Posts

Showing posts with the label KYC Directions

KYC Framework in Light of Aadhaar 2025 Amendment Regulations

RBI’s recent supervisory reviews of NBFCs repeatedly highlight one area of non-compliance: Aadhaar misuse in KYC — especially accepting unmasked Aadhaar copies , failing to obtain mandatory consent , or performing unauthorised Aadhaar verification . On  9 December 2025 , UIDAI notified the  Aadhaar (Authentication and Offline Verification) Amendment Regulations, 2025  to amend the 2021 Regulations .  This blog summarises what NBFCs must do now — and what must immediately stop. Key Amendments: 1. New Definitions Introduced: (i) " Aadhaar Application" [Reg. 2(1)(ac)]-  UIDAI now defines authorised mobile/web applications — including mAadhaar, Aadhaar App, QR Scanner App, myAadhaar Portal — which alone may be used to perform offline Aadhaar verification. NBFC implication:  All offline Aadhaar verification must be done only through these UIDAI-approved apps/tools. (ii) "Aadhaar Verifiable Credential (AVC)"  [Reg. 2(1)(be)]-   A new digital do...

RBI’s 100+ Penalties in a Year: What Went Wrong?

  In the past year, the Reserve Bank of India (RBI) has imposed more than 100 monetary penalties on banks, NBFCs, fintechs, and cooperative institutions. These penalties span a wide range of compliance failures—from customer due diligence lapses to weak cyber security, and from outsourcing gaps to violations of lending norms. While the penalties differ in size, they all point to a common theme: regulatory compliance is non-negotiable . Here’s a breakdown of the most frequent reasons behind these actions. Category Typical Lapses Illustrative Orders Key Directions Change in management Failed to take prior written permission of the RBI before appointing a director Grewal Brothers Finance Company Private Limited (15 May, 2025) Mahindra Rural Housing Finance Limited (28 March, 2025) Habitat Micro Build Ind...

RBI-Mandated Policies Every Base Layer NBFC Must Have: A Comprehensive Guide (Updated as on 5th December, 2025)

S. No. Policy Relevant Provision of Law Objective Remarks / Implementation Insights 1 Business Continuity Plan (BCP) & Disaster Recovery (DR) Policy Para 62, Reserve Bank of India (Non-Banking Financial Companies – Managing Risks in Outsourcing) Directions, 2025 Ensure uninterrupted business operations during disasters or cyberattacks. Ensure vendors follow recovery protocols; conduct regular mock drills and resilience testing. 2 Fair Practices Code Para 7, Reserve Bank of India (Non-Banking Financial Companies – Responsible Business Conduct) Directions, 2025 Promote transparency, ethical lending, and borrower protection. Use plain-language communications; disclose all charges upfront; avoid hidden clauses. ...

Inclusive Digital KYC: A Necessity or a Reform?

India’s digital transformation has streamlined the entire banking and financial services through Aadhaar, e-KYC, and video-based verification[1]. However, these systems have posed severe barriers for persons with disabilities, particularly acid attack survivors with facial/ eye disfigurements and individuals with blindness. Recognising this, the Hon’ble Supreme Court in Pragya Prasun & Ors. vs. Union of India  issued a landmark judgment on 30th April 2025, mandating inclusive reforms in KYC processes. In this regard, the Securities Exchange Board of India had earlier issued a circular no. SEBI/HO/MIRSD/SECFATF/P/CIR/2025/74 dated 23rd May, 2025, directing all its intermediaries to comply with the said Supreme Court Order. Now, on 14th August, 2025, the Reserve Bank of India has issued a notification no. RBI/2025-26/74 , wherein it has directed that all regulated entities shall mandatorily undertake appropriate measures in this regard.  Background:  Two writ petitions...