RBI · Directions

Reserve Bank of India (Rural Co-operative Banks – Managing Risks in Outsourcing) Directions, 2025

RBI/DOR/2025-26/318

In short
RBI/DOR/2025-26/318 is the Reserve Bank of India (Rural Co-operative Banks – Managing Risks in Outsourcing) Directions, 2025, issued on 28 November 2025 with immediate effect. It binds State and Central Co-operative Banks as defined in the NABARD Act, 1981, and covers outsourcing of financial services only, with no IT outsourcing chapter and no transition proviso.

This page is the record of the instrument itself — reference, dates, scope and source. For what it means in practice, read Third-party risk management in Indian BFSI.

The record

ReferenceRBI/DOR/2025-26/318
Issued byReserve Bank of India (RBI)
Instrument typeDirections
Date of issue28 November 2025
StatusIn force
BindsRural Co-operative Banks — State and Central Co-operative Banks as defined in the NABARD Act, 1981 — for outsourcing of financial services only. No IT outsourcing chapter and no transition proviso: in force with immediate effect.
Dates it setsIn effect on issue. The instrument sets no further dates.
RBI RCB outsourcing Directions, 2025 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Binds State Co-operative Banks and Central Co-operative Banks as defined in the National Bank for Agriculture and Rural Development Act, 1981.
  • Covers outsourcing of financial services only; the instrument has no IT outsourcing chapter.
  • Took effect immediately, with none of the 10 April 2026 transition the rest of the family gives existing IT agreements.
  • Issued the same day as the other eight members of the outsourcing family, one per entity class.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating →Work out which instruments bind youThird-party risk management in Indian BFSI