HomeCirculars › RBI/2024-25/31

RBI Guidance Note on Operational Risk Management and Resilience

No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2024-25/31 · issued 30 Apr 2024 · ~2 min read
Quick answerRBI issued a new guidance note updating the 2005 framework, requiring all commercial banks to strengthen operational risk management and resilience against disruptions from cyber threats, third-party dependencies, and natural causes.

What changed

RBI replaced its 2005 Guidance Note on Operational Risk Management with a new, comprehensive framework based on BCBS 2021 principles. The new note explicitly adds operational resilience as a key objective, covering disruptions from IT threats, geopolitical conflicts, pandemics, and climate change. It adopts a principle-based, proportionate approach for all regulated entities.

What it means for you

Banks must now integrate operational resilience into their risk management frameworks, ensuring they can withstand and recover from disruptions while continuing critical operations. The guidance emphasizes managing third-party and technology risks, which have grown post-pandemic. Regulatory capital requirements for operational risk remain unchanged, but the bar for risk governance and business continuity has been raised.

Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.

What banks were required to do at the time

Who it affects

All commercial banks (Scheduled, RRBs, Urban Co-op Banks, etc.), Risk management teams, Board of Directors and senior management, IT and cybersecurity departments, Third-party vendor management teams

❓ Common questions

Regulatory timeline

Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).

Does this guidance change operational risk capital requirements?

No, the guidance explicitly states that operational risk regulatory capital requirements will continue to be governed by existing applicable guidelines.

Is this a one-size-fits-all mandate?

No, RBI has adopted a proportionate approach, allowing flexibility based on the RE's size, nature, complexity, and risk profile.

What happens if there is a conflict between this guidance and other RBI instructions?

Relevant RBI instructions issued from time to time will prevail over this guidance note.

📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Repealed by RBI/2025-26/100 — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
RBI’s words: “Official withdrawal register entry #116: DOR.ORG.REC.21/14.10.001/2024-25 — "Guidance Note on Operational Risk Management and Operational Resilience" dated April 30, 2024”
📜 Read the original circular — full text as issued by RBI
RBI/2024-25/31 DOR.ORG.REC.21/14.10.001/2024-25 April 30, 2024 1. Purpose 1.1 Operational Risk is inherent in all banking/ financial products, services, activities, processes, and systems. Effective management of Operational Risk is an integral part of the Regulated Entities’ (REs) risk management framework. Sound Management of Operational Risk shows the overall effectiveness of the Board of Directors and Senior Management in administering the RE’s portfolio of products, services, activities, processes, and systems. 1.2 An operational disruption can threaten the viability of an RE, impact its customers and other market participants, and ultimately have an impact on financial stability. It can result from man-made causes, Information Technology (IT) threats (e.g., cyber-attacks, changes in technology, technology failures, etc), geopolitical conflicts, business disruptions, internal/external frauds, execution/ delivery errors, third party dependencies, or natural causes (e.g., climate change, pandemic, etc.). 1.3 An RE needs to factor in the entire gamut of risks (including the aforesaid risks in its risk assessment policies/ processes), identify and assess them using appropriate tools, monitor its material operational exposures and devise appropriate risk mitigation/management strategies using strong internal controls to minimize operational disruptions and continue to deliver critical operations, thus ensuring operational resilience. 1.4 Until recently, the predominant Operational Risks that REs faced emanated from vulnerabilities related to increasing dependence and rapid adoption of technology for provision of financial services and intermediation. However, the financial sector’s growing reliance on third-party providers (including technology service providers) exacerbated by Covid-19 pandemic with greater reliance on virtual working arrangements, has highlighted the increasing importance of Operational Risk Management and Operational Resilience; which not only benefits the RE by strengthening its ability to remain a viable going concern but also supports the financial system by ensuring continuous delivery of critical operations during any disruption. 1.5 In view of the foregoing, the Reserve Bank, through this Guidance Note on Operational Risk Management and Operational Resilience (hereafter ‘Guidance Note’) intends to: 1.5.1 promote and further improve the effectiveness of Operational Risk Management of the REs, and 1.5.2 enhance their Operational Resilience given the interconnections and interdependencies, within the financial system, that result from the complex and dynamic environment in which the REs operate. 1.6 This Guidance Note updates the “ Guidance Note on Management of Operational Risk” dated October 14, 2005 . It has been prepared based on the Basel Committee on Banking Supervision (BCBS) principles documents issued in March 2021, viz., (a) ‘Revisions to the Principles for the Sound Management of Operational Risk’ and (b) ‘Principles for Operational Resilience’ as well as the some of the international best practices. 1.7 The Guidance Note has adopted a principle-based and proportionate approach to ensure smooth implementation across REs of various sizes, nature, complexity, geographic location and risk profile of their businesses. Although the exact approach may vary from RE to RE, the Guidance Note provides an overarching guidance to REs for improving and further strengthening their Operational Risk Management Framework (ORMF). It gives adequate flexibility to REs for Operational Risk Management to enhance their ability to withstand, adapt and recover from potential operational disruptions and ensure their Operational Resilience. The systems, procedures and tools prescribed in this Guidance Note are indicative in nature and should be read in conjunction with the relevant instructions issued by Reserve Bank from time to time. In case of inconsistency, if any, the relevant instructions issued by the Reserve Bank would prevail. 1.8 The operational risk regulatory capital requirements shall continue to be guided by the applicable guidelines 1 . 2. Application 2.1 This Guidance Note shall apply to the following REs: 2.1.1 All Commercial Banks 2 ; 2.1.2 All Primary (Urban) Co-operative Banks/State Co-operative Banks/Central Co-operative Banks; 2.1.3 All All-India Financial Institutions (viz., Exim Bank, NABARD, NHB, SIDBI, and NaBFID); and 2.1.4 All Non-Banking Financial Companies including Housing Finance Companies. 3. Repeal and Transitional Arrangements With the issuance of this Guidance Note the “ Guidance Note on Management of Operational Risk” dated October 14, 2005 , stands repealed. 4. Key changes Key changes carried out in this Guidance Note vis-à-vis the repealed Guidance Note are given in Annex . Yours faithfully, (Sunil T. S. Nair) Chief General Manager Guidance Note on Operational Risk Management and Operational Resilience Index Sr. No.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2024-25/31 · issued 30 Apr 2024. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12679&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