🏦 RBI Cloud Guidelines
RBI Cloud Guidelines — Practical Checklist
Actionable checklist from RBI's cloud adoption framework for Indian banks, NBFCs, and regulated financial entities. IT governance, risk assessment, data localisation, vendor management, audit, and exit strategy.
📋 Based on: RBI Master Direction on IT (2023), RBI circular on Cloud Adoption, and Guidelines on IT Governance and Controls for REs (Regulated Entities). Always read the primary RBI circulars alongside this reference.
Who Must Comply
RBI Master Direction on Information Technology, 2023
| Entity Type | Scope | Board Approval Required? | RBI Intimation Required? |
|---|---|---|---|
| Scheduled Commercial Banks | All cloud adoption | Yes — Board IT Committee | Yes — before migration |
| Small Finance Banks / Payments Banks | All cloud adoption | Yes | Yes |
| NBFCs (Upper Layer / Middle Layer) | All cloud adoption for core systems | Yes | Inform RBI — not pre-approval |
| NBFCs (Base Layer) | Cloud for non-core systems | Senior Management approval | Not required |
| Payment Aggregators / Gateways | All cloud adoption | Yes | Yes — for core payment systems |
| Cooperative Banks | Cloud adoption with customer data | Board awareness required | Not required |
Key Principles — RBI's Position on Cloud
RBI's Master Direction on IT (2023) does not prohibit cloud adoption. It requires that REs adopt cloud in a manner that maintains operational resilience, data security, regulatory compliance, and supervisory access. The key principles are:
→
Technology Neutrality: RBI permits cloud adoption (public, private, hybrid, community) — the security and governance requirements are the same regardless of deployment model.
→
Responsibility Stays with the RE: Outsourcing to a cloud provider does not outsource regulatory responsibility. The RE remains fully accountable to RBI for compliance, even if a cloud provider is at fault.
→
Data Localisation — Non-Negotiable: Payment system data must be stored only in India. No exception for cloud. Cloud providers' India regions must be used — not routed through global infrastructure.
→
Supervisory Access — Mandatory: RBI must be able to access, audit, and inspect the RE's cloud environment and data at any time. This must be contractually secured from the cloud provider.
→
Concentration Risk Management: Heavy dependence on a single cloud provider creates systemic risk. REs must manage this through multi-cloud strategies or documented mitigations.
🏛️ IT Governance Checklist
RBI Master Direction on IT 2023 — Chapter on IT Governance
0 / 8 completed
Board IT Committee approval obtained for cloud adoption Board-level IT Committee or full Board (depending on materiality) must approve the cloud strategy, risk appetite, and vendor selection.
Mandatory
Cloud Strategy Document approved by Board Formal cloud strategy document covering: objectives, service model, deployment model, risk appetite, provider selection rationale, data classification.
Mandatory
IT Risk Framework updated to include cloud risks Existing IT Risk Framework must be updated to cover cloud-specific risks: data sovereignty, provider dependency, multi-tenancy, shared infrastructure.
Mandatory
CISO designated as responsible for cloud security CISO must be designated as the owner of cloud security policy and must have direct reporting to Board/MD/CEO on cloud risks.
Mandatory
Cloud Governance Policy approved Formal policy covering: permitted cloud services, data classification for cloud, IAM standards, incident response, exit process.
Mandatory
Cloud adoption notified to RBI (if required) Banks and systemically important NBFCs must intimate RBI before migrating core banking systems to cloud.
Mandatory for banks
Annual review of cloud strategy by Board IT Committee Cloud usage, risks, incidents, and strategy must be reviewed by Board annually.
Mandatory
Concentration risk assessed and documented Single cloud provider dependency risk must be assessed. If material concentration exists, mitigation plan documented.
Mandatory
⚠️ Cloud Risk Assessment Requirements
0 / 8 completed
Pre-migration risk assessment completed Mandatory
Risk assessment covers third and fourth-party risks Mandatory
Business Continuity and DR plan updated for cloud Mandatory
Penetration testing and VA of cloud configuration Mandatory — annual
Multi-tenancy risk assessment Mandatory
Regulatory reporting capability from cloud verified Mandatory
Cloud incident classification in risk register Mandatory
Insurance coverage reviewed for cloud risks Recommended
🇮🇳 Data Localisation Checklist (RBI-Specific)
0 / 8 completed
Payment system data stored exclusively in India Mandatory — zero tolerance
End-to-end transaction data, payment credentials, customer payment data — stored only in cloud provider's India regions (AWS ap-south-1/ap-south-2, Azure India Central/South, GCP asia-south1/asia-south2).
No cross-region replication to non-India regions enabled Mandatory
Cloud storage replication must NOT include non-India regions. AWS S3 Cross-Region Replication: only ap-south-1 ↔ ap-south-2 permitted. Verify explicitly.
Data residency contractually committed by cloud provider Mandatory
Cloud provider agreement includes explicit data residency clause: data stored only in India regions, no access from outside India without RE consent.
