Skip to main content

      On 31 July 2026, the Reserve Bank of India (RBI) issued the Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions and the Digital Payment Security Controls Directions, creating an entity-centric regulatory architecture for technology governance, cybersecurity, operational resilience and digital payment security across regulated entities. The Directions became effective immediately and require organizations to align their existing control environment with the new regulatory expectations.


      Key highlights of the report

      • Entity-centric regulatory framework

        RBI has consolidated technology-related regulatory expectations through entity-wise Master Directions, moving from fragmented regulatory instructions to a unified technology compliance framework across regulated entities

      • Technology governance and board oversight

        The directions place responsibility beyond technology teams, requiring active oversight from boards, senior management, risk, compliance and security functions for technology risk, cybersecurity and digital payment security

      • Cybersecurity, resilience and assurance framework

        The cybersecurity, technology: Risk, resilience and assurance framework directions establish a unified approach covering technology governance, cybersecurity, operational resilience, information systems assurance and third-party technology risk management

      • Six-hour cyber incident reporting requirement

        Cyber incidents must be reported within six hours of detection through the RBI DAKSH platform, along with proactive notification to CERT-In

      • Vulnerability assessment and penetration testing cadences

        For critical information systems and those in the demilitarised zone carrying a customer interface, vulnerability assessment must be conducted at least once every six months and penetration testing at least once every twelve months. For non-critical systems a risk-based approach determines the requirement

      • Disaster Recovery (DR) drill periodicity is fixed for critical systems, with a re-test requirement

        DR drills for critical information systems must be conducted at least half-yearly. Any major issue observed during a drill must be resolved and re-tested successfully before the next cycle

      • Third-party technology arrangements are covered in the cybersecurity master directions

        Third-party arrangements is the longest sub-section of chapter V and covers all third-party arrangements not within the scope of the RBI managing risks in outsourcing directions

      • Digital payment obligations apply to products, including non-financial uses

        The digital payment security controls directions covers any digital payment product or service offered for financial or non-financial transactions, expressly including balance enquiry, PIN set and change, mobile banking registration and one-time password generation

      • A policy for digital payment products is mandated

        A board approved policy covering digital payment products and services is to be formulated with details on product parameters, risk management, regulatory compliance, customer experience, and payment security requirements


      What regulated entities should do next:

      Determine applicability

      Identify applicable directions based on entity type, assess security and payment-related applicability requirements, Establish a documented applicability register

      Re-map policies and controls

      Map existing policies and standards to the new directions, Update references to repealed circulars, align governance, risk and control frameworks

      Assess gaps

      Evaluate governance arrangements, assess cybersecurity and payment security controls, Identify capability and operating model gaps

      Remediate and align controls

      Address identified control gaps, address gaps in monitoring, reporting and resilience capabilities, update procedures and technology enablement mechanisms

      Monitor and sustain

      Align audit and review programs, align regulatory reporting and evidence management processes with the new directions, establish ongoing governance and oversight mechanisms

      KPMG in India can support organisations through applicability assessments, gap assessments, remediation planning, and implementation and operationalisation of compliance measures to align with RBI's cybersecurity, technology risk, resilience and assurance framework directions and digital payment security controls directions.


      RBI’s technology focused master directions issued on 31 July 2026


      Key insights into RBI's cybersecurity, technology: Risk, resilience and assurance framework and digital payment security controls directions 

      Key Contact

      Romharsh Razdan

      Partner, Digital Trust

      KPMG in India

      How can KPMG in India help

      Supporting organisations with integrated cyber risk, compliance, and assurance solutions for sustainable growth

      New challenges and opportunities are quickly reshaping financial services

      Transformation driven by data, enabled by digital technology, and led by business initiatives
      KPMG Insights Edge

      KPMG Insights Edge

      On the go access to KPMG in India’s insights and publications