The plain-English glossary for Indian BFSI compliance.
132 terms that decide whether software clears an Indian audit — grouped by regulator, written for buyers.
Regulators
8 terms- CCA
The Controller of Certifying Authorities licenses and regulates certifying authorities for digital signatures and electronic signatures under the IT Act.
Why it matters · eSign and DSC workflows depend on whether the signing method is legally valid and issued through licensed trust infrastructure.
DSCAadhaar eSignIT Act §5- CERT-In
The Indian Computer Emergency Response Team is India’s national agency for cyber incident response and reporting directions.
Why it matters · Vendors must help BFSI customers detect, classify, preserve logs, and report incidents within regulatory timelines.
CERT-In Direction April 2022VAPT- IRDAI
The Insurance Regulatory and Development Authority of India regulates insurers, insurance intermediaries, and insurance-sector governance.
Why it matters · Insurance software must handle sensitive personal data, claims data, policyholder records, intermediary access, and cyber controls.
IRDAI Cyber GuidelinesPIIData Fiduciary- MeitY
The Ministry of Electronics and Information Technology is India’s central ministry for digital policy, including the IT Act and DPDP framework.
Why it matters · MeitY-led rules affect privacy, data processing, digital signatures, cyber policy, and compliance design for all digital vendors.
DPDP ActIT Act 2000CERT-In- NPCI
The National Payments Corporation of India operates major retail payment rails such as UPI, IMPS, RuPay, NACH, and Aadhaar-linked payment infrastructure.
Why it matters · Payment, mandate, lending, collections, and account-verification tools often touch NPCI-linked rails.
e-NACHeMandateAccount Aggregator- RBI
The Reserve Bank of India is India’s central bank and the primary regulator for banks, NBFCs, payment systems, and many digital lending workflows.
Why it matters · RBI-regulated buyers care deeply about outsourcing, IT governance, cyber resilience, customer data, auditability, KYC, digital lending, and operational risk.
RBI IT GovernanceRBI Outsourcing Master DirectionDigital LendingKFS- SEBI
The Securities and Exchange Board of India regulates India’s securities markets, including brokers, mutual funds, exchanges, depositories, portfolio managers, and market infrastructure institutions.
Why it matters · SEBI buyers often require stronger cybersecurity, cyber resilience, SOC monitoring, incident classification, and technology-risk controls.
SEBI CSCRFType-A BrokerMIICyber-SOC- UIDAI
The Unique Identification Authority of India runs Aadhaar and governs Aadhaar authentication and e-KYC use.
Why it matters · Vendors touching Aadhaar workflows must support the right authentication, consent, identity, security, and ecosystem requirements.
Aadhaar OTPAadhaar eSigne-KYC
Acts & Regulations
12 terms- CERT-In Direction April 2022
CERT-In’s 2022 directions require specified entities to report listed cyber incidents within six hours of noticing or being informed of them.
Why it matters · Vendors must preserve logs, detect incidents fast, provide reporting evidence, and support forensic readiness.
CERT-InVAPT- Cybersecurity, Technology: Risk, Resilience and Assurance FrameworkFeatured
The common title of seven RBI Directions issued on 31 July 2026, one per licence class — commercial banks, small finance banks, payments banks, urban co-operative banks, all India financial institutions, NBFCs and credit information companies. All commenced on issuance.
Why it matters · This is the framework that replaced the 2016 Cyber Security Framework and the 2023 Master Direction on IT Governance. There is no transition period: obligations applied from the day they were published.
RBIDAKSHCSOCRepeal Circular- DPDP Act 2023
India’s Digital Personal Data Protection Act creates obligations for processing digital personal data, including notice, consent, duties of data fiduciaries, and rights of data principals.
Why it matters · BFSI vendors handling customer data must support consent, data minimization, retention, security, breach handling, and contractual processing controls.
Data FiduciaryData PrincipalSignificant Data Fiduciary- DPDP Rules 2025
The Digital Personal Data Protection Rules, 2025 operationalize parts of the DPDP Act, including phased commencement for specific obligations.
Why it matters · Buyers need to know whether vendors can support compliance timelines, notices, consent mechanisms, child-data handling, and breach workflows.
Consent ManagerNegative List- IRDAI Information & Cyber Security Guidelines (2023, superseded)
IRDAI’s 2023 guidelines strengthen information and cyber security governance for insurers and insurance intermediaries.
Why it matters · Insurance buyers require security governance, access control, data classification, encryption, incident management, and third-party controls.
IRDAI- IT Act 2000
The Information Technology Act gives legal recognition to electronic records, electronic signatures, cyber offences, certifying authorities, and certain security practices.
Why it matters · It decides when electronic records and electronic signatures are legally recognized in India.
IT Act §5DSCAadhaar eSign- IT Reasonable Security Practices Rules 2011
These rules define reasonable security practices for sensitive personal data under India’s IT framework.
Why it matters · They remain relevant for baseline security controls, privacy practices, consent, and sensitive personal information handling.
Reasonable Security Practices- PMLA
The Prevention of Money Laundering Act is India’s anti-money-laundering framework for reporting entities and financial-sector due diligence.
Why it matters · KYC, onboarding, transaction monitoring, screening, and record-retention tools often need PMLA-aware controls.
e-KYC- RBI Master Direction on IT Governance (repealed)
RBI’s IT governance direction sets expectations for governance, risk, controls, assurance, vendor risk, business continuity, and auditability for regulated entities.
Why it matters · Software vendors must fit into governance, audit, source-code, access, data-integrity, and third-party-risk controls.
RBI Outsourcing Master Direction- RBI Outsourcing Master Direction
RBI’s IT outsourcing direction governs how regulated entities manage third-party technology service providers and outsourced IT arrangements.
Why it matters · SaaS vendors become part of the regulated entity’s risk perimeter; contracts, audit rights, data controls, and exit plans matter.
Material OutsourcingConcentration Risk- Repeal Circular
DoS.CO.PPG.66/11.01.005/2026-27, dated 31 July 2026, which repealed 628 supervisory circulars as the Reserve Bank issued 64 consolidated Directions in their place.
Why it matters · If you are working from a circular issued before 31 July 2026, check this list first — the instrument you are citing may no longer exist.
Cybersecurity, Technology: Risk, Resilience and Assurance Framework- SEBI CSCRF
SEBI’s Cybersecurity and Cyber Resilience Framework sets cybersecurity and resilience expectations for SEBI-regulated entities.
Why it matters · Vendors serving brokers, AMCs, MIIs, and market intermediaries must support SOC, incident response, cyber drills, access controls, and resilience evidence.
Cyber-SOCType-A BrokerMII
Compliance Concepts
26 terms- AUC
Assets Under Custody — the measure CSCRF uses to band custodians.
Why it matters · A custodian is Qualified at ₹10 lakh crore of assets under custody, small-size below ₹1 lakh crore.
AUMQualified RE- AUM
Assets Under Management — the measure CSCRF uses to band alternative investment funds, mutual funds and portfolio managers.
Why it matters · Different entity types are banded at completely different AUM figures: ₹1,000 crore makes an AIF Qualified, while a mutual fund needs ₹1 lakh crore.
AUCQualified RE- BCP
Business Continuity Plan — the arrangements for continuing essential operations through a disruption.
Why it matters · Evidence a supervisor wants is restore tests with dates and outcomes, not backup success reports. A backup report proves data was written, not that it can be recovered.
DR DrillCyber Crisis Management Plan- CIO
Chief Information Officer — the executive accountable for IT delivery.
Why it matters · Named in the Directions mainly to keep the CISO away from them: a UCB CISO must not report to the CIO, because the person running the systems should not be the person assuring them.
CISO- CISOFeatured
Chief Information Security Officer. Under the NBFC Direction the CISO reports directly to the executive overseeing risk management; under the UCB Direction at Level IV, to the top executive overseeing risk or in their absence the MD and CEO.
Why it matters · The reporting line is the substance. A UCB CISO must have no direct reporting relationship with the CIO — an independence test, not a title. At Level II a UCB may designate an official who need not carry the CISO title at all.
CIOIT Strategy CommitteeIS Audit- Comply or Explain
A supervisory approach permitting deviation from a requirement where the entity can justify it to the regulator's satisfaction.
Why it matters · Foreign banks operating in India through branch mode get this route for selected requirements of the Commercial Banks Direction. It is not an exemption — the Reserve Bank has to accept the explanation.
Commercial Bank- Concentration Risk
The risk of relying too heavily on one vendor, cloud, geography, or service provider.
Why it matters · BFSI buyers need multi-vendor, multi-region, or exit strategies when one failure could affect critical operations.
Material Outsourcing- Contract Flow-DownFeatured
The requirement to impose named cybersecurity controls on a service provider through the contract itself. For UCBs this is 12 controls at paragraph 83 plus 34 baseline controls at paragraph 85; for commercial and payments banks it is 12 plus 23.
Why it matters · The most under-covered obligation in the family, and the one most likely to be forwarded inside a bank. It sits in Chapter III, so it binds every UCB from Level I — and existing core banking and switch contracts almost certainly do not carry these clauses. If the clause is not in the agreement, it is the bank that is short, not the provider.
ASPATM SwitchMaterial Outsourcing- Cyber Capability Index
CCI — the index CSCRF uses for MIIs and Qualified REs to monitor and assess cyber resilience over time.
Why it matters · Applies only to the top two bands. If you are a mid-size or smaller RE, this is not your obligation.
CSCRFMIIQualified RE- Cyber Crisis Management Plan
A board-approved plan for detecting, containing, responding to and recovering from a cyber incident.
Why it matters · A Chapter III obligation binding every UCB from Level I. A supervisor will ask for the plan and the date it was last exercised — an unexercised plan answers only half the question.
DAKSHCERT-InBCP- Cyber Resiliency Goals
Objectives that ensure systems can withstand, respond to, and recover from cyber incidents.
Why it matters · A product is not just judged by whether it prevents attacks, but whether it helps recover without business collapse.
SEBI CSCRF- DAKSHFeatured
The Reserve Bank's Advanced Supervisory Monitoring System, at daksh.rbi.org.in, through which regulated entities file cyber incident reports.
Why it matters · Cyber incidents must be reported on DAKSH within six hours of detection. This does not discharge the separate CERT-In obligation, which runs on its own six-hour clock to a different recipient.
CERT-InCyber Crisis Management Plan- Data Fiduciary
A person or organization that determines the purpose and means of processing personal data under the DPDP Act.
Why it matters · BFSI institutions are usually data fiduciaries; vendors may be processors but still need contractual and technical safeguards.
Data PrincipalDPDP Act 2023- Data Principal
The individual to whom personal data relates under the DPDP Act.
Why it matters · Customers, borrowers, policyholders, employees, and users may all be data principals whose rights must be supported.
DPDP Act 2023Consent Manager- DR Drill
A disaster recovery exercise testing whether systems can actually be restored at the recovery site.
Why it matters · Required at least half-yearly for critical systems under the NBFC, commercial bank, payments bank, AIFI and CIC Directions. The UCB Direction says only 'periodic intervals' — do not import the half-yearly figure into a UCB assessment.
BCPCyber Crisis Management Plan- Information Asset Inventory
A current register of information assets classified by criticality.
Why it matters · Chapter III section F, binding from Level I. The evidence expected is that it is maintained, not produced once for an audit.
DSPMDLP- IS Audit
Information Systems Audit. The UCB Direction requires an IS Audit Cell within the Inspection and Audit Department, working to a board-adopted policy and reporting to the Audit Committee of the Board.
Why it matters · This is a team and a reporting line, not a tool. No software satisfies it — worth knowing, because it appears in the same chapter as controls that genuinely are products.
IT Strategy CommitteeCISOVAPT- IT Strategy Committee
A board committee overseeing technology strategy, chaired by an independent director with substantial IT expertise — defined as at least seven years managing information systems or leading technology and cybersecurity initiatives.
Why it matters · A composition test with a number in it, not a statement of intent. It is the kind of requirement a board discovers it fails during a review rather than before one.
CISOIS Audit- Material Outsourcing
Outsourcing that materially affects business operations, customer service, risk management, compliance, or regulatory supervision.
Why it matters · If a SaaS product becomes operationally critical, procurement must evaluate audit rights, exit plans, concentration risk, and resilience.
RBI Outsourcing Master DirectionConcentration Risk- Reasonable Security Practices
Security controls considered adequate under applicable law, contracts, or regulatory expectations.
Why it matters · Buyers must map vendor controls to security baselines such as access control, encryption, logging, audit, and incident response.
VAPT- Risk-Based Supervision
A regulatory approach that applies deeper scrutiny where risk is higher.
Why it matters · Systemically important institutions, high-volume fintechs, and sensitive-data processors should expect tougher vendor reviews.
Significant Data FiduciaryTop Layer NBFCType-A Broker- Scale-Based Regulation
The Reserve Bank's four-layer classification of NBFCs — Base, Middle, Upper and Top Layer — by size, activity and perceived riskiness.
Why it matters · The NBFC cybersecurity Direction attaches chapters by layer, and within the Base Layer by an asset-size test at ₹500 crore.
Base LayerMiddle LayerUpper LayerTop Layer- Significant Data Fiduciary
A data fiduciary designated for heightened obligations based on factors such as volume, sensitivity, risk, and impact.
Why it matters · Large BFSI institutions may need stronger governance, audits, DPO-style ownership, and risk assessments.
DPDP Act 2023Data Fiduciary- TPRM
Third-Party Risk Management — assessing and monitoring the risk a supplier introduces.
Why it matters · A TPRM platform can track the contract flow-down exercise; it cannot perform it. Buying one does not put a clause into an agreement your provider has not signed.
Contract Flow-DownMaterial Outsourcing- UCB LevelFeatured
The four-level grading in the UCB Direction. Level I binds every UCB; Level II adds Chapter IV; Level III adds Chapter V; Level IV adds Chapter VI. Higher levels carry everything beneath them.
Why it matters · Graded by digital services and payment-system interconnectedness, NOT by asset size. This is counter-intuitive and it is the single fact most small banks get wrong about their own obligations.
Sub-memberUPICentralised Payment Systems- UCC
Unique Client Code — the identifier by which a stock broker's active client base is counted.
Why it matters · The measure that decides a broker's CSCRF band. Qualified is above 5,00,000 active clients per UCC.
Qualified RERegulated Entity
Authentication & eSign
10 terms- Aadhaar eSignFeatured
A regulated electronic signature method that uses Aadhaar or other approved e-KYC-based authentication to issue a short-lived digital signature certificate.
Why it matters · Generic eSignature is not always enough; some Indian workflows need legally valid eSign under the IT Act framework.
CCAIT Act §5DSC- Aadhaar OTP
A one-time password sent to the mobile number linked to an Aadhaar number, used for Aadhaar authentication and certain e-KYC/eSign flows.
Why it matters · Retail lending, KYC, and Aadhaar-linked signing workflows may require Aadhaar-compatible identity verification.
Aadhaar eSignUIDAIe-KYC- Digital Signature Certificate (DSC)
A certificate issued by a licensed certifying authority that enables legally recognized digital signatures.
Why it matters · Board resolutions, statutory filings, high-assurance approvals, and certain regulated workflows may require DSC-grade signing.
CCAIT Act 2000- e-KYC
Electronic Know Your Customer verification, often using Aadhaar, offline XML, OTP, biometric, or other digital identity methods.
Why it matters · Onboarding tools must prove identity, preserve evidence, and avoid unauthorized Aadhaar or personal-data handling.
Aadhaar OTPUIDAI- e-NACH
Electronic National Automated Clearing House mandate setup for recurring payments and collections.
Why it matters · Lenders, insurers, and subscription-based BFSI products need mandate validity, authentication, and payment-rail integration.
NPCIeMandate- eMandate
A digital authorization that permits recurring debits from a customer’s account.
Why it matters · It affects lending collections, insurance premiums, SIPs, subscription finance, and repayment automation.
e-NACHNPCI- IT Act §5
Section 5 of the IT Act gives legal recognition to electronic signatures when prescribed conditions are met.
Why it matters · Buyers must distinguish between convenience signatures and signatures that satisfy Indian legal-recognition requirements.
Aadhaar eSignDSCCCA- MFA
Multi-Factor Authentication — requiring more than one independent factor to authenticate.
Why it matters · Required for privileged users and critical systems across the 2026 family, and part of the customer authentication framework at UCB Level II.
IAMSSOAadhaar OTP- SSO
Single Sign-On — one authentication event granting access to multiple applications.
Why it matters · Usually deployed alongside MFA. The control the Directions care about is the review trail, not the convenience.
IAMMFA- Video KYC
A video-based customer identification process used by regulated entities under KYC rules.
Why it matters · Vendor tooling must support recording, audit trails, consent, location checks, agent controls, and secure storage.
e-KYC
BFSI Entity Types
35 terms- Account Aggregator
A consent-based financial data-sharing entity under India’s account aggregator framework.
Why it matters · Tools integrated into AA workflows need strict consent, data minimization, security, and audit controls.
Consent ManagerData Fiduciary- AIF
Alternative Investment Fund — privately pooled investment vehicles registered with SEBI.
Why it matters · Banded by AUM under CSCRF: self-certification below ₹100 crore, Qualified at ₹1,000 crore and above.
AUMRegulated Entity- AIFI
All India Financial Institution. The 2026 Direction names five: EXIM Bank, NABARD, SIDBI, the National Housing Bank and NaBFID.
Why it matters · This is the Direction most often missing from secondary summaries of the family — which is how the claim that there are six Directions rather than seven gets into circulation.
Commercial Bank- AMC
An Asset Management Company that manages mutual fund schemes and investment products.
Why it matters · AMCs need investor-data controls, SEBI compliance, cybersecurity, access governance, and outsourcing oversight.
SEBISEBI CSCRF- ASP
Application Service Provider — a third party operating an application on a bank's behalf, most commonly the ATM Switch or the core banking platform.
Why it matters · Paragraphs 83 and 85 of the UCB Direction require named cybersecurity controls to be written into the contract with the switch ASP.
