RBI AA Framework imposes strict IT and data protection controls reflecting the elevated trust and sensitivity of consolidating financial information. (1) Data Transience (No Storage): AA shall be a data blind pipe - data passes through AA but is never stored at the AA + AA only stores consent artefacts + metadata + audit logs - NOT the actual financial data + AA has no visibility into financial data content (data encrypted end-to-end). (2) End-to-End Encryption (E2EE): data flowing from FIP to FIU passes through AA but is encrypted with FIU public key at the FIP + only the FIU can decrypt + AA cannot see plaintext data + cryptographic key management per Sahamati standards + JWT signing + RSA + ECDSA + AES-256. (3) Data Localisation: per RBI directive (Storage of Payment System Data 2018 extended to AA), all data and the entire ecosystem must operate within geographic boundaries of India + servers + processing + backup + DR sites in India + no data offshoring + cross-border transfer prohibited or restricted + Indian sovereignty over consumer financial data. (4) Information Security Policy: board-approved Information Security Policy aligned with RBI Cyber Security Framework + RBI Guidelines on Information Security + ISO 27001 + ISO 27002 + standardised CISO role + IT Steering Committee + cyber risk management + threat intelligence + SOC operations + vulnerability management + penetration testing + secure SDLC. (5) RBI IT Framework for NBFC-AA: specific IT framework requirements - access management + network segmentation + endpoint protection + database security + application security + change management + capacity planning + technology obsolescence + cloud governance + DevSecOps. (6) Outsourcing Controls: per RBI Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services + due diligence on technology vendors + audit rights + termination + exit strategy. (7) DPDP Act 2023 Compliance: aligned with Significant Data Fiduciary (SDF) obligations where applicable + Data Protection Officer (DPO) + Data Protection Impact Assessment (DPIA) + breach notification within 72 hours to Data Protection Board of India (DPBI) + customer rights (Sec 11 Access + Sec 12 Correction + Sec 13 Grievance + Sec 14 Nomination). Coordinates with RBI Cyber Security Framework + RBI Information Security Guidelines for NBFCs + ISO 27001/27002 + DPDP Act 2023 + IT Act 2000 Section 43A + CERT-In Vulnerability Reporting + Sahamati Technical Standards. RBI AA IT + Data Protection + Transience + E2EE + Localisation applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.