RBI master-direction RBI/DOR/2025-26/293 · 28 Nov 2025
Official title
Reserve Bank of India (Urban Co-operative Banks – Managing Risks in Outsourcing) Directions, 2025
Summary
Check the official recordThe Reserve Bank of India issues these Directions to govern the outsourcing of financial and information technology services by Urban Co-operative Banks. Banks retain ultimate responsibility for outsourced activities and must maintain board-approved policies for risk management, due diligence, and oversight. The Directions mandate specific contractual requirements, including audit rights and business continuity plans. Tier-3 and Tier-4 banks must also comply with additional IT-specific outsourcing provisions. Existing IT outsourcing agreements must align with these requirements upon renewal or by April 10, 2026, whichever is earlier. New agreements must comply immediately. These Directions repeal previous instructions on the subject while preserving actions taken under prior frameworks.
What you must do
Key dates
Who is affected
Exceptions
If you do not comply
RBI/DOR/2025-26/293 DOR.ORG.REC.No.212/21-04-158/2025-26 November 28, 2025
Reserve Bank of India (Urban Co-operative Banks – Managing Risks in Outsourcing) Directions, 2025
In exercise of the powers conferred by Section 35A read with Section 56 of the Banking Regulation Act, 1949, as amended vide Banking Regulation (Amendment) Act 2020 (39 of 2020), and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues the Directions hereinafter specified.
Provided that for Urban Co-operative Banks covered under the scope of these Directions as enumerated in paragraph 3, their existing Information Technology(IT) outsourcing agreements regardless of whether they are due for renewal on or after the effective date of these Directions shall comply with the provisions of these Directions either at the time of renewal or by April 10, 2026, whichever is earlier. However, the bank’s new IT outsourcing agreements that come into force on or after the effective date of these Directions, shall comply with the provisions of these Directions from the date of agreement itself.
Provided further that nothing in the preceding proviso shall be construed as permitting non-compliance with any other extant regulatory instructions or statutory requirements applicable to such arrangements.
For the purpose of these Directions, ‘Urban Co-operative Banks’ means Primary Co-operative Banks as defined under section 5(ccv) read with Section 56 of Banking Regulation Act, 1949.
Provided that Chapter IV and IT-specific provisions contained in Chapter II of these Directions shall apply only to Tier-3 and Tier-4 Urban Co-operative Banks as defined in Reserve Bank of India (Urban Co-operative Banks – Licensing, Scheduling and Regulatory Classification) Guidelines, 2025.
Explanation: While Chapter IV as a whole is applicable exclusively to Tier-3 and Tier-4 Urban Co-operative Banks, certain IT-related provisions in Chapter II (e.g., Board-level IT outsourcing policy and responsibilities of and reviews by the Board with respect to IT outsourcing) are also intended for these categories only. The remaining provisions of Chapter II are applicable to all Urban Co-operative Banks, including those in Tier-1 and Tier-2.
(1) The provisions shall apply to outsourcing arrangements entered into by a bank with a service provider, located in India or elsewhere, for outsourcing of financial services like applications processing (loan origination, credit card), document processing, marketing and research, supervision of loans, data processing and back office related activities.
Provided that for outsourced services relating to credit cards, the provisions set out in the Reserve Bank of India (Urban Co-operative Banks – Credit Cards and Debit Cards: Issuance and Conduct) Directions, 2025, as amended from time to time, shall also apply.
(2) The provisions shall not apply to outsourcing of:
(i) IT services as defined in paragraph 48(1) of these Directions, unless specified otherwise in respective paragraphs of Chapter IV; (ii) activities unrelated to banking services like usage of courier, catering of staff, housekeeping and janitorial services, security of the premises, and movement and archiving of records.
(1) These provisions shall apply to a bank’s material outsourcing of IT services, as defined in paragraph 48(2) above. In this context, ‘Outsourcing of IT Services’ shall include outsourcing of the following activities:
(i) IT infrastructure management, maintenance and support (hardware, software or firmware); (ii) network and security solutions, maintenance (hardware, software or firmware); (iii) application development, maintenance, and testing by Application Service Providers (ASPs) including ATM Switch ASPs; (iv) services and operations related to data centres; (v) cloud computing services; (vi) managed security services; and (vii) management of IT infrastructure and technology services associated with payment system ecosystem.
(2) These provisions shall not apply to the following services / activities,
(i) corporate internet banking services obtained by a bank as a corporate customer or sub-member of another Regulated Entity (RE);
Provided that for the purpose of these Directions, the following indicative (but not exhaustive) list of entities shall be considered as REs –Commercial Banks; Local Area Banks; Small Finance Banks; Payments Banks; Regional Rural Banks; Non-Banking Financial Companies in Base Layer (NBFC - BL), Middle Layer (NBFC - ML), and Upper Layer (NBFC – UL); All India Financial Institutions; Credit Information Companies; other Urban Co-operative Banks; Rural Co-operative Banks; and, Payment System Operators,
For the purpose of these Directions, ‘Commercial Banks’ means banking companies (other than Small Finance Banks, Local Area Banks, Payments Banks and Regional Rural Banks), corresponding new banks and the State Bank of India, as defined respectively under clauses (c), (da), and (nc) of section 5 of the Banking Regulation Act, 1949.
(ii) external audit services such as Vulnerability Assessment (VA) / Penetration Testing(PT), Information Systems Audit, and security review; (iii) SMS gateways (including bulk SMS service providers); (iv) procurement of IT hardware or appliances; (v) acquisition of IT software, product or application (e.g., Core Banking Solution (CBS), database, and security solutions) on a licence or subscription basis, and any enhancements made to such licensed third-party applications by the vendor (as upgrades) or on specific change request made by a bank; (vi) any maintenance service (including security patches, and bug fixes) for IT infrastructure or licensed products, provided by the Original Equipment Manufacturer (OEM) themselves, in order to ensure continued usage of the same by the bank; (vii) applications provided by financial sector regulators or institutions such as Clearing Corporation of India Limited (CCIL), National Stock Exchange (NSE), and Bombay Stock Exchange (BSE); (viii) platforms provided by entities such as Reuters, Bloomberg, and Society for Worldwide Interbank Financial Telecommunication (SWIFT); (ix) any other off-the-shelf products (e.g., anti-virus software, and email solutions) subscribed to by a bank, wherein only a license is procured with no or minimal customisation; (x) services obtained by a bank as a sub-member of a Centralised Payment System (CPS) from another RE; (xi) Business Correspondent (BC) services, payroll processing, and statement printing.