1. Executive Summary
The Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Fourth Amendment Directions, 2026, issued on 6 August 2026, represent a significant strengthening and consolidation of the regulatory framework governing loan recovery, recovery agencies and recovery agents. The provisions come into force from 1 January 2027.
The principal regulatory shift is that the RBI is moving from relatively broad principles concerning recovery agents toward a much more prescriptive governance framework covering:
-
appointment and due diligence of recovery agencies;
-
training and certification of recovery agents;
-
borrower notification;
-
monitoring and recording of recovery communications;
-
field-visit protocols;
-
permissible recovery hours;
-
privacy and customer-data protection;
-
possession and sale of secured assets;
-
technology-enabled recovery mechanisms;
-
prohibited recovery practices;
-
compensation for certain wrongful actions; and
-
dedicated grievance-redressal mechanisms.
Importantly, the Directions make it clear that outsourcing recovery does not outsource regulatory responsibility. The bank remains responsible for establishing controls, monitoring recovery agencies and ensuring that their conduct does not expose the bank to regulatory, legal or reputational risk. This is consistent with the RBI's longstanding approach to recovery-agent supervision.
The RBI's official website also identifies the August 2026 measure as an amendment concerning the conduct of regulated entities in recovery of loans and engagement of recovery agents.
2. Scope and Applicability
The Directions apply to commercial banks other than:
-
Small Finance Banks;
-
Payments Banks;
-
Regional Rural Banks; and
-
Local Area Banks.
The provisions apply to recovery of loan dues from borrowers in default, including taking possession of security. Certain provisions may also apply to normal collection from borrowers who are not in default where the Directions expressly provide for such application.
Important definitional change
The amendment introduces two important concepts:
Recovery agency means an entity or individual, other than the bank's own employees, engaged under an outsourcing arrangement to assist in recovery of loan dues, including taking possession of security.
Recovery agent means the representative of a recovery agency who interacts directly with the customer.
The definition is deliberately broad and is based on the substance of the arrangement rather than its contractual label. A Business Correspondent involved in recovery activities, for example, will be treated as a recovery agency for these purposes.
Professional interpretation
This is important from a compliance perspective because banks cannot necessarily avoid the recovery-agency framework simply by calling an arrangement something else.
The RBI is effectively saying:
If the third party performs recovery functions, the regulatory requirements follow the activity, not merely the contractual nomenclature.
3. Governance and Recovery Policy
A bank is required to establish a formal policy covering collection and recovery of loan dues, including possession of security.
The policy must address, among other matters:
-
triggers for initiating recovery;
-
graded recovery actions;
-
escalation matrices;
-
code of conduct;
-
recovery following the death of a borrower;
-
handling of financially distressed borrowers;
-
documented pre-escalation engagement; and
-
available resolution options.
For recovery agencies, the policy must additionally cover:
-
eligibility;
-
due diligence;
-
performance evaluation;
-
inspection and audit;
-
compliance controls;
-
procedures for dealing with non-compliant agencies;
-
penalties/sanctions for non-compliance; and
-
borrower compensation for losses arising from recovery actions inconsistent with the Directions.
Compliance significance
This is more than a requirement to have a document titled "Recovery Policy."
The wording indicates an expectation for a structured recovery governance framework, where the bank can demonstrate:
Default → Assessment → Pre-escalation engagement → Resolution opportunity → Escalation → Agency assignment → Monitoring → Closure
Accordingly, banks should be able to demonstrate that recovery decisions are systematic, documented and proportionate, rather than purely target-driven.
4. Engagement of Recovery Agencies
4.1 Due diligence
Banks must establish a due-diligence process for recovery agencies consistent with RBI outsourcing requirements.
Importantly, verification is required not only at the agency level but also in relation to the antecedents of individual recovery agents, both before engagement and periodically thereafter in accordance with the bank's policy.
Practical implication
A bank should therefore maintain an auditable file containing, at minimum:
-
agency due-diligence records;
-
ownership/management information;
-
contractual documentation;
-
agent identity records;
-
antecedent verification;
-
periodic re-verification;
-
training/certification status;
-
performance records; and
-
complaints and disciplinary history.
5. Mandatory Training and IIBF Certification
The bank must ensure that a recovery agency deploys only agents who have obtained the relevant certificate from the Indian Institute of Banking and Finance (IIBF) after completing the prescribed Debt Recovery Agents training programme, or training through an institute having a tie-up arrangement with IIBF.
This makes agent competency a formal compliance requirement, rather than merely a recommended internal control.
A bank should therefore have a mechanism to prevent an uncertified or expired/unverified agent from being deployed.
6. Disclosure and Transparency
One of the stronger provisions concerns transparency regarding recovery agencies.
Banks must publish an up-to-date list of recovery agencies on their websites, including details such as:
-
name;
-
type of agency — corporate or individual;
-
correspondence address;
-
period of engagement; and
-
purpose of engagement, including recovery or possession of security.
The list must be updated within seven calendar days of modification, while termination must be reflected promptly.
Borrower-specific notification
Before a recovery agency makes an in-person visit to the borrower/guarantor, the bank must provide the recovery-agency details at least one day before the first visit.
If the agency changes during the recovery process, the borrower/guarantor must be notified immediately. The same applies where an agency's engagement is terminated.
Significance
This substantially reduces the scope for an individual appearing at a borrower's premises without a verifiable connection to the bank.
It also creates an important evidentiary trail:
Bank assignment → borrower notification → authorised agent → identification → field visit
7. Customer Information and Privacy
The bank must restrict disclosure of borrower/guarantor information to employees and recovery agencies to what is necessary for recovery-related duties.
Banks must also implement safeguards, including penal provisions, against misuse of customer information.
This is a significant compliance principle:
Recovery access ≠ unrestricted customer-data access.
The agency should receive only information necessary to perform its authorised function.
This is particularly relevant for technology platforms, call centres, field-recovery applications and third-party recovery vendors.
8. Recording of Recovery Communications
Banks must document:
-
the time of calls;
-
the number of calls; and
-
the content/text of calls made by recovery personnel to borrowers/guarantors.
Calls made by the borrower/guarantor to the telephone/mobile number communicated by the bank must also be recorded.
These records generally need to be retained for six months, or, where the matter is sub judice, until disposal of the matter. The bank must also take reasonable precautions such as informing the borrower that the conversation is being recorded.
Practical consequence
A recovery call is no longer simply an operational interaction. It becomes a potentially important compliance record and evidentiary record.
Banks should therefore consider controls around:
-
call recording;
-
call metadata;
-
retention;
-
retrieval;
-
access controls;
-
audit trails; and
-
complaint/investigation processes.
9. Recovery Targets and Incentive Structures
The RBI specifically requires banks to ensure that recovery targets or incentive structures for employees and recovery agencies do not encourage harsh recovery practices.
This is a particularly important management-level requirement.
The issue is not merely whether an agent violates the Code of Conduct.
The design of the incentive system itself must not create an incentive to violate it.
For example, a recovery model excessively focused on:
"Amount collected per agent per day"
could create conduct risk if it encourages aggressive calling, repeated visits or intimidation.
Banks should therefore consider incorporating conduct/compliance indicators into agency and employee performance evaluation.
10. Taking Possession of Security
Where a bank relies on a contractual possession clause, the clause must be legally valid and clearly brought to the borrower's attention at the time of execution.
The loan agreement must address:
-
notice period before possession;
-
circumstances where the notice period may be waived;
-
possession procedure;
-
final repayment opportunity before sale/auction;
-
procedure for returning possession; and
-
sale/auction procedure.
Significance
The RBI is effectively requiring procedural transparency around repossession.
A possession right should therefore not operate as an opaque contractual power. The borrower should understand when and how the bank can exercise it.
11. Technology-Based Recovery — Major New Compliance Area
This is arguably one of the most significant aspects of the amendment.
Banks generally cannot use technology to restrict or disable functions of a borrower's mobile phone, tablet or laptop as a recovery mechanism.
There is a narrow exception where:
-
the particular device itself was financed by the bank;
-
the loan agreement expressly and unambiguously permits device restrictions;
-
prescribed notice requirements are followed; and
-
the other conditions under the Directions are satisfied.
11.1 30-day and 60-day thresholds
Restrictions cannot begin merely because a borrower has missed a payment.
The device cannot be subjected to the technology-based restriction mechanism until the associated loan has become 30 days past due, and the borrower has failed to pay despite notice.
Thereafter:
-
gradual restrictions may begin after 30 days past due;
-
the full set of contractual restrictions can take effect only after 60 days past due;
-
outgoing calls cannot be restricted before 60 days past due.
This establishes a clear regulatory distinction between:
default → notice → 30 DPD → gradual restrictions → 60 DPD → full contractual restrictions
12. Essential Device Functions
Even where device restrictions are permitted, the bank cannot disable essential functionality such as:
-
incoming calls;
-
SMS; and
-
emergency SOS features.
