Showing posts with label RBI. Show all posts
Showing posts with label RBI. Show all posts

Monday, May 2, 2011

Electronic Banking In India

This is the updated version of my previous article on same topic. Electronic banking in India or e-banking in India is increasingly being used by both banks and customers alike. This brings mobility and convenience to both banks and customers. However, with the benefits there are drawbacks of e-banking as well. This article addresses some of these concerns.

Reserve Bank of India (RBI) has come across many complaints and disputes regarding fraudulent credit card, online banking and ATM transactions. Even phishing incidences have sharply arisen in India resulting in loss of money of public at large. RBI ombudsmen office has been flooded with such complaints.

In these circumstances, online banking in India is risky. We have no e-banking laws in India and this also makes the mobile banking in India risky. Even RBI has acknowledged risks of e-banking in India.

E-banking in India cannot succeed till a strong legal framework in this is enacted. According to Praveen Dalal, managing partner of New Delhi based law firm Perry4Law and leading techno legal expert of India, we have no dedicated E-Banking Law in India. Although, RBI has issued many guidelines in this regard and even our Information Technology Act, 2000 contains some indirect and implied provisions for Internet or E-Banking yet we need a separate and dedicated law in this regard, opines Praveen Dalal.

Recently, G Gopalakrishna, the executive director of RBI, said that all Banks would have to create a position of Chief Information Officers (CIOs) as well as Steering Committees on Information Security at the Board Level at the earliest, informs Dalal. This step was taken to ensure proper Cyber Security Policies and Strategies at the highest Board Level of Banks, says Dalal.

Although RBI has mandated cyber due diligence for banks in India especially the due diligence for banks under IT Act 2000 yet banks have still to keep their functions in order. Indian banks are poor at cyber security and they are in no mood to appoint CIOs and steering committee.

Recently the final report of working group of RBI on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds has been released. It has prescribed the time limits for implementation of RBI recommendations on information security. With the deterrent approach of RBI towards non compliance, it would be safe to presume that CIOs, steering committee and cyber security related compliances would also be taken seriously by RBI.

It is high time for banks operating in India to keep their e-banking infrastructure technologically and legally sound. The best option for banks seems to be to adopt Techno Legal Measures that covers both Technical and Legal aspects of Banking, suggests Dalal.

Saturday, March 5, 2011

E-Discovery For Due Diligence By Banks In India

Banking sector of India is passing through a reformative phase. Lots of banking reforms are under process and Reserve Bank of India (RBI) is playing a major role in the same. Finance Minister Pranab Mukherjee has been extending his full support for banking and financial sector reforms as well.

Even in the fields of cyber law, cyber security, cyber due diligence, prevention of cyber banking frauds, etc RBI has issued many guidelines through its information technology vision document 2011-17. Some of the mandatory guidelines now require banks of India to appoint chief information officers (CIOs) and steering committees on information security at the board level at the earliest.

In the past, lack of cyber due diligence and absence of CIOs and steering committee has resulted in many cyber crimes and banking frauds. Techno legal experts like Praveen Dalal believe that if a proper cyber due diligence was at place, it could have prevented the recent fraud that was committed at the Gurgaon based branch of Citibank.

Banks in India must understand the importance of e-discovery practices, incidence response, first responder’s roles, cyber due diligence, etc. If banks have a sound e-discovery mechanism, many frauds can be anticipated and prevented before they occur.

E-discovery law in India has still to be enacted. Although India has the cyber law of India incorporated in the form of information technology act 2000 (IT Act 2000) yet it is far from being sufficient for cyber forensics and e-discovery purposes.

Government of India must immediately enact some good technology laws that can cater the requirements of present times. Presently, the IT Act, 2000 needs a complete overhaul as it is not meeting the needs of the hour.

Thursday, March 3, 2011

RBI Releases Its IT Vision Document For 2011-17

The Reserve Bank of India (RBI) has recently released the Report of the High Level Committee (HLC) on the IT Vision of Reserve Bank of India 2011-2017. The HLC report includes the IT Vision document for 2011-17.

RBI has set some very ambitious objectives for itself. These include transforming itself into an information intensive knowledge organisation, harnessing human resource potential, migration to enterprise architecture for IT systems, adopting appropriate business process re-engineering, etc.

RBI has also stressed upon improving its IT governance, effective project management, evolving well defined information policies as well as information security frameworks, better vendor management and outsourcing practices.

The Vision Document suggests commercial banks to move forward from their core banking solutions to enhanced use of IT in areas like MIS, regulatory reporting, overall risk management, financial inclusion and customer relationship management.

It also dwells on possible operational risks arising out of adopting technology in the banking sector which could affect financial stability and emphasises the need for internal controls, risk mitigation systems, fraud detection / prevention and business continuity plans. However, concepts like Internet banking cannot succeed in the absence of legal framework in this regard.

According to Praveen Dalal, leading techno legal expert of India and a Supreme Court lawyer, we have no dedicated Internet Banking Law in India. Although, RBI has issued many guidelines in this regard and even our Information Technology Act, 2000 contains some indirect and implied provisions for Internet Banking yet we need a separate and dedicated law in this regard, opines Dalal.

Similarly, the present banking and other technology related legal frameworks are not conducive for mobile banking in India. We do not have a well developed e-governance infrastructure in India. Similarly, on the front of e-commerce as well, India is not much successful.

RBI will begin implementing the recommendations of the HLC shortly. However, commercial banks in India must not wait for RBI’s initiations in this regard. They must start implementing due diligence requirements as prescribed by RBI as soon as possible.