India’s co-operative banking sector is entering an important phase of regulatory and operational change. The Reserve Bank of India is not merely updating individual compliance requirements; several recent initiatives point towards a broader objective of building stronger, better-governed, technologically resilient and customer-focused co-operative banks.
Issue 2 of UCB FinSight – September 2026 examines developments that could influence how Urban Co-operative Banks are licensed, governed, supervised, priced, monitored and prepared for emerging risks. The developments covered in this edition include RBI’s proposed return to on-tap licensing of UCBs, stronger standards for loan recovery, concentration-risk norms for Rural Co-operative Banks, a new harmonised approach to interest-rate determination, the ECBA framework, 24/7 cyber surveillance for UCBs and RBI’s Mission SAKSHAM for capability building.
What connects all of these developments is a common regulatory direction: growth must be accompanied by stronger governance, risk management, transparency, technology and institutional capability.
1. Draft Guidelines for ‘On-Tap’ Licensing of Urban Co-operative Banks
One of the most significant developments for the co-operative banking sector is RBI’s proposal to reopen the route for licensing new Urban Co-operative Banks through an on-tap licensing framework. Fresh applications for setting up UCBs had effectively remained frozen for more than two decades, making this proposed framework particularly important for the sector. The newsletter highlights that the proposed route is not intended to encourage unrestricted entry; rather, RBI appears to be linking new licences with a demonstrated history of financial soundness, governance quality and operational capability.
RBI’s August 2026 regulatory updates also included its invitation for public comments on draft guidelines for on-tap licensing of UCBs, confirming that this is a proposed framework rather than a final licensing regime at this stage.
Why the Draft Framework Matters
UCBs occupy a unique position in the Indian banking system. They combine the co-operative model with deposit-taking and lending functions, often maintaining strong local relationships with small businesses, professionals, traders and communities. However, the sector has also experienced episodes involving weak governance, inadequate capital, asset-quality problems and operational failures. This explains why any reopening of licensing is being approached cautiously. RBI’s focus is not simply on creating more UCBs. The emphasis is on permitting entry only where the applicant can demonstrate sufficient scale, capital strength, governance capability and financial discipline. For the sector, the proposed framework signals an important change. Growth opportunities may become available again, but they would be accompanied by significantly higher expectations regarding governance, financial soundness and regulatory preparedness.
Key Eligibility Parameters Highlighted in the Draft
The newsletter identifies the following major thresholds:
| Parameter | Proposed Requirement |
|---|---|
| Operational track record | 10 years or more |
| Deposit size | ₹10,000 crore minimum |
| Net worth | ₹300 crore minimum |
| CRAR | 12% minimum |
| Net NPA | Not more than 3% |
These numbers should not be read independently. Together, they indicate RBI’s preference for institutions that have already demonstrated sufficient size, capital strength and asset quality before they are considered for the proposed licensing route.
Why Governance Will Be Just as Important as Numbers
A bank may satisfy numerical criteria and still face regulatory concerns if its governance systems are weak. Therefore, Boards and promoters should expect RBI to examine matters such as ownership structure, management quality, financial integrity, risk controls, governance processes, operational preparedness and the proposed business plan. The broader message is that licensing is not merely a documentation exercise. Applicants would need to demonstrate that they can operate safely as a bank, protect depositors and comply with the higher standard of responsibility that accompanies a banking licence.
Application Journey
The newsletter presents the proposed journey broadly as:
Applicant eligibility assessment → submission of the prescribed application → shareholder resolution/approval → Central Registrar/NOC process where applicable → RBI scrutiny → in-principle approval and regulatory compliance.
For institutions considering this route, preparation should therefore begin well before an application is filed. Promoters should review capital adequacy, financial statements, asset quality, governance arrangements, management capability and the long-term business plan.
Practical Takeaway
The proposed return of on-tap licensing should be viewed as an opportunity for strong and mature institutions, rather than a simple reopening of the UCB licensing window. The institutions best placed to benefit will be those that can demonstrate financial strength and governance quality consistently, not merely at the time of application.
For the complete regulatory text and detailed provisions, download the official RBI notification below.
2. RBI Strengthens Responsible Business Conduct for UCBs: Recovery of Loans and Engagement of Recovery Agents
RBI’s Responsible Business Conduct Fourth Amendment Directions, 2026 introduce a more detailed framework governing loan recovery and the engagement of recovery agencies by Urban Co-operative Banks. The Directions are scheduled to become effective from 1 January 2027. The newsletter describes the amendment as an important move towards a recovery ecosystem that is effective for banks while remaining respectful and fair towards borrowers. The regulatory message is clear: a bank’s right to recover legitimate dues does not permit intimidation, harassment or uncontrolled conduct by third-party agents.
A Formal Recovery Policy Becomes Central
Every UCB should have a structured recovery framework approved at the appropriate level. The policy should clearly address when recovery action can begin, how matters are escalated, how stressed borrowers are handled, what standards recovery personnel must follow and how external recovery agencies are selected and monitored. A good policy should also define responsibilities within the bank. Recovery cannot be treated as an activity that is completely outsourced once an external agency is appointed. The bank remains responsible for the conduct of the recovery process and should have mechanisms to identify and correct non-compliant behaviour.
Due Diligence of Recovery Agencies
Before engaging an agency, a UCB should conduct proper due diligence and satisfy itself regarding the agency’s background, competence and suitability. Monitoring should continue throughout the engagement. The bank should also ensure that agents receive appropriate training and understand the applicable code of conduct. Performance incentives should not be structured in a way that indirectly encourages harassment or aggressive recovery. This is particularly important because outsourcing an activity does not mean outsourcing regulatory accountability.
Borrower Protection and Permitted Contact Hours
The Directions place substantial emphasis on respectful customer treatment. Recovery personnel should not threaten, intimidate or publicly embarrass borrowers. Excessive calling, abusive communication, intrusion into privacy and misuse of social media are incompatible with responsible recovery conduct. The newsletter highlights an important operational requirement: borrower contact for recovery should ordinarily take place only between 8:00 AM and 7:00 PM. UCBs should therefore review automated calling systems, branch-level practices and third-party agency instructions to ensure that their processes comply with the permitted contact framework.
Advance Information and Transparency
Where a recovery agency is assigned for an in-person visit, borrowers should be appropriately informed. Banks should maintain accurate and updated information about the agencies they use and retain suitable records of recovery-related communications.
Clear identification of authorised personnel reduces the risk of impersonation, fraud and disputes while also giving the borrower clarity regarding who is acting on behalf of the bank.
Grievance Redressal
The amendment also makes grievance management an important part of the recovery framework. Borrowers should have access to a mechanism through which they can report inappropriate behaviour or disputes arising from recovery action. Complaints should not simply be forwarded to the same recovery agency. The bank should retain independent oversight and take corrective action where needed.
Technology-Based Recovery Measures
Technology is increasingly being used in loan servicing and recovery. Where restrictions on financed devices or other technology-enabled measures are used, institutions need appropriate safeguards regarding prior notice, essential functionality, privacy and reversal of restrictions after the borrower makes the required payment. This reflects an important principle: technology may improve recovery efficiency, but it should not bypass fundamental standards of fairness and proportionality.
What UCBs Should Do Before 1 January 2027
UCBs should use the implementation period to:
- Review and formally approve their recovery policy.
- Reassess every empanelled recovery agency.
- Update agreements and codes of conduct.
- Train branch staff and recovery personnel.
- Review calling systems and permitted contact hours.
- Establish or strengthen recovery-related grievance mechanisms.
- Review data confidentiality and call-record maintenance.
- Examine technology-based recovery practices.
The amendment therefore goes beyond restricting aggressive recovery. It seeks to institutionalise accountability, borrower dignity and Board-level oversight throughout the recovery lifecycle.
For the complete regulatory text and detailed provisions, download the official RBI notification.
3. RBI Draft Concentration Risk Management Directions for Rural Co-operative Banks
RBI’s draft Rural Co-operative Banks – Concentration Risk Management Directions, 2026 seek to strengthen prudential controls over how Rural Co-operative Banks distribute their exposures across borrowers, groups and sectors. The Directions are proposed to take effect from 1 April 2027 and would apply to State Co-operative Banks and Central Co-operative Banks.
The logic behind concentration-risk regulation is straightforward: even a bank with a large loan portfolio can become vulnerable if too much of that portfolio is concentrated in one borrower, a connected group or a single sector.
What Is Concentration Risk?
Suppose a bank has ₹1,000 crore of loans. If a very large part is lent to one corporate group or one vulnerable sector, a problem affecting that borrower or sector could have a disproportionate effect on the bank. Concentration risk therefore arises when exposures are insufficiently diversified. RBI’s draft seeks to reduce this vulnerability through specific exposure limits, stronger Board-approved policies and greater monitoring of sectoral concentrations.
Single and Group Counterparty Limits
Under the draft, total exposure to a single counterparty should not exceed 20% of Tier-I capital, while exposure to a group of counterparties should not exceed 25% of Tier-I capital. The draft also provides a separate ceiling for exposure to a single Primary Agricultural Credit Society, subject to applicable provisions. These limits make diversification a regulatory requirement rather than merely a matter of internal preference.
Sectoral Exposure
RCBs would be expected to identify the sectors and sub-sectors to which they are exposed and establish internal limits based on their business model, sector performance and perceived risk. This means that Boards cannot simply monitor individual large accounts. They also need to ask whether the bank is becoming excessively dependent on one industry, economic activity or borrower segment.
Real Estate Exposure
The draft proposes that aggregate exposure to the real estate sector should not exceed 15% of total loans and advances. Within this limit, exposure to real estate other than housing loans to individuals would be subject to a tighter ceiling. This is especially relevant because property-sector exposures can become highly correlated during economic stress. A downturn can simultaneously affect developers, property values and borrower repayment capacity.
Unsecured Advances
Aggregate unsecured advances are proposed to be limited to 15% of total loans and advances. Unsecured lending carries higher loss risk because the bank has limited or no enforceable collateral against which to recover its dues if a borrower defaults. The proposed ceiling therefore encourages RCBs to maintain a more balanced credit portfolio.
Inter-Bank Deposits
The draft also proposes limits on deposits maintained by an RCB with another bank. Deposits with any single bank should not exceed the prescribed percentage of Tier-I capital, subject to specified exemptions. The principle is the same: a bank should not create an excessive concentration merely by moving exposure from borrowers to another financial institution.
Role of the Board
One of the most important aspects of the draft is the Board’s responsibility. Every RCB would need a comprehensive, Board-approved policy covering:
- Exposure limits for individual counterparties.
- Exposure limits for groups of connected counterparties.
- Criteria for identifying connected groups.
- Sector and sub-sector limits.
- Monitoring and escalation procedures.
This shifts concentration-risk management from a purely credit-department issue to an institution-wide governance responsibility.
What Happens to Existing Breaches?
If an exposure is already above the proposed limit when the Directions become effective, the draft provides transitional treatment instead of necessarily requiring immediate repayment. Fresh limits generally should not be sanctioned while the exposure remains above the regulatory ceiling. Existing term facilities can run down according to their original terms in specified circumstances, while revolving facilities may need to be rationalised over a defined period. This approach allows banks to move towards compliance without creating unnecessary disruption for existing borrowers.
Three Numbers RCB Boards Should Remember
| Risk Area | Proposed Ceiling |
|---|---|
| Single counterparty | 20% of Tier-I capital |
| Group of counterparties | 25% of Tier-I capital |
| Aggregate real estate exposure | 15% of total loans and advances |
These were also highlighted in Issue 2 because they communicate the core prudential direction of the draft particularly clearly.
