Master AI before it scales: RBI’s 10 commandments for tech risk | Today’s news

As India’s financial landscape accelerates into the era of artificial intelligence (AI), Reserve Bank of India (RBI) Deputy Governor Rohit Jain on Thursday laid out 10 key requirements for banks to manage technology and cyber risks.

Speaking at the State Bank of India Banking and Economics Conclave in Mumbai, Jain called for stronger governance, greater visibility of technology infrastructure, tighter controls and regular operational resilience testing as financial institutions increasingly embrace AI.

He also said that technology can no longer be seen as just an enabler of banking, but is becoming part of a bank’s risk architecture.

Read also | RBI cuts, CAS hits own trading volumes

10 point framework

His 10-point framework includes ensuring that technology governance translates into results, maintaining visibility across complex technology environments, addressing vulnerabilities and legacy systems, strengthening identity and access controls, and ensuring that security controls actually work as intended.

He also urged banks to keep risk controls in line with the pace of technological change, manage third-party and external dependencies, strengthen post-incident analysis, regularly test recovery and operational resilience, and address core architecture and capacity constraints.

“Ultimately, an important test of governance is how effectively the framework translates into outcomes,” Jain said, emphasizing that vulnerability identification alone is not enough and that material exposures need to be addressed based on their severity and potential impact.

Jain’s comments come at a time when banks are increasingly relying on cloud infrastructure, application programming interfaces (APIs), fintech providers and AI models alongside traditional banking systems.

Read also | Tata Sons’ debt-free status cannot avert listing, RBI clarifies

He warned that such interconnectedness can create risks that transcend individual institutions.

“Technology can be outsourced, but responsibility cannot,” he said, adding that banks need to understand the risks of external dependencies, including access control, concentration, recoverability, data protection and termination options.

Specifically on artificial intelligence, Jain said the technology could improve customer service, fraud detection, risk assessment and productivity, but it could also amplify errors. AI-driven outputs can impact credit decisions, fraud alerts, customer access, pricing and service delivery, which is why verification, monitoring, human oversight and clear accountability are essential, he says.

“AI is expected to fundamentally change financial services, but governance must precede scale,” Jain said.

Read also | RBI moves to boost ECB inflows to $75-80bn in FY27: Citi bank chief

He also warned that attackers are increasingly using artificial intelligence to scale phishing, impersonation and other cyber attacks, while banks can deploy the same technology for threat detection, behavioral analysis and automated incident response.

He said boards and senior management must ultimately own technology governance with clear responsibilities for business risk, compliance, operations and technology functions.

“In the era of artificial intelligence, governance must ensure the discipline to embrace innovation with confidence while ensuring that the resilience and credibility of the financial system remain paramount,” he said.

Similar Posts