Infosek
INFOSEK

RBI IT Framework for NBFCs: Tier-wise Requirements Explained

RBI's IT framework applies differently to NBFCs based on asset size and category. This guide explains tier-wise IT governance, IS audit, and cybersecurity requirements for NBFC-ICC, NBFC-ML, HFCs, and MFIs.

RBI IT Framework for NBFCs: Tier-wise Requirements Explained

The RBI IT Framework: An Overview

The Reserve Bank of India issued its Master Direction on Information Technology Framework for the NBFC Sector to address growing IT and cybersecurity risks in the non-banking financial sector. The framework applies to all NBFCs registered with RBI, but the depth of requirements varies based on the NBFC's category and asset size. The primary categories covered include NBFC-Investment & Credit Companies (NBFC-ICC), NBFC-Micro Finance Institutions (NBFC-MFI), NBFC-Factors, Mortgage Guarantee Companies, Housing Finance Companies (HFCs), and others.

The framework covers five broad areas: IT Governance, IT Infrastructure & Services Management, IT and Cyber Security, Business Continuity Planning, and IT Audit.

Tier Classification: How It Works

RBI classifies NBFCs primarily by asset size. The largest NBFCs — particularly those with assets above ₹500 crore — face substantially more detailed requirements than smaller entities. The scale-based approach means:

IT Governance Requirements

All NBFCs above a certain size are required to establish a board-level IT Strategy Committee or assign IT oversight to an existing board committee. Key governance requirements include:

IS Audit Requirements

RBI requires IS audits for NBFCs, and the auditor qualification requirements are specific. For larger NBFCs, the IS audit must be conducted by an auditor with CISA (Certified Information Systems Auditor) certification or equivalent. The audit must cover all IT systems, applications, network infrastructure, and cybersecurity controls. Key points:

BCP and Disaster Recovery Requirements

Cybersecurity Controls

NBFCs that partner with fintechs through digital lending arrangements face an additional layer of IT requirements. The digital lending infrastructure — apps, APIs, LSP systems — must all be covered by your IT governance framework, not just your core CBS.

Infosek Team

Common Compliance Gaps

If your NBFC is also active in digital lending, additional requirements apply — see our guide on RBI Digital Lending Guidelines: 10 Mistakes Lenders Are Still Making in 2025. For NBFCs in DLG arrangements with fintechs, our article on RBI DLG Rules Explained covers the specific compliance implications.

Common questions

How does RBI classify NBFCs for IT compliance?

Primarily by asset size. The largest NBFCs, particularly those with assets above 500 crore rupees, face substantially more detailed requirements including a full IT governance framework, a board-level IT committee, an annual IS audit, a comprehensive cyber security policy, a disaster recovery site with defined RTO and RPO, and a vendor management policy.

Who can conduct the RBI information systems audit?

RBI's IT framework requires the IS audit to be carried out by a CISA-certified auditor. This is a different requirement from SEBI's, which specifies a CERT-In empanelled auditor.

Topics RBI

Get your DPDP readiness assessment today.

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment