Skip to main content

      Risk and regulation are evolving rapidly as organisations navigate an increasingly complex landscape shaped by digital transformation, emerging technologies, regulatory change and heightened stakeholder expectations. As businesses become more interconnected and data-driven, risk management is moving beyond traditional compliance to focus on resilience, trust, governance and proactive risk mitigation. Organisations are increasingly required to manage a wider spectrum of risks - from cyber threats and data protection to financial crime, third-party dependencies and regulatory accountability.

      This transformation is being accelerated by the convergence of AI, data governance and evolving regulatory frameworks. Supervisory guidance around customer data protection, AI-driven cyber threats, financial crime prevention and credit risk management is reshaping how organisations identify, assess and manage risk. At the same time, businesses are leveraging new technologies such as generative AI, advanced analytics and next-generation forensic tools to strengthen investigation capabilities, enhance monitoring and improve decision-making. As risk agendas mature, the focus is shifting from reactive compliance to building credibility, transparency and enterprise-wide resilience.

      add_moderator

      Digital risk and cyber resilience

      Strengthening security, data protection and organisational resilience in an evolving threat landscape

      contact_page

      Technology-enabled risk management

      Leveraging AI, analytics and automation to enhance risk monitoring and decision-making

      security

      Regulatory compliance and governance

      Embedding transparency, accountability and trust across business operations

      At the same time, risk and regulation are increasingly being shaped by broader business, technology and ecosystem considerations.

      • Customer data protection and privacy

        Strengthening governance and data management practices 

      • AI-accelerated cyber risk management

        Enhancing safeguards against emerging digital threats

      • Transforming financial crime management

        Through generative AI and advanced analytics

      • Next-generation forensic capabilities

         Improving fraud detection, investigation and response 

      • Third-party risk management

        Strengthening oversight across increasingly interconnected ecosystems 

      • Expected credit loss and regulatory risk frameworks

        Supporting stronger financial resilience and risk assessment 

      • Workplace governance and compliance

        Integrating technology, data and operating model evolution

      • Transparency and software supply chain assurance

        Improving trust through initiatives such as  Software Bill of Materials (SBOM) frameworks

      KPMG in India empanelled by SEBI

      KPMG in India has been empanelled by the Securities and Exchange Board of India (SEBI) for assignments relating to forensic audits of listed companies.

      This empanelment reflects the strength of our forensic practice and decades of experience supporting organisations on complex investigations, financial reviews, regulatory matters and risk-related engagements.

      Latest insights

      An evidence-based assessment of illicit trade across six Indian sectors, its economic impact, enforcement challenges and the path forward

      An in-depth analysis of food safety, FSSAI compliance, cold chain management, and regulatory best practices in warehousing and distribution

      Exploring how financial institutions can strengthen grievance redressal, reduce information asymmetry, and improve customer trust

      Inspired by Aristotle’s ethics, Leonardo da Vinci’s systems thinking, and modern AI risk science

      Evolving cyber fraud and digital ecosystems demand intelligence‑led, evidence‑driven, and constantly evolving investigation models

      Driving growth with Risk and Regulations trends

      Mohit Bahl

      Partner and Head - Risk and Integrity Advisory

      KPMG in India

      Illicit trade today represents far more than a law-enforcement challenge. It impacts government revenues, consumer trust, business competitiveness and economic resilience. As India advances towards its growth ambitions, strengthening traceability, enabling technology-led enforcement and fostering greater collaboration between industry and government will be critical to protecting legitimate markets and ensuring sustainable economic development.

      Sidhartha Gautam

      Partner and Lead - Auto & Industrial Manufacturing Sector, Risk Advisory

      KPMG in India

      Illicit trade is no longer a standalone enforcement issue. It is an interconnected ecosystem that spans supply chains, digital platforms, and informal networks. To combat it effectively, we must move beyond product-level detection and focus on understanding and disrupting the networks that enable it.

      Mustafa Surka

      Partner, Forensic Services, Risk Advisory Consumer Markets & Retail Leader

      KPMG in India

      Dark patterns are no longer only a matter of user experience (UX) ethics. They are now attracting regulatory attention. For organisations across sectors such as e-commerce, travel, financial services, insurance, consumer goods, media, healthcare and technology, this makes fair digital design a business issue, not just a compliance issue.

