Part 02 — RBI Regulatory Framework
Governance & Other Directions
The regulatory backbone of SME lending is wider than credit policy. A lender’s licence is tested through governance, outsourcing, grievance handling, IT controls, cyber resilience, data localisation, recovery conduct and regulatory reporting. These rules decide how a software system logs consent, escalates complaints, supervises vendors and proves that customer money never passed through an unauthorised pool account.
Grievance and RBI Ombudsman
Section titled “Grievance and RBI Ombudsman”RBI’s borrower grievance architecture has two levels: the lender’s internal mechanism and the Reserve Bank - Integrated Ombudsman Scheme (RB-IOS). The Digital Lending Directions, 2025 make this explicit for digital loans: the RE and borrower-facing LSP must each designate nodal grievance redressal officers; their contact details must appear on the RE website, LSP website/DLA and KFS; and if a complaint is rejected, unsatisfactory or unanswered for 30 days, the borrower can go to RBI’s Complaint Management System (CMS) under RB-IOS.
For an SME lender, complaints are not just consumer-loan friction. Common complaints include wrong bureau reporting, foreclosure amount disputes, delayed NOC/charge release, collateral document return, insurance mis-selling, penal charge disputes, DSA misrepresentation, recovery agent conduct, non-credit of cash collection, and co-lending partner confusion. A robust LMS/CRM should store complaint category, source, linked loan, SLA clock, owner, resolution, compensation/refund, Ombudsman escalation and root-cause tags.
Outsourcing
Section titled “Outsourcing”RBI’s outsourcing principle is consistent across banks, NBFCs and digital lending: outsourcing does not transfer regulatory responsibility. The Digital Lending Directions cite bank outsourcing guidelines, NBFC outsourcing provisions under SBR, co-operative bank outsourcing guidelines and the 2022 recovery-agent outsourcing circular as applicable references (RBI Digital Lending Directions, footnote to para 5).
In practice, SME lenders outsource:
| Function | Control expected |
|---|---|
| DSA/connector sourcing | Empanelment, agreement, payout rules, mis-selling controls, blacklist checks. |
| Field investigation | Visit evidence, geo-tag/time stamp, conflict checks, sample re-verification. |
| Legal/valuation | Approved panel, independence, report versioning, exceptions. |
| LOS/LMS/BRE SaaS | Data residency, access control, audit logs, availability, exit plan. |
| Collections agency | Agent training, code of conduct, call/visit logs, borrower notices, cash controls. |
| Data vendors | Consent, purpose limitation, API logs, data deletion, contract scope. |
The contract should define role, data access, confidentiality, business continuity, audit rights, grievance support, sub-outsourcing restrictions, breach notification and termination. The system should expose vendor-level MIS, not bury vendor actions under the lender’s user ID.
IT Governance and Cyber
Section titled “IT Governance and Cyber”RBI’s IT governance directions for banks and NBFCs have become more detailed in recent years, including Board oversight, IT strategy, information security, cyber incident response, third-party risk, access management, audit and business continuity. For lending technology, the high-risk zones are identity proofing, mandate setup, document vault, collateral records, disbursement approvals, bank account changes, DSA payout masters, repayment allocation and write-off/settlement approvals.
Minimum controls in a lending stack:
- Maker-checker for bank account changes, disbursement, charge waiver, settlement and collateral release.
- Immutable audit trail for KFS generation, consent, sanction edits, repayment appropriation and NPA changes.
- Role-based access for sales, credit, ops, collections, partner and admin users.
- Segregation of production support from business approval.
- Encryption at rest/in transit, secrets management and strong API authentication.
- Daily reconciliation between LOS, LMS, bank statements, payment gateway/escrow and general ledger.
- Tested backup and disaster recovery for loan ledgers and document vault.
Data Localisation and Privacy
Section titled “Data Localisation and Privacy”Digital lending has a specific localisation rule: all borrower data must be stored on servers located in India; if processed outside India, it must be deleted offshore and brought back to India within 24 hours (RBI Digital Lending Directions, para 13). DLAs must collect only need-based data with explicit consent and cannot access contacts, call logs, files/media or telephony functions. Biometric data cannot be stored unless legally permitted.
This creates design constraints for cloud architecture. A US-hosted analytics warehouse, offshore support team’s downloaded CSVs, vendor logs containing borrower phone/PAN, or crash analytics SDK collecting device data can all create compliance exposure. Vendor due diligence must cover actual data flow, not just contract wording.
Internal Ombudsman and Board Governance
Section titled “Internal Ombudsman and Board Governance”RBI issued the Master Direction on Internal Ombudsman for Regulated Entities, 2023 to harmonise internal escalation across RE types. For larger lenders, this means complaint rejection should not be a single customer-service decision; eligible complaints go through Internal Ombudsman review before final rejection.
At Board level, SME lenders need approved policies for credit, pricing, fair practices, outsourcing, KYC/AML, digital lending, DLG, collections, compromise settlements/write-offs, IT/cyber, business continuity and grievance redressal. Policies should map to system controls. A Board-approved “no LSP pool account” policy is meaningless if the payments setup allows partner-controlled virtual accounts.
Regulatory Reporting
Section titled “Regulatory Reporting”Regulatory reporting touches many systems: CIC reporting, Central KYC, FIU-IND suspicious transaction reports, DLA reporting to RBI CIMS, PSL returns, NBFC regulatory returns, fraud reporting, and Ombudsman complaint data. The 2025 Digital Lending Directions require REs to report all DLAs deployed or joined on RBI’s CIMS portal and certify compliance; RBI publishes the data without validating it, so the RE remains responsible for correctness (RBI Digital Lending Directions, para 17).
For system blueprinting, governance means event provenance. Every regulatory return should be reproducible from source records: who approved, which document version, which consent, which account, which partner, which timestamp, and which reconciliation status.