The Reserve Bank issued its Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices on 7 November 2023. It is the framework that sits above the more specific rules on digital lending and payment data, and it governs how a regulated financial entity organises technology as a whole. For a software firm, it matters because it determines who at your client can approve what, and how much evidence they need from you.
Coverage is broad: all banking companies, NBFCs, credit information companies, EXIM Bank, NABARD, National Housing Bank and SIDBI. Foreign banks operating through branch mode follow a comply-or-explain approach. Local area banks, NBFC core investment companies and base layer NBFCs are outside its scope. Establishing which side of that line your client sits on is the first question in any scoping conversation, because the difference in obligation is substantial.
The governance structure is prescribed in detail. A board-level IT Strategy Committee with at least three directors, chaired by an independent director, whose members must be technically competent, meeting at least quarterly. A senior, technically competent official heading the IT function. A Chief Information Security Officer reporting directly to the executive director responsible for risk management, sitting as a permanent invitee on governance committees and owning the Security Operations Centre. And an IT Steering Committee at senior management level with both IT and business representation, also meeting at least quarterly.
That structure has a practical consequence for vendors that is easy to miss. Decisions you might expect a head of engineering to make — adopting a platform, changing an architecture, onboarding a service provider — may require committee approval on a quarterly cycle. A project plan that assumes decisions can be taken in a week will slip, not because the client is slow but because their governance does not permit it. Building the committee calendar into your delivery plan is the difference between a realistic timeline and an optimistic one.
The direction also requires structured cyber incident response and recovery management, business continuity and disaster recovery frameworks, and information systems audit provisions. For a supplier, that means your software becomes part of an audited estate: someone will ask for your access control model, your change management evidence, your incident notification commitments and your own security posture. Preparing that pack once, and keeping it current, turns a recurring interrogation into a document exchange.
The strategic reading is that the RBI has been steadily raising the bar on technology governance across the sector, and it flows downhill to suppliers. A software firm that understands the committee structure, speaks accurately about the CISO's reporting line, and arrives with audit evidence unprompted is treated as a serious partner. One that has to be walked through it consumes the client's compliance capacity, and that is remembered at renewal.