Skip to content
BankPulseBETARegulatory intelligence for Indian banking
Directions · Reserve Bank of India

Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025

UR

The four dates on this rule

At a glanceOutsourcing a task never lowers the bank's own responsibility for it. These Directions apply to every commercial bank. The provider's money and work health must be checked at least once a year.

Official RBI page

What it says

Chapter I. Preliminary

Must know

1. Deadline for existing deals

Existing IT outsourcing deals must follow these rules by April 10, 2026, or renewal, whichever comes first.

2. Sub-contractor approval

A vendor cannot bring in a sub-contractor without the bank's own approval first.

Do it

3. New deals

New IT outsourcing deals must follow the rules from the day they are signed.

4. Consent needs a check first

Before saying yes, the lender must check that the sub-deal follows the rules.

Background

5. Outsourcing rules for banks

This document sets the outsourcing rules for commercial banks.

6. Start date

These Directions came into effect on the day the Reserve Bank issued them.

7. Who is covered

These Directions apply to every commercial bank.

8. Board oversight abroad

For a foreign bank branch, the Board means the head or controlling office.

9. Foreign branch exception

Foreign bank branches can skip an IT rule only if RBI accepts their explanation.

10. Subcontractors are covered too

These rules apply the same way to work passed on to another firm.

11. Services excluded

Courier, catering, housekeeping, security, and the moving and storing of records are not covered.

12. Audit work separate

Audit work given to Chartered Accountant firms follows separate RBI rules, not these ones.

13. Material IT outsourcing only

IT outsourcing rules apply to material IT outsourcing, not a size-based tier.

Chapter II. Role of the Board

1. Responsibility stays with bank

Outsourcing a task never lowers the bank's own responsibility for it.

2. Board review cycle

The Board must review all major outsourcing deals every six months.

3. Board-approved policy

The bank's Board must approve the outsourcing policy before outsourcing starts.

4. Audit Committee oversight

The Audit Committee of the Board must watch internal audit of all outsourced work.

Chapter III. Outsourcing of Financial Services

Must know

1. Contract risk named

There is a risk that the deal with the provider cannot be enforced.

2. No mixing of records

Where a provider serves many firms, records must not be mixed.

3. Breach disclosure

Banks must tell RBI immediately about any security breach or data leak.

4. Own operations must survive

Work must not stop if a group firm's premises or systems go down.

5. Not answerable for the group

No advert may say the lender stands behind a group firm's dues.

6. Customer complaint rights

Outsourcing never removes a customer's right to complain against the bank.

Do it

7. Control stays at home

The lender must keep full control of the work it gives out.

8. Nine risks to weigh

Nine named risks must be weighed before work is given out.

9. Guard the customer data

Customer data held by the provider must be kept safe.

10. Watch their security

The lender must check the provider's safety steps often, and note any breach.

BankPulse example. A bank hires an outside firm to host its records. Signing the contract is not the end of it. The bank must review and monitor that provider's security practices and control processes on a regular basis.

11. Keep our records separable

The provider must be able to pick out our records and assets.

12. Due diligence each renewal

The provider must be checked when hired and again at each renewal.

BankPulse example. A bank's outsourcing arrangement comes up for renewal after three years. Due diligence is done again, not only when it was first signed. The question each time is whether the service provider can still meet the obligations.

13. Look outside as well

Outside reviews and market feedback should back up our own checks.

BankPulse example. A bank's own checks on a provider are not the whole picture. It also obtains independent reviews and market feedback on that service provider. Those supplement the findings of its own due diligence.

14. Systems must fit

The provider's systems must work with ours, and their service must be good enough.

15. Lawyer must vet it

A lawyer must check the written deal and say it will hold.

16. Agreement must handle risk

The deal must name the risks and say how they will be held down.

17. Room to step in

The deal must leave room to step in to meet the law.

18. Say what the relationship is

The deal must say whether the tie is agent and principal, or not.

19. A structure to watch it

There must be a team in place to watch and steer the work given out.

20. Central outsourcing record

The bank must keep a central record of each material financial-services outsourcing deal. The Board and senior management review it.

21. A yearly financial review

The provider's money and work health must be checked at least once a year.

22. Report any slippage

The review must bring out any drop in service, secrecy or safety.

23. Reconcile in time

Deals with the provider and its helpers must be matched up on time.

24. Continuity must be tested

The provider must write down, keep and test its plans to keep work going.

25. Test it together

The provider must test the plan from time to time, and joint drills may be held.

26. Have a way back

The backup plan must look at another provider, or taking the work back.

27. Ended-contract reporting

If a bank ends a financial-service vendor's contract, it must tell the Indian Banks' Association why.

28. Group party, same rules

Work given to a group firm must follow the same rules as work given outside.

29. Shared premises, clear identity

Where a group firm shares the premises, its name must be clear to customers.

30. Say who is selling

Leaflets and staff must make clear how the group firm is tied to the lender.

31. Watch the host country

Where a provider is abroad, its country's rule and politics must be watched.

32. Tell the customer

Where a customer must deal with a provider, the leaflet must say so.

33. Grievances without delay

The named officer must see that real customer complaints are put right fast.

34. Complaint deadline

Banks must set a 30-day maximum deadline to answer customer complaints.

BankPulse example. A bank may set its own deadline for answering complaints. The maximum is 30 days, and the deadline it sets must go on its website. So a bank that chooses 21 days publishes 21 days.

Background

35. No prior approval needed

Banks do not need RBI's prior approval before outsourcing a financial service.

36. Duties do not move out

Giving work out does not cut what the lender owes its customers or RBI.

37. Agent conduct liability

Banks stay responsible for what their sales agents and recovery agents do.

38. Suspicious reports stay ours

Cash and suspicious deal reports stay the lender's own job.

39. Compliance risk named

There is a risk that giving work out breaks privacy or other law.

40. Need to know only

A provider's staff may see customer data only where the job needs it.

41. Data leak liability

If customer data leaks through a vendor, the bank is liable to customers for damage.

42. Half-yearly record review

Outsourcing records go for half-yearly review by the Board too.

43. Only confidential jurisdictions

Work may go abroad only to a country that upholds secrecy terms.

44. The stricter rule wins

Where these rules and the host country's differ, the stricter one wins.

45. Complaint responsibility

The bank alone is responsible for fixing complaints about outsourced services.

46. Microfinance agent conduct

For microfinance loans, the bank answers for its agent's bad behaviour with customers.

Chapter IV. Outsourcing of Information Technology (IT) Services

Must know

1. Cyber incident reporting

Banks must tell RBI about a cyber incident within six hours of learning about it.

2. Nothing deleted in transition

The provider may not wipe or change data while the work is being moved.

Do it

3. Weigh the IT case

The case for giving out an IT job must be weighed against its risks.

4. A framework for IT risk

A risk plan must cover how IT risks are found, sized and reported.

5. Too much with one provider

The lender must weigh the risk of leaning on one provider too much.

6. Put it in writing

What each side owes the other must be set out in a written deal that binds.

7. Audit the provider

The lender must audit the provider and anyone it hires.

8. An inventory of IT services

The lender must keep a list of the IT jobs it has given out.

9. Map the dependency

The lender must map how much it leans on outside firms.

10. An exit plan required

The IT policy must set out a clear way to end the deal and keep work going.

11. Plan for each way out

The exit plan must cover each way the deal may end, and the time each needs.

12. Name the alternative

The exit plan must identify who else could do the work, or whether it comes back in-house.

13. Destroy the data safely

The deal must say how data and records are to be wiped or destroyed.

14. Must help the successor

The provider is bound to help the next provider hand over smoothly.

15. Announce the ending

Where a provider dealt with customers, the end of the deal must be made known.

16. Group choice on merit

A group firm must be picked on the same plain grounds as an outside firm.

17. Arm's length always

The lender must always deal with group firms at arm's length.

Background

18. Our data, our answer

The lender stays answerable for keeping customer data safe and whole.

19. Joint vendor audits

CICs using the same vendor can share one joint audit instead of separate ones.

20. Risk sets the audit cycle

How often the audit happens turns on the risk and what is at stake.

21. Board hears the bad news

Reports go to senior staff, and anything bad goes up to the Board.

Chapter V. Repeal and Other Provisions

1. Older rules cancelled

This document cancels all older outsourcing rules for commercial banks.

2. Old cases continue

Action already taken under the old rules stays governed by them.

The same subject for other kinds of institution

The same subject for other kinds of institution.

Other RBI rules for commercial banks

Every rule page on BankPulse  ·  Questions bankers ask, answered