RBI cyber security expectations: what NBFCs and their suppliers need in place
Regulated financial entities and the firms serving them face specific IT expectations. Here is the operational reading of what that means day to day.

Regulated financial entities in India work to cyber security expectations set by the Reserve Bank, and those expectations flow down to the firms supplying them. The published frameworks are detailed. This is the operational version: what an examiner actually asks for, and what you need in place to answer.
The recurring theme is evidence
In almost every engagement we take on in this sector, the controls broadly exist. What is missing is the ability to demonstrate them. An examiner does not ask whether you review access; they ask to see the last four reviews, who performed them and what changed as a result. Those are different questions and only one of them is usually answerable.
Access control and privilege
Named accounts, no shared administrative credentials, and privileged actions attributable to a person. Where administrators share an account, nothing that account did can be attributed, which undermines the entire audit trail.
Access reviews on a defined cycle, recorded. Joiner, mover and leaver executed as a process rather than remembered. Third-party and vendor access time-bound and reviewed, because standing supplier access is one of the most common findings.
Logging and monitoring
Centralised, time-synchronised logs with retention set to the applicable requirement. This is foundational rather than optional: incident reporting timelines cannot be met if reconstructing what happened means visiting individual machines.
Monitoring with somebody actually watching. An unwatched SIEM satisfies a procurement checkbox and detects nothing.
Data protection and residency
Encryption at rest and in transit, verified rather than assumed. Payment and customer data carries storage-location obligations, so cloud and backup design must account for where data physically rests, and that decision needs documenting rather than inferring from a provider default.
Incident response
A documented plan with named people and out-of-hours contacts. A defined decision process for whether an event is reportable. Rehearsed at least annually, because the first attempt at a coordinated response should not happen during a real incident.
CERT-In reporting timelines apply here as elsewhere, and the same preparation makes them achievable.
If you supply a regulated entity
Expect the obligations to reach you contractually even though you are not regulated directly. Your client will be asked about their supply chain and will pass the questions on. Being able to answer, with evidence, is increasingly a condition of winning the work rather than a compliance afterthought.
Where to start
Centralise logging with correct retention. Eliminate shared privileged accounts. Establish a recorded access review cycle. Verify encryption rather than assuming it. Document the incident response path with names. Those five cover the majority of what gets asked, and none of them requires a large platform purchase.
More from the Compliance desk

HIPAA Compliance: Why It's Critical for Healthcare Organizations and How We Can Help
Understanding HIPAA compliance requirements, potential penalties, security implications, and how GR IT Services helps healthcare organizations achieve and maintain compliance.
Read post
The DPDP Act for Indian businesses: what IT actually has to change
The Digital Personal Data Protection Act changes how Indian businesses must handle personal data. Here is what it means for your systems, in the order it is worth doing.
Read post
CERT-In directions: what Indian businesses have to do about incident reporting
CERT-In requires certain cyber incidents to be reported quickly and logs to be retained. Meeting that is an engineering problem you solve before an incident, not during one.
Read postHave a question about this topic?
If you would like help applying any of this to your environment, send us the specifics and an engineer will reply.