Skip to content
RegulensR
NotificationMedium impact2 weeks ago

RBI tightens IT outsourcing directions on concentration and exit testing

Regulated entities must test exit plans for material IT outsourcing arrangements rather than document them, and assess concentration at group level.

The Reserve Bank has amended its directions on outsourcing of information technology services, with two changes that require work rather than documentation.

Exit plans must be tested

The amendment states explicitly that an exit plan which has not been exercised does not evidence exitability. Regulated entities must test at least the data extraction and portability elements of exit for material arrangements, at defined intervals.

This ends the useful life of the exit plan document produced for a previous supervisory cycle describing a migration nobody has attempted.

The proportionate response is to scope a real test — data extraction and restore into an alternative environment for one material workload — and use the findings to make the plan realistic. A tested plan revealing an eighteen-month exit timeline is more supervisable than an untested one claiming six months.

Concentration is assessed at group level

Where multiple entities within a group depend on the same service provider, concentration must be assessed for the group rather than entity by entity. Several groups have discovered on running this analysis that a provider which looked immaterial at each entity is material in aggregate.

Read-across beyond BFSI

Two reasons this matters outside financial services.

If you are an IT services provider or GCC serving RBI-regulated clients, these obligations reach you contractually. Your clients will require testable exit support, group-level dependency disclosure and audit rights, and those requirements will appear in contract renewals from January.

More broadly, the direction of travel is consistent across Indian regulators. SEBI's CSCRF, IRDAI's guidelines and the CERT-In directions have all moved from documented capability toward demonstrated capability. Organisations in any sector with an exit plan nobody has tested should read this as a preview.

How Regulens customers received this

This item was scoped against every customer footprint within 15 minutes of publication. Customers to whom it applies received it routed to the named owner for the relevant theme, with the obligations decomposed, the affected entities identified and any prior assessment carried forward with the delta highlighted. Customers to whom it does not apply saw nothing — with the suppression reason recorded and auditable.

This analysis is provided for information only and does not constitute legal advice. Read it alongside the primary source it cites. Where a source reference is given (RBI/2026-27/48 DoS.CO.CSITEG), that is the authoritative text.

Get this filtered to your own footprint

Of the items we published this month, a typical customer sees fewer than twenty — scoped to their entities and licences, with the suppression reasoning available for every item they did not see.