Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • English
    • English (US)
Contact Us
CyberNX Logo
  • English
    • English (US)
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • Contact

RBI Guidelines on Logging and Monitoring: What NBFCs Must Implement

5 min read
24 Views
  • RBI Master Directions

Every NBFC generates a ton of logs. The servers’ logs. The firewall logs. The lending platform logs, because the vendor might have said so during the demo. Ask an IT team whether logging is enabled and the answer is almost always yes. But then comes the follow-up question: Who reads them? And there will probably be a silence.

The question is not whether the logs can be pulled if something breaks. But who actually looks at them, on a normal day, when nothing has gone wrong. That is a different question, and for a lot of otherwise well-run NBFCs, the honest answer is: nobody in particular.

This is the gap the regulator has quietly closed. Logs are no longer something you keep just in case of trouble. They are something you need to actively watch. This guide breaks down the RBI guidelines on logging and monitoring as they apply to NBFCs: what the rules ask for, how they scale with your size and what to put in place first.

Table of Contents

What do RBI guidelines on logging and monitoring require?

The obligations sit inside the Reserve Bank of India (Non-Banking Financial Companies – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, issued in Jul 2026. The logging and monitoring obligations break into three parts:

  • Capability: Every application or system that can access or affect critical or sensitive information must have audit logging switched on and must produce audit trails
  • Sufficiency: Those trails must be detailed enough to support an audit, stand up as forensic evidence and settle disputes, including for non-repudiation
  • Monitoring: There must be a system for regularly reviewing audit trails and system logs to detect, understand or recover from unauthorised activity or an attack

That third requirement is the one that changes the work. Buying a log aggregator satisfies capability. It does not satisfy monitoring. Somebody has to look, on a defined rhythm, and be able to show they did.

How the rules scale with your NBFC layer

Logging and monitoring duties are graded by scale-based regulation layer, so a small NBFC is not held to the same bar as an Upper Layer entity.

NBFC category  What applies to logging and monitoring 
Base Layer below ₹500 crore, and CICs Baseline IT/IS and cybersecurity requirements under Chapter III; the detailed Chapter V audit-trail and SOC requirements do not apply in the same form.
Base Layer at ₹500 crore and above Board-approved information security framework, audit trails, unauthorised-user activity logging, cybersecurity controls and six-hour DAKSH incident reporting.
Middle, Upper and Top Layer Detailed audit-trail requirements, regular monitoring of audit trails/system logs, privileged-user activity logging and periodic review, MFA for privileged users based on risk assessment, and CISO-office management/monitoring of the SOC.

The Directions require the CISO’s office to manage and monitor a SOC for Middle Layer and above, but they do not prescribe a single technical SOC architecture or mandate one specific commercial SOC product. What Middle Layer and above entities do carry is a requirement that the CISO’s office manages and monitors a Security Operations Centre (SOC). The function is expected. The blueprint is yours to design.

What NBFCs must implement

Work through these six logging and monitoring priorities in order. Each step makes the next one cheaper.

6 Things NBFCs Must Implement for Logging and Monitoring

1. Log scope

List every system that touches critical or sensitive data. Core lending platform, customer database, payment interfaces, identity systems, cloud consoles and network devices.

For each one, confirm logging is enabled and check what it captures. Many applications ship with minimal logging switched on by default.

2. Central collection

Logs sitting on the machine that produced them are easy to wipe. Pull them into one protected location where they cannot be edited by the people whose activity they record.

Central collection also makes correlation possible. A failed login on one system and a privilege change on another only tell a story together.

3. Privileged access

Anyone with elevated system entitlements needs all their activity logged and reviewed periodically. This sits directly in the rules and is a frequent audit finding.

Pair it with two-factor or multi-factor authentication for privileged users of critical systems, applied on the basis of your risk assessment.

4. Review rhythm

Decide who reviews what, and how often. Put it in writing and keep the record.

The rules ask for regular monitoring without naming a frequency, so your own documented rhythm becomes the standard you get measured against. A weekly review you complete beats a daily one you skip.

5. Vendor logs

If a service provider runs part of your technology, your contract must say that audit trails and administrative activity logs are retained by them and made available to you on request.

6. Incident path

Logs feed the incident clock. Cyber incidents must be reported on the DAKSH platform within six hours of detection, and CERT-In notified proactively. Housing finance companies report to NHB instead.

Six hours is a detection to report window. If your team needs two days to reconstruct what happened from scattered logs, the timeline has already failed.

The retention question RBI does not answer

Here is a detail that trips people up. The NBFC Directions set out logging and monitoring duties but do not name a log retention period.

That does not mean you are free to choose. The CERT-In Directions of Apr 28, 2022 require covered entities to enable logs of all their information and communications technology systems and maintain them securely for a rolling period of 180 days, within Indian jurisdiction. Those logs must be handed over when an incident is reported or when CERT-In directs. So, the working answer for most NBFCs is 180 days in India as the floor, with longer retention where audit, forensic or legal needs demand it.

Conclusion

Logging and monitoring has become a serious supervisory expectation. The systems must log, the trails must hold up as evidence and somebody must be reviewing them on a regular schedule. For most NBFCs the fastest progress comes from fixing scope and review rhythm first, then building depth. A bank-scale operation is not the goal. The goal is proper coverage of what matters, and a record showing the controls are running.

At CyberNX, our RBI Master Direction compliance services help NBFCs and financial institutions align with RBI guidelines on logging and monitoring and keep that alignment audit-ready. As a CERT-In empanelled auditor, we cover gap assessment, log architecture design, SOC operations and IS audit readiness under one roof. Talk to our experts and find out where your logging and monitoring stands today.

RBI guidelines on logging and monitoring FAQs

What do RBI guidelines on logging and monitoring require from NBFCs?

They require three things. Audit logging must be enabled on every system that can access or affect critical or sensitive information. The audit trails must be detailed enough to support audits, serve as forensic evidence and assist in dispute resolution. And there must be a system for regularly monitoring those trails and system logs to detect unauthorised activity or attacks.

How long must an NBFC retain logs?

The NBFC Directions do not specify a retention period. The CERT-In Directions of Apr 2022 require logs of information and communications technology systems to be maintained securely for a rolling 180 days within Indian jurisdiction, which serves as the practical floor for most entities.

Does every NBFC need a Security Operations Centre?

Not every NBFC. Middle Layer and above entities are required to have a SOC managed and monitored by the CISO’s office. Smaller Base Layer NBFCs carry lighter obligations, though they still need working access controls, defined user roles and the ability to detect and respond to incidents.

Do these rules apply to outsourced systems?

Yes. Where technology is outsourced, audit trails and logs of administrative activity must be retained by the service provider and made accessible to the NBFC on approved request. Accountability for the control stays with the NBFC regardless of who operates the system.

Gopakumar Panicker

Author
Gopakumar Panicker
LinkedIn

An accomplished security professional with extensive experience in Digital Security, Cloud Security, Cloud Architecture, Security Operations, and BFSI Compliance, Gopa has contributed to designing and strengthening enterprise-grade security environments, ensuring alignment with both technical and regulatory requirements. His work focuses on building resilient, scalable architectures and guiding organisations in elevating their operational maturity while meeting the stringent expectations of modern BFSI and cloud-driven ecosystems.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
Business Continuity and Disaster Recovery Planning for NBFCs in 2026

Business Continuity and Disaster Recovery Planning for NBFCs: What RBI Now Expects

Every car usually has a spare tire in the boot but almost nobody has ever fitted one. It sits there

How to Conduct an IS Audit That Meets RBI's Requirements

How to Conduct an IS Audit as per RBI’s Requirements

There are two very different ways organisations approach an IS audit. In the first, a team turns up, runs some

Building an Information Security Program That Meets RBI Standards

How to Create an Information Security Program That Meets RBI Standards

If you ask five people in a bank to describe their information security program, you will probably get five different

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English
    • English (US)
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.