Context
- RBI and SEBI are tightening cybersecurity rules to address growing AI-driven financial fraud and cyberattacks.
- SEBI introduced the IT Resilience Index (ITRI) for Market Infrastructure Institutions (MIIs) and adopted the FIRE format for cyber-incident reporting.
- RBI’s 2026 Directions strengthen cyber-risk governance, monitoring, testing and incident reporting by regulated entities.
Why AI Raises Cybersecurity Risks
- AI enables faster and large-scale fraud and cyberattacks by automating attack processes.
- Deepfakes can imitate voices, faces and identities, enabling impersonation and financial fraud.
- Greater reliance on cloud services and interconnected digital systems increases potential points of cyber failure.
SEBI’s IT Resilience Index (ITRI)
- ITRI measures the technology resilience of Market Infrastructure Institutions (MIIs) such as stock exchanges, clearing corporations and depositories.
- It covers nine parameters:
-
- Availability (20%)
- Security (20%)
- Integrity, Governance, Reliability & Monitoring, Business Continuity, Modularity & Flexibility (10% each)
- Scalability and Others (5% each)
- MIIs must assess ITRI half-yearly and submit comparative results with corrective measures within 90 days of the half-year’s end.
- It supports continuous monitoring and early detection of technology risks.
FIRE-Based Incident Reporting
- SEBI has adopted the FIRE (Format for Incident Reporting Exchange) framework for cyber-incident reporting.
- It enables staged reporting and subsequent updates as more information becomes available, even when initial details are incomplete.
RBI’s Cybersecurity Framework
RBI’s 2026 Directions strengthen cyber and technology risk management in regulated financial entities through:
- Board-level oversight and dedicated IT and information-security mechanisms.
- Continuous monitoring through Cyber Security Operations Centres (CSOCs).
- Regular vulnerability assessments, penetration testing and business continuity measures.
- Cyber-incident reporting to RBI within 6 hours of detection.
Kill-Switch Mechanism
- RBI is exploring a kill-switch that would allow users to immediately block financial transactions when fraud is suspected.
- It may also provide switch-on/switch-off controls for digital payment modes to give users greater control over their accounts.
- This can help limit financial losses by enabling faster action against fraudulent transactions.
AI Governance in Securities Markets
- SEBI is developing guidelines for the responsible use of AI/ML in securities market and already uses AI-based tools to detect unusual trading and compliance patterns.
- In January 2026, it formed a Technology Roadmap Working Group for MIIs to examine AI/ML, cloud computing, Distributed Ledger Technology (DLT), tokenisation, SupTech/RegTech and quantum-safe technologies.
Challenges
- Deepfake Fraud: AI-generated voices and images can bypass identity and KYC safeguards.
- Rapid Technological Change: Fast-evolving threats can make periodic security assessments inadequate.
- Third-Party Risks: Dependence on cloud services and vendors can create concentration and supply-chain risks.
- AI System Risks: Poor data, model manipulation and lack of transparency can affect AI reliability.
- Accountability Gap: Over-reliance on AI may create uncertainty over human responsibility for critical decisions.
Way Forward
- AI-Specific Risk Assessment: Develop AI-focused threat models and conduct continuous security testing.
- Data & Model Security: Ensure data integrity, secure access and reliable AI models.
- Resilience Testing: Regularly test systems against deepfakes, ransomware, supply-chain and cloud risks.
- Regulatory Coordination: Strengthen information-sharing among RBI, SEBI, CERT-In, financial institutions and technology providers.
- Human Oversight: Ensure clear human responsibility for critical AI-based decisions.
- Flexible Regulation: Adopt technology-neutral rules with additional safeguards for high-risk AI applications.
Conclusion
AI is reshaping the scale of financial cyber threats, requiring stronger cyber resilience and regulatory agility. Measures such as SEBI’s ITRI and FIRE, RBI’s cyber-risk framework and kill-switch mechanisms can strengthen India’s digital financial security through continuous monitoring, rapid response, responsible AI and clear accountability.
FAQs
Q1. What is SEBI’s IT Resilience Index (ITRI)?
Ans. ITRI measures the technology resilience of Market Infrastructure Institutions (MIIs) across nine parameters. It helps identify risks early through half-yearly assessments and corrective action.
Q2. What is the FIRE framework?
Ans. FIRE (Format for Incident Reporting Exchange) provides a standardised system for staged cyber-incident reporting, allowing institutions to submit updates as more information becomes available.
Q3. What is the kill-switch mechanism?
Ans. It is a proposed facility that allows users to immediately block financial transactions when fraud is suspected, helping minimise financial losses.
Q4. Why is AI governance important in financial markets?
Ans. AI can improve market surveillance but also creates risks such as deepfakes, model manipulation, data risks and cyberattacks. Therefore, human oversight, data security and clear accountability are essential.

