RBI - Commercial Banks (Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
AI / PRIVACY / CYBER RELEVANCE
Core security layer for AI/LLM deployments by banks, including vendor/cloud risk, data protection, access, logging and assurance.
AI: HighPrivacy: HighCybersecurity: Very High
READ FIRST
- Chapter III IT governance
- Chapter IV risk management
- Chapter V baseline controls
- third-party arrangements
- cryptographic controls
- continuous surveillance
PURVIEW
Creates the RBI’s broad cybersecurity, technology-risk, resilience and assurance framework for commercial banks. It covers governance, technology architecture, cyber-risk management, access controls, secure development, change management, outsourcing and third-party risk, monitoring, resilience, assurance and related controls. For AI, this is one of the most important sectoral instruments because banks deploy AI across credit, fraud, customer service, operations and risk functions while operating highly sensitive financial-data environments. AI systems therefore become part of the bank’s regulated technology and risk architecture.
Classification and legal status. Binding Directions for commercial banks in scope; effective immediately upon issuance.