Small lenders face uncontained tech risks, Swaminathan warns
RBI Speech

Small lenders face uncontained tech risks, Swaminathan warns

Urban co-operative banks must overhaul technical oversight and pool resources to manage digital threats originating outside their operations, Reserve Bank of India Deputy Governor Swaminathan J said at the Mission SAKSHAM event in Hyderabad on August 7, 2026.

When the bank sits outside the bank

Swaminathan warned that third-party reliance for core banking software and payment applications exposes small lenders to institutional vulnerabilities.

“A cyber attacker does not distinguish between a large bank and a small bank,” Swaminathan told directors and chief executives, noting that digital frauds move across accounts in minutes.

While India's four-tier regulatory framework accommodates balance sheet sizes across more than 1,400 urban co-operative banks, technical risks are not bound by geography.

The Reserve Bank of India launched Mission SAKSHAM on April 28, 2026, aiming to train 140,000 participants across five distinct functional tiers, ranging from board members to IT technicians.

Shared rails for 1,400 lenders

To overcome individual scale constraints, the central bank is directing lenders toward collective infrastructure managed by the National Urban Co-operative Finance and Development Corporation.

In Telangana, all 48 local institutions have enrolled in the training scheme, with over 100 directors attending the Hyderabad session to bring state coverage past one-third.

Swaminathan emphasized that while day-to-day IT systems can be outsourced, ultimate board responsibility for risk management and operational continuity cannot.

Training cannot substitute for enforceability

Mission SAKSHAM addresses the chronic governance deficit across India's fragmented co-operative banking sector.

Yet structured training cannot replace enforceable technical standards when outsourced vendors fail.

Without stricter board liability, shared platforms risk becoming cosmetic safeguards rather than true risk mitigators.

Report an error