RBI issues detailed norms for outsourcing of IT services by banks, NBFCs
PTI, Apr 10, 2023, 8:22 PM IST
Image credit: ANI / FIle
Mumbai: Reserve Bank of India on Monday came out with detailed norms for outsourcing of IT services by banks, NBFCs and regulated financial sector entities to ensure that such arrangements do not undermine their responsibilities and obligations to customers.
In its ‘Master Direction on Outsourcing of Information Technology Services’, RBI said that Regulated Entities (REs) have been extensively leveraging IT and IT-enabled Services (ITeS) to support their business models, products and services offered to their customers.
In February last year, the central bank proposed the issuance of suitable regulatory guidelines on outsourcing of IT services with an aim to ensure effective management of attendant risks. Later, draft norms were issued.
According to RBI, the underlying principle of the directions is to ensure that outsourcing arrangements neither diminish REs’ ability to fulfil its obligations to customers nor impede effective supervision by the central bank.
With a view to provide REs adequate time to comply with the requirements, the norms will come into effect from October 1, 2023.
A RE shall take steps to ensure that the service provider employs the same high standard of care in performing the services as would have been employed by the RE, if the same activity was not outsourced, the central bank said.
According to the central bank, a RE should not engage an IT service provider that would result in reputation of RE being compromised or weakened.
Notwithstanding whether the service provider is located in India or abroad, REs should ensure that outsourcing should neither impede nor interfere with the ability of the RE to effectively oversee and manage its activities, as per RBI.
Further, REs have been told to evaluate the need for outsourcing of IT services based on comprehensive assessment of attendant benefits, risks and availability of commensurate processes to manage those risks.
On governance framework, RBI said a RE intending to outsource any of its IT activities should have a comprehensive board-approved IT outsourcing policy.
Financial institutions should also put in place a risk management framework for outsourcing that should comprehensively deal with the processes and responsibilities for identification, measurement, mitigation, management, and reporting of risks associated with outsourcing of IT services arrangements.
Also, REs should ask their service providers to develop and establish a robust framework for documenting, maintaining and testing business continuity plan and disaster recovery plan.
A RE can also outsource any IT activity/ IT-enabled service within its business group/ conglomerate, subject to conditions specified to the conditions specified in the Master Direction.
Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.
Top News
Related Articles More
Army Havaldar Anoop Poojary cremated with full honours in Karnataka’s Udupi
13-year-old rape victim dies after giving birth to stillborn baby in Rajasthan’s Dungarpur
Row over Shah’s Ambedkar remarks: Dalit, Adivasi, OBC groups to protest in Gujarat on Dec 28
Kerala bids emotional farewell to MT Vasudevan Nair
‘Shameful, condemnable’: Rahul slams police action against protesting BPSC candidates in Patna
MUST WATCH
Latest Additions
Army Havaldar Anoop Poojary cremated with full honours in Karnataka’s Udupi
13-year-old rape victim dies after giving birth to stillborn baby in Rajasthan’s Dungarpur
YouTuber and his girlfriend rescued from drowning by IPS officer in Goa
Row over Shah’s Ambedkar remarks: Dalit, Adivasi, OBC groups to protest in Gujarat on Dec 28
Kerala bids emotional farewell to MT Vasudevan Nair
Thanks for visiting Udayavani
You seem to have an Ad Blocker on.
To continue reading, please turn it off or whitelist Udayavani.