Regulation is constant, not scheduled

26 of the 30 cybersecurity clauses in the RBI Master Direction, 2023, mapped to the controls that produce their own evidence.

An inspection team arrives, names a quarter from 18 months ago, and asks what access existed, who approved it, and what was done with it. Obligations are graded by size and licence, which sets how much you report and how often, not which controls have to exist. The 2023 Master Direction is the baseline standard across regulated entities, and 30 of its 103 granular items are cybersecurity controls.

26 / 30
Cybersecurity clauses of the Master Direction mapped

Who this applies to

Banks, NBFCs, cooperative banks, payment operators and fintechs. The Master Direction is deliberately generic rather than tied to one licence type, which is why it is the baseline that applies across regulated entities of very different sizes.

Which module carries which clauses

Module and clauses mapping
ModuleCountClauses
Audit logging and security monitoring7
IAM, contextual access control5
MDM4
UEM, endpoint hardening policies3
IGA3
PAM3
IAM, adaptive MFA2
IAM, cloud directory1
IAM, single sign-on1
CIAM Consent Manager1

30 mapping points across 26 clauses, because several clauses are carried by more than one module.

What sits outside

The remaining 73 items in the Master Direction are IT governance, business continuity, capacity planning, vendor management and audit process. Those need other systems and other teams.

Tell us which framework you're being measured against.

Send us the framework, the audit date and what you already run. We'll come back with the mapping for your environment and the evidence Akku produces for each control.