On-Premise vs Cloud for Indian Banks
This is the most consequential infrastructure decision an Indian bank's CTO makes. The wrong choice costs crores in compliance remediation, regulatory scrutiny, or cloud bills. Here is the complete picture — regulatory, financial, and technical.
What the RBI actually says
Understanding the regulations is not optional. It is the starting point.
RBI's April 2018 circular directed all payment system operators to store entire payment data — end-to-end transaction details, including payment instructions — only in India, within six months. This applies to all entities in the payment ecosystem, including processors, aggregators, and banks.
Material technology changes — including cloud migration of core banking systems — require Board or Board Committee approval, documented risk assessments, and demonstration of business continuity capability. Cloud providers must be subject to due diligence and regular audit rights.
SEBI's circular on cloud adoption requires that critical data — trading records, investor accounts, audit trails — be stored and processed within India. Overseas processing requires prior approval. Concentration risk with a single cloud provider must be managed and disclosed.
The DPDP Act empowers the Central Government to restrict cross-border transfer of personal data. For banks processing millions of customers' personal financial data, the Data Fiduciary obligations are significantly simpler to discharge on infrastructure you directly control.
Cloud is appropriate for non-core, non-regulated workloads — and Indian banks are using it effectively in these contexts:
These workloads do not involve core banking data, payment records, or personally identifiable financial information. They are appropriate candidates for cloud hosting under current RBI frameworks.
These workloads involve regulated data categories for which cloud storage either violates RBI circulars or creates unacceptable regulatory risk. They belong on-premise, on infrastructure you control.
The answer for most Indian banks is not "cloud or on-premise" — it is a governed hybrid. Core regulated workloads on-premise with AravaliStack, non-regulated workloads on cloud, unified management and security across both.
These workloads involve regulated data categories for which cloud storage either violates RBI circulars or creates unacceptable regulatory risk. They belong on-premise, on infrastructure you control.
- Marketing analytics and campaign platforms
- Customer-facing web and mobile applications (CDN)
- Disaster recovery for non-critical systems
- Development and testing environments
- Public-facing APIs where global CDN matters
DPDP Act 2023
- Marketing analytics and campaign platforms
- Customer-facing web and mobile applications (CDN)
- Disaster recovery for non-critical systems
- Development and testing environments
- Public-facing APIs where global CDN matters
- Core banking system (CBS) data
- Payment transaction records and logs
- Customer KYC, CKYC data
- Fraud detection models trained on customer data
- AML / transaction monitoring systems
- Credit scoring models and training data
- Audit logs and supervisory data
- Interest rate and treasury systems
| Dimension | Public Cloud (AWS/Azure/GCP) | On-Premise (AravaliStack) |
|---|---|---|
| RBI payment data requirement | Contractual data residency only | Physical data residency — your hardware |
| US CLOUD Act exposure | Yes — US-HQ cloud providers subject to it | None — no US software dependency |
| DPDP Act Data Fiduciary | Complex — cloud provider is sub-processor | Simple — you are sole Data Fiduciary |
| RBI supervisory access | Requires cloud provider cooperation | Direct — regulator can audit your systems |
| CERT-In 6-hour reporting | Depends on cloud provider incident logs | Full control over incident investigation |
| Core banking data | Stored on foreign-controlled infrastructure | On your hardware — full sovereignty |
| Customer PII | Subject to foreign data laws | Stays in India, on your systems |
| Fraud detection ML models | Data must leave premises for cloud ML | Train and serve on-prem — no data egress |
| Cost model | Variable OpEx — unpredictable at scale | Fixed CapEx + predictable platform licence |
| Egress fees | ₹0.08/GB — significant at banking volumes | ₹0 — internal network traffic |
| Vendor negotiation leverage | Low after lock-in | High — open source, no dependency |
| Air-gapped capability | Impossible by definition | Fully supported |
| Latency (branch-to-DC) | Network round-trip to cloud region | Direct — within your WAN |
| Business continuity | Cloud provider availability-dependent | You control DR strategy entirely |
| Scale | Elastic — instant provisioning | Planned — requires capacity management |
| Developer productivity | High — rich managed services | High — AravaliStack provides same managed services |
| Security posture | Shared responsibility model | Full ownership — zero trust by default |
| Regulatory audit | Cloud compliance reports (SOC2, ISO) | Direct audit access to all systems |
- Board-level IT governance required for cloud adoption
- The Complete Comparison
- When cloud makes sense for banks
- The Recommended Architecture: Hybrid
- Unified Control Plane
- AravaliStack manages both environments — consistent security, observability, and cost attribution
