RBI DAKSH Platform: Meaning, Uses and Cyber Incident Reporting

DAKSH RBI Advanced Supervisory Monitoring System explained

Meaning, Uses and Cyber Incident Reporting

DAKSH is the Reserve Bank of India’s supervisory platform. Banks and NBFCs use it to report to RBI, and what they report increasingly includes their vendors.

  • Glossary
  • India

The short answer

DAKSH is the Reserve Bank’s Advanced Supervisory Monitoring System, a web-based workflow application launched in October 2022 as part of RBI’s SupTech programme. Supervised entities such as banks and NBFCs use it to submit compliance responses, receive inspection communications, and report cyber incidents and payment frauds. The name means efficient and competent in Hindi. You only get a DAKSH login if you are a supervised entity; vendors never do.

That last line is why the term matters to software companies. You will not log into DAKSH, but incidents involving your product can end up inside it, filed by your customer, against their regulatory clock.

What DAKSH is

RBI supervises thousands of regulated entities. Historically that supervision ran on email, spreadsheets and fragmented returns. DAKSH consolidates it into one platform with anytime, anywhere secure access, covering inspection planning and execution, compliance monitoring, cyber incident reporting and analysis, and management reporting.

It is a supervisory tool rather than a compliance framework. DAKSH does not create new security obligations. It is the pipe through which existing obligations are evidenced, chased and escalated, which in practice makes those obligations far harder to let slide.

You, the vendor SaaS, infrastructure, or a managed service serves Supervised entity Bank, NBFC, UCB, payment operator files in DAKSH The supervisory platform RBI Supervisor No DAKSH access You never file into DAKSH. Your customer does, and an incident on your side becomes their filing. Their regulatory clock starts whether or not you have answers ready.
Swipe to see the full diagram. Supervision reaches vendors indirectly, through the entity they supply.

What flows through it

FunctionWhat happens
Compliance monitoringRBI tracks whether entities have acted on supervisory observations, with responses submitted and reviewed in the platform
Inspection planning and executionInspection scheduling, information requests and document exchange run through DAKSH rather than email
Cyber incident reportingEntities report and RBI analyses cyber incidents through the platform
Payment fraud reportingCentral Payments Fraud Information Registry reporting migrated to DAKSH from January 2023
Advisories and alertsRBI issues advisories directly to entities, with acknowledgement tracked
Dashboards and MISScreen-based reporting with maker-checker controls and generated management reports

The effect on tempo

When responses live in a tracked workflow rather than an inbox, an open item stays visible until it is closed. Supervised entities feel that pressure, and they pass it to their vendors as shorter deadlines on evidence requests.

Who has access, and who does not

Supervised entities

Banks, NBFCs, urban co-operative banks and payment system operators hold DAKSH credentials.

RBI supervisors

Inspection teams plan, request, review and escalate inside the same platform.

Vendors and service providers

No access, no login, no direct filing. Everything reaches RBI through the entity you serve.

If a vendor tells you they will handle your DAKSH submissions or make you DAKSH compliant, treat it as a misunderstanding of what DAKSH is. There is no vendor-side registration and no compliance status attached to it.

What it means if you sell to banks

DAKSH raises the cost of a slow answer. Your customer is working to a supervisory timeline they do not control, and anything they owe RBI that depends on you becomes an urgent request to you.

What your customer will need from youHow to be ready
Incident details fast enough to meet their reporting windowDetection and correlated logs that establish scope in hours, plus a defined escalation contact
Evidence that controls exist and operateContinuous evidence rather than screenshots gathered on request
Recent independent testing of your applicationA current VAPT report with remediation and retest closed out
Answers to a long vendor security questionnaireA maintained answer set, not a fresh effort per deal
Assurance mapped to a recognised frameworkISO 27001 or a SOC 2 report, plus DPDP alignment

None of this is DAKSH-specific. It is ordinary vendor diligence, applied with less patience because the entity asking is being tracked on a clock.

How Osto helps vendors keep pace

Osto covers the side of this that you control. SIEM with cross-module correlation establishes incident scope quickly instead of over days of forensics, expert-led VAPT and continuous scanning keep testing current, cloud posture, access control and encryption hold the controls a bank will ask about, and AI security questionnaires return answers in minutes. Evidence collects continuously across ISO 27001, SOC 2 and DPDP from the same controls.

Free security assessment

Answer your bank customer before the clock runs out

Correlated detection, current VAPT and continuous evidence, so a supervisory request never becomes a scramble on your side.

Get a free security assessment Book a platform walkthrough

Questionnaires in minutes · Evidence collected continuously · One platform, everything

Frequently asked questions

What is DAKSH in RBI?

DAKSH is the Reserve Bank’s Advanced Supervisory Monitoring System, a web-based workflow application launched in October 2022. Supervised entities use it for compliance responses, inspection communication, cyber incident reporting and payment fraud reporting.

What does DAKSH stand for?

It is not an acronym. DAKSH is a Hindi word meaning efficient and competent, chosen by RBI to reflect the intended capabilities of the platform.

Who can access the DAKSH portal?

RBI supervised entities such as banks, NBFCs, urban co-operative banks and payment system operators, along with RBI supervisory teams. Vendors and service providers have no access.

Can a SaaS vendor be DAKSH compliant?

No. DAKSH is a reporting platform for supervised entities, not a certification or framework. What a bank actually needs from a vendor is security controls, current testing and evidence it can rely on when it files.

Is cyber incident reporting to RBI done through DAKSH?

Yes, cyber incident reporting and analysis is one of the functions RBI built into DAKSH, alongside compliance monitoring and inspection workflows. Payment fraud reporting under CPFIR also moved to the platform in January 2023.

How is DAKSH different from CERT-In reporting?

DAKSH is RBI’s supervisory channel for its regulated entities. CERT-In operates a separate national incident reporting regime that applies far more broadly. A bank may have obligations under both.