Reserve Bank of India (Credit Information Companies – Managing Risks in Outsourcing) Directions, 2025
UR
- Applies toCredit information companies
- StatusIn force
- ImportanceMUST READ
- IssuedNovember 28, 2025
- Amendmentsnone tracked
- Length35 points in 5 sections · 3 min read
The four dates on this rule
- PublishedNovember 28, 2025The day RBI put this document out.
- Starts to applyNot statedNot stated separately in this document. Read the rule itself before you assume a start date.
- Time to get readyNot statedCannot be worked out until the day it starts to apply is known.
- Last date to actNot statedNo date to act by was found in this document. Other dates may sit inside single paragraphs.
Kept in your browser only. Your desk
Show me the points for
Nothing is removed from the page.
What it says
Chapter I. Preliminary
1. Deadline for existing deals
Existing IT outsourcing deals must follow these rules by April 10, 2026, or renewal, whichever comes first.
2. Outsourcing rules for CICs
This document sets the outsourcing rules for credit information companies.
3. Start date
These Directions came into effect on the day the Reserve Bank issued them.
4. Who is covered
These Directions apply to every credit information company.
Chapter II. Role of the Board
1. Responsibility stays with CIC
Outsourcing an IT service never lowers a CIC's own responsibility for it.
Chapter III. Outsourcing of Information Technology (IT) Services
Must know
1. Nothing deleted in transition
The provider may not wipe or change data while the work is being moved.
Do it
2. Weigh the IT case
The case for giving out an IT job must be weighed against its risks.
3. A framework for IT risk
A risk plan must cover how IT risks are found, sized and reported.
4. Too much with one provider
The lender must weigh the risk of leaning on one provider too much.
5. Guard the customer data
Customer data held by the provider must be kept safe.
6. Watch their security
The lender must check the provider's safety steps often, and note any breach.
BankPulse example. A bank hires an outside firm to host its records. Signing the contract is not the end of it. The bank must review and monitor that provider's security practices and control processes on a regular basis.
7. Due diligence each renewal
The provider must be checked when hired and again at each renewal.
BankPulse example. A bank's outsourcing arrangement comes up for renewal after three years. Due diligence is done again, not only when it was first signed. The question each time is whether the service provider can still meet the obligations.
8. Look outside as well
Outside reviews and market feedback should back up our own checks.
BankPulse example. A bank's own checks on a provider are not the whole picture. It also obtains independent reviews and market feedback on that service provider. Those supplement the findings of its own due diligence.
9. Put it in writing
What each side owes the other must be set out in a written deal that binds.
10. Lawyer must vet it
A lawyer must check the written deal and say it will hold.
11. Room to step in
The deal must leave room to step in to meet the law.
12. Say what the relationship is
The deal must say whether the tie is agent and principal, or not.
13. A structure to watch it
There must be a team in place to watch and steer the work given out.
14. Audit the provider
The lender must audit the provider and anyone it hires.
15. Report any slippage
The review must bring out any drop in service, secrecy or safety.
16. An inventory of IT services
The lender must keep a list of the IT jobs it has given out.
17. Map the dependency
The lender must map how much it leans on outside firms.
18. Continuity must be tested
The provider must write down, keep and test its plans to keep work going.
19. Name the alternative
The exit plan must identify who else could do the work, or whether it comes back in-house.
20. Destroy the data safely
The deal must say how data and records are to be wiped or destroyed.
21. Announce the ending
Where a provider dealt with customers, the end of the deal must be made known.
22. Group choice on merit
A group firm must be picked on the same plain grounds as an outside firm.
23. Arm's length always
The lender must always deal with group firms at arm's length.
24. Watch the host country
Where a provider is abroad, its country's rule and politics must be watched.
Background
25. Need to know only
A provider's staff may see customer data only where the job needs it.
26. Joint vendor audits
CICs using the same vendor can share one joint audit instead of separate ones.
27. Risk sets the audit cycle
How often the audit happens turns on the risk and what is at stake.
28. Board hears the bad news
Reports go to senior staff, and anything bad goes up to the Board.
29. Complaint responsibility
The credit information company alone is responsible for fixing complaints about outsourced services.
Chapter IV. Repeal and Other Provisions
1. Old cases continue
Action already taken under the old rules stays governed by them.
The same subject for other kinds of institution
The same subject for other kinds of institution.
Other RBI rules for credit information companies
RBI cyber security rules for credit information companies 2026
RBI internal ombudsman rules for credit information companies 2026
RBI miscellaneous rules for credit information companies 2026
Every rule page on BankPulse · Questions bankers ask, answered