RBI Digital Lending Guidelines: A Working Checklist for Credit and Compliance Teams
The governing instrument is the Reserve Bank of India (Digital Lending) Directions, 2025 — RBI/2025-26/36, DOR.STR.REC.19/21.07.001/2025-26, dated 8 May 2025. It repeals the 2020, 2022 and 2023 digital lending and DLG circulars and consolidates them into one set of thirty paragraphs across seven chapters. This is the clause-by-clause checklist.
Key facts
- One instrument, seven chapters, thirty paragraphs. The Directions took effect on issue, except paragraph 6 (LSPs serving multiple lenders) from 1 November 2025 and paragraph 17 (DLA reporting to CIMS) from 15 June 2025 (RBI, Digital Lending Directions, 2025). The RBI notification page carried no subsequent amendment as at 27 August 2026.
- They repealed three circulars outright — RBI/2019-20/258 (24 June 2020), RBI/2022-23/111 (2 September 2022) and RBI/2023-24/41 (8 June 2023, the DLG guidelines). If your compliance register still cites those circular numbers, it is pointing at repealed instruments.
- DLG is capped at 5%. Total Default Loss Guarantee cover "shall not exceed five per cent of the total amount disbursed" from a portfolio at any time, and the portfolio must be fixed, not dynamic (para 23).
- Everything reaching a credit committee has to be traceable. YuSight's CAM carries 100% of figures cited, with one-click source verification — which is what turns "our model considered bank statement inflows" into an evidence line an examiner can actually open.
- Applicability is broad. Commercial banks including SFBs, LABs and RRBs, primary urban and state and central co-operative banks, NBFCs including HFCs, and all-India financial institutions (para 3).
Which version of the RBI digital lending rules is in force?
Instrument | Circular no. | Date | Status |
|---|---|---|---|
Reserve Bank of India (Digital Lending) Directions, 2025 | RBI/2025-26/36, DOR.STR.REC.19/21.07.001/2025-26 | 8 May 2025 | In force. No amendment listed on the RBI notification page as at 27 August 2026 |
Loans sourced over Digital Lending Platforms | RBI/2019-20/258 | 24 June 2020 | Repealed by para 30 |
Guidelines on Digital Lending | RBI/2022-23/111 | 2 September 2022 | Repealed by para 30 |
Guidelines on Default Loss Guarantee | RBI/2023-24/41 | 8 June 2023 | Repealed by para 30 |
RBI/2024-25/18, DOR.STR.REC.13/13.03.00/2024-25 | 15 April 2024 | In force. Referenced by paras 4 and 8. Applies to new retail and MSME term loans sanctioned on or after 1 October 2024 | |
RBI/2023-24/53, DoR.MCS.REC.28/01.01.001/2023-24 | 18 August 2023 | In force. Referenced by para 8. Implementation date was subsequently deferred by RBI — confirm the date applicable to your book |
Use the checklists below against the 2025 Directions. Populate the owner and evidence columns before your next internal audit, not during it.
Checklist 1 — Scope and definitions (paras 3–4)
Get these four determinations in writing before anything else, because every other obligation hangs off them.
# | Control | Owner | Evidence to hold |
|---|---|---|---|
1.1 | Confirm the entity is a Regulated Entity within para 3 and record which category | Compliance | Board note recording applicability determination |
1.2 | Determine whether each product is "digital lending" — "a remote and automated lending process, largely by use of seamless digital technologies for customer acquisition, credit assessment, loan approval, disbursement, recovery, and associated customer service" (para 4) | Compliance + Product | Product-wise applicability matrix, signed |
1.3 | Identify every DLA — own and LSP — including modules embedded inside a broader app | Product + IT | DLA inventory with version, owner and go-live date |
1.4 | Classify each third party against the LSP definition: "an agent of a RE (including another RE) who carries out one or more of RE's digital lending functions… in customer acquisition, services incidental to underwriting and pricing, servicing, monitoring, recovery" (para 4) | Legal + Compliance | LSP register mapped to the definition, clause by clause |
The common failure is 1.4. A sourcing partner that also runs a scorecard, or a collections agency that operates a borrower-facing app, is an LSP whatever the contract calls it.
