Skip to content
Finin2min
RBI · Outsourcing and IT Governance

22–28: Risk, confidentiality and security

Paragraph-level professional implementation page for Outsourcing and IT Governance.

Outsourcing and IT Governance22–28Banking Regulation Act, 1949 section 35A; IT/data overlays

Finin2min Summary — in 2 Minutes

22–28 — Risk, confidentiality and security. Assess strategic, reputation, compliance, operational, legal, exit, concentration and country risk; report breaches.

Official source and legal ownership

Instrument ownerBanking Regulation Act, 1949 section 35A; IT/data overlays
Source statusCURRENT OFFICIAL SOURCE GATEWAY
Review date2026-07-19
Primary sourceCommercial Banks Managing Risks in Outsourcing Directions, 2025

Paragraph-wise Finin2min interpretation

Legal trigger

Assess strategic, reputation, compliance, operational, legal, exit, concentration and country risk; report breaches.

Control owner

Business identifies the event; Compliance confirms law; Operations/Technology executes; Independent review tests evidence.

Evidence

Official source snapshot, policy/SOP, system rule, customer/transaction record, maker-checker log, exception approval and regulatory acknowledgement.

Failure consequence

Customer harm, reporting defect, prudential misstatement, supervisory observation, monetary penalty, restriction or remediation.

Practical example

Scenario: An exception arises under Risk, confidentiality and security. The owner records the trigger, regulated entity, paragraph/reference 22–28, affected customer or exposure, applicable threshold, approval and system evidence. Compliance then tests the result against the official source rather than relying on a generic policy statement.

Implementation and evidence controls

Practical Q&A

What is the first test for Risk, confidentiality and security?

Confirm entity, product, event date, official paragraph and any stated exception.

Can a portal or system acceptance cure a legal defect?

No. Technical processing does not override the substantive Direction.

What should be retained for review?

The official source version, legal mapping, calculation or decision record, approvals, communications and filing evidence.

← PreviousNext →