Paragraph 158: When a Breach Becomes Your Auditor's Deficiency
Three paragraphs of the RBI Directions, 2026 govern how a bank must handle its testing vendor. One of them is new: a later breach of a tested system becomes a recorded deficiency against the auditor, carried into renewal.
On this page (5)
Most of the 233 paragraphs in the RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 regulate the bank. Three of them regulate how the bank must handle its testing vendor. Paragraphs 156, 157 and 158 have no counterpart in the 2016 RBI cybersecurity framework, none in the 2023 IT Governance Master Direction, and as of the second week of the new regime, no serious public commentary at all. They took effect on 31 July 2026, on issuance, with no transition period. The one that will change procurement behaviour is para 158.
The clause, in full
"The bank shall, on an ongoing basis, review the performance of the VA / PT auditor and ensure that appropriate action is taken in case of noting any deficiencies. For instance, systems, applications, or infrastructure that were subjected to VA / PT, ceteris paribus, if found to have been compromised at a later date, apparently due to vulnerabilities that were not observed or highlighted on timely basis in the VA / PT will qualify as a deficiency in discharge of function by the VA / PT auditor. Such deficiencies shall also be factored in while evaluating the competency when selecting or renewing the contract with the VA / PT auditor."
RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, para 158
The mechanism is easy to miss on a first pass. A breach is normally scored against the bank's controls. Under para 158 a breach of a system that was tested, through a vulnerability the test did not surface, is also scored against the firm that ran the test. RBI has no direct jurisdiction over the testing firm, so para 158 carries no penalty. It creates a recorded deficiency that the bank must take into its next selection or renewal decision.
The Direction places two "shall" duties on the bank: the ongoing review of auditor performance, and the carry-forward into renewal. Between them sits the deeming limb, "will qualify as a deficiency". Acting on a noted deficiency is mandatory too. Compare para 162, where red teaming is a "may" and always has been.
Three siblings carry the identical clause with different numbering: Small Finance Banks para 157, Payments Banks para 157, Credit Information Companies para 153. The Urban Co-operative Bank and NBFC instruments contain no counterpart at all, so check the instrument before citing para 158 into a UCB tender.
The two qualifiers that set the limits
"Ceteris paribus" narrows the clause considerably. All else being equal means the auditor's deficiency is assessed against a stable subject. A system materially changed after the test, a vulnerability disclosed after the test window, an attack path outside the agreed scope: the phrase exists to exclude all three.
"Not observed or highlighted on timely basis" is the harder half, and procurement should assume the broader reading. A vulnerability can appear in the report and still fall inside para 158. If it was recorded at a severity that guaranteed no one would action it, or landed in an appendix six weeks after the test window closed, a supervisor reviewing the incident is entitled to ask whether it was highlighted on a timely basis. Report hygiene, severity discipline and turnaround time have moved from service quality to contractual exposure.
Paras 156 and 157 make para 158 enforceable
Taken alone, para 158 would be a sentiment. The paragraphs above it supply the evidence trail.
Para 156 puts the competency test at every renewal, not just at onboarding. The bank "shall have control / check over audit methodology, processes, and competence of auditors", and at selection, appointment, engagement or renewal shall consider "requisite qualification, professional expertise (of the firm or company as well as the audit personnel engaged by the entity), appropriate credentials, and suitable competency". The parenthesis is the operative part. Firm-level credentials are no longer sufficient: the bank must consider the professional expertise of the named audit personnel as well as the firm, at every selection and renewal. Siblings: SFB para 155, PB para 155, CIC para 151.
This is where empanelment earns its keep. Para 159 provides that where the bank engages a CERT-In empanelled auditor, "the bank shall be guided by CERT-In's Comprehensive Cyber Security Audit Policy Guidelines". That imports a defined audit-policy regime, and its auditor-credentialing expectations, into the supervisory relationship. A CISO who has to justify a testing vendor at renewal under para 156 has a far easier paper to write when the firm is empanelled and the named testers are identifiable against that panel. Security Brigade has held CERT-In empanelment continuously since 2008, and we evidence auditor identity and designation at engagement level, not firm level.
Para 157 changes the report itself. The bank "shall review the coverage and scope of the VA / PT and ensure that reasonable assurance for each of the areas therein shall be provided explicitly in the VA / PT audit reports. The same shall be mentioned at the time of empanelling or selecting and awarding the contract with the VA / PT auditor." Two obligations in one paragraph. Per-area assurance must be explicit in the report, and the requirement must be stated at contract award. Siblings: SFB para 156, PB para 156, CIC para 152.
