Board-Level Governance And Accountability. One Platform Underneath.

RBI's 2024 Master Directions on IT Governance, Risk, Controls and Assurance Practices consolidated and updated a decade of earlier circulars into one standard covering scheduled commercial banks, cooperative banks, NBFCs, and payment system operators. The headline shift: RBI has been explicit that cybersecurity is a board-level concern, not a CIO problem.

Board-level IT governance is now mandatory, with a dedicated IT Strategy Committee at Board level, and the IT Risk Framework itself must be Board-approved, not just signed off by senior management. A Cyber Crisis Management Plan is now mandatory for all covered entities, not just the largest banks, and third-party risk management has been significantly tightened. 

TeamSync doesn't replace your IT Strategy Committee. But the evidence that committee needs to show- access governance, audit trails, vendor documentation, incident logs- is the same evidence the platform is built to produce.

What The Framework Requires

Requirement

What it actually says

Board-level governance

Board is responsible for IT governance; an IT Strategy Committee of the Board must meet at least once a quarter

Steering Committee

An executive-level Steering Committee must assist the Board committee 

CISO independence

Clear separation expected between the CISO and the head of IT 

IT risk framework

Must be Board-approved, not delegated to senior management alone 

Cyber Crisis Management Plan

Mandatory for all covered entities, regardless of size 

Third-party / vendor risk

Exit clauses, concentration-risk monitoring, and annual audits of critical vendors 

Incident detection & reporting

CERT-In's 6-hour reporting clock, plus RBI's own incident reporting expectations 

Information Systems audit

Independent IS audit, at a frequency proportionate to risk 

Data localisation

Localisation requirements for payment data remain in force, with stricter enforcement 

Asset-based tiering (NBFCs)

Higher standard applies to NBFCs with assets above ₹500 crore 

Data governance overlap

Data governance and localisation controls are further sharpened by the DPDP Act, 2023 

Penalty Exposure

RBI enforces IT governance and cybersecurity failures primarily through Section 47A of the Banking Regulation Act, 1949, with the specific cap depending on which provision was breached.

Type of contravention

Statutory exposure

Illegal deposit-related contraventions (Sec 46(3))

Up to ₹20 lakh 

General regulatory non-compliance (Sec 46(4))

Up to ₹1 crore, or twice the amount involved, whichever is more 

Continuing contravention

An additional ₹1 lakh per day after the first day 

Criminal liability (in addition to civil penalty)

Imprisonment for a term that may extend to three years 

This isn't a rarely-used power. RBI imposed 353 penalties totalling ₹54.78 crore on regulated entities in FY25, with cybersecurity framework contraventions specifically named among the causes. Beyond fines, non-compliance can also lead to operational restrictions or, in severe cases, licence action.

Flag for legal: the criminal-liability provision alongside the civil penalty is a heavier claim than anything on your other compliance pages, recommend confirming with legal how prominently to state it, if at all.

Where DPDP And RBI Overlap

Most access management, encryption, incident response, and vendor-risk controls satisfy both RBI and DPDP requirements at once; the gaps sit mainly in DPDP-specific areas like consent management and data subject rights, which need their own dedicated processes. Worth noting on this page as a cross-reference to the DPDP page rather than duplicating content. 

What Else Runs On The Same Platform

Capability

What it does inside the RBI perimeter

RBAC

Access governance evidence for IT Strategy Committee reporting

Compliance Audit Trail

Cryptographic audit chain for IS audits and incident logs

Security and Deployment

Air-gapped, on-premise deployment for data localisation requirements

Agentic Workflow

Automates incident escalation ahead of the CERT-In reporting clock

Intelligent Repository

Central, retention-ruled store for vendor contracts and governance documentation

Risk Radar

Flags contracts or documents needing closer vendor-risk review

DocuTalk

Permission-aware AI search across governance and audit documentation

What A Supervisory Exam Looks Like

Exam request

What you'd need to produce

"Show us your Board IT Strategy Committee minutes and cadence"

Governance documentation, timestamped

"Show us your vendor risk assessments for critical vendors"

Vendor audit records with access trail

"Show us your incident detection and CERT-In notification timeline"

Timestamped incident log

"Show us your data localisation evidence for payment data"

Storage-location and access records

"Show us your IS audit reports"

Generated audit package

What Changes For Compliance And IT Teams

Activity

Before

With TeamSync

Governance documentation for the Board committee

Manual compilation

Central repository with version history

Vendor risk audit trail

Spreadsheet tracking

Structured records with access trail

Incident log for CERT-In reporting

Manual timestamping

Automated, timestamped log

IS audit evidence assembly

Multi-week project

Generated artifact

DPDP/RBI overlap mapping

Two separate exercises

One control set, two compliance lenses

How TeamSync Compares

  • Legacy banking GRC suites: Strong on policy and committee-workflow tracking, but the underlying document and data layer they govern still sits elsewhere

  • Point vendor-risk platforms: Strong on third-party assessment, narrower on the broader repository and audit-trail layer around it

  • In-house governance + spreadsheets: Most flexible on paper, but incident logging, audit evidence, and vendor documentation are left entirely to the team