Tech Becomes Risk
Reserve Bank of India Deputy Governor Rohit Jain has drawn a sharp line under the changing nature of risk in Indian banking, arguing that technology is no longer merely an enabler of financial services but increasingly the architecture through which risk itself is created, transmitted and amplified. His remarks come at a time when banks are leaning harder than ever on cloud infrastructure, digital payments rails, automated decision systems and outsourced technology vendors to keep pace with customer demand and competition from fintech firms.
Jain's central message was that technological resilience must now be treated with the same seriousness as financial resilience. In practical terms, that means banks can no longer confine risk management to balance-sheet metrics, credit quality and liquidity buffers. Instead, boards and senior management must regard technology risk as a first-order enterprise risk, one that can disrupt operations, weaken customer trust and expose institutions to regulatory, legal and reputational fallout.
The warning is especially pointed for India's banking system, which has undergone one of the world's fastest digital transformations. The sector has benefited enormously from real-time payments, mobile banking and data-driven underwriting, but that speed has also widened the attack surface. A single failure in a core banking platform, a breach at a service provider or a flaw in an AI-driven process can now ripple across millions of accounts and transactions in minutes.
Governance Under Pressure
Jain's emphasis on governance reflects a broader shift in regulatory thinking: technology risk is no longer a back-office IT concern, but a board-level issue that demands clear accountability. Banks, he suggested, need stronger oversight structures that can interrogate not just whether systems are functioning, but whether they are secure, auditable and aligned with the institution's risk appetite.
That includes tighter supervision of third-party providers, a growing vulnerability in modern banking models. As lenders increasingly rely on vendors for cloud hosting, software development, payment processing and customer-facing applications, the risk profile extends well beyond the bank's own perimeter. Operational failures or cyber incidents at a vendor can quickly become bank-wide incidents, even if the institution itself has invested heavily in internal controls.
The RBI deputy governor also signaled that cybersecurity can no longer be treated as a periodic compliance exercise. The scale and sophistication of attacks targeting financial institutions have made continuous monitoring, incident response readiness and resilience testing essential. For banks, the challenge is not only preventing breaches, but ensuring they can recover quickly and continue serving customers when systems are compromised.
AI Needs Guardrails
Jain's remarks also placed artificial intelligence squarely inside the risk conversation. As banks experiment with AI for fraud detection, customer service, underwriting and internal automation, they are also inheriting new forms of model risk, bias, opacity and dependency. The promise of efficiency and precision is real, but so is the possibility of flawed outputs, poor explainability and unintended decision-making at scale.
That is why controls around AI cannot be an afterthought, Jain indicated. Banks need governance frameworks that define where AI can be used, how outputs are validated, who is accountable for errors and what safeguards exist when models behave unpredictably. In a sector where trust is the core product, the use of opaque systems without strong oversight could create as much risk as it removes.
The broader policy implication is clear: Indian banks are entering a phase in which digital sophistication must be matched by digital discipline. The institutions that thrive will likely be those that can innovate quickly without losing control of their technology stack, vendor ecosystem or automated decision systems. Jain's intervention is a reminder that in modern banking, the biggest vulnerabilities may not sit in loan books or treasury positions, but in code, connectivity and the unseen layers of infrastructure that keep the system running.
