Case Brief
By an order dated September 4, 2024, RBI imposed a monetary penalty of Rs 23,10,000 on SMFG India Credit Company Limited (formerly Fullerton India Credit Company Limited). The penalty was for non-compliance with provisions of the Master Direction - Information Technology Framework for the NBFC Sector and certain RBI directions on cyber security measures. RBI said the sustained lapses included missing monitoring and oversight clauses in outsourced-vendor contracts, not conducting IS audits for Network and Security Solutions since inception, inadequate storage/retention of audit logs for the email gateway, and failure to analyse or act on a critical malware alert from an Endpoint Detection & Response solution. The action was taken under Section 58G read with Section 58B(5)(aa) of the RBI Act, 1934 and is without prejudice to any other action RBI may initiate.
Action Snapshot
- Primary Impact
- Fine: Rs 23.1 L
- Entity Type
- NBFC
- Action Type