Customer Protection &
Responsible Business Conduct

What RBI's 15 June 2026 conduct package requires of regulated entities when they advertise, market and sell financial products (their own and third-party), who it applies to, and the eleven dark patterns it bans. In plain language, linked to the source, live from 1 January 2027.

RBC + UFS Amendments · 15 Jun 2026 Effective 1 Jan 2027 Banks · Co-ops · NBFCs · HFCs · AIFIs
At a glance
PackageRBC + UFS Amendmentstwo companion directions
Issued15 Jun 2026
Effective1 Jan 2027a runway, not a switch
Entity classes10 + 7RBC across 10, UFS across 7
Dark patterns named11illustrative, Annex IIA
Consent default"No"opt-in, per product
What the package requires

Sell honestly, prove it, own the fallout

Two companion amendments issued together: one consolidates how you advertise, market and sell into the Responsible Business Conduct Directions; the other redraws how you partner with third-party providers under the Undertaking of Financial Services Directions.

What it is

A conduct rulebook for selling

From 1 January 2027, every covered entity needs a Board-approved policy for advertising, marketing and selling its own and third-party products alike. It hard-codes explicit, per-product consent defaulted to "No", upfront fee and risk disclosure, a public list of selling agents, a ban on eleven named dark patterns, and full refund plus compensation where mis-selling is established. The companion amendment keeps agency arrangements fee-only and risk-free, and referral arrangements introduce-only.

Does this apply to you?

Applicability, by entity class

  • The Responsible Business Conduct amendment reaches ten classes: commercial, small finance, payments and local-area banks, RRBs, urban & rural co-ops, AIFIs, NBFCs and HFCs.
  • The Undertaking of Financial Services amendment reaches seven classes: commercial, small finance and payments banks, RRBs, urban & rural co-ops, and NBFCs.
  • For banks the rules sit at Para 85A to 85ZA; for NBFCs and HFCs the identical set sits at Para 101A to 101ZA. HFCs fold straight into the NBFC framework.
  • Excludes Core Investment Companies, NBFC-Account Aggregators, NOFHCs and NBFCs with no customer interface.
All of it takes effect on 1 January 2027, having been issued 15 June 2026 with a deliberate transition runway.
Core obligations
Agents

A public list of selling agents

Maintain and display an up-to-date list of empanelled DSAs/DMAs on your website, updated within seven calendar days of any change; agents must be identifiable and bound by a published Code of Conduct.

Consent

Explicit consent, defaulted to "No"

Sell only with explicit, per-product consent; disclose fees, rates and risks upfront via KFS/MITC where prescribed; the default interface choice must be "No / I do not agree".

Dark patterns

None of the eleven

Keep your app and website free of the eleven named dark patterns (false urgency, basket sneaking, drip pricing and the rest), subject to user testing and periodic internal audit.

Mis-selling

No incentives, no compulsory bundling

No employee incentive from a third-party provider, no compulsory bundling, no funding a purchase without consent, and full refund plus compensation where mis-selling is established.

Agency

Fee-only, no risk participation

Act as a third party's agent on a fee basis with no risk participation, disclosed upfront, dealing only in regulated products you're permitted to.

Referral

Introduce only, never sell

Under referral you may market and refer but not sell; your brand stays off their documents and their journey stays off your platform: only a redirect link.

Full obligation-by-obligation detail is in the two decodes below, each linked to its RBI source.
What RBI has penalised

The pattern so far

Each entry states only the reason cited in the RBI press release. Where a penalty covered more than one issue, the amount shown is the total and is not attributable to any single reason.

Bank · Public27 Mar 2026
Central Bank of India
₹63.6 Ltotal penalty
Cited reason
Opened additional BSBD accounts for certain customers who already held BSBD accounts in the bank.
Bank · Private19 Dec 2025
Kotak Mahindra Bank
₹61.95 Ltotal penalty
Cited reason
Opened another BSBD account for certain customers who already held a BSBD account in the bank.
Bank · Private05 Dec 2025
Jammu & Kashmir Bank Ltd
₹99.3 Ltotal penalty
Cited reason
Did not send final letters to customers on complaint redressal, so customers were not made aware of their right to approach the Banking Ombudsman.
Where the failures actually happen

Knowing the rule is step one.
Operationalising it across every seller is where it breaks.

A consent SOP, an agent Code of Conduct and a dark-patterns checklist only protect you if every branch, agent and sub-agent has received them, read them, and can be shown to have done so. Here's an honest split of what a policy distribution-and-attestation layer like PolicyCentral.ai does and does not address.

PolicyCentral.ai helps here

Distribute · attest · prove

The "did everyone get it, read it, and can you show an auditor" layer around the conduct package.

  • Push the Board-approved sales policy, Code of Conduct and consent SOP to every branch, employee, DSA/DMA and sub-agent, with read receipts and digital acknowledgement.
  • Distribute the dark-patterns and mis-selling guidance as trackable training content for product, design and frontline teams.
  • Maintain a tamper-evident audit trail of who received, read and acknowledged each policy and update: the evidence a supervisory review asks for.
  • Version the policy and re-push to unread staff with one click ahead of the 1 January 2027 deadline.
A different system handles this

What PolicyCentral.ai is not

We're explicit about scope: these are jobs for product, CRM and grievance tooling, not a policy platform.

  • The consent-capture and disclosure UI inside your app or onboarding journey.
  • The website list of empanelled agents and the referral-product directory themselves.
  • The mis-selling complaint, refund and compensation workflow.

Being clear about this is the point: sophisticated compliance teams trust a vendor that names its boundaries.

Go deeper
For compliance & risk teams

Get the conduct-package readiness checklist

A practical checklist for the 1 January 2027 deadline: what your sales policy, Code of Conduct and consent SOP must contain, who across your network and agents needs to acknowledge them, and the audit-trail evidence to keep ready.

Request the checklist
For CCOs, HR & InfoSec leaders

See policy attestation tracked across every branch & agent

PolicyCentral.ai shows you, live and branch-by-branch, exactly who has read and acknowledged each policy and SOP, with a tamper-evident trail you can export for an RBI review. Walk through it on your own data.

Book a walkthrough
PolicyCentral.ai builds policy management software, not legal advice. These are plain-language summaries to help your teams understand what applies to them. Always verify against the original instrument on rbi.org.in and consult your compliance/legal team before acting.
PolicyGPT
AI-powered policy assistant

Hi! I'm PolicyGPT. Ask me anything about PolicyCentral.ai — features, security, compliance, pricing, or hosting.