|
Distinguished guests, leaders of the banking and financial community, representatives from the fintech and technology world, colleagues from the Reserve Bank, ladies, and gentlemen, it is a pleasure to be here at the SBI Banking and Economic Conclave. 2. The theme of this year’s Conclave is most timely. If we were to gauge India’s performance on various parameters, we have increasingly gained share in the global economic order. Our share in global GDP has increased from 6.8% in FY2021 to 8.2% in FY20261 (on purchasing power parity basis), share in global trade has grown from 2.2% in CY2020 to 2.6% in CY2025. Globally2, UPI accounts for 49% of all global real-time payment system transaction volume. In the area of Financial Inclusion, we have been able to leverage our fast payment systems to expand the reach of financial services to all parts of the country and to all sections of the society which are increasingly being recognised the world over. As we move towards the goal of Viksit Bharat, our developmental experience offers instructive insights into how an emerging economy like ours can overcome its economic challenges to climb onto a higher growth trajectory, especially by leveraging on technology. This brings me to the theme of my talk today. 3. Over the last two decades, technology has transformed Indian banking. It has expanded access, reduced transaction costs, enabled round-the-clock services and allowed financial institutions to serve customers at a scale that would have been difficult to achieve through traditional channels alone. But I believe we are now entering a somewhat different phase. The theme of my talk, “From Digital Banking to Resilient Banking– Technology, Cyber Security and AI as Pillars of Trust”, is intended to highlight the fact that technology is no longer simply changing the way banking services are delivered; it is increasingly shaping the very architecture of banking. In my view the following three elements will play a key role in this process:
Allow me to elaborate on these aspects. Technology and the changing economics of banking 4. Technology is no longer solely an enabler of banking. Technology architecture is becoming part of the risk architecture of a bank. This distinction is important. A bank may have adequate capital and liquidity, sound governance and a strong balance sheet. But if a critical technology system is unavailable, if a cyber incident compromises operations, or if a key technology dependency fails, the customer may be unable to access an essential financial service. This means that financial resilience and technological resilience can no longer be viewed in isolation. They increasingly reinforce each other. 5. The transformation has also altered the economics of financial intermediation. Technology has progressively reduced the cost of knowing, deciding, transacting and distributing finance. Data reduces the cost of obtaining information. Digital infrastructure reduces the cost of transactions. Analytics can reduce the cost of decision-making. Digital channels reduce the cost of distribution. Artificial intelligence now has the potential to reduce the cost of processing and interpreting information itself. All of this has important implications for banking. 6. When the cost of acquiring and analysing information falls, it becomes possible to serve customers for whom conventional models may have been uneconomic. When the cost of transactions falls, small-value transactions become viable at scale. When distribution becomes digital, geographical distance becomes less of a constraint. Thus, the technological transformation of banking is not simply about doing the same things faster. It can potentially change who can be served, what can be served, and at what cost. This is one reason why technology has been such an important force behind the expansion of digital financial services in India. 7. The scale of this transformation is readily visible in India’s payment systems. UPI3 alone processed 24.9 billion transactions valued at approximately ₹30.15 lakh crore in August 2026, equivalent to nearly 79 crore transactions every day, underscoring the extent to which digital payments have become embedded in everyday economic activity. Over the past decade, UPI’s transaction volume has increased nearly 13,000-fold, with the platform processing 24,162 crore transactions during FY 2025–264. The broader digital financial infrastructure has expanded in parallel. Platforms such as Account Aggregator and the Unified Lending Interface (ULI) are also reshaping how financial information is accessed and how credit is originated, while digital public infrastructure is supporting financial inclusion, direct benefit transfers and the delivery of financial services at scale. 8. But scale also creates a new responsibility. When a system processes millions or billions of transactions, a technology failure is no longer just an inconvenience for an individual institution. Depending on the nature of the service, extent of its usage, and its interconnectedness, it can have consequences for customers, counterparties and potentially the wider financial system. Indian banking’s experience with technology 9. India’s banking journey with technology has been one of considerable success, marked by a series of institutional innovations that have transformed the way financial services are delivered. The adoption of Core Banking Solutions was a foundational turning point, enabling banks to move beyond branch-centric operations and provide customers with access to their accounts and services across locations. This created the technological foundation for internet banking, mobile banking and the subsequent expansion of digital financial services. 10. The initiatives such as UPI, Aadhar-based e-KYC, Video-based Customer Identification Process, ULI, etc., offer some important lessons. First, technology-led transformation is most effective when supported by interoperable infrastructure and common standards. Second, scale must be accompanied by appropriate governance, security and customer protection. Third, the success of a digital service depends not only on the application that customers interact with, but also on the reliability of the underlying ecosystem of banks, payment systems, technology providers and other critical dependencies. 11. However, the same journey has also provided important lessons from failures and disruptions. In India, the 2018 cyberattack on a cooperative bank, involving the compromise of its ATM switch and the subsequent misuse of the SWIFT network, demonstrated how weaknesses at a payment interface can bypass conventional controls and enable fraud across jurisdictions. The lesson was clear: securing the core banking system alone is not enough. Payment switches, connected channels, authentication mechanisms and transaction-monitoring controls must also be protected as part of an integrated architecture. 12. Instances of outages in mobile banking, internet banking and other transaction channels highlight the importance of capacity planning, legacy-system modernisation, change management, disaster recovery and third-party resilience. For customers, a technology outage is not simply a system issue; it is an inability to access their own money or complete an urgent financial transaction. 13. The 2016 cyberattack on a neighbouring country’s central bank demonstrated how compromise of systems connected to the SWIFT network, combined with weaknesses in credentials, monitoring and transaction verification, could lead to cross-border financial loss. The 2017 Equifax data breach in the United States highlighted a different dimension of technology risk: the exposure of sensitive personal and credit information. Its lesson extended beyond cybersecurity. Financial institutions must recognise that data breaches can create prolonged risks of identity theft, fraud and loss of public trust, making vulnerability management, timely patching, data protection and incident response essential components of financial resilience. 14. The 2024 CrowdStrike outage, although not a cyberattack and not confined to the financial sector, demonstrated how a faulty software update from a major technology provider could cause widespread disruption. For banks, it reinforced the importance of third-party concentration risk, controlled software deployment, testing, fallback arrangements and the ability to maintain critical services when a technology provider experiences a failure. 15. Taken together, these experiences show that technology risk can arise from several sources: cyber compromise, weak internal controls, operational failures, poorly managed change, third-party dependence and irresponsible deployment of technology. They also explain the growing emphasis on IT governance, cybersecurity, outsourcing oversight, business continuity and operational resilience. 16. The objective may not be to eliminate every failure, but to ensure that institutions are able to anticipate risks, prevent avoidable disruptions, detect incidents early, contain their impact and recover critical services while protecting customers. The Evolving Technology and Risk Landscape 17. As technology transforms banking, the risk landscape is evolving just as rapidly. We must therefore recognise technology risk, and more specifically technology architecture risk, as a first-order enterprise risk, comparable in importance to traditional balance-sheet risks. It can no longer be viewed as a back-office or purely technical concern, to be managed exclusively by the IT department. 18. The reason is straightforward. Technology is now embedded in almost every critical banking function, from core banking and payments to customer onboarding, credit assessment, fraud monitoring and regulatory reporting. A failure in the underlying technology architecture can therefore disrupt not just a system, but the delivery itself of essential financial services. 19. A bank’s technology environment today includes core banking platforms, payment applications, APIs, cloud infrastructure, data centres, software and hardware providers, cybersecurity tools, external technology service providers and, increasingly, artificial intelligence models and services. These components are interconnected, and a disruption or compromise at any one point can potentially affect the functioning of the wider ecosystem. 