Local Area Banks occupy an unusual corner of India’s banking regulation. They are full-fledged licensed banks, they take deposits, lend, and run core banking systems, but they are small, regionally confined, and few in number. That combination produces a compliance position that is widely misread: because one of the RBI’s headline technology directions carves them out, it is easy to conclude that LABs sit outside the cyber-compliance net altogether. They do not. The carve-out is narrow, and the underlying obligations remain firmly in place.
This piece sets out what a Local Area Bank actually has to do on cyber security and IT risk, what applies, what is explicitly exempt, and where the real supervisory exposure lies for a small bank running lean.
First, what a Local Area Bank is
The Local Area Bank scheme was introduced by the RBI in 1996 to bring institutional banking to a small cluster of contiguous districts, with a mandate weighted towards agriculture, rural credit and financial inclusion. A LAB is licensed under the Banking Regulation Act, 1949, operates within a restricted geography, and is deliberately modest in scale, small capital base, a limited branch network, and a customer franchise concentrated in its home region.
Crucially for compliance purposes: a LAB is a bank. It is not an NBFC, not a cooperative bank, and not a payments or small finance bank. That legal character is what determines which parts of the RBI’s technology rulebook reach it, and being a bank means the baseline expectations do not disappear just because the institution is small.
The exemption that causes the confusion
On 7 November 2023 the RBI issued its Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (the ITGRCA Directions), effective 1 April 2024. This is the consolidated, modern IT-governance rulebook for the financial sector, board-level IT strategy committees, a designated head of IT, formal IT and information-security risk management, business continuity and disaster recovery, and independent IS audit.
That Master Direction explicitly does not apply to Local Area Banks. The Directions list their applicability to scheduled commercial banks, small finance banks, payments banks, NBFCs in the upper tiers, credit information companies and the all-India financial institutions, and expressly exclude Local Area Banks (alongside NBFC-Core Investment Companies and Base Layer NBFCs).
The exemption is from the 2023 IT-governance consolidation. It is not a general exemption from cyber security, incident reporting, or the RBI’s supervisory expectations. Reading it as “LABs are out of scope for IT compliance” is the single most common and most dangerous misreading.
Why the carve-out exists is a matter of proportionality: the 2023 Directions impose a committee-and-assurance structure calibrated for larger, more complex institutions, and the RBI chose not to force that machinery onto the smallest banks. But proportionality reduces the overhead; it does not switch off the obligations.
What still applies to a Local Area Bank
Strip away the 2023 Master Direction and a substantial compliance surface remains. In practice, a LAB should treat the following as live obligations or firm supervisory expectations.
| Obligation | Source | What it means for a LAB |
|---|---|---|
| Cyber Security Framework for banks | RBI circular, 2016 (and subsequent) | The foundational cyber-security expectations issued to banks, a board-approved cyber-security policy, a cyber-crisis management plan, baseline security controls, and incident reporting. As a bank, a LAB falls within its intended universe. |
| CERT-In incident reporting | CERT-In Directions, April 2022 (under the IT Act) | Applies to all organisations, financial or not. Specified cyber incidents must be reported to CERT-In within six hours of noticing them, with logs retained for 180 days. |
| Cyber incident reporting to RBI | RBI supervisory expectation | Material cyber incidents are expected to be reported to the RBI, in addition to CERT-In, increasingly through the RBI’s centralised reporting mechanisms. |
| VAPT of internet-facing systems | Baseline security practice / supervisory expectation | Vulnerability assessment and penetration testing of internet-facing applications and infrastructure, at least annually and after significant change. Supervisors now expect manual penetration testing, evidenced remediation and re-testing, not just a scan report. |
| IS audit of IT systems | Long-standing RBI expectation for banks | Periodic, independent information-systems audit of the bank’s IT environment, with findings tracked to closure and made available to RBI inspection. |
| Outsourcing / third-party IT risk | RBI outsourcing expectations | LABs typically run on outsourced core banking and managed IT. Vendor due diligence, contractual security and audit rights, and oversight of the service provider remain the bank’s responsibility, outsourcing the function does not outsource the accountability. |
| Digital payment security controls | RBI, 2021 | Where a LAB offers internet or mobile banking, card, or UPI-linked services, the digital payment security control expectations apply to those channels. |
| DPDP Act, 2023 & Rules, 2025 | MeitY / DPDP framework | A parallel, non-RBI obligation. A LAB processes large volumes of personal and financial data and must meet DPDP notice, consent, security-safeguard, breach-notification and retention duties as they commence, ending 13 May 2027. |
Read together, the picture is clear: a LAB is exempt from one consolidation circular, not from cyber security. A board-approved security policy, an incident-response capability wired to both CERT-In and the RBI, annual VAPT with evidenced remediation, periodic IS audit, and disciplined vendor oversight are all still expected of it.
The gap between the letter and supervision
There is a distinction worth naming plainly. The letter of the 2023 Master Direction excludes LABs. Supervisory expectation is a broader thing. When the RBI inspects a small bank, it does not ignore cyber resilience because a particular consolidation circular carved the entity out; it assesses whether the bank has controls commensurate with its size, nature and risk profile. A LAB that treats the exemption as a licence to do nothing on cyber security is exposed, not necessarily to a specific circular breach, but to adverse supervisory findings, directions to remediate, and reputational risk if an incident occurs and the bank cannot show it took reasonable steps.
The proportionality principle cuts both ways. It means a two-branch bank is not expected to stand up the same committee architecture as a large private bank. It also means the bank cannot point to its size as a reason for having no cyber-security policy, no tested incident response, and no independent assurance over its outsourced core banking platform.
Where the real risk sits for a small bank
The compliance conversation for a LAB is less about volume of controls and more about a handful of concentrated exposures:
- Outsourcing concentration. A small bank almost always runs on a third-party core banking system and outsourced IT operations. The bank’s security posture is, in large part, its vendor’s security posture, but the regulatory accountability stays with the bank. Without contractual audit rights and genuine oversight, that is an unmanaged risk.
- Incident-reporting timelines. The six-hour CERT-In clock is unforgiving, and it cannot be met by a process invented during an incident. A small bank with no rehearsed playbook will miss it.
- Assurance thin on the ground. With lean teams, IS audit and VAPT are the controls most likely to be skipped or done superficially, and they are exactly what an inspector asks to see.
- Digital channels outrunning controls. As even small banks add internet banking, mobile apps and UPI, the internet-facing attack surface grows faster than a small IT team can secure it.
- The DPDP layer. Data-protection compliance is a separate track from RBI compliance, on its own timeline, and it is easy for a small bank to overlook while focused on banking-sector rules.
A proportionate compliance baseline
A Local Area Bank does not need an enterprise security programme. It needs a defensible, right-sized one. In practice, that means being able to evidence the following:
| Area | What “done” looks like for a LAB |
|---|---|
| Governance & policy | A board-approved cyber-security policy and cyber-crisis management plan, reviewed at least annually, with a named owner for information security even if the role is combined with another. |
| Risk assessment | A periodic IT and information-security risk assessment covering the core banking platform, digital channels and key vendors. |
| VAPT | Annual vulnerability assessment and penetration testing of internet-facing systems, plus testing after significant change, with findings remediated and re-tested, conducted by a CERT-In empanelled auditor. |
| Incident response | A documented, rehearsed response playbook that meets the six-hour CERT-In deadline and the RBI reporting expectation in parallel, with logs retained for 180 days. |
| IS audit | Independent information-systems audit at a proportionate frequency, findings tracked to closure and available to RBI inspection. |
| Vendor oversight | Due diligence on the core banking and IT service providers, contractual security and audit rights, and evidence that oversight actually happens. |
| Data protection | A DPDP readiness track running in parallel, data mapping, consent and notice, security safeguards and breach response, against the May 2027 horizon. |
The bottom line
Local Area Banks are exempt from the RBI’s 2023 IT Governance Master Direction, and from very little else. As licensed banks they remain within the reach of the cyber-security framework, CERT-In’s six-hour reporting rule, VAPT and IS-audit expectations, outsourcing accountability, digital-payment controls and the DPDP Act. The right posture is not to claim exemption but to build a proportionate, evidenced programme that a supervisor would recognise as reasonable for a bank of that size. Small does not mean out of scope; it means the controls should be sized to the institution, not absent from it.
SICHERTEN works with regulated financial entities across the RBI spectrum, our RBI security audits and VAPT for compliance engagements are built to produce exactly the evidence an inspection expects, sized to the entity. For the data-protection track, our DPDPA readiness assessment maps the parallel obligation. And if you are weighing where a small bank’s reporting duties overlap, CERT-In’s six-hour rule is the tighter clock to plan around.
Regulatory note: the applicability and exemption positions above reflect the RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (2023, effective 1 April 2024), the RBI Cyber Security Framework (2016 and subsequent circulars), CERT-In Directions (2022) and the DPDP Act, 2023 and Rules, 2025. Regulatory positions evolve and supervisory expectations are entity-specific; confirm the current position against the applicable RBI circulars and your supervisory correspondence before relying on this for a compliance decision.