What a smaller NBFC board has to approve
The documents, committees and roles your board must put in place under the RBI 2026 Directions or SEBI CSCRF, each cited to its own paragraph or standard.
Your board document register
This is the lightest chapter in the NBFC Directions, and the only one that reaches a Core Investment Company. It asks for two things from the board rather than seven, which is the point of reading the NBFC instrument rather than the banks’ one.
The instrument is Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, RBI/DoS/2026-27/461. It binds: All NBFCs registered under the RBI Act, 1934, the Factoring Regulation Act, 2011 or the National Housing Bank Act, 1987. Three obligation chapters, drafted as alternatives rather than as a ladder: Chapter III for Base Layer NBFCs below ₹500 crore of assets and for Core Investment Companies, Chapter IV for Base Layer NBFCs at ₹500 crore and above, and Chapter V for Middle Layer and above, excluding Core Investment Companies.
Chapter III of the NBFC Directions, which is the lightest of their three obligation chapters and the only one that reaches a Core Investment Company.
2 documents the board approves, plus 0 committees and named roles it has to put in place. Every row cites the paragraph or standard it comes from.
| Artefact | Approved by | Back before them | Clause |
|---|---|---|---|
| Strategies and policies for the Technology and Cybersecurity frameworks Document | The Board | At least annually | Chapter II, paragraph 6 |
| IT / Information Security policy Document | The Board | No interval stated | Chapter III, paragraph 8 |
What each one has to contain
- Strategies and policies for the Technology and Cybersecurity frameworks. The strategies and policies related to the Technology and Cybersecurity frameworks, reviewed by the board at least annually. Two named frameworks here, against five in the commercial banks instrument. The NBFC Directions are shorter and differently drafted throughout — six chapters and 158 paragraphs against eight and 233 — so a document list assembled from the banks’ instrument overstates what an NBFC owes.
- IT / Information Security policy. Basic security including physical and logical access controls and a defined password policy; well-defined user roles; the maker-checker principle; information security and cybersecurity controls; requirements for Digital Signature Certificates, Mobile Financial Services and social media; and system-generated reports summarising the financial position for senior management.
Indicative, and not legal advice. RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages; CSCRF standard codes and their applicability read from SEBI’s own copy of the framework. Whether an artefact reaches your entity, and what it has to say, is a determination for your compliance and legal team.
Take this away as a print-ready board document register
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Why the cybersecurity policy is its own document
Both the RBI Directions and SEBI CSCRF require a cybersecurity policy that is distinct from the IT and information security policies, so that cyber risk is visible on its own rather than as a chapter inside something longer. That is the requirement most often satisfied on paper and not in fact, and it is the one an inspection can test by asking for the document by name.
RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages. CSCRF standard codes and applicability read from SEBI’s own copy of the framework. Indicative, and not legal advice.
Every instrument cited here was verified against the issuing regulator's own notification on .Other worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- What documents must a bank board approve under the RBI 2026 Directions?
- Paragraph 7 of Chapter II requires the board to approve the strategies and policies for five named frameworks: Information Technology, Information Assets, Business Continuity, Information Security and Cybersecurity — the last expressly including Incident Response and Recovery Management and Cyber Crisis Management. Paragraph 8 requires all of them back before the board at least annually. Chapter III then adds an Information Security Policy at paragraph 14 and a Cybersecurity Policy at paragraph 15, which must be a distinct and separate document.
- Does the cybersecurity policy have to be separate from the IT policy?
- Yes, under both regimes. Paragraph 15 of the RBI Directions requires the Cybersecurity Policy to be “distinct and separate from the broader IT policy / Information Security policy” so that cyber risks and the measures against them are visible on their own. The urban co-operative bank Directions say the same at paragraph 12. One document with a security chapter inside it does not satisfy either.
- What policy does SEBI CSCRF require a board to approve?
- A comprehensive Cybersecurity and Cyber Resilience policy document encompassing CSCRF, approved by the Board, Partners or Proprietor and reviewed by them periodically, under standards GV.PO.S1, GV.PO.S2 and GV.PO.S5. The requirement most often missed is that where the entity deviates from CSCRF, the reasons for the deviation — technical or otherwise — must be stated in the policy document itself.
- Does a small urban co-operative bank need an IT Strategy Committee?
- No. The urban co-operative bank Directions raise the committee only at Level IV, and even there paragraph 8 says the bank “may consider” setting one up, with a minimum of two directors one of whom is a professional director. That is discretionary, and it is a smaller committee than the minimum of three directors the commercial banks Directions require at Chapter III.
- Does every SEBI regulated entity need a CISO?
- No. CSCRF requires a Chief Information Security Officer reporting directly to the MD and CEO for Market Infrastructure Institutions and Qualified REs, under GV.RR.S3. Mid-size, small-size and self-certification REs designate a Designated Officer instead, with the same functions and no stated reporting line to the MD and CEO. Describing the CISO requirement as applying across CSCRF overstates it for three of the five categories.