26 of the 30 cybersecurity clauses in the RBI Master Direction, 2023, mapped to the controls that produce their own evidence.
An inspection team arrives, names a quarter from 18 months ago, and asks what access existed, who approved it, and what was done with it. Obligations are graded by size and licence, which sets how much you report and how often, not which controls have to exist. The 2023 Master Direction is the baseline standard across regulated entities, and 30 of its 103 granular items are cybersecurity controls.

Banks, NBFCs, cooperative banks, payment operators and fintechs. The Master Direction is deliberately generic rather than tied to one licence type, which is why it is the baseline that applies across regulated entities of very different sizes.
| Module | Clauses | Count |
|---|---|---|
| Audit logging and security monitoring | 8(c), 15(a), 15(b), 15(c), 25(c), 27(b), 30(f) | 7 |
| IAM, contextual access control | 10(d), 19(a), 20(a), 23(c), 25(c) | 5 |
| MDM | 20(c), 20(d), 23(d), 25(b) | 4 |
| UEM, endpoint hardening policies | 20(d), 23(d), 25(b) | 3 |
| IGA | 8(c), 9(b), 19(a) | 3 |
| PAM | 19(b), 19(c), 23(c) | 3 |
| IAM, adaptive MFA | 19(c), 20(b) | 2 |
| IAM, cloud directory | 23(a) | 1 |
| IAM, single sign-on | 20(a) | 1 |
| CIAM Consent Manager | 10(d) | 1 |
30 mapping points across 26 clauses, because several clauses are carried by more than one module.
The remaining 73 items in the Master Direction are IT governance, business continuity, capacity planning, vendor management and audit process. Those need other systems and other teams.