We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

NBFCs

RBI IT Framework Compliance for NBFCs

RBI’s IT governance expectations for NBFCs scale with the layer you occupy under scale-based regulation. Middle and Upper Layer NBFCs carry obligations close to a bank’s, and digital lending adds a further overlay that most NBFCs meet late.

What RBI IT Framework requires of nbfcs

  • Layer determination (Base, Middle, Upper, Top) — this dictates the depth of every obligation that follows.
  • Board-level IT strategy and IT governance structures, with a CISO where the layer requires one.
  • IS audit covering core lending systems, customer-facing channels and the third parties operating them.
  • Digital Lending Directions compliance where DLAs or LSPs are used, including data-storage restrictions and disclosure obligations.
  • Incident reporting to RBI and CERT-In, with the six-hour CERT-In clock running from detection.

Evidence assessors actually ask for

Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.

  • Board and IT Strategy Committee minutes showing genuine oversight
  • IS audit report with management responses and closure evidence
  • Vendor due-diligence and contractual security terms for LSPs and technology partners
  • Access reviews across the core lending platform and its interfaces
  • VAPT and retest evidence for digital lending applications

Where nbfcs usually come unstuck

  • Applying Base Layer expectations after crossing into Middle Layer through growth.
  • Assuming the LSP’s controls satisfy your obligation — accountability stays with the NBFC.
  • Customer data retained by a digital lending app in breach of the storage restrictions.

Related

NBFC complianceNBFC sectorRBI auditsCERT-In directions
Scope this engagement →What it costs
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Ready to discuss your RBI IT Framework requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →