BFSI · GLOSSARY · EDITION I

The plain-English glossary for Indian BFSI compliance.

132 terms that decide whether software clears an Indian audit — grouped by regulator, written for buyers.

132
terms
8
regulator groups

Regulators

8 terms
CCA

The Controller of Certifying Authorities licenses and regulates certifying authorities for digital signatures and electronic signatures under the IT Act.

Why it matters · eSign and DSC workflows depend on whether the signing method is legally valid and issued through licensed trust infrastructure.

DSCAadhaar eSignIT Act §5
CERT-In

The Indian Computer Emergency Response Team is India’s national agency for cyber incident response and reporting directions.

Why it matters · Vendors must help BFSI customers detect, classify, preserve logs, and report incidents within regulatory timelines.

CERT-In Direction April 2022VAPT
IRDAI

The Insurance Regulatory and Development Authority of India regulates insurers, insurance intermediaries, and insurance-sector governance.

Why it matters · Insurance software must handle sensitive personal data, claims data, policyholder records, intermediary access, and cyber controls.

IRDAI Cyber GuidelinesPIIData Fiduciary
MeitY

The Ministry of Electronics and Information Technology is India’s central ministry for digital policy, including the IT Act and DPDP framework.

Why it matters · MeitY-led rules affect privacy, data processing, digital signatures, cyber policy, and compliance design for all digital vendors.

DPDP ActIT Act 2000CERT-In
NPCI

The National Payments Corporation of India operates major retail payment rails such as UPI, IMPS, RuPay, NACH, and Aadhaar-linked payment infrastructure.

Why it matters · Payment, mandate, lending, collections, and account-verification tools often touch NPCI-linked rails.

e-NACHeMandateAccount Aggregator
RBI

The Reserve Bank of India is India’s central bank and the primary regulator for banks, NBFCs, payment systems, and many digital lending workflows.

Why it matters · RBI-regulated buyers care deeply about outsourcing, IT governance, cyber resilience, customer data, auditability, KYC, digital lending, and operational risk.

RBI IT GovernanceRBI Outsourcing Master DirectionDigital LendingKFS
SEBI

The Securities and Exchange Board of India regulates India’s securities markets, including brokers, mutual funds, exchanges, depositories, portfolio managers, and market infrastructure institutions.

Why it matters · SEBI buyers often require stronger cybersecurity, cyber resilience, SOC monitoring, incident classification, and technology-risk controls.

SEBI CSCRFType-A BrokerMIICyber-SOC
UIDAI

The Unique Identification Authority of India runs Aadhaar and governs Aadhaar authentication and e-KYC use.

Why it matters · Vendors touching Aadhaar workflows must support the right authentication, consent, identity, security, and ecosystem requirements.

Aadhaar OTPAadhaar eSigne-KYC

Acts & Regulations

12 terms
CERT-In Direction April 2022

CERT-In’s 2022 directions require specified entities to report listed cyber incidents within six hours of noticing or being informed of them.

Why it matters · Vendors must preserve logs, detect incidents fast, provide reporting evidence, and support forensic readiness.

CERT-InVAPT
Cybersecurity, Technology: Risk, Resilience and Assurance Framework
Featured

The common title of seven RBI Directions issued on 31 July 2026, one per licence class — commercial banks, small finance banks, payments banks, urban co-operative banks, all India financial institutions, NBFCs and credit information companies. All commenced on issuance.

Why it matters · This is the framework that replaced the 2016 Cyber Security Framework and the 2023 Master Direction on IT Governance. There is no transition period: obligations applied from the day they were published.

RBIDAKSHCSOCRepeal Circular
DPDP Act 2023

India’s Digital Personal Data Protection Act creates obligations for processing digital personal data, including notice, consent, duties of data fiduciaries, and rights of data principals.

Why it matters · BFSI vendors handling customer data must support consent, data minimization, retention, security, breach handling, and contractual processing controls.

Data FiduciaryData PrincipalSignificant Data Fiduciary
DPDP Rules 2025

The Digital Personal Data Protection Rules, 2025 operationalize parts of the DPDP Act, including phased commencement for specific obligations.

Why it matters · Buyers need to know whether vendors can support compliance timelines, notices, consent mechanisms, child-data handling, and breach workflows.

Consent ManagerNegative List
IRDAI Information & Cyber Security Guidelines (2023, superseded)

IRDAI’s 2023 guidelines strengthen information and cyber security governance for insurers and insurance intermediaries.

Why it matters · Insurance buyers require security governance, access control, data classification, encryption, incident management, and third-party controls.

IRDAI
IT Act 2000

The Information Technology Act gives legal recognition to electronic records, electronic signatures, cyber offences, certifying authorities, and certain security practices.

Why it matters · It decides when electronic records and electronic signatures are legally recognized in India.

IT Act §5DSCAadhaar eSign
IT Reasonable Security Practices Rules 2011

These rules define reasonable security practices for sensitive personal data under India’s IT framework.

Why it matters · They remain relevant for baseline security controls, privacy practices, consent, and sensitive personal information handling.

Reasonable Security Practices
PMLA

The Prevention of Money Laundering Act is India’s anti-money-laundering framework for reporting entities and financial-sector due diligence.

Why it matters · KYC, onboarding, transaction monitoring, screening, and record-retention tools often need PMLA-aware controls.

e-KYC
RBI Master Direction on IT Governance (repealed)

RBI’s IT governance direction sets expectations for governance, risk, controls, assurance, vendor risk, business continuity, and auditability for regulated entities.

Why it matters · Software vendors must fit into governance, audit, source-code, access, data-integrity, and third-party-risk controls.

RBI Outsourcing Master Direction
RBI Outsourcing Master Direction

RBI’s IT outsourcing direction governs how regulated entities manage third-party technology service providers and outsourced IT arrangements.

Why it matters · SaaS vendors become part of the regulated entity’s risk perimeter; contracts, audit rights, data controls, and exit plans matter.

Material OutsourcingConcentration Risk
Repeal Circular

DoS.CO.PPG.66/11.01.005/2026-27, dated 31 July 2026, which repealed 628 supervisory circulars as the Reserve Bank issued 64 consolidated Directions in their place.

Why it matters · If you are working from a circular issued before 31 July 2026, check this list first — the instrument you are citing may no longer exist.

Cybersecurity, Technology: Risk, Resilience and Assurance Framework
SEBI CSCRF

SEBI’s Cybersecurity and Cyber Resilience Framework sets cybersecurity and resilience expectations for SEBI-regulated entities.

Why it matters · Vendors serving brokers, AMCs, MIIs, and market intermediaries must support SOC, incident response, cyber drills, access controls, and resilience evidence.

Cyber-SOCType-A BrokerMII

Compliance Concepts

26 terms
AUC

Assets Under Custody — the measure CSCRF uses to band custodians.

Why it matters · A custodian is Qualified at ₹10 lakh crore of assets under custody, small-size below ₹1 lakh crore.

AUMQualified RE
AUM

Assets Under Management — the measure CSCRF uses to band alternative investment funds, mutual funds and portfolio managers.

Why it matters · Different entity types are banded at completely different AUM figures: ₹1,000 crore makes an AIF Qualified, while a mutual fund needs ₹1 lakh crore.

AUCQualified RE
BCP

Business Continuity Plan — the arrangements for continuing essential operations through a disruption.

Why it matters · Evidence a supervisor wants is restore tests with dates and outcomes, not backup success reports. A backup report proves data was written, not that it can be recovered.

DR DrillCyber Crisis Management Plan
CIO

Chief Information Officer — the executive accountable for IT delivery.

Why it matters · Named in the Directions mainly to keep the CISO away from them: a UCB CISO must not report to the CIO, because the person running the systems should not be the person assuring them.

CISO
CISO
Featured

Chief Information Security Officer. Under the NBFC Direction the CISO reports directly to the executive overseeing risk management; under the UCB Direction at Level IV, to the top executive overseeing risk or in their absence the MD and CEO.

Why it matters · The reporting line is the substance. A UCB CISO must have no direct reporting relationship with the CIO — an independence test, not a title. At Level II a UCB may designate an official who need not carry the CISO title at all.

CIOIT Strategy CommitteeIS Audit
Comply or Explain

A supervisory approach permitting deviation from a requirement where the entity can justify it to the regulator's satisfaction.

Why it matters · Foreign banks operating in India through branch mode get this route for selected requirements of the Commercial Banks Direction. It is not an exemption — the Reserve Bank has to accept the explanation.

Commercial Bank
Concentration Risk

The risk of relying too heavily on one vendor, cloud, geography, or service provider.

Why it matters · BFSI buyers need multi-vendor, multi-region, or exit strategies when one failure could affect critical operations.

Material Outsourcing
Contract Flow-Down
Featured

The requirement to impose named cybersecurity controls on a service provider through the contract itself. For UCBs this is 12 controls at paragraph 83 plus 34 baseline controls at paragraph 85; for commercial and payments banks it is 12 plus 23.

Why it matters · The most under-covered obligation in the family, and the one most likely to be forwarded inside a bank. It sits in Chapter III, so it binds every UCB from Level I — and existing core banking and switch contracts almost certainly do not carry these clauses. If the clause is not in the agreement, it is the bank that is short, not the provider.

ASPATM SwitchMaterial Outsourcing
Cyber Capability Index

CCI — the index CSCRF uses for MIIs and Qualified REs to monitor and assess cyber resilience over time.

Why it matters · Applies only to the top two bands. If you are a mid-size or smaller RE, this is not your obligation.

CSCRFMIIQualified RE
Cyber Crisis Management Plan

A board-approved plan for detecting, containing, responding to and recovering from a cyber incident.

Why it matters · A Chapter III obligation binding every UCB from Level I. A supervisor will ask for the plan and the date it was last exercised — an unexercised plan answers only half the question.

DAKSHCERT-InBCP
Cyber Resiliency Goals

Objectives that ensure systems can withstand, respond to, and recover from cyber incidents.

Why it matters · A product is not just judged by whether it prevents attacks, but whether it helps recover without business collapse.

SEBI CSCRF
DAKSH
Featured

The Reserve Bank's Advanced Supervisory Monitoring System, at daksh.rbi.org.in, through which regulated entities file cyber incident reports.

Why it matters · Cyber incidents must be reported on DAKSH within six hours of detection. This does not discharge the separate CERT-In obligation, which runs on its own six-hour clock to a different recipient.

CERT-InCyber Crisis Management Plan
Data Fiduciary

A person or organization that determines the purpose and means of processing personal data under the DPDP Act.

Why it matters · BFSI institutions are usually data fiduciaries; vendors may be processors but still need contractual and technical safeguards.

Data PrincipalDPDP Act 2023
Data Principal

The individual to whom personal data relates under the DPDP Act.

Why it matters · Customers, borrowers, policyholders, employees, and users may all be data principals whose rights must be supported.

DPDP Act 2023Consent Manager
DR Drill

A disaster recovery exercise testing whether systems can actually be restored at the recovery site.

Why it matters · Required at least half-yearly for critical systems under the NBFC, commercial bank, payments bank, AIFI and CIC Directions. The UCB Direction says only 'periodic intervals' — do not import the half-yearly figure into a UCB assessment.

BCPCyber Crisis Management Plan
Information Asset Inventory

A current register of information assets classified by criticality.

Why it matters · Chapter III section F, binding from Level I. The evidence expected is that it is maintained, not produced once for an audit.

DSPMDLP
IS Audit

Information Systems Audit. The UCB Direction requires an IS Audit Cell within the Inspection and Audit Department, working to a board-adopted policy and reporting to the Audit Committee of the Board.

Why it matters · This is a team and a reporting line, not a tool. No software satisfies it — worth knowing, because it appears in the same chapter as controls that genuinely are products.

IT Strategy CommitteeCISOVAPT
IT Strategy Committee

A board committee overseeing technology strategy, chaired by an independent director with substantial IT expertise — defined as at least seven years managing information systems or leading technology and cybersecurity initiatives.

Why it matters · A composition test with a number in it, not a statement of intent. It is the kind of requirement a board discovers it fails during a review rather than before one.

CISOIS Audit
Material Outsourcing

Outsourcing that materially affects business operations, customer service, risk management, compliance, or regulatory supervision.

Why it matters · If a SaaS product becomes operationally critical, procurement must evaluate audit rights, exit plans, concentration risk, and resilience.

RBI Outsourcing Master DirectionConcentration Risk
Reasonable Security Practices

Security controls considered adequate under applicable law, contracts, or regulatory expectations.

Why it matters · Buyers must map vendor controls to security baselines such as access control, encryption, logging, audit, and incident response.

VAPT
Risk-Based Supervision

A regulatory approach that applies deeper scrutiny where risk is higher.

Why it matters · Systemically important institutions, high-volume fintechs, and sensitive-data processors should expect tougher vendor reviews.

Significant Data FiduciaryTop Layer NBFCType-A Broker
Scale-Based Regulation

The Reserve Bank's four-layer classification of NBFCs — Base, Middle, Upper and Top Layer — by size, activity and perceived riskiness.

Why it matters · The NBFC cybersecurity Direction attaches chapters by layer, and within the Base Layer by an asset-size test at ₹500 crore.

Base LayerMiddle LayerUpper LayerTop Layer
Significant Data Fiduciary

A data fiduciary designated for heightened obligations based on factors such as volume, sensitivity, risk, and impact.

Why it matters · Large BFSI institutions may need stronger governance, audits, DPO-style ownership, and risk assessments.

DPDP Act 2023Data Fiduciary
TPRM

Third-Party Risk Management — assessing and monitoring the risk a supplier introduces.

Why it matters · A TPRM platform can track the contract flow-down exercise; it cannot perform it. Buying one does not put a clause into an agreement your provider has not signed.

Contract Flow-DownMaterial Outsourcing
UCB Level
Featured

The four-level grading in the UCB Direction. Level I binds every UCB; Level II adds Chapter IV; Level III adds Chapter V; Level IV adds Chapter VI. Higher levels carry everything beneath them.

Why it matters · Graded by digital services and payment-system interconnectedness, NOT by asset size. This is counter-intuitive and it is the single fact most small banks get wrong about their own obligations.

Sub-memberUPICentralised Payment Systems
UCC

Unique Client Code — the identifier by which a stock broker's active client base is counted.

Why it matters · The measure that decides a broker's CSCRF band. Qualified is above 5,00,000 active clients per UCC.

Qualified RERegulated Entity

Authentication & eSign

10 terms
Aadhaar eSign
Featured

A regulated electronic signature method that uses Aadhaar or other approved e-KYC-based authentication to issue a short-lived digital signature certificate.

Why it matters · Generic eSignature is not always enough; some Indian workflows need legally valid eSign under the IT Act framework.

CCAIT Act §5DSC
Aadhaar OTP

A one-time password sent to the mobile number linked to an Aadhaar number, used for Aadhaar authentication and certain e-KYC/eSign flows.

Why it matters · Retail lending, KYC, and Aadhaar-linked signing workflows may require Aadhaar-compatible identity verification.

Aadhaar eSignUIDAIe-KYC
Digital Signature Certificate (DSC)

A certificate issued by a licensed certifying authority that enables legally recognized digital signatures.

Why it matters · Board resolutions, statutory filings, high-assurance approvals, and certain regulated workflows may require DSC-grade signing.

CCAIT Act 2000
e-KYC

Electronic Know Your Customer verification, often using Aadhaar, offline XML, OTP, biometric, or other digital identity methods.

Why it matters · Onboarding tools must prove identity, preserve evidence, and avoid unauthorized Aadhaar or personal-data handling.

Aadhaar OTPUIDAI
e-NACH

Electronic National Automated Clearing House mandate setup for recurring payments and collections.

Why it matters · Lenders, insurers, and subscription-based BFSI products need mandate validity, authentication, and payment-rail integration.

NPCIeMandate
eMandate

A digital authorization that permits recurring debits from a customer’s account.

Why it matters · It affects lending collections, insurance premiums, SIPs, subscription finance, and repayment automation.

e-NACHNPCI
IT Act §5

Section 5 of the IT Act gives legal recognition to electronic signatures when prescribed conditions are met.

Why it matters · Buyers must distinguish between convenience signatures and signatures that satisfy Indian legal-recognition requirements.

Aadhaar eSignDSCCCA
MFA

Multi-Factor Authentication — requiring more than one independent factor to authenticate.

Why it matters · Required for privileged users and critical systems across the 2026 family, and part of the customer authentication framework at UCB Level II.

IAMSSOAadhaar OTP
SSO

Single Sign-On — one authentication event granting access to multiple applications.

Why it matters · Usually deployed alongside MFA. The control the Directions care about is the review trail, not the convenience.

IAMMFA
Video KYC

A video-based customer identification process used by regulated entities under KYC rules.

Why it matters · Vendor tooling must support recording, audit trails, consent, location checks, agent controls, and secure storage.

e-KYC

BFSI Entity Types

35 terms
Account Aggregator

A consent-based financial data-sharing entity under India’s account aggregator framework.

Why it matters · Tools integrated into AA workflows need strict consent, data minimization, security, and audit controls.

Consent ManagerData Fiduciary
AIF

Alternative Investment Fund — privately pooled investment vehicles registered with SEBI.

Why it matters · Banded by AUM under CSCRF: self-certification below ₹100 crore, Qualified at ₹1,000 crore and above.

AUMRegulated Entity
AIFI

All India Financial Institution. The 2026 Direction names five: EXIM Bank, NABARD, SIDBI, the National Housing Bank and NaBFID.

Why it matters · This is the Direction most often missing from secondary summaries of the family — which is how the claim that there are six Directions rather than seven gets into circulation.

Commercial Bank
AMC

An Asset Management Company that manages mutual fund schemes and investment products.

Why it matters · AMCs need investor-data controls, SEBI compliance, cybersecurity, access governance, and outsourcing oversight.

SEBISEBI CSCRF
ASP

Application Service Provider — a third party operating an application on a bank's behalf, most commonly the ATM Switch or the core banking platform.