Data classification completed — payment vs non-payment Mandatory
Formal data classification identifying which data is payment system data (must be in India) and which is other data.
Data lineage mapped — all systems touching payment data Mandatory
Complete map of which cloud services process or store payment data — to ensure all are in India regions.
DR/backup site also in India (for payment data) Mandatory
If payment data is replicated for DR, the DR site must also be in India.
Sub-processors of cloud provider confirmed to be in India Mandatory
Cloud provider must disclose if sub-processors (CDN, analytics, support services) access India payment data. Foreign sub-processor access to payment data not permitted.
International transaction data — India copy confirmed Mandatory
For cross-border transactions, a copy of the end-to-end transaction data must be stored in India even if processing occurred outside India.
🤝 Cloud Vendor Management Checklist
0 / 10 completed
Cloud Service Level Agreement (SLA) reviewed by IT and Legal Mandatory
SLA must specify: uptime guarantees, incident response timelines, data recovery timelines, support access. Must be adequate for banking operations.
Regulatory audit rights secured in contract Mandatory — RBI requirement
Contract must grant RBI and the RE's auditors the right to audit the cloud provider's facilities, processes, and data relevant to the RE's operations.
Data portability terms specified Mandatory
Contract must specify: data format for export, timeline for providing data on request (max 30 days), format must be open standard (not proprietary).
Sub-contractor disclosure clause included Mandatory
Cloud provider must notify RE of any changes to material sub-contractors who process RE's data.
Breach notification commitment in contract Mandatory
Provider must notify RE of any security breach affecting RE's data within 6 hours (aligned with CERT-In requirements).
Governing law — Indian courts specified Mandatory
Disputes involving RE's data must be subject to Indian law and Indian court jurisdiction.
Concentration risk from single provider documented Mandatory
If using single cloud provider for >30% of IT operations, document concentration risk and mitigation plan.
Annual vendor performance review conducted Mandatory
Annual review of cloud provider performance against SLA, security incidents, compliance posture.
Approved cloud providers list maintained Mandatory
Maintain a Board-approved list of cloud providers authorised for different data classifications.
Business continuity from provider failure tested Mandatory
Test scenario: cloud provider becomes unavailable. Can you operate? How long? This must be tested, not just documented.
🔍 Audit & Compliance Checklist
0 / 8 completed
Annual IT audit covers cloud configuration Annual — mandatory
Cloud Security Assessment by CERT-In empanelled auditor Annual — mandatory
CloudTrail / Cloud Audit Logs retained for 7 years Mandatory
Log integrity verified — logs cannot be tampered Mandatory
Cloud security controls mapped to RBI IT Framework controls Mandatory
System Audit Report (SAR) submitted to RBI Annual — mandatory
RBI inspection access confirmed and tested Mandatory
Cloud configuration change log maintained Mandatory
🚪 Cloud Exit Strategy Checklist
⚠️ RBI explicitly requires all regulated entities to have a tested exit strategy before adopting cloud. An exit strategy is not optional — it must be documented, approved by the Board, and periodically tested.
0 / 8 completed
Exit strategy document approved by Board Mandatory — Board approval
Data export format tested and verified Mandatory
Data export timeline tested Mandatory — test annually
Alternative infrastructure identified Mandatory
Application portability assessed Mandatory
Exit cost estimated Mandatory
Exit trigger criteria defined Mandatory
Exit drill conducted Annual recommended
📁 Required Documents for RBI Cloud Compliance
Board Resolution on Cloud Adoption
Board-level approval for cloud strategy, signed and dated.
Cloud Strategy Document
Objectives, model, provider, risk appetite. Board approved.
Cloud Governance Policy
Permitted services, data classification, IAM standards, incident response, exit process.
Cloud Risk Assessment Report
Pre-migration risk assessment covering all risk categories.
IT Risk Framework (Cloud Updated)
Existing IT Risk Framework updated to include cloud-specific risks.
Data Classification Policy (Cloud)
Which data is payment data (India only), which is non-payment, and handling rules for each.
Data Lineage Map
Which systems and cloud services process or store each data category.
Cloud Service Agreement
Provider contract with: data residency, audit rights, portability, breach notification, SLAs.
Vendor Due Diligence Report
Assessment of cloud provider's security, compliance, financial stability, sub-contractors.
BCP/DR Plan (Cloud Revised)
Updated BCP/DR including cloud provider outage scenarios with tested RTO/RPO.
Exit Strategy Document
Board-approved exit plan with tested timelines and alternative infrastructure.
Annual VAPT Report (Cloud)
CERT-In empanelled auditor cloud security assessment report.
System Audit Report (SAR)
Annual SAR submitted to RBI with cloud compliance annexure.
Cloud Incident Response Plan
Cloud-specific IR plan: isolation procedures, evidence collection, CERT-In reporting.
Cloud Concentration Risk Assessment
Analysis and mitigation plan for single-provider dependency.