Banking

The RBI’s cyber warning puts payment continuity beside bank capital

A technology failure could become a funding problem through delayed payments and shared suppliers. The governor’s warning is conditional.

A metal network coupler with one connected cable and a loose connector on a slate workbench.
AI-generated editorial illustration made with Codex.
In this article

A bank can have capital to absorb losses and still struggle to complete a payment on time. That distinction gives practical meaning to Sanjay Malhotra’s warning that a future financial crisis could begin outside finance, with a geopolitical event, cyberattack or technology failure.

The Reserve Bank of India governor described those possibilities at the October 3 Kautilya Economic Conclave, according to The Financial Express, corroborating the warning reported by The Next Web. His assessment was conditional. The Indian Express also reports that he saw no imminent signs of stress.

The useful question is therefore how an operational problem could become a financial one. The answer runs through the services that move money, the dependencies shared by institutions and the quality of recovery. It does not require assuming that an attack is underway or assigning a date to a crisis.

A sound balance sheet cannot execute a stalled payment

Capital, liquidity and operational continuity solve related but different problems. Capital provides capacity to absorb losses. Liquidity supports obligations as they come due. Operational continuity enables an institution to identify and execute those obligations using functioning systems and trustworthy records. Having one form of resilience does not mechanically deliver the others.

Consider a hypothetical bank whose incoming payments are delayed while outgoing obligations continue to mature. It might need to mobilise liquid assets or arrange temporary funding even though its customers’ underlying ability to repay loans has not changed. This is a possible timing mechanism, not a finding about a particular Indian institution.

The effect would depend on which service failed, how long it remained unavailable and which alternatives still worked. A brief customer-interface outage with settlement unaffected is different from an interruption to the records or connections needed to settle transactions. An incident label alone tells an investor little about the financial consequence.

Confidence can add another channel. If customers cannot tell whether their balances are correct or when transfers will resume, their response could increase operational and funding pressure. Clear information and functioning alternatives could instead contain the disturbance. Neither reaction follows automatically from the existence of a cyber incident.

The Basel Committee’s operational resilience principles frame the objective around delivering critical operations through disruption. That shifts the assessment from whether every failure can be prevented to whether essential services can continue or recover within an institution’s tolerance. It is a standard for examining capability, not evidence that every bank already meets it.

Two suppliers can still share one point of failure

The governor’s warning about technology infrastructure and critical third parties broadens the perimeter beyond a bank’s own systems. An apparently external service can support an essential internal process. Its failure can therefore matter even when the affected bank did not build or directly operate the technology.

AI adds another layer. The Financial Stability Board’s 2025 monitoring report examines third-party dependencies and supplier concentration alongside cyber and model vulnerabilities. It also highlights gaps in the data needed to monitor these relationships. The existence of a named risk is not a measured probability of systemic failure.

A hypothetical institution could buy two applications from different firms while both depend on the same underlying cloud service or data source. Counting contracts would then overstate independence. Conversely, a shared supplier might operate robustly separated services with credible recovery arrangements. Concentration needs to be evaluated through actual dependencies, not inferred from a supplier count alone.

Materiality also depends on the task. Losing an optional document-summary service need not stop payments. Losing an essential screening or transaction-processing function could have different consequences. The relevant analytical questions concern what the system is authorised to do, whether people can take over and whether an alternative can handle the required workload.

This explains why a resilience assessment has to follow the transaction end to end. A bank’s local fallback can work technically while a counterparty, shared provider or communication link remains unavailable. A successful demonstration in isolation does not establish that the wider payment chain survives the same scenario.

Restoration must recover trustworthy records

Bringing a service back online is only one part of recovery. For a financial institution, it also matters whether restored records correctly distinguish completed, pending and rejected transactions. Otherwise, an attempt to clear a backlog could create a new problem through duplicate processing or uncertainty over obligations. This is an analytical recovery scenario, not a reported event.

The counterargument to a purely alarming reading is substantial. AI can improve operational efficiency and help financial institutions detect and manage problems; the FSB recognises potential benefits as well as vulnerabilities. A contained outage can remain an operational cost without becoming a solvency event. The sensible conclusion is to demand evidence of controls and recovery, rather than equate AI adoption with instability.

That evidence has commercial significance. Alternative capacity, reconciled data, trained staff and realistic exercises consume resources. A claimed efficiency saving is more informative when its calculation includes the arrangements needed to keep critical work functioning. This does not establish that every additional resilience expense is productive; capability and proportionate cost both require assessment.

Demonstrated recovery across shared providers, accurate transaction reconciliation and clear reporting of service interruption would support confidence in these arrangements. Repeated missed restoration targets or unresolved common dependencies would weaken it. Malhotra’s warning supplies a reason to examine those facts, while his no-imminent-stress qualification prevents the examination from turning into an unsupported crisis forecast.

Sources

Information and estimates for educational purposes. They do not constitute personal financial advice. About & methodology →

Continue reading