0tokens

Apply for AI Grants India

Financial support for innovators building the future of AI in India.

Apply now

Chat · regulatory norms for fintech

Regulatory Norms for Fintech in India: A Practical Guide

  1. aigi

    India’s fintech sector spans digital lending, payments, account aggregation, wealth technology, insurance distribution, neobanking, embedded finance and cryptocurrency-related services. Each model can trigger different regulatory norms for fintech, depending on the activity, customer, funds flow, technology and entities involved.

    For founders, compliance is not a one-time licence exercise. It is an operating system covering authorisation, KYC, data governance, cybersecurity, outsourcing, consumer protection, reporting and board oversight. This guide explains the principal regulatory framework in India and provides a practical path for building a compliant fintech business.

    What are regulatory norms for fintech?

    Regulatory norms for fintech are the laws, rules, directions, licensing requirements and supervisory expectations that govern technology-enabled financial services. In India, they are distributed across several regulators and statutes rather than consolidated in one fintech law.

    The applicable rules usually depend on:

    • Whether the business handles customer funds
    • Whether it provides credit, payments, investments or insurance
    • Whether it acts as a principal, agent, marketplace or technology provider
    • Whether it serves consumers, businesses or regulated financial institutions
    • Whether it processes personal, financial or biometric data
    • Whether the entity is incorporated in India or operates cross-border

    A fintech may therefore need to comply with multiple frameworks at once. For example, a digital lending platform could be subject to Reserve Bank of India (RBI) rules, the Prevention of Money Laundering Act, data protection requirements, consumer protection law, information technology and cybersecurity obligations, and contractual controls imposed by its partner bank or non-banking financial company (NBFC).

    Which regulators oversee fintech in India?

    Reserve Bank of India

    The RBI is the principal regulator for banking, payments, NBFCs, digital lending, prepaid instruments, payment aggregators, payment systems and several financial technology activities. RBI authorisation or compliance may be required where a business performs a regulated financial function rather than merely supplying software.

    Key RBI-regulated categories include:

    • Banks and NBFCs
    • Payment system operators
    • Payment aggregators and payment gateways
    • Prepaid payment instrument issuers
    • Account Aggregators
    • Credit information companies
    • Peer-to-peer lending platforms
    • Bharat Bill Payment System participants
    • Cross-border payment and foreign exchange activities

    Securities and Exchange Board of India

    SEBI regulates securities markets, investment advisers, research analysts, portfolio managers, stockbrokers, mutual funds, alternative investment funds, investment platforms and related intermediaries. A fintech offering personalised investment advice, executing securities trades or managing portfolios may need SEBI registration or must operate through a registered intermediary.

    Insurance Regulatory and Development Authority of India

    IRDAI oversees insurers, insurance brokers, corporate agents, web aggregators, insurance marketing firms and other insurance intermediaries. Insurtech businesses must carefully distinguish between technology support and regulated solicitation, distribution or underwriting.

    Pension Fund Regulatory and Development Authority

    PFRDA regulates pension products and intermediaries, including activities connected with the National Pension System. Fintech platforms facilitating pension onboarding or distribution may require a regulated partnership and defined controls.

    Ministry of Electronics and Information Technology

    MeitY administers important information technology and data-related rules, including cybersecurity incident reporting and intermediary obligations. The Digital Personal Data Protection Act, 2023 creates a broader framework for processing digital personal data, although practical compliance requirements depend on notified rules and implementation timelines.

    Financial Intelligence Unit–India

    The FIU-IND administers reporting obligations under the anti-money laundering framework. Reporting entities must meet requirements for customer due diligence, suspicious transaction reporting, record retention and designated compliance officers.

    Core regulatory norms for fintech business models

    Digital lending

    Digital lending is one of the most closely supervised fintech categories. RBI’s digital lending framework places responsibility on regulated entities, even when technology and customer acquisition are outsourced to lending service providers.

    Important requirements include:

    • Clear identification of the regulated lender to the borrower
    • Direct disbursal into the borrower’s bank account, subject to permitted exceptions
    • Direct repayment to the regulated entity’s account
    • Transparent disclosure of the annual percentage rate and key loan terms
    • A standardised Key Fact Statement before loan execution
    • A cooling-off period for borrowers, subject to the framework
    • No automatic increase in credit limits without explicit borrower consent
    • Restrictions on accessing contacts, call logs, files and unnecessary device data
    • Controlled and consent-based collection of personal data
    • Grievance redressal mechanisms and escalation details
    • Reporting of digital lending applications and service providers where applicable

    A fintech should not describe itself as a lender if it only provides software or lead generation. Marketing, agreements, app screens and customer communications must accurately reflect the regulated lender’s role.

    Payments and wallets

    Payment businesses may require RBI authorisation under the Payment and Settlement Systems Act, 2007. Payment aggregators, payment gateways and wallet operators face obligations involving merchant onboarding, escrow accounts, settlement timelines, chargebacks, grievance handling, cybersecurity and auditability.