ATM SwitchContract Flow-Down- Base LayerFeatured
The lowest layer of the scale-based framework for NBFCs. The 2026 Direction splits it at ₹500 crore of assets: below that a Base Layer NBFC gets Chapter III, at or above it gets Chapter IV.
Why it matters · ₹500 crore, not ₹2,500 crore — a widely syndicated summary reports the higher figure, a five-fold error that would put a whole band of NBFCs in the wrong chapter. A Base Layer NBFC under ₹500 crore owes three paragraphs: no VA or PT, no six-hour DAKSH clock, no security operations centre.
Scale-Based RegulationCore Investment CompanyMiddle Layer- Commercial Bank
A banking company other than a small finance bank, payments bank or local area bank, together with the corresponding new banks and the State Bank of India.
Why it matters · Takes RBI/DoS/2026-27/410, which runs the same eight chapters as the SFB, payments bank, AIFI and CIC Directions. Foreign branches get a comply-or-explain route on selected requirements.
Comply or ExplainPayments Bank- Core Investment Company
An NBFC whose business is holding investments in group companies rather than lending to the public.
Why it matters · CICs sit with the smallest Base Layer band whatever their size, and are explicitly excluded from Chapter V — so a large CIC carries markedly lighter obligations than an NBFC of comparable size.
Base LayerScale-Based Regulation- Credit Information Company
An entity within the definition in section 2(e) of the Credit Information Companies (Regulation) Act, 2005 — the credit bureaus.
Why it matters · Takes RBI/DoS/2026-27/470, on the common eight-chapter shape with no internal grading.
AIFI- Direct Member
A bank holding membership of a centralised payment system in its own right, without a sponsor.
Why it matters · Direct membership reaches Level III on its own for a UCB, regardless of what digital services the bank offers.
Sub-memberCentralised Payment SystemsUCB Level- FPI
Foreign Portfolio Investor.
Why it matters · Explicitly excluded from submission of compliance with CSCRF.
Regulated EntityFVCI- FVCI
Foreign Venture Capital Investor.
Why it matters · Explicitly excluded from submission of compliance with CSCRF.
Regulated EntityFPI- InvIT
Infrastructure Investment Trust.
Why it matters · Excluded from submission of compliance with CSCRF, together with REITs.
REITRegulated Entity- KRA
KYC Registration Agency — entities holding centralised KYC records for the securities market.
Why it matters · Treated at par with the MII category for CSCRF applicability, so a KRA carries the heaviest band regardless of its size.
MIIRegulated Entitye-KYC- LPCC
Limited Purpose Clearing Corporation.
Why it matters · Excluded from submission of compliance with CSCRF.
Regulated Entity- Mid-size RE
The middle CSCRF band, again defined per entity type — a broker between 50,000 and 5,00,000 active clients, a mutual fund between ₹10,000 crore and ₹1 lakh crore of AUM.
Why it matters · Your band is fixed at the start of the financial year on the previous year's data and holds all year, whatever changes in between.
Qualified RESmall-size RE- Middle Layer
The second layer of the scale-based framework for NBFCs.
Why it matters · Middle, Upper and Top Layer NBFCs all take Chapter V of the 2026 Direction — the fullest set of obligations, including VA, PT, DR drills and a security operations centre.
Scale-Based RegulationBase LayerUpper Layer- MII
A Market Infrastructure Institution, such as a stock exchange, clearing corporation, or depository.
Why it matters · MIIs require very high resilience, availability, cyber governance, and operational continuity.
SEBISEBI CSCRF- NBFC-MFI
A non-bank finance company focused on microfinance lending.
Why it matters · Tools must support small-ticket lending, customer consent, repayment, collections, KYC, and RBI scrutiny.
KFS- Payment Aggregator
An entity that facilitates merchants in accepting payments from customers and settling funds.
Why it matters · Payment aggregators face RBI authorization, cybersecurity, data, settlement, and merchant-risk expectations.
RBI- Payments Bank
A differentiated bank licensed to accept deposits up to a prescribed limit and offer payment services, but not to lend.
Why it matters · Takes RBI/DoS/2026-27/428. The Directions apply as a whole — no internal grading, though a risk-based approach is permitted for non-critical systems.
Commercial BankSmall Finance Bank- QDP
Qualified Depository Participant.
Why it matters · Excluded from CSCRF compliance.
Regulated Entity- QRTA
Qualified Registrar to an Issue and Share Transfer Agent — the larger RTAs subject to enhanced obligations.
Why it matters · One of the categories that already had a cyber framework before CSCRF and so fell in the earlier tranche of the glide path.
RTAMII- Qualified REFeatured
The second-highest CSCRF band. There is no single threshold: each entity type is graded on its own measure — a stock broker above 5,00,000 active clients, an AIF at ₹1,000 crore of AUM, a custodian at ₹10 lakh crore of assets under custody.
Why it matters · Commentary widely reports a universal '10 lakh clients' threshold. That figure appears nowhere in the circular's tables, and applying it would misclassify most entity types.
Mid-size RERegulated EntityCSCRF- Regulated Entity
SEBI's term for the nineteen entity types CSCRF applies to, from stock exchanges and depositories down to investment advisers and alternative investment funds.
Why it matters · Several RE types are excluded from CSCRF compliance altogether — foreign portfolio investors, foreign venture capital investors, REITs, InvITs, qualified depository participants, limited purpose clearing corporations and individual investment advisers.
CSCRFQualified REMII- REIT
Real Estate Investment Trust.
Why it matters · Excluded from submission of compliance with CSCRF, together with InvITs.
InvITRegulated Entity- RTA
Registrar to an Issue and Share Transfer Agent — entities maintaining investor records for issuers.
Why it matters · A CSCRF regulated entity. Qualified RTAs had their own pre-CSCRF cyber framework, now superseded.
Regulated EntityQRTA- Self-certification RE
The lightest CSCRF band, where compliance is self-certified. Credit rating agencies and collective investment schemes are placed here outright.
Why it matters · For a large share of SEBI's regulated population the honest answer is lighter than they have been told — worth checking before commissioning an audit you do not owe.
Small-size RERegulated Entity- Small Finance Bank
A bank category focused on financial inclusion, smaller borrowers, and underserved segments.
Why it matters · SFB software must handle banking-grade controls with often leaner operational teams.
RBI- Small-size RE
The lower CSCRF band, defined per entity type.
Why it matters · Non-individual investment advisers land here by assignment rather than by any threshold.
Mid-size RESelf-certification RE- Sub-member
A bank that reaches a centralised payment system indirectly, through a sponsor bank that holds direct membership.
Why it matters · A UCB reaches Level II only if it is a sub-member AND offers internet or mobile banking or holds CTS, IMPS or UPI membership. Both halves must be true — an OR reading promotes banks a level they do not belong in.
Direct MemberCentralised Payment SystemsUCB Level- Top Layer NBFC
The highest-risk layer in RBI’s scale-based NBFC regulatory framework.
Why it matters · A Top Layer NBFC should assume deep supervisory scrutiny and enterprise-grade vendor controls.
Risk-Based Supervision- Type-A Broker
A higher-risk or higher-scale securities intermediary classification under SEBI cyber frameworks.
Why it matters · Type-A entities often face stronger cyber, SOC, and resilience expectations than smaller intermediaries.
SEBI CSCRF- UCBFeatured
Urban Co-operative Bank, formally a Primary (Urban) Co-operative Bank. Roughly 1,500 operate in India.
Why it matters · The largest addressable universe under the 2026 family and the hardest self-assessment: most have no CISO, and the level test turns on operational facts rather than balance-sheet size.
UCB LevelSub-member- Upper Layer
The third layer of the scale-based framework, for NBFCs identified as warranting enhanced regulatory attention.
Why it matters · Takes Chapter V of the NBFC cybersecurity Direction, alongside Middle and Top Layer entities.
Scale-Based RegulationMiddle LayerTop Layer NBFC
Security Frameworks
24 terms- Anti-Phishing
Defences against phishing, including attacks that impersonate the bank to its own customers.
Why it matters · Chapter IV section J of the UCB Direction, attaching at Level II. It covers takedown arrangements for lookalike domains, not only inbound mail filtering.
DLPAudit Logs- Application Security Life Cycle
Building security into application development, from secure coding through source code audits to pre-release testing.
Why it matters · Chapter IV section E. Application security testing is required before go-live and after every major change — event-driven rather than calendar-driven.
OWASPSecure Configuration- Audit Logs
Records of system and user activity retained for investigation and supervisory review.
Why it matters · Chapter IV section M. A one-year security log retention requirement applies, and a supervisor will ask for a worked example of a real incident with its filing timestamps.
SIEMDAKSHCERT-In- CSOCFeatured
Cyber Security Operations Centre — round-the-clock monitoring, detection, escalation and forensic analysis of security events.
Why it matters · The same words mean very different things depending on your instrument. Under the common eight-chapter shape the CSOC is its own chapter binding every entity. Under the UCB Direction it is a Level IV obligation only — Levels I to III do not owe one.
SOCMarket SOCSIEMMDR- Cyber-SOC
A Security Operations Center that monitors, detects, investigates, and responds to cyber threats.
Why it matters · SEBI, RBI, and insurance cyber expectations increasingly reward operational monitoring, not just policy documents.
