RBI Data Localization

  • Home
  • RBI Data Localization

RBI Data Localization


The Reserve Bank of India issued a directive vide circular DPSS.CO.OD.No 2785/06.08.005/2017-18 April 8, 2018, making it mandatory for all transaction data to be stored exclusively within India.

The Reserve Bank of India issued a directive vide circular DPSS.CO.OD.No 2785/06.08.005/2017-18 April 8, 2018, making it mandatory for all transaction data to be stored exclusively within India.

SAR Audit:

A System Audit Report (SAR) is a document that organizations, particularly those involved in handling payment data, are required to submit to the Reserve Bank of India (RBI) in compliance with the data localization mandate. The SAR serves as an official record certifying that the organization has fulfilled the requirement of storing end-to-end transaction data within India.


Key Criteria for System Audit Report for Data Localization (SAR)

Based on the RBI & NPCI Guidelines, the following key criteria need to be covered as part of this audit.

  • Payment Data Elements
  • Transaction / Data Flow
  • Application Architecture
  • Network Diagram / Architecture
  • Data Storage
  • Transaction Processing
  • Activities subsequent to Payment Processing
  • Cross Border Transactions
  • Database Storage and Maintenance
  • Data Backup & Restoration
  • Data Security
  • Data Security

Approach for System Audit Report for Data Localization (SAR)

Based on our extensive experience with delivering SAR for Data Localization & Storage of Payment System Data, we have developed the following approach:

Phase 1 – Information Gathering & Documentation Review

A detailed questionnaire is shared with your teams and various documentation and evidences are collected on the architecture, implementation and controls in place. These documents are thoroughly reviewed by our experts to understand the implementation and flag any concerns.

Phase 2 – Assessment, Validation & In-Depth Control Review

In this phase, we thoroughly analyse the documentation and review the provided artifacts to ensure their validity. Additionally, we assess the technical controls according to industry best practices and examine the data flow to identify any potential risks or gaps.

Phase 3 – Remediation & Re-Validation

A detailed report will be provided that highlights any areas of concern, risks, or violations. In addition, we will offer appropriate recommendations will work closely with you to facilitate re-validation, ensuring that all gaps are addressed and successful compliance is achieved.

Phase 4 – CERT-In Empanelled Certification

As an auditor certified by CERT-IN, we thoroughly document all activities, including relevant paperwork, evidence, findings, and recommendations. We issue a CERT-IN certification for the System Audit Report (SAR) which focuses on data localization and storage of payment system data.

phases

Why do organizations need it?

  • SAR data localisation shields native citizen’s financial and personal information in moments of geopolitical crisis.
  • Shielding against anti-money laundering threats.
  • Holistic implementation of regulations to secure payment gateways.
  • Enhance IT Governance for payment service providers.

Advantages

  • Secures citizen’s data and provides data privacy and data sovereignty from foreign surveillance.
  • Unfettered supervisory access to data will help Indian law enforcement ensure better monitoring.
  • Minimises conflict of jurisdiction due to cross-border data sharing and delay in justice delivery in case of data breach.
  • It will give local governments and regulators the jurisdiction to call for the data when required.

FAQ:

  1. How much does the RBI Data Localization Audit cost?
    The cost of an RBI Data Localization Audit depends on several factors, including the size of your organization, the complexity of your IT systems and infrastructure, and the scope of the audit.

  2. How long does the RBI Data Localization Audit take?
    The duration of an RBI Data Localization Audit can vary depending on the size of your organization, the complexity of your IT systems and infrastructure, and the scope of the audit.

  3. What types of reports are included in the RBI Data Localization Audit?The RBI Data Localization Audit includes a System Audit Report for Data Localization (SAR). This report provides a comprehensive analysis of your IT systems and infrastructure, identifying potential risks and vulnerabilities that could impact the security of your data. The SAR report also includes recommendations for improving your security posture and complying with RBI regulations.

  4. What are the key criteria for the SAR report?
    The SAR report follows the guidelines provided by the RBI and includes a comprehensive analysis of your IT systems and infrastructure. The report covers several areas, including access control, network security, data protection, and incident management. The SAR report also includes recommendations for improving your security posture and complying with RBI regulations.

  5. How often do I need to conduct an RBI Data Localization Audit?
    The RBI guidelines recommend conducting an RBI Data Localization Audit at least once a year. However, the frequency of the audit can vary depending on the size of your organization, the complexity of your IT systems and infrastructure, and the scope of the audit.

Want to Know more
Get In Touch