Skip to main content

Which co-operative banks carry the RBI awareness obligation

The annual web-based quiz at ¶156 of RBI's UCB Directions, 2026 sits in Chapter V, and the applicability table at ¶4 assigns Chapter V by Level. The Level is settled first.

By Yash Kadakia
August 31, 20267 min read

The RBI (Urban Co-operative Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 were issued on 31 July 2026 and came into force on issuance. Their awareness clause, ¶156, is unusually specific about delivery. It names a vehicle: a web-based quiz and training, every year, for lower, middle and upper management.

It is also a clause that arrives conditionally. ¶156 sits in Section H, Section H sits in Chapter V, and the applicability table at ¶4 assigns Chapter V to Level III and Level IV UCBs. So the first question about the UCB awareness obligation is not what ¶156 says. It is which Level the bank is in, and that is a question the bank answers about itself.

The Level is settled first, and the bank settles it

¶10, the opening paragraph of Chapter III, puts the categorisation on the UCB:

"The UCB shall undertake a self-assessment of the level in which it fits into, based on the above-mentioned criteria, and ensure compliance with the applicable controls. However, the UCB may adopt higher level of security measures as decided by the Board based on its own assessment of risk and capabilities."

¶10 belongs to Chapter III, and ¶4 assigns Chapter III at Level I, which applies "irrespective of digital services / products offered by it". The self-assessment duty therefore reaches every UCB, whatever conclusion it reaches. It is also the first document an auditor will ask for, because it fixes which chapters everything else is measured against.

The criteria, from the table at ¶4:

LevelCriteria at ¶4Chapters applicable
Level IApplies to the UCB irrespective of the digital services or products it offersII and III
Level IISub-member of Centralised Payment Systems (CPS) and satisfies at least one of: offers internet banking to customers, view or transaction based; provides mobile banking through an application; is a direct member of CTS, IMPS or UPIII, III and IV
Level IIISatisfies at least one of: direct member of CPS; has its own ATM Switch; has a SWIFT interfaceII, III, IV and V
Level IVDirect member or sub-member of CPS and satisfies at least one of: has its own ATM Switch and SWIFT interface; hosts a data centre or provides software support to other banks, on its own or through wholly owned subsidiariesII, III, IV, V and VI

CPS membership is defined inside the table itself. ¶4 records that "As per Master Directions on Access Criteria for Payment Systems, 2017, the CPS will include Real Time Gross Settlement (RTGS) System and National Electronic Fund Transfer (NEFT) system and any other system as may be decided by RBI from time to time." Direct membership and sub-membership are read separately across the table. Level II turns on sub-membership together with a digital-service criterion; Level IV turns on direct membership or sub-membership together with an infrastructure criterion.

Level III is reached on a single criterion. Direct membership of CPS, an own ATM Switch, or a SWIFT interface: any one of the three places the UCB in Chapter V, and ¶156 with it. A co-operative bank that maintains a SWIFT interface satisfies the Level III test on that fact alone.

What Section H says

Chapter V, Section H, "User / Employee / Management Awareness", p. 39, runs to three paragraphs:

¶155. "The UCB shall encourage the reporting of suspicious behaviour incidents to the incident management team."

¶156. "The UCB shall conduct mandatory cybersecurity awareness programs for new recruits and web-based quiz and training for lower, middle, and upper management every year."

¶157. "The UCB shall sensitise its Board members on various technological developments and cybersecurity related developments periodically."

¶156 carries two limbs and they have different shapes. The first is a joiner control: mandatory cybersecurity awareness programmes for new recruits, triggered by an event rather than by a calendar. The second is a calendar control, and the words "every year" attach to it: a web-based quiz and training, for three management cohorts, annually. ¶157 sits apart from both, with the Board on a periodic cadence.

The awareness paragraphs every UCB carries

Chapter III is assigned at Level I, so its Section R, "User / Employee / Management / Board Awareness", ¶59 to ¶65, pp. 18–19, applies across the category. That is where the awareness obligation of a UCB begins, whatever Level the self-assessment produces.

