RBI master-direction RBI/DOR/2025-26/245 · 28 Nov 2025
Official title
Reserve Bank of India (Local Area Banks – Managing Risks in Outsourcing) Directions, 2025
Summary
Check the official recordThe Reserve Bank of India issued directions for Local Area Banks to manage risks in IT outsourcing. Banks must establish a Board-approved IT outsourcing policy and maintain a central database of all arrangements. The policy must define criteria for material outsourcing, risk management, and exit strategies. Banks retain ultimate responsibility for outsourced services and must ensure service providers maintain high standards of data confidentiality and security. Banks must report cyber incidents to the RBI within six hours of detection. Existing IT outsourcing agreements must comply with these directions by April 10, 2026, or upon renewal, whichever is earlier. New agreements must comply immediately. These directions do not apply to specific services like external audits, SMS gateways, or off-the-shelf product subscriptions.
What you must do
RBI/DOR/2025-26/245 DOR.ORG.REC.No.164/21-04-158/2025-26
November 28, 2025
Reserve Bank of India (Local Area Banks – Managing Risks in Outsourcing) Directions, 2025
Table of Contents
Chapter I – Preliminary
A. Short Title and Commencement
B. Applicability and Scope
C. Definitions
Chapter II – Role of the Board
A. Board-Approved Policy
B. Key Responsibilities
Chapter III – Outsourcing of Information Technology (IT) Services
A. Authorisation, Accountability, and Oversight
B. Governance Framework
B.1 Outsourcing Policy
B.2 Role of Senior Management
B.3 Role of IT Function
C. Risk Management
C.1 Risk Management Framework
C.2 Confidentiality and Security of Information
D. Outsourcing Process
D.1 Service Provider Evaluation
D.2 Outsourcing Agreement
D.3 Monitoring and Control of Outsourced Services
D.4 Inventory of Outsourced Services
D.5 Business Continuity and Management of Disaster Recovery Plan
D.6 Exit Strategy
D.7 Termination
E. Specific Outsourcing Arrangements
E.1 Outsourcing within a Group / Conglomerate
E.2 Offshore or Cross-Border Outsourcing
E.3 Outsourcing of Security Operations Centre (SOC)
E.4 Usage of Cloud Computing Services
F. Redressal of Grievances related to Outsourced Services
Chapter IV – Repeal and Other Provisions
A. Repeal and Saving
B. Application of other laws not barred
C. Interpretations
In exercise of the powers conferred by Section 35A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues the Directions hereinafter specified.
These Directions shall be called the Reserve Bank of India (Local Area Banks - Managing Risks in Outsourcing) Directions, 2025.
These Directions shall come into force with immediate effect.
Provided that a bank’s existing Information Technology (IT) outsourcing agreements regardless of whether they are due for renewal on or after the effective date of these Directions shall comply with the provisions of these Directions either at the time of renewal or by April 10, 2026, whichever is earlier. However, the bank’s new IT outsourcing agreements that come into force on or after the effective date of these Directions, shall comply with the provisions of these Directions from the date of agreement itself.
Provided further that nothing in the preceding proviso shall be construed as permitting non-compliance with any other extant regulatory instructions or statutory requirements applicable to such arrangements.
These Directions shall be applicable to Local Area Banks (hereinafter collectively referred to as 'banks' and individually as a 'bank').
These Directions shall apply to a bank’s material outsourcing of IT services, as defined in paragraph 6(3) of these Directions. In this context, ‘Outsourcing of IT Services’ shall include outsourcing of the following services:
IT infrastructure management, maintenance, and support (hardware, software or firmware);
network and security solutions, and maintenance (hardware, software or firmware);
application development, maintenance, and testing by Application Service Providers (ASPs) including ATM Switch ASPs;
services and operations related to data centres;
cloud computing services;
managed security services; and
management of IT infrastructure and technology services associated with payment system ecosystem.
