Skip to content
eQomply
  • Platform

    Platform

    • Governance
    • Risk Management
    • Compliance Management
    • Integrations
    0 +

    Evidences Tracked

    0 +

    Regulatory Workflows

  • GRC Solutions

    By Role

    • For Compliance Leaders
    • For Chief Risk Officers
    • For Data Protection Officers
    • For CISOs
    • For Internal Audit Teams

    by industry

    • Banks & NBFCs
    • Insurance
    • Capital Markets
    • Pharma & Healthcare
    • More..

    by regulations

    • RBI Compliance
    • SEBI Compliance
    • IRDAI Compliance
    • DPDP Act
    • More..

    Featured Resource

    • Compliance Documentation Best Practices
    • IRDAI AML Compliance for Insurers Explained
  • Resources
  • Company
eQomply
Request Demo
RBI Compliance

RBI Fair Practices Code Compliance for NBFCs

July 23, 2026 Pritesh Baviskar No comments yet

The Reserve Bank of India’s Fair Practices Code (FPC) remains one of the most frequently cited areas during supervisory inspections of NBFCs. Despite being in existence since 2006, RBI fair practices code compliance continues to generate a disproportionate share of inspection observations, regulatory directions, and enforcement actions. The reasons are structural: the code touches every customer-facing process, requires board-level governance, and demands documentation rigor that many NBFCs still treat as an afterthought.

For compliance leaders at NBFCs, the challenge is compounded by the fact that the FPC intersects with multiple other regulatory frameworks, including KYC/AML requirements, digital lending guidelines, and the recent DPDP Act obligations. This post breaks down the core compliance requirements, common failure points, and what a robust monitoring framework looks like in practice.

The Regulatory Foundation: RBI’s Fair Practices Code for NBFCs

The FPC framework for NBFCs originates from the Master Direction on Non-Banking Financial Company, Systemically Important Non-Deposit taking Company and Deposit taking Company (Reserve Bank) Directions, 2016, supplemented by various circulars and the updated Digital Lending Guidelines of 2022. The code applies to all NBFCs registered with RBI, regardless of whether they accept deposits.

The fundamental regulatory intent is straightforward: ensure that NBFCs deal with borrowers in a fair, transparent, and non-discriminatory manner. In practice, this translates into specific obligations across the loan lifecycle, from application receipt through disbursal, servicing, and recovery. The code also mandates a governance structure where the board of directors directly approves the fair practices policy and reviews its implementation periodically.

Unlike principle-based regulations where interpretation carries some flexibility, the FPC contains prescriptive requirements. RBI expects literal compliance with specific disclosure formats, timelines, and communication protocols. This prescriptive nature makes non-compliance easily identifiable during inspections, which is precisely why it surfaces so frequently in supervisory findings.

Key Requirements Under the Fair Practices Code

Loan Application Processing and Communication

Every loan application must be accompanied by an acknowledgement receipt. This sounds trivial until you consider an NBFC processing 50,000 applications monthly across multiple branches and digital channels. The requirement extends to maintaining a record of every application received, regardless of whether it is approved or rejected. For rejected applications, the NBFC must communicate the reasons for rejection in writing to the applicant.

The loan appraisal process itself must follow documented, non-discriminatory criteria. RBI expects that the parameters used for credit decisions are clearly defined and consistently applied. This creates a documentation obligation that extends beyond the compliance function into credit operations, where the rationale for each decision must be traceable and auditable.

Consider a mid-sized NBFC operating across 15 states with both branch-originated and digitally-originated loans. The FPC requires that the same transparency standards apply regardless of origination channel. The Digital Lending Guidelines of 2022 further reinforced this by mandating that all communication to borrowers must come from the regulated entity, not from lending service providers (LSPs) operating on its behalf.

Transparency in Terms and Conditions

The sanction letter must clearly communicate all terms and conditions, including the annualized rate of interest and the method of application thereof. Any fees or charges payable must be disclosed upfront. Changes in terms and conditions, including interest rate resets, require prior notice to borrowers with adequate lead time.

The following table summarizes the key disclosure obligations at each stage of the loan lifecycle:

Stage Disclosure Requirement Timeline
Application Acknowledgement with application details At receipt
Sanction All terms, annualized interest rate, fees, charges With sanction letter
Disbursement Loan account statement, EMI schedule At disbursement
Servicing Changes in interest rate or terms Prospective notice before effective date
Closure No-objection certificate, release of securities Within specified timeline post closure
Rejection Reasons for rejection in writing Within reasonable time

A critical nuance here relates to the “most important terms and conditions” (MITC) requirement. RBI expects that MITCs are provided in the language understood by the borrower, which for NBFCs operating in multiple states means maintaining translated versions and ensuring the correct version reaches the correct borrower. This is an operational challenge that compliance teams often underestimate until it appears as an inspection observation.

Grievance Redressal Mechanism

The FPC mandates a structured grievance redressal mechanism with clearly defined escalation paths. Every NBFC must designate a Nodal Officer for complaint resolution, display grievance redressal contact details at branches and on websites, and resolve complaints within specified timelines. The integration with the RBI Integrated Ombudsman Scheme (RB-IOS) adds another layer where unresolved complaints escalate to the regulator directly.

The regulatory expectation is not merely that a mechanism exists, but that it functions demonstrably. RBI supervisors examine complaint resolution rates, turnaround times, root cause analysis, and whether systemic issues identified through complaints translate into process corrections. This creates a feedback loop obligation: complaints are not just individual grievances to be resolved but data points that should inform policy and process changes at the institutional level.

Board-Approved Policy Requirements

The governance dimension of RBI fair practices code compliance is where many NBFCs face structural gaps. The code requires that the board of directors approve the FPC policy and review it at least annually. This is not a formality. RBI inspectors specifically verify whether the board has meaningfully engaged with the policy, whether review discussions are documented in board minutes, and whether the approved policy reflects current regulatory requirements including subsequent circulars.

The board-approved policy must cover several specific areas: loan application and processing procedures, communication standards, interest rate model and method of calculation, collection and recovery practices, and the grievance redressal mechanism. For NBFCs that have undergone significant product expansion or channel digitization since their last board review, the policy may be materially outdated relative to actual practices, which constitutes a compliance gap regardless of whether individual transactions comply with FPC principles.

There is also an obligation to ensure that the board reviews compliance with the FPC through periodic reports from the compliance function. This connects the FPC governance requirement to the broader compliance monitoring framework. Platforms like eQomply enable compliance teams to maintain policy version control, track board attestation cycles, and generate compliance status reports that directly feed into board reporting, ensuring the governance trail remains intact and inspection-ready.

Documentation and Disclosure Obligations

Documentation under the FPC operates at three levels: customer-facing disclosures, internal process records, and supervisory reporting artifacts.

Customer-facing documentation includes the MITC, loan agreements in the borrower’s language, interest rate communication, and recovery-related notices. Each of these must follow specific formatting requirements and contain prescribed information. The Digital Lending Guidelines added requirements around the Key Fact Statement (KFS), which must be provided to the borrower before loan execution and must contain all costs in an annualized format.

Internal process documentation covers the audit trail of credit decisions, complaint records, recovery action logs, and policy implementation evidence. This is where the evidence management discipline becomes critical. During inspections, RBI supervisors may request documentation for sampled transactions spanning several years. The ability to retrieve specific loan applications, sanction letters, acknowledgement receipts, and communication records for randomly selected accounts is a practical test of compliance infrastructure.

Supervisory reporting includes the annual compliance certificate, complaint data submissions, and any specific information requested during the inspection process. For teams preparing for RBI inspections, having pre-organized evidence packs mapped to FPC requirements significantly reduces the operational disruption caused by the inspection process. More on inspection preparedness is covered in our detailed guide on RBI inspection preparation.

Common Inspection Findings on Fair Practices Code

Analysis of publicly available RBI enforcement actions and supervisory observations reveals recurring patterns in FPC non-compliance. Understanding these patterns allows compliance leaders to proactively address vulnerabilities before they become findings.

