Skip to content
eQomply
  • Platform

    Platform

    • Governance
    • Risk Management
    • Compliance Management
    • Integrations
    0 +

    Evidences Tracked

    0 +

    Regulatory Workflows

  • GRC Solutions

    By Role

    • For Compliance Leaders
    • For Chief Risk Officers
    • For Data Protection Officers
    • For CISOs
    • For Internal Audit Teams

    by industry

    • Banks & NBFCs
    • Insurance
    • Capital Markets
    • Pharma & Healthcare
    • More..

    by regulations

    • RBI Compliance
    • SEBI Compliance
    • IRDAI Compliance
    • DPDP Act
    • More..

    Featured Resource

    • How to Measure Compliance Training Effectiveness
    • Fourth-Party Risk Management Explained
  • Resources
  • Company
eQomply
Request Demo
RBI Compliance

RBI Compliance for NBFCs: Key Requirements and Risks

August 7, 2026 Pritesh Baviskar No comments yet

The regulatory environment for NBFCs in India has undergone a fundamental shift over the past five years. What was once a lighter-touch supervisory regime has evolved into something that increasingly mirrors the scrutiny applied to scheduled commercial banks. For compliance officers and risk leaders at NBFCs, understanding where RBI compliance for NBFCs draws the most attention is no longer optional. It is the difference between smooth inspections and enforcement actions that can stall business growth.

This post maps the specific areas where RBI examiners focus their attention, the common findings that trip up even well-run NBFCs, and what a structurally sound compliance program looks like for an entity navigating rapid growth alongside tightening regulation.

How RBI’s Regulatory Approach to NBFCs Has Tightened

The trajectory is clear if you look at the regulatory actions between 2021 and 2024. RBI cancelled the registrations of over 2,100 NBFCs during this period, issued show-cause notices to dozens more, and imposed business restrictions on several prominent names for violations ranging from pricing opacity to inadequate KYC frameworks. The messaging from the regulator has been consistent: NBFCs that want the privileges of credit intermediation must accept the supervisory intensity that comes with it.

Several structural shifts explain this tightening. The IL&FS crisis exposed systemic risk hiding in the NBFC sector. The rapid growth of digital lending brought consumer protection concerns to the forefront. And the increasing interconnectedness between NBFCs and the banking system, through co-lending and securitization, made RBI uncomfortable with asymmetric regulatory standards across the two segments.

The October 2022 Scale Based Regulation (SBR) framework formalized what had been happening incrementally. It created a graduated regulatory architecture where compliance obligations scale with the size and systemic importance of the NBFC. This framework replaced the earlier binary classification with four distinct layers, each carrying progressively heavier compliance requirements.

Scale-Based Regulation and Its Compliance Implications

The SBR framework categorizes NBFCs into four layers: Base Layer (NBFC-BL), Middle Layer (NBFC-ML), Upper Layer (NBFC-UL), and Top Layer (NBFC-TL). The compliance implications vary significantly across these tiers, and many NBFCs that were previously in the “Investment and Credit Companies” bucket now find themselves subject to substantially more demanding requirements.

What Changes Across the Layers

Compliance Area Base Layer Middle Layer Upper Layer
Minimum Net Owned Fund ₹10 crore ₹10 crore ₹10 crore (higher leverage scrutiny)
NPA Classification 90-day overdue 90-day overdue 90-day overdue + enhanced provisioning
Corporate Governance Basic board requirements Independent directors, key committees Bank-like governance standards
Capital Adequacy (CRAR) 15% 15% 15% with CET-1 minimum of 9%
Large Exposure Framework Not applicable Applicable with limits Stricter limits aligned with banks
Internal Audit Annual Semi-annual or risk-based Concurrent audit expectations

The practical challenge for NBFCs transitioning from Base to Middle Layer, or from Middle to Upper Layer, is that the compliance obligations increase discontinuously. An NBFC crossing the ₹1,000 crore asset threshold suddenly faces Middle Layer requirements across governance, risk management, and disclosure, without proportional growth in its compliance infrastructure. This is where regulatory gaps accumulate.

Key Scrutiny Areas in RBI Compliance for NBFCs

Capital Adequacy and Provisioning

RBI examiners consistently focus on whether NBFCs maintain CRAR above the mandated 15%, and more importantly, whether the computation itself is robust. Common areas of examiner attention include the classification of instruments as Tier-I or Tier-II capital, the treatment of intangible assets in net owned funds calculations, and whether provisioning for NPAs follows the prescribed percentages without creative reclassification of assets to avoid higher provisioning buckets.

Consider an NBFC with a mixed portfolio of microfinance, vehicle loans, and unsecured personal loans. Each segment has different risk weights and provisioning norms. Examiners will test whether the NBFC’s internal systems correctly apply segment-specific provisioning rather than using blended rates that understate actual required provisions. They will also check if restructured accounts are properly flagged and whether the standstill on asset classification, permitted during COVID, was correctly unwound.

