RBI Said Your Vendor Is Now Your Responsibility. Most Lenders Have Not Finished Reading That Line and Penalties.

RBI Said Your Vendor Is Now Your Responsibility. Most Lenders Have Not Finished Reading That Line and Penalties.

August 21, 2026

There is a moment most NBFCs and digital lenders have faced in the last two years. A compliance officer forwards a circular. Someone in tech says it probably applies to banks more than us. Legal says it applies to everyone. The conversation moves on. Then audit season arrives and the gaps are not theoretical anymore.

The RBI has published three interconnected frameworks in the last three years — the IT Governance Master Direction (effective April 2024), the Outsourcing of IT Services Direction (2023), and the Managing Risks in Outsourcing Directions for NBFCs (2025). Together, they say something very clear: if a technology vendor touches your loan book, your borrower data, or your operations, what happens inside that vendor is now your regulatory problem, not just your commercial one.

What the RBI Has Actually Said

 

  • IT Governance Master Direction (April 2024): Requires board-level IT governance, vendor risk assessments before buying or renewing any third-party tech, vulnerability testing on critical systems, and documented impact assessments before outsourcing any application to a third party.
  • IT Outsourcing Direction (2023): Consolidated all earlier fragmented circulars into one framework. Requires detailed contractual provisions, audit rights, data localisation on Indian infrastructure, and clear exit management plans for all material IT vendors. Effective from October 1, 2023.
  • NBFC Outsourcing Directions (2025): The most comprehensive of the three. Redefines outsourcing as a board-level governance issue, not a procurement function. Requires RBI direct supervisory access to service providers, vendor subcontracting approval, and contractual flow-down of all regulatory obligations. Transition deadline for existing contracts: April 10, 2026 or renewal, whichever is earlier.

 

The regulatory message across all three frameworks is consistent: outsourcing technology does not outsource accountability. The NBFC remains fully responsible for confidentiality, integrity, and availability of borrower data, regardless of who is hosting or processing it.

DISCLAIMER:

This is a short summary article intended for general awareness. It does not constitute legal or compliance advice. For the complete regulatory text, please refer to the official RBI sources linked at the end of this article. Readers are strongly advised to consult the original directions and their legal or compliance advisors before taking any action.

Top 10 Things Regulated Entities Must Check Before Buying Third-Party Tech

If you are evaluating any technology vendor - LMS, LOS, collections platform, KYC API, bureau integration, or cloud infrastructure - these are the ten questions the RBI expects you to have answered before you sign the contract.

1. Board-approved outsourcing policy exists — Your board must have approved a formal outsourcing policy before you can enter into any material IT outsourcing arrangement. A procurement approval is not the same thing.

2. Documented risk and impact assessment completed — Before onboarding any third-party tech vendor, a formal risk and impact assessment must be documented, covering operational, cyber, legal, reputational, and concentration risks.

3. Vendor financial health and stability verified — Due diligence must cover the vendor's financial health, business continuity capability, track record, and whether they are operationally stable enough to support your loan book.

4. RBI audit and inspection rights in the contract — The agreement must explicitly give RBI the right to inspect the vendor. If this clause is missing or conditional on vendor consent, the arrangement is non-compliant. If RBI cannot inspect the vendor, the vendor cannot be used.

5. Data ownership and localisation confirmed — Your organisation must retain full ownership of all borrower data. Data must be stored and processed within India unless explicitly permitted otherwise. The vendor cannot claim ownership of your data.

6. Subcontracting restrictions in place — The vendor must not be permitted to subcontract any part of the outsourced activity without your prior written approval. You must know who the subcontractors are and ensure they are also compliant.

7. Concentration risk assessed — If multiple critical functions — LMS, collections, KYC, cloud — sit with the same vendor or vendor group, you must assess and document the concentration risk and have a mitigation plan.

8. Cyber incident reporting timelines agreed — For IT outsourcing, the contract must require the vendor to report any cyber incident to you within six hours of detection so you can meet your own RBI reporting obligations.

9. Exit management and business continuity plan documented — You must be able to exit the vendor arrangement without disruption to your operations. The contract must include structured exit assistance, data portability, and tested BCP and DR provisions.

10. Annual monitoring and audit rights operational — You must have the contractual right and operational capacity to audit the vendor at least once a year and monitor their performance on an ongoing basis. A central register of all material outsourcing must be maintained.

What Happens When NBFCs Get This Wrong: The Penalty Reality

The RBI's enforcement posture has shifted decisively in the last two years. The numbers make this clear.

In FY 2024-25, the RBI imposed Rs 54.78 crore in penalties across 353 banks and regulated entities — a 30% jump from the previous year. These were not edge cases. They were systematic enforcement actions across NBFCs, cooperative banks, commercial banks, and payment operators.

