RBI door. Cybersecurity, outsourcing, STR / CTR.

RBI compliance without the inspection panic.

RBI Cybersecurity Framework, outsourcing register, SAR/CTR filings, CERT-In 6-hour reporting, DPDP for customer data. Every obligation, one evidence trail, inspection-ready. Structured checklists mapped to RBI IT Framework 2016, Cyber Security Directions 2023, and the outsourcing directions, with control-level evidence collection and an audit archive that survives supervisory queries.

✓ RBI IT Framework 2016
✓ Cyber Security Directions 2023
✓ Outsourcing Guidelines
⚠ 3 controls need attention
Last assessed: Today
Real-time RBI compliance posture dashboard
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.

Your last RBI inspection cited three evidence gaps and you resolved them with a 40-page reply. You know it will happen again.

Your outsourcing register is a spreadsheet that one person maintains.

STR and CTR filings are done by the compliance team on the last day of the month, from memory.

The CERT-In 6-hour incident reporting window scares you because you're not sure who owns it.

Also worth a look if you are a licensed fintech: the Fintech door covers RBI CSF + CERT-In + DPDP as a stack.

Your regulator stack

Here's what sits above the foundation.

RBI-regulated entities live under a layered stack. The RBI Cybersecurity Framework is the operational spine. Outsourcing directions govern every vendor relationship. PMLA drives STR and CTR filings. CERT-In's 2022 directions sit on top for incident reporting. DPDP applies to customer data on the side. dcomply ships modules for each layer.

DPDP Act 2023 (customer data)
Consent capture, DSR portal for account holders, breach notification for personal data incidents.
CERT-In Directions 2022
6-hour incident reporting, 180-day log retention, KYC on VPN and crypto users where applicable.
PMLA (STR / CTR)
Suspicious Transaction Reports, Cash Transaction Reports, AI-drafted narratives, PMLA-compliant format.
RBI Outsourcing Directions
Vendor register in RBI format, DPA chain, exit playbook, concentration risk monitoring.
RBI Cybersecurity Framework
The foundation for regulated entities. Control library, evidence collection, inspection archive.
The Problem

RBI Circulars Are Complex and Constantly Changing

Banks and NBFCs face a maze of overlapping RBI directives, manual tracking leads to missed deadlines and audit findings.

Circular Overload

Hundreds of RBI circulars across IT, cyber, outsourcing, and data, impossible to track manually

Audit Findings

Non-compliance with RBI IT framework and cyber security directions leads to costly audit observations

Reporting Deadlines

Cybersecurity incident reporting to RBI has strict timelines, manual processes cause missed deadlines

Capabilities

Everything You Need for RBI Compliance

IT Framework & Cyber Security Directions

Structured checklist mapped to RBI IT Framework 2016, Cyber Security Directions 2023, and Master Directions with control-level tracking.

Outsourcing & Third-Party Risk

Track obligations under RBI outsourcing guidelines, vendor risk assessments, and concentration risk monitoring for critical service providers.

Incident Reporting Workflows

Automated workflows for cyber incident reporting to RBI with deadline alerts, template generation, and escalation tracking within prescribed timelines.

Board & Management Reporting

Auto-generate compliance dashboards for Board IT Committee and CISO reporting as required under RBI governance directives.

Circular Update Alerts

Get instant alerts when RBI issues new circulars, master directions, or FAQs relevant to your entity type, banks, NBFCs, or payment systems.

Compliance Posture Score

Real-time compliance score across all RBI frameworks with gap identification, risk prioritization, and remediation action tracking.

NBFC Compliance Calendar

Pre-loaded NBFC-specific regulatory filing calendar, quarterly, half-yearly, and annual returns mapped to RBI deadlines with automated reminders and filing status tracking.

Business Continuity Plan (BCP) Checklists

Structured BCP review checklists aligned with RBI guidance, document BCP testing schedules, recovery time objectives, last test results, and board-approved BCP status for audit readiness.

What's Included

Full RBI Compliance Coverage

Every major RBI regulatory framework mapped to actionable controls with evidence collection and audit trail.

RBI IT Framework 2016, all 6 domains

Governance, IT infrastructure, information and cyber security, IT operations, IS audit, and business continuity.

Cyber Security Directions 2023 mapping

All 22 controls with implementation guidance, evidence templates, and compliance tracking.

Outsourcing guidelines checklist

Due diligence, contract review, exit plan, concentration risk, and sub-outsourcing tracking.

Incident response timelines

6-hour and 24-hour reporting windows tracked with automated reminders and report generation.

RBI compliance FAQs

Questions CISOs and Chief Compliance Officers actually ask.

The RBI compliance surface is wide. These are the questions we get on almost every implementation call.

The Reserve Bank of India regulates non-banking financial companies through: NBFC Master Direction (governance), Cybersecurity Framework, IT Framework Master Direction, Digital Lending Guidelines 2022, Fair Practices Code, KYC Master Direction, and prudential norms on capital adequacy, provisioning, asset classification and reporting.

RBI Cybersecurity Framework for NBFCs (2017, refreshed 2023) classifies NBFCs into base, mid, and top layers. Base layer requires a board-approved policy and basic hygiene. Mid layer adds CISO, VAPT twice a year, and SOC. Top layer requires a full SOC 24/7, CBK, and cyber-insurance. Incident reporting to RBI is within 2 to 6 hours depending on severity.

RBI Digital Lending Guidelines 2022 apply to digital lending platforms and loans disbursed through digital channels by regulated entities or their partners. Key requirements include consent-based data access, no third-party servers outside India, no unsolicited credit line increases, a key fact statement in the prescribed format, and a cool-off period for borrowers.

RBI KYC Master Direction requires 5-year retention post account closure, 10-year for suspicious transactions. DPDP requires deletion on purpose exhaustion. The reconciliation is that RBI-retained fields are legally retained but blocked for secondary use. dcomply's Razorpay adapter implements this pattern.

RBI Fair Practices Code requires NBFCs to publish loan terms transparently, communicate rate changes with reasonable notice, follow a non-coercive recovery process, and address borrower grievances within 30 days. dcomply's FPC module tracks each principle.

RBI requires various supervisory returns (DNBS-1 to DNBS-10 depending on NBFC category). dcomply pre-populates from operational data and organises evidence for RBI inspections. Advocates from Decipher Consultancy handle any inspection queries.

dcomply is a software platform, not a service under the RBI outsourcing framework. You own the compliance decisions and the evidence. dcomply provides the workspace and the record-keeping.

The Cybersecurity Framework, Outsourcing of Financial Services, and IT Governance directions are covered by native modules. Sector-specific directions such as digital lending and PA/PG are handled by module extensions and are being expanded continuously.

You feed the transaction data via CSV or API. The module drafts the STR narrative, applies the PMLA structure, and routes it for compliance sign-off before filing.

dcomply is often used alongside enterprise GRC platforms for the RBI-specific record-keeping the GRC platform does not natively cover.

When an incident is logged, the module starts a 6-hour clock, enforces the mandatory fields required by the 2022 Directions, and routes the notification to CERT-In with the audit chain preserved.
Real teams, real programmes

"That conversation was over in an hour."

"The RBI inspection team asked for the outsourcing evidence. We opened the vendor register in dcomply and shared read-only access. That conversation was over in an hour."
Chief Compliance Officer, a mid-sized NBFC out of Mumbai.

Stay Ahead of RBI Audits

Automate RBI compliance tracking and never miss a deadline or audit finding

View All Features