Compliance · India

Four regulators, one control set.

An Indian bank, broker or insurer is rarely subject to one cyber instrument. It is subject to several at once, with controls that overlap almost entirely and clocks that do not — and the usual response is to run each as its own programme.

SemperWise Research Desk 9 min read Compliance
Each one assumes the one above it is finished 1 Data map 2 Notice & consent 3 Rights 4 Breach 5 Retention 6 Children's data 7 Processors 8 Safeguards 9 SDF duties start not here Map first — starting at two means doing two twice

Consider an ordinary NBFC with a securities arm. It is subject to the RBI Cyber Security Framework for its lending business, the SEBI CSCRF for its market-facing entity, and the CERT-In Directions across everything, because those apply to service providers and body corporates generally rather than by sector. An insurer has a similar picture with IRDAI in place of RBI. A listed company with none of those licences still has CERT-In, and DPDP arriving underneath all of it.

Read the instruments side by side and the striking thing is how much they agree. Access control, least privilege and periodic recertification. Patch and vulnerability management with timelines. Hardened configuration. Network segmentation. Encryption in transit and at rest. Logging that is retained and reviewed. Penetration testing on a cycle with findings closed and retested. Backups with restoration actually tested. Incident response that has been exercised. Third-party due diligence that continues after onboarding.

That is the same control set four times over, expressed in four vocabularies. And yet the common organisational response is four programmes, four spreadsheets, four sets of evidence, and four separate scrambles before four separate audits.

Where they genuinely differ

The overlap is real but it is not total, and the differences are exactly the parts that get missed when an organisation assumes "we do ISO 27001, so we are covered".

CERT-In: the clock starts at noticing

Six hours to report a listed incident, counted from noticing it — not from confirming it, completing triage or obtaining sign-off. An incident process that requires certainty before it escalates has designed itself into breach. Plus 180 days of logs held *within Indian jurisdiction*, which a 400-day archive in a foreign region does not satisfy.

RBI: the policy must stand alone

The framework is explicit that the cyber security policy is a separate, board-approved document, not a section of the IT policy. And the C-SOC is assessed on functional efficacy — a monitoring contract that has never produced an alert anybody acted on evidences nothing.

SEBI CSCRF: capability, not documentation

Obligations scale across five categories of regulated entity, so the first deliverable is establishing which one you are. The Cyber Capability Index turns resilience into a measured number for the larger categories, and SBOM and API security appear as requirements in a way the older circulars never had.

IRDAI: governance is assessed on its own terms

A board-approved policy reviewed annually, a CISO with a reporting line independent of the function that runs IT, and an Information Security Committee whose minutes are the evidence. A CISO reporting to the CTO is a recurring finding, and it is a cheap thing to fix before an audit and an awkward one to explain during it.

Run one programme, map it outward

The alternative to four programmes is not a shortcut, and it is not a spreadsheet with four columns. It is a single internal control set that each instrument maps onto — so that implementing a control once produces evidence that satisfies every instrument requiring it, and adding a new regulator is a mapping exercise rather than a new programme.

Concretely, that means three things.

  1. One control, many references.

    Your access recertification control is one control. It carries ISO 27001 A.5.18, RBI's user access control requirement, SEBI's identity and access management standard, IRDAI's recertification requirement and DPDP's reasonable security safeguards. One owner, one test date, one artefact — referenced five ways rather than performed five times.

  2. Applicability recorded with its reasoning.

    Several controls will legitimately not apply to you: SEBI obligations differ by RE category, RBI expectations by institution type. Record the exclusion *and why*. A Statement of Applicability that explains its omissions is worth considerably more to an inspector than one that simply lacks the row — and it is the difference between a defensible scope and a gap.

  3. Evidence with a date and an expiry.

    This is the part that decides whether the whole approach holds. An artefact collected once and never re-collected is not evidence of a current control; it is history. Access reviews, restoration tests, VAPT reports and audit-log reviews all have a shelf life, and the programme has to know when each one runs out rather than discovering it during an audit.

The part that testing actually settles

One more overlap is worth naming, because it is the one where the effort genuinely collapses. Every one of these four instruments requires security testing on a cycle, with findings tracked to closure and retested. RBI names vulnerability assessment, penetration testing and red team exercises. SEBI prescribes a VAPT cycle. IRDAI requires VAPT including after significant change, alongside an annual information security audit by a CERT-In empanelled auditing organisation. The testing is one exercise.

What usually prevents it from being one exercise is not the testing — it is the reporting. A pentest report arrives as a PDF of findings; somebody then maps those findings by hand onto the RBI requirement, the CSCRF control and the ISO clause, and does it again next quarter. That manual step is where the single-programme idea breaks down in practice, and it breaks down quietly, because nobody notices the mapping was skipped until the control has no evidence behind it.

The fix is to have findings arrive already mapped. A finding about a weak cipher suite is evidence about encryption in transit under every framework that requires it, and there is no reason a person should be retyping that relationship.

A note on what cannot be bought

None of these four is a certification. There is no CERT-In compliance certificate, no RBI cyber security certificate, no CSCRF certificate and no IRDAI certificate — they are statutory and regulatory obligations, assessed through inspection, audit and reporting. Anybody offering to certify you against them is selling something that does not exist.

Two related things are real and are frequently confused with it. CERT-In empanelment is a status held by auditing organisations, not a compliance mark for the entity being audited — and IRDAI requires the annual information security audit to be performed by an empanelled one. And CSCRF requires ISO 27001 certification of the critical systems estate for the larger SEBI entity categories — a certificate issued by an accredited certification body, never by a consultancy. Knowing which of these is which is, by itself, a useful filter when choosing who to work with.

SemperWise Research Desk

Compliance & Regulatory Research

Tracks primary sources — regulator notifications, standards bodies and audit guidance — and turns them into practical checklists our delivery teams use on live engagements. Every figure is checked against its original source before publication.

Next step

Talk to us about your next assessment.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.