for potential sharing, with management approval possibly at the board level depending on criticality.
📜 Compliance
Conduct thorough due diligence on service providers, including other banks, ensuring they meet all legal and regulatory requirements.
Map data flows between your bank, service provider, and customers to assess risks and ensure data movement complies with RBI norms.
Draft comprehensive service contracts covering architecture, governance, security, business continuity, and audit rights for regulators.
Establish ongoing governance processes to monitor provider security maturity and maintain accountability for shared resources.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are an IT/Systems lead at a bank this circular applies to (All Scheduled Commercial Banks (excluding RRBs), IT and IS Governance teams, Risk and compliance departments, Vendor management and procurement teams, Board of Directors (for critical asset approvals)), your first concrete step on “RBI Guidelines on Sharing IT Resources by Banks” is: “Identify and classify IT assets (data, applications, processes) for potential sharing, with management approval possibly at the board level depending on criticality.” (RBI issued this 30 Aug 2013).
Circular: RBI/2013-14/216 -- RBI Guidelines on Sharing IT Resources by Banks
Issued: 30 Aug 2013
Action required: Identify and classify IT assets (data, applications, processes) for potential sharing, with management approval possibly at the board level depending on criticality.
Action required: Conduct thorough due diligence on service providers, including other banks, ensuring they meet all legal and regulatory requirements.
Action required: Map data flows between your bank, service provider, and customers to assess risks and ensure data movement complies with RBI norms.
Action required: Draft comprehensive service contracts covering architecture, governance, security, business continuity, and audit rights for regulators.
Action required: Establish ongoing governance processes to monitor provider security maturity and maintain accountability for shared resources.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8365&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.