SEBI CSCRF- DLP
Data Leak Prevention — controls that stop sensitive data leaving the organisation across endpoints, network and cloud.
Why it matters · Chapter IV section K of the UCB Direction requires a data leak prevention STRATEGY, not merely a tool. A supervisor asks for the written strategy and evidence that the controls fire and are acted on.
DSPMInformation Asset Inventory- DSPM
Data Security Posture Management — discovery and classification of data across an estate, and assessment of its exposure.
Why it matters · The practical route to an information asset inventory that stays current. Finding the data is fast; remediating what it finds is not.
Information Asset InventoryDLP- EDR
Endpoint Detection and Response — endpoint agents that record behaviour and enable investigation and remote response.
Why it matters · EPP prevents; EDR investigates. The Directions require both anti-virus and the ability to detect and respond, and buyers frequently purchase one believing they bought both.
EPPMDR- EPP
Endpoint Protection Platform — preventive endpoint controls, principally anti-malware.
Why it matters · Chapter III section M of the UCB Direction requires anti-virus and section I requires preventing unauthorised software from running. Both bind from Level I.
EDR- IAM
Identity and Access Management — the systems governing who may reach what.
Why it matters · Chapter III section O and Chapter IV section H of the UCB Direction cover user access control; Chapter IV section I adds a customer authentication framework at Level II.
PAMMFASSO- Market SOC
A shared security operations centre that NSE and BSE were mandated by CSCRF to set up, providing monitoring to smaller SEBI regulated entities.
Why it matters · SEBI's answer to the problem that a small broker cannot realistically staff a 24x7 SOC. If you are a small-size or self-certification RE, this is likely your route.
SOCCSCRF- MDR
Managed Detection and Response — an outsourced service providing monitoring, detection and response, typically 24x7.
Why it matters · The realistic route to a CSOC for an institution that cannot staff one. What matters commercially is not the tooling but what the provider is permitted to do at 2am without calling you.
CSOCSOCSIEM- OWASP
The Open Web Application Security Project, whose Top Ten is the common reference for web application risks.
Why it matters · Named in the baseline controls a UCB must impose on its Application Service Providers by contract.
Application Security Life CycleContract Flow-Down- PAM
Privileged Access Management — controlling, recording and reviewing the use of administrative accounts.
Why it matters · Most PAM projects stall not because the product failed but because nobody could get the accounts into it. The evidence a supervisor wants is the access review trail and recorded privileged sessions.
IAMMFA- PT
Penetration Testing — a simulated attack conducted to establish what a real adversary could achieve.
Why it matters · Required at least annually for critical systems, and it must be performed by a competent independent assessor. A scanning platform produces findings; it does not discharge the testing obligation.
VAVAPTDMZ- Risk-Based Transaction Monitoring
Monitoring transactions against risk rules to detect anomalous or fraudulent activity.
Why it matters · Chapter V section I of the UCB Direction, attaching at Level III. A supervisor asks to see the system and the rules it actually runs.
SIEMUCB Level- SBOM
Software Bill of Materials — an inventory of the components inside a piece of software.
Why it matters · CSCRF names SBOM among its evolving security guidelines, alongside data classification and API security.
CSCRFTPRM- Secure Configuration
Maintaining systems to a defined hardened baseline rather than vendor defaults.
Why it matters · Chapter III section L and Chapter IV section D. Also one of the twelve controls that must be imposed on an ATM Switch provider by contract.
Contract Flow-DownDMZ- SIEM
Security Information and Event Management — collection and correlation of logs from across the estate to detect security events.
Why it matters · The licence is the small number; ingest volume drives the bill. Log retention against the one-year requirement is what a supervisor checks.
SOCAudit LogsMDR- SOC
Security Operations Centre — the team and tooling that monitors for and responds to security events. May be in-house, group-level, or a third-party managed service.
Why it matters · CSCRF requires every SEBI regulated entity to onboard a SOC, and explicitly permits using a Market SOC or a managed provider rather than building one.
CSOCMarket SOCMDR- VA
Vulnerability Assessment — automated and manual identification of known weaknesses in systems and applications.
Why it matters · Required at least every six months for critical and DMZ-facing systems across the 2026 family. Attaches from Level II for a UCB; a Level I bank does not owe a periodic VA.
PTVAPTDMZ- VAPT
Vulnerability Assessment and Penetration Testing identifies weaknesses before attackers exploit them.
Why it matters · Buyers must check whether vendors undergo regular testing and can share remediation evidence.
CERT-In- Zero Trust
A security model that assumes no user, device, network, or workload is trusted by default.
Why it matters · BFSI buyers need identity, device posture, least privilege, segmentation, and continuous verification.
