Skip to content
Glossary

RBI Cloud Adoption Guidelines

The Reserve Bank of India's framework governing how regulated financial entities may adopt cloud computing — including data localisation, security, exit management, and vendor risk requirements.

The Reserve Bank of India (RBI) has issued a series of guidelines and master directions that collectively govern cloud adoption by regulated entities — including commercial banks, NBFCs, payment system operators, and urban cooperative banks. These guidelines reflect the RBI's consistent position that technology adoption must not compromise data sovereignty, operational resilience, or supervisory access.

Core requirements

Data localisation. Regulated entities must store all data relating to payment systems exclusively in India. For banks, core banking data, customer personal information, and transaction records must reside in India. Storing this data on servers outside India — even temporarily, for processing — requires prior approval and is subject to strict conditions.

Supervisory access. The RBI must be able to access data held by regulated entities or their service providers. This is a significant constraint on cloud adoption: if data is processed on a foreign cloud infrastructure, ensuring unimpeded supervisory access requires complex contractual arrangements that may not be honoured in all jurisdictions.

Vendor risk management. Regulated entities must assess and manage concentration risk with cloud providers. Over-dependence on a single cloud provider — particularly a foreign one — is identified as a systemic risk. Entities must maintain viable exit strategies and demonstrate the ability to migrate workloads within a defined timeframe.

IT governance. The RBI's IT Framework for NBFCs and similar directions for banks require that all material technology changes — including cloud migration — be approved by the Board or a Board-level committee, with documented risk assessments and business continuity plans.

Implications for cloud architecture

Taken together, RBI's guidelines effectively require that critical banking workloads either run on-premise or on private cloud infrastructure within India, with demonstrable data sovereignty and supervisory access. Public cloud can be used for non-critical workloads, but the regulatory overhead of demonstrating compliance — third-party audits, contractual arrangements, supervisory access frameworks — is substantial. For most regulated entities, on-premise infrastructure for critical workloads is the more practical compliance path.

See it in action

Request a demo of AravaliStack and see how these concepts come to life in a production platform.