Tool 5

What cyber governance does a Regional Rural Bank owe?

The eleven board provisions in Chapter II of the RBI Directions of 31 July 2026, as tests answerable from an organisation chart and a board calendar — committee composition, the CISO’s reporting line, and what the board pack has to carry.

In short
The RBI Directions of 31 July 2026 specify board cyber obligations rather than implying them. An IT Strategy Committee needs at least three directors chaired by an independent director with seven years managing information systems; the CISO reports to the Executive Director overseeing risk, not to IT; the cybersecurity policy is a document separate from the IT policy. Each is a test a board passes or fails.

What this case turns on

This page returns no checklist, which is the answer rather than a failure of one. Regional Rural Banks have no instrument in the 2026 cyber family, and neither do Local Area Banks — the latter received (Local Area Banks – Miscellaneous) Supervisory Directions, 2026 on the same day, which is a different instrument and is not interchangeable with it. Applying Chapter II to an RRB anyway would invent an obligation, which is the mirror image of missing one.

No instrument in the 2026 cyber family binds this class. Regional Rural Banks have no instrument in the 2026 cyber family. Do not stretch the Commercial Banks Directions to cover one — its own scope clause is "banking companies (other than Small Finance Banks, Payments Banks, and Local Area Banks)", and an RRB is not within it.

What the tool returns for this class

Your entity
0instruments in the 2026 cyber family bind a regional rural bank.

Regional Rural Banks have no instrument in the 2026 cyber family. Do not stretch the Commercial Banks Directions to cover one — its own scope clause is "banking companies (other than Small Finance Banks, Payments Banks, and Local Area Banks)", and an RRB is not within it.

For every other entity class, what changed for directors in 2026, and what counts as evidence, see the full board governance check.

Indicative, and not legal advice. Whether a provision is satisfied in your case is a determination for your compliance and legal team. Every instrument cited here was verified against the issuing regulator's own notification on .

Other worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

What does the RBI require of a bank’s board on cyber security?
Chapter II of the 2026 Directions names the obligations rather than implying them: annual board approval of the IT, cybersecurity and business continuity strategies; an IT Strategy Committee of at least three directors chaired by an independent director with substantial IT expertise; a senior CISO reporting to the Executive Director or equivalent overseeing risk management; a cybersecurity policy distinct from the IT policy; and an Information Systems Audit function under Audit Committee oversight.
Can the CISO report to the Head of IT?
Not under either instrument that addresses it. The RBI Directions require the CISO to report directly to the Executive Director or equivalent overseeing risk management, and the IRDAI Information and Cyber Security Guidelines, 2026 state that an insurer’s CISO must not report to the Head of IT and must not carry business targets. The provision separates the person raising the risk from the person whose delivery timetable it inconveniences, and it is visible from an organisation chart.
What counts as substantial IT expertise for an ITSC chair?
The Directions define it as a minimum of seven years managing information systems, and require the chair to be an independent director. That turns a judgement into a composition test a board either passes or does not. Boards that satisfy it in substance often cannot evidence it from the appointment record, which fails in the same way as not satisfying it.
Does a cybersecurity policy have to be separate from the IT policy?
Yes. The Directions require two documents rather than one policy with a security section. The distinction decides what the board is approving, what the Information Systems Audit function is auditing against, and whether a security change can be made without reopening the IT policy.
Which RBI instrument sets the board obligations for an NBFC?
RBI/DoS/2026-27/461, the Non-Banking Financial Companies Directions — not the Commercial Banks Directions at 410. Seven parallel instruments were issued on 31 July 2026, one per entity class. The Chapter II board provisions do not vary between them, but the citation does, and citing the wrong one in a supervisory response is an avoidable own goal.
Do the 2026 cyber Directions apply to Regional Rural Banks?
No. Regional Rural Banks and Local Area Banks have no instrument in the 2026 cyber family at all. The Commercial Banks Directions must not be stretched to cover either — that instrument defines itself as applying to banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, and a Regional Rural Bank is not within the definition. Local Area Banks separately received Supervisory Directions of their own on the same day.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of regmap, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools