The Reserve Bank of India imposed approximately ₹27 crore in monetary penalties across 40 enforcement actions against scheduled commercial banks in calendar year 2025, marking the highest per-penalty average in recent years. The actions, disclosed through individual press statements published by the RBI for each case, spanned a wide range of compliance failures including Know Your Customer lapses, cybersecurity shortcomings, credit card conduct breaches, and governance gaps across the banking sector.
Private sector banks bore the greater share of the aggregate penalty bill, paying ₹16.28 crore compared with ₹8.78 crore for their public sector counterparts — nearly double the state-owned banks' total. Jammu and Kashmir Bank incurred the single largest penalty among private lenders at ₹3.31 crore, while State Bank of India was the most heavily fined public sector bank at ₹1.72 crore during the period.
BREAKDOWN BY INSTITUTION AND VIOLATION TYPE
Among foreign banks operating in India, HSBC attracted the highest penalty at ₹66.60 lakh, relating to KYC and regulatory compliance lapses identified during the supervisory examination process. Small finance banks accounted for more than ₹2.5 crore of the year's total, with Jana Small Finance Bank recording the largest individual fine in that segment at ₹1 crore, reflecting the RBI's broadening enforcement reach across all bank categories.
The 40 enforcement actions spanned seven broad violation categories: KYC and customer due diligence failures, cybersecurity framework breaches, credit card and debit card conduct issues, collateral and loan-to-value ratio breaches, current account discipline lapses, shortfalls in priority sector lending, and governance deficiencies. The RBI stated in its penalty notifications that all actions were based on findings from its Statutory Inspection for Supervisory Evaluation process and were not intended to cast doubt on the validity of any customer transactions or contractual arrangements.
The diversity of violation types across the 40 actions suggests that the RBI's supervisory examination teams are applying a broad lens in their assessments, reviewing everything from frontline customer-facing processes such as account opening and card issuance to backend technology controls and board-level governance arrangements. No single category of breach dominated the year's enforcement output.
ENFORCEMENT POSTURE AND INDUSTRY IMPLICATIONS
The 2025 penalty data places the RBI among the more active banking supervisors in Asia in terms of the frequency and breadth of formal enforcement actions. Forty penalty actions across a single calendar year, covering both large national banks and smaller specialised lenders, reflects a supervisory posture that treats monetary penalties as a routine tool rather than reserving them only for the most egregious or repeated breaches of regulatory requirements.
For the banking industry, the pattern of violations — and the institutions named — provides a compliance roadmap of the areas the RBI is examining most closely. Cybersecurity frameworks and KYC processes appear repeatedly across the actions, consistent with broader regulatory concerns about data protection and financial crime risks in an increasingly digital banking environment where the volume and velocity of customer onboarding has grown substantially.
Banks that have received penalties are expected to remediate the identified deficiencies and demonstrate to the RBI that corrective action has been taken, typically through a formal response to the regulator setting out the steps undertaken. Repeat violations or failure to address issues identified in prior inspections can attract more severe regulatory consequences, including restrictions on specific business activities.