Tech as risk core
MUMBAI — RBI Deputy Governor Rohit Jain on Wednesday warned that the banking sector's most consequential vulnerabilities may no longer lie only in credit books, market exposures or liquidity mismatches, but increasingly inside the technology stack that powers modern finance. In a pointed assessment of the sector's digital transformation, Jain said technology has moved from being a support function to becoming part of a bank's "risk architecture," a shift that demands a corresponding change in supervision, governance and board-level attention.
His remarks reflect a broader regulatory concern that the digitisation of banking has compressed the distance between operational convenience and systemic fragility. As banks expand cloud adoption, automate customer journeys, rely on third-party software and deploy artificial intelligence in underwriting, fraud detection and service delivery, the attack surface widens. The result is a model in which a cyber incident, vendor failure or AI error can quickly become a balance-sheet event, a reputational shock or a customer trust crisis.
Jain's framing is significant because it places technological resilience on the same strategic plane as financial resilience. For decades, banks have been trained to manage capital adequacy, asset quality and liquidity buffers. The RBI's message now appears to be that those safeguards are incomplete if the institution cannot withstand a cyber intrusion, data compromise, outage or model failure. In other words, a bank may be well capitalised and still be operationally vulnerable.
Governance under pressure
The deputy governor urged banks to treat technology risk as a first-order enterprise risk rather than a specialist IT issue. That distinction matters. In many institutions, technology oversight remains fragmented across operations, information security, compliance and vendor management teams. Jain's comments suggest the RBI wants boards and senior management to assume direct accountability for digital risk, with clearer escalation paths, stronger testing and more rigorous internal controls.
The warning also lands at a time when banks are under pressure to match the speed of fintech rivals without compromising safety. Customers expect instant payments, seamless onboarding and personalised digital services. But every layer of convenience can add complexity: more APIs, more integrations, more data flows and more dependencies on external providers. The challenge for banks is not simply to innovate faster, but to ensure that innovation does not outpace control.
Cybersecurity remains central to that equation. Financial institutions are among the most targeted sectors globally because they combine sensitive data, high transaction volumes and direct access to money movement. A successful attack can trigger service disruptions, fraud losses and regulatory scrutiny within minutes. Jain's remarks indicate that the RBI is likely to continue pushing banks toward stronger defensive architecture, including better monitoring, incident response readiness and resilience testing.
AI and third parties
Jain also highlighted the need for tighter oversight of third-party relationships and artificial intelligence controls, two areas that have become increasingly important as banks outsource more functions and experiment with machine-led decision-making. Third-party risk has become one of the most difficult governance challenges in financial services because a bank can inherit vulnerabilities from vendors it does not fully control. A failure in a cloud provider, software supplier or outsourced service desk can cascade across multiple institutions at once.
Artificial intelligence introduces a different but equally serious set of concerns. Banks are using AI to improve efficiency, detect anomalies and sharpen customer engagement, but models can also produce opaque decisions, bias, false positives and operational errors. If not properly governed, AI can amplify risk rather than reduce it. Jain's emphasis on controls suggests regulators want banks to document model behaviour, validate outputs and maintain human oversight over high-impact decisions.
The broader policy signal is clear: digital transformation is no longer a separate track from prudential supervision. It is now part of the core safety and soundness conversation. For banks, that means technology budgets, board agendas and risk committees will need to reflect a more demanding reality in which resilience is measured not only by capital ratios, but by the ability to absorb shocks from code, connectivity and computation.
As India's banking system becomes more digitally integrated, the RBI appears intent on making one point unmistakable: the next major banking failure may not begin with a bad loan, but with a broken system.
