2026-07-31
Added · Updated
Small Finance Banks must provide RBI officers with read-only access to IT systems and manpower assistance. Banks are required to strengthen post-sanction monitoring of advances to prevent fund diversion, review interest charging practices to ensure fairness, and facilitate the activation of inoperative accounts and KYC updation. Additionally, banks must obtain nominations for eligible deposit accounts, report progress on these metrics quarterly via the DAKSH portal, and implement comprehensive fraud prevention measures including legal compliance audits and a Protected Disclosure Scheme.
RBI published 31 documents in the last 30 days — get each new one by email the day it lands.
Search the Website
( 434 kb ) Reserve Bank of India (Small Finance Banks – Miscellaneous) Supervisory Directions, 2026
RBI/DoS/2026-27/425 DoS.CO.PPG.19/11.01.005/2026-27
July 31, 2026
Reserve Bank of India (Small Finance Banks – Miscellaneous) Supervisory Directions, 2026
In exercise of the powers conferred by Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest to do so, hereby, issues Directions hereinafter specified.
Chapter I - Preliminary
A. Short Title and Commencement
These Directions shall be called the Reserve Bank of India (Small Finance Banks - Miscellaneous) Supervisory Directions, 2026.
These Directions shall come into effect immediately upon issuance.
B. Applicability
C. Definitions
Chapter II - Access to IT Systems
Chapter III - Monitoring of End Use of Funds
(1) meaningful scrutiny of the periodical progress reports and operating / financial statements of the borrowers;
(2) regular visits to the assisted units and inspection of securities charged / hypothecated to the bank;
(3) periodical scrutiny of the books of accounts of the borrowers;
(4) stock audits depending upon the extent of exposure;
(5) obtention of certificates from the borrowers that the funds have been utilised for the purposes approved and in case of incorrect certification, initiation of prompt action as may be warranted, which may include withdrawal of the facilities sanctioned and legal recourse as well. In case a specific certification regarding diversion / siphoning of funds is desired from the auditors of the borrowers, a separate mandate may be awarded to them and appropriate covenants shall be incorporated in the loan agreements; and
(6) examination of all aspects of diversion of funds during internal audit / inspection of the branches and at the time of periodical reviews.
Chapter IV - Fair Practices Code - Charging of Interest
(1) Charging of interest from the date of sanction of loan or execution of loan agreement and not from the date of actual disbursement of funds to the customer. For loans disbursed by cheque, charging interest from the cheque date while handing over the cheque to the customer several days later.
(2) Charging of EMIs on the sanctioned loan amount rather than on the actual disbursed amount, without the knowledge or consent of the borrower.
(3) Any changes in the amortisation schedule originally provided in the Key Facts Statement (KFS), with each part-disbursement of loan, not being communicated to the borrowers.
(4) In case of disbursal or repayment of loans during a month, charging interest for the entire month rather than charging interest only for the period for which the loan was outstanding.
(5) Collecting one or more instalments in advance but reckoning the full loan amount for charging interest.
These and other such non-standard practices of charging interest are not in consonance with the spirit of fairness and transparency while dealing with customers. These are matters of serious concern to RBI.
The bank may use online account transfers in lieu of cheques for loan disbursal.
Chapter V - Inoperative Accounts / Unclaimed Deposits
The bank shall take necessary steps to reduce the number of inoperative accounts and accounts pending for updation / periodic updation of ‘Know Your Customer’ (KYC) and make the process of updation / periodic updation of such accounts smoother and hassle free, including by enabling seamless updation of KYC through mobile / internet banking, non-home branches, and Video Customer Identification Process, in accordance with the relevant provisions of the Reserve Bank of India (Small Finance Banks - Responsible Business Conduct) Directions, 2025 .
The bank may facilitate the process of activation of accounts of beneficiaries of various Central / State government schemes like Direct Benefit Transfer (DBT) / Electronic Benefit Transfer (EBT) etc., and accounts pending updation / periodic updation of KYC, by taking an empathetic view in such cases, since these accounts mostly pertain to the people from the underprivileged sections of the society.
