RBI master-direction RBI/DOR/2025-26/337 · 28 Nov 2025
Summary
Check the official recordThe Reserve Bank of India issued these Directions to govern the management of risks associated with the outsourcing of Information Technology (IT) services by All India Financial Institutions (AIFIs). AIFIs must maintain a Board-approved IT outsourcing policy and retain ultimate responsibility for outsourced services. The Directions mandate rigorous due diligence, contractual safeguards, and monitoring of service providers. AIFIs must report cyber incidents to the RBI within six hours of detection by the service provider. Existing IT outsourcing agreements must comply with these provisions by April 10, 2026, or upon renewal, whichever is earlier. New agreements must comply immediately. The Directions apply to material IT outsourcing, while excluding specific services like external audits and off-the-shelf product procurement.
What you must do
Key dates
Who is affected
Exceptions
RBI/DOR/2025-26/337 DOR.ORG.REC.No.256/21-04-158/2025-26 November 28, 2025
In exercise of the powers conferred by Section 45L of the Reserve Bank of India Act, 1934, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues the Directions hereinafter specified.
These Directions shall be called the Reserve Bank of India (All India Financial Institutions - Managing Risks in Outsourcing) Directions, 2025.
These Directions shall come into force with immediate effect.
Provided that an All India Financial Institution’s existing Information Technology (IT) outsourcing agreements regardless of whether they are due for renewal on or after the effective date of these Directions shall comply with the provisions of these Directions either at the time of renewal or by April 10, 2026, whichever is earlier. However, the All India Financial Institution’s new IT outsourcing agreements that come into force on or after the effective date of these Directions, shall comply with the provisions of these Directions from the date of agreement itself.
Provided further that nothing in the preceding proviso shall be construed as permitting non-compliance with any other extant regulatory instructions or statutory requirements applicable to such arrangements.
These Directions shall be applicable to All-India Financial Institutions (AIFIs) namely Export Import Bank of India (‘EXIM Bank’), National Bank for Agriculture and Rural Development (‘NABARD’), National Bank for Financing Infrastructure and Development (‘NaBFID’), National Housing Bank (‘NHB’) and Small Industries Development Bank of India (‘SIDBI’), hereinafter collectively referred to as ‘AIFIs’ and individually as an ‘AIFI’.
These Directions shall apply to an AIFI’s material outsourcing of IT services, as defined in paragraph 6(3) of these Directions. In this context, ‘Outsourcing of IT Services’ shall include outsourcing of the following services:
(i) IT infrastructure management, maintenance, and support (hardware, software or firmware); (ii) network and security solutions, and maintenance (hardware, software or firmware); (iii) application development, maintenance, and testing by Application Service Providers (ASPs) including ATM Switch ASPs; (iv) services and operations related to data centres; (v) cloud computing services; (vi) managed security services; and (vii) management of IT infrastructure and technology services associated with payment system ecosystem.
(i) corporate internet banking services obtained by an AIFI as a corporate customer or sub-member of another Regulated Entity (RE);
Provided that for the purpose of these Directions, the following indicative (but not exhaustive) list of entities shall be considered as REs - Commercial Banks; Local Area Banks; Small Finance Banks; Payments Banks; Regional Rural Banks; Non-Banking Financial Companies in Base Layer (NBFC - BL), Middle Layer (NBFC - ML), and Upper Layer (NBFC – UL); other AIFIs; Credit Information Companies; Urban Co-operative Banks; Rural Co-operative Banks; and, Payment System Operators.
For the purpose of these Directions, the ‘Commercial Banks’ means banking companies (other than Small Finance Banks, Local Area Banks, Payments Banks and Regional Rural Banks), corresponding new banks, and the State Bank of India, as defined respectively under clauses (c), (da), and (nc) of section 5 of the Banking Regulation Act, 1949.
(ii) external audit services such as Vulnerability Assessment (VA) / Penetration Testing (PT), Information Systems Audit, and security review; (iii) SMS gateways (including bulk SMS service providers); (iv) procurement of IT hardware or appliances; (v) acquisition of IT software, product or application (e.g., Core Banking Solution (CBS), database, and security solutions) on a licence or subscription basis, and any enhancements made to such licensed third-party applications by the vendor (as upgrades) or on specific change request made by an AIFI; (vi) any maintenance service (including security patches, bug fixes) for IT infrastructure or licensed products, provided by the Original Equipment Manufacturer (OEM) themselves, in order to ensure continued usage of the same by the AIFI; (vii) applications provided by financial sector regulators or institutions such as Clearing Corporation of India Limited (CCIL), National Stock Exchange (NSE), and Bombay Stock Exchange (BSE); (viii) platforms provided by entities such as Reuters, Bloomberg, and Society for Worldwide Interbank Financial Telecommunication (SWIFT); (ix) any other off-the-shelf products (e.g., anti-virus software, and email solutions) subscribed to by an AIFI, wherein only a license is procured with no or minimal customisation; (x) services obtained by an AIFI as a sub-member of a Centralised Payment System (CPS) from another RE; (xi) Business Correspondent (BC) services, payroll processing, and statement printing.
(1) ‘Group’ shall be as defined in the Reserve Bank of India (Commercial Banks - Concentration Risk Management) Directions, 2025, as amended from time to time, for the purpose of intra-group transactions and exposures.
(2) ‘IT services’ means IT services / IT enabled services / IT activities.
(3) ‘Material Outsourcing of IT Services’ are those which:
(i) if disrupted or compromised shall have the potential to significantly impact the AIFI’s business operations; or (ii) may have material impact on the AIFI’s customers in the event of any unauthorised access, loss or theft of customer information.
(4) ‘Outsourcing’ means use of a third-party (either an affiliated entity within a corporate group or an entity that is external to the corporate group) by an AIFI to perform activities on a continuing basis that would normally be undertaken by the AIFI itself, now or in the future. 'Continuing basis' shall include agreements for a limited period.
(5) ‘Service Provider’ means provider of IT services including entities related to the AIFI or those which belong to the same group or conglomerate to which the AIFI belongs.
Provided that for the purpose of these Directions, the following indicative (but not exhaustive) list of vendors and entities shall not be considered as ‘Service Providers’ as defined above:
(i) vendors providing business services using IT, (e.g., BCs); (ii) Payment System Operators (PSOs) authorised by RBI under the Payment and Settlement Systems Act, 2007 for setting up and operating Payment Systems in India; (iii) partnership based FinTech firms such as those providing co-branded applications, products, and services; (iv) FinTech firms providing services for data retrieval, and data validation and verification such as, bank statement analysis, GST returns analysis, fetching of vehicle information, digital document execution, data entry, and call centre services.; (v) telecom service providers from whom leased lines, or other similar kind of infrastructure are availed and used for transmission of data; and (vi) security or audit consultants appointed for certification, audit or VA / PT related to IT infrastructure, IT services or Information Security services in their role as independent third-party auditor, consultant or lead implementer.