Skip to main content

The awareness clauses of the RBI Directions, 2026, entity by entity

The RBI Directions, 2026 carry an employee awareness obligation for every supervised entity, and the paragraph number differs in each. Which clause binds a bank, an NBFC, a CIC or a UCB, and what each one asks for.

By Chintan Joshi
August 31, 20266 min read

The Reserve Bank of India issued six Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions on 31 July 2026, one for each supervised category, and every one of them carries an employee awareness obligation. The paragraph number is different in each. So is the cadence, and in one case so is the prescribed method. A compliance calendar built from the Commercial Banks Direction is wrong for the other five entity types, and it is wrong in substance rather than in numbering: the obligations differ in what they ask an organisation to produce.

This is the entity-by-entity reading. Which paragraph binds you, what it says, and what it asks you to be able to show.

The Directions separate measuring from training

In the Commercial Banks Direction, Section BB, User / Employee / Management Awareness, runs to ¶198–204 across pages 47–48. Three of those paragraphs carry the weight, and the regulator has drawn them apart deliberately.

¶202. “The bank shall evaluate the awareness level of employees periodically.”

That is a standing obligation to measure, and it stands as its own paragraph. The obligation to train sits in the next one.

¶203. “The bank shall establish a mechanism for continuous and adaptive capacity building to strengthen cybersecurity management. Cybersecurity awareness programmes shall be mandatory for all new recruits, and annual training shall be conducted for lower and middle management.”
¶204. “…The bank shall also provide annual training to all Board members and Senior Management on IT and cybersecurity risks and evolving best practices.”

Read in sequence: a mandatory programme at induction, annual training for lower and middle management, separate annual training for the Board and Senior Management, and, as its own requirement, periodic evaluation of how aware employees actually are.

Delivery and measurement are two obligations. Evidence that one was discharged is not evidence for the other. An attendance register answers ¶203. It does not answer ¶202.

¶202 is written at the level of the outcome. It fixes what is to be evaluated, the awareness level of employees, and the frequency, and leaves the instrument to the bank.

Which paragraph binds which entity

All six were issued on 31 July 2026 and are in force on issuance.

EntityParagraphWhat it requires
Commercial Banks¶202, ¶203, ¶204 (Section BB, pp. 47–48)Evaluate the awareness level of employees periodically. Awareness programmes mandatory for all new recruits, and annual training for lower and middle management. Annual training for all Board members and Senior Management
Payments Banks¶201Evaluate the awareness level of employees periodically
Small Finance Banks¶201Evaluate the awareness level of employees periodically
Credit Information Companies¶197“The CIC shall evaluate the awareness level of employees periodically”
Urban Co-operative Banks¶156, ¶157 (Section H, p. 39)Mandatory awareness programmes for new recruits, and a web-based quiz and training for lower, middle and upper management every year. Board members sensitised periodically. Section H sits in Chapter V, so this binds Level III and Level IV UCBs
NBFCs¶35, ¶36 (Section C.12, p. 19)An ongoing training and awareness programme for all users, and a formal mechanism to measure and track its effectiveness through periodic assessments or testing, with an up-to-date repository of the status of all users

The sentence “evaluate the awareness level of employees periodically” appears in four of the six, at four different numbers. Cite ¶202 to a payments bank and the number does not point at the clause you mean.

NBFCs: the clause reads as a specification

The NBFC Direction places the obligation in Section C.12, Training, at ¶35–36 on page 19, and writes it more tightly than any of the others.

¶35. “The NBFC shall establish and implement a robust, ongoing information security training and awareness program for all users…”
¶36. “The NBFC shall deploy a formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing. The NBFC shall also maintain an up-to-date repository of the training and awareness status of all users.”

¶36 has four parts, and each of them is separately auditable:

  • a formal mechanism, meaning a defined and repeatable method rather than an occasional exercise;
  • measurement of effectiveness, which is a property of the training and not of its delivery;
  • through periodic assessments or testing, which names the shape the method takes;
  • an up-to-date repository of the training and awareness status of all users, a retained artefact covering the whole population and current at the moment it is asked for.

The repository is the part that has to exist before the request rather than after it. Campaign results sitting in a vendor portal, an attendance sheet for one course, and a slide showing last quarter's click rate are three fragments. ¶36 asks for the status of all users, kept current.

Urban co-operative banks: a prescribed method, and a Level test before it

¶156. “The UCB shall conduct mandatory cybersecurity awareness programs for new recruits and web-based quiz and training for lower, middle, and upper management every year.”

Two features of this paragraph shape the programme. It names a delivery method, a web-based quiz. And its annual cycle reaches upper management, where the Commercial Banks Direction runs its annual training to lower and middle management at ¶203 and handles the Board and Senior Management separately at ¶204. ¶157 adds that the UCB “shall sensitise its Board members on various technological developments and cybersecurity related developments periodically.”

The applicability question comes first, though, and it is the one most easily missed. Section H sits in Chapter V. The applicability table at ¶4 assigns chapters by Level: Level I carries Chapters II and III, Level II adds Chapter IV, Level III adds Chapter V, and Level IV adds Chapter VI. ¶156 therefore binds Level III and Level IV UCBs, and the Level is set by Centralised Payment Systems membership and the criteria in that table. A statement of “the UCB awareness obligation” that omits the Level is being applied to the wrong banks.

Awareness is a reported metric, not only an activity

Two further paragraphs in the Commercial Banks Direction pull awareness into measurement and reporting. ¶194 requires a comprehensive set of metrics and lists illustrative ones, among them “extent of user awareness training”. ¶197 goes further:

“The adequacy of and adherence to cybersecurity framework shall be assessed and measured through development of indicators to assess the level of risk / preparedness. The awareness among the stakeholders including employees may also form a part of this assessment.”

Between ¶194, ¶197 and ¶202, awareness appears three times in the same Direction as something to be measured, indicated and evaluated. That is the shape of the obligation. A number, produced repeatedly, over a defined population, with a method behind it that can be described to an auditor.

The phishing paragraph that is a different obligation

Commercial Banks ¶148 requires the bank to “subscribe to anti-phishing / anti-rogue app services from external service providers for identifying and taking down phishing websites / rogue applications.” The counterpart is ¶147 for payments banks and small finance banks, ¶143 for credit information companies, and ¶123 for urban co-operative banks.

That is a takedown obligation, discharged by subscribing to an external service and evidenced by what happens to a fraudulent site. It shares a word with the awareness paragraphs and it belongs on a different row of the compliance matrix.

What to hold

  1. The Direction and the paragraph. Identify the instrument that binds the entity, and cite the number inside it rather than the number from the Commercial Banks text.
  2. For UCBs, the Level first. Chapter V applies to Level III and Level IV, so the Level determines whether ¶156 is in scope at all.
  3. The two obligations, kept apart. Training records answer the training paragraph. Evaluation results answer the evaluation paragraph.
  4. The cadence, by population. New recruits at induction, lower and middle management annually, the Board and Senior Management annually under ¶204, and for UCBs an annual cycle reaching upper management under ¶156.
  5. The evidence, and where it lives. For NBFCs this is explicit at ¶36: an up-to-date repository of the training and awareness status of all users, retained and current.

Where the obligation is to evaluate awareness across a workforce, the practical question is which instrument produces a number that means something, and what it leaves behind. A spear phishing campaign run against a defined population on a fixed cadence, reported at population level, is one method of discharging an evaluation obligation. The NBFC construction at ¶36, “periodic assessments or testing”, describes that shape directly.

About the author

Chintan Joshi

CISO & Director — Security Advisory

Oversees Security Brigade's cybersecurity advisory practice, helping regulated enterprises meet RBI, SEBI, CERT-In, and IRDAI compliance mandates. Previously held senior security leadership roles across BFSI.