RBI outsourcing guidelines
Also: RBI IT outsourcing directions, outsourcing of financial services
What is RBI outsourcing guidelines?
RBI outsourcing guidelines set the conditions under which regulated Indian financial institutions can use third parties, including technology vendors, covering due diligence, data protection, audit access, localisation and the institution's continued accountability.
What RBI outsourcing guidelines means
The Reserve Bank of India issues directions on how banks, NBFCs and other regulated entities manage outsourcing, including IT and IT-enabled services. The core principle is that a regulated entity can outsource activities but not accountability. It must assess the vendor, define the service in a contract, retain audit and inspection rights for itself and the regulator, protect customer data, plan for exit, and keep certain data within India.
For AI and software work this shapes the engagement: where models run and data resides, whether customer data can leave the entity's perimeter, what logs and audit trails must exist, how sub-contracting is controlled, and what happens to code, prompts and models on termination. It is why private, in-VPC deployments and full IP transfer matter to BFSI clients.
The guidelines are not a certification a vendor holds. They are obligations on the regulated entity, which flow down into vendor contracts. A vendor's job is to make compliance straightforward, not to claim it.
Who it really matters to
- Compliance officer: outsourcing arrangements must be inventoried, risk-assessed and auditable, with material ones reported per RBI expectations.
- CISO: data localisation, access control and the right to inspect the vendor's environment are contractual and technical requirements.
- CTO / Head of Engineering: architecture choices such as self-hosted models and zero data egress are often dictated by these directions rather than by preference.
- CFO: exit and business-continuity clauses limit lock-in and protect the institution if a vendor fails.
Why it exists
Financial institutions increasingly run on third-party technology, and a failure or breach at a vendor is a failure at the bank as far as customers and the regulator are concerned. The guidelines exist to keep responsibility with the regulated entity and to ensure it can see, audit and exit any outsourced arrangement. The trade-off is friction: vendors must accept audit rights, localisation and stricter contracts, and some cloud-first architectures are off the table. For AI specifically, it pushes towards private deployments, explicit data flows and complete audit trails, which is more work but the only arrangement that survives an inspection.
Where it is applied
- Deploying a KYC document agent inside an NBFC's own cloud account so customer documents never leave its perimeter.
- Contracting an AI voice-collections platform with audit access, sub-contractor disclosure and exit clauses aligned to RBI directions.
- Self-hosting an open-weight LLM for a bank's internal knowledge assistant to keep customer data in India.
- Building the audit trail for a lending copilot so the bank can show which model, prompt and data produced each recommendation.
- Structuring a fintech's outsourcing register and vendor assessments before a regulatory inspection.
Is RBI outsourcing guidelines a skill?
Standard / regulationA regulatory framework that regulated entities must comply with and vendors must accommodate. Eazyware's Private Agentic AI work is built for it: in-perimeter deployment, audit trails, and full transfer of code, prompts and models.
Eazyware service that covers it: Agentic AI Solutions (self-hosted). Starting prices are on the pricing page.
Frequently asked questions
Can a bank use a public LLM API under these guidelines?
It depends on what data is sent and the contractual controls in place. Many institutions choose private or in-region deployments for anything touching customer data, and reserve public APIs for non-sensitive tasks with data-handling terms reviewed by compliance.
What should a vendor contract include?
Clear service scope, data location and handling, audit and inspection rights for the entity and the RBI, sub-contracting controls, security obligations, business-continuity commitments and exit terms including return of data, code and models.