India Account Aggregator Framework (RBI)
RBI AA Audit + Logging + Authentication

India Account Aggregator Framework (RBI) RBI-AA-Audit-Logging-IT-System-Audit-Consent-Lifecycle-Authentication: RBI AA Audit + Logging - IT System Audit + Consent Lifecycle Logging + Customer Authentication + Bi-Annual Audit + RBI Inspection + Sahamati Compliance Reporting

RBI AA Audit + Logging + Authentication establishes the assurance layer for the AA ecosystem. (1) IT System Audit: per RBI Cyber Security Framework + RBI IT Guidelines for NBFC-AA - bi-annual or annual independent IT system audit by qualified auditors (CISA + CISM + DISA-certified) + scope covering Information Security + IT Operations + Application Security + Network + Database + Cloud + DR/BCP + Outsourcing + Vendor Risk + audit report submitted to RBI + Action Taken Report on findings + Board-level review. (2) Consent Lifecycle Logging: comprehensive logs of all consent events - Consent Granted + Consent Modified + Consent Paused + Consent Revoked + Consent Expired + Data Fetch Initiated + Data Fetch Successful + Data Fetch Failed + FIU Data Access + Customer Login + Customer Dashboard Access + ORS Revocation + with timestamp + IP + device fingerprint + customer ID + AA session ID + FIP ID + FIU ID + consent ID + tamper-evident + retention per RBI guidance (7 years for financial transaction logs + 2 years minimum for AA consent logs) + log immutability + WORM storage. (3) Customer Authentication: multi-factor authentication for customer access to AA - Aadhaar OTP / UIDAI eSign + mobile OTP + email OTP + biometric (where available via UIDAI) + device binding + behavioural biometrics + risk-based authentication + session timeout + concurrent session limits + idle session termination. (4) RBI Inspection: RBI Department of Supervision/Department of Non-Banking Regulation periodic inspection + on-site verification + off-site supervisory returns + standardised reporting templates + corrective action timeline. (5) Sahamati Compliance Reporting: bi-annual compliance reporting to Sahamati SRO covering operational KPIs + consent volumes + dispute statistics + customer complaints + cyber incidents + technical performance + Sahamati Code of Conduct compliance. (6) Customer Audit Access: customer can access own consent history + data fetch logs + revocation history through AA portal/app + dispute mechanism. (7) CERT-In Reporting: cyber security incidents reported to Indian Computer Emergency Response Team (CERT-In) within 6 hours per CERT-In Directions of 28 April 2022. Coordinates with RBI Cyber Security Framework + RBI Audit Guidelines for NBFCs + ISACA standards (CISA + CISM) + Sahamati Code of Conduct + DPDP Act 2023 audit obligations + IT Act 2000 + CERT-In + RBI Master Directions on Information Technology Framework. RBI AA Audit + Logging + Authentication applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.