Tech Is Now Risk
Reserve Bank of India Deputy Governor Rohit Jain has drawn a sharp line through the banking sector's digital transformation, warning that the industry's biggest vulnerabilities may now be embedded in the very systems that power modern finance. Speaking on the changing nature of banking risk, Jain said technology is no longer merely an enabler for banks but is increasingly becoming their "risk architecture," a formulation that reflects how deeply digital infrastructure now shapes operational stability, customer trust and regulatory exposure.
His remarks arrive at a moment when Indian banks are expanding their digital footprints at speed, from mobile-first customer acquisition and cloud-based operations to AI-assisted decision-making and extensive reliance on external technology vendors. That shift has delivered scale and efficiency, but it has also widened the attack surface. A failure in software, a breach in a vendor network, or an error in an automated model can now ripple across payments, lending, compliance and customer service with little warning.
Jain's message was not that technology should be slowed, but that it must be governed with the same seriousness traditionally reserved for capital, liquidity and credit risk. In effect, he argued that technological resilience is now inseparable from financial resilience. For banks, this means resilience planning can no longer stop at disaster recovery drills or periodic audits. It must extend to architecture design, data governance, access controls, incident response, model validation and continuous oversight of outsourced technology dependencies.
Governance Must Tighten
The deputy governor's emphasis on governance reflects a broader regulatory concern: as banks digitise, accountability can become diffuse. Decision-making is often spread across business teams, IT departments, risk functions, compliance units and external service providers. That fragmentation can create blind spots, especially when institutions assume that a system is secure because it is widely used or commercially mature.
Jain urged banks to treat technology risk as a first-order enterprise risk, not a technical issue to be delegated downward. That framing matters because it places responsibility squarely on boards and senior management. It implies that directors should understand not only the bank's financial exposures but also the resilience of its core systems, the concentration of its technology vendors, the quality of its cyber defences and the robustness of its AI controls.
For Indian lenders, this is particularly relevant as the sector becomes more dependent on third-party platforms for cloud hosting, payment processing, analytics, customer onboarding and fraud detection. Such partnerships can improve speed and reduce costs, but they also create concentration risk. A disruption at a critical vendor can quickly become a banking-sector event, especially when multiple institutions rely on the same infrastructure.
Jain's comments also point to the need for stronger third-party oversight. Banks are increasingly only as secure as the weakest link in their vendor chain, and regulators globally have been pressing institutions to map those dependencies more carefully. The challenge is not simply contractual. It is operational: banks must know where data resides, how it is protected, who can access it, and how quickly services can be restored if a provider fails.
AI Needs Guardrails
The deputy governor also flagged artificial intelligence as an area requiring disciplined controls. That is a timely warning. Banks are adopting AI for fraud detection, customer service, underwriting support and internal surveillance, but the technology introduces new forms of model risk, bias, opacity and over-reliance on automated outputs. If left unchecked, AI can amplify errors at scale or produce decisions that are difficult to explain to customers and supervisors.
Jain's intervention suggests that the RBI is watching this evolution closely and expects banks to build guardrails before AI becomes deeply embedded in core processes. Those guardrails are likely to include model governance, testing for drift and bias, human review for high-impact decisions, and clear escalation paths when systems behave unexpectedly. In a sector where trust is paramount, the cost of a poorly controlled algorithm can be reputational as well as financial.
The broader significance of Jain's remarks is that they recast digital transformation as a balance-sheet issue in disguise. Banks that invest aggressively in technology without matching that investment with governance, cyber resilience and vendor discipline may find that their most serious risks are no longer visible in traditional financial ratios. They may instead be hidden in code, connectivity and automation.
For India's banking system, the warning is both practical and strategic. The next major disruption may not come from a credit shock or a liquidity squeeze, but from a failure inside the technology stack that supports the entire institution. Jain's message was clear: banks that want to remain resilient must now secure the digital foundations on which their business increasingly depends.
