What your board actually has to approve
The documents, committees and roles your board must put in place under the RBI 2026 Directions or SEBI CSCRF, each cited to its own paragraph or standard.
Your board document register
Pick the entity, the NBFC chapter or the CSCRF category, and this lists what the instrument requires the board to approve — the documents, the committees and the named roles — with the paragraph or standard behind each row. It opens on a commercial bank, which owes the longest list.
A banking company other than a Small Finance Bank, Payments Bank or Local Area Bank, together with the corresponding new banks and the State Bank of India.
5 documents the board approves, plus 2 committees and named roles it has to put in place. Every row cites the paragraph or standard it comes from.
| Artefact | Approved by | Back before them | Clause |
|---|---|---|---|
| Strategies and policies for five named frameworks Document | The Board | At least annually | Chapter II, paragraphs 7 and 8 |
| Information Security Policy Document | The Board | At least annually | Chapter III, paragraph 14 |
| Cybersecurity Policy — a separate document Document | The Board | At least annually | Chapter III, paragraph 15 |
| IT Governance Framework Document | The Board | Periodically | Chapter III, paragraphs 11 and 12 |
| Enterprise-wide or operational risk management policy Document | The Board | Periodically | Chapter III, paragraph 13 |
| IT Strategy Committee of the Board Committee | The Board | Periodically | Chapter II paragraph 9, with composition at Chapter III paragraphs 16 to 19 |
| Audit Committee of the Board Committee | The Board | Periodically | Chapter II, paragraph 10 |
What each one has to contain
- Strategies and policies for five named frameworks. Information Technology, Information Assets, Business Continuity, Information Security and Cybersecurity — the last of which expressly includes Incident Response and Recovery Management and Cyber Crisis Management. Five frameworks, not three. Summaries of these Directions commonly report the board approving “the IT, cybersecurity and business continuity strategies”, which drops Information Assets and Information Security. Paragraph 8 then requires all of them back before the board at least annually, so an approval with no anniversary is a gap whatever the documents say.
- Information Security Policy. Objectives, scope, ownership and responsibility for the policy; the information security organisational structure; exceptions; compliance review; and penal measures for non-compliance.
- Cybersecurity Policy — a separate document. The strategy for combating cyber threats, sized to the complexity of the business and to acceptable levels of risk, duly approved by the board. Paragraph 15 requires this policy to be “distinct and separate from the broader IT policy / Information Security policy”, so that the cyber risks and the measures against them are visible on their own. One document with a security chapter in it does not satisfy it — this is two documents, and on the reading above, three.
- IT Governance Framework. The governance structure and processes needed to meet the strategic objectives; the roles and authority of the Board, its committee and senior management; and oversight mechanisms for accountability and for mitigating IT and cyber risk. Focus areas are strategic alignment, risk management, resource management, performance management and business continuity.
- Enterprise-wide or operational risk management policy. Periodic assessment of IT-related risks, both inherent and potential, incorporated into the existing risk policy rather than kept in a separate technology document.
- IT Strategy Committee of the Board. A minimum of three directors including its chairperson. A foreign bank operating through branch mode may rely on a controlling, head, regional or zonal office committee, provided the governance responsibilities are met.
- Audit Committee of the Board. Oversight of the Information Systems Audit.
Indicative, and not legal advice. RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages; CSCRF standard codes and their applicability read from SEBI’s own copy of the framework. Whether an artefact reaches your entity, and what it has to say, is a determination for your compliance and legal team.
Take this away as a print-ready board document register
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Why the cybersecurity policy is its own document
Both regimes insist on it, in almost the same words, and it is the requirement most often satisfied on paper and not in fact. Paragraph 15 of the commercial banks Directions requires a Cybersecurity Policy “distinct and separate from the broader IT policy / Information Security policy so that it can highlight the risks from cyber threats and the measures to address / mitigate these risks”. Paragraph 12 of the urban co-operative bank Directions says the same thing for a UCB.
So the minimum under RBI/DoS/2026-27/410 is three documents where an organisation usually has one: an IT policy, an Information Security Policy whose required contents are set out at paragraph 14, and a Cybersecurity Policy. A single policy with a security chapter in it does not meet any of the three.
Which ones come back, and when
4 of the 28 artefacts in this register carry an explicit interval, and every one of those is annual. 6 carry none at all, and that is a genuine difference between the instruments rather than a gap in the reading.
| Instrument | The clause | Interval |
|---|---|---|
| Commercial banks, SFBs, Payments Banks, AIFIs, CICs | Chapter II, paragraph 8 | Before the board at least annually |
| NBFCs | Chapter II, paragraph 6 | Reviewed by the board at least annually |
| Urban co-operative banks | Chapter II, paragraph 7 | No interval stated |
| SEBI CSCRF | GV.PO.S1, S2 and S5 | Reviewed periodically, with no interval fixed |
The UCB row is the one worth not smoothing over. RBI/DoS/2026-27/437 has a paragraph 7 that mirrors the commercial banks’ paragraph 7 and no counterpart of their paragraph 8, which is the one that requires annual re-approval. An annual cycle is good practice for a co-operative bank and it is not what the Directions say, and a compliance calendar that presents it as a requirement is asserting something the instrument does not.
Where each row comes from
Every RBI row cites a paragraph, read from the Directions on the RBI’s own notification pages. Every CSCRF row cites a standard code and its applicability, read from SEBI’s own copy of the framework — the PDF on the attachdocs path, which is the only place the standards tables and annexures appear. The circular’s landing page carries neither.
17 profiles are covered, and the lists genuinely differ: the longest runs to 9 artefacts and the shortest to 2. That range is the reason the tool asks which chapter or category you are in rather than which licence you hold.
- RBI/DoS/2026-27/410 — the commercial banks Directions, whose Chapters II and III set the pattern the other four uniform instruments repeat.
- RBI/DoS/2026-27/437 — the urban co-operative bank Directions, graded into four levels.
- SEBI’s own copy of CSCRF — the GV.PO and GV.RR standards, with the applicability column that decides which category owes what.
Related, and answering a different question: the board governance check asks whether the arrangements themselves — committee size, the CISO’s reporting line — would survive an inspection. A board can pass every one of those tests while owing four documents nobody has written. SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 is the reference record for the CSCRF circular itself.
RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages. CSCRF standard codes and applicability read from SEBI’s own copy of the framework. Indicative, and not legal advice: whether an artefact reaches your entity, and what it has to say, is a determination for your compliance and legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .Worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- What documents must a bank board approve under the RBI 2026 Directions?
- Paragraph 7 of Chapter II requires the board to approve the strategies and policies for five named frameworks: Information Technology, Information Assets, Business Continuity, Information Security and Cybersecurity — the last expressly including Incident Response and Recovery Management and Cyber Crisis Management. Paragraph 8 requires all of them back before the board at least annually. Chapter III then adds an Information Security Policy at paragraph 14 and a Cybersecurity Policy at paragraph 15, which must be a distinct and separate document.
- Does the cybersecurity policy have to be separate from the IT policy?
- Yes, under both regimes. Paragraph 15 of the RBI Directions requires the Cybersecurity Policy to be “distinct and separate from the broader IT policy / Information Security policy” so that cyber risks and the measures against them are visible on their own. The urban co-operative bank Directions say the same at paragraph 12. One document with a security chapter inside it does not satisfy either.
- What policy does SEBI CSCRF require a board to approve?
- A comprehensive Cybersecurity and Cyber Resilience policy document encompassing CSCRF, approved by the Board, Partners or Proprietor and reviewed by them periodically, under standards GV.PO.S1, GV.PO.S2 and GV.PO.S5. The requirement most often missed is that where the entity deviates from CSCRF, the reasons for the deviation — technical or otherwise — must be stated in the policy document itself.
- Does a small urban co-operative bank need an IT Strategy Committee?
- No. The urban co-operative bank Directions raise the committee only at Level IV, and even there paragraph 8 says the bank “may consider” setting one up, with a minimum of two directors one of whom is a professional director. That is discretionary, and it is a smaller committee than the minimum of three directors the commercial banks Directions require at Chapter III.
- Does every SEBI regulated entity need a CISO?
- No. CSCRF requires a Chief Information Security Officer reporting directly to the MD and CEO for Market Infrastructure Institutions and Qualified REs, under GV.RR.S3. Mid-size, small-size and self-certification REs designate a Designated Officer instead, with the same functions and no stated reporting line to the MD and CEO. Describing the CISO requirement as applying across CSCRF overstates it for three of the five categories.