Software escrow for source code – once referred to as a ‘no-brainer by a leading IT risk consultancy – will soon be mandatory for regulated entities in India.
In terms of the new master directions for regulated entities covering IT governance, risk management, controls, and assurance practices drafted by the Reserve Bank of India, regulated entities in that country will have to obtain source code from vendors for critical applications or ensure a software escrow agreement is in place.
According to Regulation Asia, the Reserve Bank was responding to the increasing dependence of banking customers on digital channels and the extensive use of outsourced IT services arrangements by regulated entities to gain access to newer technologies which could expose them to ‘significant financial, operational and reputational risks’.
Once finalised, the new master directions will apply to all scheduled commercial banks (ex. regional rural banks); small finance banks; payments banks; NBFCs (except base layer); All India Financial Institutions; and credit information companies.
Source code escrow was once referred to as a ‘no-brainer’ by Escrow Europe Director, Andrew Stekhoven, and he still maintains it is one of the most elegant steps to mitigate the risks associated with an entity’s reliance on technology it didn’t develop and doesn’t own, particularly in the SaaS environment.
He explained: “Software escrow obliges the software supplier to deposit the source code for the software with a neutral and independent trusted third party, who will release the source code to the software user when certain events take place.
“The phrase ‘source code’ is a vital one. Simply put, when your company licenses software, it more often than not gets a licence to use the machine-readable ‘object code’ but specifically not access to the ‘source code’, which programmers read and work with and which constitutes the ‘secret recipe’ for the software product.
“It’s vital because, if the software supplier is unable to support your software for any reason, the only way you are able to fix any problems or make any enhancements you need, is if you have access to the source code.
“Imagine the scenario: you have installed a new release, come month-end you suddenly find that you cannot perform vital month-end processes, you make your by-now-very-urgent support call but your supplier’s phone remains unanswered because the supplier is no longer in business, has sold the software to another firm which has decided not to support it, etc.
“The only way you can continue to function as a business is if you have access to the source code and can employ a software expert to make the changes to the software to ensure it functions as it should.”
According to Stekhoven, a scenario similar to the one he outlined above is exactly what the Reserve Bank of India’s new directives are mitigating against, in addition to addressing access controls, vulnerability assessments and penetration testing, incident response and recovery, business continuity, and disaster recovery, and information systems audits.
“The directions will come into effect six months after they are published as final by the Reserve Bank of India, sometime in 2023. They represent a logical and methodical approach to IT risk management, and should be lauded by the financial and software industries everywhere for the protection they seek to give consumers, software vendors and software users alike,” Stekhoven said.
CLICK HERE to submit your press release to MyPR.co.za.
Track Your Press Release HERE:
Check Online Visibility
Verify where this release is currently indexed:


The Cost Of Pool Covers.Do Pool Covers Merit The Cost?