← Co-operative banks
RBI Cyber Security Framework for Co-operative Banks
RBI applies a graded, level-based framework to urban co-operative banks, recognising that a small UCB cannot carry a scheduled commercial bank’s programme. The practical difficulty is that most UCBs run outsourced core banking, so the controls are operated by someone else while accountability stays with the bank.
What RBI UCB Cyber Security Framework requires of co-operative banks
- Level determination under the UCB framework, which sets the baseline controls required.
- Core banking system controls evidenced even where the CBS is vendor-operated.
- Digital channel security across internet banking, mobile, UPI, cards and AePS where offered.
- Vendor management with contractual security terms and a right to audit the CBS provider.
- Incident reporting to RBI and CERT-In, and cyber incident response the bank can actually execute.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Level assessment against the framework with gap closure tracked
- Vendor contracts carrying security obligations and audit rights
- Access reviews across CBS and digital channels, including vendor staff
- VAPT of internet and mobile banking with retest
- Incident response plan exercised, with a dated record
Where co-operative banks usually come unstuck
- Assuming the CBS vendor’s controls discharge the bank’s obligation — they do not.
- Vendor staff holding standing privileged access to the core banking system.
- Digital channels launched ahead of the security review they require.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
