[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

RBI PSO Directions §17(c)

Payments & Fintech runs on vendor software. Prove the critical stack can recover

Identify the vendor-built systems inside regulated services, keep every release current, and produce independent recovery evidence before an incident.

PAYMENTS & FINTECH SYSTEMS

The vendor-built systems inside the critical path

Payment switch

CRITICAL

Ledger and settlement

CRITICAL

KYC and fraud controls

HIGH

Reconciliation engine

HIGH

WHAT THE REGULATOR ASKS

RBI PSO Directions §17(c)

In summary

Non-bank Payment System Operators must obtain source code or establish software escrow for critical software, with the arrangement available for regulatory examination.

Read the regulation evidence map

THE EVIDENCE PACK

The artefacts that make the obligation examinable

Build Report

Deployment Runbook

Replication Report

SBOM

Signed Proof of Recovery

Institutional proof

Approved institutions across Castler’s trust infrastructure

A growing network of banks, payment institutions and financial-services leaders relies on Castler’s trust infrastructure for controlled, accountable money movement.

Named institutions across banking, payments and lending
Castler trust networkApproved institutions
HDFC Bank
SBI
Canara Bank
HDFC Bank
SBI
Canara Bank
HDFC Bank
SBI
Canara Bank
Union Bank
Indian Bank
India Post Payments
Union Bank
Indian Bank
India Post Payments
Union Bank
Indian Bank
India Post Payments
NSDL Payments
Pine Labs
Mahindra Finance
NSDL Payments
Pine Labs
Mahindra Finance
NSDL Payments
Pine Labs
Mahindra Finance
BanksPayment institutionsNBFCsFintech

REGULATORY OBLIGATIONS

Regulatory obligations for payments and fintech

Non-bank payment system operators are subject to RBI PSO Directions 2024 §17(c). Large PSOs had an April 2025 deadline; Medium PSOs April 2026.

PAYMENTS & FINTECH

Make the Payments & Fintech Software Estate recoverable.

Bring the critical system stack and applicable rulebook. We’ll map custody, verification and signed evidence.

Book a 15-min briefing
ISO 27001SOC 2 Type IIPCI DSS

No spam · Reply within one business day