Regulation is constant, not scheduled

26 of the 30 cybersecurity clauses in the RBI Master Direction, 2023, mapped to the controls that produce their own evidence.

An inspection team arrives, names a quarter from 18 months ago, and asks what access existed, who approved it, and what was done with it. Obligations are graded by size and licence, which sets how much you report and how often, not which controls have to exist. The 2023 Master Direction is the baseline standard across regulated entities, and 30 of its 103 granular items are cybersecurity controls.

  • Who this applies to
  • Which module carries which clauses
  • What sits outside
26 / 30
Cybersecurity clauses of the Master Direction mapped

Who this applies to

Banks, NBFCs, cooperative banks, payment operators and fintechs. The Master Direction is deliberately generic rather than tied to one licence type, which is why it is the baseline that applies across regulated entities of very different sizes.

Which module carries which clauses

ModuleClausesCount
Audit logging and security monitoring8(c), 15(a), 15(b), 15(c), 25(c), 27(b), 30(f)7
IAM, contextual access control10(d), 19(a), 20(a), 23(c), 25(c)5
MDM20(c), 20(d), 23(d), 25(b)4
UEM, endpoint hardening policies20(d), 23(d), 25(b)3
IGA8(c), 9(b), 19(a)3
PAM19(b), 19(c), 23(c)3
IAM, adaptive MFA19(c), 20(b)2
IAM, cloud directory23(a)1
IAM, single sign-on20(a)1
CIAM Consent Manager10(d)1

30 mapping points across 26 clauses, because several clauses are carried by more than one module.

What sits outside

The remaining 73 items in the Master Direction are IT governance, business continuity, capacity planning, vendor management and audit process. Those need other systems and other teams.

Tell us which framework you're being measured against.

Send us the framework, the audit date and what you already run. We'll come back with the mapping for your environment and the evidence Akku produces for each control.