Regulatory Framework Overview
The Reserve Bank of India (RBI) has published its updated Master Direction on IT Governance, Cloud Computing, and Technology Outsourcing (RBI/2026-27/DoR.ITG.48). The directive establishes strict regulatory guardrails for Scheduled Commercial Banks, Payment Aggregators, and Non-Banking Financial Companies (NBFCs) migrating core processing workloads to public and hybrid hyperscale cloud providers.
Core Compliance Mandates
Recognizing systemic concentration risks arising from banking dependency on global cloud service providers (CSPs), the RBI framework introduces legally binding requirements across cloud architecture, security governance, and operational sovereignty:
| Compliance Pillar | Previous Standard | Mandatory 2026 Requirement |
|---|---|---|
| Cryptographic Key Control | Provider-managed keys allowed | Customer-Managed Keys (CMK) / Bring-Your-Own-Key (BYOK) with hardware HSMs within India |
| Audit Frequency | Annual periodic assessment | Continuous automated compliance monitoring + quarterly external cloud security audit |
| Cloud Concentration Risk | Single-cloud deployment permitted | Multi-cloud portability strategy with validated exit plans executable within 48 hours |
| Incident Reporting | 6-hour window to CERT-In | Immediate 2-hour reporting to RBI Cyber Security Operation Center (CSOC) |
Sovereign Data Localization & Key Custody
Under Section 8.2 of the directive, regulated financial entities must maintain absolute custody of sensitive financial data. Cloud service providers cannot be granted access to unencrypted customer transactional records or underlying cryptographic root keys. Financial institutions must deploy Hardware Security Modules (HSMs) certified to FIPS 140-3 Level 3 physically situated within the territory of India.
Board Governance & Enforcement Penalties
The framework mandates that the Board of Directors of each regulated entity establish an Information Technology Strategy Committee chaired by an independent director. Failure to adhere to the Master Direction exposes institutions to supervisory restrictions, including bans on onboarding new digital banking customers and statutory fines under the Banking Regulation Act.