For the complete regulatory text and detailed provisions, download the official RBI notification below.
4. RBI Draft Interest Rates on Loans and Advances Directions, 2026
RBI’s draft Interest Rates on Loans and Advances Directions, 2026 propose a more harmonised framework for how regulated entities determine, document and disclose lending rates. The framework covers several classes of regulated entities, including UCBs, and is proposed to become effective from 1 April 2027.
The broader objective is to make lending rates more transparent, consistent and linked to identifiable benchmarks and borrower risk.
Board-Approved Interest Rate Policy
Every regulated entity would be required to maintain a comprehensive policy on interest rates for loans and advances, approved by its Board or an appropriately delegated Board committee.
The policy should explain:
- How the benchmark is determined.
- How the spread is calculated.
- Which loan categories are used.
- Who has authority to approve or vary pricing.
- How risk is reflected in the final interest rate.
The policy should also be periodically reviewed. For UCBs, this means loan pricing should be supported by a documented methodology rather than being driven only by branch-level discretion or informal commercial considerations.
The Basic Pricing Formula
At a simplified level, RBI’s proposed framework can be understood as:
Applicable Loan Rate = Benchmark + Risk-Based Spread; The benchmark represents the base reference rate, while the spread captures additional costs and risks associated with the borrower or facility.
Fixed and Floating Rate Loans
Both fixed-rate and floating-rate loans may be offered. For fixed-rate loans, the rate remains fixed in accordance with the agreed structure. For floating-rate facilities, the rate changes primarily when the underlying benchmark resets. Where a loan combines fixed and floating periods, the appropriate rules apply separately during the respective periods.
What Can Form Part of the Spread?
The proposed framework recognises various components, including:
- Credit Risk Premium, reflecting the borrower’s probability of default, expected loss, collateral and other mitigants.
- Operating Cost, representing costs involved in raising funds and servicing the loan.
- Term Premium, reflecting the tenor of the facility.
- Business Strategy Premium, reflecting factors such as competition, expected returns and liquidity.
A crucial point is that the credit risk premium should be linked to genuine changes in the borrower’s credit profile rather than being modified arbitrarily.
Benchmark Reset for Floating Loans
For floating-rate facilities, the benchmark and its reset methodology should be clearly disclosed in the loan documentation. RBI’s proposed framework also places limits on how long a benchmark can remain unchanged for certain institutions and loans, while providing specific relaxations to smaller UCBs and other categories. The result should be greater predictability for borrowers because the basis on which their rate changes would be known in advance.
Daily Reducing Balance
Interest is proposed to be calculated on a daily reducing balance basis. This means that interest should reflect the actual outstanding principal rather than continuing to be calculated on an amount that has already been repaid. For borrowers, this improves fairness. For banks, it requires accurate and consistent system configuration.
Special Protection for Small Loans and Agricultural Borrowers
The draft also includes specific safeguards for certain small-value and agricultural loans. For microfinance and qualifying small-value loans, regulated entities would be required to establish an appropriate ceiling on the Annual Percentage Rate, including interest and applicable charges, so that pricing does not become usurious. For specified short-term agricultural lending to small and marginal farmers, the total interest and other fees should not exceed the principal amount, subject to the conditions contained in the proposed Directions.
Transition for Existing Loans
One of the most operationally important provisions is the proposed transition of existing loans. Loans linked to earlier internal or external benchmarks are proposed to be migrated to the new interest-rate framework by 1 April 2029 through a one-time mapping exercise.
Importantly:
- Borrower consent should be obtained.
- The migration should not leave the borrower at a disadvantage in terms of the applicable interest rate.
- The regulated entity should not levy migration charges.
This gives institutions time to update technology, documentation and customer communication without requiring an overnight change to their entire loan book.
