Tool 6

What your board actually has to approve

The documents, committees and roles your board must put in place under the RBI 2026 Directions or SEBI CSCRF, each cited to its own paragraph or standard.

In short
A board under the RBI Directions of 31 July 2026 approves the strategies and policies for five named frameworks, an Information Security Policy and a separate Cybersecurity Policy. Under SEBI CSCRF it approves a Cybersecurity and Cyber Resilience policy document that must record every deviation from the framework and the reason for it. The lists differ by NBFC chapter, by urban co-operative bank level and by CSCRF category.

Your board document register

Pick the entity, the NBFC chapter or the CSCRF category, and this lists what the instrument requires the board to approve — the documents, the committees and the named roles — with the paragraph or standard behind each row. It opens on a commercial bank, which owes the longest list.

The entity you are asking about

An NBFC and an urban co-operative bank each appear more than once, because their instruments assign obligations by layer and by level rather than by entity type. Pick the line that describes you, not the licence.

7 artefactsCommercial bank

A banking company other than a Small Finance Bank, Payments Bank or Local Area Bank, together with the corresponding new banks and the State Bank of India.

5 documents the board approves, plus 2 committees and named roles it has to put in place. Every row cites the paragraph or standard it comes from.

Board artefacts for Commercial bank, each cited to its paragraph or standard
ArtefactApproved byBack before themClause
Strategies and policies for five named frameworks
Document
The BoardAt least annuallyChapter II, paragraphs 7 and 8
Information Security Policy
Document
The BoardAt least annuallyChapter III, paragraph 14
Cybersecurity Policy — a separate document
Document
The BoardAt least annuallyChapter III, paragraph 15
IT Governance Framework
Document
The BoardPeriodicallyChapter III, paragraphs 11 and 12
Enterprise-wide or operational risk management policy
Document
The BoardPeriodicallyChapter III, paragraph 13
IT Strategy Committee of the Board
Committee
The BoardPeriodicallyChapter II paragraph 9, with composition at Chapter III paragraphs 16 to 19
Audit Committee of the Board
Committee
The BoardPeriodicallyChapter II, paragraph 10

What each one has to contain

  • Strategies and policies for five named frameworks. Information Technology, Information Assets, Business Continuity, Information Security and Cybersecurity — the last of which expressly includes Incident Response and Recovery Management and Cyber Crisis Management. Five frameworks, not three. Summaries of these Directions commonly report the board approving “the IT, cybersecurity and business continuity strategies”, which drops Information Assets and Information Security. Paragraph 8 then requires all of them back before the board at least annually, so an approval with no anniversary is a gap whatever the documents say.
  • Information Security Policy. Objectives, scope, ownership and responsibility for the policy; the information security organisational structure; exceptions; compliance review; and penal measures for non-compliance.
  • Cybersecurity Policy — a separate document. The strategy for combating cyber threats, sized to the complexity of the business and to acceptable levels of risk, duly approved by the board. Paragraph 15 requires this policy to be “distinct and separate from the broader IT policy / Information Security policy”, so that the cyber risks and the measures against them are visible on their own. One document with a security chapter in it does not satisfy it — this is two documents, and on the reading above, three.
  • IT Governance Framework. The governance structure and processes needed to meet the strategic objectives; the roles and authority of the Board, its committee and senior management; and oversight mechanisms for accountability and for mitigating IT and cyber risk. Focus areas are strategic alignment, risk management, resource management, performance management and business continuity.
  • Enterprise-wide or operational risk management policy. Periodic assessment of IT-related risks, both inherent and potential, incorporated into the existing risk policy rather than kept in a separate technology document.
  • IT Strategy Committee of the Board. A minimum of three directors including its chairperson. A foreign bank operating through branch mode may rely on a controlling, head, regional or zonal office committee, provided the governance responsibilities are met.
  • Audit Committee of the Board. Oversight of the Information Systems Audit.

Indicative, and not legal advice. RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages; CSCRF standard codes and their applicability read from SEBI’s own copy of the framework. Whether an artefact reaches your entity, and what it has to say, is a determination for your compliance and legal team.

Take this away as a print-ready board document register

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Why the cybersecurity policy is its own document

Both regimes insist on it, in almost the same words, and it is the requirement most often satisfied on paper and not in fact. Paragraph 15 of the commercial banks Directions requires a Cybersecurity Policy “distinct and separate from the broader IT policy / Information Security policy so that it can highlight the risks from cyber threats and the measures to address / mitigate these risks”. Paragraph 12 of the urban co-operative bank Directions says the same thing for a UCB.

So the minimum under RBI/DoS/2026-27/410 is three documents where an organisation usually has one: an IT policy, an Information Security Policy whose required contents are set out at paragraph 14, and a Cybersecurity Policy. A single policy with a security chapter in it does not meet any of the three.

Which ones come back, and when

4 of the 28 artefacts in this register carry an explicit interval, and every one of those is annual. 6 carry none at all, and that is a genuine difference between the instruments rather than a gap in the reading.

InstrumentThe clauseInterval
Commercial banks, SFBs, Payments Banks, AIFIs, CICsChapter II, paragraph 8Before the board at least annually
NBFCsChapter II, paragraph 6Reviewed by the board at least annually
Urban co-operative banksChapter II, paragraph 7No interval stated
SEBI CSCRFGV.PO.S1, S2 and S5Reviewed periodically, with no interval fixed
Where the instruments state a review interval, and where they do not.

The UCB row is the one worth not smoothing over. RBI/DoS/2026-27/437 has a paragraph 7 that mirrors the commercial banks’ paragraph 7 and no counterpart of their paragraph 8, which is the one that requires annual re-approval. An annual cycle is good practice for a co-operative bank and it is not what the Directions say, and a compliance calendar that presents it as a requirement is asserting something the instrument does not.

Where each row comes from

Every RBI row cites a paragraph, read from the Directions on the RBI’s own notification pages. Every CSCRF row cites a standard code and its applicability, read from SEBI’s own copy of the framework — the PDF on the attachdocs path, which is the only place the standards tables and annexures appear. The circular’s landing page carries neither.

17 profiles are covered, and the lists genuinely differ: the longest runs to 9 artefacts and the shortest to 2. That range is the reason the tool asks which chapter or category you are in rather than which licence you hold.

  • RBI/DoS/2026-27/410 — the commercial banks Directions, whose Chapters II and III set the pattern the other four uniform instruments repeat.
  • RBI/DoS/2026-27/437 — the urban co-operative bank Directions, graded into four levels.
  • SEBI’s own copy of CSCRF — the GV.PO and GV.RR standards, with the applicability column that decides which category owes what.

Related, and answering a different question: the board governance check asks whether the arrangements themselves — committee size, the CISO’s reporting line — would survive an inspection. A board can pass every one of those tests while owing four documents nobody has written. SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 is the reference record for the CSCRF circular itself.

RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages. CSCRF standard codes and applicability read from SEBI’s own copy of the framework. Indicative, and not legal advice: whether an artefact reaches your entity, and what it has to say, is a determination for your compliance and legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

What documents must a bank board approve under the RBI 2026 Directions?
Paragraph 7 of Chapter II requires the board to approve the strategies and policies for five named frameworks: Information Technology, Information Assets, Business Continuity, Information Security and Cybersecurity — the last expressly including Incident Response and Recovery Management and Cyber Crisis Management. Paragraph 8 requires all of them back before the board at least annually. Chapter III then adds an Information Security Policy at paragraph 14 and a Cybersecurity Policy at paragraph 15, which must be a distinct and separate document.
Does the cybersecurity policy have to be separate from the IT policy?
Yes, under both regimes. Paragraph 15 of the RBI Directions requires the Cybersecurity Policy to be “distinct and separate from the broader IT policy / Information Security policy” so that cyber risks and the measures against them are visible on their own. The urban co-operative bank Directions say the same at paragraph 12. One document with a security chapter inside it does not satisfy either.
What policy does SEBI CSCRF require a board to approve?
A comprehensive Cybersecurity and Cyber Resilience policy document encompassing CSCRF, approved by the Board, Partners or Proprietor and reviewed by them periodically, under standards GV.PO.S1, GV.PO.S2 and GV.PO.S5. The requirement most often missed is that where the entity deviates from CSCRF, the reasons for the deviation — technical or otherwise — must be stated in the policy document itself.
Does a small urban co-operative bank need an IT Strategy Committee?
No. The urban co-operative bank Directions raise the committee only at Level IV, and even there paragraph 8 says the bank “may consider” setting one up, with a minimum of two directors one of whom is a professional director. That is discretionary, and it is a smaller committee than the minimum of three directors the commercial banks Directions require at Chapter III.
Does every SEBI regulated entity need a CISO?
No. CSCRF requires a Chief Information Security Officer reporting directly to the MD and CEO for Market Infrastructure Institutions and Qualified REs, under GV.RR.S3. Mid-size, small-size and self-certification REs designate a Designated Officer instead, with the same functions and no stated reporting line to the MD and CEO. Describing the CISO requirement as applying across CSCRF overstates it for three of the five categories.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of regmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools