RBI · URBAN CO-OPERATIVE BANKS

RBI UCB Vendor Obligations 2026Section U Compliance Guide

The RBI (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 came into force with immediate effect and repealed the previous framework. The vendor obligation — Section U, paragraphs 71 to 86 — sits in Chapter III, the Level I baseline.

16
paragraphs in Section U
Level I
where Section U sits
37
controls Para 85 requires in an ATM Switch ASP contract
6 hrs
to report an incident on DAKSH (Para 88)

Get the Full Quick Book

Enter your details below for instant access to the Quick Book and continue with the scope check.

Please tell us your name.
Please give a valid work email.
Please give a number we can reach you on.

We respect your privacy. Your details will only be used to provide the Quick Book and respond to your request.

✓

Here it is.

Your download should have started automatically. If it did not, use the button below.

The document link has not been set yet — see the comment at the top of this block.

Prefer to talk it through? Write to info@shieldbyteinfosec.com or call +91 8104995634 / 9820989640.

Para 4 sets the ladder

Which Urban Co-operative Banks Need to Comply?

Paragraph 10 makes deciding your level your own obligation, not your auditor’s — and the level you land on decides which chapters you are audited against. Section U sits below all of that, in the baseline, so it binds you either way.

LevelCriteria (paragraph 4)Chapters that bind you
Level IEvery UCB, irrespective of the digital services or products it offers.Chapters II and III
Level IISub-member of Centralised Payment Systems and offers internet banking, or mobile banking through an app, or is a direct member of CTS / IMPS / UPI.+ Chapter IV
Level IIIDirect member of CPS, or has its own ATM Switch, or has a SWIFT interface.+ Chapter V
Level IVDirect or sub-member of CPS and either has its own ATM Switch and SWIFT interface, or hosts a data centre or provides software support to other banks.+ Chapter VI
What the section asks for

Key RBI Vendor Obligations for UCBs

Read paragraph by paragraph, Section U looks larger than it is. Grouped by what an inspector would actually ask to see, it comes down to four things — each of which has to exist as a dated artefact, not a stated intention.

01

Know who they are  Para 71, 72, 74

A single register of every third-party vendor, service provider and partner, with the criticality of each service recorded against it. Due diligence run before contracting and repeated on an ongoing basis, covering all eight dimensions Para 72 names — including the provider’s virtualisation framework and its information lifecycle. For each vendor: a background check, a signed NDA, and a security policy compliance agreement.

02

Put it in the contract  Para 73, 75–77

Every outsourcing agreement carries a right to audit for the bank and a clause recognising RBI’s right to inspect the service provider. SLAs state the responsibility split on service failure and the grievance redressal route, are reviewed periodically against security controls, and carry a defined escalation procedure. Concentration risk is assessed, and exit is possible without lock-in.

03

Know where the data goes  Para 78–82

A written impact analysis for each critical service against the adverse scenarios Para 78 lists, prolonged unavailability included. An end-to-end data flow map showing where customer data moves across the provider’s shared infrastructure. Evidence of where every copy and backup is stored and how encryption keys are managed. An assessment of the provider’s user access management, end to end.

04

Prove it, and prove it fast  Para 83, 85, 86, 88

Where a third-party ATM Switch ASP is used, the thirty-seven Para 85 controls written into that contract and evidenced against. VA/PT reports and closure evidence handed over on request. And a vendor-side incident reaching you fast enough to file on DAKSH within six hours of detection — with the timestamps to prove when you knew.

The pattern worth noticing. Almost none of this can be evidenced from inside your bank alone. Most of Section U depends on artefacts your service provider has to produce — their VA/PT reports, their access management, their data flow, their patch record. Asking them late is the part that takes months.
What closes it

What Evidence Should UCBs Maintain for Vendor Compliance

ShieldRisk.ai is Shieldbyte Infosec’s third-party risk governance platform — one system of record for onboarding, background checks, contract analysis, assessment, audit and evidence, so the pack is assembled as you go rather than under deadline.

