Guide

India Business Continuity, BCP & Disaster Recovery Guide

A practical India guide connecting ISO 22301 with RBI BCM/DR expectations for covered regulated entities, SEBI BCP/DR frameworks and CERT-In cyber-crisis/security guidance.

India has a broad and rapidly evolving resilience landscape. ISO 22301 can provide a general BCMS baseline, while regulated sectors have more specific expectations. In financial services, the Reserve Bank of India (RBI) and Securities and Exchange Board of India (SEBI) publish detailed technology, BCP and disaster-recovery requirements for entities within their scope. CERT-In provides cyber-crisis and information-security guidance relevant to government and key organisations. The practical rule is to identify the exact regulated entity before turning sector requirements into a checklist.

India BCM and DR reference map

ReferenceWho it matters toContinuity / recovery emphasis
ISO 22301:2019Any organisation adopting an international BCMS baselineGovernance, BIA, strategies, plans, exercises and improvement
RBI IT Governance, Risk, Controls and Assurance Practices Directions, 2023Regulated entities listed in the RBI DirectionsIT governance, BCM/DR, availability, RTO/RPO, resilience testing, third-party arrangements and assurance
RBI sector/payment directionsSpecific RBI-regulated entities where applicableMore detailed DR/RPO/testing expectations can apply; verify the current direction for the entity
SEBI BCP/DR guidelinesCovered Market Infrastructure Institutions and other specifically covered market entitiesBusiness continuity, DR sites, data/transaction integrity, incident/crisis teams and periodic resilience drills
CERT-In Cyber Crisis Management Plan frameworkCentral Government ministries/departments/states and key organisations in Indian cyberspaceCyber-crisis preparedness, response coordination and entity-level CCMP implementation
CERT-In security guidance for government entitiesGovernment security/technology environmentsDocumented backup, critical data/configuration protection, separation and restoration readiness

RBI: connect business continuity to measurable technology recovery

The RBI 2023 IT Governance/Risk/Controls directions consolidate and update instructions that include Business Continuity and Disaster Recovery Management for the regulated entities in scope. A useful implementation connects critical business operations to information systems, defines RTO and RPO, tests recovery, records gaps and ensures third-party arrangements do not break the service chain. Other RBI directions can contain entity-specific details, so practitioners should verify the current rule set rather than applying one number to every bank, NBFC, payment operator or financial institution.

What a regulated-entity recovery record should contain

RecordData to captureWhy it matters
Critical service/systemBusiness outcome, owner, customer/market impactPrevents DR from becoming infrastructure-only
RTO/RPOApproved target, source requirement, peak-period variationGives technology a measurable recovery objective
PDC/DR architectureSites/regions, network, identity, storage, application, data and interfacesShows whether recovery avoids the same failure domain
DR drill evidenceDate, scenario, start/end times, achieved RTO/RPO, transaction/data validationDistinguishes design claims from demonstrated capability
Data reconciliationLast trusted record, in-flight items, duplicate/loss controlsProtects transaction integrity during recovery
Third partiesProvider/service, SLA/recovery commitment, test evidence, escalation and alternateOutsourcing does not remove dependency risk
Corrective actionsGap, owner, target date, retestCreates auditable improvement

SEBI: BCP/DR for market infrastructure

SEBI has issued BCP and DR guidance for Market Infrastructure Institutions (MIIs), including stock exchanges, clearing corporations and depositories, and has updated that framework over time. The guidance focuses heavily on continuity of operations and data/transaction integrity, DR/near-site arrangements, trained staff, incident/crisis-management responsibilities, switchover capability and periodic drills. Similar but separate SEBI requirements exist for other covered entities such as Qualified RTAs. Do not generalise MII-specific architecture or distance requirements to companies outside the scope of those circulars.

CERT-In: cyber crisis and backup readiness

CERT-In describes the Cyber Crisis Management Plan (CCMP) as a framework for dealing with cyber-related incidents and leads implementation across Central Government ministries/departments, states and key organisations. CERT-In guidance for government entities also emphasises documented backup procedures, maintaining current copies of critical data and configuration, physical/off-site separation where appropriate, and regular backups based on criticality. For BCM practitioners, the key lesson is to link cyber response, clean recovery, backup restoration and business continuity rather than maintaining isolated documents.

India financial-sector scenario: primary data-centre disruption

A regulated financial service loses its primary processing environment during a peak transaction period. The continuity record identifies the affected business service, approved RTO/RPO, primary/DR dependencies, last confirmed transaction sequence and decision authority. The team activates the recovery site, but does not declare success when servers are merely available. It validates integrations, transaction completeness, queue replay, security controls and customer-facing functionality. If the achieved recovery time or recovery point diverges from the approved target, the variance is recorded as a control gap with corrective action and retest.

India practitioner checklist

  • Identify whether the entity is under RBI, SEBI, another financial regulator, government/CERT-In context or only voluntary/contractual standards.
  • Maintain a matrix of current circulars/directions by legal entity; India sector requirements can be specific and frequently updated.
  • Tie every critical information system to a business service and approved RTO/RPO.
  • Measure DR drill results, including business/transaction validation, not only infrastructure switchover.
  • Include primary, DR, near-site, network, identity, data, supplier and staff dependencies as applicable.
  • Treat backup restoration and cyber clean recovery as distinct evidence areas.
  • Document vendor/outsourcing resilience and collaborative testing where risk warrants it.
  • Retain corrective actions and proof of closure; a failed target is valuable evidence only if it drives remediation.

Official references and further reading

RBI 2023 directions: BCM/DR controls to translate into evidence

The RBI Information Technology Governance, Risk, Controls and Assurance Practices Directions, 2023 consolidate requirements for covered regulated entities and include a dedicated Business Continuity and Disaster Recovery chapter. The direction requires BCP/DR capabilities to support resilience objectives and securely resume critical operations after cyber attacks or other incidents. For critical information systems, DR drills are required at least half-yearly; testing is expected to include switching to the alternate/DR site for a sufficiently long period to cover at least a full working day of usual business operations. Backup restoration, RTO/RPO, DC/DR configuration/security-patch consistency and interconnected vendor/partner readiness are also addressed.

RBI topicImplementation evidence
Board / IT governanceIT governance and committee records; annual adequacy/effectiveness review of BCP/DR
BCP/DR policyApproved policy updated for major developments/risk assessment
Critical systemsInventory and approved criticality/recovery requirements
DR drillsAt least half-yearly for critical information systems; results, major issues and retest evidence
Full working-day useEvidence that DR/alternate site served normal Beginning-of-Day to End-of-Day operations where required
Backup restorePeriodic restore evidence, usability and integrity/security checks
RTO/RPODefined objectives and demonstrated recovery; minimal RTO / near-zero RPO prioritisation for critical systems as directed
Non-zero RPODocumented data-reconciliation methodology
DC/DR consistencyConfiguration and security-patch comparison evidence
Vendors/partnersCollaborative/coordinated resilience testing for critical interconnected systems

SEBI market-infrastructure continuity

SEBI’s BCP/DR framework for covered Market Infrastructure Institutions is designed around data and transaction integrity. Current SEBI material includes requirements around disaster-recovery sites, near-site arrangements for specified institutions, geographic separation expectations, recovery objectives and testing. Treat these as sector-specific requirements: a non-MII organisation should not copy numeric requirements without confirming the applicable SEBI circular/framework.

India practitioner scenario

A regulated financial service tests a DR switch. Infrastructure starts within the technical target, but the alternate site contains one older security configuration and a downstream payment interface rejects messages. The exercise should not be scored “pass” because servers started. The evidence pack should show configuration parity, interface recovery, RPO/reconciliation, full-day operational processing where applicable, business validation and retest of the failed controls.