The Reserve Bank of India (RBI) has recently mandated Kotak Mahindra Bank to halt the acquisition of new customers via online channels and mobile banking platforms. Additionally, the RBI mandated the bank to stop issuing fresh credit cards.
This action was taken under Section 35A of the Banking Regulation Act, 1949, which empowers the RBI to intervene if it deems that the operations of a banking company are detrimental to the interests of depositors or prejudicial to the interests of the banking company itself.
Reasons behind the directive
The RBI’s directive stemmed from concerns regarding data security and deficiencies in the IT infrastructure of Kotak Mahindra Bank for the years 2022 and 2023. Despite being made aware of these issues, the bank needed to adequately address them, leading to the directive.
Specifically, serious deficiencies and non-compliances were noted in areas like IT inventory management, patch and change management, user access management, vendor risk management, data security, data leak prevention strategy, and business continuity and disaster recovery procedures.
The central bank took decisive action due to Kotak Mahindra Bank’s failure to meet the standards set for managing IT risks and ensuring information security for two consecutive years, as required by RBI regulations.
Despite being provided with specific plans to rectify these issues; the bank was found to have yet to address them upon reevaluation by the RBI. Additionally, the reports submitted by the bank to the RBI were deemed inadequate, inaccurate, or unsustainable over time.
As per the RBI, Kotak Mahindra Bank experienced numerous significant outages in its core banking system and online services over the preceding two years, attributed to insufficient IT infrastructure and risk management.
Notably, a significant service disruption occurred on April 15, causing inconvenience to the bank’s customers. These disruptions were a result of the bank’s inability to establish robust IT systems and controls commensurate with its expansion.
Impact on Existing Customers
As per RBI, Existing customers of Kotak Mahindra Bank will continue to receive services as usual, including those with credit cards. Despite the directive, the bank’s branches will still cater to new customers, offering them all available services except for the issuance of new credit cards, as stated by Kotak Mahindra Bank in a released statement.
Bank’s Commitment
Furthermore, the bank emphasized its commitment to enhancing its IT systems by adopting new technologies and pledged to collaborate with the RBI to promptly address any outstanding issues. Kotak Mahindra Bank sought to reassure its current customers of uninterrupted access to services, encompassing credit cards, mobile banking, and net banking functionalities.