
Credit information companies, credit institutions and specified users are answerable to the RBI for how they collect, secure and share credit data. Our CERT-In empanelled, CISA-certified auditors assess your compliance with the Credit Information Companies (Regulation) Act, 2005 and its rules, and give you an evidenced path to closing the gaps.
The Credit Information Companies (Regulation) Act, 2005, CICRA, also written CIRCA, governs how credit information is collected, processed, secured and shared in India. Together with the Credit Information Companies Regulations, 2006 and the Credit Information Companies Rules, 2006 (collectively, the “CIC Laws”), it sets the rules for an entire ecosystem built on sensitive borrower data.
A CICRA audit is an independent examination of whether an organisation actually follows those rules, covering data accuracy, security safeguards, privacy, access controls, fidelity and secrecy obligations, and the proper use of credit information. The Reserve Bank of India is the supervisory authority and can inspect these entities, order a special audit, and act on the findings.
Because the audit is a technical security and controls assessment, it must be carried out by a CERT-In empanelled auditor with CISA-certified personnel, which is exactly where SICHERTEN fits. A clean CICRA audit demonstrates to the RBI, your members and your customers that credit data is handled lawfully and safely.
The CIC Laws reach every organisation that touches credit data, not just the bureaus.
The technical and organisational controls protecting credit information, encryption, access management, network security, logging and monitoring, against unauthorised access, use or disclosure.
Whether credit information is collected, maintained and furnished accurately, and whether correction and dispute-handling processes work as the CIC Laws require.
Adherence to the privacy rules governing collection, purpose limitation, sharing and the maximum fees a CIC may charge, and alignment with the DPDP Act where personal data is involved.
Who can access credit information, how membership and specified-user status is governed, and whether access is restricted to permissible purposes.
The fidelity and secrecy obligations placed on CICs, credit institutions and specified users, and the safeguards and security steps mandated by the CIC Rules.
Whether the organisation has furnished correct information to the RBI, a matter the auditor must verify and, where it has not, report to the regulator.
We lay down the audit scope so every area relevant to the CIC Laws is covered, systems, data flows, controls and the entities you interact with.
We build a plan setting out the aim, criteria and the nature, timing and extent of the tests of controls, network security measures and other procedures.
We finalise the schedule with your team to minimise disruption while ensuring thorough coverage of documentation and controls.
We examine your data-handling practices, security measures and controls in depth, testing them against the requirements of the CIC Laws.
We record findings and improvements, log minor and significant non-conformities, and deliver a summary report with the standard CICRA checklist used during the audit.
Tell us about your role in the credit-information ecosystem, and our CERT-In empanelled team will scope the engagement with you.