RBI Governor Shri Sanjay Malhotra, speaking at the Global Fintech Fest (GFF) 2026 in Mumbai on 10 September 2026, announced the recognition of United FinTech Forum as the second Self-Regulatory Organisation (SRO) for the fintech sector and unveiled the tokenisation of corporate bonds with settlement through Central Bank Digital Currency (CBDC), a joint initiative with SEBI. The Governor also set out RBI's approach to AI, data fiduciary duties, proportionate activity-based regulation, and forthcoming work including the FREE-AI Committee recommendations, a draft Model Risk Management framework, and the newly constituted Q-SAFE Committee on quantum resilience.
What Was Announced at GFF 2026?
Amid broader remarks on trust and technology, the Governor made two announcements with direct, actionable significance for the fintech and capital-markets ecosystem.
📝 In Plain English: An SRO is an industry body that the RBI formally recognises to set baseline conduct standards for its members and to act as a structured channel between the industry and the regulator — it supplements, but does not replace, RBI's own regulation. Bond tokenisation means representing ownership of a corporate bond as a digital token on a shared ledger, with the actual money settlement happening through the RBI's digital currency (CBDC) rather than the conventional banking settlement rails.
Why This Matters
The corporate bond tokenisation initiative signals that RBI and SEBI are moving from pilot-stage exploration of tokenised instruments (which began with wholesale CBDC-settled Certificates of Deposit) into a second, more complex asset class. For compliance and treasury teams at NBFCs, banks and corporates that issue or hold bonds, this is an early indicator of where settlement infrastructure is headed, even though participation at this stage is expected to remain limited and pilot-driven rather than mandatory market-wide.
The second SRO recognition matters because RBI has consistently used the SRO framework as its preferred instrument for extending governance to the large population of fintechs that sit outside direct prudential regulation. Fintechs not yet regulated by RBI may increasingly find SRO membership relevant to market credibility and stakeholder engagement, even where formal membership is not compulsory.
Who Should Pay Attention to This Speech?
- Fintech companies — for signals on SRO expansion, activity-based regulation, and RBI's expectations on AI risk and data handling.
- Banks and NBFCs — for the Governor's framing of "too significant to be careless" as scale increases, and for developments in AI governance and model risk management.
- Capital market intermediaries and bond-market participants — for the corporate bond tokenisation initiative with SEBI.
- Payment aggregators and lending platforms — for references to the Unified Lending Interface (ULI), Account Aggregator framework and MuleHunter.ai.
- Compliance and risk functions generally — for early visibility into the FREE-AI Committee recommendations, the draft Model Risk Management framework, and the Q-SAFE Committee on quantum resilience, all of which may translate into binding guidance in future.
Entities with no exposure to fintech, digital lending, payments or bond markets are unlikely to be directly affected by anything in this speech.
It is also worth noting the framing the Governor placed around all of this: he described financial inclusion as fintech's single most important purpose, and specifically flagged that industry effort still gravitates toward customers who are already banked and digitally visible, urging fintechs to keep the "last mile" — informal-sector savings, micro-insurance, small-ticket credit, and credit for women entrepreneurs and small farmers in tier-3/tier-4 towns — as a central focus rather than a footnote.
The Governor's Four Ingredients of Trust
A substantial part of the address was devoted to what the Governor called the "operating discipline" of trust. He identified four elements he considers indispensable for fintechs and regulated entities alike.
1. Mitigating AI-specific risks. The Governor flagged opacity, bias and exclusion, concentration and herding, cybersecurity, data privacy and security, and erosion of human judgement as risks that must be managed to sustain consumer trust in AI-driven financial services.
2. Treating data as a fiduciary responsibility, not a business asset. He held up the Account Aggregator framework — consent-based, purpose-limited data sharing where no single entity, including the aggregator, can see or exploit the underlying data — as the architecture fintechs should internalise as a value rather than merely comply with as a rule.
3. Systemic responsibility that scales with size. Fintechs outside the prudential perimeter face proportionately lighter obligations while small, but as payment volumes, lending books or user bases grow to a point where disruption could affect the financial system, the firm acquires responsibility beyond its balance sheet — described as being "too significant to be careless."
4. Engaging early rather than exploiting regulatory gaps. The Governor cautioned against structuring business models around gaps between regulatory categories, or scaling first and seeking clarity later, pointing instead to RBI's sandbox and pilot mechanisms as the intended route for testing new models under supervision.
Practical Example: A lending fintech growing rapidly through an unregulated NBFC-partnership model might, under this framing, expect RBI's supervisory attention to increase well before its balance sheet triggers any formal registration threshold, simply because its systemic footprint has grown — this is illustrative of the Governor's stated philosophy, not a specific rule announced in the speech.
RBI's Stated Regulatory Philosophy: Activity-Based and Proportionate
The Governor articulated the regulatory principle underlying RBI's current approach to fintech as "same activity, same risk, same regulatory treatment," applied regardless of which type of entity performs the activity, and calibrated to the capacity of different institutions. He described this as deliberately light-touch where innovation is nascent and risk is contained, with RBI stepping in only once an activity scales to systemic significance or raises consumer-conduct concerns.
For compliance teams, this is best read as a statement of regulatory intent and direction rather than a new enforceable standard. It is, however, useful context for interpreting how RBI is likely to approach future rulemaking on lending, payments and data-sharing activities carried out by non-bank entities.
Digital Public Infrastructure and Tools Referenced
The Governor listed several existing and upcoming RBI initiatives that fintechs and financial institutions are expected to build on:
- Regulatory Sandbox — now on-tap with an open cohort, allowing continuous applications rather than fixed cohort windows.
- HaRBInger hackathon — RBI's annual global hackathon addressing real-world financial sector challenges.
- Unified Lending Interface (ULI) — common digital rails for consent-based, frictionless credit delivery.
- Account Aggregator framework — consent-based financial data sharing infrastructure available for fintechs to build upon.
- MuleHunter.ai — RBI's own AI-based digital fraud-detection system.
- Digital Payments Intelligence Platform (DPIP) — described as a proposed platform to further strengthen fraud prevention.
- Programmable CBDC pilots — ongoing pilots exploring targeted government benefit transfers, including under the Pradhan Mantri Garib Kalyan Anna Yojana.
- Tokenised Certificates of Deposit — issued through the Unified Markets Interface using wholesale CBDC, the precursor to the newly launched corporate bond tokenisation initiative.
What Should Practitioners Watch?
None of the following have been notified as binding requirements. They are forward-looking references from the speech that compliance and risk teams should track as they progress toward formal frameworks.
- FREE-AI Committee recommendations — RBI's committee output on AI in financial services; likely to inform future guidance.
- Draft framework on Model Risk Management — referenced as a work in progress, relevant to institutions deploying AI/ML-based credit, fraud or pricing models.
- Comprehensive AI governance framework for the financial sector — described as ongoing work, not yet finalised.
- Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE) Committee — recently constituted to examine quantum resilience of the financial sector.
Institutions using AI in credit underwriting, fraud detection or customer service, and those with exposure to long-dated cryptographic security requirements, should treat these as items to monitor for consultation papers or draft frameworks in the coming months.
Scale and Global Context Cited in the Speech
The Governor cited the following figures to illustrate the scale of India's fintech and financial inclusion story:
Beyond the numbers, the Governor framed this as an inflection point: India's first decade of fintech was largely about building for India, while the next decade is an opportunity to build for the world. He pointed to India's solutions for financial inclusion, affordable payments, digital identity and interoperable infrastructure as exportable to other emerging economies facing similar challenges, positioning India as a potential "trusted partner in shaping the future architecture of global finance."
Frequently Asked Questions
Who is United FinTech Forum, and what does SRO recognition mean for it?
United FinTech Forum has been recognised by RBI as the second Self-Regulatory Organisation for the fintech sector. This allows it to promote responsible conduct, develop industry-led baseline standards, build capacity, and serve as a structured channel of engagement between fintechs and RBI.
What is the corporate bond tokenisation initiative announced at GFF 2026?
It is a joint RBI-SEBI initiative to tokenise corporate bonds with settlement through Central Bank Digital Currency, extending RBI's earlier tokenisation work on Certificates of Deposit issued via the Unified Markets Interface.
Does this speech create any new compliance obligation?
No. This is a keynote address, not a notification, circular or amendment. It contains no new binding rule, applicability criterion, deadline or penalty.
What is RBI's stated approach to regulating fintechs of different sizes?
The Governor described RBI's approach as proportionate and activity-based — the same activity attracts the same regulatory treatment regardless of the type of entity performing it, with lighter regulation for nascent, contained-risk activity and closer supervision as an activity scales to systemic significance.
What is the Account Aggregator framework, as referenced in the speech?
It is a consent-based, purpose-limited data-sharing framework that the Governor cited as a model for treating customer financial data as a fiduciary responsibility rather than a monetisable business asset.
What is the Q-SAFE Committee?
The Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE) Committee is a recently constituted RBI committee examining the financial sector's resilience to quantum-computing-related risks.
Is the FREE-AI Committee's recommendation already implemented?
The speech references the FREE-AI Committee's recommendations as an input to RBI's ongoing work toward a comprehensive AI governance framework; it does not indicate that a final framework has been notified.
CorpLawUpdates Analysis
For compliance teams, the immediate takeaway from this speech is directional rather than actionable: no filing, form or deadline arises from it. The more durable signal is RBI's continued preference for co-opting industry through SRO structures and sandbox mechanisms rather than expanding direct prudential regulation over fintechs prematurely — a pattern likely to continue as the fintech perimeter question resurfaces with scale. Institutions running AI-based underwriting or fraud models should treat the references to the FREE-AI Committee and the Model Risk Management draft framework as the clearest advance notice yet that binding AI-governance requirements for regulated entities are being actively developed, and should begin internal readiness reviews ahead of formal consultation.
Separately, bond-market intermediaries and debt-capital-markets teams should note the corporate bond tokenisation launch as a live, joint RBI-SEBI initiative worth monitoring for participation criteria, even though the speech itself does not specify onboarding mechanics, eligible participants, or a timeline for wider rollout.
Document: "Shaping the Next Decade of Finance – Technology, Trust and Innovation"
Type: Keynote address
Speaker: Shri Sanjay Malhotra, Governor, Reserve Bank of India
Occasion: Global Fintech Festival 2026, Mumbai
Date: 10 September 2026
[INTERNAL LINK: RBI Regulatory Sandbox Framework] • [INTERNAL LINK: Account Aggregator Framework] • [INTERNAL LINK: RBI SRO Framework for Fintechs]
This article is for informational and educational purposes only and does not constitute legal or regulatory advice. Readers should verify the applicable primary regulatory source before taking action.