Real cases from 2024-25 that directly relate to third-party tech and outsourcing failures:

Hewlett Packard Financial Services India (September 2024): Penalised Rs 10.40 lakh specifically for failing to conduct Information Systems (IS) audits and failing to monitor outsourced vendors. This is a direct enforcement action for third-party tech non-compliance under the IT governance framework.

HDFC Bank (November 2025): Penalised Rs 91 lakh, with one of the specific violations being that the bank had outsourced the function of determining compliance with KYC norms to its outsourcing agents — a direct violation of the prohibition on outsourcing core compliance and decision-making functions.

Microfinance company (2024): Penalised for delegating KYC decision-making to third-party agents. The RBI imposed the penalty before any fraud or customer loss occurred — purely to enforce institutional governance discipline.

P2P NBFCs (March 2025): Multiple P2P lending platforms penalised for non-compliance with service provider agreements and failure to maintain required controls over outsourced functions.

The RBI has made it explicit: it will not wait for a fraud event or customer loss to penalise non-compliance. Governance failures on paper — missing clauses, absent audit trails, undocumented vendor assessments — are sufficient grounds for enforcement action.

The penalties themselves range from a few lakhs to several crores depending on the severity and the size of the regulated entity. But the financial penalty is rarely the most damaging consequence. Regulatory notices, public disclosure of enforcement actions, operational restrictions, and in serious cases, restrictions on new business — these are the real costs of getting third-party tech governance wrong.

The Five Compliance Gaps That Consistently Appear

No board-level outsourcing policy: Most lenders have a procurement process. Very few have a board-approved outsourcing governance framework that covers risk assessment, approval thresholds, concentration risk, and ongoing monitoring.

Vendor contracts missing mandatory clauses: The 2025 Directions mandate RBI audit rights, data ownership, subcontracting restrictions, exit management, and regulatory obligation flow-down. Most legacy contracts are missing several of these.

Mandate registration after disbursement in collections tech: A specific and common gap in collections infrastructure — when eNACH or AutoPay mandates are set up post-disbursement rather than during origination, you are already behind on your first EMI cycle.

No documented impact assessment before vendor onboarding: The IT Governance Direction requires this explicitly. Many lenders run a commercial and security review but not a formal regulatory impact assessment.

Concentration risk not tracked or reported to board: If your LMS, collections platform, bureau APIs, and cloud hosting all sit with the same vendor family, that risk must be documented, assessed, and reported to the board. Most lenders have not done this mapping.

How Letsfin Helps Lenders Meet These Requirements

Letsfin's infrastructure is built for regulated lenders. Every product is designed with the understanding that a vendor relationship with an NBFC is a regulatory relationship, not just a commercial one.

LMS and LOS with Inbuilt AI: Full audit trail capability, role-based access controls, data localisation on Indian infrastructure, and contract provisions aligned to RBI outsourcing requirements. The inbuilt AI layer handles credit decisioning, fraud detection, and early warning for at-risk accounts — all within a compliance-auditable environment.

eNACH and UPI AutoPay: Mandate registration built into the origination flow — before disbursement. Smart retry logic, pre-debit notifications, and real-time reconciliation. Compliant with NPCI guidelines.

Voice AI: Automated voice agents for collections, onboarding, and follow-ups. Call logs and outcomes recorded in a format accessible for regulatory review.

Bureau, AA and Data APIs: Pre-built integrations with credit bureaus, account aggregators, GST data, and banking data — with documented data access controls and audit capability.

Compliance-Aligned Vendor Agreements: Letsfin's agreements are structured to include the provisions the RBI's 2025 Directions require — RBI audit rights, subcontracting disclosure, data ownership, exit management, and regulatory obligation flow-down — from day one.

The Bottom Line

The RBI's third-party technology guidelines have changed what it means to buy technology as a lender. A vendor decision is no longer just a build-versus-buy calculation. It is a governance decision with regulatory consequences that show up in supervisory inspections, enforcement actions, and increasingly, public penalty disclosures.

The lenders who are ahead of this are the ones who chose technology partners who understood the regulatory environment and built for it. That is a much easier position to be in than retrofitting compliance onto a vendor stack that was never designed for it.

Official RBI Source Documents

For the complete regulatory text of all three frameworks referenced in this article, please refer to the official RBI sources below. Readers are advised to consult the original directions in full before making compliance or procurement decisions.

1. IT Governance, Risk, Controls & Assurance Practices Master Direction (2023, effective April 2024): https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12562

2. Outsourcing of IT Services Direction (2023): fidcindia.org.in/wp-content/uploads/2023/04/RBI-OUTSOURCING-OF-IT-SERVICES-10-04-23.pdf

3. NBFC Managing Risks in Outsourcing Directions (2025) — https://rbi.org.in/scripts/BS_ViewMasDirections.aspx?id=12941

4. HDFC Bank Outsourcing Penalty (Nov 2025): https://www.business-standard.com/industry/banking/rbi-imposes-91-lakh-penalty-on-hdfc-bank-for-violation-of-norms-125112800976_1.html