New Delhi: Continuing the high-level afternoon deliberations at the FutureCrime Summit 2026, industry leaders, compliance experts, and risk officers gathered for the sixth panel to examine the evolving regulatory matrix facing enterprise technology. Titled “The Cyber Compliance Mandate: Aligning Security Audits with RBI, SEBI and CERT-In Requirements,” the discussion addressed how organizations must reconcile multi-regulator mandates into a unified, continuous compliance architecture.
Enterprise Compliance Dynamics and Panel Direction

Moderated by Kumar Aniket, Legal Expert in Technology Law, the session brought together corporate leaders and legal strategists to decode the friction between statutory compliance obligations and operational security realities across regulated sectors.
The transition from periodic compliance checklists to continuous, automated auditing architectures represents a critical shift in corporate risk management. By navigating overlapping directives from regulatory bodies, enterprises can establish resilient security postures capable of satisfying statutory mandates while maintaining operational continuity.
Strategic Perspectives Across Risk Governance, Audits, and Data Sovereignty
Ajay Kanth, Head of Fraud Risk Management Unit at Aditya Birla Capital, detailed the operational requirements of institutional risk governance, arguing that regulatory alignment must evolve beyond superficial, periodic check-the-box exercises. He explained that aligning corporate fraud prevention with strict RBI and SEBI expectations requires embedding dynamic risk assessments directly into daily business operations and real-time transaction monitoring. By integrating risk controls into core workflows, financial institutions can detect anomalous activities and satisfy regulatory demands without creating administrative friction. 
Bharat Panchal, Chief Risk & Regulatory Officer for APAC and Middle East at Global Payment Network, Discover (CapitalOne), analyzed the complexities of navigating multi-jurisdictional compliance frameworks across global operations. He highlighted the significant operational challenge of harmonizing CERT-In’s rapid six-hour incident reporting timelines with stringent regional banking regulations across different cross-border jurisdictions. Panchal noted that establishing unified reporting protocols allows multinational organizations to maintain operational resilience and avoid severe compliance penalties while meeting disparate regulatory deadlines.
Sanjay Kaushik, CEO of Netrika Consultancy, examined technology governance and supply chain risk management, focusing on the heightened regulatory scrutiny surrounding third-party service providers. He pointed out that enterprise security audits can no longer be limited to internal network perimeters and must extend to rigorous, end-to-end evaluations of external vendor ecosystems. Conducting comprehensive due diligence on third-party service providers ensures that vulnerabilities in the supply chain do not become entry points for cyber intrusions or regulatory non-compliance.

Utsav Mittal, CEO of Xiarch Bharat, focused on technical security architectures, emphasizing the vital role of standardized security testing in meeting statutory frameworks. He asserted that conducting thorough Vulnerability Assessment and Penetration Testing (VAPT) through CERT-In empanelled auditors is essential for regulated entities. Utilizing certified empanelled auditors ensures that organizations meet the rigorous technical standards outlined in SEBI’s Cyber Security and Cyber Resilience Framework (CSCRF) and corresponding RBI cybersecurity guidelines.
Vinit Goenka, Secretary at the Centre for Knowledge Sovereignty, framed statutory compliance as a core imperative of national economic security and data sovereignty. He argued that adhering to regulatory directives from bodies like the RBI, SEBI, and CERT-In is not merely an administrative obligation, but a foundational pillar in protecting critical national data assets. Ensuring strict compliance across enterprise systems fosters long-term public trust in India’s expanding digital economy while safeguarding sovereign data perimeters against foreign threat vectors.
