On 28 November 2025 the Reserve Bank restructured a substantial part of its rulebook into entity-class-specific Directions. Outsourcing risk became eight separate instruments. Digital banking channel authorisation was split the same way on the same day.
The obligations are close to identical. The instruments are not. The six-hour incident reporting obligation is paragraph 14 in the all India financial institutions Direction and paragraph 61 in the one for non-banking financial companies. Same obligation, same regulator, same day of issue, different entity class.
Six months earlier, the Digital Lending Directions, 2025 repealed the September 2022 Guidelines outright. The obligation survived almost unchanged. Every document citing the 2022 circular became wrong on the same day.
A control register maintained by hand does not notice either event. It keeps pointing at a repealed circular, or at the wrong entity class, and stays internally consistent while being externally wrong. Nothing fails. Nobody is alerted. The gap surfaces during an inspection.
That is why AssureNode binds every control to a clause in a named instrument, and why the binding is a versioned object rather than a footnote.