      Recent action by the Central Consumer Protection Authority (CCPA) against several digital platforms has resulted in regulatory penalties and directions to correct practices considered deceptive. It also signals that regulators are closely examining how digital interfaces influence consumer choices and behaviour. This impacts customer perception of a brand and can lead to reputational damage for organisations.

      Manoj Kumar Vijai

      Non-Executive Chairman

      KPMG in India

      The next decade of banking will not be defined by who automates the fastest. It will be defined by who makes better decisions. As AI becomes embedded across underwriting, risk management, customer engagement and fraud prevention, banking is moving beyond digital transformation towards intelligent transformation. But with greater autonomy comes greater responsibility.

      Mohit Bahl

      Partner and Head - Risk and Integrity Advisory

      KPMG in India

       Effective risk management today is not just about addressing what we know but being prepared for what’s emerging. At KPMG in India, we are focused on anticipating evolving risks, from technology and AI to regulatory and geopolitical changes, and responding with agility and discipline.

      Strong governance and risk practices enable us to move forward with confidence in building resilience, sustaining trust, and ensuring we make decisions that are responsible, informed, and future-ready.

      Sudesh Anand Shetty

      Partner

      KPMG in India

      Third-party governance is not just about managing risk - it is about strengthening trust, protecting organisational values, and enabling sustainable growth. As organisations expand their third-party networks, effective governance is essential to safeguarding reputation, ensuring compliance, and creating long-term value.

      Suveer Khanna

      Partner and Head, Forensic Services

      KPMG in India

      Legal evidence is far more important than information- it is the foundation upon which accountability, governance and trust are built. In an increasingly digital and complex environment, organisations must ensure that evidence is collected, preserved and managed with the highest levels of integrity. A well-conducted forensic audit not only uncovers the facts but also creates a defensible narrative that can withstand regulatory, legal and stakeholder scrutiny. The difference between suspicion and action often lies in the quality of the evidence.

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      While, businesses are experiencing meaningful value from AI, most are concerned about data security, privacy and AI induced risks.

      Recent RBI advisories rightly focuses on the two important aspects:

      • Having strong governance for responsible and safe use of AI and
      • Strengthening capabilities against AI accelerated cyberattacks.
      Akhilesh Tuteja

      Partner & National Leader - Clients and Markets and Technology, Media & Telecommunications (TMT)

      KPMG in India

      AI that speeds up legacy processes is not transformation; it scales inefficiencies. Real value lies in rethinking work: challenge assumptions, redesign workflows, create new value. This requires unlearning, diverse perspectives, and courage.

      Leaders must look beyond the brief, surface unseen insights, and redefine outcomes. The future favors those who rethink problems, not just tools.

      Sumit Kapoor

      Partner, Governance, Risk & Compliance Services

      KPMG in India

      AI is not replacing auditors, it is augmenting them. By automating routine activities and unlocking deeper insights from data, AI enables Internal Audit professionals to spend less time gathering information and more time understanding risks, asking the right questions, and delivering strategic value.

      Devesh Jain

      Partner

      KPMG in India

      The future of Internal Audit is not defined by the issues it identifies, but by the insights it delivers. Assurance is table stakes; value comes from foresight, perspective, and the ability to influence better decisions.

      Sidheshwar Bhalla

      Partner, GRCS-North
      KPMG in India

      As auditors, we spend our careers helping organisations stay balanced and resilient. The same principle applies to us as individuals. Physical wellness, mental wellness, and spiritual wellness are deeply interconnected, and nurturing all three helps us bring our best selves to work and life.

      Maneesha Garg

      Partner & Head – Managed Services, Forensic, F&A, HR, Learning, Insight Led sales, Digital business operations and Sourcing

      KPMG in India

      As AI becomes central to enterprise transformation, organisations in India today are now eager to move from pilots to production, while managing legacy systems, scarce skills, and escalating cyber risk. Managed Services are fast evolving from a support function into a strategiv foundation, with AI-led scaling and transformation.

      By integrating new technologies with existing platforms, strengthening data and AI governance, and bringing deep domain expertise, managed services offer a space where Indian organisations can accelerate value creation, through focus on mission-critical processes, and build sustainable, future-ready business innovation, while maintaining the resilience and discipline required to operate at scale.

      Manoj Kumar Vijai

      Non-Executive Chairman

      KPMG in India

      Indian boards must move from passive oversight to active AI stewardship, embedding accountability, risk discipline, and value creation at the core of governance.

      As firms scale from pilots to enterprise adoption, boards must navigate a landscape defined by speed, uncertainty and structural change - without managing AI directly.

      Maneesha Garg

      Partner & Head – Managed Services, Forensic, F&A, HR, Learning, Insight Led sales, Digital business operations and Sourcing

      KPMG in India

      India Inc. is leaning on partners to fuel growth, with vendors now acting as tech and innovation extensions. But as ecosystems expand, risk rises.

      Managed services are emerging as the backbone for AI at scale, enabling secure data, compliance, and performance through a new operating model.

      Suveer Khanna

      Partner and Head, Forensic Services

      KPMG in India

      • Fraud has evolved into a full‑scale enterprise, with digital technologies accelerating both its scale and sophistication. Traditional investigation methods are struggling to keep pace, making proactive forensic readiness and evidence‑led defence a leadership imperative. Strengthening resilience requires organisations to adopt agile, intelligence‑driven forensic capabilities.

      • The division of labour is fueling fraud's industrial revolution, where fraud actors no longer operate in isolation but through specialised roles across mule, access broker, launderers, recon agents and executors.
        At the same time, the nature of evidence is changing, becoming more fragmented across devices, platforms, payment systems, cloud environments, and third-party ecosystems.
        As fraud grows in scale and complexity, necessity is driving innovation - bringing regulators, institutions, and industry participants to work more closely than ever before.
        In this new environment, organisations must move from reactive investigation to forensic readiness – built on collaboration, governance, technology-enabled intelligence, and the discipline to stay one step ahead of the fraudsters.

      • As risk landscapes continue to evolve, organisations must move beyond viewing fraud, cyber and digital threats through the lens of compliance alone.
        The discussion reinforced that while prevention, detection and response capabilities have matured significantly, the real challenge lies in building the ability to pre-empt emerging risks. In an increasingly interconnected ecosystem, resilience will be defined not by how organisations react to disruption, but by how effectively they anticipate it, adapt to it and preserve stakeholder trust through it

      Gagan Budhiraja

      Partner, Forensic-Inv
      KPMG in India

      • Modern fraud investigations must move beyond reactive approaches to become part of a continuous intelligence ecosystem. By integrating digital evidence, financial trails and advanced analytics, institutions can not only respond faster but also build stronger prevention and control frameworks for the future.

      • As fraudsters increasingly leverage AI, deepfakes, mule networks, and sophisticated social engineering techniques, the challenge before institutions is no longer just detecting suspicious transactions but understanding suspicious behaviour.
        The discussion reinforced that the future of fraud prevention lies in moving from rule-based controls to intelligence-led, behavioural risk models, supported by stronger collaboration across regulators, financial institutions, technology providers, and law enforcement agencies.

      Rajosik Banerjee

      Partner and National Head - Risk and Finance Advisory, EMA Head of Risk Services

      KPMG in India

      • Financial reporting and risk management are becoming increasingly intertwined, particularly in areas such as Fair Value measurement, Effective Interest Rate (EIR) calculations, Initial Recognition, and Expected Credit Loss (ECL) governance.

        Robust governance, transparent methodologies, and strong end-to-end processes are essential for achieving high-quality financial reporting, enhancing risk insight, and ensuring regulatory readiness in an increasingly dynamic banking environment.

      • ACPIR implementation is not just a modelling exercise, it is a business transformation programme. Beyond methodology and governance, institutions will need to carefully assess transition impacts across capital, profitability, reporting, and taxation. Early alignment between finance, risk, tax, and technology teams will be critical to ensuring a smooth and sustainable adoption journey. The quality of implementation will matter as much as compliance itself.

      Amitava Mukherjee

      Partner, Financial Risk Management

      KPMG in India

      The true impact of ECL goes far beyond finance and accounting. It will reshape business models, ICAAP, ALM, portfolio strategy, and regulatory compliance, compelling banks to embed risk thinking into every layer of decision-making.

      Somdeb Sengupta

      Partner, Financial Risk Management

      KPMG in India

      The new regulations should not be looked as mere change in provisioning norms - it gives financial institutions a powerful tool for forward looking decision making. Making informed choices at every stage of customer lifecycle - origination to collections as well as nuanced portfolio strategy can give banks real competitive advantage.

      Venkateswaran Narayanan

      Partner, Finance Advisory
      KPMG in India

      After a decade of submitting proforma Ind AS financial statements to the Reserve Bank of India (RBI), banks in India are set to implement ECL & EIR from FY 2027-28. The implementation of ECL & EIR presents the opportunity to harmonise financial, risk & regulatory reporting in the areas of provisioning, credit risk management & periodic regulatory submissions. The implementation is expected to have a lot of rigor in the areas of data, process & governance as these will be subject to audit.

      Mustafa Surka

      Partner, Forensic Services, Risk Advisory Consumer Markets & Retail Leader

      KPMG in India

      Global trade is being reshaped by geopolitics. Middle East tensions are disrupting energy and shipping, affecting nearly 20% of oil flows and up to USD5B in cargo daily. Amid the uncertainty, India is stepping up trade ties with the US, UK and EU.

      Volatility is set to stay, making structural resilience more critical than short‑term fixes. Organisations that build strong governance, embed compliance, and adopt proactive risk and investigation frameworks are better positioned to manage uncertainty, protect trust, and create durable long‑term value.

      Rajosik Banerjee

      Partner and National Head - Risk and Finance Advisory, EMA Head of Risk Services

      KPMG in India

      RBI directions for banks propose a comprehensive three-layer expected credit loss model that:

      • reinforces risk oversight,
      • embeds interest rate–driven income recognition, and
      • preserves capital strength.
      Mustafa Surka

      Partner, Forensic Services, Risk Advisory Consumer Markets & Retail Leader

      KPMG in India

      Global trade is being reshaped by geopolitics. Middle East tensions are disrupting energy and shipping, affecting nearly 20% of oil flows and up to USD5B in cargo daily. Amid the uncertainty, India is stepping up trade ties with the US, UK and EU.

      Volatility is set to stay, making structural resilience more critical than short‑term fixes. Organisations that build strong governance, embed compliance, and adopt proactive risk and investigation frameworks are better positioned to manage uncertainty, protect trust, and create durable long‑term value.

      Rajosik Banerjee

      Partner and National Head - Risk and Finance Advisory, EMA Head of Risk Services

      KPMG in India

      RBI has amended the Investment Portfolio Directions to align banks’ investment books with the new ECL & EIR framework, effective 1 April 2027.

      Key shifts:

      • HTM & AFS (debt) brought under Stage‑wise ECL provisioning
      • Mandatory use of Effective Interest Rate (EIR) and amortised cost
      • Fair value reset on 31‑Mar‑2027, with transition impact routed to reserves (not P&L)
      • Stronger linkage between NPAs and NPIs and tighter income recognition for Stage 3

      Key note: Entire investment will be carried on EIR effective April 2027, unlike in the case of existing loan portfolio, transition to EIR extended till Mar 2030. However new loans will be on EIR from April 2027

      Net effect: A decisive move towards credit‑risk‑sensitive accounting, aligning loan and investment books under a common prudential framework.

      Rajosik Banerjee

      Partner and National Head - Risk and Finance Advisory, EMA Head of Risk Services

      KPMG in India

      • RBI ACPIR Directions, 2026

        A Step Change in Credit Risk Management: The RBI has notified the much awaited ECL circular, marking a significant shift in how Indian banks assess and provision for credit risk. The framework retains the NPA regime, while introducing a forward‑looking Expected Credit Loss (ECL) model with stronger governance, system automation, and global alignment effective from April 2027.
        Key highlights include 3‑stage ECL provisioning, tighter SICR assessment, product‑wise prudential floors, EIR-based income recognition, and a phased transition period to manage capital impact. Overall, the move strengthens resilience by shifting focus from loss recognition after default to loss anticipation before default.
        It also brings in the framework of Model Risk Management (MRM) for development and validation.
        A material reform - both strategic and operational - for the banking system.

      • RBI SA-CR Directions, 2026

        RBI has also issued the Standardised Approach for Credit Risk (SA‑CR) Directions, 2026, aligning India’s capital framework with Basel III final reforms, effective 1 April 2027.
        The framework introduces greater risk sensitivity and prudence through:

        • Granular exposure‑wise risk weights
        • Enhanced use of external ratings with ODR‑based adjustments
        • Stronger treatment for unrated large exposures, CRE‑ADC, specialised lending and equity/fund investments
        • Revised CCFs, CRM norms and NPA risk weights linked to provisioning

        Overall, this is a material upgrade to credit risk capital regulation, with direct implications for capital planning, portfolio strategy and risk governance over the next two years.

      Sanjay Doshi

      Partner and Head, Transaction Services and Financial Services Advisory

      KPMG in India

      Regulations address systemic risk at the source. For state government loans, norms hinge on exposure and capital adequacy. Guarantees ease exposure limits but still require capital. The NBFC draft is unlikely to change outcomes in the near to mid term.

      Manoj Kumar Vijai

      Non-Executive Chairman

      KPMG in India

      Good financial reporting is no longer about meeting deadlines at year end. It is about building discipline, trust and clear communication throughout the year.

      Over the past few quarters, the themes for financial reporting have evolved - from Ind AS 118 and its impact on financial statements, to labour codes, and now to recent financial reporting trends, year‑end reminders, and regulatory expectations including Effective Communication Between Statutory Auditors and Those Charged with Governance (TCWG). What stood out in our breakfast session was how much the focus has shifted from just compliance to quality, clarity, and governance.

      Financial reporting is moving rapidly. Expectations from boards, regulators, and stakeholders continue to rise. Timelines are getting tighter. Disclosures are getting deeper. And communication - especially between statutory auditors and TCWG - is becoming more important than ever with an objective to strengthen oversight and improve audit quality.

      Hear from the experts

      Regulations address systemic risk at the source. For state government loans, norms hinge on exposure and capital adequacy. Guarantees ease exposure limits but still require capital. The NBFC draft is unlikely to change outcomes in the near to mid-term.

      Manoj Kumar Vijai says AI, innovation and leadership will redefine India’s banking sector at the BT Banking & Economy Summit

      Insights from the new 2026 KPMG global TPRM study

      Internal audit is not just about looking back but looking ahead. With AI and advanced analytics, we can deliver real-time insights and predictive foresight. The auditor's role is evolving into a strategic advisor—shaping future-ready businesses.

      Risk and Compliance – Trends and updates

      Download

      Risk and Compliance Update - Sixth Edition, March 2025

      Concise updates on risk and compliance for Audit heads, Risk officers, CFOs-reflecting transparency, sustainability, and governance.

      Download

      Risk and Compliance Update - Fifth Edition, December 2025

      Key highlights and developments on risk and compliance for risk leaders to interpret signals early and demonstrate reliability under concurrent stress.

       

      Download

      Risk and Compliance Update - Fourth Edition, November 2025

      This edition shares insights on regulatory changes and trends for leaders as they navigate an interconnected risk landscape and refine governance strategies.

       

      Download

      Risk and Compliance Update - Third Edition, August 2025

      Concise updates on risk and compliance for Audit heads, Risk officers, CFOs-reflecting transparency, sustainability, and governance.

      Download

      Risk and Compliance Update - Second Edition, May 2025

      Concise and relevant updates on critical risk and compliance matters for Audit heads, Risk officers, CFOs, and key decision-makers.

      KPMG Board Leadership Center

      KPMG in India’s Board Leadership Center (BLC) benchmarks leading practices in corporate governance and delivers actionable thought leadership, peer council, and networking forums to board members. It engages directors and business leaders through programmes and perspectives, drawing on global insights to promote governance across risk, strategy, talent, technology, compliance, financial reporting, and audit quality.

      Explore our Risk and Regulation insights

      Something went wrong

      Oops!! Something went wrong, please try again

      Global insights

      Conflict in the Middle East shows banks need to invest in resilience against geopolitical shocks

      Transform your risk management strategy for the future by integrating AI

      Managed services create a unified view of cyber risk

      As regulatory expectations, data complexity, and emerging technologies evolve, risk management in banking is undergoing a fundamental transformation.

      A midyear update: opportunities for businesses to navigate uncertainty with confidence

      Explore how to turn risk into an opportunity for value creation and align your organization with the demands of the modern risk environment.

      Connect with us

      Contact our specialists for more information

      connect with us