The bank may organise special campaigns for facilitating activation of inoperative accounts and accounts pending for periodic updation of KYC.
The bank may also facilitate Aadhaar updation for its customers through its branches providing Aadhaar related services.
The Customer Service Committee of the Board shall monitor the progress in reduction of inoperative accounts and accounts pending for updation of KYC and the special efforts made by the bank in this regard.
The bank shall report the progress on reduction of inoperative accounts and accounts pending for updation of KYC on a quarterly basis to the Senior Supervisory Manager (SSM), RBI through DAKSH portal.
Chapter VI - Nomination Facility
The bank shall obtain nomination in case of all existing and new eligible customers having deposit accounts, safe custody articles, and safety lockers, as the case may be, to avoid inconvenience and undue hardship to survivors / family members of deceased depositors, in accordance with relevant provisions of the Reserve Bank of India (Small Finance Banks - Responsible Business Conduct) Directions, 2025 .
The Board of Directors / Customer Service Committee (CSC) of the Board of the bank shall review, on a periodic basis, the achievement of nomination coverage.
The bank shall also report the progress on nomination coverage to the SSM, RBI through DAKSH portal on a quarterly basis.
The bank shall suitably sensitise its frontline staff in the branches for obtaining nomination as well as appropriate handling of claims of deceased constituents and dealing with nominees / legal heirs. The bank shall modify the Account Opening Forms suitably (if not already done) with provision for the customers to avail or opt out of nomination facility.
The bank, in addition to directly notifying the customers, shall publicise the benefits of using the nomination facility through various media, including launching periodical drives towards achieving a full coverage of all eligible customer accounts.
Chapter VII - Fraud Prevention Measures
From time to time, RBI has constituted various committees such as the Ghosh Committee, Gilani Committee, and Narang Committee, to examine different aspects relating to frauds and malpractices in banks and to recommend measures for their prevention and early detection. Based on the recommendations of these committees, RBI has, over the years, issued several guidelines to banks aimed at strengthening internal controls, enhanced monitoring in sensitive areas of banking operations, and curbing the occurrence of frauds. The key fraud preventive measures covered under these guidelines are outlined below.
A. Frauds due to Collusion of the Bank Officials
(1) ensure balancing of books at the stipulated intervals;
(2) interact with the concurrent auditors and enquire about the problems faced by them in auditing certain branches and indicate to them in clear terms the expectations of the management from the auditors while auditing branches; and
(3) immediately examine staff accountability and take appropriate action for the lapses / irregularities noticed.
B. Large Value Frauds
(1) Safeguards in respect of Letters of Credit and Bank Guarantee;
(2) Management Audit System and its emphasis on analysis of existing control system, its adequacy, scope and need for periodical review;
(3) Safe custody of critical items of bank stationery; and
(4) A scheme to honour alert bank staff for timely detection of frauds.
C. Retail Loans - Sanction of Bulk Proposals
(1) In all cases of bulk loan proposals received from the employees of a company / firm / organisation, the status of the employee should be confirmed from the concerned company / firm / organisation by stringent application of key KYC norms.
(2) Documents submitted by the employees such as salary slips and Income Tax returns, should be independently verified through banks' own staff. Further, on-site visit should be carried out at the residence of the applicant so as to verify the genuineness of the residential address furnished by the applicant. All the applicants / employees should be individually called in person for pre-sanction discussion to ensure discreet verification of personal details with reference to their documents and photograph submitted by them.
(3) Applications submitted by the promoters / directors of the company, builders / developers, in bulk, should not be accepted in normal circumstances with the sole purpose of portfolio enhancement or predatory lending considerations.
(4) The market reports on builders / developers should be obtained and loans should be sanctioned in respect of projects being undertaken by reputed builders / developers only. The documents to the title of property mortgaged with the bank should be verified with regard to their genuineness at the time of their acceptance and not deferred till the time of initiation of recovery proceedings.
(5) The written undertaking from the authorised drawing / disbursing officer to provide check off facility and also an undertaking to obtain No-Objection Certificate from the loan disbursing branch of the bank before releasing the terminal / superannuation benefits of the employee and to advise the disbursing branch of any transfer / re-location of the employee or before shifting the employee's salary credit to another bank or mode of payment should be obtained. The concurrent audit / regular internal inspection / vigilance inspection, statutory audit should bestow particular attention on bulk proposals for early detection of disquieting features in the portfolio.
(6) The controlling offices of the bank should review the position of retail loan portfolio of the branches on an ongoing basis with focused attention on bulk proposals to avoid their quick mortality or signs of delinquency.
D. Frauds by Deposit of Fake Title Deeds of Property
The bank officials shall follow the laid down procedures for verifying the genuineness of the documents submitted by the borrowers independently through their own advocates / solicitors. The documents sought to be submitted for creation of equitable mortgage / deposit as collateral security should be original and be verified through searches in the appropriate records of the Sub-Registrar of Assurances and Revenue and Municipal records up to or as near to the date of creation of security in the bank's favour as possible. The bank should obtain a certificate from the advocate / solicitor certifying the title to concerned property being original and not duplicate or fake and that the title is clear, marketable and free from encumbrances.
The bank shall be extra cautious while accepting sale deeds and other documents of properties as collateral securities. Necessary steps in this regard, may be detailed by the bank, in consultation with its Legal Department.
Furthermore, the bank may take the following measures:
(1) The bank may insist on opening of bank accounts by owners of properties who offer the same as collateral security against loans given to third parties.
(2) The bank should communicate with the owners of the property through registered letter to confirm proof of residence and their willingness to offer the security as collateral.
E. Frauds in Non-resident Accounts
(1) The bank shall take utmost care when non-resident deposit accounts are sought to be opened / loans sanctioned against such deposits in remote branches / places where the depositors may not have any interest, or the branches may not be having adequate expertise in dealing with such accounts.
(2) If such a deposit is being solicited by the branch and its officers as part of their deposit mobilisation efforts, the concerned Branch Manager shall take responsibility for having identified the depositor and the genuineness of the documents produced.
(3) Apart from the usual precautions, wherever such accounts are opened through a Power of Attorney, the bank may consider verifying the identity of the depositor, inter alia, by contacting the depositor over telephone and e-mail at the number and address mentioned in the application, and verifying address through internet.
(1) The application may be forwarded through a bank branch situated in the country where the NRI deposit holder resides. It would be preferable if such requests are routed through the bank branch at which the concerned NRI is maintaining their accounts since this would presuppose due diligence / compliance with KYC norms by that branch.
(2) A copy of the passport of NRI may also be called for, along with the application for loan against NRI deposits.
F. Safe Custody of Critical Documents
The bank shall exercise safeguards like maintenance of proper records, dual control, periodical balancing of books / verification, submission of control returns, and ensure their observations.
Blank Demand Drafts / Pay Orders and Mail Transfer forms should be treated as security items and the branches should take adequate safeguards against their pilferage. They should be held in joint custody and balanced daily.
The bank shall ensure that no unauthorised person has access to security items like blank cheques, drafts, fixed deposit receipts, pay orders, account opening forms, specimen signature cards / books, loose ledger sheets, and blank Letter of Credit forms.
The ledgers and other books of accounts, voucher bundles, and other items of Stationery should be stored properly.
G. Accounts opened by Employees
H. Legal Compliance Certificate
I. Legal Compliance Audit
The bank should conduct a legal compliance and due diligence audit annually and submit the report to the Chairman / Managing Director & Chief Executive Officer (MD & CEO) and the SSM, RBI.
In all banking transactions, such as opening of different types of accounts, sanctioning of overdraft facilities, opening of letters of credit, opening and operations of FCNR accounts, and project finance through consortium arrangements, if the transaction exceeds a cut off amount the concerned staff should certify that all stipulated conditions are complied with and during the internal audit, such certificate shall be checked by the internal auditor and report to the Chairman / MD & CEO and the SSM, RBI.
J. Forensic Scrutiny
K. Exercise of Discretionary Power
L. Best Practices Code in Banks
The bank shall reiterate the need for strict adherence to the laid down systems and procedures, to its branches / controlling offices. The bank may organize training programmes / seminars / workshops, for creating awareness among the field level functionaries on an ongoing basis.
The procedures for entering into transactional relationship, especially those in the fraud-prone areas, should be well documented in the BPC, compared with the best national and international practices, experimented with, and improved upon in the light of the experience gained.
Preparation of the BPC should involve examination of all procedures, processes, products, activities, and systems, existing and future (as and when a new product / process is introduced).
The BPC should be integrated with the overall risk management strategy of the bank. Apart from it being viewed in the context of prevention of frauds, it should also be considered as a part of the strategy to mitigate all possible operational risk losses.
The bank shall consider the following while compiling the BPC:
(1) The BPC should be a comprehensive and homogenous document.
(2) While the manual of instructions / circulars issued by the bank from time to time could be consolidated and incorporated, this by itself would not constitute BPC.
(3) The BPC should take into account the instructions relating to the common fraud prone areas and their prevention issued to banks by RBI from time to time.
(4) The BPC should also highlight the recommendations of the various committees constituted by RBI for prevention of frauds and banking sector reforms.
(5) The BPC should also take into account the instructions of the Central Vigilance Commission (CVC), if any, issued from time to time.
(6) The BPC should, at a minimum, cover all the functional areas like cash, safe custody of other valuables (Demand Draft / Telegraphic Transfer / Letter of Credit / Guarantee forms), deposit accounts, investment portfolio, credit portfolio, foreign exchange transactions, treasury operations, bills portfolio, remittances, cash receipts and payments, issue / payment of demand drafts, clearing transactions, government transactions, and Letters of Credit / Guarantees.
(7) The BPC may also incorporate practices that would help prevention of losses to its customers and include suitable guidance to such customers. The bank shall codify the precautions to be taken by customers and the same should be publicised by placing on its website or through any other medium.
(8) The BPC should be periodically revised and updated in the light of the experience gained, fresh instructions from RBI and suggestions made by internal / external auditors.
M. Other Instructions
The bank shall strengthen its internal control system for detection and prevention of frauds.
The concurrent / internal / statutory auditors of the bank shall specifically report to the Chairman / MD & CEO of the bank and the SSM, RBI, about anything susceptible to be a fraud or fraudulent activity or any foul play in any transaction.
The bank shall adhere strictly to the time frame fixed for reporting fraud cases to RBI as per Reserve Bank of India (Small Finance Banks – Fraud Risk Management) Directions, 2026 .
The bank shall invariably initiate departmental action against officials involved in bank frauds simultaneously with criminal action to ensure that internal fraudsters are immediately punished even if criminal cases against them continue.
Wherever there is a prima-facie case against the loan dealing officials of the bank, appropriate action in terms of Central Vigilance Commission guidelines, for their inclusion in the list of officers with doubtful integrity, should be initiated by the bank in consultation with the Central Bureau of Investigation.
The officers posted in the Vigilance Department of the bank, preferably at the Head Office, should hold meetings with the investigating authorities at periodical intervals which should be minutised and action be taken within a time frame agreed to at the meetings.
Chapter VIII - Protected Disclosure Scheme
A. Scope and Coverage
The complaints under the Scheme would cover the areas such as corruption, misuse of office, criminal offences, suspected / actual fraud, failure to comply with existing rules and regulations such as the Reserve Bank of India Act, 1934 and the Banking Regulation Act 1949, and acts resulting in financial loss / operational risk or loss of reputation, detrimental to depositors' interest / public interest.
Under the Scheme, employees of the bank, customers, stake holders, NGOs and members of public can lodge complaints.
Anonymous / pseudonymous complaints will not be covered under the Scheme and such complaints will not be entertained.
