Meaning, Uses and Cyber Incident Reporting
DAKSH is the Reserve Bank of India’s supervisory platform. Banks and NBFCs use it to report to RBI, and what they report increasingly includes their vendors.
The short answer
DAKSH is the Reserve Bank’s Advanced Supervisory Monitoring System, a web-based workflow application launched in October 2022 as part of RBI’s SupTech programme. Supervised entities such as banks and NBFCs use it to submit compliance responses, receive inspection communications, and report cyber incidents and payment frauds. The name means efficient and competent in Hindi. You only get a DAKSH login if you are a supervised entity; vendors never do.
That last line is why the term matters to software companies. You will not log into DAKSH, but incidents involving your product can end up inside it, filed by your customer, against their regulatory clock.
On this page
What DAKSH is
RBI supervises thousands of regulated entities. Historically that supervision ran on email, spreadsheets and fragmented returns. DAKSH consolidates it into one platform with anytime, anywhere secure access, covering inspection planning and execution, compliance monitoring, cyber incident reporting and analysis, and management reporting.
It is a supervisory tool rather than a compliance framework. DAKSH does not create new security obligations. It is the pipe through which existing obligations are evidenced, chased and escalated, which in practice makes those obligations far harder to let slide.
What flows through it
| Function | What happens |
|---|---|
| Compliance monitoring | RBI tracks whether entities have acted on supervisory observations, with responses submitted and reviewed in the platform |
| Inspection planning and execution | Inspection scheduling, information requests and document exchange run through DAKSH rather than email |
| Cyber incident reporting | Entities report and RBI analyses cyber incidents through the platform |
| Payment fraud reporting | Central Payments Fraud Information Registry reporting migrated to DAKSH from January 2023 |
| Advisories and alerts | RBI issues advisories directly to entities, with acknowledgement tracked |
| Dashboards and MIS | Screen-based reporting with maker-checker controls and generated management reports |
The effect on tempo
When responses live in a tracked workflow rather than an inbox, an open item stays visible until it is closed. Supervised entities feel that pressure, and they pass it to their vendors as shorter deadlines on evidence requests.
Who has access, and who does not
Supervised entities
Banks, NBFCs, urban co-operative banks and payment system operators hold DAKSH credentials.
RBI supervisors
Inspection teams plan, request, review and escalate inside the same platform.
Vendors and service providers
No access, no login, no direct filing. Everything reaches RBI through the entity you serve.
If a vendor tells you they will handle your DAKSH submissions or make you DAKSH compliant, treat it as a misunderstanding of what DAKSH is. There is no vendor-side registration and no compliance status attached to it.
What it means if you sell to banks
DAKSH raises the cost of a slow answer. Your customer is working to a supervisory timeline they do not control, and anything they owe RBI that depends on you becomes an urgent request to you.
| What your customer will need from you | How to be ready |
|---|---|
| Incident details fast enough to meet their reporting window | Detection and correlated logs that establish scope in hours, plus a defined escalation contact |
| Evidence that controls exist and operate | Continuous evidence rather than screenshots gathered on request |
| Recent independent testing of your application | A current VAPT report with remediation and retest closed out |
| Answers to a long vendor security questionnaire | A maintained answer set, not a fresh effort per deal |
| Assurance mapped to a recognised framework | ISO 27001 or a SOC 2 report, plus DPDP alignment |
None of this is DAKSH-specific. It is ordinary vendor diligence, applied with less patience because the entity asking is being tracked on a clock.
How Osto helps vendors keep pace
Osto covers the side of this that you control. SIEM with cross-module correlation establishes incident scope quickly instead of over days of forensics, expert-led VAPT and continuous scanning keep testing current, cloud posture, access control and encryption hold the controls a bank will ask about, and AI security questionnaires return answers in minutes. Evidence collects continuously across ISO 27001, SOC 2 and DPDP from the same controls.
Free security assessment
Answer your bank customer before the clock runs out
Correlated detection, current VAPT and continuous evidence, so a supervisory request never becomes a scramble on your side.
Get a free security assessment Book a platform walkthroughQuestionnaires in minutes · Evidence collected continuously · One platform, everything
Frequently asked questions
What is DAKSH in RBI?
DAKSH is the Reserve Bank’s Advanced Supervisory Monitoring System, a web-based workflow application launched in October 2022. Supervised entities use it for compliance responses, inspection communication, cyber incident reporting and payment fraud reporting.
What does DAKSH stand for?
It is not an acronym. DAKSH is a Hindi word meaning efficient and competent, chosen by RBI to reflect the intended capabilities of the platform.
Who can access the DAKSH portal?
RBI supervised entities such as banks, NBFCs, urban co-operative banks and payment system operators, along with RBI supervisory teams. Vendors and service providers have no access.
Can a SaaS vendor be DAKSH compliant?
No. DAKSH is a reporting platform for supervised entities, not a certification or framework. What a bank actually needs from a vendor is security controls, current testing and evidence it can rely on when it files.
Is cyber incident reporting to RBI done through DAKSH?
Yes, cyber incident reporting and analysis is one of the functions RBI built into DAKSH, alongside compliance monitoring and inspection workflows. Payment fraud reporting under CPFIR also moved to the platform in January 2023.
How is DAKSH different from CERT-In reporting?
DAKSH is RBI’s supervisory channel for its regulated entities. CERT-In operates a separate national incident reporting regime that applies far more broadly. A bank may have obligations under both.

