.png)
India’s banking supervision has focused heavily on procedural compliance. The next step should be stronger enforcement of risk governance, capital and controls.


Rahul Ghosh is a banking and risk expert who advises banks, corporates, and central banks, and builds tech solutions for risk management. He authored two books on risk.
September 8, 2026 at 4:08 AM IST
Internationally, a growing number of banks have been fined not for routine compliance failures, but for weaknesses in risk management itself. This marks a relatively new supervisory approach that has gathered momentum over the past decade. The question is what drove this shift, and what it means for Indian banking.
Basel II fundamentally changed the philosophy of banking regulation. It moved the system from a predominantly rule-based capital adequacy regime towards a framework that was risk-sensitive and governance-driven. Instead of simply prescribing capital through standardised rules, it required banks to identify, measure, monitor and manage risks across the enterprise. The 2008 global financial crisis reinforced this approach. Basel III and subsequent supervisory reforms made risk governance, capital planning and board oversight central to prudential regulation.
The consequences have been visible across jurisdictions. Large banks discovered that size offered no immunity. Many globally systemic institutions were among the first to face supervisory action for failing to discharge their risk management responsibilities adequately. Regulators increasingly treated weaknesses in governance and risk controls not as internal management issues, but as matters warranting monetary penalties.
The fines have covered a wide range of risk management weaknesses, with roughly a hundred significant enforcement actions across major jurisdictions. The most frequently penalised areas include risk governance and internal controls, capital planning under ICAAP, credit risk management, model risk, enterprise and operational risk, and asset-liability management, including interest rate risk in the banking book, or IRRBB.
Keeping a bank safe is ultimately the responsibility of its board and management. Supervisors do not run banks. They set minimum standards for governance, controls and risk management. Yet the breadth of global enforcement shows that regulators are increasingly willing to intervene when those standards are not met. Notably, many penalties relate to governance failures rather than isolated operational mistakes.
Meanwhile, Indian regulators have also stepped up enforcement. Over the past five years, nearly a hundred penalties have been imposed on scheduled commercial banks, alongside a smaller number on NBFCs. But the nature of these actions is materially different. Most relate to procedural lapses involving KYC and AML compliance, incorrect categorisation of accounts, reporting deficiencies, payment systems, customer service requirements or changes in board composition without prior regulatory approval.
These are important supervisory issues, but they remain largely compliance-oriented. Penalties explicitly centred on risk governance, capital planning, enterprise risk management, model risk or ALM remain relatively uncommon.
Beyond Compliance
Enforcing risk management standards is preventive rather than merely punitive. It can strengthen institutional resilience, protect depositors, improve capital allocation and reduce the probability of systemic failures. Supervisory penalties, in this sense, can improve risk culture rather than simply punish non-compliance.
Evidence suggests that sustained adherence to strong risk governance can also reduce regulatory friction. Adam Barber's 2021 study, UK Banks and the Lessons of the Great Financial Crisis (Palgrave Macmillan), documents how one large international bank's years of risk-governance reforms substantially reduced supervisory fines. When those practices were later diluted and governance priorities shifted, regulatory penalties and supervisory conflicts re-emerged. The lesson is that stronger risk governance can address the underlying causes of enforcement.
Silicon Valley Bank and Signature Bank offer the opposite lesson. Both collapsed after a relaxation of enhanced prudential standards, particularly around interest rate risk and supervisory scrutiny of mid-sized banks. Their failures showed how quickly weaknesses in risk management can become existential when supervisory vigilance is diluted.
For India, the implication is not that procedural enforcement should diminish. KYC, reporting integrity and customer protection remain indispensable. But the next stage of supervision should focus more closely on the quality of risk governance itself. Accountability should extend to ineffective oversight, weak risk appetite frameworks, deficient credit risk management and capital planning, inadequate stress testing, poor model governance and failures to manage liquidity and interest rate risks.
The need is even greater in the NBFC sector, where institutional failures over the past decade have exposed shortcomings in governance and enterprise risk management despite formal compliance with many regulatory requirements.
India has embraced risk-based regulation through Basel norms and supervisory frameworks. The logical next step is risk-based enforcement with equal conviction. As the financial system grows in size and complexity, supervision cannot stop at whether a bank has complied with the rules. It must also ask whether the bank is managing its risks well enough to withstand the next shock.