RBI UCB Vendor Obligations 2026Section U Compliance Guide
The RBI (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 came into force with immediate effect and repealed the previous framework. The vendor obligation — Section U, paragraphs 71 to 86 — sits in Chapter III, the Level I baseline.
Get the Full Quick Book
Enter your details below for instant access to the Quick Book and continue with the scope check.
Here it is.
Your download should have started automatically. If it did not, use the button below.
Prefer to talk it through? Write to info@shieldbyteinfosec.com or call +91 8104995634 / 9820989640.
Which Urban Co-operative Banks Need to Comply?
Paragraph 10 makes deciding your level your own obligation, not your auditor’s — and the level you land on decides which chapters you are audited against. Section U sits below all of that, in the baseline, so it binds you either way.
| Level | Criteria (paragraph 4) | Chapters that bind you |
|---|---|---|
| Level I | Every UCB, irrespective of the digital services or products it offers. | Chapters II and III |
| Level II | Sub-member of Centralised Payment Systems and offers internet banking, or mobile banking through an app, or is a direct member of CTS / IMPS / UPI. | + Chapter IV |
| Level III | Direct member of CPS, or has its own ATM Switch, or has a SWIFT interface. | + Chapter V |
| Level IV | Direct or sub-member of CPS and either has its own ATM Switch and SWIFT interface, or hosts a data centre or provides software support to other banks. | + Chapter VI |
Key RBI Vendor Obligations for UCBs
Read paragraph by paragraph, Section U looks larger than it is. Grouped by what an inspector would actually ask to see, it comes down to four things — each of which has to exist as a dated artefact, not a stated intention.
Know who they are Para 71, 72, 74
A single register of every third-party vendor, service provider and partner, with the criticality of each service recorded against it. Due diligence run before contracting and repeated on an ongoing basis, covering all eight dimensions Para 72 names — including the provider’s virtualisation framework and its information lifecycle. For each vendor: a background check, a signed NDA, and a security policy compliance agreement.
Put it in the contract Para 73, 75–77
Every outsourcing agreement carries a right to audit for the bank and a clause recognising RBI’s right to inspect the service provider. SLAs state the responsibility split on service failure and the grievance redressal route, are reviewed periodically against security controls, and carry a defined escalation procedure. Concentration risk is assessed, and exit is possible without lock-in.
Know where the data goes Para 78–82
A written impact analysis for each critical service against the adverse scenarios Para 78 lists, prolonged unavailability included. An end-to-end data flow map showing where customer data moves across the provider’s shared infrastructure. Evidence of where every copy and backup is stored and how encryption keys are managed. An assessment of the provider’s user access management, end to end.
Prove it, and prove it fast Para 83, 85, 86, 88
Where a third-party ATM Switch ASP is used, the thirty-seven Para 85 controls written into that contract and evidenced against. VA/PT reports and closure evidence handed over on request. And a vendor-side incident reaching you fast enough to file on DAKSH within six hours of detection — with the timestamps to prove when you knew.
What Evidence Should UCBs Maintain for Vendor Compliance
ShieldRisk.ai is Shieldbyte Infosec’s third-party risk governance platform — one system of record for onboarding, background checks, contract analysis, assessment, audit and evidence, so the pack is assembled as you go rather than under deadline.
| Paragraph | What RBI requires | What ShieldRisk does about it |
|---|---|---|
| Para 71, 72 | Regular, effective due diligence, oversight and management of third-party vendors, providers and partners — on an ongoing basis. | Vendor Register as the single system of record, Deep BGV at onboarding, and the Audit Planner driving recurring cycles rather than one-off reviews. |
| Para 74 | Background checks mandated for all third-party providers; satisfaction as to the credentials of vendor personnel accessing critical assets. | One-click Deep BGV across MCA, PAN, GST and MSME plus 20,000+ court, litigation, fraud and sanctions sources — entity and representative. |
| Para 73–77 | Agreement clauses: right to audit, RBI’s right to inspect the provider, SLA responsibility split, periodic review and escalation. | AI Contract Analyzer reads the MSA, SLA and NDA and flags weak or missing terms against the clauses the section requires. |
| Para 78–82 | Impact analysis for adverse scenarios, data location and lifecycle, encryption and key management, and the provider’s user access management. | Compliance Assessment questionnaires per vendor, with the responses and supporting artefacts held against the vendor record. |
| Para 85–86 | Controls written into the ASP contract and evidenced; VA/PT reports and closure evidence produced on request. | Evidence Vault and Findings, so every report, closure note and acknowledgement is filed against the vendor and the date it was produced. |
RBI UCB Vendor Compliance Self-Check
Fifteen statements, each tied to the paragraph that raises it. A ‘no’ is not a failure — it is a finding an inspector would raise, and every one is closable. What matters is dated evidence, per vendor, rather than a policy that says you would.
Open the check
Fill the short form at the top of this page. It opens the check here and the full document at the same time — it takes about a minute.
Take me to the formYour level
Know who they are
Put it in the contract
Know where the data goes
Prove it, and prove it fast
Where the gaps are
How Shieldbyte Infosec Can Support UCB Vendor Compliance?
CERT-In empanelled assessors work through this with the people who own the systems, and leave you with evidence rather than an opinion.
Reserve Bank of India (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 — RBI/DoS/2026-27/437 · DoS.CO.CSITEG.31/31.01.015/2026-27 dated 31 July 2026. Every paragraph number was taken directly from the circular; the four-move grouping is ours, for readability. This page is a summary prepared for orientation; it does not replace the underlying instrument or professional advice.