Indian regulators bolster cybersecurity frameworks to combat AI-driven financial fraud

Indian financial regulators, including SEBI and the Reserve Bank of India, are strengthening cyber oversight with new metrics, incident-reporting standards, and AI guidelines amid rising threats from automated fraud techniques.

Indian regulators are tightening cyber oversight as artificial intelligence makes financial fraud faster, cheaper and harder to detect. The Reserve Bank of India and the Securities and Exchange Board of India have both recently sharpened their focus on the resilience of banks, exchanges and other critical parts of the financial system, with SEBI putting new stress on measurable IT readiness and the RBI expanding its cyber framework for lenders and other financial firms.

According to The Indian Express, SEBI has introduced an IT Resilience Index for market infrastructure institutions such as stock exchanges and clearing corporations. The regulator says disruption or compromise of these systems could damage market operations and undermine trust. The index uses nine parameters, including availability, security, integrity, governance and business continuity, and is intended to make cyber resilience easier to measure and compare. It will take effect from early 2027, with institutions required to calculate it twice a year and submit rolling comparisons alongside corrective action.

The same report says SEBI has aligned its incident-reporting portal with a standard FIRE format so that cyber events can be reported in stages, from initial alert to final closure. It also plans to issue guidance on the responsible use of AI and machine learning in the market. Kamlesh Chandra Varshney, a whole-time member of SEBI, said the regulator has already formed a team to explore AI models for corporate investigations. In parallel, the RBI has released a broader cybersecurity framework for banks and financial institutions, requiring board-level oversight, dedicated internal committees and cyber-incident reporting within six hours.

The RBI has also widened its fraud compensation rules for consumers and is considering a “kill switch” that would let account holders stop transactions during suspected fraud. SEBI is examining a similar idea as part of its AI work. Experts quoted by The Indian Express warn that AI changes the threat environment by enabling automated phishing, deepfake impersonation, synthetic identities and attacks that can move at machine speed. Their view is that regulators should rely on technology-neutral accountability, backed by technical safeguards, continuous testing and clear human responsibility.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.