11 obligations, and what answers each

Derived from the chapter sub-sections of RBI/DoS/2026-27/437, so you can check the mapping against the notification rather than take it on trust. Each one links to the category guide that does the actual shortlisting, with an indicative India cost band.

Information asset inventory

UCB Level I+

Maintain a current inventory of information assets classified by criticality, so that the bank knows what it holds and which systems matter most.

₹3L₹18L

The obligation

Maintain a current inventory of information assets classified by criticality, so that the bank knows what it holds and which systems matter most.

Where it comes from

  • Chapter III §F — Inventory Management of Information Assets

What a supervisor expects to see

The inventory itself, its classification scheme, and evidence that it is maintained rather than produced once for an audit.

What answers it

DSPM & data discovery₹3L₹18L 200–1,000 endpoints, annual

Product families: IT asset management · Data discovery and classification. Cost is indicative, not a quote — the guide carries per-product pricing.

Anti-virus and endpoint protection

UCB Level I+

Protect endpoints against malware, and prevent unauthorised software from running on bank systems.

₹2L₹15L

The obligation

Protect endpoints against malware, and prevent unauthorised software from running on bank systems.

Where it comes from

  • Chapter III §M — Anti-virus
  • Chapter III §I — Preventing Access of Unauthorised Software

What a supervisor expects to see

Coverage across the estate, update currency, and how exceptions are approved and reviewed.

What answers it

Endpoint protection₹2L₹15L 200–1,000 endpoints, annual

Product families: Endpoint protection (EPP) · Endpoint detection and response (EDR) · Application allow-listing. Cost is indicative, not a quote — the guide carries per-product pricing.

Change and patch management

UCB Level I+

Apply security patches on a defined cycle, keep configurations to a secure baseline, and control changes to production systems.

₹1.5L₹12L

The obligation

Apply security patches on a defined cycle, keep configurations to a secure baseline, and control changes to production systems.

Where it comes from

  • Chapter III §N — Change and Patch Management
  • Chapter IV §F — Change and Patch Management
  • Chapter III §L — Secure Configuration

What a supervisor expects to see

Patch currency by system class, the change-approval trail, and how exceptions are tracked to closure.

What answers it

RMM & patch₹1.5L₹12L 200–1,000 endpoints, annual

Product families: Patch management · Unified endpoint management (UEM) · Configuration management. Cost is indicative, not a quote — the guide carries per-product pricing.

User access control and privileged access

UCB Level I+

Control who can reach what, with stronger authentication for privileged users and critical systems, and a customer authentication framework at Level II.

₹5L₹40L

The obligation

Control who can reach what, with stronger authentication for privileged users and critical systems, and a customer authentication framework at Level II.

Where it comes from

  • Chapter III §O — User Access Control / Management
  • Chapter IV §H — User Access Control / Management
  • Chapter IV §I — Authentication Framework for Customers

What a supervisor expects to see

The access review trail, how privileged sessions are recorded, and joiner-mover-leaver evidence.

What answers it

Privileged access management₹5L₹40L by privileged account count, annual

Product families: Privileged access management (PAM) · IAM, SSO and MFA. Cost is indicative, not a quote — the guide carries per-product pricing.

Data leak prevention

UCB Level II+

Have a strategy — not merely a tool — for preventing customer and payment data leaving the bank, covering endpoints, transit and storage.

₹4L₹30L

The obligation

Have a strategy — not merely a tool — for preventing customer and payment data leaving the bank, covering endpoints, transit and storage.

Where it comes from

  • Chapter IV §K — Data Leak Prevention Strategy

What a supervisor expects to see

The written strategy, what it classifies as sensitive, and evidence the controls fire and are acted on.

What answers it

DLP & insider risk₹4L₹30L 200–1,000 users, annual

Product families: DLP (endpoint, network, cloud) · Insider risk · Rights management. Cost is indicative, not a quote — the guide carries per-product pricing.

Email security and anti-phishing

UCB Level I+

Secure mail and messaging, and defend against phishing — including phishing that targets the bank's customers using its brand.

₹1L₹10L

The obligation

Secure mail and messaging, and defend against phishing — including phishing that targets the bank's customers using its brand.

Where it comes from

  • Chapter III §P — Secure Mail and Messaging Systems
  • Chapter IV §J — Anti-Phishing

What a supervisor expects to see

Mail authentication records, what is quarantined and why, and takedown arrangements for lookalike domains.

What answers it

Email security₹1L₹10L 200–1,000 mailboxes, annual

Product families: Email security · Anti-phishing and brand protection · Security awareness training. Cost is indicative, not a quote — the guide carries per-product pricing.

Backup, restoration and continuity

UCB Level I+

Back up what matters, be able to restore it, and hold a cyber crisis management plan that has been exercised.

₹3L₹35L

The obligation

Back up what matters, be able to restore it, and hold a cyber crisis management plan that has been exercised.

Where it comes from

  • Chapter III §T — Backup and Restoration
  • Chapter III §D — Cyber Crisis Management Plan

What a supervisor expects to see

Restore tests with dates and outcomes — not backup success reports, which prove only that data was written.

What answers it

Backup & recovery₹3L₹35L by protected TB, annual

Product families: Backup and recovery · Immutable and air-gapped storage · Disaster recovery. Cost is indicative, not a quote — the guide carries per-product pricing.

Audit logs and monitoring

UCB Level I+

Collect and retain audit logs, and be able to detect, respond to and report an incident — on DAKSH within six hours, and to CERT-In within six hours, separately.

₹8L₹90L

The obligation

Collect and retain audit logs, and be able to detect, respond to and report an incident — on DAKSH within six hours, and to CERT-In within six hours, separately.

Where it comes from

  • Chapter IV §M — Audit Logs
  • Chapter IV §N — Incident Response and Management
  • Chapter III §V — Cyber Incident Response and Recovery Management

What a supervisor expects to see

Log retention against the one-year requirement, and a worked example of a real incident with its two filing timestamps.

What answers it

SIEM & log management₹8L₹90L ingest-driven; the licence is the small number

Product families: SIEM and log management · MDR and SOC-as-a-service · Incident response. Cost is indicative, not a quote — the guide carries per-product pricing.

Vulnerability assessment and penetration testing

UCB Level II+Not a product

Vulnerability assessment of critical and DMZ-facing applications at least every six months, and penetration testing at least once a year.

The obligation

Vulnerability assessment of critical and DMZ-facing applications at least every six months, and penetration testing at least once a year.

Where it comes from

  • Chapter IV §G — Periodic Testing
  • Paragraph 116

What a supervisor expects to see

The reports themselves, the assessor's independence and competence, and the remediation trail.

Why software does not answer this

The penetration test is a service, and it must be performed by a competent independent assessor. A scanning platform produces findings; it does not discharge the testing obligation. TechBag does not perform penetration testing and does not resell it — engage a CERT-In empanelled assessor.

Information Systems Audit function

UCB Level I+Not a product

Constitute an IS Audit Cell within the Inspection and Audit Department, working to a board-adopted policy, reporting to the Audit Committee.

The obligation

Constitute an IS Audit Cell within the Inspection and Audit Department, working to a board-adopted policy, reporting to the Audit Committee.

Where it comes from

  • Chapter III §X — Information Systems Audit
  • Paragraphs 94–102

What a supervisor expects to see

The audit policy, the cell's composition and independence, and what happened to the last set of findings.

Why software does not answer this

This is a team and a reporting line, not a tool. No software satisfies it. We mention it because it appears in the same chapter as controls that are products, and a buyer working down the chapter will otherwise look for something to purchase.

Vendor and outsourcing risk, and the contract flow-down

UCB Level I+Not a product

Impose named cybersecurity controls by contract on ATM Switch and core banking service providers — 12 controls at paragraph 83 and 34 at paragraph 85 — and manage outsourcing risk generally.

The obligation

Impose named cybersecurity controls by contract on ATM Switch and core banking service providers — 12 controls at paragraph 83 and 34 at paragraph 85 — and manage outsourcing risk generally.

Where it comes from

  • Chapter III §U — Vendor / Outsourcing Risk Management
  • Paragraphs 83, 85

What a supervisor expects to see

The clauses in the executed agreements, and the correspondence where amendments were sought.

Why software does not answer this

The obligation is a contract negotiation with your existing suppliers. Software can track the exercise; it cannot perform it, and buying a TPRM platform does not put a clause into an agreement your provider has not signed.

Sub-section references read from the RBI notification on 2026-08-26 by Raj, LupusCreed. General information, not legal advice. Cost bands are indicative annual figures at Indian mid-market scale, not quotes. If we have read something wrongly, write to info@thetechbag.com.