Tool 5

Would your board’s cyber governance survive an inspection?

The eleven board provisions in Chapter II of the RBI Directions of 31 July 2026, as tests answerable from an organisation chart and a board calendar — committee composition, the CISO’s reporting line, and what the board pack has to carry.

In short
The RBI Directions of 31 July 2026 specify board cyber obligations rather than implying them. An IT Strategy Committee needs at least three directors chaired by an independent director with seven years managing information systems; the CISO reports to the Executive Director overseeing risk, not to IT; the cybersecurity policy is a document separate from the IT policy. Each is a test a board passes or fails.

Check your governance

Every question below is answerable yes or no from a document that already exists — an organisation chart, a board calendar, a policy index. None of them needs an assessment or a maturity score, and that is the point: these are the provisions checkable from outside the security function, which makes them the ones a supervisor reaches for first.

The tool opens on the shape of an entity that was compliant with the 2016 Cyber Security Framework and has not yet moved. The structural furniture is there and what is missing is specifically what 2026 added or sharpened. Change the answers to yours.

Your entity
What you can evidence today
6gaps across 11 tests, for a commercial bank.

Your class files under RBI/DoS/2026-27/410, the Commercial Banks Directions — one of seven issued on 31 July 2026, one per entity class. Citing the wrong one in a supervisory response is an avoidable own goal.

Board and committee composition

  • Gap
    Annual board approval of the three strategies

    The Directions make this a recurring agenda item rather than a one-time adoption, so an approval with no anniversary is a gap even where the strategy itself is sound. It is also the cheapest of these to fix: it is a line on next year’s board calendar.

    RBI/DoS/2026-27/410Chapter II
  • Gap
    ITSC chaired by an independent director with substantial IT expertise

    The Directions define substantial expertise as a minimum of seven years managing information systems. That makes it a composition test a board either passes or does not — and one that is answered from an appointment record rather than from an opinion. Boards that satisfy it in substance frequently cannot evidence it, which fails the same way.

    RBI/DoS/2026-27/410Chapter II
  • Met
    IT Strategy Committee of at least three directors

The CISO

  • Gap
    The CISO’s reporting line

    A CISO reporting into the IT function reports to the person whose delivery timetable the risk inconveniences. Separating the two is the entire purpose of the provision, and unlike most of what a board assures, it is visible from an organisation chart — which means it is visible to an inspector on day one.

    RBI/DoS/2026-27/410Chapter II
  • Met
    A CISO of sufficient seniority

Policy and assurance

  • Gap
    A cybersecurity policy separate from the IT policy

    The Directions require two documents rather than one policy with a security section. The distinction is not cosmetic: it decides what the board is approving, what the auditor is auditing against, and whether security changes can be made without reopening the IT policy.

    RBI/DoS/2026-27/410Chapter II
  • Met
    IS Audit under Audit Committee oversight
  • Met
    Continuous auditing of critical systems

The capability the board is assuring

  • Gap
    Half-yearly DR drills for critical systems

    Half-yearly is the expectation for critical systems, with recovery objectives set close to zero. This is a commitment about capability rather than paperwork, and it is not one that can be assembled after the incident that tests it.

    RBI/DoS/2026-27/410Chapter II and the operational chapters
  • Gap
    A measurement in the board pack, not an assurance

    "The CISO reported no significant issues" is a weaker minute than it used to be. Periodic review implies something to review — a number that moves, that the board can ask about, and that a supervisor can ask the board what it did about. An assurance can only be accepted or doubted.

    RBI/DoS/2026-27/410Chapter II
  • Met
    The six-hour DAKSH filing, owned and rehearsed

What does not apply to you

  • Insurers and insurance intermediaries: The CISO must not report to the Head of IT and must not carry business targets. IRDAI reissued its Information and Cyber Security Guidelines on 6 April 2026, and for a board the sharpest provision is structural rather than technical. Like the RBI reporting-line test above, it is answered from an organisation chart.
  • SEBI regulated entities: Compliance is reported in CSCRF’s prescribed formats. Where a regulator prescribes the shape of the evidence, an internal narrative stops being a substitute for it. The Cyber Capability Index binds Market Infrastructure Institutions and Qualified REs only.

Take this away as a print-ready board annexure

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

What changed for directors

On 31 July 2026 the RBI issued not one instrument but seven, all carrying the same title and all in force immediately. One binds each class of regulated entity, and all seven repeal the earlier cybersecurity and IT-governance instructions for the classes they cover through the same covering circular of that date, DoS.CO.PPG.66/11.01.005/2026-27.

