Information Systems (IS) Audit for RBI-Regulated Entities
RBI expects its regulated entities to prove that IT governance, security controls and cyber resilience actually work — through an independent Information Systems audit. As a CERT-In empaneled assessor, Intect conducts that audit and validates your controls the way an attacker would test them, so the assurance you report to your Board and to the regulator is earned, not assumed.
CERT-In Empaneled. Aligned to the RBI Master Direction on IT Governance, Risk, Controls & Assurance Practices. We test the controls we audit.
Assurance the regulator recognizes — and that actually holds up
An Information Systems audit is an independent examination of the technology, processes and controls a financial institution depends on — its IT governance, information and cyber security, change and access management, business continuity, third-party arrangements and the controls embedded in its critical applications.
For entities the Reserve Bank of India regulates, this is not optional housekeeping: it is the mechanism through which an institution demonstrates, to its own Audit Committee and to the regulator, that its controls are designed well and operating effectively.
The expectation was sharpened in November 2023, when RBI issued its Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices — consolidating instructions that had previously been spread across separate circulars for banks and NBFCs into a single, current framework that took effect on 1 April 2024. Alongside the longstanding Cyber Security Framework, it sets clear expectations for board-level IT governance, a defined IS Audit function, periodic vulnerability assessment and penetration testing, and resilience that is verified rather than asserted. An RBI IS audit is how an institution evidences all of it.
"A control you have documented is a claim. A control we have tested is assurance. The regulator — and your Board — should be able to tell the difference."
Who is in scope
RBI's IT governance and cyber-security expectations reach across the regulated landscape — and the depth of audit scales with an entity's size, digital footprint and role in the payment system. The Master Direction on IT Governance, Risk, Controls & Assurance Practices applies to a defined set of regulated entities; the Cyber Security Framework and the graded approach for co-operative banks extend the expectation further. We scope every engagement to the directions that apply to you.
incl. Small Finance Banks & Payments Banks (excludes Regional Rural Banks).
Top, Upper & Middle Layer, under Scale-Based Regulation.
graded by digital depth — Levels I to IV.
PSOs, PAs and payment-system participants.
CICs holding regulated credit data.
EXIM Bank, NABARD, NaBFID, NHB, SIDBI.
Whatever your category, the audit examines the same families of control — governance, risk, security, resilience, third-party arrangements and application controls — calibrated to the directions that bind you.
The directions this audit is built on
We anchor every engagement to the live RBI text — so the audit you present is current, defensible and mapped to the right source.
Master Direction on IT Governance, Risk, Controls & Assurance Practices (2023)
RBI/2023-24/107 · DoS.CO.CSITEG/SEC.7/31.01.015/2023-24 RBI's consolidated framework — issued 7 November 2023, effective 1 April 2024 — which updates and repeals twelve earlier circulars into one current set of expectations. Across its seven chapters it requires board-level IT governance (an IT Strategy Committee and an IT Steering Committee, and a Head of IT Function), IT infrastructure and services management, IT and information-security risk management (including an independent CISO), business continuity and disaster recovery, and a dedicated Information Systems (IS) Audit function overseen by the Audit Committee of the Board.
Cyber Security Framework (2016) & baseline controls
RBI's foundational cyber-security circular for banks, with its annexure of baseline cyber-security controls — board-approved policy, security operations, incident reporting timelines and periodic vulnerability assessment and penetration testing.
Cyber Security Framework for Urban Co-operative Banks — a graded approach
A tiered model that calibrates controls to a co-operative bank's digital depth and connection to the payment system, scaling from baseline cyber hygiene up to full IT/IS governance and a cyber-security operations centre.
CERT-In empanelment
RBI's cyber-security and audit expectations are met through assessments performed by appropriately competent, independent auditors — and CERT-In empanelment is the recognized credential for that work. Intect is CERT-In empaneled.
How an RBI IS audit runs
A disciplined, evidence-led path from scoping to closure — built so your team always knows where the audit stands and what to act on next.
FIG. 02 — RBI IS audit lifecycle · 01–08 · node 04 (Technical Validation / VAPT) is the offensive-edge step
What we audit against
Our coverage maps to the control families set out in the RBI Master Direction on IT Governance, Risk, Controls & Assurance Practices and the Cyber Security Framework. Across an engagement we systematically examine the following domains:
01 IT Governance Board oversight and the IT Strategy Committee, IT Steering Committee and Head of IT Function; IT-strategy alignment, roles and accountability, and how IT and cyber risk is owned and escalated to the Board.
02 IT & Information Security Risk Management The risk-management framework, the Information Security and Cyber Security policies and Cyber Crisis Management Plan, an independent CISO function, and risk identification, treatment and periodic review.
03 Access & Identity Management User provisioning and de-provisioning, privileged access, multi-factor authentication, segregation of duties and periodic access reviews.
04 Change & Patch Management Controlled change, segregation of development and production, patch currency and the management of emergency changes.
05 Cyber Security & Threat Defence Security monitoring and operations, logging, vulnerability management, malware defence and incident detection and response.
06 Business Continuity & Disaster Recovery Continuity and recovery plans, recovery-site configuration parity, periodic DR drills and tested, restorable backups.
07 IT Operations & Infrastructure Capacity and availability management, network and infrastructure security, service-level management and cryptographic controls.
08 Third-Party & Outsourcing Risk Due diligence, contractual controls, concentration and exit risk, and monitoring of service providers and cloud arrangements.
09 Application & Data Controls Controls embedded in critical applications, input and processing integrity, audit trails, and the protection of sensitive and customer data.
We don't just read your controls. We test them.
A document-only audit confirms that a control exists. An attacker doesn't care whether it exists — only whether it works. We close that gap.
The document-only audit
A traditional IS audit reviews policies, interviews owners and samples evidence to confirm a control is designed and, on paper, operating. It is necessary work — and it is where most audits stop. The trouble is that a well-written policy and a correctly configured control are not the same thing, and the difference is exactly what an attacker exploits.
The technically validated audit
Intect comes from offensive security. So where it matters, we validate controls by testing them — vulnerability assessment and penetration testing that turns "we have access controls" into demonstrated evidence of what an unauthorized user can and cannot reach. You get findings backed by proof of real exposure, not a checklist of assertions — and a report your Board and the regulator can trust because it has been earned.
We are CERT-In empaneled, so the audit is regulator-recognized — and we come from offensive security, so it is technically validated. That combination is the point.
VAPT-BACKED EVIDENCEWhat you receive
Every engagement ends in an audit your team and your Audit Committee can act on — written for the engineers who will remediate and the leadership accountable for the risk.
IS audit report
A structured report covering each control domain, findings, severity and risk, mapped to the applicable RBI direction and control objective.
Executive & Audit Committee summary
Risk posture and the state of compliance in plain language for the Board and senior management.
Technical validation evidence (the offensive edge)
VAPT findings with reproducible proof-of-concept and demonstrated impact, so control failures are evidenced, not asserted.
Gap analysis & remediation roadmap
Prioritized, specific remediation guidance with clear ownership and sequencing — not generic advice.
Remediation support & re-audit
We support your team through remediation and re-verify fixes so closure is evidenced.
Direct assessor access
A debrief with the people who performed the audit, not a handoff to a call centre.
Why regulated entities choose Intect
CERT-In Empaneled, with CISA-certified auditors — A real, regulator-recognized credential under India's national cybersecurity authority, backed by CISA-certified IS auditors on the team — so the IS audit and the technical validation behind it are accepted where it counts.
Offensive heritage — We come from penetration testing and red teaming. We audit controls by testing them, surfacing the exposure a paper review misses.
Researcher-led, not checklist-led — Engagements are run by practitioners who understand both the regulation and the adversary — so findings are accurate, contextual and defensible.
Delhi-based, regulator-fluent — An India-based team that speaks the language of RBI directions and Indian financial-sector supervision, available to your team through the engagement.
Frequently asked questions
Is an RBI IS audit a certification?
No. An Information Systems audit is an independent assurance engagement, not a certificate. It produces an audit report — for your Audit Committee, senior management and, where applicable, the regulator — evidencing how well your IT and security controls are designed and operating against the relevant RBI directions. There is no "RBI certificate"; there is credible, independent assurance.
Who is allowed to conduct it?
RBI expects this work to be performed by competent, independent auditors, and CERT-In empanelment is the recognized credential for cyber-security audits and penetration testing of regulated entities. Intect is CERT-In empaneled, so we can conduct the audit and the technical validation behind it.
How is this different from the SAR / Data Localization audit?
The SAR is a specific, annual audit that certifies payment-system data is stored in India. An IS audit is broader — it examines IT governance, security, resilience, third-party risk and application controls across your regulated functions, not only where data is stored. They are complementary; we offer both, on separate pages.
How often do we need an IS audit?
RBI's framework establishes IS audit as a periodic obligation. For critical and customer-facing (DMZ) systems, the Master Direction expects vulnerability assessment at least every six months and penetration testing at least annually — with additional testing across the system lifecycle and after any significant change. We help you set a cadence that satisfies the applicable directions and your Audit Committee's risk appetite, and we time engagements to your supervisory calendar.
What makes your audit different from a standard IS audit?
We technically validate the controls we audit. Rather than confirming on paper that a control exists, we test whether it holds — using vulnerability assessment and penetration testing to evidence real exposure. You get assurance backed by proof, which is both stronger for your Board and more defensible to the regulator.
Do you help us fix the findings, or just report them?
Both. We deliver a prioritized remediation roadmap, support your team through the fixes, and re-verify remediated controls so closure is evidenced — not just claimed.
Related RBI assurance
RBI compliance spans several distinct audits. This page covers the broad Information Systems / cyber-security audit; for the narrower, mandated audits below, see the dedicated pages.
Prove your controls. Satisfy the regulator.
Tell us your entity type and where you are in your RBI compliance cycle, and we'll scope an IS audit that fits — or connect you directly with an assessor.