Compliance hub

RBI cybersecurity expectations: identity controls for banks and NBFCs

RBI supervision treats access control as a board-level concern: the Cybersecurity Framework for banks, the Master Directions on IT Governance and scale-based regulation for NBFCs all expect demonstrable control over who can access critical systems, how they authenticate, and whether that access is periodically justified. IamLogic operationalises those expectations.

  • ISO/IEC 27001:2022 certified
  • Made in India
  • On-premises · Cloud · Hybrid
  • SAML · OIDC · OAuth2 · RADIUS
  • 24×7 support

Context

What the framework expects

RBI's framework expects banks to maintain an up-to-date inventory of access, enforce least privilege and need-to-know, implement multi-factor authentication for critical systems, and retain audit trails supporting incident investigation.

Inspection findings repeatedly cite orphan accounts, excessive privileges, shared credentials and absent access reviews — precisely the failures identity governance eliminates.

CERT-In directions additionally require 180-day log retention within India and six-hour incident reporting, which depend on having reliable authentication and access logs in the first place.

Identity obligations

The requirements that touch IAM

  • Least privilege and need-to-know across critical applications
  • Multi-factor and risk-based authentication for sensitive access
  • Periodic review and recertification of user access rights
  • Segregation of duties in financial processes
  • Comprehensive, tamper-evident audit trails retained in India

Control mapping

Requirement → IamLogic control

The table your compliance team and your auditor both want: each identity-relevant requirement, the product control that implements it, and which product it lives in.

RequirementIamLogic controlProduct
MFA / strong authentication on critical systemsAdaptive MFA (TOTP, WebAuthn, push, SMS/Email OTP, phone) with step-up policies per application sensitivityAccess Manager
Risk-based access decisionsContext-based authentication evaluating network, geolocation, time and custom Python-scripted policiesAccess Manager
Coverage of legacy core systemsBrowser-plugin SSO with credential vaulting and rotation for non-federated banking applicationsAccess Manager
Periodic access review and recertificationCertification campaigns with reviewer context, enforced revocation and retained sign-off evidenceIamLogic IGA
Segregation of duties in payments and financeSoD rule engine detecting and preventing toxic entitlement combinationsIamLogic IGA
Timely removal of access (exits, transfers)HR-driven joiner–mover–leaver automation with immediate deprovisioningIamLogic IGA
Audit trails retained within IndiaOn-premises deployment keeps every authentication and provisioning log inside your data centreBoth products

This page is provided for general information and maps regulatory expectations to IamLogic product capabilities. It is not legal advice. Regulatory obligations and timelines evolve — confirm your organisation's specific requirements with your compliance counsel.

FAQ

Common questions

Does this apply to NBFCs or only banks?

RBI's Master Direction on IT Governance (2023) and scale-based regulation extend substantially similar expectations to NBFCs in the middle and upper layers. Cooperative banks have their own tiered guidelines with the same access-control core.

Can IamLogic produce inspection-ready reports?

Yes — certification outcomes, SoD exceptions, deprovisioning timelines and authentication coverage are available as reports designed to answer inspection questionnaires directly.

Map RBI Cybersecurity Framework to your environment

A working session with our engineers: your systems, this framework's requirements, and a concrete gap list you keep either way.