The Directions run to eight chapters and the second is titled for the board. Its significance is not that boards acquired responsibility for cyber security — they already had it — but that the obligations are now specified rather than implied. A committee size, a chair's years of experience, a reporting line and a document count are all things an inspector can check without forming a view about whether your security is any good.

What counts as evidence

Several of these tests are failed by entities that satisfy them in substance. An ITSC chair with a career in information systems still fails the seven-year test if the appointment record does not show it; a CISO who in practice raises risk directly with the board still fails the reporting-line test if the chart routes them through IT. The provisions are drafted to be checkable, and checkable means evidenced.

Beneath the board chapter sits the machinery that has to exist for the board's assurance to mean anything — asset inventory with criticality classification, patch management, multi-factor authentication, data loss prevention, and a Cyber Security Operations Centre monitoring round the clock. Two timings deserve a director's attention directly: cyber incidents reported within six hours of detection on DAKSH, and disaster recovery drills half-yearly for critical systems with recovery objectives close to zero. Both are commitments about capability rather than paperwork, and neither can be assembled after the incident that tests them.

The minute that no longer works

“The CISO reported no significant issues” is a weaker minute than it used to be. Periodic review implies something to review: a measurement that changes between meetings, that the board can interrogate, and that a supervisor can ask the board what it did about. An assurance can only be accepted or doubted, which is why a board that receives nothing else has no way to demonstrate oversight rather than assert it.

This tool tells you what the instrument requires of your board. It cannot tell you what an attacker already sees, which is the other half of the same conversation — and the half that produces a number that moves. For the full chapter-by-chapter reading of the Directions see which of the seven applies to you, and for what boards must evidence across all four regulators, RBI cyber security compliance for boards.

Indicative, and not legal advice. Whether a provision is satisfied in your case is a determination for your compliance and legal team. The tests above are drawn from Chapter II and the operational chapters of the 2026 Directions; they are cited at chapter level because that is what has been read at source, and a paragraph number nobody has checked would be worth less than no citation at all. Every instrument cited here was verified against the issuing regulator's own notification on .

Worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

What does the RBI require of a bank’s board on cyber security?
Chapter II of the 2026 Directions names the obligations rather than implying them: annual board approval of the IT, cybersecurity and business continuity strategies; an IT Strategy Committee of at least three directors chaired by an independent director with substantial IT expertise; a senior CISO reporting to the Executive Director or equivalent overseeing risk management; a cybersecurity policy distinct from the IT policy; and an Information Systems Audit function under Audit Committee oversight.
Can the CISO report to the Head of IT?
Not under either instrument that addresses it. The RBI Directions require the CISO to report directly to the Executive Director or equivalent overseeing risk management, and the IRDAI Information and Cyber Security Guidelines, 2026 state that an insurer’s CISO must not report to the Head of IT and must not carry business targets. The provision separates the person raising the risk from the person whose delivery timetable it inconveniences, and it is visible from an organisation chart.
What counts as substantial IT expertise for an ITSC chair?
The Directions define it as a minimum of seven years managing information systems, and require the chair to be an independent director. That turns a judgement into a composition test a board either passes or does not. Boards that satisfy it in substance often cannot evidence it from the appointment record, which fails in the same way as not satisfying it.
Does a cybersecurity policy have to be separate from the IT policy?
Yes. The Directions require two documents rather than one policy with a security section. The distinction decides what the board is approving, what the Information Systems Audit function is auditing against, and whether a security change can be made without reopening the IT policy.
Which RBI instrument sets the board obligations for an NBFC?
RBI/DoS/2026-27/461, the Non-Banking Financial Companies Directions — not the Commercial Banks Directions at 410. Seven parallel instruments were issued on 31 July 2026, one per entity class. The Chapter II board provisions do not vary between them, but the citation does, and citing the wrong one in a supervisory response is an avoidable own goal.
Do the 2026 cyber Directions apply to Regional Rural Banks?
No. Regional Rural Banks and Local Area Banks have no instrument in the 2026 cyber family at all. The Commercial Banks Directions must not be stretched to cover either — that instrument defines itself as applying to banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, and a Regional Rural Bank is not within the definition. Local Area Banks separately received Supervisory Directions of their own on the same day.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of regmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools