RBI Deputy Governor Rohit Jain has warned that the most consequential risks facing banks may no longer sit on balance sheets or in loan books, but inside the technology systems that now power modern finance. Speaking in a sharp assessment of the sector's changing risk profile, Jain said technology is no longer merely an enabler for banks; it is becoming their "risk architecture," a shift that demands a fundamental rethink of supervision, governance and internal controls.
The message lands at a time when Indian banks are accelerating digital transformation, expanding cloud adoption, deepening API-led partnerships and deploying artificial intelligence across customer service, underwriting and fraud detection. Those advances have improved speed and scale, but they have also widened the surface area for operational disruption, cyber intrusion, vendor failure and model risk. Jain's remarks suggest the Reserve Bank of India wants banks to stop viewing these hazards as technical issues and start treating them as enterprise-level threats with direct implications for stability.
Tech As Core Risk
Jain's central argument is that technological resilience must now be considered as important as financial resilience. In practical terms, that means a bank's ability to absorb shocks is no longer determined only by capital buffers, liquidity coverage or asset quality. It also depends on whether its core systems can withstand outages, whether its data pipelines are secure, whether its vendors are reliable and whether its digital decision-making tools behave as intended under stress.
That framing is especially significant for India's banking sector, which has become one of the world's most digitally active. UPI volumes, mobile banking usage and instant credit products have all increased the industry's dependence on uninterrupted technology. A failure in one layer of the stack can now cascade quickly across payments, customer access, compliance monitoring and fraud controls. Jain's warning reflects a broader regulatory recognition that operational resilience is no longer a support function; it is a prerequisite for trust.
Governance Must Tighten
Jain urged banks to treat technology risk as a first-order enterprise risk rather than a specialist IT concern. That implies board-level oversight, clearer accountability and more rigorous challenge from senior management. Banks, he indicated, should not assume that outsourcing or automation transfers responsibility. Instead, they must maintain visibility into how systems are built, tested, monitored and recovered.
The emphasis on governance also points to a growing regulatory concern around third-party dependence. As banks rely more heavily on cloud providers, software vendors, fintech partners and outsourced service firms, their resilience becomes intertwined with external entities that may not be under direct control. A failure at a vendor can become a bank's failure in minutes. Jain's remarks suggest that oversight of these relationships must become more systematic, with stronger due diligence, contractual safeguards and ongoing monitoring.
Cybersecurity remains another central pillar. The scale of digital banking has made Indian lenders attractive targets for phishing, ransomware, credential theft and other attacks that can compromise both funds and confidence. Jain's comments indicate that the RBI expects banks to move beyond compliance checklists and build adaptive defenses that can detect, isolate and recover from incidents quickly.
AI Needs Guardrails
Jain also highlighted the need for controls around artificial intelligence, a signal that regulators are increasingly focused on the risks of automated decision-making. AI can improve fraud detection, customer support and credit assessment, but it can also introduce opacity, bias, data leakage and model drift. If banks deploy AI without robust governance, they risk embedding errors at scale and creating new forms of systemic vulnerability.
The RBI's stance appears to be that innovation cannot come at the expense of control. Banks will likely be expected to document model behavior, test outputs, monitor performance and ensure human accountability remains intact. That is particularly important in lending and compliance, where flawed automation can affect customers, regulatory reporting and reputational standing.
Jain's remarks are a reminder that the banking industry's digital future will be judged not only by speed and convenience, but by durability. As finance becomes more software-defined, the institutions best positioned to win trust will be those that can prove their systems are secure, recoverable and governed with the same seriousness as capital and liquidity. In that sense, the RBI's message is clear: the next banking crisis may not begin with a credit event, but with a technology failure.
