Compliance Obligations in Digital Lending: RBI Rules for Banks (BCP)

BCP By Ashish Jain · IIBF STORE Editorial · 10 August 2026 · Updated 23 Sep 2026 · 12 min read · 46 views
Compliance Obligations in Digital Lending: RBI Rules for Banks (BCP)

For a Banking Compliance Professional, understanding the compliance obligations in digital lending is non-negotiable — RBI treats every digital loan, however it is originated, as a transaction of the regulated entity (RE), not of the fintech app that fronts it. Since the Reserve Bank of India issued its digital lending guidelines in September 2022, banks and NBFCs have had to rebuild onboarding, disbursement, data-handling and grievance workflows around a single principle: the RE cannot outsource its accountability, even when a Lending Service Provider (LSP) or Digital Lending App (DLA) sits between the bank and the borrower. This article walks through the core rules a BCP candidate must know cold — from account-flow restrictions to the Key Fact Statement, cooling-off exits, data minimisation, Default Loss Guarantee caps and audit evidence.

📱 Why the RE Remains Fully Responsible for LSPs and DLAs

RBI's digital lending framework applies to every regulated entity — banks, NBFCs and co-operative banks — that lends through its own app, a partner DLA, or an LSP acting as an intermediary. The RE stays the lender of record: the loan sits on the RE's books, and the RE bears full responsibility for the conduct of every LSP and DLA in its lending chain, including their recovery agents.

This is an extension of the same principle that governs outsourcing governance in banks — a bank cannot outsource accountability, only the activity. Before onboarding a DLA or LSP, the RE's board-approved policy must cover due diligence on the partner's technology stack, data-security practices, privacy standards and grievance handling capacity. The RE must also publish and keep current a list of its LSPs and DLAs on its own website, so a borrower can verify whether an app is genuinely tied to a regulated lender.

This responsibility sits alongside the wider regulatory restrictions on lending covered under loans and advances regulatory restrictions — sanctioning discipline, purpose-based lending curbs and end-use monitoring do not get diluted merely because the loan originates through an app rather than a branch. Any compliance failure, mis-selling, data misuse or recovery-agent harassment by the LSP is treated, for supervisory purposes, as a failure of the RE itself, inviting RBI's usual escalation ladder including monetary penalties and business restrictions.

Regulated entity oversight extends to every lending service provider and digital lending app in the chain
Regulated entity oversight extends to every lending service provider and digital lending app in the chain

💰 Direct Disbursement and Repayment: No Pass-Through Pooling

The single most-tested rule in this chapter: all loan disbursals must be made directly into the borrower's bank account, with no intermediate pass-through or pooling account of the LSP or DLA involved. Loan proceeds cannot sit — even for a few hours — in an account controlled by the fintech partner.

Repayments work the same way in reverse. Every repayment must flow directly from the borrower's bank account to the RE's account; the LSP or DLA cannot collect EMIs into its own pool and remit them onward later. Where a payment aggregator or standing instruction is used purely as a technical rail, it must not function as a holding account that breaks the direct borrower-to-RE (and RE-to-borrower) money flow.

Any fees payable to the LSP for its services must be paid by the RE directly to the LSP, and never deducted upfront from the amount disbursed to the borrower. The borrower gets the full sanctioned amount; the RE settles the LSP's commercial arrangement separately, on its own books. This structure closes the loophole that let some fintech-led lending arrangements run pooled collection accounts that obscured true asset quality and made recovery practices harder to supervise.

Digital loan disbursement and repayment must flow directly between borrower and regulated entity accounts
Digital loan disbursement and repayment must flow directly between borrower and regulated entity accounts

📄 Key Fact Statement and the All-Inclusive APR

Before the loan contract is executed, the RE must give the borrower a standardised Key Fact Statement (KFS), summarising the loan amount, tenor, all fees, and — most importantly — the Annual Percentage Rate (APR). The APR is deliberately "all-inclusive": it folds in interest plus every processing fee, insurance premium (if bundled), documentation charge and any other recurring or non-recurring cost, so the borrower sees the true annualised cost of credit in one number, not a headline rate with charges buried in the fine print.

