India Regulatory Hub
Cross-regulator · India Deep Dive

Board Governance Map

Indian regulators legislate governance through board structures. This map shows every mandated body, who must sit on it, how often it meets and what evidence regulators expect.

Last verified: 2026-06-17
Regulator / LawMandated Body / OfficerComposition & ReportingCadenceKey Duties & Evidence
RBI — MD-ITGRC 2023IT Strategy Committee of the Board (ITSC)Min. 3 directors; chaired by independent director with IT expertise; CISO/CTO board reporting lineQuarterlyIT strategy, IT risk appetite, cyber risk review; minutes evidence MD-ITGRC §4
SEBI — CSCRF 2024Board-level Cybersecurity Committee + CISOCISO with direct board reporting; committee for MII/QRTA/RE-T1Policy review annual; committee per charterCSCRF policy approval, CCI sign-off, incident oversight
IRDAI — 2023 GuidelinesInformation Security Committee (ISC) + CISOBoard-constituted ISC; CISO appointment letter on fileQuarterlyIS policy approval, SAR review, incident and BCP oversight
DPDP Act §10Data Protection Officer (SDFs only)India-based DPO with board-level reporting; contact publishedContinuousDPIA programme, algorithm audits, grievance escalation point
Companies Act 2013 + SEBI LODRRisk Management Committee (top-1000 listed)Majority board members; chaired by a board memberAt least twice a yearCyber risk explicitly in RMC charter per LODR; risk policy review
CERT-In Directions 2022Designated Point of ContactNamed PoC communicated to CERT-InContinuousReceives directions, coordinates 6-hour reporting

Made with Emergent