The Reserve Bank of India is tightening the technology controls surrounding banks as artificial intelligence, cloud services and outside technology vendors become more deeply embedded in everyday financial services.
New cybersecurity directions issued by the RBI on July 31 require commercial banks and other regulated financial institutions to strengthen protection of customer information, maintain detailed technology inventories and continuously assess risks created by third-party service providers. The directions took effect immediately.
The measures come as banks increasingly use AI for fraud detection, customer service, document processing, credit assessment and other functions.
But the more customer data that passes through algorithms, cloud servers and outside companies, the greater the potential damage if one of those systems is compromised.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Banks Cannot Outsource Responsibility Along With Technology
One of the clearest principles in the new RBI framework is that banks remain responsible for customer data even when another company handles it.
Banks must protect sensitive business and customer information whether it is stored internally, transmitted across networks or processed at facilities managed by external vendors.
They must also create systems to prevent data leakage and ensure similar safeguards exist at vendor-operated facilities.
Third-party technology providers are also subject to much closer scrutiny.
Banks are expected to conduct vendor risk assessments, examine concentration risk and identify situations where excessive dependence on a single provider could become a point of failure.
They must regularly review service providers and ensure contracts permit audits by the bank and inspection by the RBI.
That becomes particularly important with AI.
A bank may buy an AI fraud-detection system or customer-service model from an outside technology company. But if that model leaks customer information or produces damaging errors, the bank cannot simply argue that the software belonged to someone else.
What Are Data Minimisation and Model Risk?
Two concepts are becoming increasingly important as banks use AI.
Data minimisation means collecting only the information genuinely required for a specific purpose.
For example, a banking application processing a loan may need income and credit information. It should not automatically collect unrelated photographs, contacts or other phone data merely because the technology makes doing so possible.
The RBI’s FREE-AI committee warned in 2025 that AI systems can collect more information than necessary and said this conflicts with the principles of data minimisation and purpose limitation.
Model risk refers to the possibility that an algorithm itself produces unreliable or harmful results.
Imagine several banks buying the same AI system to detect fraud.
If the model contains the same hidden flaw everywhere, it could incorrectly block genuine transactions across several institutions at once.
The RBI has highlighted precisely this kind of systemic danger. Its broader financial-stability work identifies third-party dependence, concentration, cyber risk and defective models or data among the vulnerabilities created by widespread AI adoption.
Its 2026 draft guidance on model-risk management also covers third-party models and systems using AI or machine learning, calling for governance, validation, continuous monitoring and contingency planning.
Payment Data Has Already Had to Stay in India for Years
Another point needs clarification.
The requirement to keep domestic payment data in India is not a new 2026 rule.
RBI first issued its payment-data localisation direction in April 2018.
It requires authorised payment system operators to ensure that the entire data relating to domestic payment systems is stored in systems located only in India. Banks are covered where they participate in such payment systems.
The information includes transaction details, customer data, account information, payment credentials and other data forming part of the payment instruction.
Transactions may in some cases be processed abroad, but RBI says the resulting domestic payment data must be brought back and stored only in India, with overseas copies deleted within the prescribed period. Special provisions apply to the foreign component of cross-border transactions.
So describing the requirement as saying data must “primarily” be kept in India understates the existing rule for domestic payment-system data.
The RBI requirement is considerably stricter: applicable payment data must be stored only in India, subject to its stated cross-border exceptions.
AI Adoption Is Moving Faster Than Bank Governance
The timing of the tighter technology framework is significant.
A 2026 survey of executives at 18 Indian banks and NBFCs found that 70% said AI was already being used either selectively or at scale in live operations. Customer service, fraud detection, risk analysis and document processing were among the leading applications.
But widespread use creates another risk: concentration.
If several banks rely on the same cloud company, AI model or specialised vendor, a failure at one provider could affect many institutions simultaneously.
The RBI’s latest cybersecurity directions therefore require institutions to specifically assess concentration and single-point-of-failure risks in vendor relationships.
India’s banking regulator has been moving in this direction for several years.
Its earlier work on digital lending already stressed purpose limitation, data minimisation and restrictions on unnecessary customer-data collection. It also said regulated institutions should remain responsible for third-party digital platforms handling borrower information.
AI now makes those principles harder to enforce because models often depend on enormous datasets and outside infrastructure.
For banks, the question is therefore no longer simply whether AI improves efficiency.
They will increasingly have to prove that they know what data an AI system uses, where that data travels, who can access it, which vendor controls the model and what happens if that model fails.
What this means for you:
Your bank remains responsible for protecting your information even when it uses outside cloud or AI providers. Customers should also question banking apps that request unrelated phone permissions or collect information that does not appear necessary for the service being offered.