By Michael Sell, Senior Vice President and Global Head, GARP
India’s digital transformation has been a key factor in its economic success in recent years. Digital public infrastructure (DPI), artificial intelligence (AI), and connected cloud platforms are now embedded in enterprise strategy and decision making, day-to-day operations, and customer service. Rapidly developing technology and the digitization of financial services add to the growing list of operational risk factors senior management and the boardroom need to understand, assess, manage, and mitigate to ensure enterprise resilience.
UPI transaction volume in India has surged nearly 12,000-fold over the last decade. Transactions valued at more than ₹314 lakh crore in FY 2025-26 YTD reflect the scale of nationwide adoption of a digital payment network that positions India among the largest in the world. India Inc.’s adoption of AI is referenced in Deloitte’s recent State of AI in the Enterprise survey noting forty (40) percent of India based firms report significant or full implementation of AI in their operations, compared with twenty-eight (28) percent globally.
That combination of scale and dependence expands the digital risks organizations are exposed to. Data quality, model risk and governance, and accountability, are critical to ensuring the integrity of lending decisions as AI models become more deeply embedded in retail credit assessment and corporate underwriting. Reliance on cloud computing creates efficiency but also introduces third-party risk as vendor dependencies extend the scope of cybersecurity vulnerabilities that can interrupt daily operations, erode customer satisfaction, and impact financial performance.
The question for business leaders is no longer whether a given technology is secure. It is how that technology changes the organisation’s risk exposure, and what that means for business strategy.
Digital Technology Risk is a Critical Business Risk
India’s regulators understand the dual challenge of staying ahead of developing technology by implementing balanced regulatory guidelines that encourage innovation while protecting market participants. The second edition of the Digital Threat Report recently published by the Ministry of Electronics and Information Technology, notes India’s digital economy is expected to contribute twenty (20) percent of GDP by 2030, making technology driven threats and cybersecurity a strategic priority for organisations and market regulators. It also points to the growing use of AI and deepfake techniques in cyber-attacks, and a widening attack surface as digital banking, cloud computing adoption, and open financial ecosystems expand.
As the Digital Threat Reports describes it, cybersecurity is no longer an IT issue; it is now a key business risk. That is precisely why managing digital risk requires the same disciplined approach applied to traditional financial risks like credit, market, and liquidity risk: identifying exposures, assessing their potential impact across the business, and implementing mitigation processes to build resilience.
Risk Belongs in the Boardroom
Applying that discipline is not always easily achieved. These risks cut across technology, operations, and finance, so managing them successfully requires an enterprise approach. That is why digital risk increasingly reaches the boardroom. Vendor concentration, cloud reliance, and critical third-party dependencies are operational details that need to be understood and communicated from the top down. They are questions of enterprise resilience and risk appetite, and they belong with the board and senior leadership, the same way business strategy and capital allocation are evaluated and implemented.
Building Risk Management Capabilities for the Digital Age
With boards increasingly responsible for risk appetite and oversight, they need frameworks that provide a holistic view of the risks they are overseeing, ones that bring technology, operational, financial, third-party, and emerging risks together rather than assessing them in silos. Effective enterprise risk programs depend on professionals who can design, implement, challenge, and continuously evolve risk governance processes as the business and technology change, professionals who can connect quantitative analysis, financial risk, operational resilience, AI and model risk, and business strategy into one coherent view.
Recent research on India’s cybersecurity workforce found nearly fifty percent (50) of enterprises struggle to hire professionals with AI risk and governance expertise, evidence of a broader gap in cross-disciplinary risk expertise, one that only continuous learning and professional development can close as technology, regulation, and markets continue evolving.
Building on India’s digital advantage and success will depend not only on how quickly organisations adopt innovative technology, but on how effectively they understand, measure, govern, and manage the risks embedded in it.