{"id":6063,"date":"2018-01-04T16:15:12","date_gmt":"2018-01-04T10:45:12","guid":{"rendered":"https:\/\/enterslice.com\/learning\/?p=6063"},"modified":"2020-12-31T14:00:00","modified_gmt":"2020-12-31T08:30:00","slug":"direction-information-technology","status":"publish","type":"post","link":"https:\/\/enterslice.com\/learning\/direction-information-technology\/","title":{"rendered":"RBI Master Direction on Information Technology Framework"},"content":{"rendered":"<p class=\"has-drop-cap\">The <a class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;NBFC&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Non-Banking Financial Companies (NBFC) operate similarly to banks but do not possess the legal status of a bank. Registered under the Companies Act 2013 and governed by the RBI Act&amp;#039;s section(...)&lt;\/div&gt;\"  href=\"https:\/\/enterslice.com\/learning\/terms\/nbfc\/\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]'>NBFC<\/a> (Non-Banking Finance Company) segment has grown up in size &amp; complexity over the ages. The <strong>NBFC<\/strong> (Non-Banking Finance Company) industry develops &amp; attains measure, its Information Technology \/Information Security (IT\/IS) structure, Business Continuity Planning (BCP), Disaster Recovery (DR) Management, IT audit, etc. must be benchmarked to best practices.<\/p>\n\n\n\n<p>In accordance with the directions on IT Structure for the<strong> <a href=\"https:\/\/enterslice.com\/nbfc-registration\">NBFC<\/a><\/strong> sector that is predicted to recover safety, security, efficiency in events leading to aids for NBFCs and their clients are enclosed. NBFCs may have already executed or maybe implementing some of the requirements indicated in the circular. NBFCs are therefore required to conduct a formal gap analysis between their current status and stipulations as laid out in the circular and put in place a time-bound action plan to address the gap and comply with the guidelines.<\/p>\n\n\n\n<p>The emphasis of the projected IT framework is on&nbsp;IT Governance, IT Policy, Information &amp; <strong>Cyber Security<\/strong><sup><a href=\"https:\/\/en.wikipedia.org\/wiki\/Computer_security\">[1]<\/a><\/sup>, IT Operations, IS Audit, Business Continuity Planning &amp; IT Services Outsourcing.&nbsp;The directives are characterized by two parts, those which are applicable to all NBFCs with asset size above &#8377; 500 crores (Considered Systemically Important) are provided in&nbsp;Section-A. Directions for NBFCs with asset size below &#8377; 500 crores are provided in&nbsp;Section-B of the regulation framed by the RBI.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>IT Governance for NBFC<\/strong><\/h2>\n\n\n\n<p>IT Governance is a vital part of <strong>Corporate Governance (CG)<\/strong><sup><a href=\"https:\/\/www.corpgov.net\/2015\/05\/corporate-governance-in-india\/\">[2]<\/a><\/sup>. It contains management support, administrative structure &amp; processes to safeguard that the NBFC&rsquo;s IT withstands &amp; ranges business approaches &amp; objects. Effective IT Governance is the obligation of the Board of Directors &amp; Executive Management.<\/p>\n\n\n\n<p>Definite roles &amp; responsibilities of Board and Senior Management are critical while implementing IT Governance. Clearly-defined roles permit actual project control. IT Governance Stakeholders comprise Board of Directors, IT Strategy Committees, CEOs, Business Executives, Chief Information Officers (CIOs), Chief Technology Officers (CTOs), IT Steering Committees, Chief Risk Officer &amp; Risk Committees.<\/p>\n\n\n\n<p>The simple principles of value delivery, IT Risk Management, IT resource management &amp; performance management must form the <a class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Basis&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;In finance, the &amp;quot;basis&amp;quot; is a term with several applications, including representing the difference between the spot price and the future contract price of an asset, which is vital in investment(...)&lt;\/div&gt;\"  href=\"https:\/\/enterslice.com\/learning\/terms\/basis\/\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]'>basis<\/a> of the governance framework. IT Governance has continuous life-cycle. It&rsquo;s a procedure in which IT strategy drives the procedures, using resources essential to perform responsibilities.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>IT Strategy Committee in NBFC<\/strong><\/h2>\n\n\n\n<p>NBFCs are obligatory to form an IT Strategy Committee. The chairman of the committee shall be an independent director and CIO &amp; CTO should be a part of the committee. The IT Strategy Committee should meet at an appropriate frequency but not more than 6 months should elapse between 2 meetings. The Committee will work in partnership with other Board committees &amp; Senior Management to provide input to them. It will also carry out the review &amp; amend the IT strategies in line with the corporate strategies, Board Policy reviews, cybersecurity arrangements &amp; any other matter related to IT Governance.<\/p>\n\n\n\n<p>Some of the roles and responsibilities comprise, Approving IT strategy &amp; policy documents &amp; ensuring that the management has put an effective <a href=\"https:\/\/enterslice.com\/strategic-planning-services\"><strong>strategic planning <\/strong><\/a>process in place; ascertaining that management has implemented processes &amp; practices that confirm that the IT delivers value to the business; ensuring IT investments represent a balance of risks &amp; benefits and that budgets are acceptable; monitoring the method that management uses to determine the IT resources needed to achieve strategic goals and provide high-level direction for sourcing and use of IT resources; ensuring proper balance of IT investments for sustaining NBFC&rsquo;s growth and becoming aware of exposure towards IT risks and controls.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Require IT Policy for BFC<\/strong><\/h2>\n\n\n\n<p>NBFCs may formulate a Board approved IT policy, in line with the objectives of their organization comprising the subsequent. An IT administrative structure commensurate with the size, scale and nature of business activities carried out by the NBFC; NBFCs may designate a senior executive as the Chief Information Officer (CIO) or in-Charge of IT operations whose responsibility is to ensure implementation of IT Policy to the operational level involving IT strategy, value delivery, risk management and IT resource management.<\/p>\n\n\n\n<p>To ensure technical competence at senior\/middle level management of NBFC, periodic assessment of the IT training requirements should be formulated to confirm that sufficient, competent and capable human resources are available.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Applicability of IT Governance in NBFC<\/strong><\/h2>\n\n\n\n<p><strong>The instructions have been characterized into 2 parts:<\/strong><\/p>\n\n\n\n<ul><li>Directions applicable to all NBFCs with asset size above &#8377; 500 crores (Considered Systemically Important) are provided in Section-A<\/li><li>Directions for NBFCs with asset size below &#8377; 500 crores are provided in Section-B.<\/li><\/ul>\n\n\n\n<p><strong>Section A: systemically important NBFCS i.e. with asset size above &#8377; 500 crore<\/strong><strong>&nbsp;<\/strong><\/p>\n\n\n\n<p>The importance of the strategic IT framework is on IT Governance, IT Policy, Information &amp; Cyber Security, IT Operations, IS Audit, Business Continuity Planning, and IT Services Outsourcing.<\/p>\n\n\n\n<p>Who shall be responsible for the implementation of effective IT Governance?<\/p>\n\n\n\n<p><a href=\"https:\/\/enterslice.com\/learning\/composition-board-of-directors-companies-act\/\"><strong>Board of Directors<\/strong><\/a> and Executive Management &ndash; Well-defined roles and responsibilities to enable effective project control<\/p>\n\n\n\n<p><strong>Who are the IT Governance Stakeholders?<\/strong><\/p>\n\n\n\n<ul><li>Board of Directors<\/li><li>IT Strategy Committees<\/li><li>CEOs<\/li><li>Business Executives<\/li><li>Chief Information Officers (CIOs)<\/li><li>Chief Technology Officers (CTOs)<\/li><li>IT Steering Committees<\/li><\/ul>\n\n\n\n<p><strong>(Operating at an executive level and focusing on priority setting, resource allocation, and project tracking)<\/strong><\/p>\n\n\n\n<ul><li>Chief Risk Officer and Risk Committees<\/li><li>Formation of an IT Strategy Committee<\/li><li>Chairman of the Committee &ndash; An independent director<\/li><li>Other Members &ndash; CIO &amp; CTO<\/li><li>Frequency of Meeting &ndash; An appropriate frequency with a maximum gap of 6 months between two meetings<\/li><\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Role of the Committee<\/strong><\/h4>\n\n\n\n<ul><li>Providing input to other Board committees and Senior Management<\/li><li>Carrying out the review and amending the IT strategies in line with the corporate strategies, Board Policy reviews, cyber security arrangements and any other matter related to IT Governance<\/li><li>Approving IT strategy and policy documents and ensuring that the management has put an effective strategic planning process in place<\/li><li>Ascertaining that management has implemented processes and practices that ensure that the IT delivers value to the business<\/li><li>Ensuring IT investments represent a balance of risks and benefits and that budgets are acceptable<\/li><li>Monitoring the method that management uses to determine the IT resources needed to achieve strategic goals and provide high-level direction for sourcing and use of IT resources<\/li><li>Ensuring the proper balance of IT investments for sustaining NBFC&rsquo;s growth and becoming aware of exposure towards IT risks and controls.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Section B: Directions for NBFCs with asset size below &#8377; 500 crore<\/strong><\/h2>\n\n\n\n<p>It is recommended that smaller NBFCs may start with developing basic IT systems mainly for maintaining the database. NBFCs having asset size below &#8377; 500 crores shall have a Board approved Information Technology policy\/Information system policy. The IT systems shall have:<\/p>\n\n\n\n<ul><li>Basic security aspects such as physical\/ logical access controls and well-defined password policy<\/li><li>A well-defined user role<\/li><li>A Maker-checker concept to reduce the risk of error and misuse and to ensure the reliability of data\/information<\/li><li>Information Security and Cyber Security<\/li><li>Requirements as regards Mobile Financial Services, Social Media, and Digital Signature Certificates<\/li><li>System-generated reports for Top Management summarizing <strong>financial position<\/strong> including operating and non-operating revenues and expenses, cost-benefit analysis of segments\/verticals, cost of funds, etc.<\/li><li>Adequacy to file regulatory returns to RBI (COSMOS Returns)<\/li><li>A BCP policy duly approved by the Board ensuring regular oversight of the Board by way of periodic reports (at least once every year)<\/li><li>Arrangement for backup of data with periodic testing<\/li><li>IT Systems should be progressively scaled up as the size and complexity of NBFC&rsquo;s operations increases.<\/li><\/ul>\n\n\n\n<div class=\"read\"><p><b>Read Also:<\/b> <mark><a href=\"https:\/\/enterslice.com\/learning\/outsourcing-norms-nbfc\/\">Outsourcing Norms for NBFC<\/a><\/mark>.<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The NBFC (Non-Banking Finance Company) segment has grown up in size &amp; complexity over the ages. The NBFC (Non-Banking Finance Company) industry develops &amp; attains measure, its Information Technology \/Information Security (IT\/IS) structure, Business Continuity Planning (BCP), Disaster Recovery (DR) Management, IT audit, etc. must be benchmarked to best practices. In accordance with the directions [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":6064,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[1381],"acf":{"service_id":"8"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v14.6.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>RBI Master Direction on Information Technology Framework - Enterslice<\/title>\n<meta name=\"description\" content=\"The NBFC (Non-Banking Finance Company) industry develops &amp; attains measure, its Information Technology \/Information Security (IT\/IS) structure.\" \/>\n<meta name=\"robots\" content=\"index, follow\" \/>\n<meta name=\"googlebot\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta name=\"bingbot\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/enterslice.com\/learning\/direction-information-technology\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"RBI Master Direction on Information Technology Framework - Enterslice\" \/>\n<meta property=\"og:description\" content=\"The NBFC (Non-Banking Finance Company) industry develops &amp; attains measure, its Information Technology \/Information Security (IT\/IS) structure.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/enterslice.com\/learning\/direction-information-technology\/\" \/>\n<meta property=\"og:site_name\" content=\"Enterslice\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/enterslice\" \/>\n<meta property=\"article:author\" content=\"enterslice\" \/>\n<meta property=\"article:published_time\" content=\"2018-01-04T10:45:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-12-31T08:30:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/enterslice.com\/learning\/wp-content\/uploads\/2018\/01\/pexels-photo-572056.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:creator\" content=\"@enterslice\" \/>\n<meta name=\"twitter:site\" content=\"@enterslice\" \/>\n<!-- \/ Yoast SEO plugin. -->","authorName":"Narendra Kumar","authorImageUrl":"https:\/\/enterslice.com\/learning\/wp-content\/uploads\/2019\/04\/nk-1.jpg","authorDescription":"Experienced Finance and Legal Professional with 12+ Years of Experience in Legal, Finance, Fintech, Blockchain, and Revenue Management.","postViews":664,"readingTime":4,"nextPost":{"id":6066,"slug":"it-policy-nbfc-rbi"},"prevPost":{"id":6057,"slug":"director-allowed-mfi-microfinance"},"featuredMediaUrl":"https:\/\/enterslice.com\/learning\/wp-content\/uploads\/2018\/01\/pexels-photo-572056.jpeg","postTerms":"NBFC","_links":{"self":[{"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/posts\/6063"}],"collection":[{"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/comments?post=6063"}],"version-history":[{"count":0,"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/posts\/6063\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/media\/6064"}],"wp:attachment":[{"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/media?parent=6063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/categories?post=6063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/enterslice.com\/learning\/wp-json\/wp\/v2\/tags?post=6063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}