Skip to content

Evidence request lists

RBI Cybersecurity Framework for Banks

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Data Protection

RBIBANK-4
Data Protection, Encryption, Customer Data Security

Per RBI Cyber Framework: data protection. Requirements include (a) data classification + handling + (b) encryption at rest + in transit + (c) data loss prevention + (d) customer data security per PMLA + DPDPA + (e) cross-border data transfer compliance + (f) maintain documented data protection.

Artefacts an auditor will ask for
  • RBI Cyber evidence for RBIBANK-4
Where this commonly fails
  • 6-hour incident reporting + concurrent audit + Board approval partial

Governance

RBIBANK-1
Board-Approved Cybersecurity Policy, Crisis Management

Per RBI Cybersecurity Framework for Banks: governance. Requirements include (a) maintain Board-Approved Cybersecurity Policy aligned to RBI master direction + (b) maintain Cyber Crisis Management Plan including detection + response + recovery + (c) maintain Inventory of Information Assets + classification + (d) implement governance structure including CISO + Chief Risk Officer + (e) report to Board + senior management + (f) cooperate with RBI inspections.

Artefacts an auditor will ask for
  • RBI Cyber evidence for RBIBANK-1
Where this commonly fails
  • 6-hour incident reporting + concurrent audit + Board approval partial

Identity Access

RBIBANK-3
Identity Access, Authentication, Privileged Access Management

Per RBI Cyber Framework: identity + access. Requirements include (a) Identity and Access Management + (b) Multi-Factor Authentication for sensitive systems + (c) Privileged Access Management (PAM) + (d) periodic access review + recertification + (e) maintain audit + (f) align with RBI MITM/phishing-resistant authentication.

Artefacts an auditor will ask for
  • RBI Cyber evidence for RBIBANK-3
Where this commonly fails
  • 6-hour incident reporting + concurrent audit + Board approval partial

Incident Response

RBIBANK-6
Incident Response, Reporting to RBI, CERT-In

Per RBI Cyber Framework + CERT-In Directions: incident response. Requirements include (a) incident response capability + (b) report cyber incidents to RBI within 6 hours per RBI Master Direction + (c) report to CERT-In within 6 hours per CERT-In Directions 2022 + (d) maintain incident log + (e) tabletop exercises + (f) integrate with broader IR.

Artefacts an auditor will ask for
  • RBI Cyber evidence for RBIBANK-6
Where this commonly fails
  • 6-hour incident reporting + concurrent audit + Board approval partial

Technical Controls

RBIBANK-2
Network Security, Configuration Hardening, Application Security

Per RBI Cyber Framework: technical controls. Requirements include (a) Network Security and Segmentation + (b) Secure Configuration and Hardening + (c) Application Security including web + mobile + API + (d) Endpoint protection + EDR + (e) integrate with broader InfoSec baseline + (f) maintain testing + monitoring.

Artefacts an auditor will ask for
  • RBI Cyber evidence for RBIBANK-2
Where this commonly fails
  • 6-hour incident reporting + concurrent audit + Board approval partial

Third-Party Risk

RBIBANK-7
Third-Party Risk, Outsourcing, Cloud

Per RBI Cyber Framework + Cloud Guidelines + Outsourcing Master Direction: third-party. Requirements include (a) third-party risk management + (b) cloud computing per RBI guidelines + (c) outsourcing contracts + concurrent audit + (d) ongoing monitoring + (e) right to audit + (f) cooperate with RBI inspections of third parties.

Artefacts an auditor will ask for
  • RBI Cyber evidence for RBIBANK-7
Where this commonly fails
  • 6-hour incident reporting + concurrent audit + Board approval partial

Training and Awareness

RBIBANK-8
Training, Awareness, Customer Education

Per RBI Cyber Framework: training. Requirements include (a) staff training role-based + (b) Board + senior management training + (c) customer education campaigns + (d) phishing simulations + (e) maintain training records + (f) measure effectiveness.

Artefacts an auditor will ask for
  • RBI Cyber evidence for RBIBANK-8
Where this commonly fails
  • 6-hour incident reporting + concurrent audit + Board approval partial

Vulnerability and Threat

RBIBANK-5
Vulnerability Management, Patching, Threat Intelligence

Per RBI Cyber Framework: vulnerability + threat. Requirements include (a) vulnerability assessment + penetration testing + bug bounty + (b) patching aligned to risk + (c) threat intelligence + IOC integration + (d) SOC + SIEM + (e) maintain documented programme.

Artefacts an auditor will ask for
  • RBI Cyber evidence for RBIBANK-5
Where this commonly fails
  • 6-hour incident reporting + concurrent audit + Board approval partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.