Tool 5

Board cyber governance for an NBFC

The eleven board provisions in Chapter II of the RBI Directions of 31 July 2026, as tests answerable from an organisation chart and a board calendar — committee composition, the CISO’s reporting line, and what the board pack has to carry.

In short
The RBI Directions of 31 July 2026 specify board cyber obligations rather than implying them. An IT Strategy Committee needs at least three directors chaired by an independent director with seven years managing information systems; the CISO reports to the Executive Director overseeing risk, not to IT; the cybersecurity policy is a document separate from the IT policy. Each is a test a board passes or fails.

What this case turns on

An NBFC files under RBI/DoS/2026-27/461, and reaching for the Commercial Banks Directions at 410 is the most common citation error in this area. The board provisions themselves do not vary by scale-based layer, but much of what sits beneath them does: the chapters are graded, and a Base Layer NBFC below ₹500 crore carries obligations that a Middle, Upper or Top Layer NBFC does not recognise as its own.

The instrument is Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, RBI/DoS/2026-27/461, issued 31 July 2026. It binds: All NBFCs, with chapters applying by scale-based layer — Base, Middle, Upper and Top — and to Core Investment Companies.

The provisionWhat a gap means
Annual board approval of the three strategiesThe Directions make this a recurring agenda item rather than a one-time adoption, so an approval with no anniversary is a gap even where the strategy itself is sound. It is also the cheapest of these to fix: it is a line on next year’s board calendar.
IT Strategy Committee of at least three directorsA committee below three directors does not meet the composition the Directions specify, whatever its agenda covers.
ITSC chaired by an independent director with substantial IT expertiseThe Directions define substantial expertise as a minimum of seven years managing information systems. That makes it a composition test a board either passes or does not — and one that is answered from an appointment record rather than from an opinion. Boards that satisfy it in substance frequently cannot evidence it, which fails the same way.
Board and committee composition
The provisionWhat a gap means
A CISO of sufficient seniorityThe Directions state a preference for General Manager rank or equivalent. Rank here is a proxy for standing: a CISO who cannot convene the people whose plans the risk affects is escalating rather than deciding.
The CISO’s reporting lineA CISO reporting into the IT function reports to the person whose delivery timetable the risk inconveniences. Separating the two is the entire purpose of the provision, and unlike most of what a board assures, it is visible from an organisation chart — which means it is visible to an inspector on day one.
The CISO
The provisionWhat a gap means
A cybersecurity policy separate from the IT policyThe Directions require two documents rather than one policy with a security section. The distinction is not cosmetic: it decides what the board is approving, what the auditor is auditing against, and whether security changes can be made without reopening the IT policy.
IS Audit under Audit Committee oversightThe Directions place the function under the Audit Committee and require the plan to be built on risk rather than on a fixed rotation. An IS Audit reporting into IT management is assurance over itself.
Continuous auditing of critical systemsThe Directions expect continuous auditing of critical systems where practicable, rather than an annual sample. "Where practicable" is doing real work in that sentence, but it is an argument to make in the audit plan, not one to leave unmade.
Policy and assurance
The provisionWhat a gap means
Half-yearly DR drills for critical systemsHalf-yearly is the expectation for critical systems, with recovery objectives set close to zero. This is a commitment about capability rather than paperwork, and it is not one that can be assembled after the incident that tests it.
The six-hour DAKSH filing, owned and rehearsedSix hours from detection is not long enough to work out who files. It is also not the only clock running — CERT-In’s six hours run in parallel from a different starting point, and a listed entity owes the exchanges a disclosure at twelve.
A measurement in the board pack, not an assurance"The CISO reported no significant issues" is a weaker minute than it used to be. Periodic review implies something to review — a number that moves, that the board can ask about, and that a supervisor can ask the board what it did about. An assurance can only be accepted or doubted.
The capability the board is assuring

Answer them for your own board

The tool below opens on this entity class. Tick what you can evidence today to see what is outstanding, and take the result away as an annexure your board can table.

Your entity
What you can evidence today
6gaps across 11 tests, for a non-banking financial company.

Your class files under RBI/DoS/2026-27/461, the Non-Banking Financial Companies Directions — one of seven issued on 31 July 2026, one per entity class. Citing the wrong one in a supervisory response is an avoidable own goal.

Board and committee composition

  • Gap
    Annual board approval of the three strategies

    The Directions make this a recurring agenda item rather than a one-time adoption, so an approval with no anniversary is a gap even where the strategy itself is sound. It is also the cheapest of these to fix: it is a line on next year’s board calendar.

    RBI/DoS/2026-27/461Chapter II
  • Gap
    ITSC chaired by an independent director with substantial IT expertise

    The Directions define substantial expertise as a minimum of seven years managing information systems. That makes it a composition test a board either passes or does not — and one that is answered from an appointment record rather than from an opinion. Boards that satisfy it in substance frequently cannot evidence it, which fails the same way.

    RBI/DoS/2026-27/461Chapter II
  • Met
    IT Strategy Committee of at least three directors

The CISO

  • Gap
    The CISO’s reporting line

    A CISO reporting into the IT function reports to the person whose delivery timetable the risk inconveniences. Separating the two is the entire purpose of the provision, and unlike most of what a board assures, it is visible from an organisation chart — which means it is visible to an inspector on day one.

    RBI/DoS/2026-27/461Chapter II
  • Met
    A CISO of sufficient seniority

Policy and assurance

  • Gap
    A cybersecurity policy separate from the IT policy

    The Directions require two documents rather than one policy with a security section. The distinction is not cosmetic: it decides what the board is approving, what the auditor is auditing against, and whether security changes can be made without reopening the IT policy.

    RBI/DoS/2026-27/461Chapter II
  • Met
    IS Audit under Audit Committee oversight
  • Met
    Continuous auditing of critical systems

The capability the board is assuring

  • Gap
    Half-yearly DR drills for critical systems

    Half-yearly is the expectation for critical systems, with recovery objectives set close to zero. This is a commitment about capability rather than paperwork, and it is not one that can be assembled after the incident that tests it.

    RBI/DoS/2026-27/461Chapter II and the operational chapters
  • Gap
    A measurement in the board pack, not an assurance

    "The CISO reported no significant issues" is a weaker minute than it used to be. Periodic review implies something to review — a number that moves, that the board can ask about, and that a supervisor can ask the board what it did about. An assurance can only be accepted or doubted.

    RBI/DoS/2026-27/461Chapter II
  • Met
    The six-hour DAKSH filing, owned and rehearsed

What does not apply to you

  • Insurers and insurance intermediaries: The CISO must not report to the Head of IT and must not carry business targets. IRDAI reissued its Information and Cyber Security Guidelines on 6 April 2026, and for a board the sharpest provision is structural rather than technical. Like the RBI reporting-line test above, it is answered from an organisation chart.
  • SEBI regulated entities: Compliance is reported in CSCRF’s prescribed formats. Where a regulator prescribes the shape of the evidence, an internal narrative stops being a substitute for it. The Cyber Capability Index binds Market Infrastructure Institutions and Qualified REs only.

Take this away as a print-ready board annexure

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

For every other entity class, what changed for directors in 2026, and what counts as evidence, see the full board governance check.

Indicative, and not legal advice. Whether a provision is satisfied in your case is a determination for your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .

Other worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

What does the RBI require of a bank’s board on cyber security?
Chapter II of the 2026 Directions names the obligations rather than implying them: annual board approval of the IT, cybersecurity and business continuity strategies; an IT Strategy Committee of at least three directors chaired by an independent director with substantial IT expertise; a senior CISO reporting to the Executive Director or equivalent overseeing risk management; a cybersecurity policy distinct from the IT policy; and an Information Systems Audit function under Audit Committee oversight.
Can the CISO report to the Head of IT?
Not under either instrument that addresses it. The RBI Directions require the CISO to report directly to the Executive Director or equivalent overseeing risk management, and the IRDAI Information and Cyber Security Guidelines, 2026 state that an insurer’s CISO must not report to the Head of IT and must not carry business targets. The provision separates the person raising the risk from the person whose delivery timetable it inconveniences, and it is visible from an organisation chart.
What counts as substantial IT expertise for an ITSC chair?
The Directions define it as a minimum of seven years managing information systems, and require the chair to be an independent director. That turns a judgement into a composition test a board either passes or does not. Boards that satisfy it in substance often cannot evidence it from the appointment record, which fails in the same way as not satisfying it.
Does a cybersecurity policy have to be separate from the IT policy?
Yes. The Directions require two documents rather than one policy with a security section. The distinction decides what the board is approving, what the Information Systems Audit function is auditing against, and whether a security change can be made without reopening the IT policy.
Which RBI instrument sets the board obligations for an NBFC?
RBI/DoS/2026-27/461, the Non-Banking Financial Companies Directions — not the Commercial Banks Directions at 410. Seven parallel instruments were issued on 31 July 2026, one per entity class. The Chapter II board provisions do not vary between them, but the citation does, and citing the wrong one in a supervisory response is an avoidable own goal.
Do the 2026 cyber Directions apply to Regional Rural Banks?
No. Regional Rural Banks and Local Area Banks have no instrument in the 2026 cyber family at all. The Commercial Banks Directions must not be stretched to cover either — that instrument defines itself as applying to banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, and a Regional Rural Bank is not within the definition. Local Area Banks separately received Supervisory Directions of their own on the same day.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of regmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools