Kotak Bank barred from onboarding customers online, issuing fresh credit cards


PTI, Apr 24, 2024, 4:52 PM IST

Mumbai: Cracking down on repeated non-compliance of IT norms, the RBI on Wednesday barred Kotak Mahindra Bank from onboarding new customers through its online and mobile banking channels and issuing fresh credit cards with immediate effect after the regulator found “serious deficiencies” in the lender’s IT risk management.

These actions, the RBI said, are necessitated based on significant concerns arising out of Reserve Bank’s IT examination of the bank for the years 2022 and 2023 and the continued failure on part of the bank to address these concerns in a comprehensive and timely manner.

In an almost similar action, the RBI in December 2020 had barred HDFC Bank from issuing new cards and launching new digital initiatives after repeated instances of technological outages at the lender. The restrictions were later lifted in March 2022.

In a statement regarding the supervisory action against Kotak Mahindra Bank, the RBI said: “Serious deficiencies and non-compliances were observed in the areas of IT inventory management, patch and change management, user access management, vendor risk management, data security and data leak prevention strategy, business continuity and disaster recovery rigour and drill, etc.”

The Kotak Mahindra Bank has been directed “to cease and desist”, with immediate effect, from onboarding of new customers through its online and mobile banking channels and issuing fresh credit cards. The bank shall, however, continue to provide services to its existing customers, including its credit card customers.

“The bank shall, however, continue to provide services to its existing customers, including its credit card customers,” RBI said.

For two consecutive years, the bank was assessed to be deficient in its IT Risk and Information Security Governance, contrary to requirements under Regulatory guidelines, the RBI added.

“During the subsequent assessments, the bank was found to be significantly non-compliant with the Corrective Action Plans issued by the Reserve Bank for the years 2022 and 2023, as the compliances submitted by the bank were found to be either inadequate, incorrect or not sustained,” the RBI said.

In the absence of a robust IT infrastructure and IT Risk Management framework, the RBI said the bank’s Core Banking System (CBS) and its online and digital banking channels have suffered frequent and significant outages in the last two years, the recent one being a service disruption on April 15, 2024, resulting in serious customer inconveniences.

“The bank is found to be materially deficient in building necessary operational resilience on account of its failure to build IT systems and controls commensurate with its growth,” the central bank said.

The RBI further said that in the past two years, it has been in continuous high-level engagement with the bank on all these concerns with a view to strengthening its IT resilience, but the outcomes have been far from satisfactory.

It is also observed that, of late, there has been rapid growth in the volume of the bank’s digital transactions, including transactions pertaining to credit cards, which is building further load on the IT systems, the Reserve Bank said.

“The Reserve Bank, therefore, has decided to place certain business restrictions on the bank as mentioned above, in the interest of customers and to prevent any possible prolonged outage which may seriously impact not only the bank’s ability to render efficient customer service but also the financial ecosystem of digital banking and payment systems,” the statement said.

The restrictions imposed will be reviewed upon completion of a comprehensive external audit to be commissioned by the bank with the prior approval of RBI, and remediation of all deficiencies that may be pointed out in the external audit as well as the observations contained in the RBI inspections, to the satisfaction of the Reserve Bank.

Further, these restrictions are without prejudice to any other regulatory, supervisory or enforcement action that may be initiated against the bank by the Reserve Bank, the central bank said.

Kotak Mahindra Bank Limited is scheduled to announce the consolidated and standalone audited financial results for the quarter and financial year ended March 31, 2024, on Saturday (May 4).

Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.

Top News

Pakistan Army Chief acknowledges role of Pak army in Kargil war

Ex-RG Kar hospital principal had criminal nexus with co-accused for wrongful gains: CBI

Udayavani.com “Nammane Krishna”: Broadcast of 15th Prize-Winning Reel

Trackman’s heroics avert major train disaster on Konkan Railway

Multi-storey building collapses in Lucknow; At least 3 killed, 20 injured; Several feared trapped

Centre discharges Puja Khedkar from Indian Administrative Service

Kannada actor Darshan to get TV in prison cell

Related Articles More

Byju’s auditor suggested backdating reports; resignation more of optics: Byju Raveendran

Wockhardt denies allegations of rent payment by Carol Info, its connection with SEBI orders

Bengaluru sees 19% hike in home sales: Report

Sensex tanks 1,017 pts to close at 2-week low tracking weak global trends

Mumbai college rejected him, Adani built $220 billion empire; delivers lecture at same college

MUST WATCH

Mysore Dasara

RakshaBandhan

Balu hotel | Banana leaf Meals

Krishna Janmashtami | Kreedothsava |

Pratap simha interview


Latest Additions

Geethartha Chinthane 30: God is not ‘partial’ but ‘all-encompassing’

Karnataka ushers in Ganesh Chaturthi with its customary fervour; political tussle over govt’s order

Pakistan Army Chief acknowledges role of Pak army in Kargil war

Kushinagar: Man forced to ‘sell’ son for hospital fee, 5 arrested

Ex-RG Kar hospital principal had criminal nexus with co-accused for wrongful gains: CBI

Thanks for visiting Udayavani

You seem to have an Ad Blocker on.
To continue reading, please turn it off or whitelist Udayavani.