Regulatory Framework Overview

The Reserve Bank of India (RBI) has published its updated Master Direction on IT Governance, Cloud Computing, and Technology Outsourcing (RBI/2026-27/DoR.ITG.48). The directive establishes strict regulatory guardrails for Scheduled Commercial Banks, Payment Aggregators, and Non-Banking Financial Companies (NBFCs) migrating core processing workloads to public and hybrid hyperscale cloud providers.

Core Compliance Mandates

Recognizing systemic concentration risks arising from banking dependency on global cloud service providers (CSPs), the RBI framework introduces legally binding requirements across cloud architecture, security governance, and operational sovereignty:

Compliance Pillar Previous Standard Mandatory 2026 Requirement
Cryptographic Key Control Provider-managed keys allowed Customer-Managed Keys (CMK) / Bring-Your-Own-Key (BYOK) with hardware HSMs within India
Audit Frequency Annual periodic assessment Continuous automated compliance monitoring + quarterly external cloud security audit
Cloud Concentration Risk Single-cloud deployment permitted Multi-cloud portability strategy with validated exit plans executable within 48 hours
Incident Reporting 6-hour window to CERT-In Immediate 2-hour reporting to RBI Cyber Security Operation Center (CSOC)

Sovereign Data Localization & Key Custody

Under Section 8.2 of the directive, regulated financial entities must maintain absolute custody of sensitive financial data. Cloud service providers cannot be granted access to unencrypted customer transactional records or underlying cryptographic root keys. Financial institutions must deploy Hardware Security Modules (HSMs) certified to FIPS 140-3 Level 3 physically situated within the territory of India.

Board Governance & Enforcement Penalties

The framework mandates that the Board of Directors of each regulated entity establish an Information Technology Strategy Committee chaired by an independent director. Failure to adhere to the Master Direction exposes institutions to supervisory restrictions, including bans on onboarding new digital banking customers and statutory fines under the Banking Regulation Act.