Governance, Risk & Compliance

The RBI baseline, evidenced rather than asserted.

The RBI Cyber Security Framework is a baseline, which is a polite word for a floor. Inspections do not ask whether you have a policy covering each requirement; they ask to see the requirement working.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
25Annex-1 baseline requirements
C-SOCAssessed on efficacy
BoardA separate approved policy
TestedNot merely documented

Where banks lose marks

The framework sets an indicative baseline of cyber security and resilience requirements, a Cyber Security Operations Centre expectation, and an incident reporting obligation to the Reserve Bank. Larger institutions run it alongside the wider IT governance, risk and assurance expectations; smaller co-operative banks and NBFCs often meet it for the first time under inspection pressure.

Three findings recur. **The cyber security policy is folded into the IT policy** — the framework is explicit that it must be a distinct, board-approved document, and a combined one is a finding on its own. **Logs are collected but not reviewed**, which satisfies the letter of the audit-log requirement and none of its intent. And **backups exist but restoration has never been tested**, which is the difference between a resilience control and a resilience intention.

The fourth, and the one that costs most at inspection, is the C-SOC: it is assessed on functional efficacy. A monitoring contract that has never produced an alert anybody acted on does not evidence the requirement, however much it costs.

Coverage

What we work on

The Annex-1 baseline, and the three annexures around it.

Gap assessment against the baseline

Each numbered requirement assessed against evidence, with the shortfalls and a remediation plan carrying owners and dates — which the framework asks for explicitly.

Board-approved cyber security policy

Distinct from the IT policy, owned at board level, and reviewed on a cycle you can show.

C-SOC functional efficacy

Whether the monitoring in place actually detects, analyses and drives response — tested, not assumed.

VAPT and red team exercises

Periodic testing by a competent party, findings tracked to closure and retested. Our engagements evidence this requirement directly.

Audit logs that get read

Collection, retention, protection from alteration, and a review rhythm that produces a record of having reviewed.

Backup and tested restoration

Backups protected from the same compromise as production, and restoration exercised with the result written down.

Incident response and RBI reporting

A tested plan, and the reporting path in the prescribed template within the timeline the circular sets.

Vendor and outsourcing risk

Security obligations in contracts, assessment before onboarding, and continued monitoring in a register rather than a folder.

Approach

How the engagement runs

Assess against evidence, close with owners and dates, test what the framework says must be tested.

  1. 01 · Baseline gap assessment

    Every Annex-1 requirement assessed against real evidence. The output is the gap assessment and remediation plan the framework itself asks for.

  2. 02 · Close and evidence

    Remediation with owners and dates, and the artefact for each requirement identified as it is closed rather than reconstructed later.

  3. 03 · Test what must be tested

    VAPT, restoration, incident response. The requirements that say "tested" are the ones inspections sample first.

  4. 04 · Keep it true

    Controls and evidence maintained in SemperWise One™, so the position holds between the assessment and the inspection.

In the platform

What SemperWise One carries for this framework.

Not a claim about coverage in the abstract — this is the clause library and the evidence collection that ship today.

29
Clauses in the library

Each one carried as a control with its own state, owner, test date and evidence — not a checklist item.

5
Artefacts collected automatically

Gathered on a cycle and filed against the clauses they evidence, with a collection date and an expiry.

22
Control subjects it spans

Of the 29 subjects our unified control model defines. This is what makes a second framework cheaper than the first.

How the framework divides up

  • 3 Governance
  • 2 Access
  • 2 Data
  • 2 Detection
  • 2 Logging
  • 2 Incident

Evidence the platform gathers by itself

  • Who had access
  • Policies in force
  • Audit trail continuity
  • Security safeguards in force
  • Processors engaged

Each artefact carries a collection date and an expiry, because evidence that is two years old is not evidence — it is history. When one lapses, everything resting on it is flagged rather than left quietly asserting something that stopped being true.

Already hold another framework? Most of the subjects here are ones your existing programme already covers. SemperWise One works out which, clause by clause, and proposes them — it never marks anything verified on your behalf, because verified means evidenced, and the evidence has to be pointed at this framework deliberately.

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Baseline gap assessment

Requirement by requirement, with the evidence reviewed and the shortfall stated.

Remediation plan

Owners, dates and dependencies — in the form the circular expects.

VAPT report with closure tracking

Findings verified, tracked and retested, mapped to the requirement they evidence.

Live control register

Each requirement with its state, owner, test date and dated evidence, ready for inspection.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • You are a bank, co-operative bank or NBFC preparing for an RBI inspection.
  • Your cyber security policy is a section of the IT policy.
  • You have a SOC contract and no evidence that it has ever driven a response.
  • Restoration from backup has not been tested in the last twelve months.
  • A previous inspection raised cyber findings that are still open.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

RBI Cyber Security — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Is this a certification?

No. The framework is a supervisory expectation set by the Reserve Bank, assessed through inspection and audit. There is no RBI cyber security certificate. What we provide is the gap assessment, the remediation, the testing and the evidence that stands up when it is examined.

Does it apply to NBFCs and co-operative banks?

RBI has extended cyber security expectations across regulated entity types, with requirements scaled to the entity. The practical answer for a smaller institution is that the baseline is the right reference point even where the full circular is not directly applicable — and the gap assessment establishes which requirements apply to you before any work starts.

How does this relate to the IT Governance Master Direction?

Institutions subject to the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices should treat the cyber security framework as the cyber-resilience baseline inside that wider programme rather than as a separate exercise. We run both off one control set, which is the advantage of holding them in a single platform instead of two spreadsheets.

Can you act as our C-SOC?

We assess C-SOC efficacy and can operate monitoring as a managed service. Where you already have a SOC, the more valuable engagement is usually the efficacy assessment — it is the part inspections probe, and the part most institutions have never had tested.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.