Direct Tax
Consulting
ESG Advisory
Indirect Tax
Growth Advisory
Internal Audit
BFSI Audit
Industry Audit
Valuation
RBI Services
SEBI Services
IRDA Registration
AML Advisory
IBC Services
Recovery of Shares
NBFC Compliance
IRDA Compliance
Finance & Accounts
Payroll Compliance Services
HR Outsourcing
LPO
Fractional CFO
General Legal
Corporate Law
Debt Recovery
Select Your Location
AI is becoming an important part of banking, payments, securities markets, and financial services in 2026. Many organizations are using AI for customer service, fraud detection, risk assessment, and other tasks. This is creating new cybersecurity risks.
Using AI, cybercriminals can now launch more sophisticated attacks. It confuses identity verification using deepfake voice and video. Automated phishing can be done faster and target specific individuals. AI can find vulnerabilities in software very quickly.
RBI and SEBI are tightening cybersecurity and data privacy rules. RBI’s AI and model-risk controls, six-hour cyber incident reporting, SEBI’s IT Resilience Index (ITRI), FIRE reporting, and kill-switch mechanisms are now becoming important parts of financial cybersecurity.
The previous cybersecurity system relied on finding specific vulnerabilities and fixing them. But due to AI, cyberattacks are now happening much faster. An attack can target many systems or users in a short period of time. So, just doing occasional security testing is no longer enough.
Key AI-related threats
So, financial institutions have to move towards continuous monitoring, regular testing, and rapid risk detection.
RBI is no longer seeing cybersecurity as just an IT department issue. Senior management and the board are also responsible for AI and technology-related risks. The goal is to identify any major technology risks before they arise.
Financial institutions should have a clear governance structure for cybersecurity and AI risks. The board and senior management need to review these issues regularly.
The key issues are:
In this, cybersecurity is becoming part of business risk rather than just a technical issue.
RBI’s model risk approach emphasizes more structured control over AI and machine learning models. It is important for institutions to know where and how each important model is being used.
So, an AI model should not be forgotten after deployment. Regular review and monitoring are required.
RBI’s draft approach also includes the idea of quickly restricting or shutting down high-risk or compromised AI models.
In addition to AI risk, RBI is also emphasizing rapid response in the case of cyber incidents and digital fraud. So, financial institutions have to put measures in place not only for prevention but also to take quick action after the incident occurs.
Six-Hour Cyber Incident Reporting
Applicable regulated entities are required to report significant cyber incidents to the RBI within six hours of detection.
This requires institutions to have:
Revised Fraud Compensation
The revised fraud compensation measures of June 2026 have enhanced customer protection in the case of new types of digital fraud. So, real-time fraud detection and rapid customer response have become more important.
Customer Transaction Kill Switch
RBI is also working on a customer-facing transaction kill switch. Customers will be able to quickly stop financial transactions if fraud is suspected.
This is different from the AI kill switch. An AI kill switch controls a risky or compromised AI system, while a transaction kill switch is used to stop a customer’s financial transactions.
SEBI is focusing on cyber resilience to make the securities market safer from cyber threats. Under this, the focus is on strengthening the IT systems and cybersecurity controls of Market Infrastructure Institutions (MIIs), brokers, and other regulated entities. This aims to prevent cyberattacks and detect them quickly and restore the system to normal.
SEBI IT Resilience Index (ITRI)
SEBI has launched the IT Resilience Index (ITRI) to measure the IT resilience of market infrastructure institutions. This index measures the cyber and IT readiness of an institution through various important parameters.
MIIs will have to calculate ITRI twice a year. A comparative analysis will have to be submitted within 60 days of the end of each year. If any weakness is found, corrective action will also have to be reported.
An early-warning mechanism has been put in place with ITRI. Cyber risk can be monitored regularly through this. The framework is expected to be effective from early 2027.
AI-Focused Cybersecurity Measures
SEBI is also emphasizing:
SEBI is looking at cybersecurity not just as a preventive measure but as part of continuous resilience.
FIRE Incident Reporting
SEBI is using FIRE, or Format for Incident Reporting Exchange to standardize cyber incident reporting. So, in a cyber incident, the institution will not have to wait for all the information to be ready at once.
An initial report can be made first with the available information. Additional or intermediate updates can be given as the investigation progresses. Once all the information is clear, the final report will be submitted. This will reduce the reporting delay during the incident, and SEBI will be able to keep a regular eye on the situation.
Upcoming AI and ML Guidelines
SEBI is preparing to bring new guidelines on the responsible use of AI and machine learning in the securities market. This may focus on issues like AI governance, model risk, data quality, explainability, human oversight, and accountability. Clear controls will also be created for the use of AI in financial-market activities.
Both RBI and SEBI are strengthening the cybersecurity of the financial sector. However, their focus is slightly different. RBI is mainly working on the risks of banks, NBFCs, payment systems, and other financial entities. On the other hand, SEBI is giving more importance to the resilience of the securities market and its critical infrastructure.
However, there is a common direction in the approaches of the two regulators. Both are moving towards continuous monitoring, measurable resilience, faster response, and stronger accountability. So, cybersecurity for financial institutions is no longer just an IT responsibility; it is a critical part of overall business and regulatory compliance.
RBI and SEBI’s cybersecurity requirements are getting tougher. So instead of waiting for new rules to come out, financial institutions should review their systems and processes now. Compliance, risk, and technology teams should work together to identify AI-related risks.
These tasks need to be reviewed regularly. AI technology and its associated cyber risks are changing very quickly.
AI and cybersecurity regulations are constantly changing. So, financial institutions need to understand which requirements apply and where compliance gaps exist. Enterslice can help businesses understand regulatory requirements and create the necessary compliance framework in this process.
Our Services:
AI is making the financial sector more efficient but creating new cybersecurity risks. RBI is emphasizing AI governance, model-risk management, incident reporting, and customer protection with this change. SEBI is also strengthening the cyber resilience of the securities market through ITRI, FIRE reporting, and responsible AI.
So, it is not enough for financial institutions to use technology. Continuous testing, strong governance, human oversight, vendor controls, and faster incident response are now important parts of cybersecurity strategy. As AI improves, financial cybersecurity also needs to be more proactive.
If your organization has AI or technology-based financial systems, conduct a cybersecurity and regulatory readiness review now. Enterslice can help you identify potential compliance gaps and create the necessary controls for regulatory requirements. So, contact us today for hassle-free compliance.
AI is making cyber threats faster and more sophisticated. Attackers can easily launch large-scale attacks through deepfakes, automated phishing, and AI-based vulnerability discovery. Financial institutions have sensitive customer data, payment systems, and market infrastructure. So, regulators are now emphasizing AI-related risks, continuous monitoring, and stronger risk management in the cybersecurity framework.
RBI is emphasizing board-level accountability in AI risk management. Financial institutions will have to maintain an inventory of AI and other models, classify them according to risk, and independently validate important models. Human oversight is also important. Additional controls are also needed for third-party and generative AI models. Emphasis is also being placed on having a mechanism to restrict or deactivate high-risk or compromised AI systems.
Applicable RBI-regulated entities are required to report a significant cyber incident to RBI within six hours of detection. So, it is essential to have a clear escalation process, report responsibility, and an incident-response plan. Rapid reporting allows the regulator to be aware of the threat in a timely manner and take necessary action. This is important in interconnected financial systems, as a cyber incident can create risks for other institutions as well.
An AI kill switch is a control that can be used to quickly restrict, suspend, or deactivate a high-risk or compromised AI system. A human operator can intervene if a model behaves abnormally. Its purpose is to quickly control significant financial or operational risk created by an AI system. It is different from a customer transaction kill switch, which is used to stop financial transactions in case of suspected fraud.
SEBI’s IT Resilience Index (ITRI) is a framework to measure the IT and cyber resilience of Market Infrastructure Institutions. It considers a total of nine parameters, including availability, security, integrity, governance, monitoring, and business continuity. MIIs are required to calculate ITRI twice a year. They are required to submit a comparative analysis and report on any weaknesses and corrective actions to be taken.
FIRE or Format for Incident Reporting Exchange, is a standardized approach to cyber incident reporting by SEBI. In case of an incident, the institution does not have to wait for all the information. An initial report can be made using the available information. Intermediate updates can be given as the investigation progresses, and final information can be given at the end. This makes reporting faster and more structured, and SEBI can be informed about the progress of the incident regularly.
The FIRE standard further structures cyber incident reporting. During a cyberattack, all technical details may not be available immediately. Through FIRE, a regulated entity can make an initial report with available information and later provide additional updates as per the investigation. This reduces reporting delays. So, SEBI gets regular information about the development of the incident and can take a faster regulatory response if needed.
SEBI is emphasizing the responsible use of AI and machine learning in the securities market. Issues such as governance, model risk, data quality, explainability, and human oversight will be important when using AI-based systems. Market participants need to have proper controls and security measures in their AI systems. SEBI is already using AI to identify suspicious trading patterns and is also increasing its use of AI in regulatory surveillance.
A Security Operations Centre, or SOC, helps an organisation monitor cyber threats. A Market-SOC is important for strengthening market-level monitoring in the securities market. It can help monitor and share cyber threat information from different market participants more effectively. If a new threat is detected in a single organization, it is easier to alert the broader market ecosystem. This enables a faster response to cross-firm cyber risks.
AI is becoming an important part of banking, payments, securities markets, and financial servic...
The RBI has brought a change in the concentration of risk norms for NBFCs involved in infrastru...
The Securities and Exchange Board of India (SEBI) has recently proposed some important changes...
FIU-IND, or Financial Intelligence Unit – India, is an important financial intelligence agenc...
On January 8, 2026, FIU-IND released new AML (Anti-Money Laundering) and CFT (Countering the Fi...
Are you human?: 7 + 4 =
Easy Payment Options Available No Spam. No Sharing. 100% Confidentiality
The offshore derivative instruments or ODI are the investment vehicles that are used by the overseas investors for...
22 May, 2024
The Electronic Book Provider (EBP) is a SEBI-registered recognised stock exchange that provides an electronic platf...
01 Jun, 2024