Wednesday, 2 September 2026

Digitisation of FPI Onboarding

 The recent SEBI Circular dated 20 August 2026 permitting the submission of a digitally signed Power of Attorney (PoA) as part of the registration process for Foreign Portfolio Investors (FPIs) represents a significant and welcome step towards simplification and digitalisation of the regulatory framework governing FPI onboarding.

Under the revised framework, the requirement of having the Power of Attorney subjected to notarisation, apostillisation or consularisation is effectively dispensed with where the prescribed digitally signed documentation is submitted in accordance with the applicable requirements. This is a particularly important procedural reform, as the traditional process of notarisation, apostillisation or consularisation of documents executed outside India can often be cumbersome, time-consuming and disproportionately expensive, particularly for overseas applicants having to comply with the formalities prescribed by multiple jurisdictions.

The relaxation is therefore likely to substantially reduce the administrative burden associated with FPI registration and facilitate a faster, more efficient and technology-driven onboarding process. More importantly, it reflects a regulatory approach that recognises the realities of cross-border transactions and the need to eliminate procedural requirements that may no longer serve a meaningful regulatory purpose in an increasingly digital environment.

The initiative is also consistent with the broader objective of ease of doing business, particularly in the context of attracting and facilitating foreign investment into India. While appropriate safeguards relating to authenticity, integrity and enforceability of documents must necessarily continue to remain in place, regulatory compliance should, wherever possible, be achieved through technology-enabled verification mechanisms rather than through purely procedural and documentary formalities.

It is hoped that this progressive approach adopted by SEBI will serve as a precedent for other regulators and government authorities, including the Ministry of Corporate Affairs (MCA), Reserve Bank of India (RBI) and other statutory and regulatory bodies dealing with cross-border transactions and foreign entities.

There is considerable scope for reviewing the continuing requirement of notarisation, apostillisation and consularisation of documents executed by foreign parties, particularly where the authenticity and identity of the signatory can be established through reliable digital means or other technology-enabled verification mechanisms.

A calibrated transition towards digitally signed, electronically verifiable and self-certified documentation, supplemented by appropriate risk-based verification wherever necessary, could significantly reduce compliance costs and turnaround time without compromising regulatory oversight.

SEBI’s latest initiative is therefore more than a mere procedural relaxation. It represents a broader shift towards trusting technology, reducing redundant formalities and making regulatory compliance proportionate to the underlying risk. It is hoped that other regulators will take note of this development and similarly examine whether long-standing documentary requirements can be rationalised, thereby making India’s regulatory ecosystem more efficient, predictable and conducive to cross-border investment and business.

Enabling sharing of information by KYC KRA with entities regulated by IFSC

SEBI Circular No. HO/38/15/(7)2026-MIRSD-POD/I/19255/2026 dated August 20, 2026, concerning the sharing of KYC information by SEBI-registered KYC Registration Agencies (KRAs) with entities regulated by the International Financial Services Centres Authority (IFSCA).

1. Background and objective

The Circular has been issued to facilitate interoperability and information sharing between SEBI-registered KRAs and entities regulated by IFSCA. The regulatory mechanism is enabled through Regulation 16A of the SEBI (KYC Registration Agency) Regulations, 2011.

Regulation 16A(1) permits entities regulated by other financial-sector regulators, when specified by SEBI, to access the KRA system for undertaking KYC of their clients. SEBI has now formally specified IFSCA for this purpose.

This represents an important step towards creating greater integration between the KYC infrastructure of India's securities market and the financial ecosystem operating within the International Financial Services Centre (IFSC).

2. What has changed?

The principal regulatory change is that IFSCA-regulated entities are now enabled to access the KRA system maintained by SEBI-registered KRAs for undertaking KYC of their clients.

In practical terms, this means that eligible entities regulated by IFSCA can leverage the existing KRA infrastructure rather than having to operate an entirely independent KYC information-gathering mechanism.

The Circular therefore establishes a regulatory bridge between:

SEBI/KRAs → IFSCA-regulated entities → KYC information

This is particularly relevant to the expanding financial-services ecosystem in the IFSC.

3. Applicability of SEBI KRA Regulations

The Circular makes it clear that once an IFSCA-regulated entity accesses the KRA system, the provisions of the SEBI KRA Regulations, 2011 become applicable to such entity.

This is an important compliance consideration.

Access to the KRA database is therefore not merely a facility or technological integration. The accessing entity must comply with the applicable regulatory framework governing the KRA system.

Accordingly, IFSCA-regulated entities intending to use the KRA infrastructure should ensure that their internal KYC processes, systems, controls and personnel are aligned with the applicable requirements.

4. Compliance with SEBI's KYC framework

The Circular specifically requires all entities accessing the KRA system to follow the guidelines contained in SEBI's Master Circular dated October 12, 2023 on KYC norms for the securities market, as amended from time to time.

Therefore, IFSCA-regulated entities cannot treat KRA access as an isolated technical arrangement. Their use of KRA information must be integrated with the applicable KYC compliance framework.

From a compliance perspective, entities should therefore review:

  • KYC onboarding procedures;
  • KYC verification and validation processes;
  • access controls;
  • record-keeping arrangements;
  • data handling and confidentiality;
  • internal controls governing KRA access; and
  • compliance monitoring and audit mechanisms.

5. Special requirement for Foreign Portfolio Investors

The Circular contains an additional requirement where the client is registered as a Foreign Portfolio Investor (FPI).

In such cases, entities accessing the KRA system must also comply with the Data Security guidelines contained in SEBI's Master Circular dated May 30, 2024 relating to Foreign Portfolio Investors, Designated Depository Participants and Eligible Foreign Investors, as amended from time to time.

This is particularly significant because FPI-related KYC information can involve sensitive financial and identification data.

IFSCA-regulated entities dealing with FPIs should therefore pay particular attention to:

  • information-security controls;
  • authorised access;
  • data protection;
  • secure transmission and storage;
  • prevention of unauthorised disclosure; and
  • monitoring of access to KRA information.

6. Immediate effectiveness

The Circular is effective immediately from August 20, 2026.

Consequently, IFSCA-regulated entities that intend to utilise the KRA system should assess their readiness without waiting for a separate implementation date.

7. Regulatory significance

The Circular is significant beyond its immediate KYC implications.

The IFSC ecosystem is intended to provide a globally oriented financial-services platform, and efficient KYC interoperability is an important component of such an ecosystem. Enabling IFSCA-regulated entities to access the established KRA infrastructure should potentially:

  • reduce duplication in KYC processes;
  • improve operational efficiency;
  • facilitate smoother client onboarding;
  • improve consistency of KYC information;
  • reduce compliance friction for financial-sector participants; and
  • strengthen regulatory coordination between SEBI and IFSCA.

It also reflects a broader movement towards inter-regulatory cooperation and standardisation of financial-sector KYC infrastructure.

8. Impact on IFSCA-regulated entities

From the perspective of an IFSCA-regulated entity, the Circular should be viewed as both an opportunity and a compliance responsibility.

The opportunity lies in being able to access an established KYC repository and potentially streamline client onboarding.

The corresponding responsibility is that such access brings with it the requirement to comply with the relevant SEBI KRA framework and, where applicable, the enhanced data-security requirements for FPIs.

Entities should therefore consider conducting an internal gap assessment covering:

AreaSuggested compliance action
KRA accessEstablish appropriate authorised access
KYC processesAlign procedures with SEBI KRA requirements
Internal controlsDefine responsibility and approval mechanisms
Data securityReview controls over KRA information
FPI clientsImplement applicable additional data-security requirements
Record keepingEnsure appropriate maintenance of KYC records
Employee accessRestrict access to authorised personnel
Compliance monitoringInclude KRA usage within periodic compliance reviews

9. Impact on KRAs

For SEBI-registered KRAs, the Circular effectively expands the universe of entities that may access their systems.

KRAs will therefore need to facilitate access by eligible IFSCA-regulated entities in accordance with the regulatory framework, while ensuring appropriate controls around authentication, access, information sharing and data security.

The Circular does not, however, appear from the uploaded document to prescribe a separate operational implementation mechanism or specific technical timeline for KRAs. Such operational requirements may therefore need to be read along with the applicable KRA regulations, master circulars and subsequent directions.

10. Key takeaway for compliance professionals

The most important takeaway is that IFSCA has now been specifically recognised by SEBI under Regulation 16A(1) as a regulator whose regulated entities may access the SEBI KRA system.

However, such access comes with corresponding obligations. The accessing entities must comply with the SEBI KRA Regulations and the applicable SEBI KYC framework, with additional data-security requirements applying in relation to FPI clients.

Conclusion

The August 20, 2026 Circular is a relatively concise regulatory intervention, but its practical significance is considerable. By permitting IFSCA-regulated entities to access SEBI's KRA infrastructure, SEBI has taken a concrete step towards greater harmonisation of KYC processes across India's financial regulatory architecture.

For IFSCA-regulated entities, the immediate priority should be to determine whether they intend to utilise the KRA facility and, if so, ensure that their KYC policies, systems, access controls and data-security framework are capable of meeting the requirements incorporated through the Circular.

In essence, the Circular facilitates interoperability, but interoperability comes with regulatory accountability.

Wednesday, 26 August 2026

Modification in the regulatory framework for Online Bond Platform Providers (OBPPs)

SEBI Circular dated 14 August 2026 concerning modifications to the regulatory framework for Online Bond Platform Providers (OBPPs)

1. Executive Summary

The circular primarily seeks to liberalise and simplify the regulatory framework applicable to Online Bond Platform Providers (OBPPs) and promote ease of doing business.

The principal changes are:

  1. OBPPs may offer certain products, securities and services regulated by IFSCA.
  2. OBPPs may offer 54EC bonds and the corresponding bonds issued under Section 85 of the Income-tax Act, 2025.
  3. The requirement concerning the appointment and qualifications of the Compliance Officer has been revised.
  4. Additional disclosure, labelling and grievance-redressal requirements have been prescribed for the newly permitted products.

The circular has immediate effect, while all other provisions of the NCS Master Circular remain unchanged.


2. Expansion of Permissible Products

The most significant change is the expansion of the products that an OBPP can offer.

The revised Clause 5.2 now permits an OBPP to offer, among other things:

  • Listed debt securities;
  • Listed municipal debt securities;
  • Listed securitised debt instruments;
  • Debt, municipal debt and securitised debt instruments proposed to be listed through a public offering;
  • Listed Government Securities, State Development Loans and Treasury Bills;
  • Listed Sovereign Gold Bonds;
  • Products/securities/services regulated by SEBI, RBI, IRDAI, IFSCA or PFRDA; and
  • Bonds issued under Section 54EC of the Income-tax Act, 1961 or Section 85 of the Income-tax Act, 2025.

This represents a meaningful broadening of the permissible business scope of OBPPs. Instead of functioning primarily as platforms for specified domestic debt products, OBPPs can now potentially operate as a broader distribution channel for products regulated across multiple financial-sector regulators.

This could substantially improve product diversification and customer engagement, subject to the applicable regulatory restrictions.


3. IFSCA-Regulated Products – Important Compliance Considerations

The circular specifically permits OBPPs to offer products regulated by IFSCA. However, this permission is not unrestricted.

For IFSCA-regulated products, the OBPP must:

  • Follow the manner prescribed for SEBI-registered stock brokers operating within GIFT-IFSC;
  • Comply with applicable FEMA requirements;
  • Observe the applicable Overseas Investment Rules; and
  • Comply with the limits applicable under the Liberalised Remittance Scheme (LRS).

Further, these products must be clearly identified as international or overseas instruments, so that investors do not confuse them with domestic debt securities.

Key implication: An OBPP cannot treat IFSCA products as simply another category of domestic bonds. The platform will need appropriate product segregation, disclosures, regulatory controls and investor communication.

For platforms proposing to introduce such products, FEMA/LRS compliance should therefore be incorporated into the product onboarding and transaction-processing framework.


4. 54EC Bonds – Significant New Opportunity

The circular permits OBPPs to offer bonds issued under Section 54EC of the Income-tax Act, 1961, as well as the corresponding provision under the Income-tax Act, 2025.

However, the circular makes it clear that these are tax-specific investment instruments and imposes enhanced disclosure obligations.

The OBPP must disclose matters including:

  • Eligible issuers;
  • Lock-in period;
  • Investment limits;
  • Non-transferability;
  • Tax features;
  • Application size; and
  • Exemption from listing requirements under the SEBI LODR Regulations, 2015.

The platform must also prominently state that these investments are intended for investors seeking the relevant tax benefits, subject to satisfaction of the applicable eligibility conditions.

This is commercially significant because 54EC bonds are closely connected with tax planning. Their availability through OBPPs could make such platforms more attractive to investors seeking tax-efficient investment options.

At the same time, the disclosure requirements indicate that SEBI expects OBPPs to avoid presenting these instruments merely as conventional fixed-income products.


5. Grievance Redressal – Important Distinction

For products regulated by other financial-sector regulators, the applicable regulator's directions and stipulations will govern the products. The OBPP must specify the grievance-redressal mechanism on its platform.

For 54EC bonds, however, the circular specifically requires a disclaimer that grievance redressal does not lie with SEBI but with the issuer.

This distinction should be reflected clearly in the platform's:

  • Product pages;
  • Terms and conditions;
  • Risk disclosures;
  • FAQs;
  • Complaint-management process; and
  • Investor communications.

6. Compliance Officer Requirement – Major Governance Change

The circular makes a notable change to the compliance-officer requirement.

The revised provision requires the entity to appoint a Compliance Officer in accordance with the SEBI (Stock Brokers) Regulations, 2026, who must comply with the prescribed certification requirements, namely the NISM-Series-III-A: Securities Intermediaries Compliance (Non-Fund) Certification Examination.

Importantly, the footnote records that the earlier requirement was that:

“The entity has appointed a Company Secretary as a compliance officer.”

This is a material governance relaxation/change. The requirement is no longer framed specifically around appointment of a Company Secretary. Instead, the framework aligns the Compliance Officer requirement with the regulatory architecture applicable to stock brokers.

For existing OBPPs, this warrants an immediate review of:

  • Current Compliance Officer appointment;
  • Qualification and certification status;
  • Reporting structure;
  • Compliance responsibilities;
  • Board/management approvals; and
  • Internal compliance policies.

7. Operational Impact on Existing OBPPs

Existing OBPPs should consider undertaking a structured compliance-gap assessment covering at least the following:

AreaRecommended action
Product catalogueReassess products currently offered and products now permitted
IFSCA productsEstablish separate regulatory/FEMA/LRS compliance controls
Platform architectureCreate appropriate segregation/labelling for overseas products
54EC bondsIntroduce dedicated disclosures and tax-related warnings
Grievance mechanismClearly identify the responsible regulator/issuer
Compliance OfficerReview appointment against the 2026 requirements
NISM certificationVerify applicable certification requirements
Website disclosuresUpdate product descriptions, disclaimers and investor communications
Policies & SOPsAlign internal procedures with revised Clause 5.2
Legal documentationReview T&Cs, risk disclosures and investor documentation

8. Regulatory Philosophy Behind the Circular

The circular reflects a broader regulatory approach of facilitating business expansion while retaining investor-protection safeguards.

SEBI has expanded the permissible universe of products, but it has simultaneously introduced safeguards through:

  • Product segregation;
  • Regulatory labelling;
  • FEMA/LRS compliance;
  • Tax-specific disclosures;
  • Grievance-redressal disclosures; and
  • Compliance-officer certification requirements.

Therefore, the circular should not be interpreted simply as a relaxation. It is more accurately viewed as a controlled expansion of the permissible business activities of OBPPs.


9. Key Risks for OBPPs

From a compliance perspective, the principal risks arising from the revised framework are:

a. Misclassification risk
An OBPP could inadvertently offer a product that does not fall within the permitted categories.

b. Cross-regulatory compliance risk
IFSCA products introduce additional FEMA, LRS and overseas-investment considerations.

c. Disclosure risk
Insufficient disclosure of tax characteristics, lock-in periods or non-transferability could create investor-protection concerns.

d. Regulatory confusion
Investors may incorrectly assume that all products available on an OBPP are SEBI-regulated. The circular specifically addresses this concern through product labelling and disclaimers.

e. Governance risk
Existing OBPPs should ensure that their Compliance Officer arrangements conform to the revised framework.


Overall Professional Assessment

The 14 August 2026 SEBI Circular is materially favourable to OBPPs from a business-development perspective. It broadens the permissible product universe, enables access to IFSCA-regulated offerings and expressly permits distribution of 54EC bonds.

At the same time, SEBI has adopted a compliance-by-design approach: broader product access is accompanied by enhanced disclosures, regulatory segregation, FEMA/LRS compliance and strengthened compliance-officer requirements.

For an existing OBPP, the immediate priority should therefore be a regulatory and operational gap analysis, particularly covering the revised Clause 5.2 and Annexure-XXIA. Since the circular takes effect immediately, implementation should not be deferred.

In conclusion, the circular can be viewed as a positive regulatory development for the OBPP sector, but its commercial benefits will depend on each platform's ability to implement the expanded product scope without compromising regulatory segregation, investor disclosures and cross-regulatory compliance.

Tuesday, 25 August 2026

RBI (Commercial Banks - Responsible Business Conduct) Fourth Amendment Directions, 2026

 

1. Executive Summary

The Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Fourth Amendment Directions, 2026, issued on 6 August 2026, represent a significant strengthening and consolidation of the regulatory framework governing loan recovery, recovery agencies and recovery agents. The provisions come into force from 1 January 2027.

The principal regulatory shift is that the RBI is moving from relatively broad principles concerning recovery agents toward a much more prescriptive governance framework covering:

  • appointment and due diligence of recovery agencies;
  • training and certification of recovery agents;
  • borrower notification;
  • monitoring and recording of recovery communications;
  • field-visit protocols;
  • permissible recovery hours;
  • privacy and customer-data protection;
  • possession and sale of secured assets;
  • technology-enabled recovery mechanisms;
  • prohibited recovery practices;
  • compensation for certain wrongful actions; and
  • dedicated grievance-redressal mechanisms.

Importantly, the Directions make it clear that outsourcing recovery does not outsource regulatory responsibility. The bank remains responsible for establishing controls, monitoring recovery agencies and ensuring that their conduct does not expose the bank to regulatory, legal or reputational risk. This is consistent with the RBI's longstanding approach to recovery-agent supervision.

The RBI's official website also identifies the August 2026 measure as an amendment concerning the conduct of regulated entities in recovery of loans and engagement of recovery agents.


2. Scope and Applicability

The Directions apply to commercial banks other than:

  • Small Finance Banks;
  • Payments Banks;
  • Regional Rural Banks; and
  • Local Area Banks.

The provisions apply to recovery of loan dues from borrowers in default, including taking possession of security. Certain provisions may also apply to normal collection from borrowers who are not in default where the Directions expressly provide for such application.

Important definitional change

The amendment introduces two important concepts:

Recovery agency means an entity or individual, other than the bank's own employees, engaged under an outsourcing arrangement to assist in recovery of loan dues, including taking possession of security.

Recovery agent means the representative of a recovery agency who interacts directly with the customer.

The definition is deliberately broad and is based on the substance of the arrangement rather than its contractual label. A Business Correspondent involved in recovery activities, for example, will be treated as a recovery agency for these purposes.

Professional interpretation

This is important from a compliance perspective because banks cannot necessarily avoid the recovery-agency framework simply by calling an arrangement something else.

The RBI is effectively saying:

If the third party performs recovery functions, the regulatory requirements follow the activity, not merely the contractual nomenclature.


3. Governance and Recovery Policy

A bank is required to establish a formal policy covering collection and recovery of loan dues, including possession of security.

The policy must address, among other matters:

  • triggers for initiating recovery;
  • graded recovery actions;
  • escalation matrices;
  • code of conduct;
  • recovery following the death of a borrower;
  • handling of financially distressed borrowers;
  • documented pre-escalation engagement; and
  • available resolution options.

For recovery agencies, the policy must additionally cover:

  • eligibility;
  • due diligence;
  • performance evaluation;
  • inspection and audit;
  • compliance controls;
  • procedures for dealing with non-compliant agencies;
  • penalties/sanctions for non-compliance; and
  • borrower compensation for losses arising from recovery actions inconsistent with the Directions.

Compliance significance

This is more than a requirement to have a document titled "Recovery Policy."

The wording indicates an expectation for a structured recovery governance framework, where the bank can demonstrate:

Default → Assessment → Pre-escalation engagement → Resolution opportunity → Escalation → Agency assignment → Monitoring → Closure

Accordingly, banks should be able to demonstrate that recovery decisions are systematic, documented and proportionate, rather than purely target-driven.


4. Engagement of Recovery Agencies

4.1 Due diligence

Banks must establish a due-diligence process for recovery agencies consistent with RBI outsourcing requirements.

Importantly, verification is required not only at the agency level but also in relation to the antecedents of individual recovery agents, both before engagement and periodically thereafter in accordance with the bank's policy.

Practical implication

A bank should therefore maintain an auditable file containing, at minimum:

  • agency due-diligence records;
  • ownership/management information;
  • contractual documentation;
  • agent identity records;
  • antecedent verification;
  • periodic re-verification;
  • training/certification status;
  • performance records; and
  • complaints and disciplinary history.

5. Mandatory Training and IIBF Certification

The bank must ensure that a recovery agency deploys only agents who have obtained the relevant certificate from the Indian Institute of Banking and Finance (IIBF) after completing the prescribed Debt Recovery Agents training programme, or training through an institute having a tie-up arrangement with IIBF.

This makes agent competency a formal compliance requirement, rather than merely a recommended internal control.

A bank should therefore have a mechanism to prevent an uncertified or expired/unverified agent from being deployed.


6. Disclosure and Transparency

One of the stronger provisions concerns transparency regarding recovery agencies.

Banks must publish an up-to-date list of recovery agencies on their websites, including details such as:

  • name;
  • type of agency — corporate or individual;
  • correspondence address;
  • period of engagement; and
  • purpose of engagement, including recovery or possession of security.

The list must be updated within seven calendar days of modification, while termination must be reflected promptly.

Borrower-specific notification

Before a recovery agency makes an in-person visit to the borrower/guarantor, the bank must provide the recovery-agency details at least one day before the first visit.

If the agency changes during the recovery process, the borrower/guarantor must be notified immediately. The same applies where an agency's engagement is terminated.

Significance

This substantially reduces the scope for an individual appearing at a borrower's premises without a verifiable connection to the bank.

It also creates an important evidentiary trail:

Bank assignment → borrower notification → authorised agent → identification → field visit


7. Customer Information and Privacy

The bank must restrict disclosure of borrower/guarantor information to employees and recovery agencies to what is necessary for recovery-related duties.

Banks must also implement safeguards, including penal provisions, against misuse of customer information.

This is a significant compliance principle:

Recovery access ≠ unrestricted customer-data access.

The agency should receive only information necessary to perform its authorised function.

This is particularly relevant for technology platforms, call centres, field-recovery applications and third-party recovery vendors.


8. Recording of Recovery Communications

Banks must document:

  • the time of calls;
  • the number of calls; and
  • the content/text of calls made by recovery personnel to borrowers/guarantors.

Calls made by the borrower/guarantor to the telephone/mobile number communicated by the bank must also be recorded.

These records generally need to be retained for six months, or, where the matter is sub judice, until disposal of the matter. The bank must also take reasonable precautions such as informing the borrower that the conversation is being recorded.

Practical consequence

A recovery call is no longer simply an operational interaction. It becomes a potentially important compliance record and evidentiary record.

Banks should therefore consider controls around:

  • call recording;
  • call metadata;
  • retention;
  • retrieval;
  • access controls;
  • audit trails; and
  • complaint/investigation processes.

9. Recovery Targets and Incentive Structures

The RBI specifically requires banks to ensure that recovery targets or incentive structures for employees and recovery agencies do not encourage harsh recovery practices.

This is a particularly important management-level requirement.

The issue is not merely whether an agent violates the Code of Conduct.

The design of the incentive system itself must not create an incentive to violate it.

For example, a recovery model excessively focused on:

"Amount collected per agent per day"

could create conduct risk if it encourages aggressive calling, repeated visits or intimidation.

Banks should therefore consider incorporating conduct/compliance indicators into agency and employee performance evaluation.


10. Taking Possession of Security

Where a bank relies on a contractual possession clause, the clause must be legally valid and clearly brought to the borrower's attention at the time of execution.

The loan agreement must address:

  1. notice period before possession;
  2. circumstances where the notice period may be waived;
  3. possession procedure;
  4. final repayment opportunity before sale/auction;
  5. procedure for returning possession; and
  6. sale/auction procedure.

Significance

The RBI is effectively requiring procedural transparency around repossession.

A possession right should therefore not operate as an opaque contractual power. The borrower should understand when and how the bank can exercise it.


11. Technology-Based Recovery — Major New Compliance Area

This is arguably one of the most significant aspects of the amendment.

Banks generally cannot use technology to restrict or disable functions of a borrower's mobile phone, tablet or laptop as a recovery mechanism.

There is a narrow exception where:

  • the particular device itself was financed by the bank;
  • the loan agreement expressly and unambiguously permits device restrictions;
  • prescribed notice requirements are followed; and
  • the other conditions under the Directions are satisfied.

11.1 30-day and 60-day thresholds

Restrictions cannot begin merely because a borrower has missed a payment.

The device cannot be subjected to the technology-based restriction mechanism until the associated loan has become 30 days past due, and the borrower has failed to pay despite notice.

Thereafter:

  • gradual restrictions may begin after 30 days past due;
  • the full set of contractual restrictions can take effect only after 60 days past due;
  • outgoing calls cannot be restricted before 60 days past due.

This establishes a clear regulatory distinction between:

default → notice → 30 DPD → gradual restrictions → 60 DPD → full contractual restrictions


12. Essential Device Functions

Even where device restrictions are permitted, the bank cannot disable essential functionality such as:

  • incoming calls;
  • SMS; and
  • emergency SOS features.

The restrictions must also not prevent the borrower from carrying out activities related to work or employment.

Compliance implication

A technology solution cannot simply be designed around:

"Borrower defaults → phone gets locked."

The system must incorporate regulatory rules and exceptions into its technical architecture.


13. One-Hour Unlocking Requirement and Compensation

Once dues are realised, restrictions must be reversed expeditiously and no later than one hour after realisation.

Where wrongful restriction or delayed reversal is attributable to the bank, compensation is payable at:

₹250 per hour

subject to a maximum equal to the amount of the loan disbursed.

This creates a direct financial consequence for technology or operational failures.

Banks therefore need appropriate real-time payment-to-unlock integration and monitoring.


14. Personal Data on the Device

This provision is exceptionally important.

A bank and its technology service provider must not access or use personal data on the device for recovery or any other purpose.

The provision expressly identifies data such as:

  • contacts;
  • SMS;
  • call logs;
  • photographs;
  • location history; and
  • other personal data.

Regulatory principle

The technology may control an authorised recovery mechanism in the limited circumstances permitted by the Directions.

It cannot become a surveillance mechanism.

This will be particularly important for fintechs, device-financing platforms, OEM partnerships and technology vendors.


15. Recovery-Agent Conduct

When visiting a borrower or guarantor, the recovery agent must:

  • identify himself/herself;
  • display the appropriate identity card;
  • carry an authorisation letter;
  • carry the bank's relevant notice;
  • provide relevant agency/grievance contact details.

The agent must interact only with the borrower/guarantor as applicable and must behave with civility, decency and decorum.


16. Permitted Recovery Hours

The Directions prescribe a general contact/visit window of:

08:00 to 19:00

Contact outside these hours requires the borrower's express request or authorisation.

A borrower's request to avoid contact at a particular time should ordinarily be honoured.

This should be reflected directly in:

  • dialler systems;
  • field-agent applications;
  • call-centre controls;
  • escalation workflows; and
  • agency contracts.

A system that automatically permits calls outside the prescribed window creates an obvious compliance weakness.


17. Appropriate Contact Location and Sensitive Circumstances

The agent should ordinarily contact the borrower at the borrower's chosen location.

If no specific location is chosen, or the borrower fails to attend the selected location on two or more successive occasions, contact may ordinarily move to the borrower's residence or business/occupation location.

Agents must also avoid inappropriate circumstances such as:

  • bereavement;
  • medical emergencies;
  • other calamities; and
  • marriage functions.

This reinforces the RBI's broader shift toward proportionate and humane recovery practices.


18. What Constitutes "Harsh" Recovery?

The amendment gives a detailed list of prohibited practices.

These include:

  • threatening or abusive language;
  • publishing borrower information or recordings on social media;
  • inappropriate mobile/social-media messages;
  • excessive calling or messaging;
  • contacting outside permitted hours;
  • threatening or anonymous calls;
  • harassment or intimidation of borrowers, relatives, friends or co-workers;
  • threats of violence or damage to reputation/assets; and
  • false or misleading statements concerning the debt or consequences of non-payment.

Key observation

The prohibition extends beyond the borrower.

For example, intimidating the borrower's:

relatives, referees, friends or co-workers

can constitute prohibited conduct.

This materially limits the traditional practice of applying social pressure through third parties.


19. Grievance Redressal

Banks must establish a dedicated recovery-related grievance mechanism.

Its details must be:

  • included in the loan agreement;
  • provided when the recovery agency is communicated to the borrower; and
  • included in recovery-related communications.

The communication must contain the grievance officer's:

  • name;
  • email;
  • telephone number; and
  • address.

This is an important accountability mechanism because it gives the borrower a defined escalation channel instead of leaving complaints solely with the recovery agent.


20. Overall Regulatory Impact

In my assessment, the amendment creates five major compliance pillars:

PillarRegulatory direction
GovernanceBanks must establish structured recovery policies and oversight
AccountabilityBanks remain responsible for recovery agencies
Customer protectionRecovery must be proportionate, transparent and non-coercive
Technology governanceDevice-based recovery is tightly controlled
Evidence & monitoringCalls, agency activities and complaints must be documented

The overall direction is clearly toward controlled, auditable and borrower-sensitive recovery, rather than purely outcome-driven collection.


21. Key Risks for Banks

From a compliance and operational-risk perspective, I would classify the principal risks as follows:

High Risk

1. Recovery-agent misconduct

Because the bank is required to monitor recovery agencies, misconduct by an outsourced agent can become a bank-level compliance issue.

2. Technology-enabled recovery

The 30/60-day thresholds, essential-function restrictions, one-hour unlocking requirement and ₹250/hour compensation create significant technology and operational dependencies.

3. Data misuse

Accessing customer-device data for recovery purposes is expressly prohibited.

4. Uncontrolled calling

Call frequency, timing and content now require much stronger governance.

5. Inadequate agency oversight

Simply executing an outsourcing agreement will not be sufficient. The bank needs continuing monitoring and control.


22. Recommended Compliance Architecture

For implementation before 1 January 2027, I would recommend banks establish the following framework:

A. Policy

Review and amend the Board-approved recovery policy to incorporate:

  • escalation matrix;
  • distress-handling process;
  • agency eligibility;
  • due diligence;
  • agent verification;
  • training;
  • monitoring;
  • penalties;
  • compensation;
  • technology recovery controls.

B. Contracts

Review all recovery-agency agreements to incorporate:

  • RBI-mandated conduct;
  • audit rights;
  • data restrictions;
  • call-recording obligations;
  • agent certification;
  • reporting;
  • indemnification/compensation provisions;
  • termination rights;
  • regulatory cooperation requirements.

C. Technology

Implement system controls for:

  • calling hours;
  • call recording;
  • call-frequency monitoring;
  • DPD-based restrictions;
  • 30/60-day thresholds;
  • essential-function exclusions;
  • payment-triggered unlocking;
  • one-hour SLA;
  • compensation calculation;
  • audit logs.

D. Agent Management

Maintain a centralised database covering:

  • identity;
  • certification;
  • antecedent verification;
  • agency;
  • territory;
  • authorisation;
  • training;
  • complaints;
  • disciplinary history.

E. Customer Communication

Standardise:

  • agency-intimation letters;
  • pre-visit notices;
  • authorisation letters;
  • recovery messages;
  • grievance disclosures;
  • possession notices;
  • technology restriction notices.

23. Recommended Management Dashboard

For senior management/Board oversight, I would suggest monitoring at least:

  • number of active recovery agencies;
  • number of active recovery agents;
  • percentage of agents with valid certification;
  • overdue due-diligence/re-verification cases;
  • complaints against agencies;
  • complaints substantiated;
  • prohibited-conduct incidents;
  • calls outside permitted hours;
  • excessive-call alerts;
  • field-visit exceptions;
  • data/privacy incidents;
  • device restrictions initiated;
  • wrongful device restrictions;
  • average unlocking time;
  • compensation paid;
  • agency penalties/terminations; and
  • unresolved recovery-related grievances.

This would convert the RBI requirements into measurable management controls.


24. Most Important Takeaways

If I had to reduce the entire 11-page amendment to 10 management-level conclusions, they would be:

  1. The amendment becomes effective on 1 January 2027.
  2. Banks remain accountable for recovery agencies they engage.
  3. The regulatory definition of recovery agency is deliberately broad.
  4. Recovery agents must undergo prescribed IIBF-related training/certification.
  5. Borrowers must receive greater transparency before agency-led field recovery.
  6. Recovery calls and related records require systematic documentation and retention.
  7. Recovery incentives must not encourage harsh practices.
  8. Recovery contact is generally restricted to 08:00–19:00.
  9. Technology-based device locking is permitted only in a tightly controlled device-financing context.
  10. Harassment, intimidation, public humiliation, misuse of personal data and misleading representations are expressly prohibited.

Overall conclusion

This amendment should be viewed not merely as a revision of recovery-agent guidelines, but as a comprehensive recovery-governance framework.

The most significant change is the shift in regulatory emphasis from simply controlling the conduct of individual recovery agents to controlling the entire recovery ecosystem — including the bank's policy, outsourcing arrangements, incentives, technology, data practices, communications, field operations, monitoring, grievance mechanisms and accountability.

For a bank, the key compliance question going forward should therefore not be:

"Are our recovery agents following the rules?"

but rather:

"Can we demonstrate that our entire recovery process is designed, monitored and controlled so that regulatory-compliant behaviour is the default outcome?"

That is, in my view, the central message of these Directions.

Note: The above analysis is based primarily on the uploaded RBI Directions. It is an interpretive/compliance analysis and should not be treated as a formal legal opinion. The RBI's broader regulatory framework also contains related requirements, including its outsourcing and grievance-redressal frameworks, which should be mapped separately when implementing the amendment.

Saturday, 22 August 2026

Body Language


Julius Fast’s Body Language is one of those books that manages to make an apparently ordinary aspect of everyday life suddenly seem much more intriguing. We spend our lives watching people—friends, strangers, colleagues, lovers, politicians, salesmen—yet rarely stop to consider how much information is being conveyed without a single word being spoken. Fast’s book invites us to look again: at a raised eyebrow, a folded arm, a nervous gesture, a prolonged glance, a change in posture or the subtle distance someone maintains while speaking to us.

First published in 1970, Body Language belongs to an earlier generation of popular psychology, when the systematic study of non-verbal communication was still relatively new to the general reader. Fast’s great achievement was to take ideas that could easily have remained within the territory of psychologists and researchers and turn them into something entertaining, understandable and relevant to ordinary social life. He presents body language not as an obscure academic discipline but as a kind of silent vocabulary that all of us use, often without knowing it.

One of the book’s most appealing features is its emphasis on the fact that communication extends far beyond spoken language. Words can be carefully selected, rehearsed and even deliberately deceptive; physical behaviour is often less controlled. A person may say that everything is perfectly fine while their posture, facial expression or restless movements suggest otherwise. Fast is interested in precisely these contradictions between what people say and what their bodies appear to be saying.

The book moves through a wide range of familiar human behaviours. Gestures, facial expressions, eye contact, posture, touching, physical proximity and movement are all examined as possible clues to a person's emotional state and intentions. Fast encourages the reader to become more attentive to these small details. A person leaning forward may suggest interest; someone turning away may signal discomfort or disengagement; crossed arms might indicate defensiveness—or simply that the room is cold. This last distinction is important, because one of the book’s enduring lessons is that body language cannot sensibly be interpreted in isolation.

Fast is particularly interested in the social and cultural dimensions of physical behaviour. A gesture that seems perfectly natural in one culture may carry an entirely different meaning in another. Personal space, eye contact, touching and expressions of respect or submission can vary considerably according to social conventions. This makes the subject more complicated—and more interesting—than the simplistic idea that every gesture has one fixed meaning.

There is also an enjoyable element of detective work in Fast’s approach. Reading body language becomes almost like learning to read a second language, except that its vocabulary is constantly changing according to context. The book encourages us to observe patterns rather than relying on one isolated movement. A single gesture may mean very little, but several consistent signals occurring together can provide a more revealing picture.

At the same time, Body Language should be approached with a degree of caution. Some of Fast’s interpretations reflect the popular psychological thinking of his era, and contemporary readers may find certain conclusions too categorical. Modern research into non-verbal communication has demonstrated just how difficult it can be to assign a universal meaning to a particular gesture. Cross-cultural differences, individual personality, circumstances and context all matter enormously. The familiar idea that crossed arms necessarily mean defensiveness, for example, is far too simplistic.

This does not, however, diminish the book’s value as a work of popular psychology. In fact, its limitations make it particularly interesting when read today. It can be regarded less as a definitive scientific manual and more as an engaging introduction to the subject—one that encourages curiosity and observation. Fast’s real contribution is to make the reader aware that human beings are communicating constantly, even when they are completely silent.

Another strength is the book’s readability. Fast avoids drowning the reader in technical terminology and instead relies on accessible explanations and recognizable situations. His writing has the quality of a conversation: he wants the reader to look around and test these ideas against everyday experience. That makes Body Language especially suitable for readers who are interested in psychology but do not necessarily want a heavily academic treatment of the subject.

There is also something slightly unsettling about the book. Once we begin thinking about body language, ordinary social encounters can never quite look the same again. A conversation becomes a mixture of words, pauses, expressions, gestures and physical positioning. We begin noticing who maintains eye contact, who constantly fidgets, who leans towards another person, who retreats, who mirrors another’s movements and who appears relaxed despite saying something uncomfortable. The book thus changes not only how we interpret others but also how conscious we become of our own behaviour.

Perhaps the most valuable lesson to emerge from Body Language is that observation should be accompanied by humility. The temptation is to turn body language into a secret code that allows us to “read” people's minds. Fast’s subject can easily encourage that kind of overconfidence. But human behaviour is too complicated for such certainty. A gesture is a clue, not a verdict. The intelligent reader learns to consider several signals, the surrounding circumstances and the individual involved before drawing conclusions.

Seen from the perspective of the present day, Body Language is therefore both a product of its time and a book that retains considerable charm. Its scientific assumptions may occasionally require qualification, but its central proposition remains compelling: communication is happening all the time, and much of it occurs below the level of conscious speech.

Ultimately, Julius Fast’s Body Language is best appreciated as a pioneering work of popular psychology that helped introduce generations of readers to the fascinating world of non-verbal communication. It is observant, accessible, entertaining and occasionally provocative. More than simply teaching us how to interpret gestures, it encourages us to become better observers of human beings.

And perhaps that is the book’s greatest achievement. After reading it, we become slightly more conscious of the silent conversations taking place around us—and slightly more aware that our own bodies are speaking even when we believe we are saying nothing at all.

An engaging and pioneering introduction to non-verbal communication. Some interpretations have inevitably aged, but the book remains a fascinating, highly readable exploration of the silent language of human behaviour.


Digitisation of FPI Onboarding

  The recent SEBI Circular dated 20 August 2026 permitting the submission of a digitally signed Power of Attorney (PoA) as part of the reg...