The Reserve Bank of India (RBI) has unveiled one of the biggest regulatory overhauls for Urban Cooperative Banks (UCBs) in recent years by issuing nine comprehensive Directions covering compliance, supervision, audits, fraud risk management, cybersecurity, digital payment security and supervisory reporting.
Issued on Friday, the new regulatory framework seeks to strengthen governance, transparency and risk management while aligning regulatory requirements with the size, complexity and digital maturity of UCBs. The Directions have come into force with immediate effect, although certain provisions provide transition time for eligible banks.
Among the key reforms, RBI has mandated an independent Compliance Function headed by a Chief Compliance Officer (CCO) for Tier-3 and Tier-4 UCBs, along with Board-approved compliance policies, annual compliance risk assessments and periodic oversight by the Board or Audit Committee.
The Miscellaneous Supervisory Directions consolidate several existing supervisory instructions, including the Prompt Corrective Action (PCA) framework for Tier-2, Tier-3 and Tier-4 UCBs. The framework is based on three financial indicators, Capital to Risk-weighted Assets Ratio (CRAR), Net NPA ratio and profitability, and empowers RBI to initiate timely supervisory and corrective measures for financially stressed banks.
The Directions also consolidate provisions relating to Core Banking Solution (CBS), fair practices in charging interest, nomination facilities, fraud prevention measures and vigilance.
RBI has also issued separate Directions on Internal Audit and Statutory Audit. UCBs with assets of Rs 500 crore and above will be required to adopt a Risk-Based Internal Audit (RBIA) framework, while fresh norms have been prescribed for the appointment, independence, tenure, rotation and performance review of statutory auditors.
To address growing operational and technology risks, RBI has introduced dedicated Directions on Fraud Risk Management, Digital Payment Security Controls and Cybersecurity, Technology Risk, Resilience and Assurance Framework.
The new regime requires Board-approved fraud risk policies, early warning systems, enhanced digital payment security controls and graded cybersecurity requirements. Banks must also follow due process, including issuing a detailed show-cause notice and allowing at least 21 days before classifying any borrower, entity or other concerned person as fraud.
The package also includes Supervisory Returns Directions, placing greater responsibility on Boards and senior management for data quality, reporting accuracy and IT infrastructure for regulatory reporting. Collectively, the nine Directions consolidate several existing regulatory instructions and mark a significant modernization of RBI’s supervisory framework for Urban Cooperative Banks.





