No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2013-14/335 · issued 24 Oct 2013 · ~2 min read
Quick answerRBI has issued guidelines for Regional Rural Banks (RRBs) on sharing IT resources to optimize costs while ensuring security and efficiency. RRBs must have strong IT governance, board-level approvals, and agreements with service providers that allow RBI/NABARD audit access.
The rule, in the simplest words
Before sharing IT stuff (like computers or apps), the bank must have a strong plan for how it manages technology and keeps data safe, and the top bosses (board) must say 'yes'.
The bank must sign a paper (agreement) with the company giving the IT stuff, promising that RBI (the main bank boss) and NABARD (another bank boss) can check everything anytime.
Only share IT things like teamwork tools, cleaning-up programs, office helpers, and work apps—not secret customer data without extra care.
The bank must map out where data goes (from bank to company to customers) to make sure it doesn't cross country borders illegally.
How it plays out — a real example
An IT-governance officer in Indore wants to use a shared office automation app from another bank to save money. She first gets board approval, then signs a contract that lets RBI and NABARD inspect the app anytime. She also draws a simple map showing customer loan data stays inside India, so no rules are broken.
What changed
RBI released a circular on October 24, 2013, following paragraph 101 of the Monetary Policy Statement 2013-14, emphasizing shared IT resources for cost optimization. It mandates that RRBs ensure service providers comply with all regulatory and legal requirements, and that RBI and NABARD have access to all consumed information resources.
What it means for you
RRBs can now share IT resources like collaboration tools, housekeeping, office automation, and business applications, but must first establish robust IT and IS governance. They must enter into agreements that guarantee audit access for regulators and address privacy, confidentiality, security, and business continuity. This allows cost savings but adds compliance and oversight responsibilities.
Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.
What banks were required to do at the time
Establish strong IT and IS governance with board-level approvals for any IT resource sharing decisions.
Identify and evaluate assets (data, applications, processes) for sharing, considering impact of security scenarios.
Enter into service agreements that ensure regulatory audit access for RBI and NABARD, and address all legal/geographical data movement requirements.
Map data flows between your bank, service provider, and customers to understand risk tolerance.
Prepare comprehensive service contracts covering architecture, governance, compliance, security, and incident response.
Who it affects
Regional Rural Banks (RRBs), Service providers (including other banks) offering IT resources to RRBs, RBI and NABARD (as regulators with audit access)
❓ Common questions
Regulatory timeline
Decoded by BankPulse2026-06-18 12:10 IST
repealed_by — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
What types of IT applications can RRBs share under these guidelines?
Applications related to collaboration, housekeeping, office automation, and business applications can be considered for sharing, provided they have necessary management approvals.
What must RRBs ensure in their agreements with service providers?
Agreements must guarantee that infrastructure and applications are available for audit/inspection by RBI and NABARD, and that all legal and regulatory requirements regarding data location and cross-border movement are met.
What are the key security concerns RRBs should address?
RRBs must address issues like service levels, security, governance, compliance, liability, infrastructure security, and ensure business continuity, privacy, and confidentiality are fully maintained.
📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Repealed byRBI/2025-26/100 — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
RBI’s words: “Official withdrawal register entry #77: RPCD.CO.RRB.BC.No.45/03.05.33/2013-14 — "Sharing of Information Technology Resources by Banks - Guidelines" dated October 24, 2013”
📜 Read the original circular — full text as issued by RBI
RBI/2013-14/335
RPCD.CO.RRB.BC.No. 45/03.05.33/2013-14
October 24, 2013
The Chairmen
All Regional Rural Banks
Dear Sir,
Sharing of Information Technology Resources by Banks - Guidelines
Please refer to paragraph 101 of the Monetary Policy Statement 2013-14 wherein the need for banks to examine the issue of shared IT resources to optimise costs while maintaining the desired levels of efficiency and security has been emphasised.
2. One of the pre-requisites for a bank to consume shared IT resources is the existence of a strong IT and IS Governance in the bank. It is imperative that decisions on IT resource sharing have necessary approvals of the management possibly at the board level depending on the criticality of the infrastructure or application to be shared. The applications that can be considered for sharing IT resources are those related to collaboration, housekeeping, office automation and business applications.
3. As a consumer, Regional Rural Banks may ensure that the service provider (including another bank) adheres to all regulatory and legal requirements of the country. Regional Rural Banks may necessarily enter into agreement with the service provider that the infrastructure and applications are made available for audit / inspection by the regulators of the country. Reserve Bank of India and NABARD should have access to all information resources that are consumed by Regional Rural Banks, though the resources are not physically located in the premises of banks. Further, Regional Rural Banks have to adhere to the relevant legal and regulatory requirements relating to geographical location of infrastructure and movement of data out of borders.
4. While consuming services provided by other banks or service providers, it may be ensured that all aspects relating to privacy, confidentiality, security and business continuity are fully met.
5. A document which may serve as guidance in this regard is enclosed .
6. Please acknowledge receipt of the letter to our concerned Regional Office.
Yours faithfully,
(A.Udgata)
Principal Chief General Manager
Sharing of Information Technology Resources by Banks - Steps
1. Identify the asset(s) to be included:
Data
Applications/Functions/Process
2. Evaluate the asset on the following factors-
Determine how important the data or function is to the bank
Analyse the impact of the scenarios
The asset becoming widely public & widely distributed
An employee of the service provider accessing the asset
The process or function being manipulated by an outsider
The process or function failing to provide expected results
The info/data being unexpectedly changed
The asset being unavailable for a period of time
3. Choose the external organisation carefully:
A bank
An IT Company
Any other organization
4. Map Data Flow
Map the data flow between bank, service provider, customers, other nodes
Essential to understand whether data can move in/out of the shared infrastructure provided by others
Sketch it for each of the models
Know risk tolerance
5. Assess requirements
Infrastructure
Applications
6. Analyse the Security Concerns
Issues in applications - Service levels, security, governance, compliance, liability expectations of the service provider are contractually defined
Issues in infrastructure - service provider handling Infrastructure security
7. Prepare a service contract addressing the following domains:
Architectural Framework
Governance, Enterprise Risk Management
Legal, e-Discovery
Compliance & Audit
Information Lifecycle Management
Portability & Interoperability
Security, Business Continuity, Disaster Recovery
Data Center Operations
Incident Response Issues
Application Security
Encryption & Key Management
Identity & Access Management
Virtualization
8. Understand the issues in security pitfalls
Geographical location of Infrastructure
Scope network security issues
Control Mechanism
9. Comprehend the overall security concerns
Handing over operational control to service provider while maintaining accountability
10. General Governance issues
Identify, implement process, controls to maintain effective governance, risk management, compliance
Provider security governance should be assessed for sufficiency, maturity, consistency with user ITSEC process
11. 3rd Party Governance issues
Request for clear documentation on how facility & services are assessed
Requirement of definition of what provider considers critical services, information
Perform full contract, terms of use due diligence to determine roles, accountability
12. Analyse legal issues
Functional: functions & services which have legal implications for both parties
Jurisdictional: which governments administer laws and regulations impacting services, stakeholders, data assets
Contractual: terms & conditions
Clarity on provider and consumer's roles
Litigation hold
e-Discovery searches
Expert testimony
Provider must save primary and secondary (logs) data
Location of storage data
Plan for unexpected contract termination and orderly return or secure disposal of assets
Ensuring retention of ownership of data in its original form
13. Examine compliance & audit function
Right to Audit clause
Analyze compliance scope
Regulatory impact on data security
Evidence requirements are met
Appropriate certification such as SAS 70 Type II, ISO 27001/2 audit statements
14. Study Information Lifecycle Management especially in the context of
Data security
Data Location
All copies, backups stored only at location allowed by contract, SLA and/or regulation
15. Analyse portability and interoperability
Factors necessitating switching service providers
Negotiate Contract price increase
Factor in service provider bankruptcy and service shutdown
Decrease in service quality
Business dispute
16. Understand security, business continuity, disaster recovery related issues
Centralization of data means greater insider threat from within the provider
Requirement of onsite inspections of provider facilities
Disaster recovery, Business continuity, of service provider etc.
17. Formulate appropriate Incident Response systems
Applications may not always be designed with data integrity, security in mind
Necessity to store keep application, firewall, IDS etc. logs
Management of snapshots of virtual environment
18. Plan application security
Different trust boundaries for various types of shared resources
Ensure web application security
Secure inter-host communication channel
19. Devise encryption, key management procedures
Encrypt data in transit, at rest, backup media
Secure key store
Protect encryption keys
Ensure encryption is based on industry/government standards
Limit access to key stores
Key backup & recoverability
Test these procedures
20. Manage ID, access control
Determine how service provider handles provisioning, de-provisioning
Authentication
Federation
Authorization
User profile management
21. Plan virtualization
Type of virtualization
3rd party security technology augmenting virtual OS controls that protect admin interfaces
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2013-14/335 · issued 24 Oct 2013. The plain-English explanation above is BankPulse’s own independent summary.
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8524&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.