Showing posts with label E-BANKING RISKS IN INDIA. Show all posts
Showing posts with label E-BANKING RISKS IN INDIA. Show all posts

Tuesday, January 3, 2012

E-Banking In India Is Not Safe

Electronic banking (e-banking) in India is seen as a viable and alternative mechanism to do traditional banking business. Even banking customers are happy to use the same for reasons of efficiency and time saving. However, there are many e-banking security related issues that are not paid attention to by Indian banks.

Cyber security of banking transactions in India is an important aspect that must be of paramount importance to all banks and financial institutions operating in India and elsewhere. Even Reserve Bank of India (RBI) has recommended ensuring strong cyber security for banking and financial institutions in India. RBI has even made the appointment of chief information officers (CIOs) mandatory for all banks operating in India. However, till now there is no sign of compliance with this requirement of RBI and online banking system of India is not cyber secure.

E-banking risks in India are increasing and cyber security of e-banking in India must be strengthened by various banks. In fact, e-banking cyber security in India needs to be strengthened so that customers’ confidence can improve. ATM frauds in India are increasing and so are e-banking related and credit cards frauds. RBI’s ombudsmen office is already flooded with ATM related complaints. Other banking financial frauds in India are also widespread.

Recently, Indian electronic delivery of services bill 2011 has been proposed by Indian government. The moment it becomes an applicable law, government departments and public authorities would be required to deliver public services in an electronic form. This makes using a strong cyber security essential for banks and financial institutions operating in India.

Similarly, the cyber law of India mandates cyber due diligence for Indian companies and other stakeholders. Banks of India are also required to ensure cyber law due diligence in India to escape financial, civil and criminal liabilities. Cyber security due diligence for banks in India must be taken very seriously by banks and financial institutions in India. Banks must ensure good chief information officers (CIOs) training for their staffs so that they can meet the cyber security requirements effectively.

For long banks have ignored cyber law due diligence and cyber security requirements and this has made e-banking transactions unsafe in India. E-banking in India is not safe and both Indian government and RBI must immediately step in to remedy this situation.

Monday, May 2, 2011

Electronic Banking In India

This is the updated version of my previous article on same topic. Electronic banking in India or e-banking in India is increasingly being used by both banks and customers alike. This brings mobility and convenience to both banks and customers. However, with the benefits there are drawbacks of e-banking as well. This article addresses some of these concerns.

Reserve Bank of India (RBI) has come across many complaints and disputes regarding fraudulent credit card, online banking and ATM transactions. Even phishing incidences have sharply arisen in India resulting in loss of money of public at large. RBI ombudsmen office has been flooded with such complaints.

In these circumstances, online banking in India is risky. We have no e-banking laws in India and this also makes the mobile banking in India risky. Even RBI has acknowledged risks of e-banking in India.

E-banking in India cannot succeed till a strong legal framework in this is enacted. According to Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India, we have no dedicated E-Banking Law in India. Although, RBI has issued many guidelines in this regard and even our Information Technology Act, 2000 contains some indirect and implied provisions for Internet or E-Banking yet we need a separate and dedicated law in this regard, opines Praveen Dalal.

Recently, G Gopalakrishna, the executive director of RBI, said that all Banks would have to create a position of Chief Information Officers (CIOs) as well as Steering Committees on Information Security at the Board Level at the earliest, informs Dalal. This step was taken to ensure proper Cyber Security Policies and Strategies at the highest Board Level of Banks, says Dalal.

Although RBI has mandated cyber due diligence for banks in India especially the due diligence for banks under IT Act 2000 yet banks have still to keep their functions in order. Indian banks are poor at cyber security and they are in no mood to appoint CIOs and steering committee.

Recently the final report of working group of RBI on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds has been released. It has prescribed the time limits for implementation of RBI recommendations on information security. With the deterrent approach of RBI towards non compliance, it would be safe to presume that CIOs, steering committee and cyber security related compliances would also be taken seriously by RBI.

It is high time for banks operating in India to keep their e-banking infrastructure technologically and legally sound. The best option for banks seems to be to adopt Techno Legal Measures that covers both Technical and Legal aspects of Banking, suggests Dalal.