Every car usually has a spare tire in the boot but almost nobody has ever fitted one. It sits there for years. Right size, right car, technically ready. But then one night on the highway you find out the air has gone, the jack is somewhere else, or the person meant to change it has never done it before.
Continuity plans are the same way – the backup site exists, the policy is signed. Even the recovery steps are written down in order. The one thing that has never happened is the thing that counts, which is running the actual business on the spare while customers are watching.
The Reserve Bank of India (RBI) has now closed that gap for NBFCs. Recovery is no longer something a lender writes down. It is something they have to show: on the alternate site, through a normal working day, with the results going to the board.
This blog covers what business continuity and disaster recovery planning for NBFCs now involves, how the obligations change by layer, and the few clauses that do most of the work.
What continuity planning and recovery planning each cover
The two terms get used together so often that the difference gets lost. They answer different questions.
- Business Continuity Plan (BCP): how the business keeps serving customers during a disruption, covering people, processes, premises and systems
- Disaster Recovery (DR): how the technology comes back, from which site, how quickly and with how much data intact
DR is a part of BCP. An NBFC can restore its Loan Management System in two hours and still fail its customers if collections staff have nowhere to sit and no approved process to follow.
How the rules change by NBFC layer
RBI issued the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 on Jul 31, 2026. Obligations are graded by Scale Based Regulation layer, so two NBFCs can both be compliant while doing very different things.
- Base Layer below ₹500 crore, and Core Investment Companies: a board-approved BCP policy, board reporting at least once a year and data backup with periodic testing
- Base Layer at ₹500 crore and above: a full BCP built on Business Impact Analysis, a recovery strategy, backup sites for critical systems, annual testing under worst-case scenarios and results placed before the Chief Information Officer (CIO) and the board
- Middle Layer and above, excluding Core Investment Companies: the full regime, including half-yearly DR drills, defined recovery targets and vendor resilience testing
6 things a DR drill must actually prove
For Middle Layer NBFCs and above, the drill is where the plan earns its keep. RBI is specific about what a drill has to show.
1. A real switchover
Testing has to involve actually moving to the DR site and using it as the primary site. A read-only check or a replication report is not a switchover.
2. A full working day
The alternate site must carry usual business operations for a sufficiently long period, covering at least a full working day from Beginning of Day to End of Day. A short window outside business hours does not meet this.
3. Gaps closed before the next cycle
Any major issue found during a drill has to be resolved and tested again before the next drill. Logging a gap and carrying it forward is not enough.
4. Backups that restore
Backed-up data must be periodically restored to check that it is usable. Integrity has to be preserved and the backup itself protected from unauthorised access.
5. Matching configuration
System configurations and deployed security patches at the primary data centre and the DR site must be identical. Configuration drift is the most common reason a technically available DR site fails when it is needed.
6. Vendors inside the test
Continuity and recovery capability has to extend to critical interconnected systems and networks, including those of vendors and partners, with coordinated testing that meets the NBFC’s recovery target.
RTO, RPO and the clause most plans skip
Two numbers anchor the whole exercise. Both need business sign-off, not just an IT estimate.
- Recovery Time Objective (RTO): how long a system can stay down before the business is harmed. For critical systems, RBI expects this to be minimal and approved by the IT Strategy Committee
- Recovery Point Objective (RPO): how much data the business can afford to lose. For critical systems, the expectation is near zero
Then comes the clause that rarely makes it into a plan. Where RPO is not zero, the NBFC needs a documented method for reconciling data when operations resume from the alternate site. Some data will be missing. Somebody has to know exactly how it gets rebuilt, who approves the rebuild and how the customer record is corrected.
Recovery targets also have to be defined as measurable metrics for every critical system, alongside metrics for system performance and business resumption. Without those numbers, a drill has no pass mark and the report has nothing to compare against.
Where continuity plans fall short in practice
The gaps are not always technical. They sometimes sit in governance and in the parts of the business that are not IT.
- Paper-only testing: tabletop reviews are useful, but they do not satisfy a requirement written around actual switchover
- Sites too close together: primary and DR sites must be geographically separated enough that one threat cannot affect both
- BCP treated as an IT document: continuity covers people, processes and premises, and the CIO is accountable for keeping it current
- Outsourcing assumed to transfer risk: continuity preparedness cannot be weakened by outsourcing, and NBFCs are expected to seek active assurance that providers stay ready
- No audit loop: the Information Systems audit is required to evaluate whether BCP and DR are effective, not just whether documents exist
Conclusion
The direction of travel is clear. A plan on a shared drive counts for very little. What counts is a tested switchover, recovery targets the business has signed off on, gaps that were closed rather than noted and evidence the board has seen.
At CyberNX, we help NBFCs and housing finance companies design and test business continuity and disaster recovery planning for NBFCs that can handle both an inspection and a real outage. Our work spans recovery target definition, DR architecture, drill execution and audit-ready reporting. Talk to our experts to know more about our RBI Master Direction Compliance services.
Business continuity and disaster recovery planning for NBFCs FAQs
What is business continuity and disaster recovery planning for an NBFC?
RBI’s BCP and DR requirements depend on the NBFC’s applicable regulatory layer. Chapter III requires a Board-approved BCP with periodic Board oversight and backup testing. Chapter IV requires a Board-approved BCP with BIA, recovery strategy and at least annual testing, while Chapter V imposes more detailed DR requirements, including half-yearly drills for critical information systems, defined RTO/RPO and actual switchover testing.
How often must an NBFC conduct DR drills
For Middle Layer NBFCs and above, DR drills for critical information systems are required at least half-yearly. Other systems follow a risk-based schedule. Base Layer NBFCs at ₹500 crore and above must test the BCP at least annually and whenever significant IT or business changes occur.
What is the difference between RTO and RPO?
RTO is time and RPO is data. RTO is how long a system can be down before the business suffers. RPO is how far back the recovery point sits, meaning how much recent data is lost. RBI expects minimal RTO and near-zero RPO for critical systems, with a documented reconciliation method if RPO is not zero.
Does a tabletop exercise count as a DR drill
No. RBI’s requirement is written around actual switchover to the alternate site, with the site carrying normal business operations for at least a full working day. Tabletop exercises are valuable for testing decisions and communication, but they sit alongside a live drill rather than replacing it.




