RBI 2026
VA/PT Assurance Checklist
Six entity-specific Directions were issued on 31 July 2026, and the commercial banks instrument provides that they come into effect immediately upon issuance. The VA/PT obligations inside them are a cluster, not a clause — a cadence, a scope, a documented approach, an auditor test, a report format and a quarterly return. This is the worksheet you walk your existing arrangement against, clause by clause, with somewhere to record the evidence.
RBI 2026 VA/PT Assurance Checklist
Enter your work email for the printable worksheet — the six-instrument map, the cadence and scope registers, the auditor gate, the paragraph 157 assurance table, the paragraph 158 record, and a dated plan working back from your next renewal.
Check your inbox
We've emailed you a link to download RBI 2026 VA/PT Assurance Checklist.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
We couldn't send the download link. Please try again, or contact us and we'll email you RBI 2026 VA/PT Assurance Checklist.
What it maps
Eight paragraphs, and the two nobody has been asked for before
Paragraph numbers below are from the commercial banks instrument. The worksheet maps the equivalent paragraph in each of the other five, because the obligation is structured the same way and the numbering is not.
¶151
Six months, twelve months, and “and / or”
Vulnerability assessment at least once every six months and penetration testing at least once every twelve, for critical information systems and / or those in the DMZ having a customer interface. The scope is disjunctive: either category brings a system inside it, so a scope built only from the critical-systems register misses customer-facing DMZ systems that were never classified critical.
¶¶149–150, 152
The triggers that have no calendar
Testing across the lifecycle of critical, internet facing web and mobile applications, servers and network components — pre-implementation, post-implementation and after changes. Post-implementation testing runs on production; where a test environment is used instead, ¶152 requires the deviation to be documented and approved by the Information Security Committee.
¶154
The documented approach, and the cloud line
Scope, coverage, CVSS-type scoring “and all other aspects” — and the paragraph provides that this shall also apply to the bank’s information systems hosted in a cloud environment. It is the bank’s document, which is a different thing from a tester’s methodology adopted verbatim.
¶156
The firm and the personnel, at every renewal
Control and check over audit methodology, processes and competence of auditors; and at selecting, appointing, engaging or renewing, consideration of qualification, professional expertise, credentials and competency of the firm as well as the audit personnel. Two subjects, and panels routinely evidence only the first.
¶157
Assurance stated explicitly in the report
Reasonable assurance for each of the areas in scope “shall be provided explicitly in the VA / PT audit reports”, and the requirement “shall be mentioned at the time of empanelling or selecting and awarding the contract”. A report-format mandate with a procurement deadline attached.
¶158
A later breach as the auditor’s deficiency
Where a tested system is later compromised, apparently due to vulnerabilities not observed or highlighted on a timely basis in the VA/PT, that “will qualify as a deficiency in discharge of function by the VA / PT auditor” — to be factored in at selection and renewal. Retrospective, and triggered by an event nobody controls.
¶159
The audit-policy regime that comes with an empanelled auditor
Where a CERT-In empanelled auditor is engaged, the bank shall be guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines. That is also the most direct way to evidence the ¶156 competency test at both firm and personnel level.
¶161
Quarterly closure, to two committees
The status of VA/PT closure goes before the IT Strategy Committee and the Information Security Committee every quarter. A standing artefact with a date on it, produced from the closure record rather than from the report — and a pack that reaches one committee is half the obligation.
Contents
Seventeen sections you write in
It is a worksheet, not a guide. Every section leaves somewhere to record an answer, and it publishes a word for the awkward one — “performed, not evidenced” is a different problem from a gap, and only one of them can be closed by writing something down.
Cover sheet
Your instrument, your Level or layer, the provider, the renewal date, and the scope sentence the rest of the worksheet is tested against.
Which instrument governs you
Six instruments and six reference numbers, with the VA/PT paragraph in each — plus the two scoping traps that expose a guess.
A state vocabulary
“Performed, not evidenced” and “contracted, not performed” are different problems from a gap, and a tick cannot say either.
Cadence and triggers
Paragraphs 149 to 153 and 162, with the modality of each stated, a last-performed date and an evidence reference.
Scope register
The “and / or” test worked through, then a register: system, why in scope, last VA, last PT, and what was excluded and why.
Auditor gate
Paragraphs 155, 156 and 159 with an evidence column, plus ¶135 on supplier personnel and ¶227 on where accountability stays.
The ¶157 assurance table
Your areas in scope, whether assurance is stated for each, where in the report, and what it rests on. Fill it once from today’s report and once from what you will require at award.
The ¶158 record
The chain of dated records a compromise is attributed from — scope, exclusions, communication dates, remediation, retest — and a space to write your position before you need it.
Third-party testing
What is owed through a switch provider or a shared core banking provider, and the difference between testing and sharing the report.
Citation sweep and a dated plan
Which of your programme documents still name a superseded instrument, and the order the remaining work has to happen in.
Where we sit
Paragraph 157 applies to our reports too
Paragraph 157 asks for reasonable assurance for each area in scope to be stated explicitly in the VA/PT report. The standard Indian VA/PT report is a findings report — Security Brigade’s included — and a findings report leaves assurance to be inferred from silence. Silence covers two very different things: an area tested and found sound, and an area never reached.
We would rather you read that here than discover it at delivery. The move it points to is the same whoever you buy from: ask every firm on your panel, ours among them, to show you a report that states assurance area by area — and ask before the contract is awarded, because that is the moment the paragraph names.
What we do bring is the testing itself and the evidence around it: CERT-In empanelled since 2008, named tester identity and credentials for the panel file paragraph 156 is assessed from, dated communication of high-severity findings so the timeline paragraph 158 turns on is on the record, and retest evidence referenced to the original finding. Where a CERT-In empanelled auditor is engaged, paragraph 159 provides that the bank shall be guided by CERT-In’s Comprehensive Cyber Security Audit Policy Guidelines — which is a defined regime coming into the arrangement with the auditor, not a claim about us.
Renewal or empanelment coming up?
Two things in this worksheet have to be settled at award rather than after it: the paragraph 157 assurance expectation, and your position on paragraph 158. Tell us your instrument and your renewal date and we will work back from it with you.
Talk about your VA/PT cycle