Tool 6

What a commercial bank board has to approve

The documents, committees and roles your board must put in place under the RBI 2026 Directions or SEBI CSCRF, each cited to its own paragraph or standard.

In short
A board under the RBI Directions of 31 July 2026 approves the strategies and policies for five named frameworks, an Information Security Policy and a separate Cybersecurity Policy. Under SEBI CSCRF it approves a Cybersecurity and Cyber Resilience policy document that must record every deviation from the framework and the reason for it. The lists differ by NBFC chapter, by urban co-operative bank level and by CSCRF category.

Your board document register

The commercial banks instrument is the most specified of the seven. Its paragraph 7 names five frameworks rather than the three usually reported, paragraph 8 puts all of them back before the board at least annually, and paragraph 15 insists the cybersecurity policy be a document of its own.

The instrument is Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, RBI/DoS/2026-27/410. It binds: Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters.

The entity you are asking about

An NBFC and an urban co-operative bank each appear more than once, because their instruments assign obligations by layer and by level rather than by entity type. Pick the line that describes you, not the licence.

7 artefactsCommercial bank

A banking company other than a Small Finance Bank, Payments Bank or Local Area Bank, together with the corresponding new banks and the State Bank of India.

5 documents the board approves, plus 2 committees and named roles it has to put in place. Every row cites the paragraph or standard it comes from.

Board artefacts for Commercial bank, each cited to its paragraph or standard
ArtefactApproved byBack before themClause
Strategies and policies for five named frameworks
Document
The BoardAt least annuallyChapter II, paragraphs 7 and 8
Information Security Policy
Document
The BoardAt least annuallyChapter III, paragraph 14
Cybersecurity Policy — a separate document
Document
The BoardAt least annuallyChapter III, paragraph 15
IT Governance Framework
Document
The BoardPeriodicallyChapter III, paragraphs 11 and 12
Enterprise-wide or operational risk management policy
Document
The BoardPeriodicallyChapter III, paragraph 13
IT Strategy Committee of the Board
Committee
The BoardPeriodicallyChapter II paragraph 9, with composition at Chapter III paragraphs 16 to 19
Audit Committee of the Board
Committee
The BoardPeriodicallyChapter II, paragraph 10

What each one has to contain

  • Strategies and policies for five named frameworks. Information Technology, Information Assets, Business Continuity, Information Security and Cybersecurity — the last of which expressly includes Incident Response and Recovery Management and Cyber Crisis Management. Five frameworks, not three. Summaries of these Directions commonly report the board approving “the IT, cybersecurity and business continuity strategies”, which drops Information Assets and Information Security. Paragraph 8 then requires all of them back before the board at least annually, so an approval with no anniversary is a gap whatever the documents say.
  • Information Security Policy. Objectives, scope, ownership and responsibility for the policy; the information security organisational structure; exceptions; compliance review; and penal measures for non-compliance.
  • Cybersecurity Policy — a separate document. The strategy for combating cyber threats, sized to the complexity of the business and to acceptable levels of risk, duly approved by the board. Paragraph 15 requires this policy to be “distinct and separate from the broader IT policy / Information Security policy”, so that the cyber risks and the measures against them are visible on their own. One document with a security chapter in it does not satisfy it — this is two documents, and on the reading above, three.
  • IT Governance Framework. The governance structure and processes needed to meet the strategic objectives; the roles and authority of the Board, its committee and senior management; and oversight mechanisms for accountability and for mitigating IT and cyber risk. Focus areas are strategic alignment, risk management, resource management, performance management and business continuity.
  • Enterprise-wide or operational risk management policy. Periodic assessment of IT-related risks, both inherent and potential, incorporated into the existing risk policy rather than kept in a separate technology document.
  • IT Strategy Committee of the Board. A minimum of three directors including its chairperson. A foreign bank operating through branch mode may rely on a controlling, head, regional or zonal office committee, provided the governance responsibilities are met.
  • Audit Committee of the Board. Oversight of the Information Systems Audit.

Indicative, and not legal advice. RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages; CSCRF standard codes and their applicability read from SEBI’s own copy of the framework. Whether an artefact reaches your entity, and what it has to say, is a determination for your compliance and legal team.

Take this away as a print-ready board document register

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Why the cybersecurity policy is its own document

Both the RBI Directions and SEBI CSCRF require a cybersecurity policy that is distinct from the IT and information security policies, so that cyber risk is visible on its own rather than as a chapter inside something longer. That is the requirement most often satisfied on paper and not in fact, and it is the one an inspection can test by asking for the document by name.

RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages. CSCRF standard codes and applicability read from SEBI’s own copy of the framework. Indicative, and not legal advice.

Every instrument cited here was verified against the issuing regulator's own notification on .

Other worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

What documents must a bank board approve under the RBI 2026 Directions?
Paragraph 7 of Chapter II requires the board to approve the strategies and policies for five named frameworks: Information Technology, Information Assets, Business Continuity, Information Security and Cybersecurity — the last expressly including Incident Response and Recovery Management and Cyber Crisis Management. Paragraph 8 requires all of them back before the board at least annually. Chapter III then adds an Information Security Policy at paragraph 14 and a Cybersecurity Policy at paragraph 15, which must be a distinct and separate document.
Does the cybersecurity policy have to be separate from the IT policy?
Yes, under both regimes. Paragraph 15 of the RBI Directions requires the Cybersecurity Policy to be “distinct and separate from the broader IT policy / Information Security policy” so that cyber risks and the measures against them are visible on their own. The urban co-operative bank Directions say the same at paragraph 12. One document with a security chapter inside it does not satisfy either.
What policy does SEBI CSCRF require a board to approve?
A comprehensive Cybersecurity and Cyber Resilience policy document encompassing CSCRF, approved by the Board, Partners or Proprietor and reviewed by them periodically, under standards GV.PO.S1, GV.PO.S2 and GV.PO.S5. The requirement most often missed is that where the entity deviates from CSCRF, the reasons for the deviation — technical or otherwise — must be stated in the policy document itself.
Does a small urban co-operative bank need an IT Strategy Committee?
No. The urban co-operative bank Directions raise the committee only at Level IV, and even there paragraph 8 says the bank “may consider” setting one up, with a minimum of two directors one of whom is a professional director. That is discretionary, and it is a smaller committee than the minimum of three directors the commercial banks Directions require at Chapter III.
Does every SEBI regulated entity need a CISO?
No. CSCRF requires a Chief Information Security Officer reporting directly to the MD and CEO for Market Infrastructure Institutions and Qualified REs, under GV.RR.S3. Mid-size, small-size and self-certification REs designate a Designated Officer instead, with the same functions and no stated reporting line to the MD and CEO. Describing the CISO requirement as applying across CSCRF overstates it for three of the five categories.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of regmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools