Reserve Bank of India Deputy Governor M. Rajeshwar Rao Jain said Thursday that financial institutions must establish governance frameworks for artificial intelligence before scaling the technology across operations. The warning comes as banks embed AI deeper into functions ranging from customer onboarding to fraud detection, raising the stakes for operational resilience and public trust.
"AI is expected to fundamentally change financial services - but governance must precede scale," Jain said at the SBI Banking & Economics Conclave in Mumbai. He framed technology investment as a risk investment - one that underwrites continuity, confidence, and financial stability.
Technology risk is no longer an IT problem
Jain argued that financial resilience and technological resilience can no longer be viewed in isolation. "If a critical technology system is unavailable, if a cyber incident compromises operations or if a key technology dependency fails, the customer may be unable to access an essential financial service," he said. The implication is direct: a bank's balance sheet strength means little if customers cannot reach their money.
He said technology risk is embedded across core banking functions, requiring institutions to think about cybersecurity in broader terms. "The response must therefore evolve from identifying only suspicious transactions to identifying suspicious patterns." That shift demands real-time transaction monitoring, behavioral analytics, device and identity intelligence, domain and network analysis, and information sharing across stakeholders.
Vulnerability management, timely patching, data protection, and incident response are now essential components of financial resilience, Jain added. Data breaches, he warned, create risks of identity theft, fraud, and loss of public trust - consequences that extend well beyond a single institution's walls.
AI as both weapon and shield
Jain acknowledged the dual-use nature of AI in cybersecurity. The technology "can both be an instrument of attack and a powerful tool of defense," he said, calling for AI-powered cybersecurity deployed in a coordinated and responsible manner. The message reflects growing concern among global regulators that the same tools banks use to detect fraud can be weaponized against them.
For financial institutions building internal AI capabilities, the governance challenge spans procurement, deployment, and ongoing monitoring. Courses like AI IT Strategy Training address the intersection of technology architecture and risk management that Jain described. Similarly, compliance teams navigating evolving regulatory expectations may find structured guidance through AI Regulatory Compliance Courses.
Liquidity deployment and forex reserve management
On the sidelines of the event, Jain told reporters he expects liquidity from FCNR(B) deposits to be deployed over the coming months as credit demand rises during India's festive season. "We are entering the festive season and there is a lot of credit demand. Therefore, I think the banks will be able to deploy this liquidity over the next few months," he said, noting that the RBI had met with banks to discuss their positions.
Each bank will decide credit deployment based on its pipeline, pending proposals, and liquidity outlook. "Their asset liability position will determine how they deploy that liquidity; it's basically the bank's call," Jain said.
India's foreign exchange reserves stood at $780.78 billion as of September 11, driven in part by these foreign deposits. Jain said the reserves would be managed with safety taking precedence over returns. "Safety, liquidity, and return. All three are important, but the order is also important. Because these are borrowed funds, these forex reserves have to be handled very carefully." He cited oversight frameworks, governance arrangements, and both internal and external asset managers as the mechanisms for managing the reserves.
Why this matters for finance professionals
Jain's remarks signal that Indian regulators view AI governance as a prerequisite, not an afterthought. For risk officers, compliance heads, and technology leaders, the practical takeaway is that AI deployment timelines must now account for governance infrastructure - vulnerability management, pattern-based threat detection, and cross-stakeholder information sharing - before systems go live. Banks that treat technology investment primarily as a growth lever, without the corresponding risk controls, will find themselves misaligned with the regulator's expectations.
Your membership also unlocks: