AravaliStack and RBI's cloud adoption guidelines for regulated entities.
The Reserve Bank of India's 2023 cloud guidance creates specific obligations for banks and NBFCs. AravaliStack is designed from first principles to satisfy these requirements โ architecturally, not contractually.
RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices โ Cloud Guidance
RBI's guidance on cloud adoption (2023) requires regulated entities to ensure: data residency within India, unrestricted supervisory access, audit rights, concentration risk management, and exit strategy planning. Most critically, the RBI requires that Indian banks can demonstrate control over their data โ not just a contractual promise from a foreign-headquartered cloud provider.
A 2-page checklist your IT Risk team can complete to document RBI cloud guidance compliance for your AravaliStack deployment.
We'll schedule a 45-minute technical briefing with your CISO and IT Risk team โ covering RBI compliance positioning and answering any regulatory questions.
RBI Compliance Checklist
A 2-page checklist your IT Risk team can complete to document RBI cloud guidance compliance for your AravaliStack deployment.
CISO / IT Risk Briefing
We'll schedule a 45-minute technical briefing with your CISO and IT Risk team โ covering RBI compliance positioning and answering any regulatory questions.
- RBI Requirement Status AravaliStack Approach
- Data of Indian customers must remain within India at all times
- On-premise deployment โ all data physically resides on the bank's own hardware in India. No egress to any external provider. Verifiable with a network scan, not just a contract.
- AravaliStack includes an RBI Access Portal โ a dedicated, time-limited access mechanism for regulators. Every access session is logged with immutable timestamps. No vendor mediation required.
- Banks must not have excessive dependency on any single cloud provider
- AravaliStack is infrastructure-agnostic. Deployments span multiple physical sites with no single-vendor dependency. Multi-cloud hybrid configurations are native. The bank controls the infrastructure โ no hyperscaler lock-in.
- Banks must have a viable plan to exit cloud services without service disruption
- Because the bank owns the underlying infrastructure and all data, there is no exit dependency on AravaliStack. Workloads are containerised on standard Kubernetes โ portable to any CNCF-compliant platform. Source code escrow available.
- Complete, tamper-evident audit trail of all data access and system changes
- Every user action, API call, config change, and data access is logged to an immutable, cryptographically signed audit log. Logs are stored in AravaliStack's own WORM-compliant storage layer. Export to SIEM in any format.
