Fintech is the shining example of the coming of the digital age where all financial services, from payments to opening savings accounts, accessing credit, insurance and wealth management services can be accessed from the comfort of home with a few clicks on our smartphone. Widespread use of smartphones, internet connectivity in rural areas and availability of digital public infrastructure such as Aadhaar, Aadhar-based eKYC and DigiLocker for digital identity are the key enablers of affordable financial services for people at the bottom of the pyramid. Rupa Naik, Executive Director, World Trade Center dwells on the security technologies involved and more…
Fintech is the shining example of the coming of the digital age where all financial services, from payments to opening savings accounts, accessing credit, insurance and wealth management services can be accessed from the comfort of home with a few clicks on our smartphone. Widespread use of smartphones, internet connectivity in rural areas and availability of digital public infrastructure such as Aadhaar, Aadhar-based eKYC and DigiLocker for digital identity are the key enablers of affordable financial services for people at the bottom of the pyramid.
Today, small shop owners, farmers and self-employed women in rural areas can access credit at affordable interest cost without much paperwork and collateral based on their digital payment footprint they leave on the UPI. Online aggregators and digital lending platforms have democratized access to credit and empowered borrowers by connecting them to a wide range of lenders, which helps them choose lenders based on their respective interest rate and terms of credit.
While the rapid innovation in the fintech sector has benefited masses in terms of easy availability of credit, insurance and investment services, it has also exposed consumers and the financial system to cyber attack, data leakage and other kinds of frauds.
This article underscores the critical need for collaboration among fintech firms, technology service providers and regulatory bodies to evolve a trusted, secure and resilient fintech ecosystem, based on sound data governance framework, investment in cyber security infrastructure and stringent licensing, authorization and supervision.
Cyber security Risks
As fintech ecosystem evolves rapidly, the risks of cyber security, identity theft, breach of confidentiality have assumed alarming proportion warranting heightened vigilance among regulatory organizations. With the growing instances of cyber attacks, financial institutions are investing ever more on cyber security infrastructure to safeguard their digital systems. Specifically, companies are investing on enhanced security protocols, encryption, multi-factor authentication, deployment of artificial intelligence and machine learning for early warning signals and fraud prevention or detection.
incidents such as the Cambridge Analytica data breach, theft of confidential data, including login credentials, credit card and bank account details from apps of start-ups and even well established, reputed financial institutions are well known from media reports.

Regulatory developments
While fintech companies and traditional financial institutions are doing their part by investing in robust cyber security infrastructure, the role of regulatory institutions is critical in evolving a safe and secure fintech ecosystem. Government and regulatory institutions world-wide are evolving improved data governance approach to protect data integrity.
On its part, India has evolved a Data Empowerment and Protection Architecture (DEPA) that seeks to promote technological innovation by leveraging big data, while also protecting the ownership rights of customers on their personal data. Such a data governance framework seeks to empower customers, promote economic growth through responsible fintech innovation and competitive data democracy. Specifically, this data governance framework provides for sharing of personal data of consumers, self-employed entrepreneurs, with their consent to lenders, insurance companies and wealth management entities. In order to facilitate seamless sharing of data, the Reserve Bank of India has issued regulatory framework for Account Aggregator.
Similarly, Government of India introduced the Digital Personal Data Protection Act, 2023, which will be enforced in the coming months once relevant rules are notified. Under Section 8(6) of this Act, regulated entities will have to report personal data breaches promptly to the affected data principals and the data protection board, failing which, they are liable to a fine of upto Rs. 250 crore.
Regulators across countries have different approaches and strategy for national frameworks and guidelines for digital identification system, data protection, cyber security, open banking and other aspects of the fintech sector. For instance, countries such as Australia, Argentina, Italy, Mexico and Luxembourg have prescriptive approach for open banking, while Singapore and Hong Kong have facilitative approach for open banking. Regulators in Canada, Brazil, Hong Kong, South Africa and Singapore facilitate responsible innovation in fintech sector through three initiatives, viz. innovation hub, regulatory sandbox and accelerator programs, while many other countries have either one or two of these programs to facilitate innovation. Reserve Bank of India also promotes fintech innovation through sandbox, hackathon and dedicated innovation hub.
Regulatory bodies have also evolved sound principles or guidelines for Application Programming Interfaces (APIs), Cloud Computing, Biometrics and other enabling technologies of fintech sector to protect data, ensure privacy and prevent money laundering. For instance, regulatory response have evolved in the form of guidelines for the right to audit & inspect the cyber security capability, recovery and resumption capability of cloud service providers to address any operational risks involved in outsourcing of cloud computing activity.
Regulatory best practices for secure fintech ecosystem

In this age of rapid fintech evolution, virtual banks and digital banks are competing with traditional banking entities as low cost banking service providers. Regulators across the world are responding to this innovation by deploying regulatory frameworks on licensing, authorisation and supervision of these virtual banks to protect consumers, safeguard financial stability, while also promoting responsible innovation.
Towards a trusted fintech ecosystem
The rapidly evolving fintech ecosystem comprises of three agents, viz. 1) banks & fintech companies, 2) technology service providers and 3) government & regulatory bodies. Banks and fintech companies offer innovative payments, lending, equity funding (through crowd funding platforms), wealth management and insurance services. Technology service providers offer technologies such as Application Programming Interface, Cloud Computing, Biometric, artificial intelligence and machine learning. And finally, government and regulatory authorities have responded to the fintech evolution by deploying enabling elements such as digital ID, open banking frameworks, data protection frameworks, regulatory sandbox, innovation hub and cyber security regulations.
These three agents are the pillars of the fintech ecosystem and they need to work in close coordination to build a resilient, safe and trustworthy fintech ecosystem. More specifically, regulators have a critical role in promoting healthy competition and responsible innovation in the fintech ecosystem, while also safeguarding consumer interest, data protection and financial stability.