IT Strategy Committee and IT Steering Committee
One sets direction at board level, the other turns it into projects. The exam loves swapping them.
Two committees carry IT governance in most large Indian entities. The IT Strategy Committee sits at board level and decides direction. The IT Steering Committee sits at executive level and turns that direction into projects, priorities and budgets.
The ISA 3.0 material describes both in general terms. For banks, RBI's Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (31 July 2026) now prescribe them in detail, and those Directions replaced the older IT governance instructions that most course notes quote.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
Strategy Committee vs Steering Committee
Level
IT Strategy Committee (ITSC)
Board
IT Steering Committee
Senior management (executive)
Members
IT Strategy Committee (ITSC)
Directors; the ISA 3.0 material allows non-board members too (RBI requires at least three directors in banks)
IT Steering Committee
Senior representatives from IT and business functions
Core job
IT Strategy Committee (ITSC)
Approve and guide IT strategy, satisfy itself that IT governance and risk processes work
IT Steering Committee
Align IT activities with business needs, oversee projects, priorities, costs and resources
Reports to
IT Strategy Committee (ITSC)
The board
IT Steering Committee
The ITSC and the MD / CEO
Typical evidence
IT Strategy Committee (ITSC)
Minutes approving IT strategy, budget adequacy review, annual BCP/DR review
IT Steering Committee
Project approvals, status reviews, prioritisation decisions
| IT Strategy Committee (ITSC) | IT Steering Committee | |
|---|---|---|
| Level | Board | Senior management (executive) |
| Members | Directors; the ISA 3.0 material allows non-board members too (RBI requires at least three directors in banks) | Senior representatives from IT and business functions |
| Core job | Approve and guide IT strategy, satisfy itself that IT governance and risk processes work | Align IT activities with business needs, oversee projects, priorities, costs and resources |
| Reports to | The board | The ITSC and the MD / CEO |
| Typical evidence | Minutes approving IT strategy, budget adequacy review, annual BCP/DR review | Project approvals, status reviews, prioritisation decisions |
RBI Rules for Commercial Banks (2026)
From the 2026 Directions. Other regulated entity types have their own versions of these Directions, so check the one that applies.
- check_circleThe board approves IT, information asset, business continuity, information security and cybersecurity strategies and policies. It may delegate review to the ITSC; review is at least annual and material changes go back to the board.
- check_circleITSC: at least three directors. The chair is an independent director with substantial IT expertise, defined as at least seven years managing information systems or leading technology or cybersecurity initiatives. Members must be technically competent. It meets at least quarterly.
- check_circleITSC duties include guiding the IT strategy, checking that budgets for IT and cybersecurity match the bank's risk, reviewing BCP and DR at least annually, reviewing IT capacity, and approving standards for need-based access.
- check_circleIT Steering Committee: senior management from IT and business, meeting at least quarterly. It assists the ITSC, oversees BCP and DR processes, ensures an IT architecture that meets statutory and regulatory requirements, and updates the ITSC and MD / CEO.
- check_circleAn Information Security Committee works under the ITSC's oversight, headed by someone from the risk management vertical.
- check_circleThe CISO must not report directly to the head of IT, carries no business targets, reports to the executive overseeing risk management, and is a permanent invitee to both the ITSC and the IT Steering Committee.
Quick practice on audit concepts. No signup.
What an Auditor Checks
Example: an IS audit of a private sector bank's IT governance for the Audit Committee.
- 1
Constitution
Board resolution and charter for each committee. Compare membership, chair qualifications and quorum with the Directions.
- 2
Frequency
Count meetings in the year from minutes. A quarter with no meeting is an exception.
- 3
Substance
Read the minutes. Was the IT strategy actually discussed and approved? Was the annual BCP/DR review done, or noted without discussion?
- 4
Follow-through
Trace two or three steering committee decisions to project records to see that they were acted on.
- 5
Independence of security
Check the CISO's reporting line and targets in the organisation chart and appointment letter.
How the DISA Assessment Test Tests This
The ISA 3.0 chapter questions show the pattern: "primary objective" questions that swap the two committees.
- check_circleThe steering committee's primary objective is to align IT initiatives with business objectives. Deciding IT strategy is the strategy committee's job; approving and managing projects follows from alignment.
- check_circlePrioritising IT initiatives rests mainly on expected benefits to the business, not the CIO's recommendation.
- check_circleIf an option puts the CISO under the head of IT, it is the wrong answer for a bank under the current Directions.
- check_circleOlder notes give RBI rules from the 2023 Master Direction or earlier; check numbers such as meeting frequency against the 2026 Directions.
FAQs
What is the difference between the IT strategy committee and the IT steering committee?expand_more
The IT strategy committee is a board committee that sets and oversees IT direction. The IT steering committee is an executive committee that aligns IT activities with business needs and oversees projects and resources. The steering committee reports to the strategy committee.
How often must a bank's IT Strategy Committee meet?expand_more
At least once a quarter, under RBI's 2026 Directions for commercial banks. The IT Steering Committee also meets at least quarterly.
Who should chair the IT Strategy Committee in a bank?expand_more
An independent director with substantial IT expertise, which RBI defines as at least seven years of managing information systems or leading technology or cybersecurity initiatives.
What is the primary objective of an IT steering committee?expand_more
To make sure IT initiatives are aligned with business objectives. Approving projects and monitoring IT performance follow from that.
Next steps
Take a full DISA mock testAssessment Test format, timed and scored.
