RBI · Directions

Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025

RBI/DOR/2025-26/171

In short
RBI/DOR/2025-26/171 is the Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025, issued on 28 November 2025 with immediate effect. Existing IT outsourcing agreements had to comply by 10 April 2026. It is a separate track from the 2026 cybersecurity Directions, which expressly preserve it rather than absorbing it.

The record

ReferenceRBI/DOR/2025-26/171
Issued byReserve Bank of India (RBI)
Instrument typeDirections
Date of issue28 November 2025
StatusIn force
BindsCommercial banks. Immediate effect, with existing IT outsourcing agreements to comply by 10 April 2026. Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks covered.
Dates it sets
  • 10 April 2026Existing IT outsourcing agreements to comply.
RBI outsourcing Directions, 2025 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds commercial banks, with immediate effect from 28 November 2025.
  • Gave existing IT outsourcing agreements until 10 April 2026 to comply.
  • Repeals the 2023 Master Direction on Outsourcing of IT Services for the banks it covers.
  • Remains in force after the 2026 cybersecurity Directions, whose third-party paragraphs apply only to arrangements falling outside this instrument.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • RBI NBFC outsourcing Directions, 2025 RBI/DOR/2025-26/363NBFCs, HFCs, CICs, standalone primary dealers and the account aggregator and P2P categories.
  • Commercial Banks RBI/DoS/2026-27/410Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating Third-party risk management in Indian BFSI