Swaminathan J, Deputy Governor, RBI

While the size of an Urban Co-operative Bank (UCB) may be limited, the risks it faces may originate far beyond its physical or geographical boundaries, cautioned RBI Deputy Governor Swaminathan J. He noted that the institution may be small, but the risk environment around it can be much larger.“Traditionally, we have tended to associate the complexity of a bank with its size—its balance sheet, branch network or area of operation. This remains relevant, and our four-tier regulatory framework for UCBs recognises these differences. But technology and greater interconnectedness are changing this relationship,” the Deputy Governor said in his Keynote Address at Mission SAKSHAM Programme for Directors, MDs and CEOs of UCBs in Telangana, Hyderabad on August 7, 2026.He observed that a bank may be small in size, but the systems it depends on and the risks it has to manage may be much larger and more complex. This means that its physical size or geographical presence no longer confines the risks facing a UCB.“A cyber incident may originate far outside its area of operation. A failure at a technology service provider may disrupt critical banking services. A digital fraud can move across accounts within minutes. In that sense, a UCB may be local, but its risk environment is not,” cautioned SwaminathanHe said that with the rapid adoption of technology in every aspect of banking, a UCB may face cyber threats, digital fraud, and technology failures of considerable complexity, but may not have the same resources or specialised manpower as a much larger commercial bank to deal with them.Outsourcing brings new vulnerabilitiesFurther, many UCBs depend on outside service providers for their Core Banking Solution, payment applications, data centres and other important services. This is often both necessary and efficient. It allows smaller institutions to access technology and expertise that may be difficult or expensive to build entirely on their own.However, this also changes the nature of the bank. Some activities critical to the bank’s functioning may now be performed outside the bank.“This raises a simple but important question for every Board and every CEO: how much of my bank today actually sits outside my bank? Which systems are operated by external providers? What happens if one of them is unavailable for a few hours—or for a day?“The service provider may operate the system, but responsibility for understanding the risks, putting appropriate safeguards in place and ensuring continuity of critical services continues to rest with the bank,” he said.Cyber threats do not distinguish between banksSwaminathan underscored that a cyberattacker does not distinguish between large and small banks. Digital fraud does not slow down because the bank has fewer branches. And a vulnerability in a widely used technology platform can affect several institutions simultaneously.Published on August 20, 2026