RBI Digital Lending Compliance: NBFC Playbook
How Indian NBFCs can operationalise RBI digital lending compliance — from direct money-flow and Key Fact Statements to DPDP consent and default loss guarantees.
Introduction
RBI digital lending compliance has moved from a set of advisory circulars into a hard-edged supervisory expectation that every non-banking financial company must be able to demonstrate on demand. If your NBFC lends through an app, a website, a co-lending arrangement, or a technology partner that sources and services borrowers, the Reserve Bank of India now holds you — the regulated entity — accountable for what happens across that entire chain, whether or not the borrower ever knew your name. This is a governance problem before it is a technology problem, and it is one that compliance heads, company secretaries and general counsel are increasingly asked to certify to their boards.
This article is written for that audience. It explains what the RBI digital lending framework actually requires, why it looks so different from the open-banking regimes that dominate global fintech commentary, and how an Indian NBFC can build a defensible, auditable compliance posture rather than a folder of policies that nobody follows. The short answer to the search intent is this: compliance rests on four load-bearing pillars — direct money flow between lender and borrower, full cost transparency through the Key Fact Statement, consent-based data governance aligned with the DPDP Act 2023, and clear accountability for every outsourced lending service provider.
The regime consolidated over 2022 to 2025 does not merely ask you to publish policies. It asks you to prove, through logs, contracts and monitoring, that the borrower experience matches the rulebook. That shift from paper to evidence is the theme running through everything below.
Why RBI Digital Lending Compliance Is Not Just Open Banking
Much of the global fintech conversation frames digital lending through the lens of open banking — API-driven data sharing, consumer-permissioned access to bank statements, and competition-led unbundling of financial services. India has its own account aggregator ecosystem and a formidable public digital infrastructure, but the RBI digital lending compliance framework is animated by a different anxiety. Its origin was the Working Group on Digital Lending, convened after a wave of consumer harm from unregulated apps: coercive recovery, opaque pricing, hidden data harvesting and lending by entities with no regulatory standing at all.
As a result, the Indian rules are conduct-first and lender-accountability-first, rather than data-portability-first. Where open-banking regimes ask how data can flow more freely, the RBI framework asks how money and consent can be controlled more tightly. The regulator's central move was to make the regulated entity — a bank or NBFC — answerable for the conduct of every intermediary it uses, closing the gap that let unregulated players hide behind technology partners.
For an Indian NBFC, this means you cannot import a compliance template built for a European or American open-banking product. The obligations that matter most here — direct disbursal, the Key Fact Statement, the prohibition on borrowers paying fees to intermediaries, and localisation of data — have no exact equivalent abroad. Treating this as a generic global fintech exercise is the most common and most expensive mistake we see.
- The framework grew out of consumer-harm concerns, not competition or data-portability goals.
- Regulatory accountability sits squarely with the regulated entity, never the technology partner.
- Conduct, pricing transparency and money-flow control are the primary levers, not API access.
- Global open-banking compliance templates map poorly onto India-specific obligations.
The Regulatory Architecture: REs, LSPs and DLAs
The RBI framework is built on a small vocabulary that every compliance function must internalise. A Regulated Entity, or RE, is the licensed lender — your NBFC. A Lending Service Provider, or LSP, is any agent engaged to perform one or more lending functions on your behalf: customer acquisition, underwriting support, pricing assistance, servicing or recovery. A Digital Lending App or platform, the DLA, is the mobile or web interface through which the borrower actually transacts, whether it is owned by the RE or the LSP.
The guidelines issued in September 2022, refined through subsequent circulars and consolidated into a single set of directions in 2025, apply these definitions to draw one firm line: whatever a borrower experiences through a DLA or LSP is treated as the RE's own conduct. The RBI also introduced reporting and directory expectations so that borrowers and supervisors can trace which apps belong to which regulated lender, shrinking the space in which unauthorised apps once operated.
For a company secretary or general counsel, the practical consequence is that your outsourcing register and your board-approved outsourcing policy become primary compliance instruments. Every LSP relationship needs a written agreement that allocates responsibility for grievance redressal, data handling and conduct standards, and your board must remain able to satisfy itself that these arrangements do not dilute regulatory obligations.
- RE is the licensed NBFC; the LSP is any outsourced lending-function agent; the DLA is the borrower interface.
- Borrower-facing conduct by any LSP or DLA is legally attributed to the RE.
- Written LSP agreements must fix responsibility for grievances, data and conduct.
- Board-approved outsourcing policy and an up-to-date LSP register are core evidence.
Publishing and disclosure duties
The RE must publish the names of its engaged LSPs and the DLAs operating on its behalf, and the DLA must prominently display links to the RE's website and grievance mechanism. Borrowers should never have to guess who the actual lender is. Maintaining an accurate, current list of these disclosures — and reconciling it whenever a partner is added or dropped — is a recurring compliance task, not a one-time filing.
Where the SBR framework fits
Digital lending obligations sit on top of the RBI's Scale-Based Regulation framework for NBFCs, which calibrates governance, capital and disclosure expectations to an NBFC's size and systemic importance. A larger NBFC in an upper layer faces heavier board-level governance expectations, so its digital lending controls must be correspondingly more formal, documented and independently assured.
Money Flow: The Direct Disbursal and Repayment Rule
The single most structurally important rule in the entire framework governs the movement of money. All loan disbursals and repayments must be executed directly between the borrower's bank account and the RE's bank account. Funds may not flow through, or pool in, an account belonging to the LSP or any other third party, except where the law specifically permits pass-through arrangements such as co-lending or certain statutory flows.
This rule exists to prevent the intermediary from ever controlling borrower money — the mechanism that enabled much of the earlier consumer harm. It sounds simple, but it has deep operational consequences. It shapes how you design escrow and nodal account structures, how you settle with partners, and how you reconcile at scale. Any product design that lets an LSP touch principal or collect repayments into its own account is a direct compliance breach, however commercially convenient it may appear.
Equally important is the companion rule on fees: any charges payable to the LSP for its services must be paid by the RE, not recovered directly from the borrower. The borrower's cost of credit must be fully captured in the loan pricing disclosed to them, never in side payments to an intermediary. Compliance teams should test every live product against these two rules first, because a failure here is difficult to remediate quietly and is exactly what supervisory reviews probe.
- Disbursal and repayment must move directly between borrower and RE accounts.
- LSPs and third parties must not pool or route borrower funds through their own accounts.
- Fees to LSPs are paid by the RE, never collected directly from the borrower.
- Escrow, settlement and reconciliation designs must be tested against these rules before launch.
Transparency: The Key Fact Statement and APR
Before a borrower is bound, the RE must provide a standardised Key Fact Statement, or KFS, setting out the essential terms of the loan in a clear, comparable format. At the heart of the KFS is the Annual Percentage Rate — an all-inclusive cost of credit that folds in the interest rate and every fee, so borrowers see the true price rather than a headline rate stripped of charges. The KFS must also disclose the cooling-off or look-up period during which a borrower may exit the loan by repaying principal and proportionate charges without penalty.
This transparency obligation is where paper compliance and real compliance most often diverge. Many NBFCs have a KFS template but cannot prove that the correct, personalised KFS was actually shown to and acknowledged by each borrower at the right moment in the journey. Because the KFS is generated dynamically for each loan, it is precisely the kind of artefact that must be logged, timestamped and retrievable per borrower if you are to answer a supervisory query or a consumer complaint.
Any charge not disclosed in the KFS cannot be recovered from the borrower at any later stage. That principle turns the KFS into the definitive contract-cost record, and it makes the accuracy of your APR computation a legal exposure, not merely a customer-experience nicety.
- The KFS must be provided before the borrower is bound to the loan.
- APR must capture all-in cost of credit, including every fee and charge.
- The cooling-off period must be clearly disclosed and honoured without penalty.
- Undisclosed charges cannot be recovered from the borrower later.
- Per-borrower KFS delivery must be logged, acknowledged and retrievable.
Data Governance and the DPDP Act 2023 Overlap
The RBI framework and the Digital Personal Data Protection Act 2023 now operate as two reinforcing layers over the same borrower data. The RBI rules require that data collection by DLAs be need-based, backed by the borrower's prior and explicit consent, with a clear audit trail of what was collected and why. Intrusive access to a borrower's phone — contacts, call logs, media files, and similar resources — is not permitted, and biometric data should not be stored by the DLA or LSP unless specifically allowed. Data must be stored within India, consistent with existing RBI localisation expectations.
The DPDP Act 2023 layers on top of this a general obligation framework: the NBFC acts as a data fiduciary, must obtain free, specific, informed and unambiguous consent through a clear notice, must honour the borrower's rights to access, correction and erasure, and must be prepared to report personal data breaches. Consent must be as easy to withdraw as it was to give. For lending, this means your consent architecture cannot be a single blanket checkbox buried in a terms-of-service scroll; it must be granular and genuinely revocable.
The convergence point for compliance teams is a defensible consent and retention record. You should be able to show, for any borrower, exactly what data was collected, on what consent basis, for what purpose, where it is stored, and when it will be deleted. Building that record once — and enforcing it across every LSP and DLA — satisfies both the RBI conduct rules and the DPDP fiduciary duties at the same time.
- Data collection must be need-based, purpose-limited and backed by explicit prior consent.
- Access to phone contacts, call logs and files is barred; biometric storage is restricted.
- Borrower data must be stored within India in line with RBI localisation.
- DPDP Act 2023 adds fiduciary duties: clear notice, revocable consent, access, correction, erasure and breach reporting.
- A per-borrower consent and retention ledger is the shared evidence base for both regimes.
Consent that survives scrutiny
A blanket consent bundled into onboarding will not satisfy the DPDP standard of specific and informed consent, nor the RBI's need-based collection principle. Consent should be captured per purpose, presented in plain language and, where practicable, in the borrower's chosen language, and be withdrawable through the same app. Every grant and withdrawal should be timestamped and stored so the position is provable long after the interaction.
Third-party data through the account aggregator route
Where an NBFC pulls financial information through the account aggregator ecosystem, the consent artefacts generated there become part of your evidence chain. Compliance functions should reconcile those artefacts with the RBI need-based test and the DPDP purpose limitation, rather than assuming that a consent captured elsewhere automatically covers every downstream use of the data.
Default Loss Guarantee and Outsourcing Accountability
Many digital lending models rely on a partner absorbing some portion of credit risk. The RBI addressed this through its Default Loss Guarantee, or DLG, framework — often referred to in the market as first loss default guarantee. Under it, an RE may enter into a DLG arrangement with an eligible provider only within defined limits, with the aggregate DLG cover on a loan portfolio capped at a modest percentage of that portfolio. The arrangement must be backed by an explicit contract, and the RE must continue to recognise and provide for non-performing assets on its own books regardless of any guarantee.
The intent is to stop the DLG from becoming synthetic securitisation or a device that lets an unregulated partner do the real lending while the NBFC merely rents its licence. For compliance teams, the DLG cap, the eligibility of the guarantor, the form of the guarantee and the accounting treatment must all be documented and monitored on a live basis, because a portfolio that drifts above the cap is a breach that accumulates quietly.
More broadly, the RBI treats digital lending as an outsourcing activity, which means the existing principle applies with full force: outsourcing may transfer an activity, but it never transfers the regulatory obligation. Your board and senior management remain answerable for everything an LSP does in your name, which is why LSP due diligence, contractual conduct standards, periodic audits and clear exit rights belong in your standard operating model.
- DLG arrangements are permitted only within RBI-defined limits and portfolio caps.
- The RE must still classify and provision for NPAs on its own books despite any guarantee.
- DLG structure, guarantor eligibility and accounting treatment need continuous monitoring.
- Outsourcing transfers the activity but never the regulatory obligation.
- LSP due diligence, audit rights and exit clauses are core contractual controls.
Building a Defensible Compliance Operating Model
The organisations that handle RBI digital lending compliance well treat it as a continuously monitored operating model rather than an annual policy refresh. The framework's obligations are mostly transactional — a KFS per loan, a consent per borrower, a disbursal per account, a grievance per complaint — which means the evidence you need is generated thousands of times a day and must be captured as it happens. Retrofitting proof after a supervisory letter arrives is where teams fail.
A workable model rests on three habits. First, map every obligation to a specific control and a named owner, so there is no ambiguity about who ensures direct disbursal, who verifies KFS delivery, and who monitors the DLG cap. Second, instrument the borrower journey so that the critical artefacts — consent, KFS acknowledgement, disbursal confirmation, grievance timestamps — are logged automatically and are retrievable per borrower. Third, close the loop with periodic testing and internal audit that samples real loans against the rulebook, feeding findings back to the board.
General counsel and company secretaries should also ensure the framework connects to the wider Indian compliance estate. Grievance handling must align with the RBI's integrated ombudsman expectations, recovery conduct must respect fair practice norms and the boundaries set by law, and data practices must satisfy the DPDP Act 2023. When these are managed on a single compliance backbone rather than in disconnected spreadsheets, board reporting becomes a byproduct of the system rather than a quarterly scramble.
- Map each obligation to a named control owner across the borrower lifecycle.
- Instrument the journey so consent, KFS and disbursal evidence is captured automatically.
- Run periodic internal audit sampling live loans against the rulebook.
- Integrate grievance, recovery and data controls into one compliance backbone.
- Make board and supervisory reporting a byproduct of the system, not a manual exercise.
Conclusion
RBI digital lending compliance rewards NBFCs that treat it as an engineering and governance discipline rather than a documentation exercise. The obligations are demanding but coherent: control the money, disclose the true cost, respect consent, and own the conduct of every partner acting in your name. The firms that build these controls into the borrower journey — with per-loan evidence captured automatically — turn compliance from a recurring fire drill into a quiet, provable strength that boards and supervisors can trust.
If your team is weighing how to operationalise these obligations across live products, LSP relationships and the DPDP Act 2023 overlap, a focused walkthrough is usually more useful than another policy template. Vidhaana's compliance platform maps regulatory obligations to controls, tracks per-borrower evidence and surfaces gaps before a supervisor does. Book a demo to see how your NBFC can move from scattered spreadsheets to a defensible, always-audit-ready compliance posture.
Tags
Frequently Asked Questions
Who is ultimately responsible for RBI digital lending compliance?
The regulated entity — your bank or NBFC — is fully accountable. The RBI framework attributes the conduct of every lending service provider and digital lending app to the RE. Outsourcing an activity to a technology partner transfers the task but never the regulatory obligation, so the RE's board and senior management remain answerable for the entire lending chain.
Can a lending service provider collect repayments from borrowers?
No. All disbursals and repayments must flow directly between the borrower's bank account and the RE's account, without pooling in any LSP or third-party account, except where law specifically permits pass-through structures such as co-lending. Any design that lets an intermediary control borrower money is a direct breach of the RBI digital lending framework and a common supervisory red flag.
How does the DPDP Act 2023 interact with RBI digital lending rules?
They reinforce each other over the same borrower data. RBI requires need-based, consent-backed collection with data stored in India and bars intrusive phone access. The DPDP Act 2023 adds data-fiduciary duties: clear notice, specific and revocable consent, rights to access, correction and erasure, and breach reporting. A single per-borrower consent and retention record can satisfy both regimes together.
What is the Key Fact Statement and why does it matter so much?
The Key Fact Statement is a standardised pre-contract disclosure showing the all-inclusive Annual Percentage Rate, fees, and the cooling-off period. It matters because any charge not disclosed in the KFS cannot later be recovered from the borrower. NBFCs must deliver a personalised KFS per loan and retain timestamped proof of borrower acknowledgement for supervisory and grievance purposes.
What is the cap on Default Loss Guarantee arrangements?
Under the RBI Default Loss Guarantee framework, an RE may accept guarantee cover on a digital lending portfolio only within defined limits, with aggregate DLG capped at a modest percentage of that portfolio. The RE must still classify and provision for non-performing assets on its own books. The structure, guarantor eligibility and accounting treatment must be documented and continuously monitored.
Related Solutions & Features
Explore Vidhaana capabilities related to this topic:
Transform Your Legal Operations with AI
Ready to experience the power of AI-driven legal solutions? Vidhaana's platform delivers measurable results across compliance, helping organizations reduce costs, improve accuracy, and scale operations efficiently.


