Home India Reserve Bank of India Regulation and Supervision – Adapting to the Digital Age - K...
Date: 2026-01-09 Category: Not Applicable State: Union Government Country: India

Regulation and Supervision – Adapting to the Digital Age - Keynote Address by Shri Sanjay Malhotra, Governor, Reserve Bank of India at the Third Annual Global Conference of the College of Supervisors, Mumbai, January 9, 2026

Issued by Reserve Bank of India · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** This is a keynote address by Shri Sanjay Malhotra, Governor, Reserve Bank of India, delivered on January 9, 2026, at the Third Annual Global Conference of the College of Supervisors in Mumbai. The address focuses on five key messages regarding the adaptation of regulation and supervision to the digital age. The messages are around systemic resilience, supervisory action, effective use of data, customer-centricity, and capacity building. **Key Points / Main Content** * **Systemic Resilience as a Collaborative Effort:** * The RBI views regulatory and supervisory roles as collaborative, not adversarial. * Regulation and supervision are consultative processes, with regulated entities self-regulating. * Regulators and the regulated should be partners in resilience, striving for long-term growth, stability, and integrity of the financial system. * **Supervisory Action and Enforcement as Corrective Measures:** * Supervisory action is part of a continuum that begins with training and capacity building, moving through dialogue and guidance. * Enforcement, restrictions, and penalties are measures of last resort. * Enforcement actions aim to correct and signal acceptable standards of conduct. * **Effective Use of Data:** * Efforts are underway to streamline reporting mechanisms and improve data quality, leveraging platforms like CIMS and DAKSH. * The Department of Supervision can use data for analytics and dashboards for off-site surveillance, aiming for more real-time supervision. * The Department of Regulation can use data for evidence-based regulation making. * **Customer-centricity:** * Protecting customers' interests is the cornerstone of a sustainable financial system. * Digitalization and innovations must be aligned with fair outcomes for consumers. * Collaboration is needed to detect mule accounts and suspicious transactions preemptively. * **Capacity Building:** * Improving effectiveness requires the right mix of skills within both the Reserve Bank and financial institutions. * Regulated entities should understand regulatory expectations, follow the spirit of regulation, and develop common understanding. * Supervisors and regulators need to provide timely inputs and clarifications, refining regulations based on feedback. * The College of Supervisors (CoS) can contribute to engagement and capacity building. * **Concluding Remarks:** * Regulation and supervision should remain risk-based, proportionate, and technology-neutral. * Technology must embed compliance. * Accountability should remain human. **Impact Analysis** **Regulated Entities** * **Impact:** Regulated entities are expected to collaborate with the RBI and view supervisors as partners. They must understand regulatory expectations and improve tools to combat digital fraud. * **Action Required:** Improve internal rules and procedures, provide feedback to regulators, and enhance their understanding of regulatory expectations, particularly in new areas of risk. Engage with the College of Supervisors. **Supervisors and Regulators** * **Impact:** Supervisors and regulators must refine regulations, provide timely inputs, and work collaboratively with regulated entities. * **Action Required:** Enhance data analysis capabilities, provide guidance to regulated entities, and refine existing regulations based on feedback from stakeholders. **Customers** * **Impact:** Customers are intended to benefit from customer-centric regulations and improved fraud prevention mechanisms. * **Action Required:** No specific action required directly from customers but continue to be vigilant. **Reserve Bank of India (RBI)** * **Impact:** The RBI needs to continue driving collaboration and improving its supervisory capabilities. * **Action Required:** Foster a collaborative environment, streamline reporting mechanisms, and improve data quality for effective supervision.

Key Entities Referenced

Reserve Bank of India: The central bank of India, responsible for regulation and supervision of the financial system. College of Supervisors (CoS): An institution that contributes to capacity building and provides a platform for collaboration and skill upgradation between the Reserve Bank and regulated entities. Department of Supervision: A department which builds stronger analytics and supervisory dash boards for enhanced off-site surveillance. Department of Regulation: A department that is responsible for evidence based regulation making. Mumbai: Location of the Third Annual Global Conference of the College of Supervisors.
Official Source Record View Original Source →
See Full Document Text
Regulation and Supervision – Adapting to the Digital Age Keynote Address by Shri Sanjay Malhotra, Governor, Reserve Bank of India at the Third Annual Global Conference of the College of Supervisors, Mumbai, January 9, 2026 Good morning and Namaskar. It is my privilege to address the third annual global conference of the College of Supervisors. 2. Advancement in technology is impacting all spheres of human activity – personal, business and public. Financial system is no exception. Technology has revolutionised banking over the years. Yet, today's landscape is distinct - the pace and scale of change are unprecedented. Technology has introduced new products, partners, and processes. 3. Digitalisation is widening access, enhancing efficiency, improving convenience, and enabling far more tailored financial services. At the same time, it is reshaping the nature and scale of risks. It is also accelerating the transmission of disruptions and risks underscoring the need for agility in regulatory and supervisory response. This makes the theme of the conference very apt. 4. I want to focus on five key messages today in my address: i) Systemic resilience as a collaborative effort ii) Supervisory action and enforcement as corrective measures iii) Effective use of data iv) Customer-centricity v) Capacity building I. Systemic resilience as a collaborative effort 5. First, I want to emphasise that we in RBI view our regulatory and supervisory roles vis-a-vis the regulated entities as collaborative and not adversarial. We measure our success as a regulator not only in terms of stability but also the dynamism and vibrancy in the financial sector. Similarly, for the regulated entities to succeed in the long term, stability is essential. Essentially, the objectives and purposes of the regulator and the regulated are the same viz. to ensure the long term growth, advancement, stability, integrity, and credibility of the financial system. The regulators and the regulated are in the same team and not opposite camps. We are partners in the nation’s development. Therefore, we have to work together to strike the right balance between growth and systemic stability on the one hand and between responsible innovation and consumer protection on the other hand. 16. I may mention that even the function of regulation and supervision is a collaborative effort. Almost every regulation is finalised through a consultative approach. Moreover, regulated entities also self-regulate through their own internal rules, controls, checks and procedures. Regulated entities have their own, if one can say so, in a broad sense, supervision - through their boards, senior management and assurance teams – both internal and external. Thus, while the statutory mandate to regulate and supervise lies with RBI, the obligation to uphold systemic resilience, to better serve the customers and facilitate the growth of the economy are shared responsibilities. It is a collaborative work with a collective aspiration. 7. Let us all remember that regulation works best when banks and other regulated entities view supervisors not as fault-finding inspectors, but as partners in resilience. 8. For a country like India, where banks play a critical role in financial intermediation and inclusive growth, this collaborative approach is not just desirable— it is essential. II. Supervisory action and enforcement as corrective measures 9. I now come to my second point. Supervisory action and enforcement are often viewed as the most visible aspect of regulation and supervision. It is therefore important to clarify that such actions by the Reserve Bank must be seen as part of a continuum of supervisory tools, not as a standalone response. This continuum begins with training and capacity building and moves through dialogue and guidance, off-site and on-site supervision. Enforcement, restrictions and penalties are measures of last resort. Our endeavour is to have a robust financial ecosystem where supervision encourages self-correction and enforcement acts only as backstop. 10. Moreover, the purpose of enforcement actions undertaken by the Reserve Bank is generally not punitive. The intent is largely to correct. They serve two purposes - (i) signal to those against whom such measures have been initiated; and (ii) make others aware of our acceptable standards of conduct and expectations. III. Effective use of data 11. My third point is related to reports that the regulated entities submit and the data that we collect for various purposes including supervision and regulation. We have undertaken several initiatives in the past to streamline the reporting mechanisms and improve the quality of data. We collect large amounts of data through platforms like CIMS and DAKSH. While some amount of burden is placed on all of you in this process, our supervisory capabilities have been strengthened because of your 2support. I am happy to note that the quality of data has improved recently, following introduction of the Supervisory Data Quality Index (SDQI) last year. I am confident that we will continue to collaborate for improving the system while reducing the burden placed on regulated entities. 12. While we have made good use of this data, there is scope for more effective use of this data. For example, Department of Supervision can build stronger analytics and supervisory dash boards for enhanced off-site surveillance, to support more continuous monitoring and early risk detection. Our endeavour should be to make supervision more off-site than on-site and as near real-time and not periodic. Increasingly, this will also mean using SupTech and AI-enabled tools more deeply, while retaining judgment and accountability, firmly with supervisors. Similarly, Department of Regulation can use this for evidence based regulation making. It should be our endeavour to make better and effective use of data. IV. Customer-centricity 13. I will now turn my attention to the use of technology for the benefit of customers. For all of us, protecting customers’ interest is not just a priority – it has to become the cornerstone of a sustainable and resilient financial system. Digital channels facilitate our efforts by improving inclusion and convenience. But, without guardrails, they can also facilitate opaque pricing, weak disclosures and inappropriate recovery practices. Our aim should be to ensure that digitalisation and innovations are aligned with fair outcomes for consumers. 14. A key element of this endeavour should be to protect customers from the menace of rising digital frauds, which has engaged national attention. While banks and other regulated entities individually should continue to improve their tools, techniques and processes in preventing and tackling digital frauds, this is an area where we need to collaborate with each other to build analytics and tools to detect mule accounts and suspicious transactions timely and pre-emptively. V. Capacity building 15. Before I conclude, let me acknowledge that there are huge expectations from all of us in financial system. To deliver on these expectations, and on our broader mandate, we must improve our effectiveness. This can only be achieved when we have the right mix of skills not only within the Reserve Bank across regulatory and supervisory domains but also within the financial institutions. 316. Moreover, a strong financial system needs supervisors, regulators as also the regulated entities to provide feedback and learn continuously from each other. 17. Regulated entities need to better understand regulatory expectations and requirements, particularly in the areas where models, partners, data, and digital delivery create new forms of risk. They need to imbibe the essence of regulation and follow the spirit of it and not merely follow a tick-box based compliance culture. Our endeavour, rather, should be to develop common understanding which can reduce frictions and improve outcomes. 18. Supervisors and regulators need to provide timely inputs and clarifications. Supervision should not only enforce existing regulations, but also help refine them by flagging regulatory gaps and inconsistencies observed during supervisory engagements. The amendments to the co-lending directions and lending against gold & silver jewellery last year were few recent examples where feedback from all the stakeholders helped us refine regulations. This feedback process is not just limited to supervisory engagement but also includes regulatory or supervisory reporting of data. 19. We need to intensify our engagement and capacity building efforts. This is where institutions like the College of Supervisors (CoS) can contribute immensely. CoS is not only a training institution. It is a platform for building a shared language of oversight, learning from case studies and practical scenarios. It provides a forum for skill upgradation and bridging the information gap between the Reserve Bank and our regulated entities. I urge all of you to collaborate and utilise the facilities offered by the CoS, more often. Conclusion 20. As I conclude my address, I want to emphasise that the fundamental architecture of regulation and supervision remains the same even in the digital era. They still follow the guiding principle of risk sensitivity. Regulated entities still have their stakeholders’ interest topmost in mind. Nonetheless, digitalisation has altered the landscape in many ways. I will leave you with a few key points to ponder and deliberate upon : • First, regulation and supervision must remain risk-based, proportionate, and technology-neutral; • Second, technology must embed compliance, not bypass it; and • Third, accountability must remain human, and automation should not dilute accountability —it should sharpen it. 421. I am confident that your deliberations during the day will yield actionable insights on how regulation and supervision should adapt, and how we can forge stronger pathways for cooperation with our key stakeholders and peers. 22. I thank the CoS team for organising this conference and giving me the opportunity to share my thoughts. I wish you a very productive and successful conference. Thank you. Namaskar. 5

Continue your research