Reserve Bank of India (Urban Co-operative Banks – Managing Risks in Outsourcing) Directions, 2025
UR
- Applies toUrban co-operative banks
- StatusIn force
- ImportanceMUST READ
- IssuedNovember 28, 2025
- Amendmentsnone tracked
- Length67 points in 5 sections · 6 min read
The four dates on this rule
- PublishedNovember 28, 2025The day RBI put this document out.
- Starts to applyNot statedNot stated separately in this document. Read the rule itself before you assume a start date.
- Time to get readyNot statedCannot be worked out until the day it starts to apply is known.
- Last date to actApril 10, 2026The day by which the work this rule asks for must be finished.
Kept in your browser only. Your desk
Show me the points for
Nothing is removed from the page.
What it says
Chapter I. Preliminary
Must know
1. Deadline for existing deals
Existing IT outsourcing deals must follow these rules by April 10, 2026, or renewal, whichever comes first.
Do it
2. New deals
New IT outsourcing deals must follow the rules from the day they are signed.
Background
3. Outsourcing rules for UCBs
This document sets the outsourcing rules for urban co-operative banks.
4. Start date
These Directions came into effect on the day the Reserve Bank issued them.
5. Who is covered
These Directions apply to every urban co-operative bank.
6. Tier-3 and Tier-4 scope
IT outsourcing rules under Chapter IV apply only to Tier-3 and Tier-4 UCBs.
7. Services excluded
Courier, catering, housekeeping, security, and the moving and storing of records are not covered.
8. Material IT outsourcing only
IT outsourcing rules apply to material IT outsourcing, not a size-based tier.
Chapter II. Role of the Board
1. Board-approved policy
The bank's Board must approve the outsourcing policy before outsourcing starts.
Chapter III. Outsourcing of Financial Services
Must know
1. Functions never outsourced
A bank can never hand off internal audit, compliance checks, KYC decisions or loan sanctioning to an outsider.
2. Director-owned vendors barred
A service provider cannot be owned or controlled by the bank's own director, officer or their relatives.
3. Contract risk named
There is a risk that the deal with the provider cannot be enforced.
4. No mixing of records
Where a provider serves many firms, records must not be mixed.
5. Breach disclosure
Banks must tell RBI immediately about any security breach or data leak.
6. Customer complaint rights
Outsourcing never removes a customer's right to complain against the bank.
7. Answer within thirty days
A complaint must be answered within 30 days at the most, and the procedure must sit on the website.
Do it
8. Control stays at home
The lender must keep full control of the work it gives out.
9. Nine risks to weigh
Nine named risks must be weighed before work is given out.
10. Guard the customer data
Customer data held by the provider must be kept safe.
11. Watch their security
The lender must check the provider's safety steps often, and note any breach.
BankPulse example. A bank hires an outside firm to host its records. Signing the contract is not the end of it. The bank must review and monitor that provider's security practices and control processes on a regular basis.
12. Keep our records separable
The provider must be able to pick out our records and assets.
13. Lawyer must vet it
A lawyer must check the written deal and say it will hold.
14. Agreement must handle risk
The deal must name the risks and say how they will be held down.
15. Room to step in
The deal must leave room to step in to meet the law.
16. Say what the relationship is
The deal must say whether the tie is agent and principal, or not.
17. A structure to watch it
There must be a team in place to watch and steer the work given out.
18. Central outsourcing record
The bank must keep a central record of each material financial-services outsourcing deal. The Board and senior management review it.
19. A yearly financial review
The provider's money and work health must be checked at least once a year.
20. Report any slippage
The review must bring out any drop in service, secrecy or safety.
21. Reconcile in time
Deals with the provider and its helpers must be matched up on time.
22. Test it together
The provider must test the plan from time to time, and joint drills may be held.
23. Have a way back
The backup plan must look at another provider, or taking the work back.
24. Watch the host country
Where a provider is abroad, its country's rule and politics must be watched.
25. Tell the customer
Where a customer must deal with a provider, the leaflet must say so.
26. Grievances without delay
The named officer must see that real customer complaints are put right fast.
Background
27. Hiring former employees
Former employees can be hired only if the Audit Committee confirms no in-house expertise exists.
28. Duties do not move out
Giving work out does not cut what the lender owes its customers or RBI.
29. Agent conduct liability
Banks stay responsible for what their sales agents and recovery agents do.
30. Suspicious reports stay ours
Cash and suspicious deal reports stay the lender's own job.
31. Compliance risk named
There is a risk that giving work out breaks privacy or other law.
32. Need to know only
A provider's staff may see customer data only where the job needs it.
33. Data leak liability
If customer data leaks through a vendor, the bank is liable to customers for damage.
34. Half-yearly record review
Outsourcing records go for half-yearly review by the Board too.
35. Only confidential jurisdictions
Work may go abroad only to a country that upholds secrecy terms.
36. The stricter rule wins
Where these rules and the host country's differ, the stricter one wins.
37. Complaint responsibility
The bank alone is responsible for fixing complaints about outsourced services.
Chapter IV. Outsourcing of Information Technology (IT) Services
Must know
1. Cyber incident reporting
Banks must tell RBI about a cyber incident within six hours of learning about it.
2. Nothing deleted in transition
The provider may not wipe or change data while the work is being moved.
Do it
3. Weigh the IT case
The case for giving out an IT job must be weighed against its risks.
4. Due diligence each renewal
The provider must be checked when hired and again at each renewal.
BankPulse example. A bank's outsourcing arrangement comes up for renewal after three years. Due diligence is done again, not only when it was first signed. The question each time is whether the service provider can still meet the obligations.
5. Look outside as well
Outside reviews and market feedback should back up our own checks.
BankPulse example. A bank's own checks on a provider are not the whole picture. It also obtains independent reviews and market feedback on that service provider. Those supplement the findings of its own due diligence.
6. Systems must fit
The provider's systems must work with ours, and their service must be good enough.
7. A framework for IT risk
A risk plan must cover how IT risks are found, sized and reported.
8. Too much with one provider
The lender must weigh the risk of leaning on one provider too much.
9. Put it in writing
What each side owes the other must be set out in a written deal that binds.
10. Audit the provider
The lender must audit the provider and anyone it hires.
11. An inventory of IT services
The lender must keep a list of the IT jobs it has given out.
12. Map the dependency
The lender must map how much it leans on outside firms.
13. Plan for each way out
The exit plan must cover each way the deal may end, and the time each needs.
14. Name the alternative
The exit plan must identify who else could do the work, or whether it comes back in-house.
15. Destroy the data safely
The deal must say how data and records are to be wiped or destroyed.
16. Must help the successor
The provider is bound to help the next provider hand over smoothly.
17. Announce the ending
Where a provider dealt with customers, the end of the deal must be made known.
Background
18. Joint vendor audits
CICs using the same vendor can share one joint audit instead of separate ones.
19. Risk sets the audit cycle
How often the audit happens turns on the risk and what is at stake.
Chapter V. Repeal and Other Provisions
1. Older rules cancelled
This document cancels all older outsourcing rules for commercial banks.
2. Old cases continue
Action already taken under the old rules stays governed by them.
The same subject for other kinds of institution
The same subject for other kinds of institution.
Other RBI rules for urban co-operative banks
RBI capital adequacy rules for urban co-operative banks 2025
RBI compliance officer and compliance function rules for urban co-operative banks
RBI concurrent audit rules for urban co-operative banks 2026
RBI credit bureau reporting rules for urban co-operative banks 2025
RBI credit card and debit card rules for urban co-operative banks 2025
RBI customer service and fair conduct rules for urban co-operative banks 2025
Every rule page on BankPulse · Questions bankers ask, answered