An NBFC runs on board-approved policies. RBI’s Directions require them for credit, KYC, fair practices, outsourcing, fraud, IT, compliance and more, and supervisors test not only whether each policy exists but whether it matches the current Directions. In the last twelve months, the source of almost every one of those requirements has changed.
RBI consolidated its NBFC instructions into a set of Directions issued in 2025, each updated periodically since. Then, on 31 July 2026, it issued four new supervisory Directions for NBFCs with immediate effect: Compliance Function, Internal Audit Function, Fraud Risk Management, and Cybersecurity, Technology: Risk, Resilience and Assurance Framework. Each repealed the earlier instructions on its subject.
The practical result: many NBFC policy libraries still cite circulars that no longer exist. This checklist maps the board-approved policies an NBFC needs to the Direction that requires each one, as the Directions stand in September 2026.
1. Governance and control function policies
Fit and proper policy for directors
Under the NBFC Governance Directions, 2025, NBFCs in the Middle and Upper Layers must have a board-approved policy for ascertaining the fit and proper status of directors at appointment and on a continuing basis, backed by due diligence, signed declarations scrutinized by the Nomination and Remuneration Committee, and annual confirmations as on 31 March.
Compliance policy
The new Compliance Function Directions, 2026 apply to Middle and Upper Layer NBFCs. The board-approved compliance policy must set out the compliance philosophy, expectations on compliance culture, the structure and role of the compliance function, the role of the Chief Compliance Officer, and the processes for identifying, assessing, monitoring, managing and reporting compliance risk. It must be reviewed at least once a year.
Compensation policy
The Governance Directions require Middle and Upper Layer NBFCs to adopt a board-approved compensation policy that addresses excessive risk-taking caused by misaligned pay, with the Nomination and Remuneration Committee overseeing its framing, review and implementation.
Internal audit policy
The Internal Audit Function Directions, 2026 apply to all deposit-taking NBFCs and HFCs, and to non-deposit-taking NBFCs and HFCs with assets of ₹5,000 crore and above. The board-approved policy must document the purpose, authority and responsibility of internal audit, with a clear demarcation from the risk management function and the risk-based internal audit approach.
Upper Layer transition policy
Under the Scale Based Regulation Directions, an NBFC advised by RBI that it has been placed in the Upper Layer must put in place a board-approved policy for adopting the enhanced regulatory framework within three months, along with an implementation plan.
For a decoded view of these governance requirements, see our Prudential, Governance and Reporting hub.
2. Customer conduct policies
The NBFC Responsible Business Conduct Directions, 2025 require board-approved policies and review mechanisms to ensure responsible business conduct, and provide an illustrative list:
- Fair Practices Code, preferably in the vernacular language or a language the borrower understands.
- Grievance redressal mechanism, ensuring disputes are heard and disposed of at least at the next higher level.
- Interest rates and charges: internal principles and procedures for determining interest rates and processing, penal and other charges.
- Penal charges policy, a separate board-approved policy on penal charges on loans, by whatever name called.
- Lending against gold and silver collateral.
- Fair Practices Code for microfinance loans, displayed in all offices and on the website.
- Reset of floating rate personal loans, including the option to switch between fixed and floating rates.
- Engagement of recovery agents.
- Code of conduct for DSAs, DMAs and recovery agents.
The same Directions also require a board-approved policy on the conduct of employees and the system for their recruitment, training and monitoring, and require the board to periodically review compliance with the Fair Practices Code and the functioning of the grievance redressal mechanism.
Our Fair Practices Code hub and customer protection hub decode these obligations, including the amendments on advertising, mis-selling and dark patterns that take effect on 1 January 2027.
3. KYC and anti-money laundering policies
The NBFC KYC Directions, 2025 require a KYC policy approved by the board or a delegated committee. It must include four key elements: a Customer Acceptance Policy, Risk Management, Customer Identification Procedures, and Monitoring of Transactions. The Directions also require board-approved policies, controls and procedures for a risk-based approach, and an internal policy that clearly specifies the risk-based approach to periodic updation of KYC.
Policies, simplified with AI-powered automation
Book a 20-minute demo to see how PolicyCentral.ai streamlines policy creation, distribution, and compliance across your enterprise.
Book a DemoSee our KYC and CKYCR hub for a structured breakdown.
4. Credit, risk and recovery policies
- Credit policy: the Credit Facilities Directions require a board-approved credit policy covering the areas the NBFC is active in, including single borrower and aggregate limits. Microfinance lenders also need board-approved policies on household income assessment, the repayment obligation limit, repayment flexibility and pricing.
- Credit risk management policies: required by the Credit Risk Management Directions for the areas those Directions cover, to the extent the activity is undertaken.
- Concentration risk policy: the Concentration Risk Management Directions require a comprehensive board-approved policy at every layer, internal limits for single and group exposures, and a policy for determining groups of connected counterparties.
- Stressed assets: the Resolution of Stressed Assets Directions require board-approved policies for resolution, including timelines and signs of financial difficulty, and separate policies for compromise settlements and technical write-offs. The cooling period before fresh exposure to a borrower after a compromise settlement has a floor of 12 months.
- Wilful defaulters: the Wilful and Large Defaulters Directions require a board-approved implementation policy and a non-discriminatory policy on publishing photographs of wilful defaulters.
- Asset liability management: under the ALM Directions, the board has overall responsibility for ALM systems and must set up an Asset Liability Management Committee headed by the CEO or MD.
