What a Level I co-operative bank board has to approve
The documents, committees and roles your board must put in place under the RBI 2026 Directions or SEBI CSCRF, each cited to its own paragraph or standard.
Your board document register
Level I is where every urban co-operative bank starts, whatever it offers. The instrument requires a cybersecurity policy approved by the board or the Administrator, a cyber crisis management plan, and the technology and cybersecurity strategies — and, unlike the commercial banks instrument, states no interval for bringing them back.
The instrument is Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, RBI/DoS/2026-27/437. It binds: Primary Co-operative Banks under section 5(ccv) read with section 56 of the Banking Regulation Act, 1949, graded into Levels I to IV by the digital services they offer.
Every UCB is at least Level I, whatever digital services it offers. Chapters II and III apply.
3 documents the board approves, plus 0 committees and named roles it has to put in place. Every row cites the paragraph or standard it comes from.
| Artefact | Approved by | Back before them | Clause |
|---|---|---|---|
| Strategies and policies for the Technology and Cybersecurity frameworks Document | The Board | No interval stated | Chapter II, paragraph 7 |
| Cybersecurity Policy — a separate document Document | The Board, or the Administrator | No interval stated | Chapter III, paragraphs 11 and 12 |
| Cyber Crisis Management Plan Document | The Board, or the Administrator | No interval stated | Chapter III, paragraph 15 |
What each one has to contain
- Strategies and policies for the Technology and Cybersecurity frameworks. The strategies and policies related to the Technology and Cybersecurity frameworks. The UCB instrument states no review interval. Its paragraph 7 is the counterpart of the commercial banks’ paragraph 7, but there is no counterpart of their paragraph 8, which is what requires annual re-approval. An annual cycle is good practice here and is not what the Directions say.
- Cybersecurity Policy — a separate document. A suitable approach to checking cyber threats, sized to the complexity of the business and to acceptable levels of risk, covering the aspects set out at paragraphs 12 to 15 and keeping in view the technology adopted and the digital products offered to customers. Approved by the Board “or Administrator”, which is the drafting that accounts for a co-operative bank under administration. Paragraph 12 requires the policy to be distinct from the UCB’s IT and information security policy, on the same reasoning as the commercial banks instrument.
- Cyber Crisis Management Plan. A plan for detecting cyber intrusions promptly and for responding, recovering and containing the impact of an attack. CERT-In and NCIIPC guidance is named as reference material for preparing it.
Indicative, and not legal advice. RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages; CSCRF standard codes and their applicability read from SEBI’s own copy of the framework. Whether an artefact reaches your entity, and what it has to say, is a determination for your compliance and legal team.
Take this away as a print-ready board document register
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Why the cybersecurity policy is its own document
Both the RBI Directions and SEBI CSCRF require a cybersecurity policy that is distinct from the IT and information security policies, so that cyber risk is visible on its own rather than as a chapter inside something longer. That is the requirement most often satisfied on paper and not in fact, and it is the one an inspection can test by asking for the document by name.
RBI paragraph numbers read from the Directions of 31 July 2026 on the RBI’s own notification pages. CSCRF standard codes and applicability read from SEBI’s own copy of the framework. Indicative, and not legal advice.
Every instrument cited here was verified against the issuing regulator's own notification on .Other worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- What documents must a bank board approve under the RBI 2026 Directions?
- Paragraph 7 of Chapter II requires the board to approve the strategies and policies for five named frameworks: Information Technology, Information Assets, Business Continuity, Information Security and Cybersecurity — the last expressly including Incident Response and Recovery Management and Cyber Crisis Management. Paragraph 8 requires all of them back before the board at least annually. Chapter III then adds an Information Security Policy at paragraph 14 and a Cybersecurity Policy at paragraph 15, which must be a distinct and separate document.
- Does the cybersecurity policy have to be separate from the IT policy?
- Yes, under both regimes. Paragraph 15 of the RBI Directions requires the Cybersecurity Policy to be “distinct and separate from the broader IT policy / Information Security policy” so that cyber risks and the measures against them are visible on their own. The urban co-operative bank Directions say the same at paragraph 12. One document with a security chapter inside it does not satisfy either.
- What policy does SEBI CSCRF require a board to approve?
- A comprehensive Cybersecurity and Cyber Resilience policy document encompassing CSCRF, approved by the Board, Partners or Proprietor and reviewed by them periodically, under standards GV.PO.S1, GV.PO.S2 and GV.PO.S5. The requirement most often missed is that where the entity deviates from CSCRF, the reasons for the deviation — technical or otherwise — must be stated in the policy document itself.
- Does a small urban co-operative bank need an IT Strategy Committee?
- No. The urban co-operative bank Directions raise the committee only at Level IV, and even there paragraph 8 says the bank “may consider” setting one up, with a minimum of two directors one of whom is a professional director. That is discretionary, and it is a smaller committee than the minimum of three directors the commercial banks Directions require at Chapter III.
- Does every SEBI regulated entity need a CISO?
- No. CSCRF requires a Chief Information Security Officer reporting directly to the MD and CEO for Market Infrastructure Institutions and Qualified REs, under GV.RR.S3. Mid-size, small-size and self-certification REs designate a Designated Officer instead, with the same functions and no stated reporting line to the MD and CEO. Describing the CISO requirement as applying across CSCRF overstates it for three of the five categories.