¶60 sets the general duty: the UCB "shall ensure to create a high level of awareness / familiarisation among staff at all levels including Board and Senior Management to create a cyber-safe environment". ¶63 is the operational one, and it names the subject matter:

"The UCB shall conduct awareness and training programmes for its staff on basic information security controls, including applicable Do's and Don'ts and incident reporting procedures. The UCB shall educate employees to strictly avoid clicking any links received via email (to prevent phishing / spear-phishing attacks)."

The rest of Section R extends the same duty outward: ¶61 to vendors, service providers and other concerned parties; ¶62 to the communication of acceptable-use policies; ¶64 to email attachments from unknown sources; ¶65 to training when new applications are implemented. ¶59 is permissive on its face. The UCB "may update its Board members on basic tenets / principles of IT risk / cybersecurity risk at least once a year", while ¶157 states the Board obligation in mandatory terms for a Chapter V bank.

Where ¶156 parts from the commercial-bank design

Set the UCB clauses beside the Commercial Banks Direction, also issued 31 July 2026, Section BB, pp. 47–48:

ClauseCohort namedWhat the clause names
UCB ¶156New recruitsMandatory cybersecurity awareness programmes
UCB ¶156Lower, middle and upper managementWeb-based quiz and training, every year
UCB ¶157Board membersSensitised periodically on technological and cybersecurity developments
Commercial Banks ¶203New recruitsMandatory cybersecurity awareness programmes
Commercial Banks ¶203Lower and middle managementAnnual training
Commercial Banks ¶204Board members and Senior ManagementPeriodic sensitisation to evolving threats, and annual training on IT and cybersecurity risks
Commercial Banks ¶202EmployeesEvaluate the awareness level periodically

Read down the cohort column. The commercial bank's annual training limb at ¶203 names lower and middle management, and ¶204 carries Board members and Senior Management on a separate track with its own annual training. The UCB's ¶156 puts lower, middle and upper management into a single annual cycle, through one named vehicle, and leaves the Board to ¶157's periodic sensitisation.

That is the cohort boundary, and each instrument draws it in a different place. A UCB that adopts a commercial bank's programme design and relabels the cohorts inherits a line drawn for a different clause: upper management ends up outside the annual cycle in a bank whose own clause puts it inside.

The second difference is in what each clause specifies. ¶202 of the Commercial Banks Direction states an outcome, "The bank shall evaluate the awareness level of employees periodically", and ¶203 states a cadence. ¶156 states a vehicle. A Level III or Level IV UCB designing its annual cycle is designing against a clause that has already fixed the format of delivery, which narrows the design question and sharpens the evidence question behind it.

What a Level III or Level IV UCB should hold

Four artefacts follow, and they are asked for in this order.

  • The self-assessment under ¶10. Dated, worked criterion by criterion against the ¶4 table, and recorded at the Board. Every subsequent question depends on which Level it produced.
  • The joiner record for ¶156's first limb. New recruits in the period, the awareness programme they were put through, and the completion date set against the joining date.
  • The annual cycle for ¶156's second limb. The roster for lower, middle and upper management, the quiz and the training delivered, the dates, and the completion position for each of the three cohorts separately.
  • The ¶157 record. What the Board was sensitised on, and when.

The three management cohorts map to the bank's own grade structure, so record the mapping beside the roster. A cohort drawn differently in the second year makes the two years non-comparable, and comparability is what turns an annual quiz into evidence of anything.

One adjacent clause is worth keeping separate, because the word phishing appears in two places in these Directions. ¶123, in Chapter IV, Section J, p. 34, requires the UCB to "subscribe to anti-phishing / anti-rogue application services from external service providers for identifying and taking down phishing websites / rogue applications". That is a takedown subscription, it is assigned from Level II, and it answers a different question from anything in Section H or Section R.

The order is the point. Establish the Level, record how it was established, then read the chapters the table assigns to it. A Level II UCB that runs the web-based quiz anyway is doing something ¶10 expressly contemplates, where the Board decides to adopt a higher level of security measures than its category calls for. It should be recorded as that decision, and not as the discharge of a chapter the ¶4 table assigns elsewhere.

About the author

Yash Kadakia, CERT-In Empanelment Since 2008

Founder & Chief Technology Officer

Founded Security Brigade in 2006 with the thesis that security assessment quality should be structural, not dependent on individual testers. 16+ years building platforms, teams, and methodologies that make enterprise security consistent.