BusinessManasi Praharaj31 Aug 2026

By Kanishka Gadi, Director – Corporate Solutions, EDME Insurance Broker.
India’s banking sector is navigating a period of unprecedented transformation. Digital transactions crossed 221 billion in FY25, while the value of transactions processed through digital channels exceeded INR 18,000 lakh crore, according to the Reserve Bank of India (RBI). At the same time, banks are operating in an environment defined by expanding digital ecosystems, third-party partnerships, cloud infrastructure, and real-time payments. As operations become more interconnected, the character of risk is changing. Some of the most significant threats facing banks are increasingly not coming from markets or borrowers, but from weaknesses in their own systems and processes.
Operational risk has traditionally been a second-order issue for the boards, generally taking a backseat to credit and market risk. Today, the distinction is more difficult to keep up. Technology outages, data breaches, or vendor failures can bring operations to a standstill, erode customer confidence, and draw regulatory scrutiny in hours. More importantly, these events rarely come in isolation. They often reveal deeper shortcomings in oversight, accountability, and decision-making.
When Operational Risk Becomes a Governance Issue
Operational failures are frequently described as technology incidents. They are often governance incidents that happen to surface through technology. The exploited technical vulnerability in a cyberattack may be the symptom, but the root cause may be delayed investments or inadequate control. A system outage can be perceived as operationally up but revealing deeper cracks in resilience planning and risk ownership.
This change is reflected in the increasing emphasis of the RBI on cybersecurity, operational resilience, and technology governance. Regulators are increasingly emphasising that technology risk cannot be treated as a standalone function. It must be integrated into the institution’s overall risk framework, with clear accountability that goes beyond IT teams to senior management and boards. That’s a significant implication. Operational risk can no longer be considered by banks as a compliance exercise. It has become a strategic issue that directly affects business continuity, reputation, and long-term value creation.
The increasing significance of third-party risk
Today, the banking ecosystem is much larger than just the institution. Core operations are increasingly reliant on technology vendors, cloud-service providers, payment processors, fintech partners, and outsourced service networks.
These collaborations foster innovation and efficiency, but they also create new vulnerabilities. A disruption at one of the critical service providers can quickly become a disruption for the bank and its customers. This risk is not controlled by contract or annual vendor assessments. A more advanced process is needed here. They must recognize the dependencies that exist, gauge their resilient capability, test their recovery methods, and develop an escalation framework.
Looking Beyond the Label of Risk
One of the most overlooked aspects of operational risk is its ability to hide beneath other categories of loss.
Consider a credit default. It is often classified purely as credit risk. But in many cases the root causes may be poor documentation, inadequate monitoring or poor escalation processes. One heading shows the financial loss. The root cause is elsewhere.
This highlights a broader challenge for banks. Risk events should not be viewed solely through the lens of their outcomes. Understanding how decisions were made, how controls functioned and where processes failed often provides more valuable insight than the loss itself.
Building Institutions That Are Operationally Resilient
The most resilient banks are not necessarily those with the largest compliance budgets. They are the institutions that recognise operational risk as a dynamic business challenge rather than a regulatory obligation. As banking becomes increasingly digital, interconnected and data-driven, governance frameworks must evolve at the same pace. Strong controls, clear accountability and continuous process review are no longer defensive measures; they are competitive advantages.
The future of banking will hinge not only on the ability of institutions to manage risk from outside sources, but the risk that the institution itself poses through its actions.