Compliance · IS Audit – RBI RBI Master Direction (2023) · 7 chapters

Information Systems (IS) Audit for RBI-Regulated Entities

RBI expects its regulated entities to prove that IT governance, security controls and cyber resilience actually work — through an independent Information Systems audit. As a CERT-In empaneled assessor, Intect conducts that audit and validates your controls the way an attacker would test them, so the assurance you report to your Board and to the regulator is earned, not assumed.

CERT-In Empaneled. Aligned to the RBI Master Direction on IT Governance, Risk, Controls & Assurance Practices. We test the controls we audit.

RBI Master Direction (2023) Cyber Security Framework (2016) UCB Graded Approach CERT-In Empaneled
Direction
RBI Master Direction on IT Governance, Risk, Controls & Assurance Practices (2023)
Applies to
Banks · NBFCs · UCBs · PSOs · CICs · AIFIs
Role
CERT-In empaneled — Intect conducts the audit directly
Validation
VAPT-backed technical control validation
02

Assurance the regulator recognizes — and that actually holds up

An Information Systems audit is an independent examination of the technology, processes and controls a financial institution depends on — its IT governance, information and cyber security, change and access management, business continuity, third-party arrangements and the controls embedded in its critical applications.

For entities the Reserve Bank of India regulates, this is not optional housekeeping: it is the mechanism through which an institution demonstrates, to its own Audit Committee and to the regulator, that its controls are designed well and operating effectively.

The expectation was sharpened in November 2023, when RBI issued its Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices — consolidating instructions that had previously been spread across separate circulars for banks and NBFCs into a single, current framework that took effect on 1 April 2024. Alongside the longstanding Cyber Security Framework, it sets clear expectations for board-level IT governance, a defined IS Audit function, periodic vulnerability assessment and penetration testing, and resilience that is verified rather than asserted. An RBI IS audit is how an institution evidences all of it.

"A control you have documented is a claim. A control we have tested is assurance. The regulator — and your Board — should be able to tell the difference."
03

Who is in scope

RBI's IT governance and cyber-security expectations reach across the regulated landscape — and the depth of audit scales with an entity's size, digital footprint and role in the payment system. The Master Direction on IT Governance, Risk, Controls & Assurance Practices applies to a defined set of regulated entities; the Cyber Security Framework and the graded approach for co-operative banks extend the expectation further. We scope every engagement to the directions that apply to you.

Whatever your category, the audit examines the same families of control — governance, risk, security, resilience, third-party arrangements and application controls — calibrated to the directions that bind you.

04

The directions this audit is built on

We anchor every engagement to the live RBI text — so the audit you present is current, defensible and mapped to the right source.

01

Master Direction on IT Governance, Risk, Controls & Assurance Practices (2023)

RBI/2023-24/107 · DoS.CO.CSITEG/SEC.7/31.01.015/2023-24 RBI's consolidated framework — issued 7 November 2023, effective 1 April 2024 — which updates and repeals twelve earlier circulars into one current set of expectations. Across its seven chapters it requires board-level IT governance (an IT Strategy Committee and an IT Steering Committee, and a Head of IT Function), IT infrastructure and services management, IT and information-security risk management (including an independent CISO), business continuity and disaster recovery, and a dedicated Information Systems (IS) Audit function overseen by the Audit Committee of the Board.

02

Cyber Security Framework (2016) & baseline controls

RBI's foundational cyber-security circular for banks, with its annexure of baseline cyber-security controls — board-approved policy, security operations, incident reporting timelines and periodic vulnerability assessment and penetration testing.

03

Cyber Security Framework for Urban Co-operative Banks — a graded approach

A tiered model that calibrates controls to a co-operative bank's digital depth and connection to the payment system, scaling from baseline cyber hygiene up to full IT/IS governance and a cyber-security operations centre.

04

CERT-In empanelment

RBI's cyber-security and audit expectations are met through assessments performed by appropriately competent, independent auditors — and CERT-In empanelment is the recognized credential for that work. Intect is CERT-In empaneled.

CERT-IN EMPANELED
05

How an RBI IS audit runs

A disciplined, evidence-led path from scoping to closure — built so your team always knows where the audit stands and what to act on next.

01
Scoping
Define the regulated perimeter: which RBI directions apply to you, which systems, applications and locations are in scope, and what "good" looks like for each control domain.
02
Information Gathering & Document Review
Examine policies, board and committee minutes, risk registers, network and application architecture, configurations and prior audit findings — establishing the design of your controls.
03
Control Testing
Test controls in operation, not just on paper: access provisioning and reviews, change and patch management, logging and monitoring, backup and recovery, and third-party governance.
04
Technical Validation (VAPT)
Independently validate the security controls by testing them — vulnerability assessment and penetration testing across internet-facing and internal critical systems, on the cadence the Master Direction expects for critical and DMZ systems, so exposure is proven, not assumed.
05
Gap Analysis
Measure each finding against the applicable RBI direction and control objective, assign severity and risk, and separate true gaps from documentation issues.
06
Reporting
Deliver a clear, prioritized report for both the engineers who will fix issues and the Audit Committee that must understand the risk — with evidence and concrete remediation guidance.
07
Remediation Support
Work alongside your team as fixes are implemented, clarifying control intent and helping you close findings correctly the first time.
08
Closure & Re-audit
Re-verify remediated controls so closure is evidenced, and establish the cadence for the next periodic audit and ongoing assurance.

FIG. 02 — RBI IS audit lifecycle · 01–08 · node 04 (Technical Validation / VAPT) is the offensive-edge step

06

What we audit against

Our coverage maps to the control families set out in the RBI Master Direction on IT Governance, Risk, Controls & Assurance Practices and the Cyber Security Framework. Across an engagement we systematically examine the following domains:

01 IT Governance Board oversight and the IT Strategy Committee, IT Steering Committee and Head of IT Function; IT-strategy alignment, roles and accountability, and how IT and cyber risk is owned and escalated to the Board.
RBI Master Direction (2023) Cyber Security Framework
02 IT & Information Security Risk Management The risk-management framework, the Information Security and Cyber Security policies and Cyber Crisis Management Plan, an independent CISO function, and risk identification, treatment and periodic review.
RBI Master Direction (2023) Cyber Security Framework
03 Access & Identity Management User provisioning and de-provisioning, privileged access, multi-factor authentication, segregation of duties and periodic access reviews.
RBI Master Direction (2023) Cyber Security Framework
04 Change & Patch Management Controlled change, segregation of development and production, patch currency and the management of emergency changes.
RBI Master Direction (2023) Cyber Security Framework
05 Cyber Security & Threat Defence Security monitoring and operations, logging, vulnerability management, malware defence and incident detection and response.
RBI Master Direction (2023) Cyber Security Framework
06 Business Continuity & Disaster Recovery Continuity and recovery plans, recovery-site configuration parity, periodic DR drills and tested, restorable backups.
RBI Master Direction (2023) Cyber Security Framework
07 IT Operations & Infrastructure Capacity and availability management, network and infrastructure security, service-level management and cryptographic controls.
RBI Master Direction (2023) Cyber Security Framework
08 Third-Party & Outsourcing Risk Due diligence, contractual controls, concentration and exit risk, and monitoring of service providers and cloud arrangements.
RBI Master Direction (2023) Cyber Security Framework
09 Application & Data Controls Controls embedded in critical applications, input and processing integrity, audit trails, and the protection of sensitive and customer data.
RBI Master Direction (2023) Cyber Security Framework
07

We don't just read your controls. We test them.

A document-only audit confirms that a control exists. An attacker doesn't care whether it exists — only whether it works. We close that gap.

Confirms the claim

The document-only audit

A traditional IS audit reviews policies, interviews owners and samples evidence to confirm a control is designed and, on paper, operating. It is necessary work — and it is where most audits stop. The trouble is that a well-written policy and a correctly configured control are not the same thing, and the difference is exactly what an attacker exploits.

Proves the control

The technically validated audit

Intect comes from offensive security. So where it matters, we validate controls by testing them — vulnerability assessment and penetration testing that turns "we have access controls" into demonstrated evidence of what an unauthorized user can and cannot reach. You get findings backed by proof of real exposure, not a checklist of assertions — and a report your Board and the regulator can trust because it has been earned.

We are CERT-In empaneled, so the audit is regulator-recognized — and we come from offensive security, so it is technically validated. That combination is the point.

VAPT-BACKED EVIDENCE
08

What you receive

Every engagement ends in an audit your team and your Audit Committee can act on — written for the engineers who will remediate and the leadership accountable for the risk.

01

IS audit report

A structured report covering each control domain, findings, severity and risk, mapped to the applicable RBI direction and control objective.

02

Executive & Audit Committee summary

Risk posture and the state of compliance in plain language for the Board and senior management.

03

Technical validation evidence (the offensive edge)

VAPT findings with reproducible proof-of-concept and demonstrated impact, so control failures are evidenced, not asserted.

VAPT-BACKED
04

Gap analysis & remediation roadmap

Prioritized, specific remediation guidance with clear ownership and sequencing — not generic advice.

05

Remediation support & re-audit

We support your team through remediation and re-verify fixes so closure is evidenced.

06

Direct assessor access

A debrief with the people who performed the audit, not a handoff to a call centre.

CERT-In Empaneled CISA-Certified IS Auditors RBI Master Direction on IT Governance, Risk, Controls & Assurance Practices RBI Cyber Security Framework UCB Graded Approach VAPT-backed validation
09

Why regulated entities choose Intect

CERT-In Empaneled CISA-Certified IS Auditors

CERT-In Empaneled, with CISA-certified auditors — A real, regulator-recognized credential under India's national cybersecurity authority, backed by CISA-certified IS auditors on the team — so the IS audit and the technical validation behind it are accepted where it counts.

Offensive heritage — We come from penetration testing and red teaming. We audit controls by testing them, surfacing the exposure a paper review misses.

Researcher-led, not checklist-led — Engagements are run by practitioners who understand both the regulation and the adversary — so findings are accurate, contextual and defensible.

Delhi-based, regulator-fluent — An India-based team that speaks the language of RBI directions and Indian financial-sector supervision, available to your team through the engagement.

10

Frequently asked questions

Is an RBI IS audit a certification?

No. An Information Systems audit is an independent assurance engagement, not a certificate. It produces an audit report — for your Audit Committee, senior management and, where applicable, the regulator — evidencing how well your IT and security controls are designed and operating against the relevant RBI directions. There is no "RBI certificate"; there is credible, independent assurance.

Who is allowed to conduct it?

RBI expects this work to be performed by competent, independent auditors, and CERT-In empanelment is the recognized credential for cyber-security audits and penetration testing of regulated entities. Intect is CERT-In empaneled, so we can conduct the audit and the technical validation behind it.

How is this different from the SAR / Data Localization audit?

The SAR is a specific, annual audit that certifies payment-system data is stored in India. An IS audit is broader — it examines IT governance, security, resilience, third-party risk and application controls across your regulated functions, not only where data is stored. They are complementary; we offer both, on separate pages.

How often do we need an IS audit?

RBI's framework establishes IS audit as a periodic obligation. For critical and customer-facing (DMZ) systems, the Master Direction expects vulnerability assessment at least every six months and penetration testing at least annually — with additional testing across the system lifecycle and after any significant change. We help you set a cadence that satisfies the applicable directions and your Audit Committee's risk appetite, and we time engagements to your supervisory calendar.

What makes your audit different from a standard IS audit?

We technically validate the controls we audit. Rather than confirming on paper that a control exists, we test whether it holds — using vulnerability assessment and penetration testing to evidence real exposure. You get assurance backed by proof, which is both stronger for your Board and more defensible to the regulator.

Do you help us fix the findings, or just report them?

Both. We deliver a prioritized remediation roadmap, support your team through the fixes, and re-verify remediated controls so closure is evidenced — not just claimed.

11

Related RBI assurance

RBI compliance spans several distinct audits. This page covers the broad Information Systems / cyber-security audit; for the narrower, mandated audits below, see the dedicated pages.

Scope an engagement

Prove your controls. Satisfy the regulator.

Tell us your entity type and where you are in your RBI compliance cycle, and we'll scope an IS audit that fits — or connect you directly with an assessor.