RBI Compliance Software for Banks, NBFCs and Other Regulated Entities
RBI compliance software is a centralised system for governance, risk management and compliance, built to meet RBI's regulatory requirements, replacing spreadsheets and email trails. Sigmify GRC is that platform, built for banks, NBFCs and other Regulated Entities.
Quick answer
The Three Instruments in Force Right Now
- Compliance monitoring circular (RBI/2023-24/117): replace spreadsheet tracking with one enterprise-wide, workflow-based system integrated to DAKSH.
- 2026 cyber Directions: seven Directions, issued 31 Jul 2026, resetting cyber governance.
- 2025 outsourcing Directions: govern third and party arrangements on their own separate track.
Deadline passed
Where the Compliance Monitoring Deadline Stands
- Original deadline: 30 June 2024.
- Extended to: 30 April 2025 (circular dated 25 Nov 2024).
- Same circular added a DAKSH Straight and Through Processing requirement.
- Both dates have now passed.
The requirement
What the RBI Compliance Monitoring Circular Requires
RBI/2023-24/117, Streamlining of Internal Compliance Monitoring Function, issued 31 January 2024, directs Regulated Entities to overhaul compliance tracking. Every entity in scope must put in place a system that delivers:
A circular dated 25 November 2024 extended the deadline to 30 April 2025 and added a further requirement: the system must integrate with RBI's DAKSH portal through Straight and Through Processing.
Scope
Which Regulated Entities Are in Scope
- Regional Rural Banks: not in scope.
- Base Layer NBFCs: not under this circular.
- Payment Aggregators and Payment Gateways: not under this circular; separate RBI instruments apply.
- Payments Banks: a different licence category, and in scope.
| Entity class | Status | In scope of RBI/2023-24/117 |
|---|---|---|
| Scheduled Commercial Banks | In scope | Yes, excluding Regional Rural Banks |
| Small Finance Banks | In scope | Yes |
| Payments Banks | In scope | Yes |
| Primary (Urban) Co-operative Banks | In scope | Yes, Tier III and Tier IV |
| Non-Banking Financial Companies | In scope | Yes, Upper and Middle Layer, including Housing Finance Companies |
| Credit Information Companies | In scope | Yes |
| All India Financial Institutions | In scope | Yes, including EXIM Bank, NABARD, NaBFID, NHB and SIDBI |
| Regional Rural Banks | Out of scope | No |
| Base Layer NBFCs | Out of scope | Not under this circular |
| Payment Aggregators and Payment Gateways | Out of scope | Not under this circular; separate RBI instruments apply |
At a glance
Which RBI Instrument Applies: The Circular, the 2026 Cyber Directions and the 2025 Outsourcing Directions, Side by Side
They are three separate instruments with different jobs, and a Regulated Entity can be bound by all three at once. Sigmify GRC converts all three into assigned, evidenced, board-reportable tasks in one platform.
RBI/2023-24/117 · 31 Jan 2024
Compliance Monitoring Circular
- What it means: Replace spreadsheet based tracking with an enterprise wide, workflow based system. Reaches SCBs excluding RRBs, SFBs, Payments Banks, Tier III/IV UCBs, Upper and Middle Layer NBFCs, CICs and AIFIs
- What you’d normally do: Stand up collaboration, obligation monitoring, escalation, recorded deviation approval and a unified senior management dashboard; integrate to DAKSH via Straight and Through Processing.
- What Sigmify GRC does: Role based ownership per control, a shared obligation register, automated escalation triggers, maker checker deviation workflow, a live RBI compliance monitoring dashboard, and status data structured for DAKSH Straight and Through Processing.
Seven Directions · 31 Jul 2026
2026 Cyber Directions
- What it means: Repealed the 2016 Cyber Security Framework and the 2023 Master Direction on IT Governance. Seven instruments, one per entity class, in force immediately with no transition period; NBFC obligations attach by layer, UCBs by four level grading, RRBs have no instrument in this family.
- What you’d normally do: Annual board approval of IT, cybersecurity and business continuity strategies; an IT Strategy Committee meeting the composition test; a CISO reporting to the executive overseeing risk; a cybersecurity policy distinct from the IT policy; an IS Audit function under Audit Committee oversight.
- What Sigmify GRC does: Control library entries carrying the applicable Direction for each entity class, each governance obligation tracked with an owner, a review cadence and retained evidence.
Managing Risks in Outsourcing · 28 Nov 2025
2025 Outsourcing Directions
- What it means: Runs on its own track and remains in force. The 2026 Directions carve around it: their third-party provisions apply only to arrangements falling outside the outsourcing instrument.
- What you’d normally do: Determine which arrangements fall under which instrument; remediate legacy IT outsourcing contracts, since the 10 April 2026 date has passed.
- What Sigmify GRC does: Vendors treated as their own asset category, a dedicated RBI vendor risk management register, contract level obligation tracking with renewal and remediation dates.
Obligation mapping
Every RBI Obligation, Mapped to Sigmify GRC
Eight obligations run across the instruments in force, and each maps to a specific supporting capability.
| RBI obligation | How Sigmify GRC addresses it |
|---|---|
| Communication and collaboration | Task assignment with role based ownership per control, in platform commenting, and a shared obligation register visible to every function. |
| Identify, assess, monitor and manage compliance requirements | Control library mapped to RBI instruments, with applicability assessment by entity class and layer, updated as regulations change. |
| Escalation for non compliance | Automated reminders and escalation triggers ahead of due dates, routed by ownership and severity. |
| Recorded approval for deviations or delays | Structured deviation workflow with maker checker sign off, recorded remarks, revised deadlines and full audit traceability. |
| Unified dashboard for senior management | Live RBI compliance monitoring dashboard and risk scorecards for the executive committee and board. |
| DAKSH integration | Compliance status data structured for Straightand Through Processing to the DAKSH portal. |
| Vendor and outsourcing accountability | Dedicated RBI vendor risk management register with controls mapped to third and party assets and arrangements. |
| Board approved cyber security policy and assurance testing | Control library entries covering RBI cyber security framework governance, testing cadence and evidence retention. |
On a clock
The Obligations That Repeat, and How Often
Some RBI obligations are recurring frequencies, not one-time implementations, so a missed period can’t be back-filled before an inspection. That’s where a scheduled, evidenced platform earns its place over a document repository.
| Obligation | Frequency or deadline |
|---|---|
| Cyber incident reporting to RBI on DAKSH | Within six hours of detection. |
| Vulnerability assessment | At least half yearly. |
| Penetration testing of critical systems | At least annually by independent trained assessors. |
| Disaster recovery drills for critical systems | Half yearly. |
| Board approval of IT, cybersecurity and business continuity strategies | Annual. |
Where things actually stand
The Deadline Is Already Behind You
- Seven cyber Directions (31 Jul 2026): in force immediately, no transition period
- 2025 outsourcing Directions: never stopped applying
- Cyber incident reporting: six hours to RBI on DAKSH, six hours to CERT-In: two filings, two recipients, one deadline
- None of it can be produced late
Built to Run Inside That Environment
- Every obligation lands as an assigned task with an owner and due date
- Evidence attaches at completion, not assembled afterwards
- A maker checker trail sits behind every deviation
- A live dashboard shows the entity’s real time compliance position
Scoped to the Entity You Actually Are
A control library that shows every obligation to every entity is a library nobody trusts.
- Applicability assessment scopes the library to the entity’s actual layer
- A Middle Layer NBFC isn’t shown Upper Layer obligations it doesn’t have
- Only the obligations that bind are shown
Scope, Instruments and What Changed
SBR
NBFC Obligations Follow the Layer, Not the Label
Deposit and taking vs non deposit and taking no longer determines scope; it was retired when Scale Based Regulation took effect on 1 Oct 2022.
- Obligations follow the Base, Middle, Upper or Top Layer, and Core Investment Company status
- Compliance monitoring circular reaches Upper and Middle Layer NBFCs
- 2026 cyber Directions reach all NBFCs, chapters attaching by layer
CYBER
What replaced the RBI Cyber Security Framework?
The 2016 Cyber Security Framework and the 2023 Master Direction on IT Governance were repealed 31 July 2026, replaced by seven Directions, one per entity class:
- Commercial banks, small finance banks, payments banks
- Urban co-operative banks, all India financial institutions
- NBFCs, credit information companies
All came into force immediately, with no transition period.
THIRD PARTY
Two Third and Party Regimes, Running Side by Side
- 2026 Directions do not replace RBI’s outsourcing rules
- Managing Risks in Outsourcing Directions, 2025 (issued 28 Nov 2025) remain in force, on a separate track
- 2026 Directions third and party provisions apply only to arrangements falling outside the outsourcing instrument
- A regulated entity answers to both
How the Platform Works
From Requirement to Task, on a Schedule
Every control becomes an assigned task on a set cadence: daily, weekly, monthly, quarterly or annual. Reminders fire ahead of due dates, evidence attaches directly to the task, and sign offs stay logged for full traceability.
- Applicability assessment: scoping the control library by entity class, NBFC layer or UCB level, so obligations shown are obligations that bind.
- Deviation workflow: structured requests for delayed or partially completed compliance, with maker checker approval by the competent authority and tracked revised deadlines, which is what RBI/2023-24/117’s requirement for recorded approval of any deviation or delay calls for in practice.
- Evidence library and reopening of compliances: evidence attached at the point of completion and retained for inspection; internal audit can reopen a closed compliance with documented observations.
- Task decomposition and categorisation: a primary compliance broken into sub tasks across departments, each requirement linked to a category and surfaced across dashboards and reports.
Nothing to Rip Out
No rip and replace required.
- SIEM logs and security events attach directly as evidence on compliance tasks.
- HRM data attaches the same way, so there’s no hunting for proof across five tools during an inspection.
- Completed tasks and evidence roll up into a live dashboard, risk scorecards and board reports.
- External auditors review evidence in platform, not through exported email.
- Available as cloud or on premises deployment.
The Checklist
Every Box RBI Actually Asks You to Check
Sigmify GRC’s control library maps every item below to an assigned, trackable task.
Scoping
- Entity class confirmed, and which of the seven 2026 Directions binds you
- NBFC layer or UCB level confirmed
- Whether the compliance monitoring circular applies
Governance
- Role based ownership per control
- IT Strategy Committee meeting the composition test, including the chair’s seven year expertise requirement
- CISO reporting line confirmed on the current organisation chart
- Cybersecurity policy distinct from the IT policy
Monitoring and escalation
- A structured framework to identify, assess, monitor and manage every obligation on a recurring schedule
- Automated escalation triggers ahead of due dates
- A maker checker approval trail for any deviation or delay
Reporting and DAKSH
- One unified dashboard for senior management and the board
- Straight and Through Processing integration to DAKSH
- Named owners for DAKSH and CERT In filing, both within six hours
Third and party risk
- A dedicated vendor risk register with vendors tracked as their own asset category
- Legacy IT outsourcing contracts remediated against the 2025 Directions
Cyber security
- Information asset inventory with criticality classification
- MFA for privileged users and critical systems
- 24×7 monitoring with SIEM based log collection and correlation
- Half yearly vulnerability assessment, annual penetration testing by independent assessors, half yearly DR drills
Audit readiness
- Evidence attached to each task as it is completed, not assembled after the fact: that is how RBI compliance is proved during an inspection
- IS Audit function under Audit Committee oversight
- In platform evidence review for external auditors
Sigmify GRC converts RBI requirements into assigned tasks, pulls evidence from your SIEM and HRM automatically, and rolls it into dashboards, scorecards and audit-ready reports.
Related: ISO 27001 compliance · SOC 2 compliance · DPDPA compliance · Vendor and outsourcing risk under RBI
