Tech as risk core
Reserve Bank of India Deputy Governor Rohit Jain has delivered a pointed warning to the banking sector: the greatest threats to a lender's stability may no longer come only from credit deterioration, liquidity stress or market volatility, but from the technology systems that now power nearly every banking function. In remarks that reflect the regulator's growing concern over digital fragility, Jain said technology is no longer merely an enabler for banks. It is becoming their "risk architecture."
That framing is significant. It suggests a shift in supervisory thinking from viewing technology as an operational support layer to treating it as a core determinant of institutional safety and soundness. For banks that have spent the past decade racing to digitise payments, lending, onboarding, compliance and customer service, the message is clear: the same systems that create scale and efficiency can also amplify failure if they are poorly governed, inadequately tested or over-dependent on external vendors.
Jain's comments come at a time when Indian banks and financial firms are under pressure to expand digital services while defending themselves against a more complex threat landscape. Cyberattacks, cloud outages, software vulnerabilities, third-party failures and misuse of artificial intelligence are no longer hypothetical risks. They are operational realities that can interrupt transactions, expose customer data, damage trust and trigger regulatory scrutiny. In that environment, the RBI's emphasis on technological resilience signals that banks will be expected to demonstrate the same discipline over digital infrastructure that they already apply to capital, liquidity and asset quality.
Governance under scrutiny
The deputy governor's central argument was that technology risk must be treated as a first-order enterprise risk, not as a narrow IT issue delegated to technical teams. That distinction matters because many institutions still manage digital risk in silos, with cybersecurity, vendor management, model governance and business continuity handled separately. Jain's remarks imply that this approach is no longer sufficient.
Banks, he said, need stronger governance structures that place technology risk squarely before senior management and boards. That means directors must understand not only the business benefits of digital transformation, but also the concentration risks created by common software stacks, outsourced infrastructure and automated decision systems. It also means banks must be able to answer basic supervisory questions: Where are critical workloads hosted? Which vendors are mission-critical? How quickly can systems recover from disruption? What controls exist around AI-driven decision-making?
The RBI has increasingly pushed regulated entities to strengthen oversight of third-party dependencies, and Jain's comments reinforce that direction. As banks rely more heavily on cloud providers, fintech partners, software developers and managed service firms, the perimeter of risk extends well beyond the institution itself. A failure at a vendor can quickly become a failure at the bank. That makes due diligence, contractual safeguards, monitoring and exit planning essential rather than optional.
AI and cyber pressure
Jain also highlighted the need for stronger cybersecurity and controls around artificial intelligence, two areas that are rapidly reshaping banking operations. Cybersecurity remains the most immediate and visible threat, with banks facing persistent attempts to breach systems, disrupt services or steal sensitive information. But the rise of AI introduces a different class of risk: opaque models, biased outputs, weak explainability and the possibility that automated tools may be deployed faster than institutions can govern them.
For lenders, the challenge is not simply to adopt new technology, but to do so in a way that preserves trust, accountability and operational continuity. That requires rigorous testing, clear escalation paths, independent validation and a culture that treats resilience as a business imperative rather than a compliance exercise. Jain's remarks indicate that the RBI expects banks to build that culture before a major failure forces the issue.
The broader policy message is unmistakable. In a financial system increasingly shaped by digital rails, the resilience of a bank's technology stack is now inseparable from the resilience of the bank itself. For Indian lenders, the next major shock may not arrive through a loan book or a bond portfolio. It may arrive through a server, a vendor, a code update or an AI model that was not governed tightly enough.
That is why Jain's warning lands with unusual force. It reframes technology from a source of competitive advantage into a source of systemic vulnerability — and it places the burden on banks to prove they can manage both at once.