The restrictions must also not prevent the borrower from carrying out activities related to work or employment.
Compliance implication
A technology solution cannot simply be designed around:
"Borrower defaults → phone gets locked."
The system must incorporate regulatory rules and exceptions into its technical architecture.
13. One-Hour Unlocking Requirement and Compensation
Once dues are realised, restrictions must be reversed expeditiously and no later than one hour after realisation.
Where wrongful restriction or delayed reversal is attributable to the bank, compensation is payable at:
₹250 per hour
subject to a maximum equal to the amount of the loan disbursed.
This creates a direct financial consequence for technology or operational failures.
Banks therefore need appropriate real-time payment-to-unlock integration and monitoring.
14. Personal Data on the Device
This provision is exceptionally important.
A bank and its technology service provider must not access or use personal data on the device for recovery or any other purpose.
The provision expressly identifies data such as:
-
contacts;
-
SMS;
-
call logs;
-
photographs;
-
location history; and
-
other personal data.
Regulatory principle
The technology may control an authorised recovery mechanism in the limited circumstances permitted by the Directions.
It cannot become a surveillance mechanism.
This will be particularly important for fintechs, device-financing platforms, OEM partnerships and technology vendors.
15. Recovery-Agent Conduct
When visiting a borrower or guarantor, the recovery agent must:
-
identify himself/herself;
-
display the appropriate identity card;
-
carry an authorisation letter;
-
carry the bank's relevant notice;
-
provide relevant agency/grievance contact details.
The agent must interact only with the borrower/guarantor as applicable and must behave with civility, decency and decorum.
16. Permitted Recovery Hours
The Directions prescribe a general contact/visit window of:
08:00 to 19:00
Contact outside these hours requires the borrower's express request or authorisation.
A borrower's request to avoid contact at a particular time should ordinarily be honoured.
This should be reflected directly in:
-
dialler systems;
-
field-agent applications;
-
call-centre controls;
-
escalation workflows; and
-
agency contracts.
A system that automatically permits calls outside the prescribed window creates an obvious compliance weakness.
17. Appropriate Contact Location and Sensitive Circumstances
The agent should ordinarily contact the borrower at the borrower's chosen location.
If no specific location is chosen, or the borrower fails to attend the selected location on two or more successive occasions, contact may ordinarily move to the borrower's residence or business/occupation location.
Agents must also avoid inappropriate circumstances such as:
-
bereavement;
-
medical emergencies;
-
other calamities; and
-
marriage functions.
This reinforces the RBI's broader shift toward proportionate and humane recovery practices.
18. What Constitutes "Harsh" Recovery?
The amendment gives a detailed list of prohibited practices.
These include:
-
threatening or abusive language;
-
publishing borrower information or recordings on social media;
-
inappropriate mobile/social-media messages;
-
excessive calling or messaging;
-
contacting outside permitted hours;
-
threatening or anonymous calls;
-
harassment or intimidation of borrowers, relatives, friends or co-workers;
-
threats of violence or damage to reputation/assets; and
-
false or misleading statements concerning the debt or consequences of non-payment.
Key observation
The prohibition extends beyond the borrower.
For example, intimidating the borrower's:
relatives, referees, friends or co-workers
can constitute prohibited conduct.
This materially limits the traditional practice of applying social pressure through third parties.
19. Grievance Redressal
Banks must establish a dedicated recovery-related grievance mechanism.
Its details must be:
-
included in the loan agreement;
-
provided when the recovery agency is communicated to the borrower; and
-
included in recovery-related communications.
The communication must contain the grievance officer's:
-
name;
-
email;
-
telephone number; and
-
address.
This is an important accountability mechanism because it gives the borrower a defined escalation channel instead of leaving complaints solely with the recovery agent.
20. Overall Regulatory Impact
In my assessment, the amendment creates five major compliance pillars:
| Pillar | Regulatory direction |
|---|
| Governance | Banks must establish structured recovery policies and oversight |
| Accountability | Banks remain responsible for recovery agencies |
| Customer protection | Recovery must be proportionate, transparent and non-coercive |
| Technology governance | Device-based recovery is tightly controlled |
| Evidence & monitoring | Calls, agency activities and complaints must be documented |
The overall direction is clearly toward controlled, auditable and borrower-sensitive recovery, rather than purely outcome-driven collection.
21. Key Risks for Banks
From a compliance and operational-risk perspective, I would classify the principal risks as follows:
High Risk
1. Recovery-agent misconduct
Because the bank is required to monitor recovery agencies, misconduct by an outsourced agent can become a bank-level compliance issue.
2. Technology-enabled recovery
The 30/60-day thresholds, essential-function restrictions, one-hour unlocking requirement and ₹250/hour compensation create significant technology and operational dependencies.
3. Data misuse
Accessing customer-device data for recovery purposes is expressly prohibited.
4. Uncontrolled calling
Call frequency, timing and content now require much stronger governance.
5. Inadequate agency oversight
Simply executing an outsourcing agreement will not be sufficient. The bank needs continuing monitoring and control.
22. Recommended Compliance Architecture
For implementation before 1 January 2027, I would recommend banks establish the following framework:
A. Policy
Review and amend the Board-approved recovery policy to incorporate:
-
escalation matrix;
-
distress-handling process;
-
agency eligibility;
-
due diligence;
-
agent verification;
-
training;
-
monitoring;
-
penalties;
-
compensation;
-
technology recovery controls.
B. Contracts
Review all recovery-agency agreements to incorporate:
-
RBI-mandated conduct;
-
audit rights;
-
data restrictions;
-
call-recording obligations;
-
agent certification;
-
reporting;
-
indemnification/compensation provisions;
-
termination rights;
-
regulatory cooperation requirements.
C. Technology
Implement system controls for:
-
calling hours;
-
call recording;
-
call-frequency monitoring;
-
DPD-based restrictions;
-
30/60-day thresholds;
-
essential-function exclusions;
-
payment-triggered unlocking;
-
one-hour SLA;
-
compensation calculation;
-
audit logs.
D. Agent Management
Maintain a centralised database covering:
-
identity;
-
certification;
-
antecedent verification;
-
agency;
-
territory;
-
authorisation;
-
training;
-
complaints;
-
disciplinary history.
E. Customer Communication
Standardise:
-
agency-intimation letters;
-
pre-visit notices;
-
authorisation letters;
-
recovery messages;
-
grievance disclosures;
-
possession notices;
-
technology restriction notices.
23. Recommended Management Dashboard
For senior management/Board oversight, I would suggest monitoring at least:
-
number of active recovery agencies;
-
number of active recovery agents;
-
percentage of agents with valid certification;
-
overdue due-diligence/re-verification cases;
-
complaints against agencies;
-
complaints substantiated;
-
prohibited-conduct incidents;
-
calls outside permitted hours;
-
excessive-call alerts;
-
field-visit exceptions;
-
data/privacy incidents;
-
device restrictions initiated;
-
wrongful device restrictions;
-
average unlocking time;
-
compensation paid;
-
agency penalties/terminations; and
-
unresolved recovery-related grievances.
This would convert the RBI requirements into measurable management controls.
24. Most Important Takeaways
If I had to reduce the entire 11-page amendment to 10 management-level conclusions, they would be:
-
The amendment becomes effective on 1 January 2027.
-
Banks remain accountable for recovery agencies they engage.
-
The regulatory definition of recovery agency is deliberately broad.
-
Recovery agents must undergo prescribed IIBF-related training/certification.
-
Borrowers must receive greater transparency before agency-led field recovery.
-
Recovery calls and related records require systematic documentation and retention.
-
Recovery incentives must not encourage harsh practices.
-
Recovery contact is generally restricted to 08:00–19:00.
-
Technology-based device locking is permitted only in a tightly controlled device-financing context.
-
Harassment, intimidation, public humiliation, misuse of personal data and misleading representations are expressly prohibited.
Overall conclusion
This amendment should be viewed not merely as a revision of recovery-agent guidelines, but as a comprehensive recovery-governance framework.
The most significant change is the shift in regulatory emphasis from simply controlling the conduct of individual recovery agents to controlling the entire recovery ecosystem — including the bank's policy, outsourcing arrangements, incentives, technology, data practices, communications, field operations, monitoring, grievance mechanisms and accountability.
For a bank, the key compliance question going forward should therefore not be:
"Are our recovery agents following the rules?"
but rather:
"Can we demonstrate that our entire recovery process is designed, monitored and controlled so that regulatory-compliant behaviour is the default outcome?"
That is, in my view, the central message of these Directions.
Note: The above analysis is based primarily on the uploaded RBI Directions. It is an interpretive/compliance analysis and should not be treated as a formal legal opinion. The RBI's broader regulatory framework also contains related requirements, including its outsourcing and grievance-redressal frameworks, which should be mapped separately when implementing the amendment.