Non-communication of Rejection Reasons

This remains the single most common FPC observation. NBFCs either do not communicate rejection reasons at all, or communicate them in vague, template language that does not meet the specificity standard. In digital lending contexts, automated rejections often lack the documentation trail that demonstrates a reason was communicated to the applicant.

Interest Rate and Fee Transparency Gaps

Inspectors frequently find discrepancies between the disclosed interest rate methodology and actual computation, undisclosed processing fees or convenience charges levied through LSPs, and failure to provide prior notice for interest rate changes. These findings often intersect with concerns under the KYC and AML compliance framework, particularly where customer due diligence processes do not adequately document the agreed terms of engagement.

Recovery Practices Non-compliance

The FPC places specific restrictions on recovery practices, including prohibition of intimidation, restrictions on calling hours, and requirements around notice before initiating recovery actions. NBFCs using third-party recovery agents face additional obligations around agent training, supervision, and accountability for agent conduct. Findings in this area frequently escalate to serious enforcement actions given the consumer harm dimension.

Outdated Board-Approved Policies

A surprisingly common finding is that the board-approved FPC policy does not reflect current regulatory requirements. Where an NBFC has expanded into new products (e.g., digital personal loans, BNPL, co-lending arrangements) without updating the FPC policy to cover these products, the governance gap extends to every transaction in those categories.

Grievance Redressal Deficiencies

Observations here range from non-functional complaint channels to inadequate escalation mechanisms to failure to conduct root cause analysis on complaint trends. RBI increasingly expects that complaint data is analyzed for systemic patterns and that the board reviews complaint analytics as part of its FPC governance responsibilities.

Building Compliance Monitoring for Fair Practices

Effective RBI fair practices code compliance requires a monitoring framework that operates continuously rather than through periodic check-the-box reviews. The structural challenge is that FPC obligations are embedded in operational processes owned by business teams (credit, operations, collections) rather than the compliance function directly. Compliance must therefore build monitoring mechanisms that provide visibility without requiring manual intervention in every transaction.

Defining Control Points and Monitoring Triggers

The first step is mapping every FPC obligation to a specific process step, system control, or documentation checkpoint. For each requirement, define what “good” looks like in measurable terms: acknowledgement generated within X hours of application receipt, rejection communication sent within Y days of decision, interest rate disclosure matching actual computation within Z basis points tolerance.

This mapping creates the control framework against which monitoring can operate. Consider an NBFC with both branch and digital channels. The control framework must account for different system environments while maintaining a unified compliance standard. The monitoring triggers will differ (manual check at branch vs. system-generated alert for digital) but the compliance standard remains identical.

Evidence Capture and Retention

For every control point, define what evidence constitutes proof of compliance. This includes system-generated logs, signed documents, communication records, and timestamp evidence. The evidence retention framework must align with the inspection look-back period, which for RBI can extend to three years or more for specific areas of concern.

A centralized evidence management approach, where compliance artifacts from multiple source systems are consolidated into an auditable repository, reduces the risk of evidence gaps during inspections. eQomply’s evidence management capabilities are designed precisely for this use case, enabling compliance teams to maintain inspection-ready documentation with automatic capture from operational systems and complete audit trails.

Periodic Testing and Reporting

Beyond continuous monitoring, the compliance function should conduct periodic thematic reviews of FPC adherence. This involves sampling transactions, reviewing complaint data for FPC-related themes, assessing training effectiveness for customer-facing staff and recovery agents, and verifying that disclosures remain current and accurate.

The output of this monitoring feeds into multiple governance streams: the compliance function’s own risk assessment, board reporting on FPC compliance status, and preparation materials for supervisory interactions. A well-structured monitoring framework transforms FPC compliance from a reactive, inspection-driven exercise into a proactive governance discipline.

Connecting FPC Monitoring to Broader GRC Infrastructure

Fair practices code compliance does not exist in isolation. It connects to customer data protection obligations under the DPDP Act (particularly around purpose limitation and notice requirements), to conduct risk frameworks, and to operational risk assessment. A compliance team managing these obligations through disconnected tools, spreadsheets, and manual trackers faces inevitable gaps when the regulatory requirement is for integrated, real-time oversight.

Regulated enterprises that consolidate their compliance monitoring infrastructure gain a structural advantage: the ability to see how a single process failure (say, non-communication of terms in digital lending) creates compliance exposure across multiple regulatory domains simultaneously, whether FPC, digital lending guidelines, or data protection requirements.

Moving from Reactive to Structural Compliance

The difference between NBFCs that consistently receive clean inspection reports on FPC compliance and those that accumulate observations lies not in awareness of requirements but in the infrastructure supporting ongoing adherence. Requirements are well-documented and publicly available. The execution challenge is in maintaining compliance across thousands of daily transactions, multiple channels, changing product portfolios, and evolving regulatory expectations.

Compliance leaders who recognize this as an infrastructure problem rather than a knowledge problem position their institutions to handle not just current FPC requirements but the inevitable expansions, whether through new digital lending norms, enhanced disclosure requirements, or tighter grievance resolution timelines.

If your NBFC is looking to build or strengthen its RBI fair practices code compliance monitoring framework with the kind of centralized evidence management, policy governance, and regulatory mapping that inspections demand, a focused walkthrough of how eQomply supports this would be worth 30 minutes of your time.

  • compliance
  • fair practices
  • NBFC
  • RBI
Pritesh Baviskar
Pritesh Baviskar

Founder at eQomply. Writes about compliance, regulatory shifts, and what it takes to build GRC functions that actually work.

Post navigation

Previous
Next

Search

Categories

  • Board Reporting (5)
  • CERT-In (4)
  • Compliance Management (8)
  • DPDP Act (10)
  • Evidence Management (5)
  • GRC (7)
  • Guides (5)
  • IRDAI Compliance (4)
  • Perspectives (1)
  • RBI Compliance (9)
  • SEBI Compliance (5)
  • Third Party Risk (4)
  • Uncategorized (4)

Recent posts

  • DPDP Act Compliance for Healthcare Organizations
  • RBI Fair Practices Code Compliance for NBFCs
  • Internal Audit and Compliance: How to Work Better Together

Tags

AMC AML audit audit readiness banking BFSI board reporting breach notification case-studies CERT-In circulars cloud compliance consent CRO cyber audit cybersecurity data protection documentation DPDP evidence governance GRC incident reporting inspection insurance IRDAI IRM IT governance metrics NBFC outsourcing payment aggregator policy management privacy RBI regulation risk management risk register SEBI third party risk vendor monitoring vendor risk version control VPN

Related posts

DPDP Act

DPDP Act Compliance for Healthcare Organizations

July 24, 2026 Pritesh Baviskar No comments yet

Healthcare organizations in India process some of the most sensitive personal data imaginable. From diagnostic reports and prescriptions to genetic information and mental health records, the volume and sensitivity of health data places hospitals, pharma companies, and diagnostic chains squarely in the high-risk category under the Digital Personal Data Protection Act, 2023. DPDP Act compliance […]

Board Reporting

Internal Audit and Compliance: How to Work Better Together

July 22, 2026 Pritesh Baviskar No comments yet

Explore how internal audit and compliance teams can align on risks, controls, evidence, and findings to improve governance.

Evidence Management

Compliance Documentation Best Practices

July 21, 2026 Pritesh Baviskar No comments yet

Discover compliance documentation best practices, including version control, traceability, retention, and audit-ready record management.

Subscribe to Field Notes

    Enterprise GRC for regulated industries

    Platform
    • Overview
    • Policy Management
    • Risk Management
    • Compliance
    Solutions
    • By Role
    • By Industry
    • By Regulation
    Resources
    • Field Notes
    • Guides
    • Regulatory Library
    • Terms of Services
    • Privacy Policy

    © QomplySuite Private Limited Copyright 2026