ParagraphWhat RBI requiresWhat ShieldRisk does about it
Para 71, 72Regular, effective due diligence, oversight and management of third-party vendors, providers and partners — on an ongoing basis.Vendor Register as the single system of record, Deep BGV at onboarding, and the Audit Planner driving recurring cycles rather than one-off reviews.
Para 74Background checks mandated for all third-party providers; satisfaction as to the credentials of vendor personnel accessing critical assets.One-click Deep BGV across MCA, PAN, GST and MSME plus 20,000+ court, litigation, fraud and sanctions sources — entity and representative.
Para 73–77Agreement clauses: right to audit, RBI’s right to inspect the provider, SLA responsibility split, periodic review and escalation.AI Contract Analyzer reads the MSA, SLA and NDA and flags weak or missing terms against the clauses the section requires.
Para 78–82Impact analysis for adverse scenarios, data location and lifecycle, encryption and key management, and the provider’s user access management.Compliance Assessment questionnaires per vendor, with the responses and supporting artefacts held against the vendor record.
Para 85–86Controls written into the ASP contract and evidenced; VA/PT reports and closure evidence produced on request.Evidence Vault and Findings, so every report, closure note and acknowledgement is filed against the vendor and the date it was produced.
Self-assessment

RBI UCB Vendor Compliance Self-Check

Fifteen statements, each tied to the paragraph that raises it. A ‘no’ is not a failure — it is a finding an inspector would raise, and every one is closable. What matters is dated evidence, per vendor, rather than a policy that says you would.

🔒

Open the check

Fill the short form at the top of this page. It opens the check here and the full document at the same time — it takes about a minute.

Take me to the form

Your level

01
You have formally self-assessed which of the four levels your bank falls into, and recorded the basis for it.Para 10

Know who they are

02
You hold a single register of every third-party vendor, service provider and partner, with the criticality of each service recorded.Para 71
03
Due diligence is run before contracting and repeated on an ongoing basis — not once at onboarding.Para 72
04
That due diligence covers all eight dimensions Para 72 names, including the provider’s virtualisation framework and information lifecycle.Para 72(1–8)
06
For every vendor you hold all three of: a background check, a signed NDA, and a security policy compliance agreement.Para 74

Put it in the contract

05
Every outsourcing agreement carries a right to audit for the bank and a clause recognising RBI’s right to inspect the service provider.Para 73
07
SLAs state the responsibility split on service failure and the grievance redressal route, and are reviewed periodically against security controls.Para 75, 76
08
You have assessed concentration risk, and every agreement has an exit clause that avoids lock-in to a single vendor.Para 72(3)

Know where the data goes

09
Each critical service has a written impact analysis against the adverse scenarios Para 78 lists, including prolonged unavailability.Para 78
10
You can produce an end-to-end data flow map showing where customer data moves across your provider’s shared infrastructure.Para 79
11
You know, and can evidence, where your provider stores every copy and backup of your data, and how their encryption keys are managed.Para 72(5), 81
12
You assess your provider’s user access management — provisioning, de-provisioning, authentication, federation, authorisation, profiles.Para 82

Prove it, and prove it fast

13
If you use a third-party ATM Switch ASP, all thirty-seven Para 85 controls are written into that contract and evidenced against.Para 83, 85
14
Your providers hand you their VA/PT reports and closure evidence on request, and you hold them in one place.Para 85(34–35)
15
A vendor-side incident reaches you fast enough to file on DAKSH within six hours of detection, with the timestamps to prove it.Para 86, 88
0 of 15 answered
0
of 15 yes
Your result

Where the gaps are

Download the full Quick Book
Want the no’s turned into a dated plan? Write to info@shieldbyteinfosec.com.

How Shieldbyte Infosec Can Support UCB Vendor Compliance?

CERT-In empanelled assessors work through this with the people who own the systems, and leave you with evidence rather than an opinion.

info@shieldbyteinfosec.com +91 8104995634 / 9820989640

Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 — RBI/DoS/2026-27/437 · DoS.CO.CSITEG.31/31.01.015/2026-27 dated 31 July 2026. Every paragraph number was taken directly from the circular; the four-move grouping is ours, for readability. This page is a summary prepared for orientation; it does not replace the underlying instrument or professional advice.

error: Content is protected !!