Issued by the Reserve Bank of India in November 2023 as the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices.
RBI's directions on outsourcing of IT services require regulated entities to maintain robust exit strategies and business-continuity arrangements so critical operations survive a service provider's exit or failure. For a CIO, CISO or compliance officer, the practical issue is whether a critical third-party application can remain available when the provider fails, exits, is acquired or can no longer support the product.
Software escrow addresses custody: who holds the source code, build materials and documentation. Software Recoverability addresses the next question: whether those materials have been independently rebuilt, deployed and tested. The distinction matters because an agreement and a deposit do not prove that recovery can be completed within the institution’s operational tolerance.
Castler therefore treats the requirement as part of vendor onboarding. The agreement and first deposit are established when the relationship begins, every release is captured, and the verification evidence is renewed before an auditor, insurer or supervisor asks for it.