A CERT-In Empanelled Auditing Organization
Home/Blog/Regulatory Updates
Regulatory Updates

Local Area Banks and RBI compliance: exempt, but not off the hook

Local Area Banks occupy an unusual corner of India’s banking regulation. They are full-fledged licensed banks, they take deposits, lend, and run core banking systems, but they are small, regionally confined, and few in number. That combination produces a compliance position that is widely misread: because one of the RBI’s headline technology directions carves them out, it is easy to conclude that LABs sit outside the cyber-compliance net altogether. They do not. The carve-out is narrow, and the underlying obligations remain firmly in place.

This piece sets out what a Local Area Bank actually has to do on cyber security and IT risk, what applies, what is explicitly exempt, and where the real supervisory exposure lies for a small bank running lean.

First, what a Local Area Bank is

The Local Area Bank scheme was introduced by the RBI in 1996 to bring institutional banking to a small cluster of contiguous districts, with a mandate weighted towards agriculture, rural credit and financial inclusion. A LAB is licensed under the Banking Regulation Act, 1949, operates within a restricted geography, and is deliberately modest in scale, small capital base, a limited branch network, and a customer franchise concentrated in its home region.

Crucially for compliance purposes: a LAB is a bank. It is not an NBFC, not a cooperative bank, and not a payments or small finance bank. That legal character is what determines which parts of the RBI’s technology rulebook reach it, and being a bank means the baseline expectations do not disappear just because the institution is small.

The exemption that causes the confusion

On 7 November 2023 the RBI issued its Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (the ITGRCA Directions), effective 1 April 2024. This is the consolidated, modern IT-governance rulebook for the financial sector, board-level IT strategy committees, a designated head of IT, formal IT and information-security risk management, business continuity and disaster recovery, and independent IS audit.

That Master Direction explicitly does not apply to Local Area Banks. The Directions list their applicability to scheduled commercial banks, small finance banks, payments banks, NBFCs in the upper tiers, credit information companies and the all-India financial institutions, and expressly exclude Local Area Banks (alongside NBFC-Core Investment Companies and Base Layer NBFCs).

The exemption is from the 2023 IT-governance consolidation. It is not a general exemption from cyber security, incident reporting, or the RBI’s supervisory expectations. Reading it as “LABs are out of scope for IT compliance” is the single most common and most dangerous misreading.

Why the carve-out exists is a matter of proportionality: the 2023 Directions impose a committee-and-assurance structure calibrated for larger, more complex institutions, and the RBI chose not to force that machinery onto the smallest banks. But proportionality reduces the overhead; it does not switch off the obligations.

What still applies to a Local Area Bank

Strip away the 2023 Master Direction and a substantial compliance surface remains. In practice, a LAB should treat the following as live obligations or firm supervisory expectations.

ObligationSourceWhat it means for a LAB
Cyber Security Framework for banksRBI circular, 2016 (and subsequent)The foundational cyber-security expectations issued to banks, a board-approved cyber-security policy, a cyber-crisis management plan, baseline security controls, and incident reporting. As a bank, a LAB falls within its intended universe.
CERT-In incident reportingCERT-In Directions, April 2022 (under the IT Act)Applies to all organisations, financial or not. Specified cyber incidents must be reported to CERT-In within six hours of noticing them, with logs retained for 180 days.
Cyber incident reporting to RBIRBI supervisory expectationMaterial cyber incidents are expected to be reported to the RBI, in addition to CERT-In, increasingly through the RBI’s centralised reporting mechanisms.
VAPT of internet-facing systemsBaseline security practice / supervisory expectationVulnerability assessment and penetration testing of internet-facing applications and infrastructure, at least annually and after significant change. Supervisors now expect manual penetration testing, evidenced remediation and re-testing, not just a scan report.
IS audit of IT systemsLong-standing RBI expectation for banksPeriodic, independent information-systems audit of the bank’s IT environment, with findings tracked to closure and made available to RBI inspection.
Outsourcing / third-party IT riskRBI outsourcing expectationsLABs typically run on outsourced core banking and managed IT. Vendor due diligence, contractual security and audit rights, and oversight of the service provider remain the bank’s responsibility, outsourcing the function does not outsource the accountability.
Digital payment security controlsRBI, 2021Where a LAB offers internet or mobile banking, card, or UPI-linked services, the digital payment security control expectations apply to those channels.
DPDP Act, 2023 & Rules, 2025MeitY / DPDP frameworkA parallel, non-RBI obligation. A LAB processes large volumes of personal and financial data and must meet DPDP notice, consent, security-safeguard, breach-notification and retention duties as they commence, ending 13 May 2027.

Read together, the picture is clear: a LAB is exempt from one consolidation circular, not from cyber security. A board-approved security policy, an incident-response capability wired to both CERT-In and the RBI, annual VAPT with evidenced remediation, periodic IS audit, and disciplined vendor oversight are all still expected of it.

The gap between the letter and supervision

There is a distinction worth naming plainly. The letter of the 2023 Master Direction excludes LABs. Supervisory expectation is a broader thing. When the RBI inspects a small bank, it does not ignore cyber resilience because a particular consolidation circular carved the entity out; it assesses whether the bank has controls commensurate with its size, nature and risk profile. A LAB that treats the exemption as a licence to do nothing on cyber security is exposed, not necessarily to a specific circular breach, but to adverse supervisory findings, directions to remediate, and reputational risk if an incident occurs and the bank cannot show it took reasonable steps.

The proportionality principle cuts both ways. It means a two-branch bank is not expected to stand up the same committee architecture as a large private bank. It also means the bank cannot point to its size as a reason for having no cyber-security policy, no tested incident response, and no independent assurance over its outsourced core banking platform.

Where the real risk sits for a small bank

The compliance conversation for a LAB is less about volume of controls and more about a handful of concentrated exposures:

A proportionate compliance baseline

A Local Area Bank does not need an enterprise security programme. It needs a defensible, right-sized one. In practice, that means being able to evidence the following:

AreaWhat “done” looks like for a LAB
Governance & policyA board-approved cyber-security policy and cyber-crisis management plan, reviewed at least annually, with a named owner for information security even if the role is combined with another.
Risk assessmentA periodic IT and information-security risk assessment covering the core banking platform, digital channels and key vendors.
VAPTAnnual vulnerability assessment and penetration testing of internet-facing systems, plus testing after significant change, with findings remediated and re-tested, conducted by a CERT-In empanelled auditor.
Incident responseA documented, rehearsed response playbook that meets the six-hour CERT-In deadline and the RBI reporting expectation in parallel, with logs retained for 180 days.
IS auditIndependent information-systems audit at a proportionate frequency, findings tracked to closure and available to RBI inspection.
Vendor oversightDue diligence on the core banking and IT service providers, contractual security and audit rights, and evidence that oversight actually happens.
Data protectionA DPDP readiness track running in parallel, data mapping, consent and notice, security safeguards and breach response, against the May 2027 horizon.

The bottom line

Local Area Banks are exempt from the RBI’s 2023 IT Governance Master Direction, and from very little else. As licensed banks they remain within the reach of the cyber-security framework, CERT-In’s six-hour reporting rule, VAPT and IS-audit expectations, outsourcing accountability, digital-payment controls and the DPDP Act. The right posture is not to claim exemption but to build a proportionate, evidenced programme that a supervisor would recognise as reasonable for a bank of that size. Small does not mean out of scope; it means the controls should be sized to the institution, not absent from it.

SICHERTEN works with regulated financial entities across the RBI spectrum, our RBI security audits and VAPT for compliance engagements are built to produce exactly the evidence an inspection expects, sized to the entity. For the data-protection track, our DPDPA readiness assessment maps the parallel obligation. And if you are weighing where a small bank’s reporting duties overlap, CERT-In’s six-hour rule is the tighter clock to plan around.

Regulatory note: the applicability and exemption positions above reflect the RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023, effective 1 April 2024), the RBI Cyber Security Framework (2016 and subsequent circulars), CERT-In Directions (2022) and the DPDP Act, 2023 and Rules, 2025. Regulatory positions evolve and supervisory expectations are entity-specific; confirm the current position against the applicable RBI circulars and your supervisory correspondence before relying on this for a compliance decision.

RBILocal Area BanksBankingCERT-InIT Governance
Share

Keep reading

Related insights

Regulatory Updates

RBI IT governance: a primer for NBFCs

The RBI has raised its expectations on IT governance, risk and audit for NBFCs. A high-level primer on the obligations and how non-banking finance companies can meet them.

3 min read
Regulatory Updates

RBI, SEBI and IRDAI: keeping pace with India’s financial-sector cyber rules

India’s financial regulators have raised the bar on cybersecurity and resilience. A high-level guide to the RBI, SEBI and IRDAI expectations and how regulated entities can stay current.

4 min read
Regulatory Updates

CERT-In’s six-hour incident reporting: what Indian organisations must do

CERT-In requires certain cyber incidents to be reported within six hours. What the directions cover, the obligations they create, and how to be ready to report in time.

4 min read

Have a question this raised?

Our team turns guidance like this into working compliance and security programmes. Tell us where you are, we’ll help you plan the next step.