India has a broad and rapidly evolving resilience landscape. ISO 22301 can provide a general BCMS baseline, while regulated sectors have more specific expectations. In financial services, the Reserve Bank of India (RBI) and Securities and Exchange Board of India (SEBI) publish detailed technology, BCP and disaster-recovery requirements for entities within their scope. CERT-In provides cyber-crisis and information-security guidance relevant to government and key organisations. The practical rule is to identify the exact regulated entity before turning sector requirements into a checklist.
India BCM and DR reference map
| Reference | Who it matters to | Continuity / recovery emphasis |
|---|---|---|
| ISO 22301:2019 | Any organisation adopting an international BCMS baseline | Governance, BIA, strategies, plans, exercises and improvement |
| RBI IT Governance, Risk, Controls and Assurance Practices Directions, 2023 | Regulated entities listed in the RBI Directions | IT governance, BCM/DR, availability, RTO/RPO, resilience testing, third-party arrangements and assurance |
| RBI sector/payment directions | Specific RBI-regulated entities where applicable | More detailed DR/RPO/testing expectations can apply; verify the current direction for the entity |
| SEBI BCP/DR guidelines | Covered Market Infrastructure Institutions and other specifically covered market entities | Business continuity, DR sites, data/transaction integrity, incident/crisis teams and periodic resilience drills |
| CERT-In Cyber Crisis Management Plan framework | Central Government ministries/departments/states and key organisations in Indian cyberspace | Cyber-crisis preparedness, response coordination and entity-level CCMP implementation |
| CERT-In security guidance for government entities | Government security/technology environments | Documented backup, critical data/configuration protection, separation and restoration readiness |
RBI: connect business continuity to measurable technology recovery
The RBI 2023 IT Governance/Risk/Controls directions consolidate and update instructions that include Business Continuity and Disaster Recovery Management for the regulated entities in scope. A useful implementation connects critical business operations to information systems, defines RTO and RPO, tests recovery, records gaps and ensures third-party arrangements do not break the service chain. Other RBI directions can contain entity-specific details, so practitioners should verify the current rule set rather than applying one number to every bank, NBFC, payment operator or financial institution.
What a regulated-entity recovery record should contain
| Record | Data to capture | Why it matters |
|---|---|---|
| Critical service/system | Business outcome, owner, customer/market impact | Prevents DR from becoming infrastructure-only |
| RTO/RPO | Approved target, source requirement, peak-period variation | Gives technology a measurable recovery objective |
| PDC/DR architecture | Sites/regions, network, identity, storage, application, data and interfaces | Shows whether recovery avoids the same failure domain |
| DR drill evidence | Date, scenario, start/end times, achieved RTO/RPO, transaction/data validation | Distinguishes design claims from demonstrated capability |
| Data reconciliation | Last trusted record, in-flight items, duplicate/loss controls | Protects transaction integrity during recovery |
| Third parties | Provider/service, SLA/recovery commitment, test evidence, escalation and alternate | Outsourcing does not remove dependency risk |
| Corrective actions | Gap, owner, target date, retest | Creates auditable improvement |
SEBI: BCP/DR for market infrastructure
SEBI has issued BCP and DR guidance for Market Infrastructure Institutions (MIIs), including stock exchanges, clearing corporations and depositories, and has updated that framework over time. The guidance focuses heavily on continuity of operations and data/transaction integrity, DR/near-site arrangements, trained staff, incident/crisis-management responsibilities, switchover capability and periodic drills. Similar but separate SEBI requirements exist for other covered entities such as Qualified RTAs. Do not generalise MII-specific architecture or distance requirements to companies outside the scope of those circulars.
CERT-In: cyber crisis and backup readiness
CERT-In describes the Cyber Crisis Management Plan (CCMP) as a framework for dealing with cyber-related incidents and leads implementation across Central Government ministries/departments, states and key organisations. CERT-In guidance for government entities also emphasises documented backup procedures, maintaining current copies of critical data and configuration, physical/off-site separation where appropriate, and regular backups based on criticality. For BCM practitioners, the key lesson is to link cyber response, clean recovery, backup restoration and business continuity rather than maintaining isolated documents.