This is where digital lending compliance overlaps with the broader interest rates on advances framework — the KFS-APR requirement is a digital-specific tightening of the same disclosure discipline that governs pricing transparency across all lending products. A BCP candidate should remember that the KFS is not optional marketing collateral; it is a pre-contract disclosure document, and any material term in the loan agreement not reflected in the KFS is treated as a compliance gap.

REs must also ensure the KFS is issued in a language the borrower understands, and before — not alongside or after — the borrower's consent to the loan contract. A KFS buried deep inside an app's terms-and-conditions flow, where the borrower cannot meaningfully review the APR before agreeing, does not meet this requirement even if a KFS technically exists somewhere in the journey.

💡 Exam Tip: If a question asks what makes the APR "all-inclusive," the answer is: it captures interest plus every fee, charge and cost recovered by the RE or LSP over the life of the loan — not just the headline interest rate.
Key Fact Statement disclosure with the all-inclusive Annual Percentage Rate before loan execution
Key Fact Statement disclosure with the all-inclusive Annual Percentage Rate before loan execution

🔒 Cooling-Off Period, Data Minimisation and Default Loss Guarantee

Every digital loan must carry a cooling-off (or look-up) period during which the borrower can walk away by repaying only the principal and the proportionate APR for the period the loan was live — no prepayment penalty, no exit fee. RBI has set this as a floor, not a ceiling: REs may offer a longer window, but the minimum is at least three days for loans with a tenor of seven days or more, and at least one day for shorter-tenor loans.

Loan TenorMinimum Cooling-Off PeriodPenalty-Free Exit?
7 days or moreAt least 3 days
Less than 7 daysAt least 1 day
After the cooling-off window closesGoverned by the RE's normal foreclosure/prepayment terms

Data minimisation is the second pillar: a DLA may collect only the data it strictly needs for the specific loan product, with the borrower's explicit, one-time consent for each data category, and a clear option to deny or later revoke consent. RBI's rules specifically bar continuous or background access to a borrower's contact list, call logs, photo gallery/media and files — categories that fintech apps had routinely mined for aggressive, often abusive, recovery tactics. This dovetails with the onboarding discipline candidates study under KYC compliance framework for banks, where data collected for identity verification must also stay purpose-bound.

⚠️ Common Mistake: Candidates often assume the RBI ban is on "collecting personal data" generally. It is narrower and sharper — the prohibition specifically targets access to contacts, call logs, media/gallery and files without explicit, need-based consent, not data collection as a whole.

Where an RE wants a first-loss cushion from a fintech partner, it may accept a Default Loss Guarantee (DLG), but RBI's June 2023 guidelines cap DLG cover at 5% of the underlying loan portfolio and require it to be disclosed, as set out on the Reserve Bank of India's notifications and circulars page — DLG cannot be structured as an off-balance-sheet device to disguise the RE's real credit risk.

📢 Grievance Redressal, Credit Bureau Reporting and Compliance Audit Evidence

Every RE must appoint a nodal grievance redressal officer specifically for fintech/digital lending complaints, whose contact details are published on the RE's website and inside the app itself. If the LSP's or DLA's own grievance channel fails to resolve a complaint within the RE's stipulated timeline, the borrower can escalate to the RE's nodal officer, and from there to the Reserve Bank — including under the Reserve Bank - Integrated Ombudsman Scheme, which also covers grievances tied to digital lending. This mirrors the escalation logic candidates already study for the internal ombudsman in banks, and it connects to the customer-facing commitments under the BCSBI code of commitment to customers, which still shapes fair-treatment expectations even in a digital-first lending journey.

Every digital loan — irrespective of tenor, ticket size, or whether it is originated by the RE's own app or a partner DLA — must be reported to Credit Information Companies (CICs) exactly as any other retail loan would be. RBI closed the earlier gap where very short-tenor digital loans slipped outside bureau reporting; today, short-duration digital credit lines are expected to reflect on the borrower's credit bureau record like any other facility.

For compliance testing, examiners expect the RE to retain hard evidence, not policy statements alone: a signed board-approved digital lending policy, due-diligence records for every LSP/DLA on the published list, API-level logs showing the KFS was issued and accepted before contract execution, consent logs for every data category accessed, cooling-off exit records, DLG disclosure documentation and periodic audit reports on each DLA's technology and data practices. A compliance officer who cannot produce this evidence trail on demand has, in RBI's eyes, not actually implemented the framework — regardless of how the policy document reads.

🧠 Practice MCQs: Compliance Obligations in Digital Lending

Q1. Under RBI's digital lending guidelines, disbursement of loan proceeds must flow: (a) Through an escrow account maintained by the LSP (b) Directly between the RE's account and the borrower's account, without any pass-through pool account (c) Through a pass-through pool account of the digital lending app (d) Through a nodal account of the payment aggregator held for more than one day

Answer: (b) — RBI's digital lending guidelines prohibit any pass-through or pooling account; money must move directly between the borrower's account and the RE's account.

Q2. The Key Fact Statement (KFS) for a digital loan must prominently disclose: (a) Only the loan tenor (b) Only the LSP's registration certificate number (c) The all-inclusive Annual Percentage Rate (APR) (d) Only the RE's board resolution number

Answer: (c) — The KFS must disclose the all-inclusive APR, capturing interest and every fee so the borrower sees the true annualised cost.

Q3. Digital Lending Apps are prohibited from accessing which borrower data without explicit, need-based consent? (a) Loan account number (b) PAN details submitted during onboarding (c) Contact list, call logs and media files (d) Loan repayment schedule

Answer: (c) — RBI specifically bars continuous or background access to a borrower's contacts, call logs, media/gallery and files.

Q4. During the cooling-off/look-up period, a borrower who wants to exit a digital loan must pay: (a) Nothing; the loan is cancelled free of cost (b) The principal plus a penal exit charge (c) Only the principal, with all interest waived (d) The principal and proportionate APR, without penalty

Answer: (d) — Exit during the cooling-off period requires repaying the principal and the proportionate APR for the period the loan was live, with no penalty.

Q5. Who is ultimately responsible for compliance failures by a Lending Service Provider engaged for digital lending? (a) The LSP alone (b) The regulated entity that engaged the LSP (c) The credit information company (d) The borrower

Answer: (b) — The RE cannot outsource accountability; it remains fully responsible for the conduct of every LSP and DLA it engages.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

What are the compliance obligations in digital lending for banks under RBI rules?

The regulated entity must remain fully responsible for every Lending Service Provider and Digital Lending App it engages, route all disbursals and repayments directly between its own account and the borrower's account, issue a Key Fact Statement with the all-inclusive APR, offer a cooling-off exit, minimise data collection and report every digital loan to credit bureaus.

Can a digital lending app hold borrower repayments in its own account before passing them to the bank?

No. RBI's digital lending guidelines prohibit any pass-through or pooling account operated by the LSP or DLA — repayments must move directly from the borrower's bank account to the regulated entity's account.

What data can a digital lending app legally access from a borrower's phone?

Only data that is strictly need-based for the specific loan, collected with explicit, one-time consent per category. RBI specifically bars continuous or background access to contacts, call logs, media/gallery and files.

What happens if a borrower's grievance against a digital lending app is not resolved?

The borrower can escalate to the regulated entity's dedicated nodal grievance redressal officer for fintech/digital lending complaints, and further to the Reserve Bank - Integrated Ombudsman Scheme if the RE fails to resolve it within its stipulated timeline.

✅ Conclusion: Build Digital Lending Compliance Mastery for BCP

Digital lending compliance keeps showing up in BCP papers because it sits at the intersection of everything the syllabus already tests — outsourcing governance, fair-practice disclosure, data protection and grievance redressal — applied to a channel regulators watch closely. Lock in the six anchor rules: RE responsibility for LSPs/DLAs, no pass-through pooling, the KFS-APR pairing, the cooling-off exit, data minimisation, and DLG caps with disclosure, and most exam questions on this topic become straightforward recall rather than reasoning from scratch.

Keep building this muscle chapter by chapter — revisit related ground in IRAC norms and wilful defaulters for how digital-loan defaults eventually get classified, and browse more compliance topics on the Banking Compliance Professional tag hub. Then test yourself with full-length questions at iibf.store/tests before exam day.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading