1. Executive Summary
The RBI (NBFCs – Compliance Function) Directions, 2026 represent a significant strengthening of the compliance governance framework applicable to NBFCs in the Middle and Upper Layers. The framework moves beyond a conventional compliance-monitoring model and establishes the Compliance Function as an independent, adequately resourced and institution-wide governance function with direct access to senior management, the Board/Audit Committee of the Board and RBI.
The Directions adopt a proportionality-based approach, requiring NBFCs to structure their compliance framework according to their governance arrangements, scale of operations, risk profile and organisational structure.
A particularly important feature is the enhanced status accorded to the Chief Compliance Officer (CCO). The CCO is required to have appropriate seniority, independence, tenure, access to information and direct reporting arrangements, while restrictions have been imposed on "dual hatting" and reporting relationships with business verticals.
The Directions also introduce a stronger emphasis on technology-enabled compliance monitoring, requiring comprehensive, integrated, enterprise-wide and workflow-based compliance solutions with escalation mechanisms and a unified management dashboard.
2. Applicability and Regulatory Scope
The Directions apply to NBFCs in the Middle Layer and Upper Layer registered under the RBI Act, 1934 or the Factoring Regulation Act, 2011, unless otherwise specified. They are aligned with the regulatory structure prescribed under RBI's Scale Based Regulation framework.
This is important because the regulatory expectation is not merely that an NBFC should have a compliance officer or maintain a compliance calendar. The Directions contemplate an enterprise-wide compliance architecture covering statutory, regulatory, conduct and supervisory requirements.
The definition of Compliance Risk is also broad, encompassing the risk of regulatory sanctions, material financial loss and reputational loss resulting from failure to comply with applicable laws, regulations, rules and codes of conduct.
3. Board and Audit Committee Responsibilities
The Board/ACB assumes a central governance role.
It must ensure that an appropriate Compliance Policy is established and implemented and must prescribe the periodicity for reviewing compliance risk.
The framework therefore places compliance squarely within the Board's governance responsibilities rather than treating it as merely an operational or administrative function.
Annual compliance risk assessment
Senior management must conduct an annual compliance risk assessment identifying and evaluating significant compliance risks and preparing a plan to manage them.
The annual review must cover, among other matters:
- compliance failures during the preceding year;
- consequential losses and regulatory action;
- remedial and disciplinary measures;
- major regulatory guidelines issued during the year;
- compliance with fair-practice codes;
- standards prescribed by self-regulatory bodies;
- accounting standards; and
- rectification of significant deficiencies identified through audits and RBI inspections.
Implication: The Board/ACB should expect compliance reporting to become considerably more analytical. A simple statement that "all compliances have been completed" would not adequately demonstrate the nature of oversight contemplated by these Directions.
4. Board-Approved Compliance Policy
The Compliance Policy must be comprehensive and clearly articulate:
- the NBFC's compliance philosophy;
- expectations regarding compliance culture;
- the structure and role of the Compliance Function;
- the role of the CCO;
- processes for identifying, assessing, monitoring, managing and reporting compliance risk.
The policy must be reviewed at least annually.
It must additionally address independence of the Compliance Function, regulatory monitoring, compliance testing, reporting to senior management and the Board/ACB, access to information, dissemination of regulatory changes and compliance approval of new processes and products.
Professional observation
This effectively requires an NBFC to treat its Compliance Policy as a living governance document, rather than a static policy prepared merely for regulatory purposes.
5. Independence of the Compliance Function
One of the strongest themes running through the Directions is independence.
The Compliance Function must be:
- independent;
- sufficiently resourced;
- clearly defined in terms of responsibilities; and
- subject to periodic independent review.
Even where separate departments are responsible for individual statutory or regulatory areas, those departments retain responsibility for their respective areas, while the Compliance Function provides overall oversight.
This creates a useful distinction between:
Primary compliance responsibility → respective business/functional departments
and
Overall compliance oversight → Compliance Function.
Accordingly, compliance cannot be outsourced entirely to the Compliance Department; every employee retains responsibility for complying with applicable requirements.
6. Staffing and Competence
The Directions require the Compliance Function to have personnel possessing knowledge across multiple disciplines, including:
- statutory and regulatory requirements;
- law;
- accountancy;
- risk management;
- information technology; and
- business-line/audit experience.
The NBFC is also required to provide appropriate succession planning so that future skill gaps do not undermine the compliance framework.
This is significant because the regulatory expectation is shifting from a compliance function based predominantly on legal/regulatory knowledge to a multidisciplinary risk-oriented compliance capability.
7. Expanded Responsibilities of the Compliance Function
The Directions assign extensive responsibilities to Compliance.
The Compliance Function must, at a minimum:
- assist the Board and senior management in implementing the Compliance Policy;
- identify and assess compliance risk;
- analyse compliance risks associated with existing and new products/processes;
- monitor new products intensively for at least the first six months;
- undertake representative compliance testing;
- report compliance failures;
- ensure timely implementation of RBI supervisory directions;
- monitor Risk Mitigation Plans/Monitorable Action Plans;
- coordinate communication of RBI inspection compliance; and
- oversee regulatory requirements arising from other regulators.
The requirement concerning new products is particularly noteworthy. Compliance is expected to participate before launch and then continue intensive monitoring for at least six months.
This establishes a preventive compliance model, rather than a purely detective one.
8. Compliance Testing
The Compliance Function must conduct sufficient and representative compliance testing, with results reported to senior management.
Compliance failures must also be circulated among staff together with preventive instructions, and staff accountability for major compliance failures must be examined.
This creates three distinct layers:
Identification → Testing → Corrective/Preventive Action
An effective NBFC compliance framework should therefore maintain documented evidence of:
- testing undertaken;
- sample selection;
- exceptions identified;
- root-cause analysis;
- responsible personnel;
- corrective action;
- timelines; and
- closure validation.
9. Internal Audit Interface
Compliance risk must form part of the Internal Audit risk assessment framework, while the Compliance Function itself must be subject to regular internal audit.
The CCO must be informed of audit findings concerning compliance.
This creates an important feedback loop:
Compliance monitoring → Internal Audit → Audit findings → CCO → Compliance risk assessment → Corrective action
The Compliance Function therefore cannot operate in isolation from Internal Audit and enterprise risk management.
10. Chief Compliance Officer – Major Governance Changes
The CCO provisions are among the most consequential elements of the Directions.
Appointment
The CCO must be selected through a defined process based on recommendations of a committee constituted by the Board/ACB, with the final appointment decision resting with the Board/ACB. External recruitment is expressly permitted.
The CCO must possess:
- a clean track record;
- unquestionable integrity;
- industry understanding;
- knowledge of risk management;
- knowledge of regulations and legal requirements; and
- sensitivity to supervisory expectations.
Tenure
The CCO must ordinarily have a minimum fixed tenure of three years.
The Board/ACB may relax this by one year in exceptional circumstances, subject to appropriate succession planning.
Premature transfer or removal is permitted only in exceptional circumstances with the explicit prior approval of the Board/ACB and after a defined and transparent internal process.
This is a significant safeguard against the possibility that compliance independence could be compromised through arbitrary changes in the CCO's position.
11. CCO Seniority and Reporting
The CCO must be a senior executive positioned not below two levels from the CEO. For Middle Layer NBFCs, this requirement may be relaxed by one additional level.
The CCO must have direct reporting lines to:
- the MD & CEO; and/or
- the Board/ACB.
Where the CCO reports to the MD & CEO, the Board/ACB must meet the CCO quarterly on a one-to-one basis, without senior management, including the MD & CEO.
The Board/ACB must also review the CCO's performance appraisal.
This is a strong governance mechanism intended to preserve the CCO's ability to communicate concerns directly to the Board.
12. Prohibition on "Dual Hatting"
The Directions expressly prohibit dual hatting where the CCO has responsibilities creating conflicts of interest, particularly responsibilities relating to business.
The CCO should generally not be a member of committees dealing with matters such as purchases or sanctions where this could conflict with the CCO's compliance role. If the CCO participates, the role is restricted to an advisory capacity.
This provision is particularly relevant for NBFCs where the compliance function has historically been combined with legal, risk, secretarial or business responsibilities.
Existing organisational structures may therefore need to be reassessed.
13. Direct Access to RBI and Regulators
The CCO is required to have the ability to exercise independent judgment and communicate directly with regulators and supervisors.
The CCO is also the nodal point of contact between the NBFC and regulators/supervisors and must participate in structured or regular discussions with RBI.
Further, RBI must receive prior intimation before appointment, premature transfer, resignation, early retirement, removal or other changes concerning the CCO's tenure. Appointment information must include the candidate's profile and a Fit and Proper certification by the MD & CEO.
14. New Product Governance
The CCO must be a member of the new product committee(s).
If no such committee exists, the CCO must evaluate all new products before launch.
This effectively embeds compliance into the product approval lifecycle.
NBFCs should therefore consider establishing a formal New Product Approval Process, incorporating:
Business proposal → Risk assessment → Compliance assessment → Legal review → Technology assessment → Management approval → Launch → Six-month enhanced monitoring.
15. Technology-Enabled Compliance
The Directions require NBFCs to implement comprehensive, integrated, enterprise-wide and workflow-based compliance solutions.
The technology framework should provide for:
- stakeholder communication and collaboration;
- identification and assessment of compliance requirements;
- compliance monitoring and management;
- escalation of non-compliance;
- recording of approvals for deviations/delays; and
- a unified dashboard for senior management.
This is an important development because it suggests a move away from spreadsheet-driven and manually maintained compliance systems towards technology-enabled compliance management.
16. Repeal and Transitional Considerations
The Directions repeal the existing Directions, instructions and guidelines relating to the Compliance Function applicable to NBFCs.
However, actions already taken or initiated under the repealed framework continue to be governed by the earlier provisions. Existing rights, liabilities, penalties, investigations and proceedings are similarly preserved.
The new Directions are also in addition to other applicable laws, rules, regulations and directions, and do not derogate from them.
17. Key Compliance Implications for an NBFC
An NBFC covered by these Directions should undertake a structured gap assessment immediately.
| Area | Key Requirement | Recommended Action |
|---|---|---|
| Compliance Policy | Board-approved and annually reviewed | Review/revise policy |
| Compliance Risk | Annual assessment | Establish documented risk assessment |
| Board Oversight | Periodic compliance review | Strengthen Board/ACB reporting |
| CCO | Fixed minimum tenure | Review appointment terms |
| CCO Independence | Direct access/reporting | Review reporting structure |
| Dual Hatting | Conflicts prohibited | Review CCO responsibilities |
| Compliance Testing | Representative testing | Establish formal testing programme |
| New Products | CCO evaluation + six-month monitoring | Formalise NPA framework |
| RBI Directions | Time-bound implementation | Establish regulatory action tracker |
| Audit | Compliance risk in Internal Audit | Align Audit Plan |
| Technology | Integrated workflow-based system | Assess compliance technology |
| Training | Regulatory dissemination | Establish structured training programme |
| Succession | Avoid skill gaps | Develop compliance succession plan |
18. Recommended Immediate Action Plan
I would recommend that an NBFC undertake the following in six stages:
Stage 1 – Regulatory Gap Assessment
Map each requirement of the 2026 Directions against the existing compliance framework and identify gaps.
Stage 2 – CCO Assessment
Review:
- designation and seniority;
- reporting structure;
- tenure;
- independence;
- dual-hatting;
- Board/ACB access;
- regulatory interaction rights; and
- performance appraisal mechanism.
Stage 3 – Policy Review
Revise the Board-approved Compliance Policy to specifically address all requirements under paragraphs 8 and 9 of the Directions.
Stage 4 – Compliance Operating Model
Document:
- compliance ownership;
- Compliance Function oversight;
- testing methodology;
- regulatory change management;
- escalation mechanisms;
- exception management;
- new-product compliance assessment; and
- RBI inspection/action-plan monitoring.
Stage 5 – Board Governance
Introduce a structured Board/ACB Compliance Dashboard covering:
- compliance status;
- overdue compliances;
- material exceptions;
- compliance risk profile;
- regulatory changes;
- RBI inspection observations;
- corrective actions;
- new product compliance reviews; and
- significant compliance incidents.
Stage 6 – Technology Assessment
Evaluate whether the existing compliance-management system can provide the enterprise-wide workflow, escalation, deviation approval and dashboard capabilities required by the Directions.
19. Overall Professional Assessment
The 2026 Directions represent a material elevation of the compliance function within the governance architecture of covered NBFCs.
The central regulatory message is that compliance is no longer to be viewed as a periodic checklist or post-facto control mechanism. Instead, RBI expects compliance to operate as an independent, adequately resourced, risk-sensitive and technology-enabled function that is embedded into the organisation's decision-making processes.
The most significant areas requiring management attention are likely to be:
- independence and stature of the CCO;
- elimination of conflicts and dual-hatting;
- Board/ACB oversight;
- annual compliance-risk assessment;
- documented compliance testing;
- integration of compliance into new-product approval;
- monitoring of RBI supervisory observations and action plans;
- integration with Internal Audit and risk management; and
- implementation of an enterprise-wide technology-enabled compliance system.
For a covered NBFC, the appropriate response should therefore be a formal implementation and gap-remediation programme, rather than merely updating the Compliance Policy.
In conclusion, the Directions materially strengthen the three lines of defence by giving the Compliance Function greater independence, authority and Board access while simultaneously increasing the accountability of senior management and business functions for compliance. Their successful implementation will require corresponding changes not only to policies and procedures, but also to organisational structure, governance practices, reporting mechanisms, product-approval processes, employee accountability and technology infrastructure.
