Skip to main content

Outsourcing of Information Technology Services by RBI regulated entities

Reserve Bank of India (RBI) has issued directions on outsourcing of information technology services by the regulated entities.

What is the objective of the directions?

Regulated Entities (REs) have been extensively leveraging Information Technology (IT) and IT enabled Services (ITeS) to support their business models, products and services offered to their customers. REs also outsource substantial portion of their IT activities to third parties, which expose them to various risks.

The underlying principle of the directions on outsourcing of information technology services is to ensure that outsourcing arrangements neither diminish REs ability to fulfil its obligations to customers nor impede effective supervision by the Reserve Bank of India (RBI).

From when are the directions effective?

The directions on outsourcing of information technology services will come into effect from October 01, 2023.

With respect to existing outsourcing arrangements that are already in force as on the date of issuance of the directions, REs shall ensure that –

  • The agreements that are due for renewal before October 01, 2023, comply with the directions as on the renewal date (preferably), but within 12 months from the date of issuance of the directions.
  • The agreements that are due for renewal on or after October 01, 2023, comply with the directions as on the renewal date or 36 months from the date of issuance of the directions whichever is earlier.

With respect to new outsourcing arrangements, REs shall ensure that –

  • The agreements that come into force before October 01, 2023, comply with the directions as on the agreement date (preferably) but within 12 months from the date of issuance of the directions.
  • The agreements that come into force on or after October 01, 2023, shall comply with the provisions of the directions from the date of agreement itself.

Which entities are covered under the directions?

The directions shall be applicable to the following REs –

  • Commercial Banks including Foreign Banks, Local Area Banks (LABs), Small Finance Banks (SFBs), Payments Banks (PBs)
  • Primary Co-operative Banks in ‘Tier 3’ and ‘Tier 4’ as defined under revised regulatory framework for Urban Co-operative Banks (UCBs)
  • Non-Banking Financial Companies in ‘Top Layer’, ‘Upper Layer’ and ‘Middle Layer’ as defined under Scale Based Regulation (SBR) framework for NBFCs
  • Credit Information Companies (CICs)
  • All India Financial Institutions (AIFIs) –
    • Export-Import Bank of India (EXIM Bank)
    • National Bank for Agriculture and Rural Development (NABARD)
    • National Bank for Financing Infrastructure and Development (NaBFID)
    • National Housing Bank (NHB) 
    • Small Industries Development Bank of India (SIDBI)

Which arrangements are covered under the directions?

The directions shall apply to Material Outsourcing of Information Technology (IT) Services arrangements entered by the REs.

“Material Outsourcing of IT Services” are those which –

  • If disrupted or compromised shall have the potential to significantly impact the RE’s business operations; or
  • May have material impact on the RE’s customers in the event of any unauthorised access, loss or theft of customer information.

What are the regulatory and supervisory requirements in respect of outsourcing arrangements?

  • Outsourcing of any activity shall not diminish RE’s obligations as also of its Board and Senior Management, who shall be ultimately responsible for the outsourced activity. 
  • RE shall take steps to ensure that the service provider employs the same high standard of care in performing the services as would have been employed by the RE, if the same activity was not outsourced. 
  • REs shall not engage an IT service provider that would result in reputation of RE being compromised or weakened.
  • Notwithstanding whether the service provider is located in India or abroad, the REs shall ensure that the outsourcing should neither impede nor interfere with the ability of the RE to effectively oversee and manage its activities. 
  • RE shall ensure that the outsourcing does not impede the RBI in carrying out its supervisory functions and objectives.
  • REs shall ensure that the service provider, if not a group company, shall not be owned or controlled by any director, or key managerial personnel, or approver of the outsourcing arrangement of the RE, or their relatives. However, an exception to this requirement may be made with the approval of Board / Board level Committee, followed by appropriate disclosure, oversight and monitoring of such arrangements. The Board shall inter-alia ensure that there is no conflict of interest arising out of third-party engagements.

What shall be the grievance redressal mechanism under outsourcing arrangements?

  • REs shall have a robust grievance redressal mechanism that shall not be compromised in any manner on account of outsourcing, i.e., responsibility for redressal of customers’ grievances related to outsourced services shall rest with the RE.
  • Outsourcing arrangements shall not affect the rights of a customer against the RE, including the ability of the customer to obtain redressal as applicable under relevant laws.
What are other instruction regarding outsourcing arrangements?
  • REs shall evaluate the need for Outsourcing of IT Services based on comprehensive assessment of attendant benefits, risks and availability of commensurate processes to manage those risks.
  • In considering or renewing an Outsourcing of IT Services arrangement, appropriate due diligence shall be performed to assess the capability of the service provider to comply with obligations in the outsourcing agreement on an ongoing basis. 
  • REs shall ensure that their rights and obligations and those of each of their service providers are clearly defined and set out in a legally binding written agreement. 
  • RE intending to outsource any of its IT activities shall put in place a comprehensive Board approved IT outsourcing policy.
  • REs shall put in place a Risk Management framework for Outsourcing of IT Services that shall comprehensively deal with the processes and responsibilities for identification, measurement, mitigation, management, and reporting of risks associated with Outsourcing of IT Services arrangements. 
  • Public confidence and customer trust in REs is a prerequisite for their stability and reputation. Hence, REs shall seek to ensure the preservation and protection of the security and confidentiality of customer information in the custody or possession of the service provider. Access to customer information by staff of the service provider shall be on need-to-know basis. 
  • REs shall effectively assess the impact of concentration risk posed by multiple outsourcings to the same service provider and / or the concentration risk posed by outsourcing critical or material functions to a limited number of service providers. 
  • REs shall require their service providers to develop and establish a robust framework for documenting, maintaining and testing Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP).
  • REs shall have in place a management structure to monitor and control its Outsourced IT activities.
  • RE may outsource any IT activity / IT enabled service within its business group / conglomerate, subject to the conditions similar to those applicable in case of third-party.
  • The engagement of a service provider based in a different jurisdiction exposes the RE to country risk. RE shall closely monitor government policies of the jurisdiction in which the service provider is based and the political, social, economic and legal conditions on a continuous basis, as well as establish sound procedures for mitigating the country risk. 
  • The Outsourcing of IT Services policy shall contain a clear exit strategy with regard to outsourced IT activities / IT enabled services, while ensuring business continuity during and after exit.


References

Reserve Bank of India. (2023, April 10). 'Master Direction on Outsourcing of Information Technology Services'. Retrieved from https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12486&Mode=0


Follow at - Telegram   Instagram   LinkedIn   Twitter   Facebook

Comments

Popular Posts

Policies to be formulated by NBFC-BL

Non-Banking Financial Companies (NBFCs) are required to formulate various policies for effective corporate governance and operations. This article lists out some of the important policies to be formulated by the Base Layer NBFCs (NBFC-BL). Business Model Master Direction – Reserve Bank of India (Non-Banking Financial Company – Scale Based Regulation) Directions, 2023 dated October 19, 2023 Para 1.1 of Annex II – In view of the criticality of the nature of the business model in determining the classification of financial assets and restrictions on subsequent reclassification, NBFCs are advised to put in place Board approved policies that clearly articulate and document their business models and portfolios. Para 1.2 of Annex II – NBFCs shall frame their policy for sales out of amortised cost business model portfolios. Expected Credit Losses (ECL) Policy Master Direction – Reserve Bank of India (Non-Banking Financial Company – Scale Based Regulation) Directions, 2023 dated October 19, 202...

Special Rupee Vostro Accounts (SRVAs)

Reserve Bank of India (RBI) has consolidated the guidelines governing Special Rupee Vostro Accounts (SRVAs). Who can open and maintain Special Rupee Vostro Accounts (SRVAs)? Authorised Dealer (AD) banks in India may open Special Rupee Vostro Accounts (SRVAs) of its branch outside India or a bank resident outside India. Which transactions can be settled through SRVA? The settlement of cross-border trade transactions through SRVA is an additional arrangement for invoicing, payment and settlement of exports and imports in Indian Rupee (INR).  All permissible capital and current account transactions under Foreign Exchange Management Act (FEMA) may be settled through the SRVA.  AD banks maintaining SRVA are permitted to open additional current account for exporter / importer, exclusively for settlement of export / import transactions. What can be the source and use of funds in SRVA? SRVA may be funded by way of inward remittances or transfer from other repatriable INR accounts in t...

Cash Reserve Ratio (CRR) and Statutory Liquidity Ratio (SLR)

Reserve Bank of India (RBI) has issued the directions on maintenance of Cash Reserve Ratio (CRR) and Statutory Liquidity Ratio (SLR) by banks. To whom are the directions applicable? The directions are applicable to the following Regulated Entities (REs) – Commercial Banks  Small Finance Banks (SFBs) Payments Banks (PBs) Local Area Banks (LABs) Regional Rural Banks (RRBs) Primary (Urban) Co-operative Banks (UCBs) Rural Co-operative Banks – State Co-operative Banks (StCBs) District Central Co-operative Banks (DCCBs) What is CRR? Every bank shall maintain in India by way of cash reserve, a sum equivalent to such percent of its Net Demand and Time Liabilities (NDTL) in India, as the RBI in terms of Section 42(1) of the RBI Act, 1934 (for scheduled banks) and Section 18(1) of the Banking Regulation Act (BR Act), 1949 (for non-scheduled banks) [including provisions of Section 18(1) of the BR Act as applicable to co-operative banks], may specify. What is incremental CRR? In terms of Secti...

Highlights of RBI Annual Report 2025-26 – Chapter 7 to 12

Reserve Bank of India (RBI) has published its annual report for the financial year 2025-26. In a series of articles, we will go through the highlights of the report. This is the fifth and final article in the series.  Chapter 7 – Public Debt Management The ways and means advances (WMA) limit for the Government of India (GoI) for H1:2025-26 (April to September 2025) was fixed at ₹1,50,000 crore and for H2:2025-26 (October 2025 to March 2026) was fixed at ₹50,000 crore. The RBI entered into an agreement with the Government of National Capital Territory of Delhi (GNCTD), under Section 21A(1) of the RBI Act, 1934, to carry on the general banking business of GNCTD and manage its rupee public debt. The WMA limit of GNCTD was set at ₹890 crore, taking the aggregate WMA limit of all the states / UTs to ₹61,008 crore. The RBI introduced Separate Trading of Registered Interest and Principal of Securities (STRIPS) in the state government securities. Retail Direct Gilt (RDG) account – An au...

Unique Transaction Identifier (UTI) for OTC Derivative Transactions

Reserve Bank of India (RBI) has issued directions on Unique Transaction Identifier (UTI) for over-the-counter (OTC) derivative transactions. What are the existing norms for reporting of OTC derivative transactions? At present, all transactions in OTC markets for rupee interest rate derivatives, forward contracts in Government securities, foreign currency derivatives, foreign currency interest rate derivatives, and credit derivatives are reported to the Trade Repository managed by Clearing Corporation of India Limited (CCIL-TR).  What are the directions on Unique Transaction Identifier (UTI) for OTC derivative transactions? Unique Transaction Identifier (UTI), a unique identifier assigned to an OTC derivative transaction, shall be generated / reported for all transactions in OTC derivatives market.  The directions shall be applicable to OTC derivative transactions entered into on or after January 01, 2027. UTI shall be generated in accordance with the UTI Technical Guidanc...