RBI Compliance for NBFCs: Key Requirements and Risks
The regulatory environment for NBFCs in India has undergone a fundamental shift over the past five years. What was once a lighter-touch supervisory regime has evolved into something that increasingly mirrors the scrutiny applied to scheduled commercial banks. For compliance officers and risk leaders at NBFCs, understanding where RBI compliance for NBFCs draws the most attention is no longer optional. It is the difference between smooth inspections and enforcement actions that can stall business growth.
This post maps the specific areas where RBI examiners focus their attention, the common findings that trip up even well-run NBFCs, and what a structurally sound compliance program looks like for an entity navigating rapid growth alongside tightening regulation.
How RBI’s Regulatory Approach to NBFCs Has Tightened
The trajectory is clear if you look at the regulatory actions between 2021 and 2024. RBI cancelled the registrations of over 2,100 NBFCs during this period, issued show-cause notices to dozens more, and imposed business restrictions on several prominent names for violations ranging from pricing opacity to inadequate KYC frameworks. The messaging from the regulator has been consistent: NBFCs that want the privileges of credit intermediation must accept the supervisory intensity that comes with it.
Several structural shifts explain this tightening. The IL&FS crisis exposed systemic risk hiding in the NBFC sector. The rapid growth of digital lending brought consumer protection concerns to the forefront. And the increasing interconnectedness between NBFCs and the banking system, through co-lending and securitization, made RBI uncomfortable with asymmetric regulatory standards across the two segments.
The October 2022 Scale Based Regulation (SBR) framework formalized what had been happening incrementally. It created a graduated regulatory architecture where compliance obligations scale with the size and systemic importance of the NBFC. This framework replaced the earlier binary classification with four distinct layers, each carrying progressively heavier compliance requirements.
Scale-Based Regulation and Its Compliance Implications
The SBR framework categorizes NBFCs into four layers: Base Layer (NBFC-BL), Middle Layer (NBFC-ML), Upper Layer (NBFC-UL), and Top Layer (NBFC-TL). The compliance implications vary significantly across these tiers, and many NBFCs that were previously in the “Investment and Credit Companies” bucket now find themselves subject to substantially more demanding requirements.
What Changes Across the Layers
| Compliance Area | Base Layer | Middle Layer | Upper Layer |
|---|---|---|---|
| Minimum Net Owned Fund | ₹10 crore | ₹10 crore | ₹10 crore (higher leverage scrutiny) |
| NPA Classification | 90-day overdue | 90-day overdue | 90-day overdue + enhanced provisioning |
| Corporate Governance | Basic board requirements | Independent directors, key committees | Bank-like governance standards |
| Capital Adequacy (CRAR) | 15% | 15% | 15% with CET-1 minimum of 9% |
| Large Exposure Framework | Not applicable | Applicable with limits | Stricter limits aligned with banks |
| Internal Audit | Annual | Semi-annual or risk-based | Concurrent audit expectations |
The practical challenge for NBFCs transitioning from Base to Middle Layer, or from Middle to Upper Layer, is that the compliance obligations increase discontinuously. An NBFC crossing the ₹1,000 crore asset threshold suddenly faces Middle Layer requirements across governance, risk management, and disclosure, without proportional growth in its compliance infrastructure. This is where regulatory gaps accumulate.
Key Scrutiny Areas in RBI Compliance for NBFCs
Capital Adequacy and Provisioning
RBI examiners consistently focus on whether NBFCs maintain CRAR above the mandated 15%, and more importantly, whether the computation itself is robust. Common areas of examiner attention include the classification of instruments as Tier-I or Tier-II capital, the treatment of intangible assets in net owned funds calculations, and whether provisioning for NPAs follows the prescribed percentages without creative reclassification of assets to avoid higher provisioning buckets.
Consider an NBFC with a mixed portfolio of microfinance, vehicle loans, and unsecured personal loans. Each segment has different risk weights and provisioning norms. Examiners will test whether the NBFC’s internal systems correctly apply segment-specific provisioning rather than using blended rates that understate actual required provisions. They will also check if restructured accounts are properly flagged and whether the standstill on asset classification, permitted during COVID, was correctly unwound.
Asset Classification and Income Recognition
The shift to 90-day NPA recognition for all NBFCs (effective from March 2022 for those previously on 120/180-day norms) caught several entities underprepared. RBI inspections routinely surface instances where system-level NPA tagging does not align with the prescribed norms, where upgradation of NPAs happens without full clearance of arrears, or where accounts are shown as “regular” through tactical evergreening, such as disbursing a new loan to service an existing one.
The November 2021 circular on NPA classification clarified that the “days past due” calculation must be based on the repayment schedule specified in the loan agreement, with no discretionary buffers. Examiners will pull transaction-level data to verify this, making it critical that your loan management system and compliance tracking operate on the same data with consistent definitions.
Fair Practices Code and Customer Protection
This has become one of the most actively enforced areas of RBI compliance for NBFCs, particularly those operating in digital lending or with LSP (Lending Service Provider) partnerships. RBI’s fair practices code requirements cover loan agreement transparency, interest rate communication, grievance redressal timelines, and recovery practices.
Inspections in 2023 and 2024 have focused heavily on whether NBFCs disclose the all-inclusive cost of credit upfront, whether Key Fact Statements are provided before disbursement, and whether recovery agents operate within the boundaries prescribed by the code. For NBFCs that rely on fintech partnerships for origination, the examiner’s lens extends to whether the NBFC exercises meaningful control over the customer experience or has effectively outsourced regulatory responsibilities to unregulated entities.
IT Governance and Cybersecurity
The June 2023 Master Direction on IT Governance, Risk, Assurance, and Information Security for NBFCs brought technology risk squarely into the compliance perimeter. This framework requires NBFCs above certain thresholds to maintain an IT Strategy Committee at the board level, conduct periodic vulnerability assessments, maintain a Security Operations Center or equivalent capability, and report cybersecurity incidents to CERT-In within six hours.
Consider an NBFC managing compliance across RBI’s master directions on IT governance and CERT-In’s incident reporting requirements simultaneously. The IT governance direction mandates specific controls around data localization, access management, and business continuity planning. CERT-In requires rapid incident escalation with specific taxonomies. This creates a situation where the compliance team must track obligations from multiple regulators that sometimes overlap, sometimes conflict in their timelines, and almost always require coordinated evidence across IT, operations, and legal functions.
Outsourcing Risk Management
RBI’s guidelines on outsourcing of financial services apply to NBFCs with particular force because the sector’s operating model relies heavily on third-party relationships, from loan origination through fintech partners to collections through recovery agencies to technology through cloud providers.
Examiners look for documented outsourcing policies approved by the board, risk assessments for each material outsourcing arrangement, contractual provisions ensuring RBI’s right to inspect the service provider, and evidence that the NBFC monitors outsourced activities on an ongoing basis rather than treating the vendor contract as a compliance endpoint. The gap between having a policy document and demonstrating active oversight of outsourced activities is where most NBFCs face adverse findings.
Common Inspection Findings Specific to NBFCs
Having reviewed publicly available enforcement orders and speaking with compliance practitioners across the NBFC segment, certain patterns emerge repeatedly in RBI inspection findings. Understanding these patterns helps compliance teams prioritize their readiness efforts.
Documentation and Evidence Gaps
The most frequent category of adverse findings relates not to the absence of controls, but to the inability to demonstrate that controls operate effectively. An NBFC may have a robust loan approval process, but if the credit committee minutes are not maintained in a retrievable format, or if policy attestations from branch staff cannot be produced on demand, the examiner will record it as a deficiency. This is fundamentally an evidence management problem, not a policy design problem.
Governance Deficiencies
Findings in this category include boards that meet infrequently, risk management committees that lack independent representation, compliance officers who report to the CFO rather than the board, and the absence of documented criteria for identifying material outsourcing arrangements. For NBFCs in the Middle and Upper layers, RBI expects governance structures that mirror banking norms, including a Chief Compliance Officer with direct board access and a dedicated risk management function independent of business lines.
Concentration and Connected Lending
RBI pays close attention to whether NBFCs exceed single-borrower and group-borrower exposure limits, and whether lending to related parties follows the prescribed arm’s-length framework. Promoter-linked entities, common in the NBFC space, attract particular scrutiny. Examiners will trace fund flows to determine if loans have been extended to entities with undisclosed connections to the NBFC’s promoter group.
Delayed Regulatory Filings
NBFCs are required to submit periodic returns to RBI, including the NBS-7 (quarterly), ALM statements, CRILC reporting, and various compliance certificates. Consistent delays in these filings, even when the underlying compliance posture is sound, signal supervisory risk and can trigger increased inspection frequency. The challenge for growing NBFCs is that the number of required filings increases with scale, often outpacing the compliance team’s capacity.
Building a Compliance Program for a Growing NBFC
A structurally sound RBI compliance program for NBFCs must account for three realities: the regulatory perimeter will continue expanding, the inspection frequency will increase as you grow, and the expectation of demonstrable evidence (rather than policy-on-paper) will intensify.
Map Obligations to Specific Master Directions
The starting point is a comprehensive obligation register that maps each compliance requirement to its source regulation, assigns ownership within the organization, sets deadlines, and tracks completion status. For a Middle Layer NBFC, this register will typically include 200 to 400 discrete obligations across capital adequacy, asset classification, fair practices, IT governance, outsourcing, KYC/AML, and corporate governance norms. Maintaining this in spreadsheets works until your first inspection reveals the gaps in version control and audit trails.
Establish Inspection Readiness as a Continuous State
The most common mistake is treating inspection preparation as an event rather than an operating discipline. NBFCs that perform well in RBI inspections maintain audit-ready documentation at all times: board minutes indexed by topic, policy versions with clear effective dates, evidence of control operation (not just control design), and a clear trail from regulatory requirement to organizational implementation.
This requires systems that automatically capture compliance evidence as part of daily operations rather than retrospectively assembling it when the inspection letter arrives. eQomply’s approach to evidence management addresses exactly this challenge, linking regulatory obligations to the operational evidence that demonstrates compliance, maintained continuously rather than reconstructed under time pressure.
Consolidate Cross-Regulatory Tracking
An NBFC’s regulatory universe extends beyond RBI. CERT-In’s six-hour incident reporting, the DPDP Act’s data protection obligations, SEBI requirements for listed entities, and sector-specific norms (like insurance regulations for credit-linked products) all create overlapping compliance demands. The compliance function must consolidate these into a unified tracking framework that prevents regulatory arbitrage between functions, where IT handles CERT-In independently from the compliance team handling RBI’s IT governance direction, resulting in inconsistent controls and duplicated effort.
Invest in Scalable Infrastructure Early
The structural challenge for NBFCs is that regulatory obligations increase discontinuously (at each SBR layer transition) while compliance infrastructure typically scales linearly with headcount. This mismatch creates periodic crises where the organization’s growth triggers new regulatory requirements that the existing team and tools cannot absorb.
Platforms like eQomply are designed specifically for this growth trajectory in Indian regulated enterprises, providing pre-mapped regulatory workflows for RBI master directions, automated obligation tracking, and inspection-ready reporting that scales with organizational complexity without requiring proportional headcount increases.
Conclusion: Compliance as Competitive Advantage
For NBFCs operating in today’s regulatory environment, the cost of compliance gaps extends well beyond penalties. Business restrictions, reputational damage, and increased supervisory burden all constrain growth far more than the investment required to build a robust compliance program. The NBFCs that thrive under the SBR framework will be those that treat compliance infrastructure as a growth enabler, building systems that scale with regulatory complexity rather than reacting to each new directive in isolation.
If your NBFC is navigating a layer transition, preparing for its next RBI inspection, or looking to consolidate compliance tracking across multiple regulatory frameworks, it may be worth exploring how purpose-built GRC infrastructure can reduce that burden. You can schedule a demo with eQomply to see how Indian NBFCs are operationalizing RBI compliance at scale.



