The Reserve Bank of India imposed monetary penalties on five scheduled commercial banks in May 2025 in a coordinated enforcement action covering cybersecurity failures, Know Your Customer lapses, and a range of other conduct and governance breaches. ICICI Bank received the largest individual fine at ₹97.80 lakh, followed by Bank of Baroda at ₹61.40 lakh, while Axis Bank, IDBI Bank, and Bank of Maharashtra each faced penalties of approximately ₹29 to ₹32 lakh.

The RBI stated that all five actions were based on findings from its Statutory Inspection for Supervisory Evaluation process and that the penalties were not intended to pronounce on the validity of any transactions entered into by these institutions with their customers. The simultaneous publication of multiple penalty orders reflects the RBI's practice of conducting coordinated supervisory examination cycles across the banking system.

VIOLATIONS ACROSS THE FIVE LENDERS

ICICI Bank's ₹97.80 lakh penalty encompassed the broadest range of violations, spanning the RBI's Cyber Security Framework, Know Your Customer directions, and the Credit Card and Debit Card Issuance and Conduct directions. The breadth of the violations across three distinct regulatory frameworks suggests that the RBI's inspection team identified systemic compliance gaps rather than isolated, one-off failures.

Bank of Baroda was penalised ₹61.40 lakh for contraventions of provisions relating to financial services and customer service norms. Axis Bank's ₹29.60 lakh fine related to the unauthorised operation of internal accounts, a category of breach that points to weaknesses in internal controls and account governance processes. IDBI Bank received a ₹31.80 lakh penalty connected to the Kisan Credit Card interest subvention scheme, while Bank of Maharashtra was fined the same amount for KYC-related deficiencies.

The mix of institutions — spanning large private sector banks, public sector lenders, and a development finance institution — underscores that the RBI's supervisory scrutiny applies uniformly across ownership categories. Neither the size of the institution nor its state ownership provides a shield against formal penalty action when inspection findings indicate regulatory breaches.

ENFORCEMENT SIGNALS AND COMPLIANCE EXPECTATIONS

The multi-bank enforcement action is consistent with the RBI's stated approach of using the Statutory Inspection for Supervisory Evaluation findings as the evidentiary basis for penalty orders. The regulator's willingness to act against major institutions including ICICI Bank — India's largest private sector lender by assets — reinforces that penalties are not reserved for smaller or weaker banks.

Cybersecurity compliance has emerged as a particular area of focus in recent RBI examinations, reflecting the rapid digitalisation of banking services in India and the corresponding increase in technology-related risk. Banks are expected to maintain robust cyber defences, incident response capabilities, and controls over customer data, and inspection teams are increasingly allocating significant examination resources to assessing these areas.

Each of the five banks will be required to respond formally to the RBI, demonstrating that the identified deficiencies have been addressed through specific corrective actions. The regulator typically expects institutions to confirm remediation within a defined period and may conduct follow-up reviews to verify that the measures taken are effective. For banks that have received penalties across multiple regulatory frameworks in a single action, the compliance remediation workload is correspondingly more complex.