{"what_this_is":"The machine-readable twin of the BankPulse page for one RBI rulebook. Same points, same dates, same paragraph references as the page a person reads. RBI's own wording is not reproduced here: each point names the RBI paragraph, the character offset into the text BankPulse read and the sha256 of that text, so the claim can be checked against RBI's own document.","schema_version":1,"release_id":"d653cdb0a5","generated_at":"2026-09-15T00:33:59.117975+00:00","id":"md13592","title":"Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026","document_kind":"Directions","page":"https://bankpulse.ai/rule/md13592","status":"In force","importance":{"code":"MR","label":"MUST READ","weight":"Must read","why":"Binding RBI Directions naming this institution class in the title","layer":"bankpulse_inference"},"applies_to":{"shown":"Finance companies","class_code":"NBFC","from":"the document's own title","layer":"bankpulse_inference"},"dates":{"prid":"md13592","mode":"four_dates_v1","published":{"label":"Published","value":"Jul 31, 2026","stated":true,"why":"The day RBI put this document out."},"effective":{"label":"Starts to apply","value":"","stated":false,"why":"Not stated separately in this document. Read the rule itself before you assume a start date."},"transition":{"label":"Time to get ready","value":"","stated":false,"why":"Cannot be worked out until the day it starts to apply is known."},"deadline":{"label":"Last date to act","value":"","stated":false,"why":"No date to act by was found in this document. Other dates may sit inside single paragraphs."},"sources":{"published":"doc_date in data/highlights/md13592.json","effective":"none held","transition":"none held","deadline":"none held"}},"rbi_source":{"url":"https://rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=13592","document_date":"Jul 31, 2026","read_by_bankpulse":"2026-08-21 16:26:02 UTC","text_sha256":"bb9ea6de3814e5d9be5b7e33f5d161293c2d8173a31486b4b40bcc5902ca8421","word_count":10382,"standing_last_checked":"Standing checked on RBI’s Master Directions index, 15 September 2026, 5:58 am IST."},"counts":{"points_shown":80,"points_naming_an_rbi_paragraph":80,"points_stored":80,"actions":0,"amendments":0},"points":[{"n":1,"claim":"md13592-0d6e2ba1","page_group":"Chapter I. Preliminary","stored_section":"WHO IT APPLIES TO","heading":"Below 500 crore","plain_english":"Chapter three binds a base layer company below Rs 500 crore in assets.","rbi_paragraph":"Para 3(2)","rbi_char_offset":4289,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"A base layer company with ₹300 crore of assets is under ₹500 crore. Chapter three applies to it. A company at ₹700 crore is not covered by that chapter.","anchor":"https://bankpulse.ai/rule/md13592#p1","layer":"bankpulse"},{"n":2,"claim":"md13592-fd343e83","page_group":"Chapter I. Preliminary","stored_section":"WHO IT APPLIES TO","heading":"At 500 crore and above","plain_english":"Chapter four binds a base layer company of Rs 500 crore in assets and above.","rbi_paragraph":"Para 3(3)","rbi_char_offset":4617,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"A base layer company with ₹700 crore of assets is at ₹500 crore or above. Chapter four applies to it. One at ₹300 crore is not covered by that chapter.","anchor":"https://bankpulse.ai/rule/md13592#p2","layer":"bankpulse"},{"n":3,"claim":"md13592-24b4564d","page_group":"Chapter I. Preliminary","stored_section":"THE CORE IDEA","heading":"Cyber rules for NBFCs","plain_english":"This paper sets the cyber and technology risk rules for non-banking financial companies.","rbi_paragraph":"Para 1","rbi_char_offset":3585,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p3","layer":"bankpulse"},{"n":4,"claim":"md13592-1840df20","page_group":"Chapter I. Preliminary","stored_section":"KEY DATES","heading":"Start date","plain_english":"These Directions took effect at once.","rbi_paragraph":"Para 2","rbi_char_offset":3780,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p4","layer":"bankpulse"},{"n":5,"claim":"md13592-009c1210","page_group":"Chapter I. Preliminary","stored_section":"THE CORE IDEA","heading":"Split by asset size","plain_english":"Which chapter binds a finance company turns on its asset size and its layer.","rbi_paragraph":"Para 3","rbi_char_offset":3845,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p5","layer":"bankpulse"},{"n":6,"claim":"md13592-dc084aed","page_group":"Chapter I. Preliminary","stored_section":"WHO IT APPLIES TO","heading":"Who is covered","plain_english":"These Directions apply to every non-banking financial company.","rbi_paragraph":"Para 3(1)","rbi_char_offset":3930,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p6","layer":"bankpulse"},{"n":7,"claim":"md13592-89cbf7d7","page_group":"Chapter I. Preliminary","stored_section":"WHO IT APPLIES TO","heading":"Middle layer and above","plain_english":"Chapter five binds middle, upper and top layer companies, but not core investment ones.","rbi_paragraph":"Para 3(4)","rbi_char_offset":4735,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p7","layer":"bankpulse"},{"n":1,"claim":"md13592-0fcc4524","page_group":"Chapter II. Role of the Board","stored_section":"WHO SHOULD ACT","heading":"Board approves the policies","plain_english":"The Board must approve the plans and policies for technology and cyber security.","rbi_paragraph":"Para 6","rbi_char_offset":11697,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p8","layer":"bankpulse"},{"n":1,"claim":"md13592-583c18a6","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"KEY DATES","heading":"Six months between meetings","plain_english":"For a smaller company, no more than six months may pass between committee meetings.","rbi_paragraph":"Para 15(3)","rbi_char_offset":15651,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p9","layer":"bankpulse"},{"n":2,"claim":"md13592-62ebbbc9","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"KEY DATES","heading":"Six hours to report","plain_english":"A cyber incident must be reported on the DAKSH platform within six hours of detection.","rbi_paragraph":"Para 28","rbi_char_offset":24755,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p10","layer":"bankpulse"},{"n":3,"claim":"md13592-0a6731c6","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHO SHOULD ACT","heading":"Reports to the Board","plain_english":"What the IT Strategy Committee decides must be placed before the Board.","rbi_paragraph":"Para 15(5)","rbi_char_offset":16018,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p11","layer":"bankpulse"},{"n":4,"claim":"md13592-ea78979d","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHO SHOULD ACT","heading":"Chief information officer","plain_english":"The company must name a senior executive as chief information officer for IT work.","rbi_paragraph":"Para 18(2)","rbi_char_offset":18344,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p12","layer":"bankpulse"},{"n":5,"claim":"md13592-1c8319b3","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHO SHOULD ACT","heading":"Assess IT training needs","plain_english":"The company must check its IT training needs so that skill matches the work.","rbi_paragraph":"Para 18(3)","rbi_char_offset":18604,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p13","layer":"bankpulse"},{"n":6,"claim":"md13592-c927983f","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHAT CHANGES","heading":"Support IPv6 traffic","plain_english":"Public facing systems of the NBFC must be able to carry IPv6 traffic.","rbi_paragraph":"Para 18(4)","rbi_char_offset":18878,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p14","layer":"bankpulse"},{"n":7,"claim":"md13592-21ba2811","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHAT CHANGES","heading":"Split IT from security","plain_english":"The IT function and the information security function must be kept apart.","rbi_paragraph":"Para 21(2)","rbi_char_offset":20028,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p15","layer":"bankpulse"},{"n":8,"claim":"md13592-eaef9b7a","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHO SHOULD ACT","heading":"Check the privileged staff","plain_english":"Staff with access to critical systems must pass a strict background check.","rbi_paragraph":"Para 21(4)","rbi_char_offset":21111,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p16","layer":"bankpulse"},{"n":9,"claim":"md13592-6ab0d1ae","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHAT CHANGES","heading":"Two people to approve","plain_english":"A maker and checker control must require two people before a transaction is done.","rbi_paragraph":"Para 21(6)","rbi_char_offset":21483,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p17","layer":"bankpulse"},{"n":10,"claim":"md13592-20107011","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHAT CHANGES","heading":"Use public key methods","plain_english":"The company must widen the use of public key methods to keep data safe and provable.","rbi_paragraph":"Para 21(9)","rbi_char_offset":22330,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p18","layer":"bankpulse"},{"n":11,"claim":"md13592-6ff10616","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHAT CHANGES","heading":"Four steps in a crisis","plain_english":"The crisis plan must cover four steps: detection, containment, response and recovery.","rbi_paragraph":"Para 25","rbi_char_offset":23798,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p19","layer":"bankpulse"},{"n":12,"claim":"md13592-534f5812","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"KEY DATES","heading":"Yearly risk assessment","plain_english":"The company must run a full risk assessment of its IT systems at least once a year.","rbi_paragraph":"Para 32","rbi_char_offset":25631,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p20","layer":"bankpulse"},{"n":13,"claim":"md13592-498a30df","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"WHAT CHANGES","heading":"Board approved change policy","plain_english":"The company must have a Board approved policy for handling changes to its systems.","rbi_paragraph":"Para 41","rbi_char_offset":28730,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p21","layer":"bankpulse"},{"n":14,"claim":"md13592-8ada3e95","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"KEY DATES","heading":"Test the continuity plan","plain_english":"The company must test its continuity plan at least once a year and after big changes.","rbi_paragraph":"Para 59(4)","rbi_char_offset":36326,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p22","layer":"bankpulse"},{"n":15,"claim":"md13592-e0edbbe2","page_group":"Chapter IV. Requirements for NBFCs (Base Layer with asset size ₹500 crore and above)","stored_section":"KEY DATES","heading":"IS audit once a year","plain_english":"The audit of information systems may be run at least once a year.","rbi_paragraph":"Para 56","rbi_char_offset":33563,"weight":"BACKGROUND","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p23","layer":"bankpulse"},{"n":1,"claim":"md13592-663c1eb5","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Seven years of skill","plain_english":"Real IT skill here means at least seven years of running or guiding IT work.","rbi_paragraph":"Para 71(2)","rbi_char_offset":42136,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p24","layer":"bankpulse"},{"n":2,"claim":"md13592-8f2223ba","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"KEY DATES","heading":"Committee meets each quarter","plain_english":"The IT Strategy Committee must meet at least once every three months.","rbi_paragraph":"Para 72","rbi_char_offset":42578,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p25","layer":"bankpulse"},{"n":3,"claim":"md13592-7e8bdb84","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"A steering committee too","plain_english":"A steering group of senior staff must also meet at least once every three months.","rbi_paragraph":"Para 75","rbi_char_offset":44494,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p26","layer":"bankpulse"},{"n":4,"claim":"md13592-a65aa6f9","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Keep the two apart","plain_english":"The security officer must not report to the head of IT and gets no business target.","rbi_paragraph":"Para 81","rbi_char_offset":47322,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p27","layer":"bankpulse"},{"n":5,"claim":"md13592-c0dab697","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"KEY DATES","heading":"Quarterly cyber review","plain_english":"The security officer must place a cyber risk review before the Board every three months.","rbi_paragraph":"Para 82(7)","rbi_char_offset":48945,"weight":"MUST KNOW","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p28","layer":"bankpulse"},{"n":6,"claim":"md13592-d24cbf54","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"No unsupported software","plain_english":"The NBFC must not run outdated hardware or software that the maker no longer backs.","rbi_paragraph":"Para 92","rbi_char_offset":51489,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p29","layer":"bankpulse"},{"n":7,"claim":"md13592-911373a3","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Put the code in escrow","plain_english":"Where the source code cannot be had, the NBFC must place it in escrow.","rbi_paragraph":"Para 105","rbi_char_offset":55516,"weight":"MUST KNOW","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p30","layer":"bankpulse"},{"n":8,"claim":"md13592-cd1dc5a1","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"No manual data changes","plain_english":"Data moving between critical systems must not be changed by hand on the way.","rbi_paragraph":"Para 119","rbi_char_offset":61141,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p31","layer":"bankpulse"},{"n":9,"claim":"md13592-1355676e","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"KEY DATES","heading":"Six months, then a year","plain_english":"Critical systems need a scan every six months and an attack test every 12 months.","rbi_paragraph":"Para 121","rbi_char_offset":61693,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"Suppose a scan is run in January and the next in July, six months later. The attack test run in January is next due the following January, 12 months later.","anchor":"https://bankpulse.ai/rule/md13592#p32","layer":"bankpulse"},{"n":10,"claim":"md13592-464e8771","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"KEY DATES","heading":"Drill every six months","plain_english":"Recovery drills for critical systems must be held at least once every six months.","rbi_paragraph":"Para 129","rbi_char_offset":64019,"weight":"MUST KNOW","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p33","layer":"bankpulse"},{"n":11,"claim":"md13592-62cdf065","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Housing companies tell NHB","plain_english":"A housing finance company keeps reporting cyber incidents to NHB and not to RBI.","rbi_paragraph":"Para 141","rbi_char_offset":66858,"weight":"MUST KNOW","role":"Compliance","team":null,"products_covered":["housing-loan"],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p34","layer":"bankpulse"},{"n":12,"claim":"md13592-d4d23143","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"IT risk sits inside","plain_english":"The wider risk policy must also test IT risk from time to time.","rbi_paragraph":"Para 67","rbi_char_offset":41205,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p35","layer":"bankpulse"},{"n":13,"claim":"md13592-95d1eb83","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"KEY DATES","heading":"Board sees them yearly","plain_english":"These plans and policies must go to the Board for review at least once a year.","rbi_paragraph":"Para 69","rbi_char_offset":41601,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p36","layer":"bankpulse"},{"n":14,"claim":"md13592-4b270014","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Three directors at least","plain_english":"The IT Strategy Committee must have at least three directors as members.","rbi_paragraph":"Para 71(1)","rbi_char_offset":41866,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p37","layer":"bankpulse"},{"n":15,"claim":"md13592-f541883c","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Chair