Prudential, Governance
& Reporting

What RBI's consolidated 2025 Directions require of an NBFC's balance sheet, board and regulatory returns, who they apply to layer by layer, and what RBI has actually penalised, from leverage breaches and late returns to NPA upgrades and cross-directorships, in plain language, linked to the source.

Consolidated Directions · 28 Nov 2025 NBFCs · HFCs · Banks · ARCs Last reviewed: Sep 2026
At a glance
InstrumentsNBFC Directions, 2025Governance · Capital · Concentration · IRACP · Disclosures
Issued / in force28 Nov 2025Supervisory Returns: 31 Jul 2026
LayersBase · Middle · UpperTop Layer kept empty
Base Layer leverageNot more than 7outside liabilities / owned fund
NPA threshold90 days overdueupgrade only on full arrears
Actions in tracker20banks, NBFCs & ARCs
What the rules require

Prudential, governance & reporting, in plain terms

Keep the balance sheet within the limits set for your layer, keep the board and its key people within the governance rules, classify and disclose honestly, and file every return on time and correctly. Most penalties here are one of those four loops quietly failing.

What it is

One framework, several directions, scaled by layer

Since 28 Nov 2025 the NBFC rulebook is a set of entity-class Directions that all read their applicability from the Scale Based Regulation framework: four layers (Base, Middle, Upper and a Top Layer that RBI keeps empty unless systemic risk demands otherwise). The Governance Directions set who may sit where and which policies the board must own; Capital Adequacy and Concentration Risk cap leverage and exposure; IRACP fixes when a loan is non-performing and when it may be upgraded; Financial Statements fix what the notes to accounts must disclose; and the Supervisory Returns Directions of 31 Jul 2026 fix what is filed with RBI and by when. Commercial banks carry parallel 2025 Directions, with their asset-classification rules being replaced from 1 Apr 2027.

Does this apply to you?

Applicability, by layer and entity class

  • NBFC Base Layer: the leverage cap, the board-approved concentration-risk policy, the core governance chapter and the full returns calendar. P2P platforms, Account Aggregators and Type I NBFCs always sit here.
  • NBFC Middle Layer: everything above plus CRAR, single-party and group exposure limits, the fit-and-proper and Chief Compliance Officer policies, and the bar on key people holding office in other Middle or Upper Layer NBFCs. Deposit-takers, CICs, IFCs and HFCs are always Middle Layer or above.
  • NBFC Upper Layer: NBFCs RBI names each year; the Large Exposure Framework replaces the Middle Layer exposure limits.
  • Commercial banks, SFBs, RRBs, co-operative banks and AIFIs each have their own 2025 Governance, Concentration Risk, Securitisation, Interest Rate on Deposits and IRACP Directions, and their own 2026 Supervisory Returns and Fraud Risk Management Directions.
  • Asset Reconstruction Companies under the ARC Directions, 2025, including the board-approved policy on management fees.
HFCs, NBFC-MFIs, mortgage guarantee companies and CICs follow the NBFC IRACP Directions unless their own 2025 Directions say otherwise. Check the entity-specific instrument first.
Core obligations
Leverage & capital

Base Layer leverage of 7, CRAR of 15 per cent above it

A Base Layer NBFC's leverage ratio (total outside liabilities divided by owned fund) may not exceed seven at any point of time. Middle Layer and above hold a minimum CRAR of 15 per cent, with Tier 2 capped at 100 per cent of Tier 1. A leverage breach drew a penalty this year.

Exposure limits

25 per cent single party, 40 per cent group

A Middle Layer NBFC's credit and investment exposure may not exceed 25 per cent of Tier 1 capital to a single party or 40 per cent to a single group (with a small infrastructure add-on). Upper Layer NBFCs follow the Large Exposure Framework at 20 per cent of eligible capital. Two NBFCs were penalised for breaching these in July 2026.

Governance

No key person in another Middle or Upper Layer NBFC

Except for a subsidiary, Key Managerial Personnel may not hold any office, including a directorship, in any other NBFC-ML or NBFC-UL. Directors must pass a board-approved fit-and-proper test at appointment and on a continuing basis, and NBFCs above ₹5,000 crore must appoint a Chief Risk Officer.

Asset classification

90 days to NPA, full arrears to come back

An account is non-performing once interest or an instalment is overdue for more than 90 days. An NPA may be upgraded to standard only when the entire arrears of interest and principal are paid, and where a borrower has several facilities, across all of them. Restructured accounts follow the Resolution of Stressed Assets Directions in addition.

Disclosures

Complaints and frauds in the notes to accounts

The notes to accounts must carry a summary of customer and Ombudsman complaints (pending, received, disposed, rejected) and the amount of fraud reported for the year. Two NBFCs were penalised in 2026 for disclosing these incorrectly or incompletely.

