Every NBFC generates a ton of logs. The servers’ logs. The firewall logs. The lending platform logs, because the vendor might have said so during the demo. Ask an IT team whether logging is enabled and the answer is almost always yes. But then comes the follow-up question: Who reads them? And there will probably be a silence.
The question is not whether the logs can be pulled if something breaks. But who actually looks at them, on a normal day, when nothing has gone wrong. That is a different question, and for a lot of otherwise well-run NBFCs, the honest answer is: nobody in particular.
This is the gap the regulator has quietly closed. Logs are no longer something you keep just in case of trouble. They are something you need to actively watch. This guide breaks down the RBI guidelines on logging and monitoring as they apply to NBFCs: what the rules ask for, how they scale with your size and what to put in place first.
What do RBI guidelines on logging and monitoring require?
The obligations sit inside the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued in Jul 2026. The logging and monitoring obligations break into three parts:
- Capability: Every application or system that can access or affect critical or sensitive information must have audit logging switched on and must produce audit trails
- Sufficiency: Those trails must be detailed enough to support an audit, stand up as forensic evidence and settle disputes, including for non-repudiation
- Monitoring: There must be a system for regularly reviewing audit trails and system logs to detect, understand or recover from unauthorised activity or an attack
That third requirement is the one that changes the work. Buying a log aggregator satisfies capability. It does not satisfy monitoring. Somebody has to look, on a defined rhythm, and be able to show they did.
How the rules scale with your NBFC layer
Logging and monitoring duties are graded by scale-based regulation layer, so a small NBFC is not held to the same bar as an Upper Layer entity.
| NBFC category | What applies to logging and monitoring |
| Base Layer below ₹500 crore, and CICs | Baseline IT/IS and cybersecurity requirements under Chapter III; the detailed Chapter V audit-trail and SOC requirements do not apply in the same form. |
| Base Layer at ₹500 crore and above | Board-approved information security framework, audit trails, unauthorised-user activity logging, cybersecurity controls and six-hour DAKSH incident reporting. |
| Middle, Upper and Top Layer | Detailed audit-trail requirements, regular monitoring of audit trails/system logs, privileged-user activity logging and periodic review, MFA for privileged users based on risk assessment, and CISO-office management/monitoring of the SOC. |
The Directions require the CISO’s office to manage and monitor a SOC for Middle Layer and above, but they do not prescribe a single technical SOC architecture or mandate one specific commercial SOC product. What Middle Layer and above entities do carry is a requirement that the CISO’s office manages and monitors a Security Operations Centre (SOC). The function is expected. The blueprint is yours to design.
What NBFCs must implement
Work through these six logging and monitoring priorities in order. Each step makes the next one cheaper.
1. Log scope
List every system that touches critical or sensitive data. Core lending platform, customer database, payment interfaces, identity systems, cloud consoles and network devices.
For each one, confirm logging is enabled and check what it captures. Many applications ship with minimal logging switched on by default.
2. Central collection
Logs sitting on the machine that produced them are easy to wipe. Pull them into one protected location where they cannot be edited by the people whose activity they record.
Central collection also makes correlation possible. A failed login on one system and a privilege change on another only tell a story together.
3. Privileged access
Anyone with elevated system entitlements needs all their activity logged and reviewed periodically. This sits directly in the rules and is a frequent audit finding.
Pair it with two-factor or multi-factor authentication for privileged users of critical systems, applied on the basis of your risk assessment.
4. Review rhythm
Decide who reviews what, and how often. Put it in writing and keep the record.
The rules ask for regular monitoring without naming a frequency, so your own documented rhythm becomes the standard you get measured against. A weekly review you complete beats a daily one you skip.
5. Vendor logs
If a service provider runs part of your technology, your contract must say that audit trails and administrative activity logs are retained by them and made available to you on request.
6. Incident path
Logs feed the incident clock. Cyber incidents must be reported on the DAKSH platform within six hours of detection, and CERT-In notified proactively. Housing finance companies report to NHB instead.
Six hours is a detection to report window. If your team needs two days to reconstruct what happened from scattered logs, the timeline has already failed.
The retention question RBI does not answer
Here is a detail that trips people up. The NBFC Directions set out logging and monitoring duties but do not name a log retention period.
That does not mean you are free to choose. The CERT-In Directions of Apr 28, 2022 require covered entities to enable logs of all their information and communications technology systems and maintain them securely for a rolling period of 180 days, within Indian jurisdiction. Those logs must be handed over when an incident is reported or when CERT-In directs. So, the working answer for most NBFCs is 180 days in India as the floor, with longer retention where audit, forensic or legal needs demand it.
Conclusion
Logging and monitoring has become a serious supervisory expectation. The systems must log, the trails must hold up as evidence and somebody must be reviewing them on a regular schedule. For most NBFCs the fastest progress comes from fixing scope and review rhythm first, then building depth. A bank-scale operation is not the goal. The goal is proper coverage of what matters, and a record showing the controls are running.
At CyberNX, our RBI Master Direction compliance services help NBFCs and financial institutions align with RBI guidelines on logging and monitoring and keep that alignment audit-ready. As a CERT-In empanelled auditor, we cover gap assessment, log architecture design, SOC operations and IS audit readiness under one roof. Talk to our experts and find out where your logging and monitoring stands today.
RBI guidelines on logging and monitoring FAQs
What do RBI guidelines on logging and monitoring require from NBFCs?
They require three things. Audit logging must be enabled on every system that can access or affect critical or sensitive information. The audit trails must be detailed enough to support audits, serve as forensic evidence and assist in dispute resolution. And there must be a system for regularly monitoring those trails and system logs to detect unauthorised activity or attacks.
How long must an NBFC retain logs?
The NBFC Directions do not specify a retention period. The CERT-In Directions of Apr 2022 require logs of information and communications technology systems to be maintained securely for a rolling 180 days within Indian jurisdiction, which serves as the practical floor for most entities.
Does every NBFC need a Security Operations Centre?
Not every NBFC. Middle Layer and above entities are required to have a SOC managed and monitored by the CISO’s office. Smaller Base Layer NBFCs carry lighter obligations, though they still need working access controls, defined user roles and the ability to detect and respond to incidents.
Do these rules apply to outsourced systems?
Yes. Where technology is outsourced, audit trails and logs of administrative activity must be retained by the service provider and made accessible to the NBFC on approved request. Accountability for the control stays with the NBFC regardless of who operates the system.




