Board cyber governance for a commercial bank
The eleven board provisions in Chapter II of the RBI Directions of 31 July 2026, as tests answerable from an organisation chart and a board calendar — committee composition, the CISO’s reporting line, and what the board pack has to carry.
What this case turns on
The Commercial Banks Directions define their own scope by exclusion — banking companies other than Small Finance Banks, Payments Banks and Local Area Banks — and the first two are excluded because each has its own instrument in the family. Foreign banks operating through branches follow a comply-or-explain approach on selected provisions, which is a different obligation from the one below rather than a lighter version of it.
The instrument is Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, RBI/DoS/2026-27/410, issued 31 July 2026. It binds: Banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, together with corresponding new banks and the State Bank of India. Foreign banks operating through branches follow comply-or-explain on selected chapters.
| The provision | What a gap means |
|---|---|
| Annual board approval of the three strategies | The Directions make this a recurring agenda item rather than a one-time adoption, so an approval with no anniversary is a gap even where the strategy itself is sound. It is also the cheapest of these to fix: it is a line on next year’s board calendar. |
| IT Strategy Committee of at least three directors | A committee below three directors does not meet the composition the Directions specify, whatever its agenda covers. |
| ITSC chaired by an independent director with substantial IT expertise | The Directions define substantial expertise as a minimum of seven years managing information systems. That makes it a composition test a board either passes or does not — and one that is answered from an appointment record rather than from an opinion. Boards that satisfy it in substance frequently cannot evidence it, which fails the same way. |
| The provision | What a gap means |
|---|---|
| A CISO of sufficient seniority | The Directions state a preference for General Manager rank or equivalent. Rank here is a proxy for standing: a CISO who cannot convene the people whose plans the risk affects is escalating rather than deciding. |
| The CISO’s reporting line | A CISO reporting into the IT function reports to the person whose delivery timetable the risk inconveniences. Separating the two is the entire purpose of the provision, and unlike most of what a board assures, it is visible from an organisation chart — which means it is visible to an inspector on day one. |
| The provision | What a gap means |
|---|---|
| A cybersecurity policy separate from the IT policy | The Directions require two documents rather than one policy with a security section. The distinction is not cosmetic: it decides what the board is approving, what the auditor is auditing against, and whether security changes can be made without reopening the IT policy. |
| IS Audit under Audit Committee oversight | The Directions place the function under the Audit Committee and require the plan to be built on risk rather than on a fixed rotation. An IS Audit reporting into IT management is assurance over itself. |
| Continuous auditing of critical systems | The Directions expect continuous auditing of critical systems where practicable, rather than an annual sample. "Where practicable" is doing real work in that sentence, but it is an argument to make in the audit plan, not one to leave unmade. |
| The provision | What a gap means |
|---|---|
| Half-yearly DR drills for critical systems | Half-yearly is the expectation for critical systems, with recovery objectives set close to zero. This is a commitment about capability rather than paperwork, and it is not one that can be assembled after the incident that tests it. |
| The six-hour DAKSH filing, owned and rehearsed | Six hours from detection is not long enough to work out who files. It is also not the only clock running — CERT-In’s six hours run in parallel from a different starting point, and a listed entity owes the exchanges a disclosure at twelve. |
| A measurement in the board pack, not an assurance | "The CISO reported no significant issues" is a weaker minute than it used to be. Periodic review implies something to review — a number that moves, that the board can ask about, and that a supervisor can ask the board what it did about. An assurance can only be accepted or doubted. |
Answer them for your own board
The tool below opens on this entity class. Tick what you can evidence today to see what is outstanding, and take the result away as an annexure your board can table.
Your class files under RBI/DoS/2026-27/410, the Commercial Banks Directions — one of seven issued on 31 July 2026, one per entity class. Citing the wrong one in a supervisory response is an avoidable own goal.
Board and committee composition
- Gap
Annual board approval of the three strategies
The Directions make this a recurring agenda item rather than a one-time adoption, so an approval with no anniversary is a gap even where the strategy itself is sound. It is also the cheapest of these to fix: it is a line on next year’s board calendar.
RBI/DoS/2026-27/410 — Chapter II - Gap
ITSC chaired by an independent director with substantial IT expertise
The Directions define substantial expertise as a minimum of seven years managing information systems. That makes it a composition test a board either passes or does not — and one that is answered from an appointment record rather than from an opinion. Boards that satisfy it in substance frequently cannot evidence it, which fails the same way.
RBI/DoS/2026-27/410 — Chapter II - Met
IT Strategy Committee of at least three directors
The CISO
- Gap
The CISO’s reporting line
A CISO reporting into the IT function reports to the person whose delivery timetable the risk inconveniences. Separating the two is the entire purpose of the provision, and unlike most of what a board assures, it is visible from an organisation chart — which means it is visible to an inspector on day one.
RBI/DoS/2026-27/410 — Chapter II - Met
A CISO of sufficient seniority
Policy and assurance
- Gap
A cybersecurity policy separate from the IT policy
The Directions require two documents rather than one policy with a security section. The distinction is not cosmetic: it decides what the board is approving, what the auditor is auditing against, and whether security changes can be made without reopening the IT policy.
RBI/DoS/2026-27/410 — Chapter II - Met
IS Audit under Audit Committee oversight
- Met
Continuous auditing of critical systems
The capability the board is assuring
- Gap
Half-yearly DR drills for critical systems
Half-yearly is the expectation for critical systems, with recovery objectives set close to zero. This is a commitment about capability rather than paperwork, and it is not one that can be assembled after the incident that tests it.
RBI/DoS/2026-27/410 — Chapter II and the operational chapters - Gap
A measurement in the board pack, not an assurance
"The CISO reported no significant issues" is a weaker minute than it used to be. Periodic review implies something to review — a number that moves, that the board can ask about, and that a supervisor can ask the board what it did about. An assurance can only be accepted or doubted.
RBI/DoS/2026-27/410 — Chapter II - Met
The six-hour DAKSH filing, owned and rehearsed
What does not apply to you
- Insurers and insurance intermediaries: The CISO must not report to the Head of IT and must not carry business targets. IRDAI reissued its Information and Cyber Security Guidelines on 6 April 2026, and for a board the sharpest provision is structural rather than technical. Like the RBI reporting-line test above, it is answered from an organisation chart.
- SEBI regulated entities: Compliance is reported in CSCRF’s prescribed formats. Where a regulator prescribes the shape of the evidence, an internal narrative stops being a substitute for it. The Cyber Capability Index binds Market Infrastructure Institutions and Qualified REs only.
Take this away as a print-ready board annexure
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
For every other entity class, what changed for directors in 2026, and what counts as evidence, see the full board governance check.
Indicative, and not legal advice. Whether a provision is satisfied in your case is a determination for your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .
Other worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- What does the RBI require of a bank’s board on cyber security?
- Chapter II of the 2026 Directions names the obligations rather than implying them: annual board approval of the IT, cybersecurity and business continuity strategies; an IT Strategy Committee of at least three directors chaired by an independent director with substantial IT expertise; a senior CISO reporting to the Executive Director or equivalent overseeing risk management; a cybersecurity policy distinct from the IT policy; and an Information Systems Audit function under Audit Committee oversight.
- Can the CISO report to the Head of IT?
- Not under either instrument that addresses it. The RBI Directions require the CISO to report directly to the Executive Director or equivalent overseeing risk management, and the IRDAI Information and Cyber Security Guidelines, 2026 state that an insurer’s CISO must not report to the Head of IT and must not carry business targets. The provision separates the person raising the risk from the person whose delivery timetable it inconveniences, and it is visible from an organisation chart.
- What counts as substantial IT expertise for an ITSC chair?
- The Directions define it as a minimum of seven years managing information systems, and require the chair to be an independent director. That turns a judgement into a composition test a board either passes or does not. Boards that satisfy it in substance often cannot evidence it from the appointment record, which fails in the same way as not satisfying it.
- Does a cybersecurity policy have to be separate from the IT policy?
- Yes. The Directions require two documents rather than one policy with a security section. The distinction decides what the board is approving, what the Information Systems Audit function is auditing against, and whether a security change can be made without reopening the IT policy.
- Which RBI instrument sets the board obligations for an NBFC?
- RBI/DoS/2026-27/461, the Non-Banking Financial Companies Directions — not the Commercial Banks Directions at 410. Seven parallel instruments were issued on 31 July 2026, one per entity class. The Chapter II board provisions do not vary between them, but the citation does, and citing the wrong one in a supervisory response is an avoidable own goal.
- Do the 2026 cyber Directions apply to Regional Rural Banks?
- No. Regional Rural Banks and Local Area Banks have no instrument in the 2026 cyber family at all. The Commercial Banks Directions must not be stretched to cover either — that instrument defines itself as applying to banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, and a Regional Rural Bank is not within the definition. Local Area Banks separately received Supervisory Directions of their own on the same day.