CICRA Compliance & Information Security Audit
Credit Information Companies hold some of the most sensitive data in the country — the borrowing history of millions of people and businesses. The Credit Information Companies (Regulation) Act, 2005 makes the accuracy, privacy and security of that data a legal duty, and RBI now requires it to be verified by an independent information-systems audit. As a CERT-In Empaneled assessor, Intect conducts that audit and validates your controls the way an attacker would test them — so the assurance you place before your Board and the regulator is earned, not assumed.
CERT-In Empaneled. Aligned to CICRA 2005, the CIC Rules & Regulations 2006, and RBI's Credit Information Reporting Directions, 2025. We test the controls we audit.
The law that governs India's credit data — and the audit that now proves it
The Credit Information Companies (Regulation) Act, 2005 — Act 30 of 2005 — is the law that governs how credit information is collected, held, shared and protected in India. It created the framework under which Credit Information Companies (CICs) — the credit bureaus such as TransUnion CIBIL, Experian, Equifax and CRIF High Mark — are registered and regulated by the Reserve Bank of India. The Act, together with the Credit Information Companies Rules, 2006 and Regulations, 2006, makes accuracy, privacy and security of credit information a statutory obligation — not just for the bureaus, but for the credit institutions (banks, NBFCs, housing-finance companies, co-operative banks and others) that furnish data to them and the Specified Users that draw on it.
What changed in January 2025 is how that obligation is verified. RBI's Master Direction — Credit Information Reporting Directions, 2025, issued under Section 11 of the Act, now requires that entities sharing in credit information have their information systems audited by a CISA-certified auditor — for Specified Users on a half-yearly basis, and for entities receiving consent-based credit information at least annually — with the audit scoped explicitly to the Act's security and privacy sections and the IS-audit report placed before the CIC's Board and shared with RBI's supervisory team. An information-security audit that was once a matter of prudence is now an explicit, recurring regulatory expectation across the credit-information ecosystem.
"Credit data is among the most sensitive an organization can hold. CICRA makes protecting it a legal duty — and the regulator now wants that duty audited, not assumed."
Three roles, one chain of custody for credit data
CICRA does not regulate a single type of company — it governs an ecosystem. Credit data flows from the lenders who originate it, through the bureaus that hold and analyse it, to the users who rely on it to make decisions.
Each role carries its own statutory obligations for accuracy, privacy, permitted purpose and security, and RBI's directions now attach an IS-audit expectation to that flow. We scope every engagement to the role — or roles — you play in it.
CREDIT INFORMATION COMPANIES CREDIT INSTITUTIONS SPECIFIED USERS
Credit Information Companies (CICs) — The bureaus — registered and regulated by RBI under Section 5 (examples: TransUnion CIBIL, Experian, Equifax and CRIF High Mark).
Credit Institutions (CIs) — The data furnishers — banks, NBFCs, HFCs, co-operative banks, ARCs and AIFIs.
Specified Users (SUs) — The data consumers — members and other users specified by RBI.
Whatever your place in the chain, the same obligations recur — keep the data accurate, hold it under the Act's privacy principles, use it only for a permitted purpose, secure it against unauthorised access, retain it no longer than allowed — and prove all of it through an independent information-systems audit.
The instruments this audit is built on
We anchor every engagement to the live text — the Act, its Rules and Regulations, and RBI's current directions — so the audit you present is current, defensible and mapped to the right source.
Credit Information Companies (Regulation) Act, 2005
Act 30 of 2005
The parent statute. It establishes RBI registration and regulation of CICs (Section 5) and sets the core duties: accuracy and security of credit information (Section 19), the privacy principles (Section 20) governing collection, processing, sharing, purpose and retention, the right of correction (Section 21), and the prohibition on unauthorised access (Section 22) — with penalties for breach.
Credit Information Companies Rules, 2006
Operational detail behind the Act
The operational detail behind the Act. They set the steps for security and safeguards by credit institutions and CICs (Rule 18), data security and system-integrity requirements (Rule 23), the prohibition on unauthorised access, use or disclosure (Rule 28) and the fidelity and secrecy obligation (Rule 29) — the exact rules RBI now names in the IS-audit scope.
Credit Information Companies Regulations, 2006
Membership, format, accuracy, preservation
The mechanics of membership, the RBI-approved data format, accuracy and update cadence, and preservation — including the requirement to protect credit information against loss, unauthorised access, use, modification or disclosure, and minimum retention periods for credit and personal data.
RBI Credit Information Reporting Directions, 2025
RBI/DoR/2024-25/125 · 6 January 2025
RBI's consolidated Master Direction under Section 11 of the Act. It requires a CISA-certified IS audit — half-yearly for Specified Users, annually for consent-based recipients — scoped to Sections 19, 20 and 22 of CICRA and Rules 18(b), 23, 28 and 29 of the CIC Rules, with the report placed before the CIC's Board and shared with RBI.
How a CICRA compliance and security audit runs
A disciplined, evidence-led path from scoping to closure — built so your team always knows where the audit stands and what to act on next, and so the report stands up to RBI's supervisory review.
FIG. 02 — CICRA audit lifecycle · 01–03 scoping through control testing · 04 technical validation (VAPT) — the offensive edge · 05–08 gap analysis through closure
What we audit against
Our coverage maps to the statutory duties in CICRA and the exact Rules RBI names in the IS-audit scope. Across an engagement we systematically examine the following areas.
Accuracy & Security of Credit Information (Section 19)
That credit information is accurate, complete and duly protected against loss and unauthorised access — the Act's foundational data-quality and security duty.
Privacy Principles (Section 20)
How the privacy principles are operationalised: lawful collection, fair processing, secrecy, accuracy before sharing, purpose limitation, controlled disclosure and defined retention — the spine of the Act's data-protection regime.
Permissible Purpose & Disclosure
That credit information is collected, used and disclosed only for the purposes the Act permits and only to members and Specified Users entitled to receive it — never resold or passed on for unconsented use.
Unauthorised Access (Section 22 · Rule 28)
The technical and procedural controls that prevent unauthorised access, use or disclosure of credit information, online and offline — the breach the Act penalises directly.
Security Safeguards & System Integrity (Rules 18 & 23)
The steps for security and safeguards by credit institutions and CICs, and the data-security and system-integrity controls the Rules require — access control, encryption, monitoring and secure data exchange.
Fidelity, Secrecy & Need-to-Know (Rule 29)
The fidelity and secrecy obligation in practice: that employees and agents access credit information on a strict need-to-know basis under binding confidentiality.
Retention, Deletion & Data Localization
Retention limited to what the Act, Rules and 2025 Directions allow — including the six-month limit on consent-based credit information and the requirement to process and store credit information in India.
Correction & Grievance Redressal (Section 21)
The mechanisms for updating credit information on request within the statutory timeline, dispute handling and the grievance-redressal system the directions require.
We don't just read your controls. We test them.
A CISA-scoped IS audit confirms that a control exists and is documented. An attacker doesn't care whether it exists — only whether it holds. With credit data, the difference is the whole point.
The document-only audit
A conventional information-systems audit reviews policies, interviews owners and samples evidence to confirm a control is designed and, on paper, operating. It is necessary work — it satisfies the letter of the IS-audit obligation — and it is where most audits stop. The trouble is that a well-written access policy and an access control an outsider can walk through are not the same thing, and with credit information the gap between them is millions of people's financial histories.
The technically validated audit
Intect comes from offensive security. So where it matters, we validate the controls protecting credit data by testing them — vulnerability assessment and penetration testing that turns "we have access controls" into demonstrated evidence of exactly what an unauthorised user can and cannot reach. You get findings backed by proof of real exposure, not a checklist of assertions — and an audit your Board and RBI's supervisory team can trust because it has been earned.
We are CERT-In Empaneled, so the audit is regulator-recognized — and we come from offensive security, so it is technically validated. With data this sensitive, that combination is the point.
VAPT-BACKED VALIDATIONWhat you receive
Every engagement ends in an audit your team and your Board can act on — written for the engineers who will remediate and the leadership and regulator accountable for the risk.
CICRA compliance & IS audit report
A structured report covering each control area, findings, severity and risk, mapped to the applicable section of the Act, the Rules and the 2025 Directions — formatted to be placed before the Board and shared with RBI.
Executive & Board summary
Compliance posture and risk in plain language for the Board and senior management.
Technical validation evidence (the offensive edge)
VAPT findings with reproducible proof-of-concept and demonstrated impact, so control failures around credit data are evidenced, not asserted.
Gap analysis & remediation roadmap
Prioritized, specific remediation guidance mapped to Sections 19, 20 and 22 and the named Rules, with clear ownership and sequencing.
Remediation support & re-audit
We support your team through remediation and re-verify fixes so closure is evidenced.
Direct assessor access
A debrief with the people who performed the audit, not a handoff to a call centre.
Why the credit-information ecosystem chooses Intect
CERT-In Empaneled, with CISA-certified auditors — A real, regulator-recognized credential under India's national cybersecurity authority, and CISA-certified IS auditors on the team — so we perform the audit RBI mandates and the technical validation behind it. CICs sit inside the RBI-regulated perimeter; this is the same empanelment that underpins our RBI IS Audit work.
Offensive heritage — We come from penetration testing and red teaming. We audit the controls protecting credit data by testing them, surfacing exposure a paper review misses.
Researcher-led, not checklist-led — Engagements are run by practitioners who understand both the regulation and the adversary — so findings are accurate, contextual and defensible to RBI.
Delhi-based, regulator-fluent — An India-based team that speaks the language of CICRA, the CIC Rules and Regulations and RBI directions, available to your team through the engagement.
Related compliance services
CICs and the credit institutions around them carry obligations that reach beyond CICRA. These adjacent engagements often run alongside a CICRA audit.
Frequently asked questions
Is there a "CICRA certificate" Intect can issue?
No. CICRA is a law, not a certification scheme — there is no certificate to award. Compliance is demonstrated through an independent information-systems audit and the evidence behind it. Intect conducts that audit and the technical validation that backs it; we make your controls and your IS-audit report defensible to your Board and to RBI. Registration of a Credit Information Company itself is granted by the Reserve Bank, not by any auditor.
Who needs a CICRA information-security audit?
The credit-information ecosystem as a whole: the Credit Information Companies (the bureaus), the credit institutions — banks, NBFCs, housing-finance companies, co-operative banks, ARCs and AIFIs — that furnish data to them, and the Specified Users that draw on it. RBI's 2025 Directions attach an explicit CISA-certified IS-audit expectation to entities sharing in credit information.
How often is the IS audit required, and who must conduct it?
RBI's Credit Information Reporting Directions, 2025 require the audit to be performed by a CISA-certified auditor. For Specified Users, the IS audit is half-yearly; for entities receiving consent-based credit information from CICs, it is at least annually, or earlier if warranted. The IS-audit report is placed before the CIC's Board and shared with RBI's supervisory team. We help you set and meet the cadence that applies to your role.
What exactly must the IS audit cover?
RBI scopes it precisely: adherence to Sections 19, 20 and 22 of CICRA, 2005 — accuracy and security, the privacy principles, and unauthorised access — and Rules 18(b), 23, 28 and 29 of the CIC Rules, 2006 — security safeguards, data security and system integrity, the prohibition on unauthorised access, use or disclosure, and fidelity and secrecy — along with use of credit information only for permitted purposes. Our control areas map directly to these.
What's the difference between a CISA-certified IS audit and Intect being CERT-In Empaneled — and does Intect have both?
Yes — Intect brings both, in one team. RBI's directions call for a CISA-certified auditor to perform the CICRA IS audit, and our engagement team includes CISA-certified IS auditors, so we conduct that statutory audit directly. CERT-In Empanelment is the national credential for cyber-security audit and penetration testing of regulated entities — it is what lets us validate the controls technically, by testing them, rather than confirming them on paper. One team satisfies the CISA audit requirement and proves the controls actually hold.
How is this different from a standard IS audit?
We technically validate the controls we audit. Rather than confirming on paper that an access control or encryption control exists, we test whether it holds — using vulnerability assessment and penetration testing to evidence real exposure of sensitive credit data. You get assurance backed by proof, which is both stronger for your Board and more defensible to the regulator.
Do you help us fix the findings, or just report them?
Both. We deliver a prioritized remediation roadmap mapped to the specific sections and rules, support your team through the fixes, and re-verify remediated controls so closure is evidenced — not just claimed.
Protect the data you're trusted with. Prove it to the regulator.
Tell us your role in the credit-information chain — CIC, credit institution or Specified User — and where you are in your audit cycle, and we'll scope a CICRA compliance and security audit that fits, or connect you directly with an assessor.