Open resource, CC BY 4.0
RBI cyber security audit checklist
The controls an RBI supervisory review actually asks about, in the order the inspection tends to move through them.
Work through it here
This is the artifact, not a preview of it. Tick items off as you go. Progress is kept in this browser and nothing is sent anywhere, so there is no account and no email step.
0 of 29 checksSaved in this browser only
1Board and governance
2Network and system controls
3Access management
4Monitoring and response
5Testing and assurance
6Third party and continuity
Where the facts come from
Nothing here is our opinion dressed up as a rule. Every line traces back to a published source, cited so you can check it.
- RBI Cyber Security Framework in Banks, June 2016
- Master Direction on Digital Payment Security Controls, February 2021
- Master Direction on Outsourcing of IT Services, April 2023
What people use it for
Running a dry run before the inspection, using the same order the inspection uses.
Licence
Published under Creative Commons Attribution 4.0. Copy it, cut it about, put it in your own audit pack, sell the work you do with it. Credit Threatsys and you are within the licence. There is no email gate and there never will be.
More open resources
- India compliance registryEvery cyber security obligation an Indian organisation can be held to, in one table, with the regulator and the trigger against each.Open it
- CERT-In directions readiness checklistThe April 2022 directions turned into checks you can actually run, including the log retention and clock sync duties people miss.Open it
- DPDP compliance timelineWhat the DPDP Act asks for, in the order you have to do it, with the dependencies that decide what you can start today.Open it
What supervision is testing now
The pattern in supervisory findings has shifted from whether a control exists to whether the institution can show who owns it, who reviewed it, and what happened when it failed. That is a governance test wearing technical clothing.
The Master Direction on IT Governance, Risk, Controls and Assurance Practices places specific responsibilities on the board and on a board level IT strategy committee. In practice that means minutes recording decisions against named owners, and evidence of what changed by the next meeting.
Two institutions with comparable security postures can receive very different inspection outcomes on that difference alone.
Third party and concentration risk
Outsourcing does not move accountability, and this is now tested directly. Which critical functions run on a vendor. What happens if that vendor is unavailable for a week. When did you last test that. What audit right do you hold.
Most institutions answer the first. Few answer the second with anything beyond a contractual clause. Almost none have exercised the third.
Concentration is the specific probe. If four critical services run in one cloud region operated by one provider, the fact that each contract is individually sound does not address the correlated failure.
Continuity, tested rather than documented
A BCP that has never been exercised counts for little. A DR test where the application team knew the date and pre-warmed the environment counts for less than the institution thinks.
What holds up is an unannounced or minimally announced failover, with recovery time measured rather than asserted, and a written record of what did not work.
Reports recording a clean test with no issues attract scepticism, correctly, because a real failover always surfaces something.
What to fix first
Board paperwork, because it is the cheapest gap to close and it colours how everything else is read. Named owners, dated decisions, recorded follow ups.
Then map critical services to their third parties and identify the concentration.
Then run one unannounced failover this quarter and write down honestly what broke.
Then reconcile privileged access against your HR record. Standing administrative access in a regulated institution is the finding that becomes an enforcement conversation, and the reconciliation is a fortnight of dull work that reliably finds accounts belonging to people who left years ago.
None of this requires new technology, which is usually the uncomfortable part of the conversation.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












