RBI master-direction · 28 Nov 2025
RBI/DOR/2025-26/171 DOR.ORG.REC.No.90/21-04-158/2025-26 November 28, 2025 Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025 Table of Contents Chapter I – Preliminary A. Short Title and Commencement B. Applicability and Scope C. Definitions Chapter II – Role of the Board A. Board-…
RBI/DOR/2025-26/171 DOR.ORG.REC.No.90/21-04-158/2025-26 November 28, 2025
Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025
Table of Contents
Chapter I – Preliminary A. Short Title and Commencement B. Applicability and Scope C. Definitions
Chapter II – Role of the Board A. Board-Approved Policy B. Key Responsibilities
Chapter III – Outsourcing of Financial Services A. Definitions B. Activities that shall not be outsourced C. Authorisation, Accountability, and Oversight D. Governance Framework D.1 Outsourcing Policy D.2 Role of Senior Management E. Risk Management E.1 Evaluation of the Risks E.2 Confidentiality and Security of Information F. Outsourcing Process F.1 Service Provider Evaluation F.2 Outsourcing Agreement F.3 Monitoring and Control of Outsourced Activities F.4 Business Continuity and Management of Disaster Recovery Plan F.5 Termination G. Specific Outsourcing Arrangements G.1 Outsourcing within a Group / Conglomerate G.2 Offshore outsourcing H. Redressal of Grievances related to Outsourced Services
Chapter IV – Outsourcing of Information Technology (IT) Services A. Definitions B. Authorisation, Accountability, and Oversight C. Governance Framework C.1 Outsourcing Policy C.2 Role of Senior Management C.3 Role of IT Function D. Risk Management D.1 Risk Management Framework D.2 Confidentiality and Security of Information E. Outsourcing Process E.1 Service Provider Evaluation E.2 Outsourcing Agreement E.3 Monitoring and Control of Outsourced Services E.4 Inventory of Outsourced Services E.5 Business Continuity and Management of Disaster Recovery Plan E.6 Exit Strategy E.7 Termination F. Specific Outsourcing Arrangements F.1 Outsourcing within a Group / Conglomerate F.2 Offshore or Cross-Border outsourcing F.3 Outsourcing of Security Operations Centre (SOC) F.4 Usage of Cloud Computing Services G. Redressal of Grievances related to Outsourced Services
Chapter V – Repeal and Other Provisions A. Repeal and saving B. Application of other laws not barred C. Interpretations
In exercise of the powers conferred by Section 35A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues the Directions hereinafter specified.
Chapter I – Preliminary
A. Short Title and Commencement
These Directions shall be called the Reserve Bank of India (Commercial Banks - Managing Risks in Outsourcing) Directions, 2025.
These Directions shall come into force with immediate effect.
Provided that a bank’s existing Information Technology (IT) outsourcing agreements regardless of whether they are due for renewal on or after the effective date of these Directions shall comply with the provisions of these Directions either at the time of renewal or by April 10, 2026, whichever is earlier. However, the bank’s new IT outsourcing agreements that come into force on or after the effective date of these Directions, shall comply with the provisions of these Directions from the date of agreement itself.
Provided further that nothing in the preceding proviso shall be construed as permitting non-compliance with any other extant regulatory instructions or statutory requirements applicable to such arrangements.
B. Applicability and Scope
For the purpose of these Directions, ‘Commercial Banks’ means banking companies (other than Small Finance Banks, Local Area Banks, Payments Banks and Regional Rural Banks), corresponding new banks, and the State Bank of India, as defined respectively under clauses (c), (da), and (nc) of section 5 of the Banking Regulation Act, 1949.
Provided that in respect of foreign banks operating in India through branch mode, any reference to the Board or Board of Directors in these Directions shall be read as a reference to the Head Office or Controlling Office that has oversight over the branch operations in India. Additionally, with respect to the Directions contained in Chapter IV regarding outsourcing of IT services, foreign banks shall be subject to a ‘comply or explain’ approach, which shall allow them to deviate from any specific provision of those Directions, subject to examination and acceptance by RBI of a reasonably justifiable explanation for such deviation.
(1) The provisions shall apply to outsourcing arrangements entered into by a bank with a service provider which may be either a member of the group / conglomerate to which the bank belongs, or an unrelated party, which is located in India or elsewhere, for outsourcing of financial services like applications processing (loan origination, credit card), document processing, marketing and research, supervision of loans, data processing and back office related activities.
Provided that for outsourced services relating to credit cards, the provisions set out in the Reserve Bank of India (Commercial Banks – Credit Cards and Debit Cards: Issuance and Conduct) Directions, 2025, as amended from time to time, shall also apply to the applicable entities.
(2) The provisions shall also apply, mutatis mutandis, to subcontracted activities. For this purpose, the outsourcing contract shall provide for prior approval or consent of the bank before a service provider engages any subcontractor for all or part of the outsourced activity. Before granting such consent, the bank shall review the subcontracting arrangement and ensure that the same complies with the Directions set out in Chapter III of these Directions.
(3) The provisions shall not apply to outsourcing of:
(1) The provisions shall apply to a bank’s material outsourcing of IT services, as defined in paragraph 53(2). In this context, ‘Outsourcing of IT Services’ shall include outsourcing of the following services:
(2) The provisions shall not apply to the following services:
(i) corporate internet banking services obtained by a bank as a corporate customer or sub-member of another Regulated Entity (RE);
Provided that for the purpose of these Directions, the following indicative (but not exhaustive) list of entities shall be considered as REs – other Commercial Banks; Local Area Banks; Small Finance Banks; Payments Banks; Regional Rural Banks; Non-Banking Financial Companies in Base Layer (NBFC - BL), Middle Layer (NBFC - ML), and Upper Layer (NBFC – UL); All India Financial Institutions; Credit Information Companies; Urban Co-operative Banks; Rural Co-operative Banks; and, Payment System Operators;
(ii) external audit services such as Vulnerability Assessment (VA) / Penetration Testing (PT), Information Systems Audit, and security review;
(iii) SMS gateways (including bulk SMS service providers);
(iv) procurement of IT hardware or appliances;
(v) acquisition of IT software, product or application (e.g., Core Banking Solution (CBS), database, and security solutions) on a licence or subscription basis, and any enhancements made to such licensed third-party applications by the vendor (as upgrades) or on specific change request made by a bank;
(vi) any maintenance service (including security patches, and bug fixes) for IT infrastructure or licensed products, provided by the Original Equipment Manufacturer (OEM) themselves, in order to ensure continued usage of the same by the bank;
(vii) applications provided by financial sector regulators or institutions such as Clearing Corporation of India Limited (CCIL), National Stock Exchange (NSE), and Bombay Stock Exchange (BSE);
(viii) platforms provided by entities such as Reuters, Bloomberg, and Society for Worldwide Interbank Financial Telecommunication (SWIFT);
(ix) any other off-the-shelf products (e.g., anti-virus software, and email solutions) subscribed to by a bank, wherein only a license is procured with no or minimal customisation;
(x) services obtained by a bank as a sub-member of a Centralised Payment System (CPS) from another RE;
(xi) Business Correspondent (BC) services, payroll processing, and statement printing.