Compliance hub
RBI cybersecurity expectations: identity controls for banks and NBFCs
RBI supervision treats access control as a board-level concern: the Cybersecurity Framework for banks, the Master Directions on IT Governance and scale-based regulation for NBFCs all expect demonstrable control over who can access critical systems, how they authenticate, and whether that access is periodically justified. IamLogic operationalises those expectations.
Context
What the framework expects
RBI's framework expects banks to maintain an up-to-date inventory of access, enforce least privilege and need-to-know, implement multi-factor authentication for critical systems, and retain audit trails supporting incident investigation.
Inspection findings repeatedly cite orphan accounts, excessive privileges, shared credentials and absent access reviews — precisely the failures identity governance eliminates.
CERT-In directions additionally require 180-day log retention within India and six-hour incident reporting, which depend on having reliable authentication and access logs in the first place.
Identity obligations
The requirements that touch IAM
- Least privilege and need-to-know across critical applications
- Multi-factor and risk-based authentication for sensitive access
- Periodic review and recertification of user access rights
- Segregation of duties in financial processes
- Comprehensive, tamper-evident audit trails retained in India
Control mapping
Requirement → IamLogic control
The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.
| Requirement | IamLogic control | Product |
|---|---|---|
| MFA / strong authentication on critical systems | Adaptive MFA (TOTP, WebAuthn, push, SMS/Email OTP, phone) with step-up policies per application sensitivity | Access Manager |
| Risk-based access decisions | Context-based authentication evaluating network, geolocation, time and custom Python-scripted policies | Access Manager |
| Coverage of legacy core systems | Browser-plugin SSO with credential vaulting and rotation for non-federated banking applications | Access Manager |
| Periodic access review and recertification | Certification campaigns with reviewer context, enforced revocation and retained sign-off evidence | IamLogic IGA |
| Segregation of duties in payments and finance | SoD rule engine detecting and preventing toxic entitlement combinations | IamLogic IGA |
| Timely removal of access (exits, transfers) | HR-driven joiner–mover–leaver automation with immediate deprovisioning | IamLogic IGA |
| Audit trails retained within India | On-premises deployment keeps every authentication and provisioning log inside your data centre | Both products |
This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.
FAQ
Common questions
Does this apply to NBFCs or only banks?
RBI's Master Direction on IT Governance (2023) and scale-based regulation extend substantially similar expectations to NBFCs in the middle and upper layers. Cooperative banks have their own tiered guidelines with the same access-control core.
Can IamLogic produce inspection-ready reports?
Yes — certification outcomes, SoD exceptions, deprovisioning timelines and authentication coverage are available as reports designed to answer inspection questionnaires directly.
Map RBI Cybersecurity Framework to your environment
A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.