RBI Digital Lending Directions 2025: LSP, DLA, KFS, APR, Cooling-Off, Data, DLG/FLDG & Compliance

By Adv. Govind Bali
Fastrack Legal Solutions LLP

The Reserve Bank of India (Digital Lending) Directions, 2025, issued on 8 May 2025, consolidated the RBI’s earlier digital-lending instructions into a single framework and added important requirements for multi-lender LSP platforms and the public directory of Digital Lending Apps.

The Directions matter not only to banks and NBFCs. They directly shape how Lending Service Providers (LSPs), Digital Lending Apps (DLAs), technology vendors, recovery partners and customer-acquisition platforms may operate when they support an RBI-regulated lender.

The central principle is simple: outsourcing does not outsource regulatory responsibility. The Regulated Entity remains responsible for ensuring that the digital lending model, borrower journey, funds flow, data handling, recovery practices and LSP conduct comply with the regulatory framework.

For implementation support, see our Digital Lending & LSP Compliance and NBFC Regulatory & Compliance Advisory pages. For agreement-level issues, see NBFC–LSP Agreement: Key Clauses and RBI Compliance.


What Changed Under the 2025 Directions?

The 2025 Directions consolidate the earlier 2022 digital-lending guidelines and the 2023 DLG framework, while adding two major structural developments:

  • Multi-lender LSP transparency: LSPs partnering with multiple regulated lenders must present available loan offers in a transparent and non-manipulative manner.
  • DLA reporting and public directory: regulated entities must report their DLAs and relevant LSP-operated DLAs through RBI’s reporting framework, supporting a public directory intended to help borrowers verify whether a DLA is associated with a regulated lender.

Most provisions took effect from 8 May 2025. The DLA reporting requirement under paragraph 17 became effective from 15 June 2025, while the multi-lender arrangement requirements under paragraph 6 became effective from 1 November 2025.


Who Must Comply?

The Directions apply to digital lending activities of:

  • Commercial Banks;
  • Primary Urban Co-operative Banks, State Co-operative Banks and Central Co-operative Banks;
  • Non-Banking Financial Companies, including Housing Finance Companies; and
  • All-India Financial Institutions.

An LSP is not treated as the balance-sheet lender merely because it performs customer acquisition, underwriting support, servicing, monitoring or recovery. The regulated lender remains responsible for the outsourced arrangement.


What Is an LSP?

A Lending Service Provider is an agent of a Regulated Entity that performs one or more parts of the lender’s digital-lending functions. Depending on the engagement, this can include:

  • customer acquisition;
  • lead generation;
  • underwriting support;
  • pricing support;
  • servicing;
  • monitoring;
  • collection and recovery support;
  • technology interfaces; and
  • portfolio-related operational functions.

The legal structure of an LSP agreement should therefore match the actual operating model. A contract describing an LSP as a mere “technology provider” will not solve a regulatory problem if the platform is in fact performing lender-facing or borrower-facing lending functions.


What Is a Digital Lending App or DLA?

A DLA can be a mobile or web-based interface facilitating digital lending. It may be owned by the regulated lender itself or operated by an LSP engaged by the lender.

For compliance purposes, the important question is not who owns the code. The key questions are:

  • Who controls the borrower journey?
  • Who displays the loan offer?
  • Who collects data?
  • Who communicates charges?
  • Who handles repayments?
  • Who conducts recovery?
  • Who receives complaints?

RE–LSP Due Diligence Is Mandatory

A regulated lender should conduct meaningful due diligence before appointing an LSP and continue monitoring the relationship afterward.

A practical LSP diligence file should examine:

  1. corporate identity and beneficial ownership;
  2. financial capacity;
  3. technology architecture;
  4. cybersecurity controls;
  5. data privacy and storage;
  6. customer-facing conduct;
  7. complaint history;
  8. recovery practices;
  9. subcontractors;
  10. business continuity;
  11. regulatory and litigation history;
  12. ability to comply with RBI requirements.

The lender should also retain effective audit, monitoring, reporting, remediation and termination rights in the contract.


Multi-Lender Platforms: New Transparency Rules

Where an LSP has arrangements with multiple regulated lenders and presents loan offers to a borrower, the 2025 framework requires materially greater transparency.

The borrower should receive a digital view of the available offers from willing lenders, containing key information such as:

  • name of the regulated lender;
  • loan amount;
  • tenor;
  • APR;
  • repayment obligation; and
  • other material terms and conditions.

The presentation should permit an informed comparison rather than steer the borrower through hidden ranking preferences.

No dark patterns

LSPs should not use deceptive interface design to push a borrower toward a particular lender or product. A ranking based on a transparent, pre-disclosed metric can be distinguished from manipulative presentation.

This means product screens, recommendation logic, sorting defaults, highlighted offers and user-interface nudges should be included in legal and compliance testing.


Creditworthiness Cannot Be Outsourced Away

The regulated lender remains responsible for adequate credit appraisal. A digital journey should capture sufficient information to assess the borrower’s economic profile and repayment capacity in accordance with the applicable lending framework.

For an LSP, this means an underwriting model cannot be treated as a black box that the lender accepts without governance. The RE should understand the inputs, decision flow, overrides, exception handling and risk controls around the credit process.


KFS: Key Fact Statement

The borrower should receive a Key Fact Statement before execution of the loan contract in the applicable format. The KFS is intended to show the economically important terms of the loan in a standardised and understandable manner.

It should enable the borrower to understand items including:

  • loan amount;
  • interest and APR;
  • repayment schedule;
  • fees and charges;
  • penal or contingent charges where required by the applicable framework;
  • grievance redressal details;
  • recovery mechanism; and
  • cooling-off terms.

A charge that is absent from the required disclosures can create a regulatory and customer-dispute issue.


APR: Why It Matters

The Annual Percentage Rate is designed to communicate the annualised cost of the credit facility rather than only the nominal interest rate.

Digital-lending interfaces that advertise only “1.5% per month” or a similar simplified number without allowing the borrower to understand the all-in credit cost can create a transparency problem.

Product, legal, finance and technology teams should therefore reconcile:

Loan engine → KFS → sanction letter → repayment schedule → website/app display → customer communication.

Those numbers should not contradict one another.


Loan Disbursal and Repayment: Direct Funds Flow

A foundational digital-lending rule is that disbursal and repayment should ordinarily occur directly between the borrower and the regulated lender, subject to the recognised exceptions in the RBI framework.

The LSP should not casually become a pass-through pool account for loan disbursals or customer repayments.

A compliance review should map every rupee:

RE bank account → borrower/end-beneficiary → borrower repayment → RE bank account.

If the live funds flow differs from the agreement, the documentation alone does not cure the operational defect.


Who Pays the LSP?

LSP compensation and customer charges should be structured consistently with the RBI framework. The regulated lender should not use the LSP as a mechanism for imposing undisclosed borrower costs.

The commercial agreement should separately identify:

  • lead-generation fee;
  • servicing fee;
  • technology fee;
  • collection/recovery fee;
  • performance-linked fee where legally permissible;
  • DLG-related economics where applicable;
  • taxes.

Borrower-facing charges should reconcile with the KFS and loan documents.


Cooling-Off Period: Minimum One Day Under the 2025 Framework

The 2025 Directions retain a cooling-off mechanism but give the regulated lender’s Board greater flexibility in setting the period, subject to a minimum of one day.

During the cooling-off period, the borrower should have an express option to exit the digital loan by paying the principal and proportionate APR without penalty. A reasonable one-time processing fee may be retained where permitted and disclosed in the KFS.

This should be built into the product and technology workflow. A cooling-off right that exists only in a policy PDF but cannot actually be exercised through the operational process is a compliance weakness.


Grievance Redressal

The RE and relevant LSP/DLA should provide clear grievance channels. Borrowers should be able to identify the grievance officer and lodge complaints through accessible channels.

The regulatory responsibility ultimately remains with the regulated lender. Where a complaint is rejected, not satisfactorily resolved or remains unanswered for the prescribed period, the RBI Ombudsman/CMS framework may become available to the borrower in accordance with the applicable scheme.

Complaint data should also be treated as a compliance signal. Repeated complaints about the same fee, recovery agent or app screen often indicate a process defect rather than isolated customer dissatisfaction.


Recovery Agents and Digital Collection Practices

Digital lending does not dilute fair-recovery obligations. The borrower should know when a recovery agent is authorised, and the lender remains responsible for outsourced recovery conduct.

Contracts and SOPs should prohibit:

  • threatening or abusive communication;
  • harassment of contacts;
  • misrepresentation of legal authority;
  • public shaming;
  • unauthorised data use;
  • unapproved recovery channels;
  • contact outside permitted conduct standards.

Recovery calls, assignments, agent identity and escalation should be auditable.


Data Collection Must Be Need-Based and Consensual

The 2025 Directions require data collection through the RE’s DLA or an LSP’s DLA to be need-based and based on prior and explicit borrower consent with an audit trail.

The DLA should not access mobile-phone resources such as:

  • contact lists;
  • call logs;
  • files and media;
  • telephony functions;

merely because the app can technically request those permissions.

One-time access to facilities such as camera, microphone or location may be taken where necessary for onboarding or KYC, subject to explicit consent.


Consent Architecture Matters

Consent should not be buried inside a single broad “I agree” box.

A defensible borrower journey should document:

  • what data is collected;
  • why it is collected;
  • who receives it;
  • whether sharing is necessary;
  • how consent is obtained;
  • how consent can be withdrawn where applicable;
  • retention and deletion rules.

The data policy, app permissions and actual API calls should tell the same story.


Data Storage and Offshore Processing

The 2025 Directions continue the Indian data-storage requirement for digital lending. Where data is processed outside India, the framework requires the data to be brought back to India and deleted from the overseas servers within 24 hours of processing.

This has practical consequences for cloud architecture, analytics providers, AI models, customer-support tools and cross-border technology vendors.

A legal review should therefore include a data-flow diagram, not merely a privacy policy.


Biometric Data

The Directions restrict storage or collection of biometric data by REs and LSPs unless permitted under the applicable statutory framework.

A FinTech should not assume that customer convenience is sufficient legal justification for retaining biometric data.


Privacy Policy

The RE and its LSPs should maintain a comprehensive privacy policy consistent with applicable law and RBI requirements. Where third parties are permitted to collect personal information through a DLA, those third parties should be transparently addressed.

For broader data-governance review, see our Data Protection & Privacy Risk Audit.


Reporting to Credit Information Companies

Digital lending does not fall outside credit-reporting obligations merely because a loan is small, short-term or originated through an app.

REs must ensure that lending through their own DLAs and LSP-operated DLAs is reported to Credit Information Companies as required by the regulatory framework.

Structured short-term credit and deferred-payment products should therefore be tested for their reporting treatment rather than labelled “BNPL” or “merchant credit” and assumed to be outside the system.


DLA Reporting and RBI Public Directory

Regulated entities are required to report relevant DLA particulars through RBI’s CIMS framework. The directory is intended to help customers verify the claimed association between a DLA and a regulated entity.

The listing does not mean that RBI has independently approved, licensed or endorsed the third-party DLA. Marketing material should not misrepresent inclusion in the directory as an RBI approval badge.

The lender remains responsible for correctness and timely updating of the information it submits.


DLG / FLDG: What Is Permitted?

The 2025 Directions consolidate the framework for Default Loss Guarantee (DLG), commonly referred to in the market as FLDG.

An RE may enter into DLG arrangements only with an LSP or another RE engaged as an LSP. An LSP providing DLG must be incorporated as a company under the Companies Act, 2013.

DLG is not a substitute for underwriting. The lender must continue to conduct robust credit appraisal irrespective of the guarantee.


Board-Approved DLG Policy

An RE entering into DLG arrangements should maintain a Board-approved framework addressing matters including:

  • eligibility of DLG providers;
  • financial capacity;
  • nature and extent of cover;
  • monitoring and review;
  • fees;
  • portfolio identification;
  • invocation;
  • disclosures;
  • risk governance.

Every new or renewed DLG arrangement should be supported by due diligence showing that the provider has the capacity to honour the guarantee.


Permitted Forms of DLG

The regulatory framework permits DLG in specified forms, including:

  • cash deposited with the RE;
  • fixed deposit with a Scheduled Commercial Bank with lien in favour of the RE; and
  • bank guarantee in favour of the RE.

A commercial promise by an LSP to “cover first loss” without the required structure is not enough.


DLG Cap: 5%

The DLG cover is capped at 5% of the relevant loan portfolio calculated in accordance with the RBI framework.

The DLG set should consist of identifiable and measurable sanctioned loan assets and remains fixed for the purpose of determining the cover.

Portfolio design, loan additions and exclusions should therefore be controlled before the DLG arrangement is operationalised.


DLG Invocation: 120-Day Rule

The RE is required to invoke DLG within the applicable maximum overdue period of 120 days, unless the loan dues are made good earlier.

The DLG agreement should therefore clearly specify:

  • default trigger;
  • portfolio and loan identification;
  • notice mechanics;
  • invocation calculation;
  • payment timeline;
  • recoveries after invocation;
  • reporting and audit evidence.

DLG Does Not Change Borrower Liability or NPA Recognition

DLG does not permit the lender to ignore asset-classification or provisioning rules. Recognition of NPA and provisioning remains the RE’s responsibility.

Invocation of DLG also does not extinguish the borrower’s underlying liability. Recovery from the borrower can continue in accordance with law and the contract.


DLG Disclosure

The framework requires public disclosures relating to DLG-backed portfolios. LSPs involved in such arrangements should therefore maintain an operational process for monthly disclosure and reconciliation rather than treating the website disclosure as a one-time exercise.


Digital Lending Compliance Matrix

Area Control to Test
LSP onboarding Due diligence, contract, audit rights, monitoring
Loan offers Transparent comparison and no dark patterns
KFS APR and charges reconcile with product engine
Funds flow Direct RE–borrower flow except permitted cases
Cooling-off Operational exit mechanism, minimum statutory period
Complaints Named officer, escalation, 30-day monitoring
Recovery Agent controls, conduct monitoring, audit trail
Data Need-based, explicit consent, restricted phone access
Storage India storage and offshore-processing controls
DLA directory Accurate CIMS reporting and no false RBI endorsement
CIC reporting All required digital credit reported
DLG Eligibility, 5% cap, permitted form, invocation and disclosure

What Should an NBFC Audit First?

A practical digital-lending audit should begin with live operations:

  1. Identify every LSP and DLA.
  2. Map every customer screen.
  3. Map every money flow.
  4. Map all borrower data collected and every recipient.
  5. Compare KFS numbers with the loan engine.
  6. Test cooling-off functionality.
  7. Review complaint logs.
  8. Sample recovery calls and agent assignments.
  9. Review DLA reporting.
  10. Test DLG portfolios and disclosures.
  11. Review subcontractors and cloud vendors.
  12. Create remediation owners and deadlines.

The most common compliance failure is a gap between the signed agreement and the live digital journey.


Common Digital Lending Mistakes

  • Calling the LSP a technology vendor when it performs lending functions.
  • Allowing the LSP to control funds through an impermissible pass-through arrangement.
  • KFS figures not matching the actual repayment schedule.
  • Undisclosed borrower charges.
  • App permissions accessing contacts or call logs.
  • No real cooling-off process.
  • DLA directory information becoming outdated.
  • Recovery agents operating without effective lender oversight.
  • DLG treated as a substitute for underwriting.
  • DLG exceeding the regulatory cap or structured in an impermissible form.
  • Offshore data processing without the required repatriation/deletion controls.

Frequently Asked Questions

Do the 2025 Directions apply to NBFCs?

Yes. The framework applies to NBFCs, including HFCs, along with the other categories of regulated entities specified by RBI.

Can an LSP itself lend from its own balance sheet?

An LSP arrangement does not itself confer lender status. If an entity is actually extending credit from its own balance sheet, the regulatory perimeter must be separately analysed.

Can an LSP collect repayments into its own account?

Ordinarily the digital-lending framework requires direct repayment into the RE’s account, subject to the recognised exceptions.

What is the minimum cooling-off period?

Under the 2025 framework, the Board-determined cooling-off period is subject to a minimum of one day.

Can a DLA access the borrower’s contact list?

The RBI framework requires DLAs to desist from accessing mobile resources such as contact lists and call logs. Data collection should be need-based and consented.

Can data be processed outside India?

The 2025 Directions permit offshore processing subject to the requirement that the data be brought back to India and deleted from the overseas server within 24 hours of processing.

What is the DLG cap?

DLG is capped at 5% of the relevant loan portfolio in accordance with the RBI calculation framework.

How quickly must DLG be invoked?

The Directions prescribe a maximum overdue period of 120 days for invocation unless the borrower makes good the dues earlier.

Does RBI’s DLA directory mean an app is RBI-approved?

No. The directory reflects information submitted by regulated entities and should not be represented as RBI licensing or endorsement of the third-party app.


Key Takeaways

The Digital Lending Directions should be implemented as an operating model, not merely a legal memo.

A compliant structure should align:

RE responsibility → LSP contract → DLA screens → KFS/APR → funds flow → cooling-off → recovery → data architecture → CIC/DLA reporting → DLG controls.

If even one of those layers does not match the approved regulatory model, the problem can become a customer-protection, outsourcing, data or supervisory issue.


Authoritative Regulatory Sources


Disclaimer

This article is for general legal awareness and educational purposes only. It is not intended as advertisement or solicitation and does not constitute legal or regulatory advice for any particular bank, NBFC, FinTech, LSP, DLA, DLG or lending product. Applicability must be assessed against the specific regulated entity, product, customer journey, contractual structure and current RBI directions.

Leave a Comment

Your email address will not be published. Required fields are marked *