RBI will be the Nodal Agency to receive complaints under the Scheme. RBI would keep the identity of the complainant secret, except in cases where complaint turns out to be vexatious or frivolous and action has to be initiated against the complainant as mentioned below:
(1) The institution against which complaint has been made can take action against complainants in cases where motivated / vexatious complaints are made under the Scheme, after being advised by RBI. An opportunity of hearing will, however, be given by the bank to the complainant before taking such action.
(2) Final action taken by RBI on the complaint will be intimated to the complainant.
B. Procedure for Lodging the Complaint under the Scheme
The complaint should be sent in a closed / secured envelope.
The envelope should be addressed to The Chief General Manager, Reserve Bank of India, Department of Supervision, Fraud Monitoring Group, 2nd Floor, Maker Tower-E, Cuffe Parade, Mumbai 400 005. The envelope should be superscribed ‘Complaint under Protected Disclosure Scheme for Banks’.
The complainant should give his / her name and address in the beginning or end of the complaint or in an attached letter. In case of an employee making such complaint, details such as name, designation, department, institution and place of posting should be furnished.
Complaints can also be made through e-mail also giving full details as specified above.
The complainant should ensure that the issue raised by him involves dishonest intention / moral angle. They should study all the relevant facts and understand their significance. They should also make an effort, if possible, to resolve the issue through internal channels in order to avoid making the complaint.
The text of the complaint should be carefully drafted so as not to give any details or clue to complainant's identity. The details of the complaint should be specific and verifiable.
In order to protect the identity of the complainant, RBI will not issue any acknowledgement of receipt of the complaint and the complainants are advised not to enter into any further correspondence with the RBI in their own interest. RBI assures that, subject to the facts of the case being verifiable, it would take necessary action, as provided under the scheme. If any further clarification is required, RBI will get in touch with the complainant.
If the complaint is accompanied by particulars of the person making the complaint, the RBI shall take the following steps:
(1) If necessary, it would ascertain from the complainant whether they were the person who made the complaint or not.
(2) The identity of the complainant will not be revealed unless the complainant himself has made the details of the complaint either public or disclosed his identity to any other authority.
(3) The identity of the complainant will be concealed, RBI will make discreet inquiries to ascertain if there is any basis for proceeding further with the complaint.
(4) Either as a result of the discreet enquiry, or on the basis of complaint itself without any enquiry, if RBI is of the opinion that the matter requires to be investigated further, RBI may consider calling for the comments / response from the Chairman / MD & CEO of the concerned bank.
(5) After obtaining the response of the concerned bank and / or on the basis of an independent scrutiny conducted / ordered by RBI, if RBI is of the opinion that the allegations are substantiated, then RBI shall recommend appropriate action to the concerned bank. These shall, inter alia, include the following:
(i) Appropriate action to be initiated against the concerned official.
(ii) Appropriate administrative steps for recovery of the loss caused to the bank as a result of the corrupt act or mis-use of office, or any other offence covered by the Scheme.
(iii) Recommend to the appropriate authority / agency for initiation of criminal proceedings, if warranted by the facts and circumstances of the cases.
(iv) Recommend taking corrective measures to prevent recurrence of such events in future.
(v) Consider initiating any other action that it deems fit keeping in view the facts of the case.
(6) If any person is aggrieved by any action on the ground that he is victimized due to filing of the complaint or disclosure, he may file an application before the RBI seeking redressal in the matter. RBI will take such action, as deemed fit. In case the complainant is an employee of the bank, RBI may give suitable directions to the concerned bank, preventing initiation of any adverse personnel action against the complainant.
(7) Either on the basis of application of the complainant or on the basis of information gathered, if the RBI is of the opinion that either the complainant or the witnesses in the case need protection, the RBI shall issue appropriate directions to the concerned bank.
(8) The system described herein shall be in addition to the existing grievances redressal mechanism in place. However, secrecy of identity shall be observed, only if the complaint is received under the scheme.
(9) In case RBI finds that the complaint is motivated or vexatious, RBI shall be at liberty to take appropriate steps.
