Skip to content
Comparison · Indian Banking

On-Premise vs Cloud for Indian Banks

This is the most consequential infrastructure decision an Indian bank's CTO makes. The wrong choice costs crores in compliance remediation, regulatory scrutiny, or cloud bills. Here is the complete picture — regulatory, financial, and technical.

The Regulatory Framework

What the RBI actually says

Understanding the regulations is not optional. It is the starting point.

RBI's April 2018 circular directed all payment system operators to store entire payment data — end-to-end transaction details, including payment instructions — only in India, within six months. This applies to all entities in the payment ecosystem, including processors, aggregators, and banks.

Material technology changes — including cloud migration of core banking systems — require Board or Board Committee approval, documented risk assessments, and demonstration of business continuity capability. Cloud providers must be subject to due diligence and regular audit rights.

SEBI's circular on cloud adoption requires that critical data — trading records, investor accounts, audit trails — be stored and processed within India. Overseas processing requires prior approval. Concentration risk with a single cloud provider must be managed and disclosed.

The DPDP Act empowers the Central Government to restrict cross-border transfer of personal data. For banks processing millions of customers' personal financial data, the Data Fiduciary obligations are significantly simpler to discharge on infrastructure you directly control.

Cloud is appropriate for non-core, non-regulated workloads — and Indian banks are using it effectively in these contexts:

These workloads do not involve core banking data, payment records, or personally identifiable financial information. They are appropriate candidates for cloud hosting under current RBI frameworks.

These workloads involve regulated data categories for which cloud storage either violates RBI circulars or creates unacceptable regulatory risk. They belong on-premise, on infrastructure you control.

The answer for most Indian banks is not "cloud or on-premise" — it is a governed hybrid. Core regulated workloads on-premise with AravaliStack, non-regulated workloads on cloud, unified management and security across both.

These workloads involve regulated data categories for which cloud storage either violates RBI circulars or creates unacceptable regulatory risk. They belong on-premise, on infrastructure you control.

  • Marketing analytics and campaign platforms
  • Customer-facing web and mobile applications (CDN)
  • Disaster recovery for non-critical systems
  • Development and testing environments
  • Public-facing APIs where global CDN matters

DPDP Act 2023

  • Marketing analytics and campaign platforms
  • Customer-facing web and mobile applications (CDN)
  • Disaster recovery for non-critical systems
  • Development and testing environments
  • Public-facing APIs where global CDN matters
  • Core banking system (CBS) data
  • Payment transaction records and logs
  • Customer KYC, CKYC data
  • Fraud detection models trained on customer data
  • AML / transaction monitoring systems
  • Credit scoring models and training data
  • Audit logs and supervisory data
  • Interest rate and treasury systems
DimensionPublic Cloud (AWS/Azure/GCP)On-Premise (AravaliStack)
RBI payment data requirementContractual data residency onlyPhysical data residency — your hardware
US CLOUD Act exposureYes — US-HQ cloud providers subject to itNone — no US software dependency
DPDP Act Data FiduciaryComplex — cloud provider is sub-processorSimple — you are sole Data Fiduciary
RBI supervisory accessRequires cloud provider cooperationDirect — regulator can audit your systems
CERT-In 6-hour reportingDepends on cloud provider incident logsFull control over incident investigation
Core banking dataStored on foreign-controlled infrastructureOn your hardware — full sovereignty
Customer PIISubject to foreign data lawsStays in India, on your systems
Fraud detection ML modelsData must leave premises for cloud MLTrain and serve on-prem — no data egress
Cost modelVariable OpEx — unpredictable at scaleFixed CapEx + predictable platform licence
Egress fees₹0.08/GB — significant at banking volumes₹0 — internal network traffic
Vendor negotiation leverageLow after lock-inHigh — open source, no dependency
Air-gapped capabilityImpossible by definitionFully supported
Latency (branch-to-DC)Network round-trip to cloud regionDirect — within your WAN
Business continuityCloud provider availability-dependentYou control DR strategy entirely
ScaleElastic — instant provisioningPlanned — requires capacity management
Developer productivityHigh — rich managed servicesHigh — AravaliStack provides same managed services
Security postureShared responsibility modelFull ownership — zero trust by default
Regulatory auditCloud compliance reports (SOC2, ISO)Direct audit access to all systems
  • Board-level IT governance required for cloud adoption
  • The Complete Comparison
  • When cloud makes sense for banks
  • The Recommended Architecture: Hybrid
  • Unified Control Plane
  • AravaliStack manages both environments — consistent security, observability, and cost attribution