(i) corporate internet banking services obtained by a bank as a corporate customer or sub-member of another Regulated Entity (RE);
Provided that for the purpose of these Directions, the following indicative (but not exhaustive) list of entities shall be considered as REs - Commercial Banks; other LABs; Small Finance Banks; Payments Banks; Regional Rural Banks; Non-Banking Financial Companies in Base Layer (NBFC - BL), Middle Layer (NBFC - ML), and Upper Layer (NBFC – UL); All India Financial Institutions; Credit Information Companies; Urban Co-operative Banks; Rural Co-operative Banks; and, Payment System Operators.
For the purpose of these Directions, ‘Commercial Banks’ means banking companies (other than Small Finance Banks, Local Area Banks, Payments Banks and Regional Rural Banks), corresponding new banks, and the State Bank of India as defined respectively under clauses (c), (da), and (nc) of section 5 of the Banking Regulation Act, 1949.
(ii) external audit services such as Vulnerability Assessment (VA) / Penetration Testing (PT), Information Systems Audit, and security review;
(iii) SMS gateways (including bulk SMS service providers);
(iv) procurement of IT hardware or appliances;
(v) acquisition of IT software, product, or application (e.g., Core Banking Solution (CBS), database, and security solutions) on a licence or subscription basis, and any enhancements made to such licensed third-party applications by the vendor (as upgrades) or on specific change request made by a bank;
(vi) any maintenance service (including security patches, bug fixes) for IT infrastructure or licensed products, provided by the Original Equipment Manufacturer (OEM) themselves, in order to ensure continued usage of the same by the bank;
(vii) applications provided by financial sector regulators or institutions such as Clearing Corporation of India Limited (CCIL), National Stock Exchange (NSE), and Bombay Stock Exchange (BSE);
(viii) platforms provided by entities such as Reuters, Bloomberg, and Society for Worldwide Interbank Financial Telecommunication (SWIFT);
(ix) any other off-the-shelf products (e.g., anti-virus software, and email solutions) subscribed to by a bank, wherein only a license is procured with no or minimal customisation;
(x) services obtained by a bank as a sub-member of a Centralised Payment System (CPS) from another RE;
(xi) Business Correspondent (BC) services, payroll processing, and statement printing.
(1) ‘Group’ shall be as defined in the Reserve Bank of India (Commercial Banks – Concentration Risk Management) Directions, 2025, as amended from time to time, for the purpose of intragroup transactions and exposures.
(2) ‘IT services’ means IT services / IT enabled services / IT activities.
(3) ‘Material Outsourcing of IT Services’ are those which:
if disrupted or compromised shall have the potential to significantly impact the bank’s business operations; or
may have material impact on the bank’s customers in the event of any unauthorised access, loss or theft of customer information.
(4) ‘Outsourcing’ means use of a third party (either an affiliated entity within a corporate group or an entity that is external to the corporate group) by a bank to perform activities on a continuing basis that would normally be undertaken by the bank itself, now or in the future. 'Continuing basis' shall include agreements for a limited period.
(5) ‘Service Provider’ means provider of IT services including entities related to the bank or those which belong to the same group or conglomerate to which the bank belongs.
Provided that for the purpose of these Directions, the following indicative (but not exhaustive) list of vendors and entities shall not be considered as ‘Service Providers’ defined above:
vendors providing business services using IT e.g., BCs);
Payment System Operators (PSOs) authorised by RBI under the Payment and Settlement Systems Act, 2007 for setting up and operating Payment Systems in India;
partnership based FinTech firms such as those providing co-branded applications, products, and services;
FinTech firms providing services for data retrieval, data validation and verification such as, bank statement analysis, GST returns analysis, fetching of vehicle information, digital document execution, data entry and call centre services;
telecom service providers from whom leased lines or other similar kind of infrastructure are availed and used for transmission of data; and
security or audit consultants appointed for certification, audit or VA / PT related to IT infrastructure, IT services, or Information Security services in their role as independent third-party auditor, consultant or lead implementer.
Key dates
Who is affected
Exceptions