ZTNA- ZTNA
Zero Trust Network Access gives users access to specific applications instead of broad network access.
Why it matters · It can reduce VPN risk, improve access control, and simplify audit evidence for remote and third-party access.
Zero Trust
Data & Privacy
4 terms- Consent Manager
A registered or regulated mechanism that helps individuals manage consent for data sharing.
Why it matters · Consent-heavy workflows such as account aggregation and data sharing need trustworthy consent architecture.
Data PrincipalAccount Aggregator- Cross-Border Data Transfer
The transfer of personal data outside India, subject to applicable law, contract, and regulatory controls.
Why it matters · BFSI buyers must understand where customer data is stored, processed, replicated, supported, and backed up.
DPDP Act 2023Negative List- Data Localization
Keeping certain data within India, either because law, regulator, contract, or internal policy requires it.
Why it matters · Residency can be the difference between an audit-ready product and a conditional-risk product.
RBI- Negative List
A list of countries or destinations to which data transfer may be restricted or prohibited.
Why it matters · Procurement must check whether vendors can restrict data movement, support regional controls, and prove processing locations.
DPDP Rules 2025Cross-Border Data Transfer
Operational Tech
13 terms- ATM SwitchFeatured
The system that routes ATM transactions between a bank's core banking platform and the card networks. Frequently outsourced to a third-party Application Service Provider.
Why it matters · Running your own switch reaches Level III for a UCB. Outsourcing it triggers the contract flow-down: the bank must impose named cybersecurity controls on the provider by contract, and the obligation sits on the bank, not the supplier.
Contract Flow-DownASPSWIFT- Centralised Payment SystemsFeatured
The Reserve Bank's centrally operated payment systems. A bank participates either as a direct member or as a sub-member through a sponsor bank.
Why it matters · For an urban co-operative bank, membership type is half of the Level II test and the whole of the Level III test. It is not a technical detail — it decides which chapters bind you.
Sub-memberDirect MemberUCB Level- CTS
Cheque Truncation System — the clearing system that settles cheques as images rather than physical instruments.
Why it matters · Direct CTS membership is one of the digital-service triggers that, combined with sub-membership, places a UCB at Level II.
IMPSUPIUCB Level- DMZ
Demilitarised Zone — the network segment holding systems reachable from the internet, separated from internal networks.
Why it matters · The Directions single out critical and DMZ-facing applications for six-monthly vulnerability assessment, because those are the systems an attacker reaches first.
VAPTSecure Configuration- FLDG
First Loss Default Guarantee is an arrangement where a lending service provider absorbs part of loan losses, subject to RBI rules.
Why it matters · Digital-lending vendors must structure guarantees, disclosures, and risk-sharing within RBI limits.
RBI- IMPS
Immediate Payment Service — NPCI's round-the-clock interbank funds transfer service.
Why it matters · Direct IMPS membership is a Level II trigger for a UCB when combined with sub-membership of centralised payment systems.
CTSUPINPCIUCB Level- KFS
A Key Fact Statement is a standardized summary of loan terms given to borrowers before execution.
Why it matters · Lending platforms must generate accurate, transparent, auditable KFS disclosures.
RBI- Master Direction
A consolidated RBI direction that groups regulatory instructions on a specific topic.
Why it matters · Master Directions often become the procurement checklist for regulated buyers.
RBI- RMM
Remote Monitoring and Management — the tooling used to keep endpoints patched, monitored and repairable at a distance.
Why it matters · Patch currency by system class is what a supervisor checks, together with how exceptions are tracked to closure.
UEMSecure Configuration- SWIFT
The international messaging network banks use for cross-border payment instructions.
Why it matters · Maintaining a SWIFT interface reaches Level III for a UCB on its own, and combined with an ATM switch reaches Level IV.
ATM SwitchUCB Level- Tokenization
Replacing sensitive payment data with tokens to reduce exposure of card or payment credentials.
Why it matters · Payment and checkout tools must reduce data exposure and support compliant payment processing.
NPCI- UEM
Unified Endpoint Management — centralised configuration, patching and control of endpoints.
Why it matters · The delivery mechanism for the patch and configuration obligations in Chapter III sections L and N.
RMMSecure Configuration- UPIFeatured
Unified Payments Interface — NPCI's real-time payment system.
Why it matters · The trigger most small banks overlook. A co-operative bank of a few hundred crore that took UPI membership carries Level II obligations its balance sheet would never suggest.
IMPSCTSNPCIUCB Level
Methodology, glossary, and long-form analysis for Indian BFSI procurement.
What each control requires, and which tool category answers it.
Seven RBI Directions plus SEBI and IRDAI. Two taps to your instrument and what you owe.