NBFC Software and Digital Lending: RBI Rules for Vendors
Quick Answer
NBFC software covers origination, underwriting, KYC, disbursement, servicing, collections and regulatory reporting. Outsourcing it does not outsource your accountability to the Reserve Bank of India. The RBI (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025 require Indian data storage, audit and inspection rights, sub-contractor liability and six-hour incident reporting written into the contract. By Mr. Sumeet Katariya, CEO, Accucia Softwares Pvt. Ltd.
An NBFC does not just buy lending software. It takes on its vendor's compliance posture, and the regulator will ask about it. The demo goes well, the security questionnaire goes badly, the contract gets signed anyway. Then an inspection arrives and the gaps are yours. Our finance and banking page covers how we work with lenders.
What NBFC software actually covers
Ask five vendors what NBFC software means and you get five scopes. Here is the stack an operating lender actually runs.
Loan origination. Lead capture, forms, document upload, deduplication, sanction workflow. Demos are strongest here and implementations weakest, because the hard part is your credit policy, not the form builder.
Underwriting and rules engine. Scorecards, policy rules, deviation handling, approval hierarchy. The test is whether your credit head can change a rule without a code release. If not, you bought a fixed product someone called a platform. Our AI for finance page covers auditable models.
KYC and eKYC. Identity checks and the Video based Customer Identification Process, set out at paragraph 18 of the RBI Master Direction on Know Your Customer, 2016, last updated 14 August 2025. V-CIP is not a video call on a form.
Disbursement. Bank account validation, payment file generation, reconciliation of returns and failures.
Loan management and servicing. Schedules, part payment, foreclosure, restructuring, interest recalculation, charges, statements. This decides whether your books tie out at month end.
Collections. Bucketing, allocation, promise to pay tracking, receipts, settlement approval.
Co-lending and BC reconciliation. Under the RBI (Co-Lending Arrangements) Directions, 2025, effective 1 January 2026, each entity must retain at least ten per cent of individual loans, shares must move to the partner within fifteen calendar days of disbursement, and the originator may give a default loss guarantee of up to five per cent of loans outstanding. Your software evidences all three.
Regulatory reporting. Returns, bureau submissions and the extracts an inspection team asks for.
[Diagram: eight-stage loan lifecycle from Application to Closure with compliance checkpoints on four stages, see Inline Media Notes for the generation prompt.]
The vendor clauses RBI expects, section by section
A correction first, because much vendor collateral is out of date. On 28 November 2025 the RBI issued the Reserve Bank of India (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025, notification RBI/DOR/2025-26/363, repealing the outsourcing instructions applicable to NBFCs including the 2023 IT outsourcing framework. Existing IT outsourcing agreements had to comply at renewal or by 10 April 2026, whichever came earlier. Both still matter, because RFP templates keep quoting the 2023 sections.
Seven obligations belong in the contract. Data must be stored only in India, under paragraph 74 of the 2025 Directions; ask for the named cloud region in writing, not the word "India" on a slide. The same Directions also give you the right to audit the vendor and its sub-contractors and take copies of their audit reports, the right to information about third parties in the supply chain, and the right for RBI or its nominee to inspect infrastructure, applications, data and documents. They make the vendor liable for its sub-contractors and require written consent before any is engaged. On exit, paragraphs 84 to 88 require plans per termination scenario, minimum execution periods, safe destruction of records and a bar on unilateral erasure.
Incident reporting deserves its own paragraph. Paragraph 61 requires the vendor to report cyber incidents without undue delay so you can report to RBI within six hours of detection. There is a second clock nobody writes into the contract: the CERT-In directions of 28 April 2022, under section 70B of the Information Technology Act, 2000, require listed incidents to reach CERT-In within six hours of noticing, and ICT logs to be kept for a rolling 180 days within Indian jurisdiction. Two clocks, one runbook.
Chapter IV of the 2025 Directions, carrying the IT outsourcing provisions, applies in full from the Middle Layer upward. Base Layer NBFCs get the core provisions and certain Board-level requirements, not the chapter.
Certifications in lieu of independent audits, and where we stand
The rule is narrower than most vendors imply. Paragraph 79 of the 2025 Directions allows a regulated entity, depending on its own risk assessment, to rely on globally recognised third-party certifications made available by the service provider in lieu of conducting independent audits, while stating that this does not absolve the entity of responsibility for assurance on controls safeguarding data security.
It removes the obligation to send your own auditor. It does not remove your responsibility, and a certificate is not evidence a control worked on a given day.
Now our position, because most vendors blur it. Accucia is implementing an ISO 27001 information security management system. An auditor has been appointed and certification is targeted for Q1 2027. We are not certified today and we will not claim otherwise. We will publish the certificate number and scope on our trust page the day it is issued. ISO 9001 is also not held and is in progress.
CERT-In empanelment is separate and is not substitutable by ISO 27001. In Indian BFSI procurement it is a mandatory gate in its own right, because the application security audit must be done by an organisation on the CERT-In panel, which listed 236 empanelled organisations at the time of writing. We are not on it and do not claim to be. The client commissions that audit; we build to the auditor's requirements and implement every finding. Our trust page says the same in a form your compliance team can file.
What a digital lending platform has to enforce, not just document
The 2022 guidelines are gone. Since 8 May 2025 the operative instrument is the Reserve Bank of India (Digital Lending) Directions, 2025, notification RBI/2025-26/36. Clause 30 withdrew the June 2020 circular, the September 2022 Guidelines on Digital Lending and the June 2023 default loss guarantee guidelines. Four provisions have to live in code.
Direct disbursal to the borrower. Clause 9 requires disbursement always into the borrower's bank account, with narrow carve-outs for statutory mandates, co-lending and specified end-use loans. In no case may it go to a third-party account, including a lending service provider's, and the fund flow must not be controlled by a third party. In code: validate the account against the borrower record, make penny-drop mandatory, block any other release.
Key Fact Statement. Clause 8 requires a KFS per the RBI circular of 15 April 2024, and requires digitally signed documents on the lender's letterhead, including the KFS, sanction letter and terms, to flow automatically to the borrower's registered email or SMS on execution. The system sends it, not a person.
Cooling-off period. Clause 10 lets the borrower exit by paying principal and the proportionate annual percentage rate without penalty during a period set by the Board and not shorter than one day. A one-time processing fee may be retained if disclosed upfront in the KFS. Your APR apportionment must be right on day one.
Credit bureau reporting. Clause 16 requires lending through the lender's digital lending apps, or those of its lending service providers, to be reported to credit information companies whatever its nature or tenor.
Build versus buy for an NBFC under Rs 500 crore AUM
Buy the core, build the edges. Under the RBI's scale based regulation framework of 22 October 2021, a non-deposit taking NBFC with assets below Rs 1,000 crore sits in the Base Layer, while every deposit taking NBFC sits in the Middle Layer whatever its size. So a Rs 400 crore lender carries a lighter obligation today and hits a step-up when it crosses Rs 1,000 crore or takes deposits. Retrofitting audit logging and data residency into a live book is the most expensive work we do.
Loan origination core
Our call: Buy
The condition that decides it: Can a configured product cover 80 per cent of your book
Rules and underwriting
Our call: Buy engine, build rules
The condition that decides it: You own the rules, whoever owns the engine
KYC and V-CIP
Our call: Buy from a specialist
The condition that decides it: Certified vendors, constant regulatory change
Loan management and servicing
Our call: Buy
The condition that decides it: Recalculation defects are hardest to unwind
Collections
Our call: Buy base, build allocation
The condition that decides it: Allocation is an advantage, receipting is not
Co-lending reconciliation
Our call: Build or configure heavily
The condition that decides it: Retention, transfer window and DLG maths are partner-specific
Borrower app and portal
Our call: Build
The condition that decides it: Your brand surface and KFS delivery path
Reporting extracts
Our call: Build
The condition that decides it: Formats change and you must follow that week
Cost is driven by product count, number of integrations, whether V-CIP is in scope, co-lending complexity and audit trail depth. We publish how we scope and estimate on our cost page rather than quoting bands that collapse on contact with a real credit policy.
