Skip to content

Part 02 — RBI Regulatory Framework

Regulatory Architecture

Indian SME lending sits inside a layered regulatory stack: Parliament creates the statutes, the Reserve Bank of India (RBI) issues binding directions to regulated entities (REs), and product-level schemes such as Priority Sector Lending (PSL), CGTMSE and MUDRA shape what lenders actually book. For a lending system designer, the key distinction is not “bank versus fintech”; it is “whose balance sheet carries the exposure, which RBI direction applies, and what operational evidence must be retained”.

RBI’s core lending powers come mainly from the Banking Regulation Act, 1949 for banks and the Reserve Bank of India Act, 1934 for Non-Banking Financial Companies (NBFCs). RBI’s 2025 digital lending framework explicitly cites sections 21, 35A and 56 of the Banking Regulation Act, sections 45JA, 45L and 45M of the RBI Act, the National Housing Bank Act, the Factoring Regulation Act and the Credit Information Companies (Regulation) Act as its authority base (Reserve Bank of India (Digital Lending) Directions, 2025, May 8, 2025). That citation pattern is useful: it tells you whether a rule is a conduct rule, prudential rule, credit-information rule, or a hybrid.

Banks are deposit-taking institutions with access to current accounts, payments rails and low-cost retail deposits. Their SME lending rules are spread across commercial-bank credit facility directions, interest-rate directions, asset-classification rules, PSL directions and conduct directions. NBFCs cannot take demand deposits and normally fund themselves through bank lines, debentures, securitisation, direct assignment, market borrowings and equity. Their lending is governed by RBI registration, prudential and conduct rules, with special category rules for housing finance companies (HFCs), NBFC-MFIs, NBFC-Factors, NBFC-P2P platforms and Account Aggregators.

A fintech, DSA, anchor platform or loan marketplace is usually not a lender unless it is itself a bank/NBFC. In RBI vocabulary it is commonly a Lending Service Provider (LSP) or a Digital Lending App/platform (DLA). The RE remains responsible for the borrower-facing act, even if the acquisition, document capture, bank-statement analysis, KYC workflow or collections calling is done by a vendor. The 2025 Digital Lending Directions say this directly: outsourcing to an LSP does not dilute the RE’s statutory or regulatory obligations (RBI Digital Lending Directions, para 5).

NBFC regulation is built around Scale-Based Regulation (SBR), introduced through the 2021 framework and consolidated in the Master Direction - Reserve Bank of India (Non-Banking Financial Company - Scale Based Regulation) Directions, 2023, October 19, 2023. The layers are:

LayerWho falls herePractical effect
Base Layer (NBFC-BL)Smaller NBFCs, generally below the Middle Layer threshold and not in special higher-risk classesLighter prudential requirements, but still subject to registration, KYC, fair practices, CIC reporting and outsourcing rules.
Middle Layer (NBFC-ML)Deposit-taking NBFCs, NBFCs with asset size of ₹1,000 crore and above, standalone primary dealers, infrastructure debt fund NBFCs, core investment companies, HFCs and other specified categoriesTighter governance, capital, exposure, disclosure and risk-management requirements.
Upper Layer (NBFC-UL)Systemically important NBFCs identified by RBIEnhanced regulatory requirements; historically top ten eligible NBFCs by asset size were always included. RBI changed the UL methodology in June 2026.
Top Layer (NBFC-TL)Intended to remain empty unless RBI sees exceptional systemic riskEntity-specific higher capital and supervisory intensity.

The important 2026 change is that RBI moved away from the earlier score-based identification of NBFC-UL to a simpler absolute criterion: asset size of ₹1,00,000 crore and above, and made eligible government-owned NBFCs includable under the revised criteria (RBI press release, June 24, 2026). This matters for large SME lenders because UL status affects concentration limits, governance, disclosure, and sometimes how aggressively the lender can originate through partnerships.

The last three years have been unusually active:

DateDirection or circularWhat changed for SME lending
October 19, 2023NBFC SBR Master DirectionReplaced fragmented NBFC prudential directions with a layer-wise framework for NBFCs.
August 18, 2023 and December 29, 2023Penal charges circular and extensionPenal interest as a revenue line was curbed; penal charges must be reasonable, non-capitalised and disclosed.
April 15, 2024Key Facts Statement (KFS) circularKFS/APR became a standard pre-contract disclosure across retail and MSME loans.
March 24, 2025PSL Directions, 2025Replaced the 2020 PSL directions from April 1, 2025 (RBI PSL Directions, 2025).
May 8, 2025Digital Lending Directions, 2025Consolidated 2020, 2022 and DLG instructions; added multi-lender DLA and DLA directory requirements.
August 6, 2025Co-Lending Arrangements Directions, 2025Broadened co-lending beyond the earlier PSL bank-NBFC model and made 10% minimum retention and escrow mechanics explicit.
June 24, 2026NBFC-UL methodology amendmentReworked Upper Layer identification and included eligible government NBFCs.

In practice, an SME loan file should answer five regulatory questions before sanction:

  1. Who is the RE on record: bank, SFB, NBFC-ICC, HFC, NBFC-Factor, or a co-lending pair?
  2. Is the borrower an MSME and does the exposure qualify for PSL, CGTMSE, MUDRA/CGFMU or another guarantee scheme?
  3. Is the journey digital, assisted-digital or branch-led? If a DLA or LSP is involved, the digital lending and outsourcing controls apply.
  4. Is the product term loan, working capital, invoice finance, LAP, supply-chain finance, or non-fund based credit? Different prudential and collateral norms may follow.
  5. Who services, collects, reports to CICs, and handles complaints?

This is why Part 2 cross-links forward into digital operating models, co-lending business models, KYC onboarding and delinquency fundamentals. Regulation is not just a compliance annex; it defines the system’s parties, ledgers, disclosures, audit trails, event timelines and exception queues.