Triad ICS
Menu

Insights/Regulatory Newsroom

RBI Cyber Security Framework: Compliance Guide for Fintech Startups

Published

Reading time2 minutes

FromTriad ICS Research

Which RBI directions apply to you depends on what you are. A map for founders.

“RBI cyber security compliance” means different things depending on whether you are a bank, an NBFC, a payment aggregator, a prepaid instrument issuer, or a technology partner to one of them. The first step for any fintech founder is to work out which set of directions applies. This guide is a general map, not legal advice; confirm the specifics for your licence.

The main instruments

  • Banks: the Cyber Security Framework in Banks (June 2016) set the pattern: a board-approved cyber security policy distinct from the IT policy, a cyber crisis management plan, continuous monitoring, and prompt reporting of incidents to RBI.
  • Regulated entities broadly: the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (November 2023), effective from April 2024, covers IT governance, risk management, business continuity and information systems audit for banks, NBFCs and other regulated entities.
  • Non-bank payment system operators: the Master Directions on Cyber Resilience and Digital Payment Security Controls (July 2024) apply to payment aggregators, PPI issuers and similar operators, with phased timelines by size. Large operators were due by April 2025 and medium operators by April 2026; small and very small operators have until April 2028.
  • Digital payment products: the Master Direction on Digital Payment Security Controls (February 2021) sets expectations for internet banking, mobile banking and card payments.
  • Data storage: RBI’s April 2018 directive requires payment system data to be stored only in India.

What these have in common

Across the directions, the recurring expectations are:

  • Board-level ownership of cyber risk, with a named senior officer responsible.
  • A documented policy and risk assessment, reviewed regularly.
  • Secure development and testing of applications and APIs before release.
  • Strong customer authentication and fraud monitoring.
  • Logging, monitoring and timely incident reporting to RBI, alongside CERT-In’s six-hour requirement.
  • Periodic vulnerability assessments, penetration tests and audits.
  • Oversight of vendors and outsourced IT service providers.

If you are a technology partner

Many startups are not regulated directly but serve banks or NBFCs. Your customer’s obligations flow to you through contracts: audit rights, data localisation, incident notification and security testing. Expect detailed due diligence, and prepare for it.

Getting started

Identify your regulatory category, collect the applicable directions, and build a control map that links each requirement to an owner and evidence. That map becomes your compliance programme and your answer to every partner bank’s questionnaire.

This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.

Turn Insight into Action