IBA Control Catalogue — IBA Model Cyber Policy
Key areas from the IBA Model Cybersecurity Policy and adjacent master circulars, mapped to RBI MD-ITGRC where applicable.
| # | Area | Key IBA Guidance | RBI Cross-Reference |
|---|---|---|---|
| 1 | Information Security Governance | Board IT/Risk Committee, CISO with board reporting line, annual cyber risk appetite, dedicated cyber risk budget — IBA template board charters available | Aligns with MD-ITGRC §4 (Governance) — IBA expands RBI principles into model board minutes and charter language |
| 2 | Cyber Hygiene Programme | Employee security awareness at induction + annual refresh; quarterly phishing simulation campaigns; secure coding practices for in-house developers; SOC monitoring of unusual access patterns | Maps to MD-ITGRC §22 (Awareness & Training) — IBA prescribes specific simulation cadences |
| 3 | Vendor Risk (TPRM) | IBA template TPRM questionnaire (200+ items) for banks to issue to fintech partners; tiered vendor classification; annual on-site audit for critical vendors | Maps to MD-ITGRC §4 (TPRM) + Outsourcing of IT Services MD 2023 |
Sign in to unlock — every free trial includes full Pro access to the deep-dive catalogues.
Sign in to unlockIBA guidance is non-binding but referenced by RBI in supervision. Verify the source IBA document before relying on any specific clause.