Why This Matters for UCBs
For a UCB, implementation will involve much more than revising a policy. It may require changes across:
Board policy → ALM/Treasury → Credit underwriting → Loan documentation → Core Banking System → Customer disclosures → Internal audit.
The institutions that begin mapping these dependencies early will be much better positioned for implementation.
For the complete regulatory text and detailed provisions, download the official RBI notification below.
5. RBI ECBA Framework for UCBs: A Roadmap for Stronger Governance and Sustainable Growth
The Eligibility Criteria for Business Authorisation (ECBA) framework represents another important change for Urban Co-operative Banks. The framework links business authorisations and expansion opportunities with measurable indicators of financial soundness, governance and operational preparedness. Issue 2 presents ECBA as a roadmap for stronger governance and sustainable growth. The central principle is simple: a bank seeking greater operational freedom should first demonstrate that it is financially and institutionally ready for that expansion.
ECBA Replaces the Earlier FSWM Approach
The new ECBA regime replaces the earlier Financially Sound and Well Managed (FSWM) framework as the basis for assessing UCB eligibility for specified business authorisations. Under ECBA, financial strength and governance are evaluated through objective conditions rather than relying on a broad or subjective notion of soundness.
Core Financial and Governance Conditions
Important conditions include:
| Parameter | ECBA Expectation |
|---|---|
| CRAR | Applicable regulatory minimum must be maintained |
| Net NPA | Not more than 3% |
| Profitability | Net profit during the preceding two financial years |
| Accumulated losses | Nil |
| CRR/SLR | No default during the relevant current/preceding period |
| Core Banking Solution | Fully implemented |
| Supervisory status | No specified RBI/NABARD supervisory/PCA restrictions |
| Professional directors | At least two, where applicable to UCBs |
The framework therefore evaluates more than profitability. A UCB also needs sound asset quality, adequate capital, proper liquidity compliance, technology readiness and effective governance.
Annual Assessment
ECBA eligibility is assessed using the audited financial statements as at 31 March of the immediately preceding financial year. This makes financial-year-end data particularly important. Banks planning to seek business authorisation cannot wait until the date of application to correct weaknesses; they need to maintain their position consistently.
Board Responsibility
The Board should review and approve the bank’s ECBA status. This is important because business expansion should not be treated solely as a management decision.
The Board should understand:
- Whether the bank satisfies each ECBA condition.
- Whether any deterioration is likely.
- Whether the proposed expansion is consistent with capital and operational capacity.
- Whether systems and governance can support a larger footprint.
Compliance Validity
Once assessed, ECBA status remains valid for the specified period under the framework, subject to the applicable annual review requirements. This creates a regular discipline around eligibility rather than a one-time certification.
Business Expansion
For eligible UCBs, ECBA can facilitate applications for new branches, ATMs and processing centres. Larger Tier 3 and Tier 4 UCBs meeting prescribed conditions may also obtain greater flexibility regarding expansion beyond their state of registration. This makes ECBA commercially important. A strong compliance position can directly affect the bank’s ability to expand.
What ECBA Means Strategically
ECBA connects regulatory compliance with business strategy. Capital adequacy, NPAs, profitability, liquidity, CBS implementation and governance are no longer merely compliance numbers. They can determine whether a bank is able to grow.
For Boards, the question should therefore move from:
“Are we compliant today?” to: “Are our financial and governance metrics strong enough to support where we want the bank to be tomorrow?”
That is arguably the most important strategic implication of ECBA.
6. Amit Shah Calls for Stronger Cybersecurity and 24/7 Cyber Surveillance for UCBs
Cybersecurity has become one of the most important operational risks facing the co-operative banking sector. Issue 2 highlights the announcement regarding 24/7 cyber surveillance for Urban Co-operative Banks and the emphasis placed on stronger cyber preparedness. This development should be viewed against the rapid digitisation of banking. Even smaller UCBs now rely extensively on Core Banking Solutions, payment networks, internet connectivity, vendors, data centres and digital service providers. As dependence on technology increases, a cyber incident is no longer simply an “IT problem”. It can become a business continuity, customer protection, financial, reputational and governance problem.
