11 obligations, and what answers each
Derived from the chapter sub-sections of RBI/DoS/2026-27/437, so you can check the mapping against the notification rather than take it on trust. Each one links to the category guide that does the actual shortlisting, with an indicative India cost band.
Information asset inventory
UCB Level I+Maintain a current inventory of information assets classified by criticality, so that the bank knows what it holds and which systems matter most.
₹3L–₹18L
Information asset inventory
UCB Level I+Maintain a current inventory of information assets classified by criticality, so that the bank knows what it holds and which systems matter most.
₹3L–₹18L
The obligation
Where it comes from
- Chapter III §F — Inventory Management of Information Assets
What a supervisor expects to see
What answers it
Product families: IT asset management · Data discovery and classification. Cost is indicative, not a quote — the guide carries per-product pricing.
Anti-virus and endpoint protection
UCB Level I+Protect endpoints against malware, and prevent unauthorised software from running on bank systems.
₹2L–₹15L
Anti-virus and endpoint protection
UCB Level I+Protect endpoints against malware, and prevent unauthorised software from running on bank systems.
₹2L–₹15L
The obligation
Where it comes from
- Chapter III §M — Anti-virus
- Chapter III §I — Preventing Access of Unauthorised Software
What a supervisor expects to see
What answers it
Product families: Endpoint protection (EPP) · Endpoint detection and response (EDR) · Application allow-listing. Cost is indicative, not a quote — the guide carries per-product pricing.
Change and patch management
UCB Level I+Apply security patches on a defined cycle, keep configurations to a secure baseline, and control changes to production systems.
₹1.5L–₹12L
Change and patch management
UCB Level I+Apply security patches on a defined cycle, keep configurations to a secure baseline, and control changes to production systems.
₹1.5L–₹12L
The obligation
Where it comes from
- Chapter III §N — Change and Patch Management
- Chapter IV §F — Change and Patch Management
- Chapter III §L — Secure Configuration
What a supervisor expects to see
What answers it
Product families: Patch management · Unified endpoint management (UEM) · Configuration management. Cost is indicative, not a quote — the guide carries per-product pricing.
User access control and privileged access
UCB Level I+Control who can reach what, with stronger authentication for privileged users and critical systems, and a customer authentication framework at Level II.
₹5L–₹40L
User access control and privileged access
UCB Level I+Control who can reach what, with stronger authentication for privileged users and critical systems, and a customer authentication framework at Level II.
₹5L–₹40L
The obligation
Where it comes from
- Chapter III §O — User Access Control / Management
- Chapter IV §H — User Access Control / Management
- Chapter IV §I — Authentication Framework for Customers
What a supervisor expects to see
What answers it
Product families: Privileged access management (PAM) · IAM, SSO and MFA. Cost is indicative, not a quote — the guide carries per-product pricing.
Data leak prevention
UCB Level II+Have a strategy — not merely a tool — for preventing customer and payment data leaving the bank, covering endpoints, transit and storage.
₹4L–₹30L
Data leak prevention
UCB Level II+Have a strategy — not merely a tool — for preventing customer and payment data leaving the bank, covering endpoints, transit and storage.
₹4L–₹30L
The obligation
Where it comes from
- Chapter IV §K — Data Leak Prevention Strategy
What a supervisor expects to see
What answers it
Product families: DLP (endpoint, network, cloud) · Insider risk · Rights management. Cost is indicative, not a quote — the guide carries per-product pricing.
Email security and anti-phishing
UCB Level I+Secure mail and messaging, and defend against phishing — including phishing that targets the bank's customers using its brand.
₹1L–₹10L
Email security and anti-phishing
UCB Level I+Secure mail and messaging, and defend against phishing — including phishing that targets the bank's customers using its brand.
₹1L–₹10L
The obligation
Where it comes from
- Chapter III §P — Secure Mail and Messaging Systems
- Chapter IV §J — Anti-Phishing
What a supervisor expects to see
What answers it
Product families: Email security · Anti-phishing and brand protection · Security awareness training. Cost is indicative, not a quote — the guide carries per-product pricing.
Backup, restoration and continuity
UCB Level I+Back up what matters, be able to restore it, and hold a cyber crisis management plan that has been exercised.
₹3L–₹35L
Backup, restoration and continuity
UCB Level I+Back up what matters, be able to restore it, and hold a cyber crisis management plan that has been exercised.
₹3L–₹35L
The obligation
Where it comes from
- Chapter III §T — Backup and Restoration
- Chapter III §D — Cyber Crisis Management Plan
What a supervisor expects to see
What answers it
Product families: Backup and recovery · Immutable and air-gapped storage · Disaster recovery. Cost is indicative, not a quote — the guide carries per-product pricing.
Audit logs and monitoring
UCB Level I+Collect and retain audit logs, and be able to detect, respond to and report an incident — on DAKSH within six hours, and to CERT-In within six hours, separately.
₹8L–₹90L
Audit logs and monitoring
UCB Level I+Collect and retain audit logs, and be able to detect, respond to and report an incident — on DAKSH within six hours, and to CERT-In within six hours, separately.
₹8L–₹90L
The obligation
Where it comes from
- Chapter IV §M — Audit Logs
- Chapter IV §N — Incident Response and Management
- Chapter III §V — Cyber Incident Response and Recovery Management
What a supervisor expects to see
What answers it
Product families: SIEM and log management · MDR and SOC-as-a-service · Incident response. Cost is indicative, not a quote — the guide carries per-product pricing.
Vulnerability assessment and penetration testing
UCB Level II+Not a productVulnerability assessment of critical and DMZ-facing applications at least every six months, and penetration testing at least once a year.
Vulnerability assessment and penetration testing
UCB Level II+Not a productVulnerability assessment of critical and DMZ-facing applications at least every six months, and penetration testing at least once a year.
The obligation
Where it comes from
- Chapter IV §G — Periodic Testing
- Paragraph 116
What a supervisor expects to see
Why software does not answer this
The penetration test is a service, and it must be performed by a competent independent assessor. A scanning platform produces findings; it does not discharge the testing obligation. TechBag does not perform penetration testing and does not resell it — engage a CERT-In empanelled assessor.
Information Systems Audit function
UCB Level I+Not a productConstitute an IS Audit Cell within the Inspection and Audit Department, working to a board-adopted policy, reporting to the Audit Committee.
Information Systems Audit function
UCB Level I+Not a productConstitute an IS Audit Cell within the Inspection and Audit Department, working to a board-adopted policy, reporting to the Audit Committee.
The obligation
Where it comes from
- Chapter III §X — Information Systems Audit
- Paragraphs 94–102
What a supervisor expects to see
Why software does not answer this
This is a team and a reporting line, not a tool. No software satisfies it. We mention it because it appears in the same chapter as controls that are products, and a buyer working down the chapter will otherwise look for something to purchase.
Vendor and outsourcing risk, and the contract flow-down
UCB Level I+Not a productImpose named cybersecurity controls by contract on ATM Switch and core banking service providers — 12 controls at paragraph 83 and 34 at paragraph 85 — and manage outsourcing risk generally.
Vendor and outsourcing risk, and the contract flow-down
UCB Level I+Not a productImpose named cybersecurity controls by contract on ATM Switch and core banking service providers — 12 controls at paragraph 83 and 34 at paragraph 85 — and manage outsourcing risk generally.
The obligation
Where it comes from
- Chapter III §U — Vendor / Outsourcing Risk Management
- Paragraphs 83, 85
What a supervisor expects to see
Why software does not answer this
The obligation is a contract negotiation with your existing suppliers. Software can track the exercise; it cannot perform it, and buying a TPRM platform does not put a clause into an agreement your provider has not signed.
Sub-section references read from the RBI notification on 2026-08-26 by Raj, LupusCreed. General information, not legal advice. Cost bands are indicative annual figures at Indian mid-market scale, not quotes. If we have read something wrongly, write to info@thetechbag.com.