← NBFCs
RBI IT Framework Compliance for NBFCs
RBI’s IT governance expectations for NBFCs scale with the layer you occupy under scale-based regulation. Middle and Upper Layer NBFCs carry obligations close to a bank’s, and digital lending adds a further overlay that most NBFCs meet late.
What RBI IT Framework requires of nbfcs
- Layer determination (Base, Middle, Upper, Top) — this dictates the depth of every obligation that follows.
- Board-level IT strategy and IT governance structures, with a CISO where the layer requires one.
- IS audit covering core lending systems, customer-facing channels and the third parties operating them.
- Digital Lending Directions compliance where DLAs or LSPs are used, including data-storage restrictions and disclosure obligations.
- Incident reporting to RBI and CERT-In, with the six-hour CERT-In clock running from detection.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Board and IT Strategy Committee minutes showing genuine oversight
- IS audit report with management responses and closure evidence
- Vendor due-diligence and contractual security terms for LSPs and technology partners
- Access reviews across the core lending platform and its interfaces
- VAPT and retest evidence for digital lending applications
Where nbfcs usually come unstuck
- Applying Base Layer expectations after crossing into Middle Layer through growth.
- Assuming the LSP’s controls satisfy your obligation — accountability stays with the NBFC.
- Customer data retained by a digital lending app in breach of the storage restrictions.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