20. This leads to an important principle: Technology may be outsourced, but not the accountability. A bank may rely on an external provider for its infrastructure, software or cybersecurity capabilities. However, it must continue to understand the risks associated with that dependency, including access controls, concentration, recoverability, data protection and exit options. 21. The perimeter of technology risk is therefore no longer necessarily the perimeter of the bank. A vulnerability in a connected fintech, a software provider, a payment interface or a common cloud environment can have implications beyond the institution in which the vulnerability originates. A dependency that appears manageable for one institution may become a concentration risk when several banks and financial entities rely on the same provider. The risk architecture of the financial system must consequently be assessed not only at the level of individual institutions, but also across the interconnected ecosystem. The evolving cybersecurity landscape 22. Cybersecurity, too, can no longer be understood simply as the protection of an institution’s external perimeter. The threat landscape is becoming more complex and increasingly combines technological vulnerabilities with human behaviour. Ransomware can affect the availability of critical systems and disrupt service continuity. Compromised credentials can provide access to sensitive applications. APIs provide significant efficiency and interoperability, but also introduce additional points of exposure. Insider threats can exploit legitimate access, while social engineering can manipulate employees and customers without necessarily requiring a sophisticated technical breach. The emergence of deepfakes, voice cloning and AI-enabled fraud adds a further dimension. Malicious actors can use these technologies to impersonate individuals, generate convincing communications and personalise fraudulent interactions at scale. 23. The attacker is therefore not always attempting to break through the strongest technical defence. In many cases, the objective may be to exploit the weakest identity, process, interface or human decision within a connected ecosystem. This requires us to think about cybersecurity in broader terms. It is not only about protecting networks and systems. It is also about protecting identities, credentials, devices, data, APIs, payment channels, third-party connections and the integrity of decision-making processes. The response must therefore evolve from identifying only suspicious transactions to identifying suspicious patterns. This requires a combination of real-time transaction monitoring, behavioural analytics, device and identity intelligence, domain and network analysis, and information sharing across relevant stakeholders. Artificial intelligence: expanding both opportunity and risk 24. AI adds another layer to this evolving risk landscape. AI can strengthen customer service, improve fraud detection, support risk assessment, enhance productivity and help institutions analyse large volumes of information. At the same time, it can amplify errors as quickly as it amplifies efficiency. This is particularly relevant in financial services, where automated outputs can influence credit decisions, fraud alerts, customer access, pricing and service delivery. The use of AI must, therefore, be accompanied by appropriate validation, monitoring, human oversight and clear accountability. 25. We face an unusual technological contest in which both the defender and the attacker increasingly have access to similar tools. The advantage will not necessarily belong to the institution that deploys the most sophisticated technology. It may belong to the institution that can understand, govern and deploy technology with the greatest degree of discipline and foresight. 26. AI can be both an instrument of attack and a powerful tool of defence: while malicious actors can use it to scale phishing, impersonation, vulnerability exploitation and other cyberattacks, financial institutions can deploy AI for continuous threat detection, behavioural anomaly analysis and automated incident response. The banking ecosystem should, therefore, move towards the coordinated and responsible adoption of AI-enabled cybersecurity capabilities, including centralised threat intelligence and automated detection and response mechanisms, so that emerging threats can be identified and contained at ecosystem speed, rather than addressed only after individual institutions have been targeted. Governance must evolve with technology 27. Managing these risks requires capacity on two fronts. The first is technological capacity: secure architecture, resilient infrastructure, effective monitoring, appropriate redundancy, tested recovery arrangements and the ability to identify and respond to emerging threats. The second is human capacity. Institutions require professionals who understand not only cybersecurity and technology, but also banking operations, risk management, data governance and the implications of interconnected financial systems. Technology risk cannot be managed effectively if responsibility is fragmented between business teams, IT teams, cybersecurity functions and external providers, without a common understanding of critical services and potential consequences. Even as technology becomes more advanced, human judgement remains essential. Employees must be equipped to identify social engineering, challenge unusual requests, handle privileged access responsibly and respond effectively during incidents. Senior management and Boards must also possess sufficient technological understanding to question assumptions, evaluate dependencies and assess whether resilience arrangements have genuinely been tested. Responsibility for technology governance must rest with the Board and senior management, with clear ownership across business risk, compliance, operations and technology functions. Data governance 28. In a digital bank, data is simultaneously an asset, an input, a control mechanism and a source of risk. We often speak of protecting data. We should equally speak of whether the data is accurate, whether its lineage is known, whether access is appropriately controlled, whether it retains integrity, and whether it can be recovered when systems are disrupted. A sophisticated risk model built on poor-quality data does not necessarily enable sophisticated risk management. It creates sophisticated looking errors. This is why data governance has to be viewed not only through the lens of privacy and security, but also through the lens of resilience and decision quality. Reliable data supports risk assessment, fraud detection, cyber defence, regulatory reporting and recovery from disruption. Accuracy, integrity, lineage, availability and recoverability need to be considered as integral elements of technology resilience. Building a World-Class Financial System: Innovating with Confidence, Resilience and Trust 29. A developed Indian economy requires a world-class financial system, and a world-class financial system today can be built only on the foundation of world-class technology. Our objective must therefore be to harness technology not merely for greater efficiency and convenience, but also for resilience, inclusion, security and trust. Ten Key Requirements in the area of Technology and Cyber Risk Management 30. I would now like to highlight ten key requirements in the area of Technology and Cyber Risk Management. i. From Governance arrangements and technology risk frameworks to effective resolution: the important test of governance is ultimately how effectively the framework translates into outcomes. ii. Maintaining visibility across complex technology environments: effective risk management involves adequate visibility of the assets and exposures that need to be managed. iii. Addressing vulnerabilities and legacy technology in a timely manner: the challenge is not only to identify vulnerabilities but also to address material exposures in a timely manner based on their severity and potential impact. iv. Managing identity and access risk: strong authentication, appropriate access privileges and effective monitoring remain fundamental to sound identity and access management. v. Ensuring that security controls deliver the intended outcomes: the emphasis should not solely be on deployment of security controls, but on whether these are operating effectively. vi. Keeping controls aligned with the pace of technology change: risk management and control processes need to evolve in step with the speed at which technology is developed, implemented and scaled. vii. Managing third-party and external dependencies: understanding critical external dependencies, their potential impact and the resilience of associated arrangements is an important part of technology-risk management. viii. Strengthening post-incident analysis and learning: the value of a post incident review ultimately lies in reducing the likelihood and impact of recurrence. ix. Testing recovery and operational resilience: regular and realistic testing is important for validating recovery arrangements and strengthening preparedness. x. Addressing underlying architecture and capacity constraints: addressing such underlying factors is important for sustained improvement in technology-risk management. Conclusion 31. Ultimately, sound technology governance is not about attempting to eliminate every possibility of failure. It is about developing the institutional capacity to identify vulnerabilities early, make informed decisions, limit the impact of disruptions, protect customers and recover critical services. This requires a combination of strong oversight, capable personnel, resilient architecture, effective controls and a culture in which technology risk is recognised as a shared responsibility. In the AI era, governance must provide the discipline that enables innovation to be adopted with confidence, while ensuring that the resilience and trustworthiness of the financial system remain paramount. 32. The road ahead requires ambition tempered with caution. We must innovate quickly, but not blindly; embrace AI and emerging technologies, but with accountability; and pursue interconnectedness, while ensuring that resilience is not compromised. We must compete on innovation, but collaborate on security and resilience. 33. I thank the organisers for the opportunity to share my thoughts and wish the Conclave all success. Thank you. 1 IMF World Economic Outlook, April 2026. 2 Press Information Bureau release dated Dec 8, 2025 3 Source: NPCI (monthly data – Aug 2026) 4 RBI Annual Report (Total UPI transactions processed during 2025-26) |
