India Hub/RBI/Control Catalogue
Layer 1 · Risk Managers · Auditors — implementation

RBI Control Catalogue

Every control domain from MD-ITGRC 2023, numbered, in plain English with entity scope and 2023 status.

Last verified: 2026-06-17
#Domain / Control AreaKey Requirement (Plain English)Entity ScopeStatus
1IT Governance StructureBoard must constitute an IT Strategy Committee; CTO/CISO must have board-level reporting line; IT risk integrated into enterprise risk frameworkBanks, NBFCs (asset >₹1000 Cr), UCBsNew 2023
2Information Security PolicyBoard-approved IS policy reviewed annually; covers data classification, access control, incident response, and third-party riskAll REsUpdated 2023
3IT Risk AssessmentFormal IT risk assessment at least annually; results reported to Board IT Committee; risk appetite statement for IT risk definedAll REsUpdated 2023
Unlock all 22 rows — Pro

Sign in to unlock — every free trial includes full Pro access to the deep-dive catalogues.

Sign in to unlock

Catalogue curated from MD-ITGRC 2023. Always verify against the source Master Direction at rbi.org.in before relying on a clause.

Made with Emergent