Paragraph 158: When a Breach Becomes Your Auditor's Deficiency
Three paragraphs of the RBI Directions, 2026 govern how a bank must handle its testing vendor — and one of them makes a later breach of a tested system a recorded deficiency against the auditor, carried into renewal. There is no counterpart in the 2016 framework or the 2023 Master Direction.
On this page (5)
Most of the 233 paragraphs in the RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 regulate the bank. Three of them regulate how the bank must handle its testing vendor. Paragraphs 156, 157 and 158 have no counterpart in the 2016 RBI cybersecurity framework, none in the 2023 IT Governance Master Direction, and as of the second week of the new regime, no serious public commentary at all. They took effect on 31 July 2026, on issuance, with no transition period. The one that will change procurement behaviour is para 158.
The clause, in full
"The bank shall, on an ongoing basis, review the performance of the VA / PT auditor and ensure that appropriate action is taken in case of noting any deficiencies. For instance, systems, applications, or infrastructure that were subjected to VA / PT, ceteris paribus, if found to have been compromised at a later date, apparently due to vulnerabilities that were not observed or highlighted on timely basis in the VA / PT will qualify as a deficiency in discharge of function by the VA / PT auditor. Such deficiencies shall also be factored in while evaluating the competency when selecting or renewing the contract with the VA / PT auditor."
RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, para 158
Read it twice, because the mechanism is easy to miss on the first pass. A breach is normally scored against the bank's controls. Under para 158 a breach of a system that was tested, through a vulnerability the test did not surface, is also scored against the firm that ran the test. It is not a penalty and RBI has no direct jurisdiction over the testing firm. It is something more durable: a recorded deficiency that the bank is obliged to carry into the next selection or renewal decision.
Both duties the Direction places on the bank are "shall" — the ongoing review of auditor performance, and the carry-forward into renewal — and the deeming limb between them reads "will qualify as a deficiency". The review is mandatory, the action on noting a deficiency is mandatory, and the carry-forward into renewal is mandatory. Compare para 162, where red teaming is a "may" and always has been. Procurement teams should not confuse the two.
Three siblings carry the identical clause with different numbering: Small Finance Banks para 157, Payments Banks para 157, Credit Information Companies para 153. The Urban Co-operative Bank and NBFC instruments contain no counterpart at all, which is worth knowing before someone cites para 158 into a UCB tender where it does not exist.
The two qualifiers that decide the argument
"Ceteris paribus" is doing real work. All else being equal means the auditor's deficiency is assessed against a stable subject. A system materially changed after the test, a vulnerability disclosed after the test window, an attack path outside the agreed scope: these are the conditions the phrase exists to exclude. An auditor is not being made liable for the passage of time.
"Not observed or highlighted on timely basis" is the harder half, and procurement should assume the broader reading. A vulnerability that appeared in the report is not automatically outside para 158. If it was recorded at a severity that guaranteed no one would action it, or landed in an appendix six weeks after the test window closed, a supervisor reviewing the incident is entitled to ask whether it was highlighted on a timely basis. Report hygiene, severity discipline and turnaround time have just become contractual exposure rather than service quality.
Paras 156 and 157 are what make para 158 enforceable
Taken alone, para 158 would be a sentiment. The paragraphs above it supply the evidence trail.
Para 156 puts the competency test at every renewal, not just at onboarding. The bank "shall have control / check over audit methodology, processes, and competence of auditors", and at selection, appointment, engagement or renewal shall consider "requisite qualification, professional expertise (of the firm or company as well as the audit personnel engaged by the entity), appropriate credentials, and suitable competency". The parenthesis is the operative part. Firm-level credentials are no longer sufficient. The bank must consider the professional expertise of the named audit personnel as well as the firm, at every selection and renewal. Siblings: SFB para 155, PB para 155, CIC para 151.
This is where empanelment earns its keep. Para 159 provides that where the bank engages a CERT-In empanelled auditor, "the bank shall be guided by CERT-In's Comprehensive Cyber Security Audit Policy Guidelines" — a defined audit-policy regime, with defined auditor-credentialing expectations, imported into the supervisory relationship. A CISO who has to justify a testing vendor at renewal under para 156 has a far easier paper to write when the firm is empanelled and the named testers are identifiable against that panel. Security Brigade has held CERT-In empanelment continuously since 2008, and we evidence auditor identity and designation at engagement level rather than firm level.
Para 157 changes the report itself. The bank "shall review the coverage and scope of the VA / PT and ensure that reasonable assurance for each of the areas therein shall be provided explicitly in the VA / PT audit reports. The same shall be mentioned at the time of empanelling or selecting and awarding the contract with the VA / PT auditor." Two obligations in one paragraph. Per-area assurance must be explicit in the report, and the requirement must be stated at contract award. Siblings: SFB para 156, PB para 156, CIC para 152.
Most VA/PT reports in the Indian market today do not do this. They list findings. A findings list is not an assurance statement. Under para 157 the report has to say, area by area, what was covered and what assurance is being given over it, so that a supervisor reading it afterwards can tell the difference between an area that was tested and found clean and an area that was never reached. That distinction is precisely what para 158 turns on when a breach lands.
And para 161 closes the loop: closure status of VA/PT observations goes to the ITSC and the ISC at least quarterly (SFB para 160, PB para 160, CIC para 156). Four checkpoints a year at the ITSC, a Board-level committee, and at the ISC, each one a dated record of what was reported and what was fixed. That is the trail a para 158 assessment will be reconstructed from.
Our position, stated plainly
We are willing to be held to para 158. That is the point of writing this piece, and it is not a comfortable sentence for a testing firm to publish.
If a system we tested is compromised through a vulnerability that was in scope, present at the time of testing, and not surfaced in our report, that is our deficiency. We would expect it to be recorded as such and factored into our renewal. We do not want the version of this market where the vendor writes a limitation-of-scope annexe long enough to make the question unanswerable.
What we will hold to in return is the qualifier RBI itself wrote in. Ceteris paribus. Scope agreed in writing, systems in the state they were tested in, findings assessed against what was knowable at the time. A firm that accepts para 158 honestly has to be given the conditions to meet it, which means scope arguments happen at the start of an engagement rather than after an incident.
Across 6,700+ assessments and 1,000+ clients since 2008, the commercial answer to para 158 has never been disclaimers. It is coverage you can point to, severity ratings that mean something, and retests that close findings rather than restate them.
What to put in your next statement of work
The renewal cycle starting now is the first one governed by para 156 to 158. Five clauses will do most of the work:
- Named-personnel credentialing (para 156). Require the CVs, certifications and empanelment status of the individuals who will perform the work, not the firm's brochure. Require notification and re-approval if the named team changes mid-contract. Repeat the exercise at every renewal, because para 156 says "or renewing".
- Per-area assurance in the deliverable (para 157). Specify the report format in the contract, not after award, since para 157 requires the expectation to be stated when the bank empanels its own auditor panel or awards the contract. Every area in scope gets an explicit assurance statement. Every area excluded gets named as excluded.
- Timeliness defined numerically. para 158 turns on findings being "highlighted on timely basis". Put numbers on it: critical findings notified within a fixed number of hours of discovery rather than at report delivery, draft report within a fixed number of working days of test completion, retest window fixed.
- Scope in writing, with change control. The ceteris paribus qualifier only protects an auditor whose scope is documented, and it only protects the bank if scope changes are traceable. Both sides need this clause.
- A performance review schedule (para 158). The Direction says "on an ongoing basis". Attach the review to the quarterly para 161 closure pack that already goes to the ITSC and the ISC, rather than creating a separate process nobody runs.
Vendors who have been selling annual point-in-time testing against the old RBI cybersecurity framework will find these five clauses uncomfortable. That is the intended effect. RBI has given every commercial bank, Small Finance Bank, Payments Bank and Credit Information Company a documented, supervisory basis for asking a testing vendor to demonstrate competence at every renewal, and a documented consequence when the testing missed something. Ask the question at your next renewal and see which vendors can answer it.
Talk to Security Brigade about VA/PT on the para 151 cadence (SFB and PB para 150, CIC para 146), a report format built for para 157, and CERT-In empanelled testers you can name.
About the author
Security Brigade Editorial Team
Continue reading
All articles →ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on You
Four of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract — 24 of them for commercial banks, 37 for urban co-operative banks. The obligation flows down even where it does not sit at the top.
Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys You
The RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups — and it is a relaxation subject to RBI accepting your explanation, not an exemption.
Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 Cadence
A commercial bank running annual point-in-time VAPT re-scoped to the RBI Directions, 2026 — six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC that did not previously exist as an artefact.