India’s central bank warns banks to tighten controls as AI transforms banking landscape

The Reserve Bank of India underscores the need for stronger governance and risk management as banks accelerate AI adoption amid rising cybersecurity threats and complex dependencies.

India’s banks are entering the artificial intelligence era with a sharper warning from the country’s central bank: adoption must not outrun control. At a banking conclave in Mumbai, Reserve Bank of India Deputy Governor Rohit Jain said financial firms need stronger governance, better visibility into their systems and more rigorous testing of resilience as they add AI to their operations. He argued that technology is no longer just a support function in banking but part of the risk structure itself.

Jain set out a ten-point framework that begins with a simple test: whether governance actually produces results. According to his remarks, banks should map their technology environments more clearly, deal with vulnerabilities and legacy systems, tighten identity and access management, and make sure security controls work as intended. He also called for risk controls to keep pace with technological change, more scrutiny of third-party dependencies, better post-incident review, regular recovery testing and attention to underlying architecture and capacity limits.

His comments reflect the growing complexity of bank operations as institutions lean on cloud services, application programming interfaces, fintech partners and AI models alongside core banking systems. Jain warned that those links can create risks that extend beyond any single institution. While technology can be outsourced, he said, accountability cannot. Banks, he added, must understand concentration risk, recoverability, data protection and exit options when they rely on outside providers.

The deputy governor also drew a direct line between AI’s promise and its dangers. He said the technology can improve customer service, fraud detection, risk assessment and productivity, but can also magnify errors if it is not carefully validated and monitored. Because AI outputs can affect lending decisions, fraud alerts, customer access, pricing and service delivery, Jain said human oversight and clear responsibility remain essential. He also warned that attackers are using AI to scale phishing, impersonation and other cyberthreats, even as banks deploy the same tools for threat detection and automated incident response.

Jain’s remarks build on a broader regulatory push in India. In June, the RBI proposed a framework for managing AI and machine-learning risks in banking, including board-approved model risk management policies covering AI models used by regulated entities. That follows earlier RBI findings showing that many banks have allocated less than 10% of their IT budgets to emerging technologies, even as they increasingly rely on outsourced cloud and AI services for customer support, sales, risk management and verification. SBI Chairperson C.S. Setty has separately warned that more advanced AI can produce faster-moving fraud and deeper model-risk problems, underscoring the RBI’s message that banks must strengthen oversight before they scale the technology.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.