Integration reality: bureau, bank statements, NACH and accounting
Four integrations decide whether your go-live slips.
Bureau pulls. Contracts, test environments and formats differ by bureau. Budget for commercial onboarding, not just API work, and design retry and caching so one outage does not stall the queue.
Bank statement analysis. The Account Aggregator route runs under the RBI's Account Aggregator Directions, 2016, last updated September 2024. Two design facts: nothing moves without the customer's explicit consent, and no financial information accessed by the aggregator resides with it. Your consent artefact and your storage of fetched data are your responsibility.
NACH and eNACH. The NACH e-mandate API variant authenticates through net banking credentials or debit card with OTP, and destination bank coverage is not universal. NPCI publishes the live member list. Check your segment's banks against it before promising a digital mandate flow.
Accounting handoff. Decide early whether the lending system posts to the general ledger directly or produces a daily journal file. Direct posting is cleaner and far harder to reverse when something is wrong. On mid-size builds, including the banking work for AMC Bank in India, a daily file with approval held up better.
What to put in the RFP
Lift this into your requirements document.
Data stored in India
Where it comes from: MD 2025 para 74
Wording to ask for: "All NBFC and customer data shall be stored only in India. The Supplier shall name the cloud provider and region in Schedule 1."
Audit of vendor and sub-contractors
Where it comes from: MD 2025, audit rights over the supplier and its sub-contractors
Wording to ask for: "The NBFC and its auditors may audit the Supplier and any sub-contractor and obtain any audit report."
Supply chain disclosure
Where it comes from: MD 2025, disclosure of third parties in the supply chain
Wording to ask for: "The Supplier shall provide on request a current list of every third party that processes, stores or accesses NBFC data."
RBI inspection access
Where it comes from: MD 2025, RBI right of inspection
Wording to ask for: "The Supplier acknowledges the authority of RBI, or its nominee, to access its infrastructure, data, documents and premises."
Sub-contractor liability and consent
Where it comes from: MD 2025, liability for sub-contractors and prior consent
Wording to ask for: "The Supplier remains liable for its sub-contractors and needs prior written consent before engaging one or changing hosting location."
Incident reporting inside six hours
Where it comes from: MD 2025 para 61; CERT-In 2022
Wording to ask for: "The Supplier shall notify the NBFC of any cyber incident within two hours of detection, so the NBFC can report within six."
Log retention in India
Where it comes from: CERT-In Directions, 28 April 2022
Wording to ask for: "The Supplier shall keep ICT system logs for a rolling 180 days within Indian jurisdiction."
Exit, data return and destruction
Where it comes from: MD 2025 paras 84 to 88
Wording to ask for: "On termination the Supplier shall give transition assistance, return all data in an agreed open format, then destroy its copies."
CERT-In empanelled security audit
Where it comes from: CERT-In empanelment panel
Wording to ask for: "The application shall pass a security audit by a CERT-In empanelled organisation commissioned by the NBFC, all findings fixed before go-live."
Direct disbursal enforced in code
Where it comes from: DL Directions 2025, cl.9
Wording to ask for: "The system shall block disbursement to any account other than the borrower's verified bank account, save for the clause 9 exceptions."
Automatic KFS delivery
Where it comes from: DL Directions 2025, cl.8
Wording to ask for: "On execution the system shall automatically send the signed Key Fact Statement to the borrower's registered email and SMS."
Cooling-off exit computation
Where it comes from: DL Directions 2025, cl.10
Wording to ask for: "The system shall compute a cooling-off exit amount of principal plus proportionate APR plus any disclosed one-time fee, with no penalty."
Accucia's view
Most NBFCs at this size overbuy the origination front end and underbuy the audit trail. The front end is what the board sees. The audit trail decides whether an inspection takes two days or two months. Given the choice we argue for the trail, and that has cost us work.
Second, and it costs us more. We will tell you to buy a proven loan management core rather than build one, even though building it is the larger contract for us. Interest recalculation, part payment and foreclosure logic were solved years ago. What is worth your money is the layer holding your credit policy, co-lending partners and reporting formats, because that changes quarterly.
Third, on procurement honesty. We will not sign a statement saying we are CERT-In empanelled, because we are not, and we will not let ISO 27001 be presented as an equivalent. We would rather lose a shortlist than have your compliance head defend a claim we made.
Across eight years, 730 plus projects, 500 plus clients worldwide and 25 plus industry verticals, regulated builds are where saying no early saved the most money. Our lending automation page sets out how we run these engagements, and you can talk to us.
Frequently Asked Questions
What is NBFC software?
NBFC software runs lending end to end: loan origination, underwriting rules, KYC, disbursement, loan management and servicing, collections, co-lending reconciliation and regulatory reporting. Most lenders buy a core product and build the layers specific to their own credit policy and lending partners.
Which RBI rules apply to an NBFC's software vendor?
The RBI (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025, dated 28 November 2025, govern outsourcing including IT services, and replaced the 2023 IT outsourcing framework. Digital lending is governed separately by the RBI (Digital Lending) Directions, 2025, dated 8 May 2025.
Does the 2023 IT Outsourcing Master Direction still apply to NBFCs?
No. The 2025 NBFC outsourcing Directions repealed the earlier outsourcing instructions. Existing IT outsourcing agreements had to comply at renewal or by 10 April 2026, whichever came earlier. Many RFP templates still quote the 2023 section numbers, so it helps to know both.
Can we accept a vendor's ISO 27001 instead of auditing them?
Sometimes. Paragraph 79 of the 2025 Directions allows reliance on globally recognised third-party certifications in lieu of independent audits, based on your own risk assessment. It does not transfer your responsibility for data security.
Is ISO 27001 a substitute for CERT-In empanelment?
No, they are different gates. ISO 27001 certifies an information security management system. CERT-In empanelment identifies organisations approved to perform security audits in India. BFSI procurement usually requires an audit by an empanelled organisation, and no vendor certification replaces it.
Who commissions the CERT-In empanelled audit?
The client commissions it. As the software partner, Accucia builds to the empanelled auditor's requirements, supports the test cycle and implements every finding before go-live. We do not hold CERT-In empanelment ourselves and never present ourselves as an empanelled auditor.
Does Accucia hold ISO 27001?
No. Accucia is implementing an ISO 27001 information security management system. An auditor has been appointed and certification is targeted for Q1 2027. We are not certified today and we will not claim otherwise. ISO 9001 is also not held and is in progress. We state this at proposal stage.
Where must NBFC data be stored?
In India. Paragraph 74 of the RBI (Non-Banking Financial Companies, Managing Risks in Outsourcing) Directions, 2025 requires storage of data only in India as per extant regulatory requirements. Name the cloud provider and region in the contract.
How quickly must a cyber incident be reported?
Within six hours of detection to the Reserve Bank of India, under paragraph 61 of the 2025 Directions. The CERT-In directions of 28 April 2022 separately require reporting within six hours of noticing.
What must a digital lending platform enforce in code?
Four things. Disbursal only to the borrower's verified bank account, with no third-party or pool account in the flow. Automatic delivery of the signed Key Fact Statement. A correct cooling-off exit amount. Bureau reporting of all digital lending, whatever the tenor.
How long is the digital lending cooling-off period?
The Board of the regulated entity sets it in the loan policy and, under clause 10 of the RBI Digital Lending Directions, 2025, it cannot be shorter than one day. The borrower exits by paying principal and proportionate APR without penalty.
Should a small NBFC build or buy its lending platform?
Buy the origination and loan management core; build the rules, co-lending reconciliation, borrower app and reporting extracts. A non-deposit taking NBFC below Rs 1,000 crore in assets sits in the Base Layer, so obligations step up sharply at that threshold.
Build compliant lending systems with Accucia.