Indian financial institutions face a unique regulatory challenge when adopting cloud. Multiple regulators - RBI, SEBI, IRDAI, PFRDA - have issued guidelines that affect how cloud services can be used, where data can be stored, and what security controls must be implemented. RBI's outsourcing framework requires banks and payment system operators to ensure that their cloud providers meet specific security, availability, and data localization requirements. The data localization mandate requires that payment system data related to Indian transactions is stored exclusively in India. This does not prohibit cloud usage, but it does restrict your choice of cloud regions and services. SEBI's CSCRF includes specific provisions for cloud security, requiring regulated entities to assess cloud provider security through their vendor risk management framework and ensure that the cloud deployment meets the same security standards as an on-premises environment. PCI DSS 4.0.1 is technology-agnostic - it applies equally to cloud and on-premises environments. The shared responsibility model adds complexity because both the cloud provider and the customer have PCI DSS obligations, and the division of responsibility varies by service model. Understanding which controls are your responsibility versus the cloud provider's is the foundation of cloud compliance in financial services.
The Shared Responsibility Model and What It Means for Compliance
Cloud providers operate on a shared responsibility model where they secure the infrastructure, and you secure your workloads, data, and access. The division depends on the service model. In IaaS, you are responsible for the operating system, applications, data, and network configuration. The provider manages the hypervisor, physical infrastructure, and physical security. In PaaS, the provider additionally manages the operating system and runtime, but you remain responsible for applications and data. In SaaS, you are primarily responsible for access management and data protection. The practical implication for compliance is that migrating to cloud does not transfer your compliance obligations to the provider. If you process cardholder data in an AWS EC2 instance, you are responsible for hardening the operating system, configuring the firewall, implementing intrusion detection, managing encryption, and maintaining access controls. AWS is responsible for the physical security of the data center, the hypervisor layer, and the availability of the compute service. Many financial institutions misunderstand this model and assume that using a PCI DSS-certified cloud provider makes their deployment PCI DSS compliant. It does not. The provider's compliance covers their layer of the stack - everything above that is your responsibility. Obtain your cloud provider's PCI DSS Attestation of Compliance and their shared responsibility matrix. Map each PCI DSS requirement to either the provider's responsibility, your responsibility, or shared responsibility. This mapping is essential for your own PCI DSS assessment.
Data Localization and Cross-Border Considerations
RBI's data localization directive requires that the full end-to-end transaction data for payment transactions involving India must be stored in systems located in India. This includes the entire payment transaction chain - from transaction initiation to settlement. If you use cloud infrastructure for payment processing, your compute and storage resources must be deployed in Indian cloud regions. All three major cloud providers - AWS, Azure, and Google Cloud - have regions in India. However, data localization goes beyond just choosing an Indian region. Verify that your data does not transit through non-Indian regions during processing. Some cloud services route traffic through global load balancers or edge nodes that may be located outside India. Ensure that backup, disaster recovery, and log storage also reside in Indian regions. For DPDP compliance, the cross-border transfer framework is different. DPDP permits transfer to countries not on the restricted list but requires appropriate contractual safeguards. This means your cloud provider contracts must address data residency, processing restrictions, and the right to audit. The practical challenge is implementing these requirements across multi-cloud and hybrid environments. Organizations with workloads spanning multiple clouds and on-premises infrastructure need a consistent data governance framework that tracks where data resides across all environments and enforces location-based policies automatically.
Designing a Compliance-Ready Cloud Architecture
Start with network architecture. Implement network segmentation in the cloud using Virtual Private Clouds, subnets, security groups, and network ACLs. For PCI DSS compliance, the cardholder data environment must be segmented from non-CDE workloads. In cloud environments, this means separate VPCs or virtual networks for the CDE, with tightly controlled traffic flow between segments. Implement centralized logging and monitoring. Cloud environments generate enormous volumes of logs - cloud provider activity logs, operating system logs, application logs, and network flow logs. Centralize these in a SIEM or security analytics platform and build detection rules for common attack patterns. For PCI DSS Requirement 10, ensure that all access to cardholder data in the cloud is logged with sufficient detail for forensic investigation. Implement identity and access management with the principle of least privilege. Use cloud-native IAM services to enforce granular access controls. Implement MFA for all administrative access. Avoid long-lived access keys - use temporary credentials through role assumption wherever possible. For PCI DSS Requirement 7 and 8, document your access control model and evidence how least privilege is enforced. Implement encryption at rest and in transit for all sensitive data. Use cloud-native encryption services with customer-managed keys for maximum control. For PCI DSS Requirement 3, ensure that primary account numbers are encrypted with keys that you manage, not shared keys managed by the cloud provider. For Requirement 4, enforce TLS 1.2 or higher for all data in transit.
Cloud Security Monitoring and Incident Response
Cloud environments require a different approach to security monitoring compared to traditional on-premises infrastructure. You cannot deploy network taps or inline security appliances in the same way. Instead, leverage cloud-native security services - GuardDuty in AWS, Defender for Cloud in Azure, Security Command Center in Google Cloud - combined with your own SIEM infrastructure. Implement cloud security posture management to continuously assess your cloud configuration against security baselines. Configuration drift is the primary risk in cloud environments - a security group change, an S3 bucket made public, or an IAM policy that is too permissive can create exposure within minutes. Automated compliance checking catches these misconfigurations before attackers do. Your incident response plan must address cloud-specific scenarios. How do you isolate a compromised cloud instance? How do you preserve forensic evidence in an ephemeral compute environment? How do you communicate with your cloud provider during an incident? For RBI-regulated entities, the incident reporting timeline of 6 hours means your cloud incident response playbook must be practiced and validated through regular drills. Container and serverless workloads add additional complexity. Traditional security monitoring approaches that rely on host-based agents do not work in serverless environments. Implement runtime protection for containers, monitor function invocations in serverless architectures, and ensure that your logging covers the full execution lifecycle of ephemeral workloads.
Q: Can banks in India use public cloud for core banking?
A: Yes, with appropriate regulatory compliance. RBI permits cloud usage but requires data localization, vendor risk management, and security controls equivalent to on-premises deployments.
Q: Does using a PCI DSS-certified cloud provider make us compliant?
A: No. The provider's certification covers their infrastructure layer. You remain responsible for securing your workloads, data, and access controls within the cloud environment.
Q: Where should we store payment data in the cloud?
A: In Indian cloud regions only. RBI mandates that payment system data for Indian transactions must be stored in India. Ensure that backups, logs, and DR sites also reside in Indian regions.
QRC provides cloud security assessments and compliance consulting for financial services. Contact us to evaluate your cloud security posture.

+91 9594449393
+1 4847906355
+63 9208320598
+44 1519470017
+84 908370948
+7 9639173485
+62 81808037776
+90 5441016383
+66 993367171
+254 725235855
+256 707194495
+46 700548490