Showing posts with label SEBI. Show all posts
Showing posts with label SEBI. Show all posts

Wednesday, January 4, 2012

Mobile Banking Cyber Security Is Required In India

Mobile banking in India is moving towards an acceptance level. However, till now very few people and institutions are comfortable in using mobile banking in India. Mobile banking in India is still not popular according to RBI. There are certain shortcomings of mobile banking in India that are still left unaddressed.

For instance, mobile governance in India is still not well established. M-governance in India is essential before mobile banking can be successfully implemented in India. We have no regulatory framework for m-governance in India. Even the proposed electronic delivery of services bill 2011 of India has failed to provide a mandatory legal framework for electronic delivery of services in India, including for mobile banking. In short, India is still not ready for m-governance and cloud computing especially in the absence of dedicated e-commerce laws in India.

Mobile banking in India is risky due to absence of mobile cyber security in India. Further, online banking system of India is not secure. In the absence of adequate cyber security safeguards, e-banking in India is not safe. The cyber security trends in India 2011 have also proved that Internet banking cyber security in India is in poor shape and it needs to be strengthened. Even data security, privacy and cyber security in Indian banking industry is not satisfactory.

Online banking risks in India are increasing and this is also shaking the confidence of customers in the same. Even RBI has acknowledged risks of e-banking in India. ATM frauds in India are increasing. In fact, Reserve Bank of India (RBI) has recently released the report of its working group on securing card present transaction that covers ATM security and credit card security issues as well. Internet banking risks in India cannot be effectively tackled till we have dedicated Internet banking laws in India.

Although an integrated banking law of India has been proposed yet it may take some years before it is actually enacted. In an interesting development, the RBI removed limits from mobile banking transactions limits in India. This is good for the development of mobile banking in India but is bad for the interests of mobile banking customers who have almost no safeguards against cyber crimes and technology assisted financial frauds happening in the mobile banking field.

The cyber law in India has prescribed cyber law due diligence for various stakeholders. Cyber due diligence for banks in India is just a part of the same. Cyber due diligence for Indian companies including banks operating in India is very stringent. However, Indian banks are not following the guidelines of RBI prescribing mandatory cyber security requirements for banks of India. Further, banks are also liable

Even on the policy front, mobile banking has received a bad response form Indian government. For instance, absence of effective encryption laws in India and non use of robust encryption in India has made the mobile security very weak in India. Instead of making the encryption requirements redundant and weak, India must concentrate upon further strengthening the same for better and secure mobile communications. Governments of most developed countries allow the usage of strong encryption standards ranging from 128 bits to 256 bits or more to ensure the security of sensitive information exchanged via Internet and other networks. However, India is still clinging to 40 bits encryption standards for the simple reason that intelligence and security agencies of India are not capable enough to break strong encryptions.

A weak mobile banking infrastructure would also affect other projects and schemes as well. For instance, recently the Securities and Exchange Board of India (SEBI) has declared about its intentions to introduce electronic initial public offer (E-IPO) in India. This is a good step but E-IPO cannot succeed in the absence of strong mobile banking and Internet banking infrastructure. Online payments mechanisms in India must also be suitable strengthened to make such proposals workable.

India must give these considerations some serious thoughts if it wishes to encash the benefits of technology. Otherwise, concepts like Internet banking and mobile banking are more nuisance than luxury in India.

Tuesday, May 24, 2011

RBI Mandates Information Giving Of Strictures Passed Against Directors

Reserve Bank of India (RBI) has been streamlining the management of banking and financial institutions of India. It has taken many pro active steps in this regard. From prescribing a more stringent cyber due diligence policy for banks to mandating a requirement to appoint chief information officers (CIOs) and steering committee at the board level, RBI has taken many reformative steps.

In fact, cyber due diligence and banking due diligence could have prevented the recent Citibank fraud. The truth is that banks and financial institutions in India are not serious at all regarding cyber due diligence, cyber crimes, financial frauds and cyber security. Till now RBI’s guidelines on steering committee and CIOs have not been fulfilled by banks of India. Even RBI has recently imposed non compliance penalty upon 19 banks of India in another case.

However, despite all these actions, the higher management of banks have not been persuaded to take due diligence seriously. Now RBI has decided to change this position and it has asked banks to seek information from their directors on any adverse strictures passed by financial sector regulators against them.

This means if directors of banks are negligent in meeting various due diligence requirements, statutory obligations, cyber law and cyber security requirements, etc and any stricture is passed against them in this regard that would have to be reported.

RBI has also partially modified the format of “Declaration and Undertaking” prescribed for the purpose of conducting due diligence to determine the “fit and proper” status of directors. Banks should get information whether the director at any time come to the adverse notice of a regulator such as the Securities and Exchange Board of India (SEBI) and the Insurance and Regulatory Development Authority (IRDA) .

Henceforth, banks should obtain declaration and undertaking from existing directors and also persons to be appointed or elected as director. It is not necessary for a candidate to mention about orders and findings by regulators which have been later on reversed or set aside in toto. But they would have to make a mention of the same, in case the reversal and setting aside is on technical reasons like limitation or lack of jurisdiction and not on merit. If the order (of the regulator) is temporarily stayed and the appellate or court proceedings are pending, the same also should be mentioned, RBI added.

This is a good step in the right direction by RBI. This would bring not only discipline among the higher management but would also ensure statutory and due diligence compliances on their behalf.