We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · BFSI audit practice

RBI cybersecurity audit for NBFCs

RBI’s Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (and the earlier IT-framework and outsourcing directions) require NBFCs to run independent IT and cyber-security audits sized to their scale. CyberSigma is a CERT-In empanelled auditor with a dedicated BFSI practice: we assess your IT governance, cyber-security controls, VAPT posture, third-party/outsourcing risk and business continuity against the applicable RBI direction, and give you an auditable, prioritised report your Board and RBI inspection can rely on.

Get a free RBI readiness snapshot →Book a 20-minute BFSI-audit call
Who needs it

Which NBFCs this applies to

RBI applies IT-governance and cyber-security expectations on a graded, scale-based basis. Middle- and upper-layer NBFCs face the fullest requirements, but base-layer entities still need proportionate IT and information-security controls, and lenders in digital-lending arrangements carry specific obligations.

Scope

What the audit covers

IT governance & risk
Board oversight, IT strategy, policies, risk management and MIS.
Cyber-security controls
Access control, network security, logging/monitoring, patch and vulnerability management.
VAPT & resilience
Application and infrastructure testing, business continuity and disaster recovery.
Third-party & outsourcing
Vendor due diligence, cloud and digital-lending partner risk under RBI outsourcing norms.
Regulation

Applicable RBI directions

The RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices; the Master Direction on Digital Payment Security Controls where relevant; RBI outsourcing directions; and the Digital Lending guidelines for lending partnerships.

Timeline & cost

Timeline and cost factors

Timeline
A focused NBFC audit typically runs 3–6 weeks depending on layer, systems and the number of outsourced/digital-lending arrangements.
Cost factors
NBFC layer and size, number of applications and third parties, whether VAPT is bundled, and remediation support scope.
Evidence & deliverables

What you provide and receive

Required evidence
Policies, access reviews, patch and vulnerability records, logs, BCP/DR tests, vendor contracts and prior audit closure evidence.
Deliverables
A Board-ready audit report mapped to the applicable RBI direction, a prioritised remediation plan, and closure retest evidence.
Common failures

Findings boards underestimate

  • Weak outsourcing/vendor governance for cloud and digital-lending partners
  • Incomplete logging and monitoring, and untested incident response
  • Access reviews and privileged-access controls not evidenced
  • BCP/DR documented but not tested against real recovery objectives
Proof

See how we’ve done it before

Relevant case study
How an NBFC closed RBI IT-audit gaps and evidenced Board-level assurance. Read case studies →
Redacted sample deliverable
Inspect a redacted audit report first. Request a redacted sample →

Worried about a supplier becoming your breach?

Get a free third-party risk scoping call — share your work email and we frame your vendor tiers, gaps and next steps.

RBI cyber-security audit for NBFCs — FAQs

Which RBI direction applies to our NBFC?

It depends on your NBFC layer and activities. Middle- and upper-layer NBFCs face the fullest IT-governance and assurance requirements; base-layer entities need proportionate controls. We confirm the exact applicable direction during scoping.

Do you cover digital-lending partners?

Yes. We assess outsourcing and digital-lending arrangements against RBI’s outsourcing and Digital Lending guidelines, including your due diligence and monitoring of Lending Service Providers.

Is VAPT included?

It can be bundled. As a CERT-In empanelled auditor we can combine the governance audit with application and infrastructure VAPT for a single, coherent report.

Talk to our BFSI audit practice

Get a clear read on your applicable RBI direction, gaps and the fastest path to a Board-ready audit. Reply within four business hours.

Book a 20-minute BFSI call →

Ready to discuss your RBI cybersecurity audit for NBFCs requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.