Why it matters · Paragraphs 83 and 85 of the UCB Direction require named cybersecurity controls to be written into the contract with the switch ASP.

ATM SwitchContract Flow-Down
Base Layer
Featured

The lowest layer of the scale-based framework for NBFCs. The 2026 Direction splits it at ₹500 crore of assets: below that a Base Layer NBFC gets Chapter III, at or above it gets Chapter IV.

Why it matters · ₹500 crore, not ₹2,500 crore — a widely syndicated summary reports the higher figure, a five-fold error that would put a whole band of NBFCs in the wrong chapter. A Base Layer NBFC under ₹500 crore owes three paragraphs: no VA or PT, no six-hour DAKSH clock, no security operations centre.

Scale-Based RegulationCore Investment CompanyMiddle Layer
Commercial Bank

A banking company other than a small finance bank, payments bank or local area bank, together with the corresponding new banks and the State Bank of India.

Why it matters · Takes RBI/DoS/2026-27/410, which runs the same eight chapters as the SFB, payments bank, AIFI and CIC Directions. Foreign branches get a comply-or-explain route on selected requirements.

Comply or ExplainPayments Bank
Core Investment Company

An NBFC whose business is holding investments in group companies rather than lending to the public.

Why it matters · CICs sit with the smallest Base Layer band whatever their size, and are explicitly excluded from Chapter V — so a large CIC carries markedly lighter obligations than an NBFC of comparable size.

Base LayerScale-Based Regulation
Credit Information Company

An entity within the definition in section 2(e) of the Credit Information Companies (Regulation) Act, 2005 — the credit bureaus.

Why it matters · Takes RBI/DoS/2026-27/470, on the common eight-chapter shape with no internal grading.

AIFI
Direct Member

A bank holding membership of a centralised payment system in its own right, without a sponsor.

Why it matters · Direct membership reaches Level III on its own for a UCB, regardless of what digital services the bank offers.

Sub-memberCentralised Payment SystemsUCB Level
FPI

Foreign Portfolio Investor.

Why it matters · Explicitly excluded from submission of compliance with CSCRF.

Regulated EntityFVCI
FVCI

Foreign Venture Capital Investor.

Why it matters · Explicitly excluded from submission of compliance with CSCRF.

Regulated EntityFPI
InvIT

Infrastructure Investment Trust.

Why it matters · Excluded from submission of compliance with CSCRF, together with REITs.

REITRegulated Entity
KRA

KYC Registration Agency — entities holding centralised KYC records for the securities market.

Why it matters · Treated at par with the MII category for CSCRF applicability, so a KRA carries the heaviest band regardless of its size.

MIIRegulated Entitye-KYC
LPCC

Limited Purpose Clearing Corporation.

Why it matters · Excluded from submission of compliance with CSCRF.

Regulated Entity
Mid-size RE

The middle CSCRF band, again defined per entity type — a broker between 50,000 and 5,00,000 active clients, a mutual fund between ₹10,000 crore and ₹1 lakh crore of AUM.

Why it matters · Your band is fixed at the start of the financial year on the previous year's data and holds all year, whatever changes in between.

Qualified RESmall-size RE
Middle Layer

The second layer of the scale-based framework for NBFCs.

Why it matters · Middle, Upper and Top Layer NBFCs all take Chapter V of the 2026 Direction — the fullest set of obligations, including VA, PT, DR drills and a security operations centre.

Scale-Based RegulationBase LayerUpper Layer
MII

A Market Infrastructure Institution, such as a stock exchange, clearing corporation, or depository.

Why it matters · MIIs require very high resilience, availability, cyber governance, and operational continuity.

SEBISEBI CSCRF
NBFC-MFI

A non-bank finance company focused on microfinance lending.

Why it matters · Tools must support small-ticket lending, customer consent, repayment, collections, KYC, and RBI scrutiny.

KFS
Payment Aggregator

An entity that facilitates merchants in accepting payments from customers and settling funds.

Why it matters · Payment aggregators face RBI authorization, cybersecurity, data, settlement, and merchant-risk expectations.

RBI
Payments Bank

A differentiated bank licensed to accept deposits up to a prescribed limit and offer payment services, but not to lend.

Why it matters · Takes RBI/DoS/2026-27/428. The Directions apply as a whole — no internal grading, though a risk-based approach is permitted for non-critical systems.

Commercial BankSmall Finance Bank
QDP

Qualified Depository Participant.

Why it matters · Excluded from CSCRF compliance.

Regulated Entity
QRTA

Qualified Registrar to an Issue and Share Transfer Agent — the larger RTAs subject to enhanced obligations.

