Working across banks, NBFCs, co-operative banks and payment operators, the pattern in supervisory findings has shifted in a way that is worth stating plainly. The questions are less about whether a control exists and more about whether the institution can show who owns it, who reviewed it, and what happened when it failed.
That is a governance test wearing technical clothing, and it is why technically strong institutions still collect findings.
Board level ownership is the recurring theme
The Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices puts specific responsibilities on the board and on a board level IT strategy committee. In practice that means minutes.
An institution that can produce a risk register, dated board minutes showing it was discussed, decisions recorded against named owners, and evidence of what changed by the next meeting, is in a different position from one that has all the same controls and no paper trail. We have watched two institutions with comparable security postures receive very different inspection outcomes on exactly that difference.
If your IT strategy committee has met twice this year and the minutes record attendance rather than decisions, that is a finding waiting to be written.
The gap that surprises people is the third party
Outsourcing does not move accountability, and supervision has become considerably more direct about testing this. The questions we now see asked: which of your critical functions run on a vendor, what happens if that vendor is unavailable for a week, when did you last test that, and what right do you hold to audit them.
Most institutions can answer the first. Fewer can answer the second with anything other than a contractual clause. Almost none have exercised the third.
Concentration risk is the specific thing being probed. If four of your critical services run in one cloud region operated by one provider, the fact that each contract is individually sound does not address the correlated failure.
Business continuity is being tested rather than documented
The direction of travel is unmistakable. A BCP document that has never been exercised counts for very little, and a DR test where the application team knew the date and pre warmed the environment counts for less than the institution thinks.
What holds up: an unannounced or minimally announced failover, with the recovery time measured rather than asserted, and a written record of what did not work. Reports that record a clean test with no issues attract scepticism, correctly, because a real failover always surfaces something.
Incident reporting has two clocks now
Reportable incidents go to CERT-In within six hours under the 2022 Directions. Institutions under RBI supervision have their own reporting expectations on top, and where personal data is involved the DPDP Act 2023 adds a third obligation with different triggers and a different recipient.
Build one detection and triage process, then three reporting paths off it. Institutions that build one reporting process and assume it satisfies everyone tend to notify the wrong body on the wrong timeline.
What we would fix first in a bank or NBFC today
Get the board paperwork right, because it is the cheapest gap to close and it colours how everything else is read. Named owners, dated decisions, recorded follow ups.
Map your critical services to their third parties and identify the concentration. You cannot manage a dependency you have not written down.
Run one unannounced failover of one critical service this quarter and write down honestly what broke.
Reconcile privileged access against your HR record. Standing administrative access in a regulated financial institution is the finding that turns into an enforcement conversation.
None of that requires new technology, which is usually the uncomfortable part of the conversation. The institutions that come through inspection well are rarely the ones with the largest security budgets. They are the ones that can show their working.