must be independent","plain_english":"The chair of that committee must be an independent director with real IT skill.","rbi_paragraph":"Para 71(2)","rbi_char_offset":41953,"weight":"DO IT","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p38","layer":"bankpulse"},{"n":16,"claim":"md13592-b67dfd4b","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Security committee under it","plain_english":"An information security committee must sit under the IT Strategy Committee.","rbi_paragraph":"Para 77","rbi_char_offset":45209,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p39","layer":"bankpulse"},{"n":17,"claim":"md13592-f724002f","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Name a head of IT","plain_english":"The NBFC must name a senior officer with real IT skill as head of the IT work.","rbi_paragraph":"Para 78","rbi_char_offset":46165,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p40","layer":"bankpulse"},{"n":18,"claim":"md13592-72f4eba2","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Head of IT duties","plain_english":"The head of IT must keep projects in line with policy and set up the backup site.","rbi_paragraph":"Para 79","rbi_char_offset":46411,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p41","layer":"bankpulse"},{"n":19,"claim":"md13592-2bfd61be","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Name a security officer","plain_english":"A senior officer, best of general manager rank, must be named security officer.","rbi_paragraph":"Para 81","rbi_char_offset":47188,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p42","layer":"bankpulse"},{"n":20,"claim":"md13592-1b402444","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Staff and budget for security","plain_english":"The security office must be well staffed and its budget set by the threats seen.","rbi_paragraph":"Para 81(3)","rbi_char_offset":47615,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p43","layer":"bankpulse"},{"n":21,"claim":"md13592-97551602","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Have a security policy","plain_english":"The NBFC must have an information security policy that sets scope, owner and penalty.","rbi_paragraph":"Para 83","rbi_char_offset":49204,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p44","layer":"bankpulse"},{"n":22,"claim":"md13592-5f185dc7","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"A separate cyber policy","plain_english":"The cyber security policy must be kept apart from the wider IT policy.","rbi_paragraph":"Para 84","rbi_char_offset":49522,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p45","layer":"bankpulse"},{"n":23,"claim":"md13592-9eb98002","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"KEY DATES","heading":"Risk committee reviews yearly","plain_english":"The risk committee must review and update the risk policy at least once a year.","rbi_paragraph":"Para 94","rbi_char_offset":52036,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p46","layer":"bankpulse"},{"n":24,"claim":"md13592-29284841","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"KEY DATES","heading":"Security check each year","plain_english":"The NBFC must review its security set up and policies at least once a year.","rbi_paragraph":"Para 98","rbi_char_offset":53686,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p47","layer":"bankpulse"},{"n":25,"claim":"md13592-785596d0","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Data migration policy","plain_english":"The NBFC must have a data migration policy that keeps data whole and correct.","rbi_paragraph":"Para 99","rbi_char_offset":54062,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p48","layer":"bankpulse"},{"n":26,"claim":"md13592-a5649021","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Keep a data dictionary","plain_english":"The NBFC must keep a data dictionary so that systems share one meaning of data.","rbi_paragraph":"Para 100","rbi_char_offset":54455,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p49","layer":"bankpulse"},{"n":27,"claim":"md13592-db951296","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Guard the data centre","plain_english":"Physical controls must protect the data centre and the backup site from harm.","rbi_paragraph":"Para 101","rbi_char_offset":54668,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p50","layer":"bankpulse"},{"n":28,"claim":"md13592-31ce883c","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Keep the sites apart","plain_english":"The data centre and the backup site must be far apart in place.","rbi_paragraph":"Para 102","rbi_char_offset":54981,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p51","layer":"bankpulse"},{"n":29,"claim":"md13592-3e102a48","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Vendors must support it","plain_english":"The NBFC must tie down software support from its vendors by formal agreement.","rbi_paragraph":"Para 104","rbi_char_offset":55268,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p52","layer":"bankpulse"},{"n":30,"claim":"md13592-75e13613","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Get the source code","plain_english":"The NBFC must get the source code for every critical application from the vendor.","rbi_paragraph":"Para 105","rbi_char_offset":55438,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p53","layer":"bankpulse"},{"n":31,"claim":"md13592-e38c2c3a","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Written word from the vendor","plain_english":"The vendor must confirm in writing that the software carries no known flaw or malware.","rbi_paragraph":"Para 106","rbi_char_offset":55842,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p54","layer":"bankpulse"},{"n":32,"claim":"md13592-03ae8664","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"KEY DATES","heading":"Check capacity each year","plain_english":"The NBFC must check how much IT capacity it needs at least once a year.","rbi_paragraph":"Para 108","rbi_char_offset":56946,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p55","layer":"bankpulse"},{"n":33,"claim":"md13592-50424d0b","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Log every critical system","plain_english":"Every system that touches critical or sensitive data must keep an audit trail.","rbi_paragraph":"Para 109","rbi_char_offset":57441,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p56","layer":"bankpulse"},{"n":34,"claim":"md13592-687b2d84","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Trails must stand as proof","plain_english":"Audit trails must be full enough to serve as proof and to settle a dispute.","rbi_paragraph":"Para 110","rbi_char_offset":57523,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p57","layer":"bankpulse"},{"n":35,"claim":"md13592-a77541c3","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Watch the audit trails","plain_english":"The NBFC must watch audit trails and system logs to find any attack or misuse.","rbi_paragraph":"Para 111","rbi_char_offset":57909,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p58","layer":"bankpulse"},{"n":36,"claim":"md13592-15f2a48d","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Use strong encryption","plain_english":"Key length, methods and protocols used to send and hold data must be strong.","rbi_paragraph":"Para 118","rbi_char_offset":60592,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p59","layer":"bankpulse"},{"n":37,"claim":"md13592-598ddf75","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Independent testers only","plain_english":"Scans and attack tests must be run by trained and independent security experts.","rbi_paragraph":"Para 122","rbi_char_offset":62095,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p60","layer":"bankpulse"},{"n":38,"claim":"md13592-17174880","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Follow the ISO standard","plain_english":"The continuity and recovery policy must follow best practice such as ISO 22301.","rbi_paragraph":"Para 127","rbi_char_offset":63417,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p61","layer":"bankpulse"},{"n":39,"claim":"md13592-fdfba237","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Run on the backup site","plain_english":"A recovery test must run the backup site as the main site for a full working day.","rbi_paragraph":"Para 131","rbi_char_offset":64420,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p62","layer":"bankpulse"},{"n":40,"claim":"md13592-fd42c647","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Test your backups","plain_english":"The NBFC must back data up and restore it now and then to prove it works.","rbi_paragraph":"Para 133","rbi_char_offset":64780,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p63","layer":"bankpulse"},{"n":41,"claim":"md13592-23d531af","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Near zero data loss","plain_english":"The NBFC must aim for the least recovery time and near zero data loss.","rbi_paragraph":"Para 135","rbi_char_offset":65195,"weight":"DO IT","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p64","layer":"bankpulse"},{"n":42,"claim":"md13592-e6f9d9b3","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Both sites must match","plain_english":"The settings and security patches at the main and backup sites must be the same.","rbi_paragraph":"Para 137","rbi_char_offset":65562,"weight":"DO IT","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p65","layer":"bankpulse"},{"n":43,"claim":"md13592-85225cbf","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Have a response policy","plain_english":"The NBFC must have a written policy on how it answers and recovers from an incident.","rbi_paragraph":"Para 139","rbi_char_offset":65994,"weight":"DO IT","role":"Compliance","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p66","layer":"bankpulse"},{"n":44,"claim":"md13592-ab4d7822","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Have an IS audit policy","plain_english":"The NBFC must have an information systems audit policy.","rbi_paragraph":"Para 150","rbi_char_offset":68425,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p67","layer":"bankpulse"},{"n":45,"claim":"md13592-ce9657e0","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"KEY DATES","heading":"Audit policy reviewed yearly","plain_english":"The audit committee must approve that policy and review it at least once a year.","rbi_paragraph":"Para 150","rbi_char_offset":68609,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p68","layer":"bankpulse"},{"n":46,"claim":"md13592-aa02ff51","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Separate IS audit function","plain_english":"The NBFC must have a