Most VA/PT reports in the Indian market today list findings and stop there. Under para 157 the report has to say, area by area, what was covered and what assurance is being given over it, so that a supervisor reading it afterwards can tell the difference between an area that was tested and found clean and an area that was never reached. That distinction is what para 158 turns on when a breach lands.
Para 161 sets the reporting cadence: closure status of VA/PT observations goes to the ITSC and the ISC at least quarterly (SFB para 160, PB para 160, CIC para 156). Four checkpoints a year at the ITSC, a Board-level committee, and at the ISC, each one a dated record of what was reported and what was fixed. That is the trail a para 158 assessment will be reconstructed from.
Our position
We are willing to be held to para 158.
If a system we tested is compromised through a vulnerability that was in scope, present at the time of testing, and not surfaced in our report, that is our deficiency. We would expect it to be recorded as such and factored into our renewal. We do not want a market where the vendor writes a limitation-of-scope annexe long enough to make the question unanswerable.
In return we will hold to the qualifier RBI itself wrote in. Ceteris paribus. Scope agreed in writing, systems in the state they were tested in, findings assessed against what was knowable at the time. Scope arguments belong at the start of an engagement, not after an incident.
Across 6,700+ assessments and 1,000+ clients since 2006, the commercial answer to para 158 is coverage you can point to, severity ratings that mean something, and retests that close findings instead of restating them.
What to put in your next statement of work
The renewal cycle starting now is the first one governed by para 156 to 158. Five clauses will do most of the work:
- Named-personnel credentialing (para 156). Require the CVs, certifications and empanelment status of the individuals who will perform the work, not the firm's brochure. Require notification and re-approval if the named team changes mid-contract. Repeat the exercise at every renewal, because para 156 says "or renewing".
- Per-area assurance in the deliverable (para 157). Specify the report format in the contract, not after award, since para 157 requires the expectation to be stated when the bank empanels its own auditor panel or awards the contract. Every area in scope gets an explicit assurance statement. Every area excluded gets named as excluded.
- Timeliness defined numerically. Para 158 turns on findings being "highlighted on timely basis". Put numbers on it: critical findings notified within a fixed number of hours of discovery, not at report delivery; draft report within a fixed number of working days of test completion; retest window fixed.
- Scope in writing, with change control. The ceteris paribus qualifier only protects an auditor whose scope is documented, and it only protects the bank if scope changes are traceable. Both sides need this clause.
- A performance review schedule (para 158). The Direction says "on an ongoing basis". Attach the review to the quarterly para 161 closure pack that already goes to the ITSC and the ISC, instead of creating a separate process nobody runs.
Vendors who have been selling annual point-in-time testing against the old RBI cybersecurity framework will find these five clauses uncomfortable. That is the intended effect. RBI has given every commercial bank, Small Finance Bank, Payments Bank and Credit Information Company a documented, supervisory basis for asking a testing vendor to demonstrate competence at every renewal, and a documented consequence when the testing missed something. Ask the question at your next renewal and see which vendors can answer it.
Talk to Security Brigade about VA/PT on the para 151 cadence (SFB and PB para 150, CIC para 146), a report format built for para 157, and CERT-In empanelled testers you can name.
About the author
Regulatory and Technical Research · Security Brigade
The editorial team reads the primary sources so you do not have to. Every regulatory piece here is written against the circular, Direction or standard itself and cites the paragraph, and every technical piece is reviewed by the practice lead who runs that kind of engagement.
Continue reading
All articles →ATM Switch and CBS Providers: The Controls Your Bank Customers Must Now Impose on You
Four of the six RBI Directions require banks to impose named cybersecurity controls on their ATM Switch and core banking service providers by contract: 24 of them for commercial banks, 37 for urban co-operative banks. The controls land on the provider, and the bank is the one that has to put them there.
Foreign Bank Branches and Comply-or-Explain: What Paragraph 4 Actually Buys You
The RBI Directions, 2026 contain exactly one comply-or-explain device, and it applies only to foreign banks operating in India through branch mode. It covers four chapters and sixteen named paragraph groups. The relaxation is conditional: RBI has to accept your explanation.
Case Study: Moving a Commercial Bank from Annual Testing to the Paragraph 151 Cadence
A commercial bank on annual point-in-time VAPT re-scoped its programme to the RBI Directions, 2026: six-monthly vulnerability assessment, production-environment testing, cloud in scope, and a quarterly closure pack for the ITSC and ISC produced for the first time.