Checklist 2 — RE–LSP arrangements (paras 5–6)
# | Control | Owner | Evidence to hold |
|---|---|---|---|
2.1 | Written agreement with every LSP defining roles, responsibilities and obligations (para 5) | Legal | Executed agreement, clause-mapped to para 5 |
2.2 | Enhanced due diligence covering technical capability, data privacy policies, storage practice and conduct record (para 5) | Vendor Risk | Due diligence file with findings and sign-off |
2.3 | Periodic review of LSP conduct; mechanism to monitor the loan portfolio sourced through each LSP (para 5) | Vendor Risk + Credit | Review calendar, minutes, portfolio-wise MIS |
2.4 | Where the LSP has arrangements with multiple lenders: a digital view of all matching loan offers, with RE name, amount, tenor, APR, other terms, monthly repayment and penal charges (para 6, effective 1 November 2025) | Product + Compliance | Screen captures of the offer-display page, dated |
2.5 | Offer-matching logic is consistent for similarly placed borrowers and products; content unbiased and free of dark patterns (para 6) | Product + Model Risk | Documented matching rules, change log, UX review note |
2.6 | LSP does not promote one RE's product over another through design (para 6) | Compliance | Independent UX/dark-pattern assessment |
Checklist 3 — Money flow (para 9)
This is the paragraph that fails examinations most often, and it is not a documentation control — it is a plumbing control.
# | Control | Owner | Evidence to hold |
|---|---|---|---|
3.1 | Disbursement goes directly into the borrower's bank account — the only exceptions are a statutory or regulatory mandate, specified end-use flows, and money moving between REs in co-lending (para 9) | Treasury + Ops | Disbursement flow diagram plus a sampled bank-side trail |
3.2 | No pass-through, pool or nodal account controlled by the LSP anywhere in the disbursement path (para 9) | Treasury | Account mandate list showing signatories and control |
3.3 | Repayment and servicing are executed by the borrower directly into the RE's bank account (para 9) | Ops | Collections architecture note, NACH mandate templates |
3.4 | Fund flow is not controlled directly or indirectly by any third party including the LSP (para 9) | Internal Audit | Audit testing memo on account control |
3.5 | LSP fees and charges are paid by the RE, not recovered from the borrower (para 9) | Finance | LSP invoices and settlement ledger |
Test 3.4 by tracing a real disbursement and a real repayment end to end, not by reading the contract. Contracts describe the intended flow. Bank statements describe the actual one.
Checklist 4 — Disclosures, KFS and APR (para 8)
# | Control | Owner | Evidence to hold |
|---|---|---|---|
4.1 | KFS issued to every borrower before execution, in the format of the KFS circular of 15 April 2024 (para 8) | Product + Compliance | KFS template, borrower-level issuance log |
4.2 | APR disclosed as "the annual cost of credit to the borrower which includes interest rate and all other charges associated with the credit facility" | Product | APR computation sheet per product |
4.3 | KFS validity: at least three working days for tenor of seven days or more; one working day for tenor under seven days | Product | System configuration record |
4.4 | Penal charges levied as charges, not as penal interest added to the rate; no capitalisation; quantum and reason disclosed in the KFS | Product + Finance | Charge schedule, KFS specimen, system rule |
4.5 | Digitally signed loan documents, KFS, summary of product, sanction letter, T&Cs and account statements sent to the borrower on record by email or SMS on execution (para 8) | Ops | Delivery logs with timestamps |
4.6 | RE website discloses all digital lending products, LSP details, grievance mechanism and privacy policy (para 8) | Compliance + Marketing | Dated page archives |
Worked example: what an APR actually comes out at
Illustrative. Figures constructed to show the arithmetic, not drawn from any lender's product.
A ₹1,00,000 personal loan, 12 months, 18% p.a. on a reducing balance, with a ₹2,000 processing fee and ₹1,500 insurance premium both deducted at disbursement.
Contracted rate 18.00% p.a. reducing
EMI (₹1,00,000, 18% p.a., 12 months) ₹9,168
Total repaid (12 × ₹9,168) ₹1,10,016
Total interest ₹10,016
Net amount actually received by borrower
₹1,00,000 − ₹2,000 − ₹1,500 ₹96,500
Internal rate of return on the actual cash flows
(₹96,500 in, twelve payments of ₹9,168 out) 2.0766% per month
Annualised, simple (× 12) 24.92%
Annualised, compounded ((1.020766)^12 − 1) 27.97%
The borrower's headline rate is 18%. The cost of credit is around 25%. That difference is the entire point of the APR disclosure. Use the computation method set out in the annexes to the KFS circular for the figure that goes on the statement — the simple-versus-compounded annualisation convention should be confirmed against that annex before it is hard-coded into your product engine.
Checklist 5 — Creditworthiness and cooling-off (paras 7, 10)
# | Control | Owner | Evidence to hold |
|---|---|---|---|
5.1 | Independent assessment of borrower creditworthiness before every loan, capturing an economic profile including age, occupation and income (para 7) | Credit | Assessment record per loan, with inputs retained |
5.2 | No automatic increase in credit limit without the borrower's explicit request and consent (para 7) | Product | Limit-change audit trail showing borrower request |
5.3 | Board-approved cooling-off period policy, not less than one day (para 10) | Board + Compliance | Board resolution and policy document |
5.4 | Borrower given an explicit option "to exit a digital loan by paying the principal and the proportionate APR without any penalty" during the cooling-off period (para 10) | Product | Exit flow screens, exit computation logic |
5.5 | Any one-time processing fee retained on exit is reasonable and was disclosed in the KFS (para 10) | Product + Compliance | KFS specimen showing the fee, exit settlement samples |
5.6 | Cooling-off exits are reported, monitored and reconciled | Ops | Monthly exit MIS |
Note the wording on 5.4 — principal plus proportionate APR, not proportionate interest. If your exit calculator charges only interest for the days used and quietly keeps the fees, it is not computing what the Directions require.
Checklist 6 — Data, consent and storage (paras 12–15)
# | Control | Owner | Evidence to hold |
|---|---|---|---|
6.1 | Data collection by the RE's DLA and every LSP DLA is "need-based and with prior and explicit consent of the borrower having audit trail" (para 12) | DPO + IT | Data inventory mapped to purpose; consent audit trail |
6.2 | No access to mobile phone file and media, contact list, call logs or telephony functions (para 12) | IT Security | App permission manifest, per release |
6.3 | One-time access to camera, microphone, location or similar only for onboarding or KYC, with explicit consent (para 12) | IT Security | Permission flow screens, consent records |
6.4 | Borrower can give or deny consent for specific data, restrict disclosure to third parties, manage retention, revoke consent and request deletion (para 12) | Product + DPO | Consent management console, deletion request log |
6.5 | LSPs hold no personal information beyond "basic minimal data (viz., name, address, contact details of the customer, etc.)" required for their scope of work (para 13) | Vendor Risk + DPO | LSP data-field schedule in the agreement; sampled attestation |
6.6 | No biometric data storage by the RE or its LSPs unless expressly permitted by statute (para 13) | DPO | Data classification register |
6.7 | Data stored only on servers located in India; where processed abroad, deleted from offshore servers and brought back to India within 24 hours of processing (para 13) | IT + DPO | Hosting architecture, offshore processing log with deletion timestamps |
6.8 | Comprehensive privacy policy for the RE and each LSP, publicly available (para 14) | DPO + Legal | Published policy, version history |
6.9 | Compliance with applicable cybersecurity and technology standards (para 15) | CISO | Standards mapping and last assessment report |
Control 6.7 is the one that catches lenders using an offshore analytics or model-hosting vendor. Twenty-four hours is a hard number and the evidence has to be a log, not an assurance.
Checklist 7 — Grievance redressal (para 11)
# | Control | Owner | Evidence to hold |
|---|---|---|---|
7.1 | Nodal grievance redressal officer designated by the RE and by every borrower-interfacing LSP (para 11) | Compliance | Appointment letters, current contact details |
7.2 | Officer name and contact displayed prominently on the RE website, LSP website and every DLA (para 11) | Marketing + Product | Dated screen captures of each surface |
7.3 | Complaint lodging facility available on the DLA and on the website (para 11) | Product | Complaint form screens, ticketing system record |
7.4 | Borrowers informed that if the complaint is rejected wholly or partly, or unanswered within 30 days of receipt, they may escalate on the RBI CMS portal under RB-IOS (para 11) | Compliance | Complaint acknowledgement template carrying the escalation text |
7.5 | Complaints against LSPs tracked to closure by the RE, not left with the LSP | Compliance | Consolidated complaint MIS, RE-owned |
Checklist 8 — Reporting (paras 16–17)
# | Control | Owner | Evidence to hold |
|---|---|---|---|
8.1 | All lending through the RE's DLAs and its LSPs' DLAs reported to CICs "irrespective of its nature/ tenor" (para 16) | Credit Ops | CIC submission files and acknowledgements |
8.2 | Structured digital lending products over merchant platforms involving short-term or deferred payments reported to CICs by the RE (para 16) | Credit Ops | Product-wise reporting map |
8.3 | All DLAs deployed or joined — own and LSPs', exclusive or as platform participant — reported on the CIMS portal (cims.rbi.org.in, listed among RBI's reporting portals) (para 17) | Compliance | CIMS submission receipts |
8.4 | CIMS entries updated whenever a DLA is added or an engagement ceases (para 17) | Compliance | Change log tied to the DLA inventory |
8.5 | Chief Compliance Officer certification that DLAs comply with regulatory instructions, including that each DLA links to the RE website, has a nodal grievance officer and meets the data collection and storage provisions | CCO | Signed certification, retained |
RBI publishes the submitted DLA data without verifying it, and inclusion in that list does not amount to registration, authorisation or endorsement. Do not let a marketing team quote it as approval.
Checklist 9 — Default Loss Guarantee (paras 18–28)
# | Control | Owner | Evidence to hold |
|---|---|---|---|
9.1 | DLG accepted only from an LSP or another RE acting as an LSP, and only from an entity incorporated under the Companies Act, 2013 (para 18) | Legal | Provider incorporation documents |
9.2 | Board-approved DLG policy in place before entering any arrangement (para 19) | Board | Board resolution and policy |
9.3 | DLG is not treated as a substitute for credit appraisal; independent underwriting standards applied and evidenced (para 19) | Credit | Underwriting policy, sampled files |
9.4 | Declaration from the DLG provider, certified by its statutory auditor, of aggregate DLG outstanding, number of REs and portfolios covered, and past default rates (para 19) | Vendor Risk | Auditor-certified declaration, current |
9.5 | No DLG on revolving credit, credit cards, or loans covered by government credit guarantee schemes; NBFC-P2P restrictions observed (para 20) | Product + Compliance | Product eligibility matrix |
9.6 | Legally enforceable DLG contract stating extent of cover, form, invocation timeline and disclosure obligations (para 21) | Legal | Executed contract |
9.7 | DLG held only as cash deposit, fixed deposit with a lien marked in favour of the RE, or bank guarantee (para 22) | Treasury | Security holding records with lien confirmations |
9.8 | Total DLG cover not exceeding 5% of the total amount disbursed from the portfolio at any time, on a fixed — not dynamic — portfolio (para 23) | Risk | Portfolio-level DLG utilisation report |
9.9 | NPA recognition done by the RE under extant IRAC norms regardless of DLG; DLG not set off against individual loans (para 24) | Finance + Credit | Asset classification working |
9.10 | Regulatory capital computed under extant norms; if the DLG provider is an RE, it deducts the full outstanding DLG from capital (para 25) | Finance | Capital computation working |
9.11 | DLG invoked within a maximum overdue period of 120 days unless the loan is made good (para 26) | Ops | Invocation register with dates |
9.12 | LSPs publish, monthly and within 7 working days, the total number and amount of portfolios and the DLG amounts on each (para 27) | Vendor Risk | Archived LSP website disclosures |
9.13 | CGTMSE, CRGFTLIH, NCGTC and BIS/IMF/MDB guarantees correctly excluded from the DLG definition (para 28) | Compliance | Guarantee classification note |
Control 9.13 matters for MSME books. A CGTMSE-covered facility is not a DLG arrangement and must not be counted against the 5% cap. If you are structuring MSME cover, the MSME loan underwriting process guide walks through where CGTMSE sits in the file.
What does RBI's framework require from an automated underwriting system?
The Directions do not prescribe model documentation the way a model risk regulation would. What they do is impose three requirements that a black-box decisioning stack cannot satisfy:
Independent assessment (para 7). The RE — not the LSP, not the platform — must assess creditworthiness, and must capture an economic profile including age, occupation and income. If the LSP runs the scorecard and the RE only sees an accept or decline, the RE cannot evidence its own assessment.
Audit trail on consent (para 12). Every data element the model consumes needs a prior, explicit, borrower-level consent with a trail. That means the model's feature list and the consent schedule have to reconcile, field by field.
Consistency across similarly placed borrowers (para 6). Where an LSP serves multiple lenders, the matching logic must follow a consistent approach for similarly placed borrowers and products. That is a testable claim, and testing it requires the rules to be written down.
The practical answer is a decision record that carries, for each proposal, the inputs used, the document and page each input came from, the rules and overrides applied, who applied them, and when. That is the same evidence a credit committee wants and an examiner asks for. YuSight builds it as a by-product — 100% of figures in the memo cited to source, with a complete workflow audit trail from document upload to sanction letter. For what the memo itself should contain, see what a credit appraisal memorandum is, and for how the same evidence chain works in a traditional bank file, the credit appraisal process in Indian banks.
FAQ
What do the RBI digital lending guidelines require?
They require that money moves only between the borrower and the regulated entity with no third-party pass-through, that every borrower gets a Key Fact Statement with an all-in APR, that there is a board-approved cooling-off period of at least one day, that data collection is need-based and consented with an audit trail, that data sits on Indian servers, that a nodal grievance officer is named on every app and website, and that every digital lending app is reported to RBI on the CIMS portal.
Who is a Lending Service Provider under RBI rules?
Paragraph 4 defines an LSP as an agent of a regulated entity — including another regulated entity — who carries out one or more of the RE's digital lending functions in customer acquisition, services incidental to underwriting and pricing, servicing, monitoring or recovery, for a specific loan or a loan portfolio. What the commercial contract calls the party is irrelevant; the test is the function performed.
What does RBI's framework require from an automated underwriting system?
That the regulated entity, not the platform, makes the creditworthiness assessment and can evidence it; that every data input has prior explicit borrower consent with an audit trail; and that where an LSP serves several lenders, the offer-matching logic is consistent for similarly placed borrowers. In practice that means a per-proposal decision record showing inputs, sources, rules and overrides.
Is the 2022 digital lending circular still valid?
No. Paragraph 30 of the 2025 Directions repeals RBI/2022-23/111 dated 2 September 2022, along with the 2020 digital lending platforms circular and the 2023 DLG guidelines. Compliance registers still citing those numbers need updating.
How long is the cooling-off period?
The Directions do not fix a number. Each regulated entity's board determines the period, and it cannot be less than one day. During it the borrower can exit by repaying principal plus the proportionate APR with no penalty, though a reasonable one-time processing fee disclosed in the KFS may be retained.
Can an LSP hold borrower data?
Only basic minimal data — name, address, contact details and similar — needed to perform its scope of work under the RE–LSP agreement. Nothing more. Biometric data cannot be stored unless a statute expressly permits it, and all data must sit on servers in India.
What is the cap on Default Loss Guarantee?
Five per cent of the total amount disbursed from the portfolio, measured at any point in time, on a portfolio that is fixed rather than dynamic. DLG can only be held as a cash deposit, a lien-marked fixed deposit or a bank guarantee, and must be invoked within a maximum overdue period of 120 days.
Does CGTMSE cover count as DLG?
No. Paragraph 28 expressly excludes CGTMSE, CRGFTLIH and NCGTC schemes, and guarantees from BIS, the IMF and multilateral development banks, from the DLG definition. They sit outside the 5% cap.
What happens if a borrower complaint is not resolved?
If the regulated entity rejects the complaint wholly or partly, or does not reply within 30 days of receiving it, the borrower may escalate through the RBI Complaint Management System portal under the Reserve Bank–Integrated Ombudsman Scheme. That escalation route has to be stated to the borrower, not just be available.
Key takeaways
- The single instrument in force is the Reserve Bank of India (Digital Lending) Directions, 2025, dated 8 May 2025. Three earlier circulars are repealed. Check your register.
- Paragraph 9 — direct disbursal to the borrower and direct repayment to the RE, with no LSP-controlled pass-through — is a plumbing control. Test it on a real transaction trail, not on the contract.
- The APR is the whole cost of credit, and it is routinely 6 to 10 percentage points above the headline rate once fees and insurance come out of the disbursed amount.
- Twenty-four hours for offshore-processed data to be deleted and returned to India, 30 days before a complaint escalates to RB-IOS, 120 days maximum overdue before DLG invocation, 5% cap on DLG. These are hard numbers and they need logged evidence.
- Every checklist row above needs a named owner and a specific artefact. A control with no evidence column filled in is not a control.
See the audit trail an examiner would see — [book a live demo](https://yuverse.ai/yusight).