    A company must assess whether it is:

    • Providing payment infrastructure to a regulated entity
    • Aggregating payments from customers for merchants
    • Issuing a stored-value instrument
    • Operating a payment system
    • Facilitating cross-border transactions

    The distinction affects licensing, capital, governance and operational requirements. Customer funds should not be commingled with operating funds, and settlement flows must be documented and reconciled.

    Account Aggregator services

    Account Aggregators operate within an RBI-regulated consent-based financial data-sharing framework. Their role is to facilitate the transfer of financial information between financial information providers and users, based on explicit consent.

    An Account Aggregator must implement consent artefacts, data minimisation, purpose limitation, security controls and restrictions against storing or using customer financial information beyond the authorised framework. A general data analytics platform cannot automatically perform Account Aggregator functions without meeting the applicable authorisation and ecosystem requirements.

    Wealthtech and investment platforms

    Investment apps must determine whether their services constitute execution, distribution, research, investment advice or portfolio management. SEBI registration may be necessary for regulated activities.

    Common compliance risks include:

    • Presenting generic content as personalised investment advice
    • Recommending securities without the required registration
    • Misrepresenting returns or using misleading performance claims
    • Failing to disclose commissions and conflicts of interest
    • Inadequate risk profiling and suitability processes
    • Using unregistered third parties for customer acquisition

    Technology does not remove the underlying regulatory character of the service. An algorithm that gives personalised recommendations can still trigger investment-adviser obligations.

    Insurtech

    Insurance distribution models must be mapped to the correct IRDAI category. A platform that compares products may be a web aggregator; one that sells policies may need a distribution licence or operate through a licensed intermediary. Product explanations, disclosures, consent records, commission statements and customer servicing must be controlled.

    Crypto and virtual digital assets

    Virtual digital asset businesses face a complex environment. India taxes certain virtual digital asset transactions, while anti-money laundering obligations apply to specified activities involving virtual digital assets. Registration with the FIU-IND may be required for covered services such as exchange, transfer, safekeeping or administration.

    Tax treatment does not itself mean that a token activity is authorised as a regulated investment or payment product. Founders should obtain specialist legal and tax advice before launching custody, exchange, lending, derivatives or tokenisation services.

    KYC, AML and customer due diligence

    Know Your Customer and anti-money laundering controls are central regulatory norms for fintech. Covered entities must establish the customer’s identity, understand the nature and purpose of the relationship, monitor transactions and report suspicious activity where required.

    A practical KYC programme should include:

    • Customer identification and verification procedures
    • Beneficial ownership checks for companies and partnerships
    • Risk-based customer classification
    • Sanctions and politically exposed person screening
    • Transaction monitoring rules and alert handling
    • Suspicious transaction escalation and reporting
    • Periodic customer information updates
    • Record retention and audit trails
    • Staff training and compliance testing

    Video KYC, Aadhaar-based processes, PAN verification and digital document checks must be used only through permitted methods and with appropriate consent and security controls. A fintech should maintain evidence showing what was collected, why it was collected, how it was verified and who approved exceptions.

    Data protection and consent management

    Fintechs process highly sensitive financial information, making privacy governance a core business requirement. The Digital Personal Data Protection framework, sector-specific RBI rules and contractual requirements may apply simultaneously.

    Key controls include:

    • A clear notice explaining data processing purposes
    • Valid, informed and purpose-specific consent where required
    • Collection of only necessary information
    • Defined retention and deletion schedules
    • Mechanisms for access, correction and grievance handling
    • Vendor and cloud-service due diligence
    • Encryption in transit and at rest
    • Role-based access and privileged-access monitoring
    • Incident response and breach escalation procedures
    • Controls for sharing data with lenders, insurers and analytics providers

    Consent should not be hidden in lengthy terms and conditions. Screens should separate essential service consent from optional marketing consent, record timestamps and preserve the version of the notice shown to the user.

    Cybersecurity and technology governance

    Regulated fintechs are expected to maintain resilient systems, protect customer information and manage technology risk. Depending on the activity, requirements may arise from RBI directions, CERT-In directions, sectoral standards, contractual obligations and audit expectations.

    A mature security programme should cover:

    • Asset inventory and data-flow mapping
    • Secure software development lifecycle controls
    • Vulnerability scanning and penetration testing
    • Multi-factor authentication for privileged access
    • Security logging and monitoring
    • Backup, disaster recovery and business continuity
    • Ransomware and fraud response playbooks
    • Patch and endpoint management
    • Secure application programming interfaces
    • Independent audits and remediation tracking

    CERT-In directions include incident-reporting and log-retention expectations for relevant entities. Fintechs should define reporting ownership before an incident occurs, rather than relying on an engineering team to interpret regulatory deadlines during a crisis.

    Outsourcing, cloud and third-party risk

    Most fintechs depend on cloud providers, KYC vendors, payment processors, collection agencies, call centres and software suppliers. Outsourcing does not transfer regulatory accountability.

