Reserve Bank of India (Rural Co-operative Banks – Managing Risks in Outsourcing) Directions, 2025
RBI/DOR/2025-26/318
This page is the record of the instrument itself — reference, dates, scope and source. For what it means in practice, read Third-party risk management in Indian BFSI.
The record
| Reference | RBI/DOR/2025-26/318 |
|---|---|
| Issued by | Reserve Bank of India (RBI) |
| Instrument type | Directions |
| Date of issue | 28 November 2025 |
| Status | In force |
| Binds | Rural Co-operative Banks — State and Central Co-operative Banks as defined in the NABARD Act, 1981 — for outsourcing of financial services only. No IT outsourcing chapter and no transition proviso: in force with immediate effect. |
| Dates it sets | In effect on issue. The instrument sets no further dates. |
What it says
- Binds State Co-operative Banks and Central Co-operative Banks as defined in the National Bank for Agriculture and Rural Development Act, 1981.
- Covers outsourcing of financial services only; the instrument has no IT outsourcing chapter.
- Took effect immediately, with none of the 10 April 2026 transition the rest of the family gives existing IT agreements.
- Issued the same day as the other eight members of the outsourcing family, one per entity class.
What accounts of this instrument get wrong
Read the instrument
The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.
Instruments that change what this one requires
Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.
- RBI outsourcing Directions, 2025 RBI/DOR/2025-26/171 — Commercial banks — a separate outsourcing track the 2026 Directions preserve rather than absorb.
- RBI UCB outsourcing Directions, 2025 RBI/DOR/2025-26/293 — Urban Co-operative Banks — every tier for financial outsourcing, Tier 3 and 4 for IT.
This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .