Skip to content

Part 04 — Digital & Embedded Lending

Regulatory Guardrails Applied

The practical rule for digital and embedded lending is simple: if a regulated entity (RE) books the loan, it remains responsible even when the customer journey, data capture, reminders, collections or technology are performed by a lending service provider (LSP). The Reserve Bank of India (Digital Lending) Directions, 2025, dated May 8, 2025, consolidated earlier digital lending rules and added requirements for multi-lender LSP journeys and the RBI digital lending app (DLA) directory. These guardrails determine what can and cannot be built in the models covered in operating models.

DLG: 5 Percent Is A Cap, Not A Business Model

Section titled “DLG: 5 Percent Is A Cap, Not A Business Model”

Default loss guarantee (DLG), often called first-loss default guarantee (FLDG) in industry language, is a contractual arrangement where a provider compensates an RE for default loss up to a specified percentage of a loan portfolio. RBI now permits it only inside a tight framework. Under the 2025 digital lending directions, the DLG provider must be an eligible LSP or RE-LSP incorporated as a company, the RE needs a board-approved DLG policy, the DLG must not substitute for credit appraisal, and the portfolio must be an identifiable fixed set of sanctioned loans. The cover cannot exceed 5 percent of the disbursed amount of that portfolio at any given time.

The form is also restricted: cash deposit with the RE, fixed deposit with a scheduled commercial bank with lien in favour of the RE, or bank guarantee. Invocation must happen within a maximum overdue period of 120 days unless the borrower cures the default, and non-performing asset (NPA) recognition remains the RE’s responsibility. Recoveries after invocation may be shared contractually, but the borrower’s liability is not reduced merely because DLG was invoked.

Applied to embedded lending, this ends the old aggressive structure where a platform could say, “we will cover the first 15 percent, you just book the loans.” A 5 percent cap can align incentives for a granular book, but it cannot rescue weak sourcing. It also does not apply to every product: DLG is not permitted for revolving credit facilities offered through digital lending channels and credit cards, and it is excluded for loans already covered by specified government guarantee schemes.

In co-lending, the Reserve Bank of India (Co-Lending Arrangements) Directions, 2025, dated August 6, 2025, permit the originating RE to provide DLG up to 5 percent of loans outstanding under the co-lending arrangement, governed by the digital lending framework.

DLG structure where an LSP provides cash deposit, FD lien or bank guarantee to a regulated entity, capped at 5 percent of a fixed loan portfolio, while borrowers repay the RE account.
DLG cover sits beside the regulated loan book; borrower fund flow, NPA recognition and credit appraisal remain with the RE.

KFS And APR: Pricing Must Survive Disclosure

Section titled “KFS And APR: Pricing Must Survive Disclosure”

The Key Facts Statement (KFS) is the antidote to disguised pricing. The RBI circular Key Facts Statement (KFS) for Loans & Advances, April 15, 2024, is referenced in the digital lending and co-lending directions. For digital SME products, KFS must force all borrower-paid costs into annual percentage rate (APR): interest, processing fee, documentation fee, platform-related charges charged to the borrower, insurance if mandatory for the loan, and penal charges where applicable.

This constrains product design. A merchant cash advance priced as “0.05 percent per day” has to be represented as APR. A B2B checkout credit line with supplier subvention must still disclose borrower cost if the borrower pays any fee or interest. A co-lending loan must disclose the blended rate and other charges. A platform cannot show a teaser EMI while hiding onboarding fees in a separate partner screen.

For multi-lender LSPs, the 2025 digital lending directions require a comparable digital view: lender name, loan amount, tenor, APR, monthly repayment obligation and penal charges, plus a KFS link for each matching RE. The platform can rank offers only on a publicly pre-disclosed metric and cannot use dark patterns to push one lender.

Fund Flow Rules Break Many Platform Shortcuts

Section titled “Fund Flow Rules Break Many Platform Shortcuts”

RBI’s fund-flow rule is one of the sharpest operational constraints. Digital loan disbursement must be made by the RE into the borrower’s bank account. Exceptions exist for statutory/regulatory mandates, co-lending money movement between REs, and specific end-use disbursal where money goes directly to the end-beneficiary. Repayment and servicing must be directly between borrower and RE account, not through an LSP pool account. LSP fees must be paid by the RE and cannot be separately collected from the borrower by the LSP.

This affects four common designs:

DesignCompliance implication
Payment processor deducts repayment from settlementsProcessor can facilitate instructions, but money flow and authorization must land correctly with the RE.
Marketplace pays supplier directlyCleaner when documented as specific end-use disbursal to end-beneficiary.
LSP collects processing feeNot permitted if it is a fee for the LSP’s lending services; RE pays LSP. Borrower-paid charges must be in KFS.
Co-lending splitMust use escrow under co-lending directions and maintain each RE’s borrower account.

For system builders, this means every payment event needs a “fund-flow legal basis” field: borrower disbursal, end-beneficiary disbursal, co-lending escrow transfer, repayment, cash recovery exception or fee settlement.

Digital lending products often want phone contacts, SMS, device data and platform behavioural data. RBI restricts that impulse. Data collection by RE or LSP DLAs must be need-based, with prior explicit consent and an audit trail. DLAs must not access mobile phone resources such as files/media, contact list, call logs or telephony functions. One-time access to camera, microphone or location may be taken only when necessary for onboarding/KYC and with explicit consent.

Borrowers must be able to give or deny consent for specific data use, restrict third-party disclosure, revoke consent and seek deletion where required. Personal data sharing with third parties needs explicit consent unless required by law or regulation. Data must be stored only on servers in India; if processed outside India, it must be deleted from overseas servers and brought back to India within 24 hours. These rules are central to Account Aggregator, GST and anchor-data underwriting journeys covered in OCEN, ONDC & future.

Grievance, Website Disclosures And DLA Directory

Section titled “Grievance, Website Disclosures And DLA Directory”

The borrower must know who to complain to. The RE and borrower-facing LSP must appoint nodal grievance redressal officers, display contact details on the RE website, LSP website and DLA, and include them in the KFS. If a complaint is rejected, partly rejected, unsatisfactorily answered or unanswered for 30 days, the borrower can use RBI’s Complaint Management System under the Reserve Bank - Integrated Ombudsman Scheme.

RE websites must keep updated details of digital lending products, DLAs, LSPs, LSP activities, customer-care details, grievance mechanism, RBI CMS and Sachet links, and privacy policies. REs also had to report DLAs on RBI’s Centralised Information Management System (CIMS), with the initial reporting due June 15, 2025. The RBI directory is based on RE submissions and is not an RBI endorsement; this matters because fraudulent apps often misuse the language of “RBI listed.”

The digital lending directions sit on top of outsourcing rules. The RE must conduct enhanced due diligence on an LSP’s technical capability, data privacy, conduct history and compliance ability, then monitor conduct periodically. If the LSP acts as a recovery agent, the RE must ensure responsible recovery conduct and tell the borrower the recovery agent’s details before contact.

Embedded models therefore need more than API uptime clauses. The partner agreement should specify data fields, consent text, KFS responsibility, complaint routing, recovery conduct, audit rights, incident reporting, business continuity, termination assistance, DLG if any, and deletion/return of borrower data. A platform with excellent distribution but weak compliance controls is a regulatory liability for the lender.