What the 2026 RBI Directions ask of a UCB
RBI/DoS/2026-27/437 grades urban co-operative banks into four levels by digital depth. A Level I UCB owes no CISO; only a Level IV owes an operations centre.
RBI/DoS/2026-27/437 binds Primary Co-operative Banks — urban co-operative banks — under section 5(ccv) read with section 56 of the Banking Regulation Act, 1949. Unlike the instruments for commercial banks, small finance banks or payments banks, it does not apply one set of obligations to everyone it names. It sorts each bank into one of four levels and gives each level a different stack of chapters.
The sorting test is not asset size. It is, in the Directions’ own phrase, the bank’s digital depth and interconnectedness to the payment systems landscape — which means two co-operative banks of the same size can sit two levels apart because one of them offers a mobile banking application.
Working out your level
| Level | Criteria | Chapters |
|---|---|---|
| I | Every UCB, whatever digital services or products it offers. | II, III |
| II | A sub-member of Centralised Payment Systems that also meets at least one of: offers internet banking, view-based or transactional; provides mobile banking through an application; or is a direct member of CTS, IMPS or UPI. | II, III, IV |
| III | A direct member of Centralised Payment Systems, or a bank running its own ATM switch or a SWIFT interface. | II, III, IV, V |
| IV | A direct member or sub-member of Centralised Payment Systems that either has both its own ATM switch and a SWIFT interface, or hosts a data centre or provides software support to other banks — itself or through a wholly owned subsidiary. | II, III, IV, V, VI |
Centralised Payment Systems, for this purpose, means RTGS and NEFT and any other system the RBI adds, following the Master Directions on Access Criteria for Payment Systems, 2017.
The chapters stack
A Level III UCB complies with Chapters II, III, IV and V. It does not comply with Chapter V alone. That sounds obvious until you look at the NBFC Directions issued the same day, where the three obligation chapters are drafted as alternatives and exactly one binds any given firm.
What each level adds
Chapter III — every UCB, 24 sections
The Level I baseline is not thin. It opens with a self-assessment, then a Board-approved cybersecurity policy, an IT architecture, a cyber crisis management plan, and defined roles for the Board and senior management. The controls run through inventory management of information assets, protection of customer and payment information, cryptographic controls, prevention of unauthorised software, environmental and network controls, secure configuration, anti-virus, change and patch management, user access control, secure mail and messaging, removable media, awareness for staff and customers, backup and restoration, vendor and outsourcing risk management, incident response and recovery, controls on deploying a new application, and an information systems audit.
Chapter IV — Level II adds 14 sections
IT resource planning, a Chief Information Security Officer or equivalent official, and a second and deeper pass at network security, secure configuration, the application security life cycle, change and patch management, periodic testing, user access control, authentication for customers, anti-phishing, data leak prevention, database integrity, audit logs and incident response.
Chapter V — Level III adds nine sections
Network management, secure configuration and the application security life cycle again at a higher standard, plus user access control, advanced real-time threat defence and management, maintenance and analysis of audit logs, incident response, awareness, and a risk-based transaction monitoring system.
Chapter VI — Level IV adds seven sections
A Cyber Security Operations Centre, participation in cyber drills, incident response, metrics, forensics, an IT strategy and policy, and an IT and information systems governance framework.
Where the CISO and the operations centre appear
Two obligations decide most of what this framework costs a co-operative bank, and both sit further up than people expect.
- A CISO is first required at Level II. The requirement for a Chief Information Security Officer or equivalent official is the second section of Chapter IV. A Level I UCB owes a Board-approved cybersecurity policy, a crisis management plan, an asset inventory and an information systems audit — but no named security officer.
- A Cyber Security Operations Centre is first required at Level IV. It is the opening section of Chapter VI, which only a Level IV bank attracts. A Level III UCB running its own ATM switch owes advanced real-time threat defence and transaction monitoring, and does not owe a staffed operations centre.
So the level test is a budgeting question before it is a compliance one. Adding a mobile banking application takes a bank from Level I to Level II and brings a CISO with it.
Proportionality runs one way
A UCB may adopt higher security measures than its level requires, as its Board decides on its own assessment of risk and capability. And a UCB that already runs a dedicated CISO or a governance framework of the kind Chapter VI describes may continue with that structure as a matter of best practice, whatever level the criteria give it.
There is no corresponding route downwards. Nothing in the Directions lets a bank argue its way to a lower level than the criteria produce, and the criteria are factual — whether there is an application, whether there is a SWIFT interface — rather than matters of judgement.
Read next
- The seven Directions of 31 July 2026 — the family, and why five of the seven are the same instrument re-addressed.
- What the 2026 Directions ask of an NBFC — the other graded instrument, and the one that grades the other way.
- RBI/DoS/2026-27/437 — the reference record: dates, status, and the RBI’s own copy.
Level criteria, chapter applicability and section lists read from RBI/DoS/2026-27/437 on the RBI’s own notification page, issued 31 July 2026. Indicative, and not legal advice: your level, and therefore your chapters, are a determination for your compliance team.
Every instrument cited here was verified against the issuing regulator's own notification on .Questions this page answers
- How is a UCB’s level decided under the 2026 RBI Directions?
- By the digital services the bank actually offers and how it connects to the payment systems, not by asset size. Level I covers every UCB whatever it offers. Level II is a sub-member of Centralised Payment Systems that also offers internet banking, mobile banking through an application, or is a direct member of CTS, IMPS or UPI. Level III is a direct CPS member, or one running its own ATM switch or a SWIFT interface. Level IV is a CPS member or sub-member with both its own ATM switch and a SWIFT interface, or one that hosts a data centre or provides software support to other banks.
- Does a small urban co-operative bank need a CISO?
- Not at Level I. The requirement for a Chief Information Security Officer or equivalent official sits in Chapter IV, which a UCB picks up at Level II — that is, once it is a Centralised Payment Systems sub-member offering internet or mobile banking, or a direct member of CTS, IMPS or UPI. A Level I UCB owes Chapters II and III, which require a Board-approved cybersecurity policy, a cyber crisis management plan, an asset inventory and an information systems audit, but no named security officer.
- When does a UCB need a Cyber Security Operations Centre?
- At Level IV, and only at Level IV. The Cyber Security Operations Centre requirement is the first section of Chapter VI, which is the chapter a UCB attracts when it is a Centralised Payment Systems member or sub-member with both its own ATM switch and a SWIFT interface, or when it hosts a data centre or provides software support to other banks. Chapter VI also brings participation in cyber drills, metrics, forensics and a full IT governance framework.
- Are the UCB chapters cumulative or alternatives?
- Cumulative. A Level III UCB complies with Chapters II, III, IV and V together, not with Chapter V alone. This is the opposite of the NBFC Directions issued the same day, where the three obligation chapters are mutually exclusive and only one applies to any given firm — so the two instruments cannot be read using the same mental model.
- Can a UCB adopt a higher level than its category requires?
- Yes, and only in that direction. The Directions let a UCB adopt higher security measures on its Board’s own assessment of risk and capability, and a UCB that already has a dedicated CISO or a governance framework of the kind Chapter VI describes may continue with that structure as a matter of best practice, whatever its level. There is no route to a lower level than the criteria produce.