India financial-sector scenario: primary data-centre disruption
A regulated financial service loses its primary processing environment during a peak transaction period. The continuity record identifies the affected business service, approved RTO/RPO, primary/DR dependencies, last confirmed transaction sequence and decision authority. The team activates the recovery site, but does not declare success when servers are merely available. It validates integrations, transaction completeness, queue replay, security controls and customer-facing functionality. If the achieved recovery time or recovery point diverges from the approved target, the variance is recorded as a control gap with corrective action and retest.
India practitioner checklist
- Identify whether the entity is under RBI, SEBI, another financial regulator, government/CERT-In context or only voluntary/contractual standards.
- Maintain a matrix of current circulars/directions by legal entity; India sector requirements can be specific and frequently updated.
- Tie every critical information system to a business service and approved RTO/RPO.
- Measure DR drill results, including business/transaction validation, not only infrastructure switchover.
- Include primary, DR, near-site, network, identity, data, supplier and staff dependencies as applicable.
- Treat backup restoration and cyber clean recovery as distinct evidence areas.
- Document vendor/outsourcing resilience and collaborative testing where risk warrants it.
- Retain corrective actions and proof of closure; a failed target is valuable evidence only if it drives remediation.
Official references and further reading
- RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023 — RBI directions covering IT governance, controls and BCM/DR for specified regulated entities.
- SEBI BCP/DR Guidelines for MIIs, 2021 — BCP/DR framework for covered market infrastructure institutions.
- SEBI modifications, 2024 — Later modifications to the MII BCP/DR framework.
- CERT-In Cyber Crisis Management Plan — Government/key-organisation cyber-crisis framework context.
- CERT-In security guidance for government entities — Includes data-backup and information-security practices.
- ISO 22301:2019 — International BCMS baseline.
RBI 2023 directions: BCM/DR controls to translate into evidence
The RBI Information Technology Governance, Risk, Controls and Assurance Practices Directions, 2023 consolidate requirements for covered regulated entities and include a dedicated Business Continuity and Disaster Recovery chapter. The direction requires BCP/DR capabilities to support resilience objectives and securely resume critical operations after cyber attacks or other incidents. For critical information systems, DR drills are required at least half-yearly; testing is expected to include switching to the alternate/DR site for a sufficiently long period to cover at least a full working day of usual business operations. Backup restoration, RTO/RPO, DC/DR configuration/security-patch consistency and interconnected vendor/partner readiness are also addressed.
| RBI topic | Implementation evidence |
|---|---|
| Board / IT governance | IT governance and committee records; annual adequacy/effectiveness review of BCP/DR |
| BCP/DR policy | Approved policy updated for major developments/risk assessment |
| Critical systems | Inventory and approved criticality/recovery requirements |
| DR drills | At least half-yearly for critical information systems; results, major issues and retest evidence |
| Full working-day use | Evidence that DR/alternate site served normal Beginning-of-Day to End-of-Day operations where required |
| Backup restore | Periodic restore evidence, usability and integrity/security checks |
| RTO/RPO | Defined objectives and demonstrated recovery; minimal RTO / near-zero RPO prioritisation for critical systems as directed |
| Non-zero RPO | Documented data-reconciliation methodology |
| DC/DR consistency | Configuration and security-patch comparison evidence |
| Vendors/partners | Collaborative/coordinated resilience testing for critical interconnected systems |
SEBI market-infrastructure continuity
SEBI’s BCP/DR framework for covered Market Infrastructure Institutions is designed around data and transaction integrity. Current SEBI material includes requirements around disaster-recovery sites, near-site arrangements for specified institutions, geographic separation expectations, recovery objectives and testing. Treat these as sector-specific requirements: a non-MII organisation should not copy numeric requirements without confirming the applicable SEBI circular/framework.
India practitioner scenario
A regulated financial service tests a DR switch. Infrastructure starts within the technical target, but the alternate site contains one older security configuration and a downstream payment interface rejects messages. The exercise should not be scored “pass” because servers started. The evidence pack should show configuration parity, interface recovery, RPO/reconciliation, full-day operational processing where applicable, business validation and retest of the failed controls.