5. Technology, outsourcing and fraud policies
Outsourcing and IT outsourcing policies
The Managing Risks in Outsourcing Directions, 2025 require an NBFC that outsources financial services to have a comprehensive board-approved outsourcing policy, and one that outsources IT services to have a board-approved IT outsourcing policy. Both must include a framework for evaluating the risk and materiality of each arrangement.
IT, information security, cybersecurity and BCP policies
The new Cybersecurity and Technology Directions, 2026 apply to all NBFCs, with graded chapters by size. They require a board-approved IT or IS policy, a board-approved information security policy, a board-approved cybersecurity policy setting out the strategy to combat cyber threats, and a board-approved business continuity plan policy with periodic reports to the board at least once a year.
Fraud risk management policy
The new Fraud Risk Management Directions, 2026 apply to NBFCs in the Upper and Middle Layers, and to Base Layer NBFCs with assets of ₹500 crore and above. The board-approved policy must set out the roles of the board, board committees and senior management, and cover prevention, early detection, investigation and reporting.
It must build in principles of natural justice: a detailed show cause notice, at least 21 days to respond, and a reasoned order before any person or entity is classified as fraudulent. Middle and Upper Layer NBFCs must also maintain an Early Warning Signals framework under the policy. The board must review the policy at least once in three years. A separate policy on engaging external auditors for fraud investigations is also required.
Why NBFC policy libraries fall out of date
RBI updates its Directions frequently. Several of the Directions cited above carry “updated as on” dates in July and August 2026 alone. A policy that restates a threshold, a timeline or a process from a Direction can become inaccurate the day the Direction changes, and the 31 July 2026 repeal of older fraud, IT, compliance and audit instructions means many policies now reference a source that no longer exists.
Supervisors examine policies against the current text. Our RBI enforcement tracker shows the kinds of process and policy failures that RBI penalizes in practice.
The last mile: policies that must reach the branch and the field
Many of these policies govern people far from head office. The Fair Practices Code, the recovery agent policy, the code of conduct for DSAs and DMAs, the staff conduct policy and the KYC policy all have to be applied by branch staff, collection teams and third-party agents, often in regional languages. The RBC Directions explicitly expect borrower communication in a language the borrower understands, and that is only possible if the staff doing the communicating understand the policy first.
That means distributing each current version to the right audience, including agents and DSAs, collecting an acknowledgment, and repeating the cycle after every update. We covered the workforce side of this for banks and NBFCs, and why multilingual delivery is now a compliance necessity.
For drafting, our free templates for KYC and Customer Due Diligence, Anti-Money Laundering, Fraud Risk Management, Customer Complaint Redressal, Vendor and Third-Party Compliance and Business Continuity and Disaster Recovery are a starting point to adapt to the Directions above.
How PolicyCentral.ai helps NBFCs
PolicyCentral.ai holds every board-approved policy in one library, with its owner, approval trail, version history and review date, so annual and three-yearly reviews are scheduled rather than remembered. Each approved version is distributed to the right audience, from the board to branch staff and field agents, in ten Indian languages, with tamper-evident acknowledgment records ready for an RBI inspection.
Staff can ask questions such as “What is our penal charges policy for a missed EMI?” and get an answer grounded in the current approved text. If your policy library still cites circulars that were repealed on 31 July, request a demo and bring your fraud risk management policy.
Frequently Asked Questions
Which board-approved policies must an NBFC have?
It depends on the NBFC’s layer, size and activities. Commonly required policies include the KYC policy, Fair Practices Code, grievance redressal, interest rate and penal charges policies, recovery agent and DSA codes, credit policy, concentration risk policy, stressed asset resolution and compromise settlement policies, outsourcing and IT outsourcing policies, IT, information security, cybersecurity and BCP policies, and a fraud risk management policy. Middle and Upper Layer NBFCs also need fit and proper, compliance and compensation policies.
What did RBI change for NBFCs on 31 July 2026?
RBI issued four new Directions for NBFCs with immediate effect: Compliance Function, Internal Audit Function, Fraud Risk Management, and Cybersecurity, Technology: Risk, Resilience and Assurance Framework. Each repealed the earlier instructions on its subject, so policies that cite the older circulars should be updated to reference the new Directions.
How often must an NBFC review its compliance policy?
Under the Compliance Function Directions, 2026, which apply to Middle and Upper Layer NBFCs, the board-approved compliance policy must be reviewed at least once a year.
Which NBFCs need a board-approved fraud risk management policy?
Under the Fraud Risk Management Directions, 2026, NBFCs in the Upper and Middle Layers, and Base Layer NBFCs with assets of ₹500 crore and above, must have one. The board must review it at least once in three years, and it must provide for natural justice, including a show cause notice with at least 21 days to respond before classifying anyone as fraudulent.
Does the NBFC Fair Practices Code have to be in a regional language?
The Responsible Business Conduct Directions state that the Fair Practices Code should preferably be in the vernacular language or a language understood by the borrower, and that communications to borrowers, including sanction letters and notices of changes in terms, should be in the vernacular or a language the borrower understands.
How can PolicyCentral.ai help an NBFC manage board-approved policies?
PolicyCentral.ai maintains each policy with its approval trail, version history and review date, automates review cycles, distributes approved versions to the board, staff and field agents in ten Indian languages, keeps tamper-evident acknowledgment records for RBI inspections, and gives staff an AI assistant that answers questions from the current policy text.