[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

RBI IT Directions §12(f)

Banking & NBFCs runs on vendor software. Prove the critical stack can recover

Identify the vendor-built systems inside regulated services, keep every release current, and produce independent recovery evidence before an incident.

BANKING & NBFCS SYSTEMS

The vendor-built systems inside the critical path

Core banking platform

CRITICAL

Payment switch

CRITICAL

Lending origination

HIGH

Risk and fraud engine

HIGH

WHAT THE REGULATOR ASKS

RBI IT Directions §12(f)

In summary

Regulated entities must obtain source code for critical vendor applications or establish software escrow arrangements that include all updates and programme fixes.

Read the regulation evidence map

THE EVIDENCE PACK

The artefacts that make the obligation examinable

Build Report

Deployment Runbook

Replication Report

SBOM

Signed Proof of Recovery

Institutional proof

Approved institutions across Castler’s trust infrastructure

A growing network of banks, payment institutions and financial-services leaders relies on Castler’s trust infrastructure for controlled, accountable money movement.

Named institutions across banking, payments and lending
Castler trust networkApproved institutions
HDFC Bank
SBI
Canara Bank
HDFC Bank
SBI
Canara Bank
HDFC Bank
SBI
Canara Bank
Union Bank
Indian Bank
India Post Payments
Union Bank
Indian Bank
India Post Payments
Union Bank
Indian Bank
India Post Payments
NSDL Payments
Pine Labs
Mahindra Finance
NSDL Payments
Pine Labs
Mahindra Finance
NSDL Payments
Pine Labs
Mahindra Finance
BanksPayment institutionsNBFCsFintech

REGULATORY OBLIGATIONS

Regulatory obligations for banks and NBFCs

Banks, NBFCs and payment institutions operating in India are subject to software escrow and recoverability mandates under RBI IT Directions 2023 §12(f) and RBI PSO Directions 2024 §17(c). SEBI CSCRF applies to capital-markets-facing entities.

BANKING & NBFCS

Make the Banking & NBFCs Software Estate recoverable.

Bring the critical system stack and applicable rulebook. We’ll map custody, verification and signed evidence.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day