On 31 July 2026, the Reserve Bank of India (RBI) issued the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions and the Digital Payment Security Controls Directions, creating an entity-centric regulatory architecture for technology governance, cybersecurity, operational resilience and digital payment security across regulated entities. The Directions became effective immediately and require organizations to align their existing control environment with the new regulatory expectations.
Key highlights of the report
What regulated entities should do next:
KPMG in India can support organisations through applicability assessments, gap assessments, remediation planning, and implementation and operationalisation of compliance measures to align with RBI's cybersecurity, technology risk, resilience and assurance framework directions and digital payment security controls directions.
RBI’s technology focused master directions issued on 31 July 2026
Key insights into RBI's cybersecurity, technology: Risk, resilience and assurance framework and digital payment security controls directions