Returns

Monthly in 15 days, quarterly and yearly in 21

Under the Supervisory Returns Directions, 2026, returns are due within 15 days of a month-end and within 21 days of a quarter-end or year-end; audited returns within five working days of the auditor's signature; a fraud monitoring return within 14 days of classification. Data must be accurate and complete, and RBI may fine for a breach.

Two further bars keep recurring in penalties: no synthetic securitisation (Securitisation Directions, paragraph 5, for NBFCs and banks alike) and, for banks, no interest on current-account balances (Interest Rate on Deposits Directions, paragraph 8) and the statutory bar on loans to directors under section 20 of the Banking Regulation Act.
What RBI has penalised

The pattern across FY25-26 and FY26-27

20 of the actions in our tracker cite a prudential, governance or reporting failure, and they cluster tightly. NPAs upgraded before the arrears were cleared or not recognised on restructuring, a managing director or KMP sitting on another NBFC's board, a group exposure over the limit, returns and a balance sheet filed late, complaints and frauds misstated in the notes to accounts, a synthetic securitisation structure, interest paid on current accounts. Each is a known rule that a process stopped enforcing. The actions below are drawn from RBI press releases.

Each entry states only the reason cited in the RBI press release. Where a penalty covered more than one issue, the amount shown is the total and is not attributable to any single reason.

ARC08 Sep 2026
Asset Care & Reconstruction Enterprise Limited
₹27.3 Lpenalty
Cited reason (prudential / governance)
Violated the regulatory requirement on the charging of management fees.
NBFC · ICC02 Sep 2026
Hinduja Leyland Finance Limited
₹6.2 Ltotal penalty
Cited reason (prudential / governance)
Undertook activities in the nature of synthetic securitisation, which the Securitisation of Standard Assets directions do not permit.
Multiple reasons
NBFC · ICC14 Aug 2026
Muthoot MCred Limited
₹3.1 Lpenalty
Cited reason (prudential / governance)
Upgraded certain non-performing loan accounts to standard without the entire arrears of interest and principal across all credit facilities being repaid.

Showing 3 of 20 prudential, governance and reporting actions, see all of them in the enforcement tracker.

Where the failures actually happen

Understanding the rule is step one.
Operationalising it is where penalties occur.

A leverage cap, an exposure limit or a returns calendar only holds if the people who approve loans, appoint directors and file returns know the current rule and can prove they do. Here's an honest split of what a policy distribution-and-attestation layer like PolicyCentral.ai does and does not address.

PolicyCentral.ai helps here

Distribute · attest · prove

The "did everyone get it, read it, and can you show an auditor" layer around your prudential and governance framework.

  • Push the board-approved policies the Directions require, concentration-risk, fit-and-proper, compliance-function, NPA classification and upgrade SOPs, the returns calendar, to every credit, secretarial and finance team member, with read receipts and digital acknowledgement.
  • When the rulebook changes, as it did wholesale on 28 Nov 2025 and again with the 31 Jul 2026 returns and fraud directions, version the policy, re-push to affected staff, and chase the unread automatically.
  • Put the governance rules that trip boards, the KMP cross-office bar, the director fit-and-proper cycle, in front of directors and the company secretary as trackable, acknowledged content before every appointment.
  • Maintain a tamper-evident audit trail of who received, read and acknowledged each version, the evidence a supervisory review asks for first.
A different system handles this

What PolicyCentral.ai is not

We're explicit about scope, these are jobs for your loan, treasury and reporting stack, not a policy platform.

  • The loan management system that ages overdues, flags NPAs and blocks premature upgrades.
  • Capital, leverage and exposure computation and the limit-monitoring engines around them.
  • Regulatory reporting tools that assemble and file returns with RBI, and the financial-statement close.

Being clear about this is the point, sophisticated compliance teams trust a vendor that names its boundaries.

Go deeper
For compliance, risk & finance teams

Get the board-policy & returns-calendar checklist

A practical checklist of the board-approved policies the 2025 NBFC Directions expect for your layer, the governance rules to brief directors on before every appointment, the returns calendar under the 2026 Supervisory Returns Directions, and the audit-trail evidence to keep ready for a supervisory review.

Request the checklist
For CCOs, CROs & company secretaries

See policy attestation tracked across every team and every director

PolicyCentral.ai shows you, live and team-by-team, exactly who has read and acknowledged each prudential policy, governance rule and returns procedure, and every update, with a tamper-evident trail you can export for an RBI review. Walk through it on your own data.

Book a walkthrough
PolicyCentral.ai builds policy management software, not legal advice. These are plain-language summaries to help your teams understand what applies to them. Always verify against the original instrument on rbi.org.in and consult your compliance/legal team before acting.
PolicyGPT
AI-powered policy assistant

Hi! I'm PolicyGPT. Ask me anything about PolicyCentral.ai: features, security, compliance, pricing, or hosting.