What RBI's 15 June 2026 conduct package requires of regulated entities when they advertise, market and sell financial products (their own and third-party), who it applies to, and the eleven dark patterns it bans. In plain language, linked to the source, live from 1 January 2027.
Two companion amendments issued together: one consolidates how you advertise, market and sell into the Responsible Business Conduct Directions; the other redraws how you partner with third-party providers under the Undertaking of Financial Services Directions.
From 1 January 2027, every covered entity needs a Board-approved policy for advertising, marketing and selling its own and third-party products alike. It hard-codes explicit, per-product consent defaulted to "No", upfront fee and risk disclosure, a public list of selling agents, a ban on eleven named dark patterns, and full refund plus compensation where mis-selling is established. The companion amendment keeps agency arrangements fee-only and risk-free, and referral arrangements introduce-only.
Maintain and display an up-to-date list of empanelled DSAs/DMAs on your website, updated within seven calendar days of any change; agents must be identifiable and bound by a published Code of Conduct.
Sell only with explicit, per-product consent; disclose fees, rates and risks upfront via KFS/MITC where prescribed; the default interface choice must be "No / I do not agree".
Keep your app and website free of the eleven named dark patterns (false urgency, basket sneaking, drip pricing and the rest), subject to user testing and periodic internal audit.
No employee incentive from a third-party provider, no compulsory bundling, no funding a purchase without consent, and full refund plus compensation where mis-selling is established.
Act as a third party's agent on a fee basis with no risk participation, disclosed upfront, dealing only in regulated products you're permitted to.
Under referral you may market and refer but not sell; your brand stays off their documents and their journey stays off your platform: only a redirect link.
Each entry states only the reason cited in the RBI press release. Where a penalty covered more than one issue, the amount shown is the total and is not attributable to any single reason.
A consent SOP, an agent Code of Conduct and a dark-patterns checklist only protect you if every branch, agent and sub-agent has received them, read them, and can be shown to have done so. Here's an honest split of what a policy distribution-and-attestation layer like PolicyCentral.ai does and does not address.
The "did everyone get it, read it, and can you show an auditor" layer around the conduct package.
We're explicit about scope: these are jobs for product, CRM and grievance tooling, not a policy platform.
Being clear about this is the point: sophisticated compliance teams trust a vendor that names its boundaries.
A practical checklist for the 1 January 2027 deadline: what your sales policy, Code of Conduct and consent SOP must contain, who across your network and agents needs to acknowledge them, and the audit-trail evidence to keep ready.
Request the checklistPolicyCentral.ai shows you, live and branch-by-branch, exactly who has read and acknowledged each policy and SOP, with a tamper-evident trail you can export for an RBI review. Walk through it on your own data.
Book a walkthrough