Why 24/7 Surveillance Matters
Cyber threats do not operate according to banking hours. Malware, phishing, credential theft, suspicious transactions, network intrusions and technology failures can arise at any time. A monitoring environment that operates continuously can help identify abnormal events quickly and reduce the time between detection and response. This matters because the financial impact of a cyber incident can increase significantly if suspicious activity remains unnoticed.
Real-Time Threat Detection
Effective cyber surveillance should allow institutions to identify events such as:
- Unusual login activity.
- Suspicious network traffic.
- Repeated failed access attempts.
- Malware alerts.
- Abnormal payment patterns.
- Unauthorised changes to systems.
- Potential data exfiltration.
However, generating alerts is only the first step. Banks need a clear process for reviewing and escalating those alerts.
Rapid Incident Response
A cyber-monitoring system has limited value if an alert is generated but nobody is authorised or prepared to act.
UCBs therefore need clearly defined incident-response procedures covering:
- Identification of the event.
- Initial assessment.
- Containment.
- Escalation.
- Recovery.
- Regulatory reporting where applicable.
- Root-cause analysis.
- Corrective action.
Regular cyber drills can help verify whether these procedures work in practice.
Staff Capability Is Equally Important
Cybersecurity is not purely a technology investment. Human behaviour remains a major source of cyber risk. Employees should therefore be trained to recognise phishing attempts, suspicious attachments, credential theft, social-engineering attacks and unusual customer activity. Senior management and Boards also need sufficient understanding to ask meaningful questions about cyber risk.
Third-Party Technology Risk
Many UCBs use vendors for CBS platforms, payment applications, data centres, cloud services, cybersecurity tools and other critical infrastructure. The bank cannot assume that cybersecurity becomes the vendor’s responsibility merely because a system is outsourced. Contracts, service levels, audit rights, incident-reporting obligations, data-security standards and business-continuity arrangements should therefore be reviewed carefully.
Board-Level Governance
Cybersecurity increasingly belongs on the Board agenda.
The Board does not need to become a technical team, but it should understand:
- The bank’s critical systems.
- Major cyber vulnerabilities.
- Key third-party dependencies.
- Incident-response readiness.
- Backup and recovery arrangements.
- Whether major audit findings remain unresolved.
- Whether management has sufficient specialist resources.
The central message of this development can therefore be summarised in one sentence:
Cybersecurity today is not only an IT function; it is part of institutional governance and customer trust.
7. Mission SAKSHAM: Scaling Capability Through Co-operation
RBI Deputy Governor Shri Swaminathan J.’s speech on 25 August 2026 places capability-building at the centre of the future of Urban Co-operative Banks. Mission SAKSHAM recognises a practical challenge: UCBs may differ enormously in size, but they increasingly operate in the same complex digital and interconnected banking environment. As the RBI speech explains, customers expect convenient and reliable digital banking regardless of whether they are dealing with a large commercial bank or a smaller UCB. Technology dependence, cyber threats, digital fraud and outsourcing have consequently changed the nature of risk for UCBs.
A Small Bank Can Face Large Risks
Historically, banking complexity was often associated with institutional size: larger balance sheets, more branches and broader geographical operations generally implied greater complexity. Technology changes this assumption.
A small UCB may depend on:
- A third-party Core Banking Solution.
- External payment applications.
- Remote data centres.
- Cloud or technology service providers.
- Digital customer interfaces.
A cyber incident affecting one of these systems can disrupt the bank even if the bank itself has only a limited physical presence. As RBI succinctly explained in the Mission SAKSHAM speech, a bank may be local, but its risk environment is not.