    Vendor contracts should address:

    • Service levels and uptime
    • Information security standards
    • Data ownership and permitted use
    • Sub-outsourcing approval
    • Audit and inspection rights
    • Incident notification timelines
    • Business continuity and exit assistance
    • Data return and secure deletion
    • Regulatory access to records

    Founders should maintain a critical-vendor register and classify suppliers according to customer impact, data sensitivity and operational dependency. Concentration risk is important: using one provider for identity, payments and communications may create a single point of failure.

    Consumer protection and fair practices

    Fintech products must be understandable, fairly marketed and supported by accessible complaint channels. Disclosures should explain pricing, fees, interest, penalties, auto-debits, cancellation rights, data use and the identity of the regulated entity.

    Avoid:

    • Dark patterns that pressure customers into consent
    • Hidden charges or pre-ticked optional services
    • Guaranteed-return claims
    • Unclear lending or insurance advertisements
    • Aggressive recovery practices
    • Misleading rankings or comparison results
    • Customer support that cannot escalate complaints

    A board-approved grievance policy should define response timelines, escalation officers, complaint categorisation and root-cause analysis. Complaint data should feed product and control improvements.

    Corporate, tax and foreign exchange considerations

    A fintech’s corporate structure should match its regulatory model. Investors and founders should assess foreign direct investment rules, sectoral caps, beneficial ownership, downstream investment, related-party transactions and capital requirements.

    Other areas may include:

    • Goods and Services Tax on platform or intermediary fees
    • Income-tax withholding and reporting
    • Equalisation or cross-border digital service considerations
    • Foreign exchange rules for international collections and remittances
    • Accounting treatment for customer funds and escrow balances
    • Transfer pricing for cross-border group services
    • Employment and contractor compliance

    A regulated partnership should not be used merely as a label. Agreements must allocate responsibilities, customer ownership, compliance testing, audit rights and liability in a way that reflects actual operations.

    A compliance roadmap for fintech founders

    1. Map the product

    Document every customer journey, money movement, data element, contractual relationship and revenue stream. Identify whether the platform advises, distributes, underwrites, lends, aggregates, settles or merely provides technology.

    2. Identify the regulator and licence

    Create a regulatory matrix showing the activity, applicable regulator, required authorisation, responsible entity, reporting duties and launch dependencies. Obtain specialist advice where the classification is uncertain.

    3. Design the operating model

    Decide whether to apply for a licence, partner with an existing regulated entity or limit the product to unregulated technology services. Do not launch regulated functions before the permissions and agreements are in place.

    4. Build compliance by design

    Integrate KYC, consent, disclosures, limits, approval workflows, audit logs and complaint handling into the product architecture. Manual workarounds should be documented and temporary.

    5. Test before launch

    Conduct legal, security, privacy, operational and customer-experience reviews. Test edge cases such as failed payments, disputed transactions, account closure, data deletion, fraud alerts and service outages.

    6. Monitor continuously

    Regulatory compliance requires recurring audits, policy updates, training, board reporting, vendor reviews and regulatory change tracking. Assign named owners and measurable control indicators.

    Common mistakes to avoid

    • Assuming all fintech activity is unregulated technology
    • Treating a partner’s licence as a blanket approval for every feature
    • Collecting excessive app permissions
    • Launching before agreements and customer disclosures are final
    • Ignoring state-level consumer or employment requirements
    • Failing to reconcile customer funds daily
    • Outsourcing KYC or collections without oversight
    • Treating cybersecurity as an annual checklist
    • Using artificial intelligence without explainability, monitoring and human escalation
    • Keeping no evidence of consent, approvals or control testing

    FAQ: Regulatory norms for fintech in India

    Does every fintech need an RBI licence?

    No. A software provider that does not perform regulated financial functions may not need an RBI licence. However, lending, payment, wallet, Account Aggregator and other activities can require authorisation or operation through an appropriately regulated partner.

    Can a startup offer digital loans without becoming an NBFC?

    A startup may provide technology or lending-service functions to a regulated lender, subject to the applicable RBI framework and contract. It generally cannot present itself as the lender or independently perform regulated lending without the required structure and permissions.

    What is the most important fintech compliance requirement?

    There is no single requirement. Product classification, licensing, KYC/AML, data protection, cybersecurity, consumer protection and accurate customer disclosures must be addressed together.

    Are fintech regulations the same across India?

    Central financial regulators establish the principal framework, but state laws, tax rules, consumer obligations and sector-specific requirements can also apply. Cross-border services introduce additional foreign exchange and data considerations.

    How can an AI fintech manage compliance risk?

    Maintain human oversight for high-impact decisions, document model purpose and data lineage, test for bias and performance drift, protect personal data, provide explanations where appropriate, and retain audit logs for decisions and interventions.

    Apply for AI Grants India

    Building compliant AI for finance requires strong technical execution and a clear understanding of India’s regulatory environment. Apply to AI Grants India for support and opportunities designed for Indian AI founders.

    Last updated 17 September 2026

AIGI may be inaccurate. Replies seeded from the guide above.