Industries
NBFC and digital lending — RBI IS audit readiness
Lending, payments and collections platforms sit under RBI IT-governance and IS-audit scrutiny, ITGC expectations and supervisory reporting.
Applicable regulations
- RBI Master Direction on IT Governance, Risk and Controls
- RBI Digital Lending (DLA) directions
- IT general controls (ITGC) expectations
- DPDP Act 2023
Common cybersecurity risks
- Data leakage from digital-lending apps and third-party LSP exposure
- Weak ITGC over change, access and backups
- Unmonitored collections and customer-data flows
- Supervisory findings without evidenced closure
Audit findings we typically see
- Incomplete DLA and LSP due-diligence evidence
- Access-recertification gaps across lending systems
- Backup and restore not tested to policy
- IS-audit observations left open past their timelines
Services required
- RBI digital-lending (DLA) audit
- IT general controls (ITGC) audit
- Third-party and LSP risk assessment
- VAPT for lending apps and APIs
Our engagement approach
- Discovery. Map the lending stack, LSP partners and data flows against RBI directions.
- Assessment. ITGC and IS-audit gap testing with prioritised findings.
- Remediation. Control design and evidence templates for supervisory closure.
- Reporting. An IS-audit-ready report and board pack.
Expected evidence
- LSP and third-party due-diligence records
- ITGC test results
- Backup and restore test evidence
- IS-audit closure tracker
Indicative timeline
Readiness usually runs 6 to 12 weeks, depending on lending-stack complexity.
Deliverables
- RBI-mapped gap assessment
- ITGC audit report
- VAPT reports with closure
- Board and IS-audit reporting pack
Related case study
Free tool
Try it free →Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