Asset Classification and Income Recognition

The shift to 90-day NPA recognition for all NBFCs (effective from March 2022 for those previously on 120/180-day norms) caught several entities underprepared. RBI inspections routinely surface instances where system-level NPA tagging does not align with the prescribed norms, where upgradation of NPAs happens without full clearance of arrears, or where accounts are shown as “regular” through tactical evergreening, such as disbursing a new loan to service an existing one.

The November 2021 circular on NPA classification clarified that the “days past due” calculation must be based on the repayment schedule specified in the loan agreement, with no discretionary buffers. Examiners will pull transaction-level data to verify this, making it critical that your loan management system and compliance tracking operate on the same data with consistent definitions.

Fair Practices Code and Customer Protection

This has become one of the most actively enforced areas of RBI compliance for NBFCs, particularly those operating in digital lending or with LSP (Lending Service Provider) partnerships. RBI’s fair practices code requirements cover loan agreement transparency, interest rate communication, grievance redressal timelines, and recovery practices.

Inspections in 2023 and 2024 have focused heavily on whether NBFCs disclose the all-inclusive cost of credit upfront, whether Key Fact Statements are provided before disbursement, and whether recovery agents operate within the boundaries prescribed by the code. For NBFCs that rely on fintech partnerships for origination, the examiner’s lens extends to whether the NBFC exercises meaningful control over the customer experience or has effectively outsourced regulatory responsibilities to unregulated entities.

IT Governance and Cybersecurity

The June 2023 Master Direction on IT Governance, Risk, Assurance, and Information Security for NBFCs brought technology risk squarely into the compliance perimeter. This framework requires NBFCs above certain thresholds to maintain an IT Strategy Committee at the board level, conduct periodic vulnerability assessments, maintain a Security Operations Center or equivalent capability, and report cybersecurity incidents to CERT-In within six hours.

Consider an NBFC managing compliance across RBI’s master directions on IT governance and CERT-In’s incident reporting requirements simultaneously. The IT governance direction mandates specific controls around data localization, access management, and business continuity planning. CERT-In requires rapid incident escalation with specific taxonomies. This creates a situation where the compliance team must track obligations from multiple regulators that sometimes overlap, sometimes conflict in their timelines, and almost always require coordinated evidence across IT, operations, and legal functions.

Outsourcing Risk Management

RBI’s guidelines on outsourcing of financial services apply to NBFCs with particular force because the sector’s operating model relies heavily on third-party relationships, from loan origination through fintech partners to collections through recovery agencies to technology through cloud providers.

Examiners look for documented outsourcing policies approved by the board, risk assessments for each material outsourcing arrangement, contractual provisions ensuring RBI’s right to inspect the service provider, and evidence that the NBFC monitors outsourced activities on an ongoing basis rather than treating the vendor contract as a compliance endpoint. The gap between having a policy document and demonstrating active oversight of outsourced activities is where most NBFCs face adverse findings.

Common Inspection Findings Specific to NBFCs

Having reviewed publicly available enforcement orders and speaking with compliance practitioners across the NBFC segment, certain patterns emerge repeatedly in RBI inspection findings. Understanding these patterns helps compliance teams prioritize their readiness efforts.

Documentation and Evidence Gaps

The most frequent category of adverse findings relates not to the absence of controls, but to the inability to demonstrate that controls operate effectively. An NBFC may have a robust loan approval process, but if the credit committee minutes are not maintained in a retrievable format, or if policy attestations from branch staff cannot be produced on demand, the examiner will record it as a deficiency. This is fundamentally an evidence management problem, not a policy design problem.

Governance Deficiencies

Findings in this category include boards that meet infrequently, risk management committees that lack independent representation, compliance officers who report to the CFO rather than the board, and the absence of documented criteria for identifying material outsourcing arrangements. For NBFCs in the Middle and Upper layers, RBI expects governance structures that mirror banking norms, including a Chief Compliance Officer with direct board access and a dedicated risk management function independent of business lines.

Concentration and Connected Lending

RBI pays close attention to whether NBFCs exceed single-borrower and group-borrower exposure limits, and whether lending to related parties follows the prescribed arm’s-length framework. Promoter-linked entities, common in the NBFC space, attract particular scrutiny. Examiners will trace fund flows to determine if loans have been extended to entities with undisclosed connections to the NBFC’s promoter group.

Delayed Regulatory Filings

NBFCs are required to submit periodic returns to RBI, including the NBS-7 (quarterly), ALM statements, CRILC reporting, and various compliance certificates. Consistent delays in these filings, even when the underlying compliance posture is sound, signal supervisory risk and can trigger increased inspection frequency. The challenge for growing NBFCs is that the number of required filings increases with scale, often outpacing the compliance team’s capacity.

Building a Compliance Program for a Growing NBFC

A structurally sound RBI compliance program for NBFCs must account for three realities: the regulatory perimeter will continue expanding, the inspection frequency will increase as you grow, and the expectation of demonstrable evidence (rather than policy-on-paper) will intensify.

Map Obligations to Specific Master Directions

The starting point is a comprehensive obligation register that maps each compliance requirement to its source regulation, assigns ownership within the organization, sets deadlines, and tracks completion status. For a Middle Layer NBFC, this register will typically include 200 to 400 discrete obligations across capital adequacy, asset classification, fair practices, IT governance, outsourcing, KYC/AML, and corporate governance norms. Maintaining this in spreadsheets works until your first inspection reveals the gaps in version control and audit trails.

Establish Inspection Readiness as a Continuous State

The most common mistake is treating inspection preparation as an event rather than an operating discipline. NBFCs that perform well in RBI inspections maintain audit-ready documentation at all times: board minutes indexed by topic, policy versions with clear effective dates, evidence of control operation (not just control design), and a clear trail from regulatory requirement to organizational implementation.

This requires systems that automatically capture compliance evidence as part of daily operations rather than retrospectively assembling it when the inspection letter arrives. eQomply’s approach to evidence management addresses exactly this challenge, linking regulatory obligations to the operational evidence that demonstrates compliance, maintained continuously rather than reconstructed under time pressure.

Consolidate Cross-Regulatory Tracking

An NBFC’s regulatory universe extends beyond RBI. CERT-In’s six-hour incident reporting, the DPDP Act’s data protection obligations, SEBI requirements for listed entities, and sector-specific norms (like insurance regulations for credit-linked products) all create overlapping compliance demands. The compliance function must consolidate these into a unified tracking framework that prevents regulatory arbitrage between functions, where IT handles CERT-In independently from the compliance team handling RBI’s IT governance direction, resulting in inconsistent controls and duplicated effort.

Invest in Scalable Infrastructure Early

The structural challenge for NBFCs is that regulatory obligations increase discontinuously (at each SBR layer transition) while compliance infrastructure typically scales linearly with headcount. This mismatch creates periodic crises where the organization’s growth triggers new regulatory requirements that the existing team and tools cannot absorb.

Platforms like eQomply are designed specifically for this growth trajectory in Indian regulated enterprises, providing pre-mapped regulatory workflows for RBI master directions, automated obligation tracking, and inspection-ready reporting that scales with organizational complexity without requiring proportional headcount increases.

Conclusion: Compliance as Competitive Advantage

For NBFCs operating in today’s regulatory environment, the cost of compliance gaps extends well beyond penalties. Business restrictions, reputational damage, and increased supervisory burden all constrain growth far more than the investment required to build a robust compliance program. The NBFCs that thrive under the SBR framework will be those that treat compliance infrastructure as a growth enabler, building systems that scale with regulatory complexity rather than reacting to each new directive in isolation.

If your NBFC is navigating a layer transition, preparing for its next RBI inspection, or looking to consolidate compliance tracking across multiple regulatory frameworks, it may be worth exploring how purpose-built GRC infrastructure can reduce that burden. You can schedule a demo with eQomply to see how Indian NBFCs are operationalizing RBI compliance at scale.

  • compliance
  • NBFC
  • RBI
  • regulation
Pritesh Baviskar
Pritesh Baviskar

Founder at eQomply. Writes about compliance, regulatory shifts, and what it takes to build GRC functions that actually work.

Post navigation

Previous
Next

Search

Categories

  • Board Reporting (5)
  • CERT-In (5)
  • Compliance Management (12)
  • DPDP Act (10)
  • Evidence Management (6)
  • GRC (9)
  • Guides (5)
  • IRDAI Compliance (5)
  • Perspectives (1)
  • RBI Compliance (10)
  • SEBI Compliance (6)
  • Third Party Risk (5)
  • Uncategorized (4)

Recent posts

  • Fintech Compliance Challenges in India
  • SEBI Investor Grievance Compliance: Key Requirements
  • Three Lines of Defense: How the Model Works in Practice

Tags

AML audit audit readiness banking banking compliance BFSI board reporting brokers capital markets case-studies CERT-In circulars compliance CRO CSCRF cybersecurity data fiduciary data protection documentation DPDP DPO enforcement evidence framework governance GRC gst compliance incident reporting inspection insurance IRDAI IT governance multi-regulator NBFC outsourcing penalties privacy RBI regulation risk management SEBI spreadsheets stock market third party risk vendor risk

Related posts

Compliance Management

Fintech Compliance Challenges in India

August 13, 2026 Pritesh Baviskar No comments yet

Fintech compliance challenges in India grow as companies scale, bringing more regulatory obligations and scrutiny.

SEBI Compliance

SEBI Investor Grievance Compliance: Key Requirements

August 12, 2026 Pritesh Baviskar No comments yet

Understand SEBI investor grievance compliance, including SCORES, response timelines, escalation requirements for brokers and AMCs.

Compliance Management

Whistleblower Compliance in India: Key Requirements

August 6, 2026 Pritesh Baviskar No comments yet

Understand whistleblower compliance requirements in India, including SEBI, RBI, and Companies Act obligations along with protection measures.

Subscribe to Field Notes

    Enterprise GRC for regulated industries

    Platform
    • Overview
    • Policy Management
    • Risk Management
    • Compliance
    Solutions
    • By Role
    • By Industry
    • By Regulation
    Resources
    • Field Notes
    • Guides
    • Regulatory Library
    • Terms of Services
    • Privacy Policy

    © QomplySuite Private Limited Copyright 2026