Skip to main content

RBI Mandates IT Services Framework For REs

The new comprehensive master direction on information technology governance, risk, controls and assurance practices to be implemented by Regulated entities (REs) comprising of scheduled commercial banks (excluding regional rural banks); small finance banks; payments banks; NBFCs in top, upper and middle layers; all India financial institutions and credit information companies effective from 1st April 2024 shall facilitate the easy administration of IT and cyber governance and compliance, in place of the prevalent multiple circulars.

REs shall facilitate the easy administration of IT and cyber governance and compliance, in place of the prevalent multiple circulars
REs shall facilitate the easy administration of IT and cyber governance and compliance, in place of the prevalent multiple circulars

In the case of foreign banks, the directions state that they shall be subject to a ‘comply or explain’ approach in terms of the applicability of these Directions and they do not need to constitute any Committees (Board or Executive level) referred in this Master Direction at the branch level. They have been given the flexibility to leverage upon controlling office/ head office/ regional/ zonal Committees for compliance with this Master Direction as long as governance obligations/responsibilities outlined for the prescribed committees are met.

The master direction clearly outlines the role (including authority) of the board of directors, board-level committee and senior management of these REs in discharging their responsibilities to protect the interests of customers. and consolidates and updates the guidelines, instructions and circulars on IT Governance Risk, Controls, Assurance Practices and Business Continuity/ Disaster Recovery Management issued earlier.

The master direction makes it mandatory for the REs to put in place a robust IT Service Management Framework for supporting their information systems and infrastructure to ensure the operational resilience of their entire IT environment (including Disaster Recovery sites). Further its stresses the need to have a documented data migration policy specifying a systematic process for data migration, ensuring data integrity, completeness and consistency. In the wake of cyber and IT fraud, RBI in its master direction has stressed the need for IT applications to have the necessary audit and system logging capability and ability to provide audit trails. Further, in order to strengthen the IT infrastructure, the RBI through its direction highlights the need to adopt internationally accepted and published standards that are not deprecated/ demonstrated to be insecure/ vulnerable and the configurations involved in implementing controls to be compliant with extant laws and regulatory instructions.

While the approval of strategies and policies related to the IT function lies in the hands of the Board, these directions put the responsibility on the CEO to institute effective oversight on the planning and execution of IT Strategy as well as to ensure that cyber security posture of the RE is robust; and overall, IT contributes to productivity, effectiveness and efficiency in business operations. The directions designate a Chief Information Security Officer (CISO) who will be responsible for driving IT/ cyber security, compliance and related regulatory guidelines, and administering policies of the RE.

From a compliance perspective, REs have to ensure that appropriate vendor risk assessment process & controls proportionate to assessed risk & materiality has been put in place. Further, it shall be the responsibility of the REs to maintain an enterprise data dictionary to enable data sharing among applications & information systems

The RBI through this master direction, recognizing the increased relevance of IT infrastructure in the financial services space, has detailed the mandatory implementation and review of the IT systems and applications in order to keep a check on the processes, data security and integrity, disaster recovery management as well as business continuity in order to protect the interest of various stakeholders including customers. The directions mandate the adoption of several procedures and processes like IT Strategic Planning, Service Level Management (SLM), product approval and quality assurance process (for new IT-based business products) in order to ensure that the banking sector delivers secure products and services to its clients. In this era of digitisation and increasing threats, the master direction provides the required structure and procedures to secure banking systems.

Comments

Popular posts from this blog

‘I’m just not afraid’: Lynda Carter on her online activism and Wonder Woman

  The afterlife of the movie star with a single, iconic role is a curiosity. Between 1976 and 1979, Lynda Carter appeared in three seasons of Wonder Woman , a hit so huge that for those of us who saw it as children, she remains a somewhat mystical figure. Knight Rider was great, the A-Team was fun, but Wonder Woman – jumping between boulders, sparks flying from her wrist plates – was something else. Here is Carter today, in a pastel-colored blazer on video chat from her home in Maryland, and although I’m a 46-year-old woman with two children and a mortgage, I can’t help it: I’m completely agog. “It was such a short part of my life, but it has made a bigger impact than any other thing I’ve done,” says Carter, who is 70 and looks nothing of the sort. Among the many reasons to love her, is her good grace in the face of a generation’s obsession with those three short years of her life. To know more: https://www.theguardian.com/film/2022/jul/25/lynda-carter-interview-twitter-w...

Australian teenager feared dead months after Islamic State attack on Syrian prison

  Yusuf Zahab, who was taken to Syria when he was 11, was wounded in January during fighting between IS fighters and Kurdish-led forces at a makeshift prison An Australian teenager is believed to have died in a Syrian prison holding Islamic State (IS) suspects, months after he begged the Australian government for assistance, his family and a leading rights group have said. Yusuf Zahab was detained in Guweiran prison in Hasakah city alongside suspected IS members for more than three years when it was attacked by IS in January in an attempt to free its fighters. During the fighting, an audio recording by Zahab begging for help made it outside the jail and was widely publicised. "I got injured in my head and my hand," Zahab said at the time. "I lost a lot of blood … There's no doctors here, there's no one who can help me. I'm very scared. I need help. Please… [My] friends got killed in front of me, a 14-year-old, a 15-year-old… There's a lot of bodies, dead...

"Juhar, Namaskar," Says Droupadi Murmu, 1st Tribal President

  New Delhi:  Droupadi Murmu was administered oath of office by Chief Justice of India NV Ramana. Former president Ram Nath Kovind, outgoing Vice President M Venkaiah Naidu, Prime Minister Narendra Modi and Congress president Sonia Gandhi were present at the event To know more: https://www.ndtv.com/india-news/president-elect-droupadi-murmu-to-take-oath-today-10-points-3189839#pfrom=home-ndtv_topscroll