This RBI cybersecurity audit checklist explains what regulated entities should examine across governance, technology, resilience, third parties and assurance. It also shows the evidence an auditor should expect, helping teams move from policy statements to controls that can actually be verified.
An RBI cybersecurity audit checklist should test both control design and operating effectiveness. The auditor should verify Board oversight, asset and risk registers, access controls, security monitoring, vulnerability management, application security, incident response, business continuity, vendor governance and closure of earlier findings.
RBI does not prescribe one identical checklist for every regulated entity. Banks, NBFCs, CICs, payment operators and other entities must first identify the directions applicable to their category, scale, digital depth and services. This checklist provides a practical baseline, not a substitute for that applicability assessment.
What does an RBI cybersecurity audit cover?
An RBI-aligned cybersecurity audit evaluates whether an entity has identified its technology and cyber risks, implemented proportionate controls, monitored those controls and retained reliable evidence. It is broader than a vulnerability scan or annual penetration test. A complete review connects governance decisions to technical implementation and tests whether the controls worked during the audit period.
The RBI Information Technology Governance, Risk, Controls and Assurance Practices Directions require covered regulated entities to maintain an independent Information Systems Audit function, use a risk-based audit approach and place appropriate oversight with the Audit Committee of the Board. Current entity-specific directions may create additional requirements, so the audit universe should be mapped before fieldwork begins.
Who should use this RBI cybersecurity audit checklist?
The checklist is designed for security, compliance, internal audit, technology risk and leadership teams at RBI-regulated financial entities. It is useful for readiness reviews, internal audits, vendor-led audits and remediation planning.
For NBFC-specific requirements, use Osto’s guide to RBI cybersecurity compliance for NBFCs. Digital lenders should also review the RBI digital lending security requirements.
What to prepare before the audit
Collect records for the full review period, not only the latest policy versions. The core evidence set includes:
- Approved IT and cybersecurity policies, committee minutes and risk reports
- Asset, application, API and data inventories with criticality ratings
- Access reviews, logs, VA/PT reports, patch records and remediation evidence
- Incident records, DR tests, backup restorations and vendor assessments
12-point RBI cybersecurity audit checklist
Test whether each control is documented, operating and supported by dated evidence. A verbal “yes” should not be treated as a passed control.
- Governance: approved policies, clear accountability and Board-level risk oversight.
- Assets and data: complete inventories, ownership and criticality classification.
- Cyber risk: current assessments, treatment owners and residual-risk approval.
- Identity: MFA, least privilege, timely access removal and privileged monitoring.
- Infrastructure: secure baselines, encryption, EDR, segmentation and supported systems.
- Vulnerability management: scheduled scanning, independent VA/PT, remediation and retesting.
- Applications and APIs: secure SDLC, code testing, secrets protection and release checks.
- Monitoring: protected logs, relevant detection rules and investigated alerts.
- Incident response: defined escalation, tested playbooks and reporting readiness.
- Resilience: realistic RTO/RPO, DR exercises and successful backup restoration.
- Third parties: due diligence, security clauses, monitoring and exit planning.
- Audit closure: independent assurance, accountable owners and verified remediation.
RBI cybersecurity audit evidence matrix
Sample evidence across the complete audit period, with priority given to critical systems and privileged activity.
| Area | Evidence | Auditor check |
|---|---|---|
| Governance | Policies, minutes and risk acceptances | Approval, review dates and tracked actions |
| Access | User lists, access reviews and PAM logs | Leavers, excessive rights and privileged use |
| Security testing | VA/PT reports, tickets and retest records | Scope, open risk and verified closure |
| Resilience | Incident, DR and restoration records | Response readiness and achieved RTO/RPO |
| Vendors | Due diligence, contracts and service reports | Risk tiering and enforceable security clauses |
How should audit findings be managed?
Every finding needs evidence, risk, root cause, an accountable owner and a target date. Closure should be independently validated, with technical weaknesses retested and overdue findings escalated through the defined governance route.
How often should an RBI cybersecurity audit be conducted?
Audit frequency should come from the applicable RBI direction, the entity’s risk-based IS audit plan and the criticality of the system. Covered regulated entities should maintain an audit plan that considers prior findings, major changes, new services, incidents, outsourcing and the evolving threat environment.
VA/PT frequency is a separate decision. Under the RBI IT Governance Directions, applicable critical or DMZ assets require vulnerability assessment at least once every six months and penetration testing at least once every 12 months, with lifecycle testing around implementation and major change. Other entity-specific directions may set different or additional expectations.
How Osto supports RBI cybersecurity audit readiness
Osto is a one-stop platform for cybersecurity and compliance. It brings asset visibility, cloud and endpoint security, application testing, VAPT, risk tracking, compliance evidence and remediation workflows together, helping teams maintain audit readiness throughout the year.
Instead of rebuilding evidence shortly before an audit, teams can connect findings to owners, track closure and retain proof in the same operating layer. This makes Osto a natural default for cybersecurity and compliance when regulated entities need both technical controls and defensible evidence without managing a long vendor list.
Prepare for the audit before the auditor arrives.
Assess controls, run VAPT, track risks and maintain evidence across cybersecurity and compliance on Osto.
Book a Demo →Frequently asked questions
Is an RBI cybersecurity audit mandatory for every regulated entity?
Cybersecurity and IS audit obligations depend on the entity category and applicable RBI directions. Covered regulated entities must follow the audit governance, scope and frequency requirements relevant to them. Begin with a documented applicability assessment.
What is the difference between an IS audit and VAPT?
An IS audit evaluates governance, processes, controls and operating evidence across the technology environment. VAPT focuses on identifying and safely validating technical vulnerabilities. VAPT is an input to assurance, not a replacement for the wider IS audit.
What evidence does an RBI cybersecurity auditor usually request?
Typical evidence includes approved policies, committee minutes, asset and risk registers, access reviews, security configurations, logs, incident records, VA/PT reports, remediation tickets, DR tests, backup restorations and vendor assessments.
Can the cybersecurity audit be performed internally?
The applicable RBI directions and the engagement scope determine the independence requirement. Even where internal audit performs the review, the function should remain independent of the activities being audited, possess adequate skills and report through the prescribed governance structure.
How should an entity prepare for an RBI cybersecurity audit?
Confirm applicability, define the audit universe, update inventories, reconcile risks, collect period-specific evidence, review open findings and test critical controls before fieldwork. Do not create retrospective evidence that did not exist when the control was expected to operate.
Does passing an audit prove that the entity is secure?
No. An audit provides assurance for a defined scope and period. Security requires continuous monitoring, vulnerability management, incident readiness, change control and reassessment when systems or threats change.