(10) In the event of the identity of the informant being disclosed in spite of RBI's directions to the contrary, then RBI shall be authorised to initiate appropriate action as per extant regulations against the person or agency making such disclosure. RBI may also direct such person or agency to suitably compensate the complainant.
C. Protected Disclosure Policy
Chapter IX – Vigilance
A. Preamble
B. Introduction
C. Vigilance Angle
(1) Demanding and / or accepting gratification other than legal remuneration in respect of an official act or for using his influence with any other official;
(2) Obtaining valuable thing, without consideration or with inadequate consideration from a person with whom he has or is likely to have official dealings or his subordinates have official dealings or where he can exert influence;
(3) Obtaining for himself or for any other person any valuable thing or pecuniary advantage by corrupt or illegal means or by abusing his position as an employee;
(4) Possession of assets disproportionate to their known sources of income; and
(5) Cases of misappropriation, forgery or cheating or other similar criminal offences.
D. Chief of Internal Vigilance
D.1 Appointment
D.2 Tenure
D.3 Association with Sensitive Matters
D.4 Submission of Reports and Returns - Review
E. Preventive Vigilance
(1) undertake a study of existing procedure and practices prevailing in the bank with a view to modifying those procedures or practices which provide a scope for corruption, and also to find out the causes of delay, the points at which it occurs and devise suitable steps to minimize delays at different stages;
(2) undertake a review of the regulatory functions with a view to see whether all of them are strictly necessary and whether the manner of discharge of those functions and exercise of powers of control are capable of improvement;
(3) devise adequate methods of control over exercise of discretion so as to ensure that discretionary powers are not exercised arbitrarily but in a transparent and fair manner; and
(4) identify the areas in his organisation which are prone to corruption and to ensure that the officers of proven integrity only are posted in those areas;
F. Staff Rotation and Mandatory Leave
G. Complaints
(1) Complaints received from employees of the bank or from the public;
(2) Departmental inspection reports and stock verification surveys;
(3) Scrutiny of annual property statements;
(4) Scrutiny of transactions reported under the Conduct Rules;
(5) Reports of irregularities in accounts detected in the routine audit of accounts, e.g., tampering with records, over-payments, and misappropriation of money or materials;
(6) Audit reports of the accounts of the bank;
(7) Complaints and allegations appearing in the press;
(8) Source information, if received verbally from an identifiable source, to be reduced in writing; and
(9) Intelligence gathered by agencies like Central Bureau of Investigation and local bodies.
H. Investigation Agency for Conducting Investigations
I. Review of Cases entrusted to Investigating Agencies
J. Action against Persons making False Complaints
K. Liaison with Agencies
Chapter X - Repeal and Other Provisions
A. Repeal and Saving
With the issue of these Directions, the existing Directions, instructions, and guidelines relating to areas covered in these Directions as applicable to Small Finance Banks stand repealed, as communicated vide circular no. DoS.CO.PPG.66/11.01.005/2026-27 dated July 31, 2026 . The Directions, instructions and guidelines repealed prior to issuance of these Directions shall continue to remain repealed.
Notwithstanding such repeal, any action taken or purported to have been taken, or initiated under the repealed Directions, instructions, or guidelines shall continue to be governed by the provisions thereof. All approvals or acknowledgments granted under these repealed lists shall be deemed as governed by these Directions. Further, the repeal of these directions, instructions, or guidelines shall not in any way prejudicially affect:
(1) any right, obligation or liability acquired, accrued, or incurred thereunder;
(2) any penalty, forfeiture, or punishment incurred in respect of any contravention committed thereunder;
(3) any investigation, legal proceeding, or remedy in respect of any such right, privilege, obligation, liability, penalty, forfeiture, or punishment as aforesaid; and any such investigation, legal proceedings or remedy may be instituted, continued, or enforced and any such penalty, forfeiture or punishment may be imposed as if those directions, instructions, or guidelines had not been repealed.
B. Application of Other Laws Not barred
C. Interpretations
(Tarun Singh) Chief General Manager
Top
Back to previous page
Read the rest free
Source: Reserve Bank of India — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works