RBI’s Technology Maker-Checker Conundrum

Beyond the remediated BANK.IN security episode lies a larger governance challenge as AI rewrites the economics of institutional assurance.

Article related image
Author
Srinath Sridharan

Dr. Srinath Sridharan is a Corporate Advisor & Independent Director on Corporate Boards. He is the author of ‘Family and Dhanda’.

Author
Anand Venkatanarayanan

Anand Venkatanarayanan is a strategic security and digital policy researcher.

July 20, 2026 at 5:12 AM IST

The BANK.IN initiative was conceived as a trust architecture for India’s digital banking ecosystem. Ironically, the governance questions raised by its implementation may prove more consequential than the technical vulnerability that brought them to light.

India’s banking regulator has spent over a decade building one of the world’s most sophisticated digital financial ecosystems. As artificial intelligence dramatically lowers the cost of discovering vulnerabilities, assurance mechanisms designed for an earlier technological era must evolve just as rapidly. 

Mastering digital technology has historically been one of the more difficult challenges for India’s banking ecosystem. Many regulated entities underinvested in cybersecurity, not out of indifference but because specialist capabilities were scarce and expensive. 

Internal Capability
Recognising that technological resilience would become integral to financial stability, the Reserve Bank of India invested in building dedicated internal capability through ReBIT, its specialised technology arm, which supports the RBI’s supervisory functions by strengthening information security oversight across regulated entities.

The regulator’s role has itself evolved considerably. What began as a conventional oversight model has progressively expanded into one where the RBI has also become a provider of critical financial infrastructure. It now operates both the NEFT and RTGS settlement systems that underpin inter-bank settlements, illustrating how the central bank has moved beyond regulation to become an active steward of the infrastructure on which India’s financial system increasingly depends.

NPCI represents another dimension of this institutional evolution. Established as a not-for-profit entity owned by banks, it not only provides payment services such as IMPS but also owns and operates nationally significant payment infrastructure, including UPI.

While the RBI continues to exercise regulatory oversight through its powers to supervise, issue directions and impose penalties, NPCI has also assumed operational responsibilities that resemble those of a quasi-regulator, including the approval of Third-Party Application Providers and the implementation of market-cap decisions within the payments ecosystem.

The same pattern is evident elsewhere within the RBI ecosystem. IFTAAS operates the Secure Financial Messaging System, which forms the backbone of communication between intra-bank and inter-bank applications. It also provides a community cloud for regulated financial institutions that often lack the scale to influence commercial cloud providers on pricing, technology architecture or the sovereign risks arising from increasing geopolitical dependence on global digital infrastructure.

IDRBT, originally established to undertake research and development in financial technology, has similarly evolved beyond its founding mandate. In addition to providing cyber-threat intelligence through services such as IBCART and functioning as a Certification Authority for financial institutions and servers, it serves as the registrar for the BANK.IN and FIN.IN domains. These trusted domains were introduced to encourage regulated financial institutions to migrate to a more secure digital identity framework as part of a broader effort to reduce cyber fraud across the banking system.

RBIHL represents yet another extension of this expanding institutional architecture through platforms dedicated to mule-account detection, the Unified Lending Interface for digital credit delivery and fraud-risk scoring. Viewed collectively, these institutions demonstrate how the RBI ecosystem has evolved into an interconnected network where regulation, technology development, infrastructure creation and operational enablement increasingly coexist.

Viewed holistically, India’s banking regulatory architecture today has three defining characteristics. First, there is a single regulator, the RBI. Second, it is supported by specialised subsidiaries and related organisations that provide critical technology capabilities and infrastructure across different segments of the financial ecosystem. Third, several of these institutions also perform operational responsibilities that increasingly resemble those of quasi-regulators.

Maker-Checker
Every successful institutional model eventually creates its own governance challenges.

The most significant of these is the maker-checker principle. The regulator is no longer confined to performing a supervisory role. Through its wider ecosystem, it is also involved in building infrastructure, operating platforms, developing technology capabilities and encouraging regulated entities to adopt them. Convergence of these, within a closely connected institutional ecosystem, inevitably creates a maker-checker challenge.

Sound governance has long recognised that institutions responsible for designing and operating critical systems should also be independently assessed for assurance if cyber-risk management is to remain credible.

The findings of independent security researchers into the security concerns of the BANK.IN registry illustrates why this principle matters. The researchers reported that the registry’s API had been left unauthenticated, exposing usernames, mobile numbers, email addresses, IP addresses and encrypted passwords.

More significantly, privileged super-administrator credentials were found not only for IDRBT, the registry manager, but also for the technology vendor responsible for developing the platform.

The issue was therefore not merely a software vulnerability. It raised broader questions about implementation, privileged access governance and institutional assurance over systems intended to strengthen trust.

The subsequent sequence of events raises equally important governance questions. The vulnerability was responsibly reported to CERT-In, remediated and subsequently confirmed by the researchers. 

Yet there was no substantive public explanation from either IDRBT or the regulator regarding the incident or the institutional lessons drawn from it. Following remediation, a considered public disclosure would have further strengthened confidence in the integrity of the regulatory ecosystem. 

Assurance vs Disclosure
Institutions entrusted with stewardship of critical public financial infrastructure carry a heightened obligation to demonstrate the standards of transparency and accountability they expect from the entities under their supervision.

Perhaps the more important question, however, concerns assurance rather than disclosure. It is well recognised within the financial sector that ReBIT possesses the technical capability to undertake sophisticated application security assessments. If that capability already exists within the broader regulatory ecosystem, why was it not deployed before independent researchers uncovered the weakness? 

One may reasonably argue that ReBIT should not serve as the external auditor of another institution within the same ecosystem because that itself could create a maker-checker conflict. That argument deserves consideration. It does not, however, diminish the case for rigorous internal assessment using capabilities that already exist. 

Artificial intelligence is steadily reducing the cost of discovering vulnerabilities while simultaneously increasing the sophistication of those capable of exploiting them. That fundamentally changes the economics of institutional assurance. Systems considered adequately tested only a few years ago now require far more frequent, independent and adversarial scrutiny. 

The governance question is therefore no longer whether India’s banking regulator should build technology. It unquestionably must. The question is whether assurance over that technology should continue to rely primarily on institutional proximity or increasingly incorporate independent verification commensurate with the systemic importance of the infrastructure involved. 

In the age of AI, the maker-checker principle can no longer remain merely an operational control within financial institutions. It must become a governance principle for the institutions that design, operate and supervise the nation’s critical financial infrastructure. Trust ultimately depends not only on who builds the system, but also on who independently checks the maker.

Governance is strengthened when institutions ask difficult questions of themselves before others ask those questions on their behalf.

The authors’ forthcoming book, ‘Power of UncertAInty: The Last Battle for Sovereignty, Privacy and Identity’, examines the challenge of building resilient Indian digital sovereignty in the age of artificial intelligence.