Why it matters · One of the categories that already had a cyber framework before CSCRF and so fell in the earlier tranche of the glide path.

RTAMII
Qualified RE
Featured

The second-highest CSCRF band. There is no single threshold: each entity type is graded on its own measure — a stock broker above 5,00,000 active clients, an AIF at ₹1,000 crore of AUM, a custodian at ₹10 lakh crore of assets under custody.

Why it matters · Commentary widely reports a universal '10 lakh clients' threshold. That figure appears nowhere in the circular's tables, and applying it would misclassify most entity types.

Mid-size RERegulated EntityCSCRF
Regulated Entity

SEBI's term for the nineteen entity types CSCRF applies to, from stock exchanges and depositories down to investment advisers and alternative investment funds.

Why it matters · Several RE types are excluded from CSCRF compliance altogether — foreign portfolio investors, foreign venture capital investors, REITs, InvITs, qualified depository participants, limited purpose clearing corporations and individual investment advisers.

CSCRFQualified REMII
REIT

Real Estate Investment Trust.

Why it matters · Excluded from submission of compliance with CSCRF, together with InvITs.

InvITRegulated Entity
RTA

Registrar to an Issue and Share Transfer Agent — entities maintaining investor records for issuers.

Why it matters · A CSCRF regulated entity. Qualified RTAs had their own pre-CSCRF cyber framework, now superseded.

Regulated EntityQRTA
Self-certification RE

The lightest CSCRF band, where compliance is self-certified. Credit rating agencies and collective investment schemes are placed here outright.

Why it matters · For a large share of SEBI's regulated population the honest answer is lighter than they have been told — worth checking before commissioning an audit you do not owe.

Small-size RERegulated Entity
Small Finance Bank

A bank category focused on financial inclusion, smaller borrowers, and underserved segments.

Why it matters · SFB software must handle banking-grade controls with often leaner operational teams.

RBI
Small-size RE

The lower CSCRF band, defined per entity type.

Why it matters · Non-individual investment advisers land here by assignment rather than by any threshold.

Mid-size RESelf-certification RE
Sub-member

A bank that reaches a centralised payment system indirectly, through a sponsor bank that holds direct membership.

Why it matters · A UCB reaches Level II only if it is a sub-member AND offers internet or mobile banking or holds CTS, IMPS or UPI membership. Both halves must be true — an OR reading promotes banks a level they do not belong in.

Direct MemberCentralised Payment SystemsUCB Level
Top Layer NBFC

The highest-risk layer in RBI’s scale-based NBFC regulatory framework.

Why it matters · A Top Layer NBFC should assume deep supervisory scrutiny and enterprise-grade vendor controls.

Risk-Based Supervision
Type-A Broker

A higher-risk or higher-scale securities intermediary classification under SEBI cyber frameworks.

Why it matters · Type-A entities often face stronger cyber, SOC, and resilience expectations than smaller intermediaries.

SEBI CSCRF
UCB
Featured

Urban Co-operative Bank, formally a Primary (Urban) Co-operative Bank. Roughly 1,500 operate in India.

Why it matters · The largest addressable universe under the 2026 family and the hardest self-assessment: most have no CISO, and the level test turns on operational facts rather than balance-sheet size.

UCB LevelSub-member
Upper Layer

The third layer of the scale-based framework, for NBFCs identified as warranting enhanced regulatory attention.

Why it matters · Takes Chapter V of the NBFC cybersecurity Direction, alongside Middle and Top Layer entities.

Scale-Based RegulationMiddle LayerTop Layer NBFC

Security Frameworks

24 terms
Anti-Phishing

Defences against phishing, including attacks that impersonate the bank to its own customers.

Why it matters · Chapter IV section J of the UCB Direction, attaching at Level II. It covers takedown arrangements for lookalike domains, not only inbound mail filtering.

DLPAudit Logs
Application Security Life Cycle

Building security into application development, from secure coding through source code audits to pre-release testing.

Why it matters · Chapter IV section E. Application security testing is required before go-live and after every major change — event-driven rather than calendar-driven.

OWASPSecure Configuration
Audit Logs

Records of system and user activity retained for investigation and supervisory review.

Why it matters · Chapter IV section M. A one-year security log retention requirement applies, and a supervisor will ask for a worked example of a real incident with its filing timestamps.

SIEMDAKSHCERT-In
CSOC
Featured

Cyber Security Operations Centre — round-the-clock monitoring, detection, escalation and forensic analysis of security events.

Why it matters · The same words mean very different things depending on your instrument. Under the common eight-chapter shape the CSOC is its own chapter binding every entity. Under the UCB Direction it is a Level IV obligation only — Levels I to III do not owe one.

SOCMarket SOCSIEMMDR
Cyber-SOC

A Security Operations Center that monitors, detects, investigates, and responds to cyber threats.

Why it matters · SEBI, RBI, and insurance cyber expectations increasingly reward operational monitoring, not just policy documents.

SEBI CSCRF
DLP

Data Leak Prevention — controls that stop sensitive data leaving the organisation across endpoints, network and cloud.

Why it matters · Chapter IV section K of the UCB Direction requires a data leak prevention STRATEGY, not merely a tool. A supervisor asks for the written strategy and evidence that the controls fire and are acted on.

DSPMInformation Asset Inventory
DSPM

Data Security Posture Management — discovery and classification of data across an estate, and assessment of its exposure.

Why it matters · The practical route to an information asset inventory that stays current. Finding the data is fast; remediating what it finds is not.

Information Asset InventoryDLP
EDR

Endpoint Detection and Response — endpoint agents that record behaviour and enable investigation and remote response.

Why it matters · EPP prevents; EDR investigates. The Directions require both anti-virus and the ability to detect and respond, and buyers frequently purchase one believing they bought both.

EPPMDR
EPP

Endpoint Protection Platform — preventive endpoint controls, principally anti-malware.

Why it matters · Chapter III section M of the UCB Direction requires anti-virus and section I requires preventing unauthorised software from running. Both bind from Level I.

EDR
IAM

Identity and Access Management — the systems governing who may reach what.

Why it matters · Chapter III section O and Chapter IV section H of the UCB Direction cover user access control; Chapter IV section I adds a customer authentication framework at Level II.

PAMMFASSO
Market SOC

A shared security operations centre that NSE and BSE were mandated by CSCRF to set up, providing monitoring to smaller SEBI regulated entities.

Why it matters · SEBI's answer to the problem that a small broker cannot realistically staff a 24x7 SOC. If you are a small-size or self-certification RE, this is likely your route.

SOCCSCRF
MDR

Managed Detection and Response — an outsourced service providing monitoring, detection and response, typically 24x7.

Why it matters · The realistic route to a CSOC for an institution that cannot staff one. What matters commercially is not the tooling but what the provider is permitted to do at 2am without calling you.

CSOCSOCSIEM
OWASP

The Open Web Application Security Project, whose Top Ten is the common reference for web application risks.

Why it matters · Named in the baseline controls a UCB must impose on its Application Service Providers by contract.

Application Security Life CycleContract Flow-Down
PAM

Privileged Access Management — controlling, recording and reviewing the use of administrative accounts.

Why it matters · Most PAM projects stall not because the product failed but because nobody could get the accounts into it. The evidence a supervisor wants is the access review trail and recorded privileged sessions.

IAMMFA
PT

Penetration Testing — a simulated attack conducted to establish what a real adversary could achieve.

Why it matters · Required at least annually for critical systems, and it must be performed by a competent independent assessor. A scanning platform produces findings; it does not discharge the testing obligation.

VAVAPTDMZ
Risk-Based Transaction Monitoring

Monitoring transactions against risk rules to detect anomalous or fraudulent activity.

Why it matters · Chapter V section I of the UCB Direction, attaching at Level III. A supervisor asks to see the system and the rules it actually runs.

SIEMUCB Level
SBOM

Software Bill of Materials — an inventory of the components inside a piece of software.

Why it matters · CSCRF names SBOM among its evolving security guidelines, alongside data classification and API security.

CSCRFTPRM
Secure Configuration

Maintaining systems to a defined hardened baseline rather than vendor defaults.

Why it matters · Chapter III section L and Chapter IV section D. Also one of the twelve controls that must be imposed on an ATM Switch provider by contract.

Contract Flow-DownDMZ
SIEM

Security Information and Event Management — collection and correlation of logs from across the estate to detect security events.

Why it matters · The licence is the small number; ingest volume drives the bill. Log retention against the one-year requirement is what a supervisor checks.

SOCAudit LogsMDR
SOC

Security Operations Centre — the team and tooling that monitors for and responds to security events. May be in-house, group-level, or a third-party managed service.

Why it matters · CSCRF requires every SEBI regulated entity to onboard a SOC, and explicitly permits using a Market SOC or a managed provider rather than building one.

CSOCMarket SOCMDR
VA

Vulnerability Assessment — automated and manual identification of known weaknesses in systems and applications.

Why it matters · Required at least every six months for critical and DMZ-facing systems across the 2026 family. Attaches from Level II for a UCB; a Level I bank does not owe a periodic VA.

PTVAPTDMZ
VAPT

Vulnerability Assessment and Penetration Testing identifies weaknesses before attackers exploit them.

Why it matters · Buyers must check whether vendors undergo regular testing and can share remediation evidence.

CERT-In
Zero Trust

A security model that assumes no user, device, network, or workload is trusted by default.

Why it matters · BFSI buyers need identity, device posture, least privilege, segmentation, and continuous verification.

ZTNA
ZTNA

Zero Trust Network Access gives users access to specific applications instead of broad network access.

Why it matters · It can reduce VPN risk, improve access control, and simplify audit evidence for remote and third-party access.

Zero Trust

Data & Privacy

4 terms
Cross-Border Data Transfer

The transfer of personal data outside India, subject to applicable law, contract, and regulatory controls.

Why it matters · BFSI buyers must understand where customer data is stored, processed, replicated, supported, and backed up.

DPDP Act 2023Negative List
Data Localization

Keeping certain data within India, either because law, regulator, contract, or internal policy requires it.

Why it matters · Residency can be the difference between an audit-ready product and a conditional-risk product.

RBI
Negative List

A list of countries or destinations to which data transfer may be restricted or prohibited.

Why it matters · Procurement must check whether vendors can restrict data movement, support regional controls, and prove processing locations.

DPDP Rules 2025Cross-Border Data Transfer

Operational Tech

13 terms
ATM Switch
Featured

The system that routes ATM transactions between a bank's core banking platform and the card networks. Frequently outsourced to a third-party Application Service Provider.

Why it matters · Running your own switch reaches Level III for a UCB. Outsourcing it triggers the contract flow-down: the bank must impose named cybersecurity controls on the provider by contract, and the obligation sits on the bank, not the supplier.

Contract Flow-DownASPSWIFT
Centralised Payment Systems
Featured

The Reserve Bank's centrally operated payment systems. A bank participates either as a direct member or as a sub-member through a sponsor bank.

Why it matters · For an urban co-operative bank, membership type is half of the Level II test and the whole of the Level III test. It is not a technical detail — it decides which chapters bind you.

Sub-memberDirect MemberUCB Level
CTS

Cheque Truncation System — the clearing system that settles cheques as images rather than physical instruments.

Why it matters · Direct CTS membership is one of the digital-service triggers that, combined with sub-membership, places a UCB at Level II.

IMPSUPIUCB Level
DMZ

Demilitarised Zone — the network segment holding systems reachable from the internet, separated from internal networks.

Why it matters · The Directions single out critical and DMZ-facing applications for six-monthly vulnerability assessment, because those are the systems an attacker reaches first.

VAPTSecure Configuration
FLDG

First Loss Default Guarantee is an arrangement where a lending service provider absorbs part of loan losses, subject to RBI rules.

Why it matters · Digital-lending vendors must structure guarantees, disclosures, and risk-sharing within RBI limits.

RBI
IMPS

Immediate Payment Service — NPCI's round-the-clock interbank funds transfer service.

Why it matters · Direct IMPS membership is a Level II trigger for a UCB when combined with sub-membership of centralised payment systems.

CTSUPINPCIUCB Level
KFS

A Key Fact Statement is a standardized summary of loan terms given to borrowers before execution.

Why it matters · Lending platforms must generate accurate, transparent, auditable KFS disclosures.

RBI
Master Direction

A consolidated RBI direction that groups regulatory instructions on a specific topic.

Why it matters · Master Directions often become the procurement checklist for regulated buyers.

RBI
RMM

Remote Monitoring and Management — the tooling used to keep endpoints patched, monitored and repairable at a distance.

Why it matters · Patch currency by system class is what a supervisor checks, together with how exceptions are tracked to closure.

UEMSecure Configuration
SWIFT

The international messaging network banks use for cross-border payment instructions.

Why it matters · Maintaining a SWIFT interface reaches Level III for a UCB on its own, and combined with an ATM switch reaches Level IV.

ATM SwitchUCB Level
Tokenization

Replacing sensitive payment data with tokens to reduce exposure of card or payment credentials.

Why it matters · Payment and checkout tools must reduce data exposure and support compliant payment processing.

NPCI
UEM

Unified Endpoint Management — centralised configuration, patching and control of endpoints.

Why it matters · The delivery mechanism for the patch and configuration obligations in Chapter III sections L and N.

RMMSecure Configuration
UPI
Featured

Unified Payments Interface — NPCI's real-time payment system.

Why it matters · The trigger most small banks overlook. A co-operative bank of a few hundred crore that took UPI membership carries Level II obligations its balance sheet would never suggest.

IMPSCTSNPCIUCB Level