separate information systems audit function with the right skill.","rbi_paragraph":"Para 152","rbi_char_offset":68861,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p69","layer":"bankpulse"},{"n":47,"claim":"md13592-ef5d403d","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Plan audits by risk","plain_english":"Audit planning must follow a risk based approach.","rbi_paragraph":"Para 153","rbi_char_offset":69286,"weight":"DO IT","role":"Audit","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p70","layer":"bankpulse"},{"n":48,"claim":"md13592-9aa40a4f","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"First line of defence","plain_english":"The head of IT is the first line of defence for IT controls and IT risk.","rbi_paragraph":"Para 80","rbi_char_offset":46797,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p71","layer":"bankpulse"},{"n":49,"claim":"md13592-f678451f","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Always invited","plain_english":"The security officer is a standing invitee to both the IT committees.","rbi_paragraph":"Para 82(3)","rbi_char_offset":48518,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p72","layer":"bankpulse"},{"n":50,"claim":"md13592-9b54bc26","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Reports to the top","plain_english":"The security officer reports to the executive director who looks after risk.","rbi_paragraph":"Para 82(6)","rbi_char_offset":48814,"weight":"BACKGROUND","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p73","layer":"bankpulse"},{"n":51,"claim":"md13592-6d0b23c6","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Plan the technology refresh","plain_english":"The NBFC must plan to replace hardware and software before support runs out.","rbi_paragraph":"Para 93","rbi_char_offset":51700,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p74","layer":"bankpulse"},{"n":52,"claim":"md13592-67129961","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"THE CORE IDEA","heading":"Access on business need","plain_english":"Access to information assets is allowed only where there is a real business need.","rbi_paragraph":"Para 113","rbi_char_offset":58760,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p75","layer":"bankpulse"},{"n":53,"claim":"md13592-c1f31a42","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Two factor for privilege","plain_english":"A second factor is needed to sign in for privileged users of critical systems.","rbi_paragraph":"Para 115","rbi_char_offset":59048,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p76","layer":"bankpulse"},{"n":54,"claim":"md13592-ad9cefc7","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHAT CHANGES","heading":"Rules for remote work","plain_english":"Remote work needs safe systems, a second sign in factor and a list of remote devices.","rbi_paragraph":"Para 116","rbi_char_offset":59230,"weight":"BACKGROUND","role":"Technology","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p77","layer":"bankpulse"},{"n":55,"claim":"md13592-5a9633d9","page_group":"Chapter V. Requirements for NBFCs (Middle Layer and above excluding CICs)","stored_section":"WHO SHOULD ACT","heading":"Audit committee oversees IS","plain_english":"The audit committee of the Board oversees the audit of information systems.","rbi_paragraph":"Para 149","rbi_char_offset":68341,"weight":"BACKGROUND","role":"Board","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":null,"anchor":"https://bankpulse.ai/rule/md13592#p78","layer":"bankpulse"},{"n":1,"claim":"md13592-ed77acc3","page_group":"Chapter VI. Repeal and Other Provisions","stored_section":"WHAT IT REPLACES","heading":"Other laws still apply","plain_english":"These Directions add to other laws and rules and do not replace them.","rbi_paragraph":"Para 157","rbi_char_offset":71137,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"A bank follows these Directions and thinks the matter is closed. It is not. Any other laws, rules, regulations or directions in force still apply on top. Where another one asks for more, the bank does the more.","anchor":"https://bankpulse.ai/rule/md13592#p79","layer":"bankpulse"},{"n":2,"claim":"md13592-a449e126","page_group":"Chapter VI. Repeal and Other Provisions","stored_section":"THE CORE IDEA","heading":"RBI has the last word","plain_english":"RBI may issue clarifications, and its reading of these Directions is final.","rbi_paragraph":"Para 158","rbi_char_offset":71585,"weight":"BACKGROUND","role":"All staff","team":null,"products_covered":[],"products_excluded":[],"bankpulse_example":"Two banks read the same clause differently. Neither reading settles it. RBI may issue clarifications, and its interpretation of any provision is final and binding on all concerned entities.","anchor":"https://bankpulse.ai/rule/md13592#p80","layer":"bankpulse"}],"actions":[],"amendments":[],"layers":{"rbi_source":"Facts taken from RBI's own document.","bankpulse":"BankPulse's plain-English summary of RBI's document.","bankpulse_inference":"BankPulse's own inference, not stated by RBI."},"rbi_wording_not_included":"By design. BankPulse never republishes RBI's exact sentences. Use rbi_paragraph with rbi_source.url to read RBI's own words.","terms":"BankPulse's plain-English summaries are BankPulse's own work. The underlying regulation is the Reserve Bank of India's. Always check the RBI document named in rbi_source before acting."}