
The Reserve Bank of India has issued the Reserve Bank of India (Urban Co-operative Banks – Digital Payment Security Controls) Directions, 2026 under Section 35-A read with Section 56 of the Banking Regulation Act, 1949, the Payment and Settlement Systems Act, 2007, and other enabling provisions, with immediate effect. These comprehensive directions prescribe security controls for digital payment products and services offered by Urban Co-operative Banks, covering governance, Board-approved policies, security risk management, digital payment architecture, application security lifecycle, authentication framework, fraud risk management, reconciliation, customer protection, awareness, grievance redressal, and security controls for internet banking, mobile payment applications, and specified card payment operations. The directions require risk assessments, secure development practices, vulnerability assessment and penetration testing, multi-factor authentication, encryption, transaction monitoring, fraud detection, customer alerts, secure handling of payment data, dispute resolution mechanisms, and compliance with specified payment card security standards where applicable. As per the latest RBI notification, these directions repeal earlier Digital Payment Security Controls directions applicable to Urban Co-operative Banks while preserving actions taken under the repealed framework.
Urban co-operative banks face cyber risks that exceed their physical size limitations, according to RBI Deputy Governor Swaminathan J. Speaking at the Mission SAKSHAM programme for UCB directors in Telangana, he emphasized that while UCBs may be smaller institutions, the risks they face can be much larger than their geographical presence. Swaminathan noted that cyber attackers do not distinguish between large and small banks, stating that digital fraud does not slow down because the bank has fewer branches. The growing use of technology in banking has fundamentally changed the nature of risks faced by smaller financial institutions, with the Deputy Governor highlighting that while the size of a UCB may be limited, the risks it faces may originate far beyond its physical or geographical boundaries. As reported by The Hindu BusinessLine, Swaminathan cautioned that a cyber incident may originate far outside its area of operation, a failure at a technology service provider may disrupt critical banking services, and a digital fraud can move across accounts within minutes. He stressed that a UCB may be local, but its risk environment is not.
Many UCBs depend on outside service providers for critical functions such as Core Banking Solutions, payment applications and data centres, creating additional vulnerabilities. As reported by The Hindu BusinessLine, Swaminathan posed the critical question to bank boards and CEOs: 'How much of my bank today actually sits outside my bank?' He stressed that while outsourcing allows smaller banks to access technology and expertise, it also creates risks that require careful management. Banks must understand which systems are operated by external providers and what would happen if a service provider becomes unavailable for hours or even a day. The service provider may operate the system, but responsibility for understanding the risks, putting appropriate safeguards in place and ensuring continuity of critical services continues to rest with the bank. Smaller UCBs cannot be expected to build every specialised capability internally, instead requiring common infrastructure, shared expertise and sector-level arrangements to manage their technology and operational challenges more effectively.
Customers today expect banking services to be available quickly and conveniently through digital channels, including fund transfers, payments and account access. According to the RBI Deputy Governor, meeting these expectations requires UCBs to strengthen their technology and digital capabilities. However, smaller UCBs may not have the same resources and specialized manpower available to larger commercial banks to deal with complex cyber threats, digital fraud and technology failures. As reported by The Hindu BusinessLine, Swaminathan noted that a UCB may face cyber threats, digital fraud, and technology failures of considerable complexity, but may not have the same resources or specialised manpower as a much larger commercial bank to deal with them. This creates a significant challenge for smaller institutions in maintaining adequate security infrastructure while meeting evolving customer demands for digital banking services.
The Reserve Bank launched Mission SAKSHAM on April 28 to build capabilities across the UCB sector, as highlighted by Swaminathan. The programme aims to cover about 1.4 lakh participants and includes separate learning programmes for board members, senior management, assurance function heads, IT technical employees and other employees. The initiative addresses the need for smaller UCBs to develop shared infrastructure, sector-level arrangements and common expertise to manage their technology and operational challenges more effectively. As reported by The Hindu BusinessLine, the programme represents a comprehensive approach to addressing the unique vulnerabilities faced by smaller urban cooperative banks in the current digital banking environment. The Deputy Governor emphasized that traditionally, we have tended to associate the complexity of a bank with its size—its balance sheet, branch network or area of operation. But technology and greater interconnectedness are changing this relationship.