NBFC ¶36: measure the training, and keep the repository
The RBI Directions, 2026 place four separately auditable requirements on an NBFC in one paragraph. What ¶36 asks for, phrase by phrase, and what has to exist before a supervisor asks to see it.
The NBFC Direction writes the awareness obligation as a specification. In one paragraph the Reserve Bank names four things: a mechanism, a property to be measured, the shape the measurement takes, and a record to be kept. Two sentences, four requirements, each separately auditable.
This is a reading of the clause phrase by phrase, and of what has to be in front of a supervisor for each part.
The clause, and where it sits
The Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for NBFCs were issued on 31 July 2026, in force on issuance. The training obligation is Section C.12, Training, at ¶35–36, page 19.
¶35. “The NBFC shall establish and implement a robust, ongoing information security training and awareness program for all users…”
¶36. “The NBFC shall deploy a formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing. The NBFC shall also maintain an up-to-date repository of the training and awareness status of all users.”
¶35 establishes the programme. ¶36 attaches to it — such training points back at the ¶35 programme — and sets out how the NBFC is to know whether it worked, and what record survives it.
The construction binds NBFCs and no one else. Commercial banks at ¶202, payments banks and small finance banks at ¶201, and credit information companies at ¶197 each carry a single differently-worded sentence: “evaluate the awareness level of employees periodically”. Urban co-operative banks carry a prescribed method instead, at ¶156, in Chapter V, which binds Level III and Level IV UCBs.
¶36 is the most prescriptive awareness clause in the six Directions, which cuts both ways: more of the answer is fixed, and the clause itself describes what the answer looks like.
1. A formal mechanism
The verb is deploy. What has to exist is an operating thing, not a statement of intent in a policy document.
Formal carries the rest of the weight. A mechanism is formal when it is written down before it is used, owned by a named function, and repeatable by someone other than whoever ran it last. The working test: could a colleague run the next cycle from the document alone and produce a comparable number? A method that lives in one person’s memory, or that is adjusted each cycle to suit the result, is an exercise repeated rather than a mechanism deployed.
Described to a supervisor, a formal mechanism sets out at least the following, and does not change without a recorded reason:
- the population it applies to, and the cohorts within it;
- the interval, fixed in advance rather than fitted around availability;
- the instrument, and how it is prepared;
- the measures, defined precisely enough that two people compute them identically;
- where results are recorded, and who receives them;
- what follows a result, and who decides it.
The clause also pairs two verbs: measure and track. Measurement produces a reading; tracking keeps the series. A mechanism that yields one number a year and retains nothing to set beside it satisfies the first verb and not the second.
2. Effectiveness, which is a property of the result
The object of measurement is “the effectiveness of such training”. Not its coverage, not its completion, not its quality as courseware. Whether it worked.
The distinction is easiest to see in the artefacts an organisation already holds. An attendance register, an LMS completion percentage, a course pass mark, a certificate: each is a record of delivery. They are the right evidence for ¶35, and they belong in the repository the second sentence asks for. What they establish is that the training reached people.
A measure of effectiveness is taken outside the training, against the behaviour the training was meant to change, at a moment when the person is not aware they are being measured for that purpose. It answers a different question: when the situation the module described actually appears, what does the workforce do?
Effect also implies a before and an after. A single reading describes a state; effectiveness shows in the movement between readings taken the same way, which is why the clause asks for the series and not only the number. The first measurement is the baseline the rest are read against.
3. Through periodic assessments or testing
The clause names the shape. Two forms are offered, and they are not the same instrument.
An assessment puts a question to the user and scores the answer: a knowledge quiz, a scenario-based questionnaire, a judgement exercise. It measures what people know and can recall. The Directions treat it as a recognised instrument — the Urban Co-operative Banks Direction prescribes a web-based quiz outright at ¶156.
A test puts the behaviour itself in front of the population under conditions resembling the real thing, and records what happens. A simulated phishing campaign against a defined population is one form; a vishing call against the service desk procedure is another. What a test measures is conduct rather than recall, which is the thing the training was intended to change.
Phishing simulation is a method of discharging ¶36, not a term the paragraph uses. The clause requires periodic assessments or testing and leaves the instrument to the NBFC. A simulation run against a defined population and reported at population level answers it because it produces what the clause asks for: a repeatable measurement of behaviour, over a population, that can be set beside the last one.
On cadence, the clause fixes the property and leaves the interval to the NBFC to set and to defend. An interval is defensible when it is written into the mechanism in advance, covers the whole population within a stated cycle rather than re-testing a convenient sample, and is short enough that the repository can honestly be called up to date between cycles. Comparability usually decides the number: readings taken far apart, or under instruments of drifting difficulty, cannot be read as a trend.
Where the testing is conducted by a CERT-In empanelled auditing organisation, two rules govern how it runs. CISG-2025-02 §13.2.7(ii), p. 50 requires that “specific written permissions must be obtained” from the auditee organisation before process testing or social engineering. §15.2.2(iii), pp. 55–56 requires that testing aimed at general staff “must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized”, since “the purpose is to evaluate overall awareness and the effectiveness of security processes”. Authorisation is settled first; the reading that comes back is a population figure.
4. An up-to-date repository of the status of all users
The second sentence is a separate obligation with its own verb: the NBFC shall maintain a repository. Three constraints sit inside one phrase.
Of the training and awareness status. Two statuses, joined by and. Where each user stands against the ¶35 programme, and where the awareness measurements taken under the first sentence place them. A record holding only the first is a training record; the clause names both.
Of all users. ¶35 uses the same population term for the programme itself. Completeness is a property of the artefact: a record covering the people who happened to fall inside the last campaign is not the one ¶36 describes. Joiners, movers and leavers pass through it continuously, which makes it an operational dataset rather than a report.
Up-to-date. The clause is in the present tense, and it decides whether the artefact exists at all. A repository assembled in the fortnight after a supervisor asks for it was, at the moment of the request, three fragments: results in a vendor portal, completions in an LMS export, and last quarter’s figure on a slide.
The two halves of ¶36 meet here. A test conducted under the anonymisation rule returns cohort figures rather than names, and that is what enters the repository from the testing side: a cohort, a date, the instrument, the measurement. The per-user rows carry training status and coverage.
A repository of identified individuals is personal data, and the Digital Personal Data Protection Act, 2023 applies: s.8(5) requires reasonable security safeguards, and s.8(7)(a) requires erasure “as soon as it is reasonable to assume that the specified purpose is no longer being served”. The current status of all users serves a live regulatory purpose; the raw response dataset from a single campaign has a shorter useful life than the measurement drawn from it.
What ¶36 asks you to be able to produce
| The phrase | What it asks for | What answers it |
|---|---|---|
| “deploy a formal mechanism” | A defined, owned, repeatable method | The written method — owner, population, cohorts, interval, instrument, measures — carried unchanged between cycles |
| “measure and track the effectiveness” | A reading of what the programme changed, and the series it belongs to | Measurement taken outside the training, against the behaviour it targets, with earlier readings retained and comparable |
| “through periodic assessments or testing” | The instrument and the interval | A cycle set in advance, covering the population, with the authorisation recorded where an external party runs it |
| “an up-to-date repository … of all users” | A complete and current record | Both statuses, the whole population, current at the moment of the request |
The four parts fail separately. An NBFC can run a well-attended programme with a completion rate near a hundred per cent and still be short of the first sentence, because completion is delivery. It can run a good annual test and still be short of the second, because the status of all users sits across three systems and none is current. ¶36 asks for both, in one place, with the method behind them written down before anyone enquires who ran it.
About the author
Richa Sunar
VP — Business Development
Drives business development and strategic partnerships at Security Brigade, expanding the firm's footprint across industry verticals and geographies.
Continue reading
All articles →Spear phishing versus bulk simulation: what changes in the test and in the numbers
A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a six-person cohort is reported when a percentage would identify people.
Scoping a phishing simulation programme in India
What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the escalation contacts and the written authorisation CERT-In requires.
Measuring the executive population
RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual result. What an executive exercise reports instead.