Risk Architecture Shift
RBI Deputy Governor Rohit Jain has delivered a pointed warning to India's banking sector: the biggest threats to financial stability may now be embedded inside the technology stack itself. Speaking on the changing nature of banking risk, Jain said technology is no longer merely an operational tool or a growth lever, but increasingly the architecture through which risk is created, transmitted and amplified.
That framing marks a significant shift in how regulators are viewing the digital transformation of finance. For years, banks have spoken about technology as an enabler of scale, speed and customer reach. Jain's message suggests the balance has changed. As core banking, payments, lending, compliance and customer service become more digitised, resilience can no longer be measured only in capital buffers, liquidity ratios or asset quality. It must also be judged by the strength of systems, code, data controls and incident response.
The RBI official's remarks land at a time when Indian banks are expanding their digital footprints across mobile banking, instant payments, cloud adoption, automated underwriting and AI-assisted operations. Each of those shifts improves efficiency, but each also widens the attack surface. A cyber intrusion, a vendor outage, a model failure or a data integrity breach can now disrupt customer access and confidence as quickly as a balance-sheet shock.
Cyber Risk Becomes Core
Jain urged banks to treat technology risk as a first-order enterprise risk rather than a specialist IT issue. That distinction matters. In many institutions, technology oversight still sits in silos, separated from board-level discussions on credit, market or operational risk. The RBI's message is that such separation is no longer defensible when digital systems are intertwined with every major banking function.
The emphasis on governance is especially important. Stronger oversight, Jain indicated, should begin at the board and senior management level, where technology decisions are often approved without the same scrutiny applied to traditional financial exposures. Banks, he suggested, need clearer accountability for cyber preparedness, resilience testing, recovery planning and the management of technology dependencies.
Cybersecurity remains the most visible threat, but it is not the only one. The growing use of third-party service providers, cloud platforms and fintech integrations means banks are increasingly exposed to failures outside their direct control. A disruption at a vendor can cascade into a bank's customer-facing systems, payment rails or internal operations. Jain's call for tighter third-party oversight reflects a broader regulatory concern that outsourcing does not outsource responsibility.
AI Needs Guardrails
Artificial intelligence is emerging as another area of concern. Banks are deploying AI for fraud detection, customer service, credit assessment and process automation, but the technology also introduces model risk, bias, explainability challenges and governance gaps. Jain's warning implies that AI cannot be treated as a plug-and-play productivity tool without controls that ensure transparency, testing and human accountability.
For lenders and insurers, the implications are substantial. As underwriting, claims processing and customer engagement become more automated, errors can scale faster and spread wider. A flawed model can misprice risk, exclude customers unfairly or trigger compliance failures. In a sector where trust is central, even isolated technology failures can have systemic consequences if they erode confidence in digital channels.
The RBI's stance also reflects a wider global regulatory trend. Supervisors in major financial markets are increasingly pushing banks to prove operational resilience, not just financial soundness. That includes stress testing technology systems, mapping critical dependencies, improving incident reporting and ensuring that recovery objectives are realistic rather than theoretical. Jain's comments place India firmly within that shift.
For banks, the message is clear: digital transformation is no longer just a competitive strategy. It is a risk-management challenge that must be governed with the same seriousness as lending, capital and liquidity. In the RBI's view, the institutions best positioned for the next phase of banking will not simply be the most digital, but the most resilient.
