An overview of how RBI frameworks treat VAPT for banks, NBFCs, payment aggregators and fintech partners, and how to plan testing that satisfies them.
Why RBI cares about VAPT
The Reserve Bank of India has steadily raised cyber security expectations for the entities it regulates. Its cyber security framework for banks, the Master Direction on IT governance, risk, controls and assurance practices, and sector-specific guidance for NBFCs, urban co-operative banks and payment system operators all expect regulated entities to identify and fix vulnerabilities through periodic testing.
This article is a practical overview, not legal advice. Always refer to the latest RBI circulars that apply to your entity.
Which entities are affected
Scheduled commercial banks, small finance and payments banks, urban and rural co-operative banks, NBFCs across the scale-based layers, payment aggregators and gateways, and prepaid payment instrument issuers all have expectations around security testing. Fintech companies that partner with banks are usually brought into scope through the bank's own vendor and outsourcing requirements, which typically ask for a recent VAPT report.
What typically needs testing
Internet and mobile banking, customer-facing apps and portals, payment and UPI integrations, APIs exposed to partners, core banking and loan management systems, and the network and cloud infrastructure that hosts them. Testing is expected both periodically and after significant changes, such as a new product launch or major upgrade.
Planning your testing year
Map every critical system to its testing frequency. Schedule external-facing systems more often than internal ones. Leave time for remediation and retesting before board or inspection deadlines. Keep evidence: scope documents, reports, remediation tickets and retest results. Choosing a CERT-In empanelled auditor such as Scantra Security gives inspectors and bank partners additional confidence.