Outsourcing Does Not Transfer Responsibility
A vendor may operate an important system, but the responsibility for understanding the risk and maintaining suitable safeguards continues to rest with the bank. Boards and senior management therefore need sufficient internal knowledge to oversee outsourced arrangements effectively. This does not mean every UCB must employ large teams of technology, cybersecurity, compliance and risk specialists. For many smaller banks, that would be uneconomical. Instead, RBI’s approach recognises the value of shared capability.
Co-operation Beyond Traditional Co-operative Banking
Mission SAKSHAM gives the idea of co-operation a modern extension. Historically, co-operation in a UCB referred mainly to the relationship between the institution and its members.
Today, UCBs may also benefit from co-operating with one another through:
- Common technology infrastructure.
- Shared specialist expertise.
- Sector-level cybersecurity arrangements.
- Common training platforms.
- Standardised learning resources.
The National Urban Co-operative Finance and Development Corporation, as an umbrella organisation, can play an important role in supporting these common capabilities.
Mission SAKSHAM at a Glance
Mission SAKSHAM was launched by RBI on 28 April 2026 and seeks to reach around 1.4 lakh participants across the UCB sector. The initiative recognises that capability needs differ according to a person’s role.
The five learning groups are:
| Learning Group | Primary Focus |
|---|---|
| Board Members | Governance, oversight and strategic understanding |
| Senior Management | Leadership, decision-making and risk management |
| Heads of Assurance Functions | Compliance, audit and control effectiveness |
| IT Technical Employees | Technology and operational resilience |
| Other Employees | Role-relevant institutional capability |
The learning model combines physical programmes with online learning through the NUCFDC platform.
Early Participation
RBI’s August speech noted significant participation in Telangana. All 48 UCBs in the State had already been represented in at least one Mission SAKSHAM programme, while more than 100 directors, including chairpersons, were participating in the programme referred to in the speech. These figures are useful, but RBI made an even more important point: the success of SAKSHAM should not ultimately be judged by the number of programmes held or certificates issued. Its real value will be determined by whether training produces better understanding, better decisions and stronger institutions.
“Capacity Is Best Built Before It Is Tested”
This is perhaps the most valuable governance message from Mission SAKSHAM. Capability-building should not start only after a supervisory problem, cyberattack or compliance failure occurs.
Banks should continuously ask:
- What capabilities must we retain internally?
- Which critical functions depend on outside providers?
- Do we understand those dependencies?
- Can we properly supervise our vendors?
- Where can common platforms and shared expertise improve our capabilities?
RBI’s concluding message is especially relevant for smaller institutions: an institution may be small, but its capability need not be.
Although each development discussed above covers a different area, they collectively reveal several recurring regulatory expectations.
1. Governance is becoming more operational
Boards are increasingly expected to understand how policies work in practice. Approving a policy once a year is no longer sufficient if recovery agents, lending systems, technology vendors or branches do not follow it effectively.
2. Growth will increasingly depend on regulatory readiness
The on-tap licensing proposals and ECBA framework demonstrate that expansion opportunities will be linked to financial and governance quality. A UCB that wants to grow must therefore treat compliance as part of its growth infrastructure.
3. Technology risk is now banking risk
Cybersecurity, digital resilience and outsourcing are no longer specialist concerns for the IT department alone. They require Board oversight, management accountability and continuous monitoring.
4. Policies need measurable controls
Whether the topic is recovery practices, interest-rate pricing or concentration risk, RBI is increasingly requiring institutions to move from broad principles to clearly measurable frameworks. Banks should therefore ask not only, “Do we have a policy?” but also, “Can we demonstrate that the policy is working?”
5. Capability-building must be continuous
Regulation, technology and customer expectations are evolving too quickly for training to remain a one-time exercise. Mission SAKSHAM reinforces the importance of continuous learning across Boards, management, assurance functions, IT teams and operational staff.
For the complete regulatory text and detailed provisions, download the official RBI notification below.





