Bharat Cred Solutions
Knowledge Center
RBI

RBI Digital Lending & Payment Compliance 2026: Authentication, Co-Lending, LEI and Cybersecurity Rules for Banks & NBFCs

22 min read

RBI Digital Lending & Payment Compliance 2026: Authentication, Co-Lending, LEI and Cybersecurity Rules for Banks & NBFCs

Last Updated: August 2026

The regulatory environment for digital lending and financial services in India has entered a new phase in 2026.

For banks, NBFCs, fintech companies, Lending Service Providers (LSPs), payment participants and institutions involved in co-lending, compliance is no longer limited to having a policy document on paper.

The RBI's recent regulatory framework increasingly connects digital lending, borrower protection, authentication, payment security, data governance, co-lending, default-loss guarantees, credit risk management and technology outsourcing into one broader risk-management ecosystem.

Several important RBI frameworks are now operational, including the RBI (Digital Lending) Directions, 2025, RBI (Co-Lending Arrangements) Directions, 2025, and the RBI (Authentication Mechanisms for Digital Payment Transactions) Directions, 2025.

This guide explains what these changes mean for banks and NBFCs in 2026, what compliance teams should review, and where the biggest operational risks are.

Quick answer: RBI's 2026 regulatory direction is towards stronger borrower protection, two-factor and transaction-specific authentication, risk-sensitive payment controls, transparent digital lending, regulated co-lending structures, controlled DLG arrangements, stronger data governance and tighter oversight of technology service providers.


Key Takeaways

  • RBI's Digital Lending Directions, 2025 consolidate major requirements governing digital lending by regulated entities.

  • Digital lending arrangements involving LSPs require formal agreements, enhanced due diligence and continued responsibility by the regulated entity.

  • Multi-lender digital lending journeys must present borrowers with relevant loan offers in an objective and comparable manner.

  • RBI's 2025 authentication directions require at least two distinct authentication factors for applicable digital payments, subject to specified exemptions.

  • For applicable digital payment transactions other than card-present transactions, at least one authentication factor must be dynamic.

  • RBI has permitted additional risk-based checks for transactions presenting higher fraud risk.

  • The new Co-Lending Arrangements Directions, 2025 apply from January 1, 2026, subject to the framework's transitional provisions.

  • Each regulated entity participating in a co-lending arrangement must retain at least 10% of each individual loan in its books.

  • Co-lending borrowers must receive a blended interest rate calculated according to the participating REs' funding shares.

  • DLG under digital lending remains subject to RBI's prescribed eligibility, due-diligence, structure and 5% cap requirements.

  • LEI requirements apply to relevant non-individual borrowers with aggregate exposure of ₹5 crore and above.

  • RBI's IT outsourcing framework requires regulated entities to maintain strong oversight of technology service providers, including timely cyber-incident escalation.

  • Compliance should be treated as a continuous operational process rather than a one-time documentation exercise.


1. What Has Changed in RBI Digital Lending Compliance in 2026?

Digital lending in India has evolved rapidly.

Loan origination, credit assessment, customer onboarding, KYC, repayment, collections and customer service are increasingly performed through digital platforms and third-party technology providers.

This creates efficiency, but it also creates regulatory risks.

A digital lending journey may involve:

Borrower → Digital Lending App → LSP → NBFC/Bank → Credit Bureau → Payment System → Technology Provider → Collection Partner

Every additional participant can introduce operational, cybersecurity, conduct and data-protection risks.

The RBI's Digital Lending Directions, 2025 therefore focus on ensuring that outsourcing and technology do not dilute the responsibility of the regulated entity.

The fundamental principle is simple:

A bank or NBFC cannot outsource its regulatory responsibility.

If an NBFC uses an LSP to acquire customers, support underwriting, service loans or conduct recovery activities, the NBFC remains responsible for regulatory compliance.


2. RBI Digital Lending Directions 2025: What NBFCs Need to Know

The RBI Digital Lending Directions, 2025 apply to digital lending activities of regulated entities including commercial banks, specified cooperative banks, NBFCs and All-India Financial Institutions.

The framework addresses:

  • Lending Service Providers

  • Digital Lending Apps

  • borrower creditworthiness

  • borrower disclosures

  • Key Facts Statements

  • loan disbursement

  • repayment

  • cooling-off periods

  • grievance redressal

  • data collection

  • data storage

  • privacy

  • cybersecurity

  • credit bureau reporting

  • DLA reporting

  • Default Loss Guarantee

The Directions were issued to consolidate earlier digital-lending instructions and introduce additional measures for areas such as multiple-lender arrangements and the RBI's digital lending app directory.


3. What Is an LSP Under RBI Digital Lending Rules?

A Lending Service Provider, or LSP, is an agent of a regulated entity that performs one or more digital lending functions.

Depending on the arrangement, an LSP may assist with:

  • customer acquisition

  • underwriting support

  • pricing-related services

  • loan servicing

  • loan monitoring

  • recovery

  • customer interaction

  • technology-enabled lending processes

The relationship between an NBFC and an LSP should be governed by a formal contractual agreement.

The regulated entity must conduct enhanced due diligence before engaging the LSP.

The assessment should consider areas such as:

  • technical capability

  • data privacy

  • data storage

  • borrower treatment

  • regulatory compliance

  • previous conduct

  • operational capability

  • cybersecurity

  • financial and reputational risks

The NBFC must also periodically review the LSP.

Most importantly, outsourcing the activity does not transfer the NBFC's regulatory responsibility.


4. Multiple-Lender Digital Lending: What Changed?

One of the important developments in the RBI's Digital Lending Directions is the treatment of digital lending platforms working with multiple regulated entities.

Where an LSP works with multiple lenders, the borrower must be provided with a digital view of the loan offers that match the borrower's requirements.

The presentation should include relevant information such as:

  • lender name

  • loan amount

  • loan tenure

  • Annual Percentage Rate (APR)

  • monthly repayment obligation

  • applicable penal charges

  • link to the relevant KFS

The purpose is to allow borrowers to compare available offers rather than being pushed towards a particular lender.

The RBI also requires the presentation to be unbiased and objective and restricts deceptive or dark-pattern-based mechanisms designed to influence borrowers unfairly.

This is important for fintech platforms because loan-offer ranking is now a regulatory design issue, not merely a product-design issue.


5. Key Facts Statement: Why KFS Matters in Digital Lending

The Key Facts Statement is one of the most important borrower-protection tools in the digital lending framework.

A borrower should be able to understand the actual economics of a loan before accepting it.

The KFS framework brings transparency to items such as:

  • APR

  • applicable charges

  • repayment obligations

  • loan terms

  • penal charges

  • other important financial information

Digital lending platforms should therefore ensure that KFS generation is integrated directly into the lending workflow.

A compliance team should not rely on manually generated documents after loan approval.

The better approach is:

Credit decision → Loan configuration → KFS generation → Borrower acceptance → Digital execution → Document delivery

This creates a clear audit trail.


6. RBI Digital Lending Data Protection Requirements

Data governance is another major area of RBI scrutiny.

Digital lending platforms frequently process sensitive borrower information.

The RBI framework requires data collection to be:

  • need-based

  • supported by borrower consent

  • auditable

  • linked to a defined purpose

Digital lending apps should not freely access unnecessary mobile resources.

The framework specifically restricts unnecessary access to resources such as:

  • contact lists

  • call logs

  • files

  • media

  • telephony functions

Limited access to facilities such as camera, microphone or location may be permitted when necessary for onboarding or KYC and supported by explicit consent.

The objective is to prevent digital lending from becoming a mechanism for uncontrolled borrower surveillance.


7. Where Should Digital Lending Data Be Stored?

The RBI Digital Lending Directions also establish important requirements around borrower data.

Regulated entities must ensure appropriate controls around:

  • personal information

  • data storage

  • data retention

  • data destruction

  • third-party access

  • privacy policies

  • cybersecurity

The framework requires data to be stored on servers located in India, subject to applicable statutory and regulatory requirements.

Where data is processed outside India, the framework requires it to be deleted from overseas servers and brought back to India within the prescribed timeline.

For NBFCs using cloud infrastructure, SaaS platforms, analytics systems or overseas technology vendors, this makes vendor-level data mapping increasingly important.


8. RBI Authentication Mechanisms for Digital Payments in 2026

Another major regulatory development is the RBI's Authentication Mechanisms for Digital Payment Transactions Directions, 2025.

These directions become applicable to payment system providers and participants by April 1, 2026, unless a specific provision has another timeline.

The framework applies to domestic digital payment transactions, subject to specified exemptions.

The key principle is:

Two-factor authentication remains the foundation.

Applicable digital payment transactions must use at least two distinct authentication factors unless an exemption applies.

Authentication factors can involve:

Something you know

Examples:

  • PIN

  • password

  • passphrase

Something you have

Examples:

  • device

  • hardware token

  • software token

Something you are

Examples:

  • fingerprint

  • other biometrics

The RBI framework does not require the industry to eliminate SMS OTP.

Instead, it creates greater flexibility for alternative authentication mechanisms while maintaining minimum security principles.


9. At Least One Authentication Factor Must Be Dynamic

For applicable digital payment transactions other than card-present transactions, at least one authentication factor must be dynamically created or proven.

In practical terms, the authentication proof should be unique to the transaction.

This is important because a static credential can be reused or compromised.

A stronger authentication architecture may therefore involve:

Transaction → Risk evaluation → Dynamic authentication challenge → Verification → Payment approval

rather than relying exclusively on a reusable static credential.

This opens the door to technologies such as:

  • device-bound authentication

  • software tokens

  • biometrics

  • cryptographic authentication

  • passkeys

  • transaction-specific challenges

The exact technology should be selected according to the regulated entity's risk framework and applicable requirements.


10. Is SMS OTP Banned by RBI in 2026?

No.

This is an important distinction.

The RBI's 2025 Authentication Mechanisms Directions do not simply prohibit SMS OTP.

Instead, the framework allows a broader range of authentication factors while requiring the authentication mechanism to meet principles around:

  • two distinct factors

  • dynamism

  • robustness

  • transaction security

Therefore, the correct compliance strategy is not:

“Remove SMS OTP immediately.”

It is:

“Design an authentication architecture that satisfies RBI's principles and can use appropriate alternative factors where required.”


11. Risk-Based Authentication Under RBI's 2026 Framework

The RBI directions also permit issuers to adopt additional checks based on transaction risk.

Risk evaluation can consider parameters such as:

  • transaction location

  • user behaviour

  • device characteristics

  • historical transaction profile

  • contextual signals

  • transaction risk

For higher-risk transactions, additional verification may be introduced.

This creates a more sophisticated model:

Low-risk transaction

Normal authentication flow.

Medium-risk transaction

Additional contextual checks.

High-risk transaction

Step-up authentication or additional verification.

The important regulatory distinction is that the RBI framework permits risk-based additional checks; it should not be described as prescribing one specific RBA technology or mandatory proprietary scoring engine for every issuer.


12. Cross-Border Card-Not-Present Authentication: October 2026 Deadline

Another important deadline is October 1, 2026.

For specified cross-border Card-Not-Present transactions involving cards issued in India, card issuers must put mechanisms in place to validate authentication requests raised by overseas merchants or overseas acquirers.

Card issuers must also put in place a risk-based mechanism for handling cross-border CNP transactions.

This means payment institutions should review:

  • BIN registration

  • card-network connectivity

  • authentication routing

  • overseas merchant scenarios

  • fraud-risk systems

  • CNP transaction monitoring

  • exception handling

  • customer authentication journeys


13. RBI Co-Lending Arrangements Directions 2025

Co-lending is another major regulatory area for NBFCs in 2026.

The RBI issued the Co-Lending Arrangements Directions, 2025, which came into force from January 1, 2026, subject to the framework's provisions regarding existing arrangements.

The framework applies to eligible arrangements involving:

  • commercial banks

  • All-India Financial Institutions

  • NBFCs, including Housing Finance Companies

Digital lending arrangements involving co-lending must comply with the Digital Lending Directions as well as the Co-Lending Directions.


14. Minimum 10% Retention Under the New Co-Lending Framework

One of the most important changes is the minimum participation requirement.

Under the 2025 Co-Lending Directions:

Each regulated entity participating in the co-lending arrangement must retain a minimum 10% share of each individual loan in its own books.

This is different from the older 20% NBFC retention framework that many articles still quote.

Therefore, NBFC compliance teams should not simply copy old co-lending policies into their 2026 documentation.

The actual structure should be reviewed against the 2025 Directions.


15. Blended Interest Rate in Co-Lending

The borrower should not be presented with disconnected lending rates from each participating entity.

Under the new framework, the final interest rate charged to the borrower is a blended interest rate.

It is calculated based on the interest rates applicable to the respective regulated entities and weighted according to their proportionate funding share.

For example:

If:

  • Bank funds 80%

  • NBFC funds 20%

and their respective applicable rates are different, the final borrower rate is calculated using the prescribed weighted approach.

Any changes in the underlying rates must be reflected appropriately in the updated blended rate and communicated to the borrower.


16. Co-Lending KFS and Borrower Transparency

Co-lending agreements must clearly define responsibilities between the participating regulated entities.

The borrower should be informed about:

  • the participating entities

  • their respective roles

  • customer interface

  • servicing responsibilities

  • grievance redressal

  • relevant loan terms

  • applicable charges

  • the blended rate

The KFS framework is therefore particularly important in co-lending.

The objective is to ensure that borrowers understand who is providing the credit, who is servicing the relationship and what the actual cost of borrowing is.


17. Escrow and Operational Requirements for Co-Lending

The new co-lending framework also establishes operational controls.

Transactions between the participating regulated entities and the borrower are to be routed through an appropriate escrow arrangement.

The agreement should clearly specify how funds are appropriated between the originating and partner regulated entities.

Each RE should maintain the borrower's account for its respective share.

The respective loan shares should also be reflected in the books without delay and, in any case, within the prescribed 15-calendar-day period from disbursement.

This means co-lending requires coordination between:

Origination + Core Lending System + Accounting + Escrow + Reconciliation + CIC Reporting + Customer Service


18. DLG / FLDG Rules for Digital Lending and Co-Lending

Default Loss Guarantee, commonly referred to as DLG or FLDG, remains an important area of regulatory attention.

The RBI Digital Lending Directions allow specified regulated entities to enter into DLG arrangements with eligible providers subject to detailed conditions.

DLG should not replace proper credit underwriting.

A regulated entity must continue to perform robust credit assessment even when a DLG arrangement exists.

DLG arrangements must be supported by legally enforceable agreements and appropriate due diligence.

Permitted forms include:

  • cash deposited with the RE

  • fixed deposit with lien in favour of the RE

  • bank guarantee

The DLG cover is subject to a 5% cap under the Digital Lending Directions.

The cap is applied to the relevant outstanding portfolio according to the RBI framework.

Therefore, the idea that FLDG can simply be used to transfer unlimited credit risk to a fintech or LSP is incorrect.


19. DLG Does Not Remove the NBFC's Credit Risk Responsibility

This is one of the most important compliance principles.

A DLG arrangement does not mean:

“The fintech guarantees the loan, therefore the NBFC does not need strong underwriting.”

That approach would defeat the purpose of the regulatory framework.

The NBFC remains responsible for:

  • credit appraisal

  • NPA recognition

  • provisioning

  • portfolio monitoring

  • DLG due diligence

  • regulatory reporting

  • borrower protection

The RBI framework specifically maintains responsibility for recognising individual loan assets as NPA and provisioning according to applicable norms.


20. LEI Requirement for Large Non-Individual Borrowers

Legal Entity Identifier, or LEI, is another important compliance requirement for institutional lending.

An LEI is a unique 20-character identifier used to identify legal entities participating in financial transactions.

RBI extended the LEI requirement to relevant non-individual borrowers of banks and financial institutions, including NBFCs.

For relevant borrowers with aggregate exposure of ₹5 crore and above, the LEI requirement applies according to RBI's framework.

The exposure calculation includes relevant fund-based and non-fund-based exposure.

This is particularly important for:

  • corporate borrowers

  • MSMEs with large institutional exposures

  • infrastructure borrowers

  • corporate lending businesses

  • NBFC underwriting teams

  • bank-NBFC co-lending arrangements


21. Why LEI Matters for NBFCs

LEI improves the ability of financial institutions to identify legal entities and understand aggregate financial exposures.

For an NBFC, LEI verification can become part of:

Borrower onboarding → KYC → Corporate identification → Exposure assessment → Credit underwriting → Sanction → Monitoring

If an eligible borrower does not obtain the required LEI, the applicable RBI framework can restrict new exposure or renewal/enhancement according to the prescribed requirements.

Therefore, LEI verification should not be treated as an administrative afterthought.

It should be integrated into the credit workflow.


22. RBI Cybersecurity and IT Outsourcing Requirements for NBFCs

Digital lending creates another important dependency:

technology vendors.

NBFCs increasingly depend on:

  • cloud providers

  • loan management systems

  • KYC providers

  • API providers

  • payment gateways

  • analytics platforms

  • collection technology

  • cybersecurity providers

  • data-processing vendors

The RBI's IT outsourcing framework requires regulated entities to maintain appropriate oversight of material IT outsourcing arrangements.

The fact that a system is operated by a third party does not remove the NBFC's responsibility.


23. The 6-Hour Cyber Incident Reporting Requirement

Under RBI's IT outsourcing framework, regulated entities must ensure that cyber incidents affecting outsourced IT services are reported by the service provider to the RE without undue delay so that the RE can report the incident to RBI within six hours of detection by the third-party service provider.

This creates a practical requirement for:

Vendor detection → Immediate escalation → NBFC incident response → RBI reporting → Investigation → Remediation

The compliance challenge is therefore not simply having a cybersecurity policy.

The NBFC needs a functioning incident-response mechanism with:

  • vendor escalation contacts

  • severity classification

  • notification SLAs

  • incident ownership

  • escalation matrix

  • RBI reporting process

  • forensic investigation

  • root-cause analysis

  • recovery procedures

  • post-incident review


24. What NBFCs Should Audit in Their Digital Lending Technology Stack

A 2026 digital lending compliance audit should examine the complete technology journey.

Customer onboarding

Check:

  • KYC

  • consent

  • data collection

  • authentication

  • audit trails

Credit assessment

Check:

  • borrower information

  • income data

  • underwriting rules

  • automated decision systems

  • credit bureau integration

Loan approval

Check:

  • sanction workflow

  • KFS generation

  • digital signatures

  • borrower disclosures

Disbursement

Check:

  • borrower bank account

  • third-party payment restrictions

  • reconciliation

  • co-lending flows

Repayment

Check:

  • payment routing

  • authentication

  • transaction monitoring

  • failed-payment handling

Collections

Check:

  • recovery-agent authorization

  • borrower communication

  • data access

  • grievance mechanisms

Technology

Check:

  • cloud infrastructure

  • vendor access

  • data storage

  • encryption

  • incident management

  • business continuity

  • disaster recovery


25. 2026 RBI Compliance Checklist for NBFCs

A practical compliance review can be organised into ten areas.

1. Digital Lending

  • LSP agreements

  • LSP due diligence

  • DLA inventory

  • DLA reporting

  • borrower disclosures

  • KFS

  • cooling-off period

  • grievance redressal

2. Data Governance

  • consent management

  • data minimisation

  • privacy policy

  • data storage

  • data retention

  • data deletion

  • third-party data sharing

3. Authentication

  • two-factor authentication

  • dynamic authentication factor

  • authentication independence

  • fraud-risk controls

  • transaction monitoring

  • cross-border CNP readiness

4. Co-Lending

  • partner due diligence

  • 10% minimum retention

  • blended interest rate

  • KFS

  • escrow

  • loan transfer timeline

  • borrower-level asset classification

  • CIC reporting

5. DLG / FLDG

  • eligible provider

  • Board-approved policy

  • legal agreement

  • due diligence

  • 5% cap

  • permitted form of security

  • invocation process

  • disclosure

6. LEI

  • borrower identification

  • aggregate exposure calculation

  • LEI verification

  • renewal monitoring

  • sanction controls

7. Cybersecurity

  • incident response

  • vendor escalation

  • cyber monitoring

  • RBI reporting

  • CERT-In coordination where applicable

  • forensic investigation

8. IT Outsourcing

  • vendor due diligence

  • contracts

  • SLA

  • audit rights

  • data controls

  • concentration risk

  • business continuity

  • exit strategy

9. Customer Protection

  • transparent pricing

  • KFS

  • grievance redressal

  • recovery-agent disclosures

  • borrower communication

  • privacy

10. Governance

  • Board-approved policies

  • compliance ownership

  • internal audit

  • statutory audit

  • regulatory reporting

  • periodic review


26. Common RBI Compliance Mistakes NBFCs Should Avoid

Mistake 1: Treating the LSP as the compliance owner

The NBFC remains responsible.

Mistake 2: Copying an old co-lending agreement

The 2025 Co-Lending Directions introduced important changes.

Mistake 3: Using the old 20% retention rule without checking applicability

The new framework requires each participating RE to retain at least 10% of each individual loan.

Mistake 4: Treating DLG as a substitute for underwriting

DLG does not eliminate credit appraisal requirements.

Mistake 5: Assuming SMS OTP is prohibited

The RBI authentication framework does not simply ban SMS OTP.

Mistake 6: Building a risk engine without governance

Technology must be supported by documented policies, monitoring and auditability.

Mistake 7: Ignoring third-party technology risk

Cloud providers, APIs and technology vendors can create regulatory exposure.

Mistake 8: Treating LEI as a paperwork requirement

LEI should be integrated into institutional-credit workflows.

Mistake 9: Maintaining disconnected compliance systems

KFS, loan systems, payment systems, CRM, accounting and regulatory reporting should work from consistent data.

Mistake 10: Waiting for an RBI inspection

The objective should be continuous readiness rather than inspection-time preparation.


27. How to Build a Strong RBI Compliance Framework for an NBFC

A mature compliance architecture can be built around five layers.

Layer 1 — Regulatory Mapping

Map every RBI requirement to:

  • policy

  • process

  • system

  • owner

  • evidence

Layer 2 — Technology Controls

Convert regulatory requirements into system rules.

For example:

LEI requirement → automated eligibility check

KFS requirement → mandatory document generation

2FA requirement → authentication control

DLG cap → automated exposure monitoring

Layer 3 — Monitoring

Create dashboards for:

  • overdue accounts

  • authentication failures

  • fraud alerts

  • DLG exposure

  • vendor incidents

  • unresolved complaints

  • regulatory exceptions

Layer 4 — Audit

Conduct periodic:

  • compliance audits

  • technology audits

  • vendor audits

  • data audits

  • lending-process audits

Layer 5 — Continuous Improvement

Regulatory compliance should be updated whenever:

  • RBI issues a new direction

  • an existing direction changes

  • a product changes

  • a technology vendor changes

  • a new lending model is introduced


28. What Does RBI Compliance Mean for a Fintech Partner?

Fintech companies working with NBFCs should also understand that regulatory responsibility does not disappear because the fintech is not itself an NBFC.

If the fintech operates as an LSP, it can become an important part of the regulated entity's compliance ecosystem.

Fintech partners should therefore prepare for:

  • enhanced due diligence

  • contractual compliance

  • data governance

  • cybersecurity

  • borrower protection

  • transparent loan offers

  • recovery conduct

  • incident reporting

  • audit access

  • business continuity

A fintech that wants to become a long-term partner to regulated entities should therefore build its technology and governance architecture around RBI expectations from the beginning.


29. What Should NBFC Promoters Do Now?

If you operate or are planning to establish an NBFC, compliance should be built into the business model from day one.

Start with a regulatory gap assessment covering:

  1. NBFC structure

  2. applicable RBI directions

  3. lending products

  4. digital lending architecture

  5. LSP relationships

  6. co-lending arrangements

  7. DLG/FLDG structures

  8. KFS and borrower disclosures

  9. data governance

  10. cybersecurity

  11. IT outsourcing

  12. LEI controls

  13. credit reporting

  14. grievance redressal

  15. internal audit

This approach is significantly stronger than trying to add compliance after the lending business is already operational.


30. Frequently Asked Questions

What are the RBI digital lending guidelines for 2026?

RBI's digital lending framework for 2026 is primarily governed by the RBI Digital Lending Directions, 2025 along with other applicable RBI directions covering authentication, KFS, outsourcing, cybersecurity, credit reporting and co-lending. The framework focuses on regulated-entity responsibility, borrower protection, LSP governance, data protection, transparent lending and risk management.

What is the RBI two-factor authentication rule for digital payments in 2026?

Applicable digital payment transactions must generally use at least two distinct authentication factors unless an RBI-recognised exemption applies. For applicable transactions other than card-present transactions, at least one factor must be dynamically created or proven and be unique to the transaction.

Is SMS OTP banned by RBI in 2026?

No. RBI's Authentication Mechanisms for Digital Payment Transactions Directions, 2025 do not prohibit SMS OTP. They establish broader principles allowing different authentication factors while requiring minimum security standards.

What is risk-based authentication under RBI rules?

Risk-based authentication allows issuers to use additional checks depending on transaction risk. Parameters can include transaction location, user behaviour, device attributes and historical transaction patterns.

What are RBI co-lending guidelines for 2026?

The RBI Co-Lending Arrangements Directions, 2025 provide a framework for eligible co-lending arrangements between regulated entities. Among other requirements, each RE must retain at least 10% of each individual loan, borrower pricing uses a blended interest rate, and specified operational, disclosure and asset-classification controls apply.

What is the RBI DLG limit?

Under the RBI Digital Lending Directions, 2025, DLG cover on a specified outstanding portfolio is subject to a maximum of 5% of the amount disbursed from that loan portfolio at any given time, subject to the detailed provisions of the Directions.

What is FLDG in digital lending?

FLDG, commonly referred to as Default Loss Guarantee or DLG, is a contractual arrangement where an eligible provider agrees to compensate a regulated entity for credit losses up to a specified amount, subject to RBI's eligibility, due-diligence, structure, cap and other requirements.

What is the RBI LEI threshold for NBFC borrowers?

RBI's LEI framework applies to relevant non-individual borrowers with aggregate exposure of ₹5 crore and above from covered banks and financial institutions, with NBFCs included within the relevant financial institutions.

What is RBI's 6-hour cyber incident reporting requirement?

Under RBI's IT outsourcing framework, regulated entities must ensure that cyber incidents involving outsourced IT service providers are escalated without undue delay so that the RE can report the incident to RBI within six hours of detection by the third-party service provider.

What is the RBI Digital Lending App directory?

RBI requires regulated entities to report their deployed Digital Lending Apps through its prescribed reporting system. The reported information is published to help borrowers verify the association claimed by a digital lending app. Inclusion in the reported list should not be represented as RBI registration, authorization or endorsement of the app.

What is the cooling-off period under RBI digital lending rules?

Digital borrowers must be provided an explicit option to exit a digital loan during an initial cooling-off period by paying the principal and proportionate APR without penalty. The period is determined by the Board-approved policy of the regulated entity and cannot be less than one day.

What should an NBFC audit in 2026?

An NBFC should review digital lending, LSP governance, KFS, borrower protection, authentication, data privacy, cybersecurity, co-lending, DLG, LEI, credit reporting, IT outsourcing, grievance redressal and regulatory reporting.


Conclusion: RBI Compliance Is Becoming a Technology Discipline

The most important lesson from the RBI's recent regulatory framework is that compliance is no longer limited to legal documentation.

Modern NBFC compliance sits at the intersection of:

Regulation + Credit Risk + Technology + Data + Cybersecurity + Customer Protection + Governance

An NBFC may have a perfectly written policy and still have a compliance gap if its technology does not enforce the policy.

The stronger model is therefore:

RBI Regulation → Internal Policy → Business Process → Technology Control → Monitoring → Audit Evidence

For NBFCs, fintechs and financial institutions operating in India's rapidly expanding digital-credit ecosystem, building this structure early can reduce regulatory risk, improve operational control and create a more scalable lending business.


Need Help With NBFC Regulatory & Digital Lending Compliance?

Bharat Cred Solutions works with businesses operating across the financial-services ecosystem, including NBFC setup, RBI-related regulatory requirements, NBFC compliance, lending operations, financial advisory and related business infrastructure.

If your organisation is:

  • planning to establish an NBFC

  • reviewing its RBI compliance framework

  • launching a digital lending product

  • entering a bank-NBFC co-lending arrangement

  • reviewing DLG/FLDG structures

  • strengthening NBFC cybersecurity and technology controls

  • preparing for a regulatory or compliance review

our team can help assess the applicable regulatory requirements and identify the areas that need attention.

Speak with Bharat Cred Solutions about your NBFC compliance requirements.

Have a specific question about this?

Talk it through with our team on a strategy call.

Need Help?