We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · BFSI audit practice

RBI cybersecurity audit for NBFCs

RBI’s Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (and the earlier IT-framework and outsourcing directions) require NBFCs to run independent IT and cyber-security audits sized to their scale. CyberSigma is a CERT-In empanelled auditor with a dedicated BFSI practice: we assess your IT governance, cyber-security controls, VAPT posture, third-party/outsourcing risk and business continuity against the applicable RBI direction, and give you an auditable, prioritised report your Board and RBI inspection can rely on.

Get a free RBI readiness snapshot →Book a 20-minute BFSI-audit call
Who needs it

Which NBFCs this applies to

RBI applies IT-governance and cyber-security expectations on a graded, scale-based basis. Middle- and upper-layer NBFCs face the fullest requirements, but base-layer entities still need proportionate IT and information-security controls, and lenders in digital-lending arrangements carry specific obligations.

Scope

What the audit covers

IT governance & risk
Board oversight, IT strategy, policies, risk management and MIS.
Cyber-security controls
Access control, network security, logging/monitoring, patch and vulnerability management.
VAPT & resilience
Application and infrastructure testing, business continuity and disaster recovery.
Third-party & outsourcing
Vendor due diligence, cloud and digital-lending partner risk under RBI outsourcing norms.
Regulation

Applicable RBI directions

The RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices; the Master Direction on Digital Payment Security Controls where relevant; RBI outsourcing directions; and the Digital Lending guidelines for lending partnerships.

Timeline & cost

Timeline and cost factors

Timeline
A focused NBFC audit typically runs 3–6 weeks depending on layer, systems and the number of outsourced/digital-lending arrangements.
Cost factors
NBFC layer and size, number of applications and third parties, whether VAPT is bundled, and remediation support scope.
Evidence & deliverables

What you provide and receive

Required evidence
Policies, access reviews, patch and vulnerability records, logs, BCP/DR tests, vendor contracts and prior audit closure evidence.
Deliverables
A Board-ready audit report mapped to the applicable RBI direction, a prioritised remediation plan, and closure retest evidence.
Common failures

Findings boards underestimate

  • Weak outsourcing/vendor governance for cloud and digital-lending partners
  • Incomplete logging and monitoring, and untested incident response
  • Access reviews and privileged-access controls not evidenced
  • BCP/DR documented but not tested against real recovery objectives
Proof

See how we’ve done it before

Relevant case study
How an NBFC closed RBI IT-audit gaps and evidenced Board-level assurance. Read case studies →
Redacted sample deliverable
Inspect a redacted audit report first. Request a redacted sample →

Worried about a supplier becoming your breach?

Get a free third-party risk scoping call — share your work email and we frame your vendor tiers, gaps and next steps.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • Payment system data storage in IndiaEffective 6 October 2018

    RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.

    Circular number cited for retrieval via RBI's notification search; we deliberately avoid deep-linking RBI's session-bound URLs.

  • IT Governance Master DirectionEffective 1 April 2024

    Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.

    Direction number cited for retrieval via RBI notification search; RBI deep links are session-bound.

  • IT Outsourcing Master DirectionEffective 1 October 2023

    Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.

    Direction number cited for retrieval via RBI notification search.

  • Digital Payment Security Controls Master DirectionEffective 18 February 2021

    Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.

    Direction cited by title and date for retrieval via RBI notification search.

  • Cyber Security Framework in BanksEffective 2 June 2016

    RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.

Related in this cluster

RBI cyber-security audit for NBFCs — FAQs

Which RBI direction applies to our NBFC?

It depends on your NBFC layer and activities. Middle- and upper-layer NBFCs face the fullest IT-governance and assurance requirements; base-layer entities need proportionate controls. We confirm the exact applicable direction during scoping.

Do you cover digital-lending partners?

Yes. We assess outsourcing and digital-lending arrangements against RBI’s outsourcing and Digital Lending guidelines, including your due diligence and monitoring of Lending Service Providers.

Is VAPT included?

It can be bundled. As a CERT-In empanelled auditor we can combine the governance audit with application and infrastructure VAPT for a single, coherent report.

Talk to our BFSI audit practice

Get a clear read on your applicable RBI direction, gaps and the fastest path to a Board-ready audit. Reply within four business hours.

Book a 20-minute BFSI call →

Ready to discuss your RBI cybersecurity audit for NBFCs requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.