Compliance hub

RBI cybersecurity expectations: identity controls for banks and NBFCs

RBI supervision treats access control as a board-level concern: the Cybersecurity Framework for banks, the Master Directions on IT Governance and scale-based regulation for NBFCs all expect demonstrable control over who can access critical systems, how they authenticate, and whether that access is periodically justified. IamLogic operationalises those expectations.

  • ISO/IEC 27001:2022 certified
  • Made in India
  • On-premises · Cloud · Hybrid
  • SAML · OIDC · OAuth2 · RADIUS
  • 24×7 support

Context

What the framework expects

RBI's framework expects banks to maintain an up-to-date inventory of access, enforce least privilege and need-to-know, implement multi-factor authentication for critical systems, and retain audit trails supporting incident investigation.

Inspection findings repeatedly cite orphan accounts, excessive privileges, shared credentials and absent access reviews — precisely the failures identity governance eliminates.

CERT-In directions additionally require 180-day log retention within India and six-hour incident reporting, which depend on having reliable authentication and access logs in the first place.

Identity obligations

The requirements that touch IAM

  • Least privilege and need-to-know across critical applications
  • Multi-factor and risk-based authentication for sensitive access
  • Periodic review and recertification of user access rights
  • Segregation of duties in financial processes
  • Comprehensive, tamper-evident audit trails retained in India

Control mapping

Requirement → IamLogic control

The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.

Requirement IamLogic control Product
MFA / strong authentication on critical systems Adaptive MFA (TOTP, WebAuthn, push, SMS/Email OTP, phone) with step-up policies per application sensitivity Access Manager
Risk-based access decisions Context-based authentication evaluating network, geolocation, time and custom Python-scripted policies Access Manager
Coverage of legacy core systems Browser-plugin SSO with credential vaulting and rotation for non-federated banking applications Access Manager
Periodic access review and recertification Certification campaigns with reviewer context, enforced revocation and retained sign-off evidence IamLogic IGA
Segregation of duties in payments and finance SoD rule engine detecting and preventing toxic entitlement combinations IamLogic IGA
Timely removal of access (exits, transfers) HR-driven joiner–mover–leaver automation with immediate deprovisioning IamLogic IGA
Audit trails retained within India On-premises deployment keeps every authentication and provisioning log inside your data centre Both products

This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.

FAQ

Common questions

Does this apply to NBFCs or only banks?

RBI's Master Direction on IT Governance (2023) and scale-based regulation extend substantially similar expectations to NBFCs in the middle and upper layers. Cooperative banks have their own tiered guidelines with the same access-control core.

Can IamLogic produce inspection-ready reports?

Yes — certification outcomes, SoD exceptions, deprovisioning timelines and authentication coverage are available as reports designed to answer inspection questionnaires directly.

Map RBI Cybersecurity Framework to your environment

A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.