From 1 January 2027, any regulated entity that advertises, markets or sells a financial product, its own or a third party's, must do it under a Board-approved policy, take explicit, defaulted-to-"No" consent, disclose fees and risks upfront, keep a public list of its selling agents, keep its app and website free of eleven named "dark patterns", and refund and compensate in full where mis-selling is established.
On 15 June 2026 RBI consolidated its advertising, marketing and sale rules into the Responsible Business Conduct (RBC) Directions, 2025 via a Second Amendment, and issued the same framework as separate notifications to all ten regulated-entity classes. The substance is identical across them; only the paragraph numbering differs by class. This decode states the obligations in plain terms and cites the Commercial Banks numbering (paragraphs 85A to 85ZA, Annex IIA) as the worked reference.
Who it applies to
The same Second Amendment was issued, on 15 June 2026, to ten regulated-entity classes, each amending that class's own Responsible Business Conduct Directions, 2025:
- Commercial Banks (other than SFBs, Payments Banks, RRBs and Local Area Banks), and separately Small Finance Banks, Payments Banks, Local Area Banks and Regional Rural Banks.
- Urban Co-operative Banks and Rural Co-operative Banks.
- All India Financial Institutions (EXIM Bank, NABARD, NHB, SIDBI, NaBFID).
- NBFCs, excluding Core Investment Companies, NBFC-Account Aggregators, NOFHCs and NBFCs with no customer interface; the rules additionally extend to NBFC-P2P, Mortgage Guarantee Companies and Standalone Primary Dealers.
- Housing Finance Companies, which RBI folds straight into the NBFC framework: an HFC must comply with paragraphs 101A to 101ZA of the NBFC RBC Directions, 2025.
What it requires
Grouped by what each obligation is about. Described in plain terms; verify the exact clause text against the source before acting.
A Board-approved policy (Para 85A to 85B)
One policy covering own and third-party products
A comprehensive policy for advertising, marketing and sale of both own and third-party products, covering how suitability and appropriateness are judged, the customer-feedback mechanism, and compensation where mis-selling occurs.
Cover the selling-agent lifecycle
If the entity uses Direct Selling / Marketing Agents, the policy must also set their eligibility criteria, pre- and post-engagement due diligence, sub-agent training, what activities they may be assigned, performance standards, inspection/audit, controls and the penal action for non-compliance.
Direct Selling / Marketing Agents (Para 85C to 85F, 85O)
A public, current list of agents
Maintain and display on the website an up-to-date list of empanelled DSAs/DMAs, name, type (corporate/individual), address, period of engagement and products handled, and update it within seven calendar days of any change. The definition deliberately catches BCs, Loan Service Providers and the like, whatever they are called.
Identifiable, qualified, bound by a Code of Conduct
Any agent, sub-agent or third-party-provider representative present in the entity's premises must be clearly distinguishable from staff, with 'on person' identification, and must hold any qualification the relevant regulator prescribes. A Code of Conduct binds staff, agents, sub-agents and provider representatives; the entity must take a signed undertaking to abide by it and publish the Code on its website.
No impersonation
Agents must not mislead customers about who they are, and sub-agents or provider representatives must not pass themselves off as the entity's own employees.
Consent & disclosure (Para 85G to 85I)
Explicit consent, per product
Sell only with the customer's explicit consent: a signed declaration, OTP approval, digitally recorded confirmation or a clearly demarcated consent block in the agreement. Where one form covers several products, each must be listed separately and the customer able to pick only what they want. Consent records must be kept for one year after the contract ends.
Key features, drawn to attention
Before consent, prominently disclose fees/charges/interest, risks, the financial commitment, lock-in, and exit terms including penalties. Where RBI or another regulator prescribes a format, a Key Facts Statement (KFS) or Most Important Terms & Conditions (MITC), that format must be used.
Default to "No"
A consent interface must not let the user proceed without passing through the applicable terms, and the default choice must be 'No' / 'I do not agree'.
Advertising, marketing & agent conduct (Para 85J to 85N)
Never pass a third-party product off as your own
An entity must not advertise or market a third-party product/service (TPPS) as its own, and must clarify its role when giving a provider's details to a customer.
Clear, factual promotional material
All pamphlets, brochures and digital creatives must be clear and factual and disclose the interest rate and associated fees/charges; terms and conditions must be prominent at every point of sale and digital channel. Promotional alerts may go only to customers who have opted in, and unsubscribing must be easy and simple.
A conduct code for anyone who sells
Staff, agents, sub-agents and provider representatives must disclose fees/rates upfront, share full terms, contact customers only between 09:00 and 19:00 (unless the customer asked otherwise), honour "Do Not Disturb", respect privacy, not visit homes without consent, and not mislead, coerce or make false commitments.
Suitability & documentation (Para 85P to 85T)
Assess suitability before selling
Except for products the policy treats as suitable for everyone, suitability and appropriateness must be assessed: product features, risk-return, horizon, complexity and fees, weighed against the customer's age, income, financial literacy and risk tolerance, using any regulator-prescribed assessment.
Product-specific forms, regional language, acknowledgement
Use a specific application form per product that names its nature (loan, deposit, insurance, mutual fund, pension, hybrid) and features; in a multi-product digital form, separate each product and take consent for each. Documents must be available in the customer's language; an acknowledgement with a contact number must follow each application; and the signed terms must be handed to the customer on completion.
Preventing mis-selling (Para 85U to 85X)
No incentives that drive mis-selling
Policies and practices must not create incentives to mis-sell, and no employee may receive any incentive, direct or indirect, from a third-party provider for selling its product.
No compulsory bundling, no funding without consent
An entity must not compulsorily bundle a third-party product with its own. Where a third-party product is genuinely needed as a risk mitigant, the customer must be free to buy it from any provider. And it must not fund a purchase out of a sanctioned loan without the customer's explicit consent.
No dark patterns in any interface
The entity and its agents must ensure their user interfaces deploy no dark patterns, subject to user testing and periodic internal audit, and must follow the CCPA's Guidelines for Prevention and Regulation of Dark Patterns, 2023. RBI's illustrative list of eleven is below.
Feedback & redress (Para 85Y to 85Z)
Feedback within 30 days, reviewed half-yearly
Seek customer feedback within 30 days of a sale (via call-backs or surveys run by a team not involved in selling) to confirm the customer understood the product and its risks, and prepare a half-yearly report that feeds back into policy.
Full refund and compensation on mis-selling
A customer may complain within the regulator-specified window, or within 30 days of receiving the signed terms if none is specified. Where mis-selling is established, the entity must refund the entire amount paid, cancel the sale where applicable, and compensate the customer for any loss per its approved policy.
The 11 dark patterns RBI named
RBI's illustrative list of deceptive interface designs a bank or its agents must not deploy. Plain-language summaries of each, see Annex IIA of the notification for the full text and illustrations.
False Urgency
Faking scarcity or a deadline (countdown timers, "rate rises if you don't act now") to push an immediate decision.
Basket Sneaking
Slipping extra items into checkout without consent, e.g. defaulting loan-protection insurance into a loan application.
Confirm Shaming
Guilt-tripping the user out of declining ("No, I don't want extra security for my account") to subvert their choice.
Forced Action
Forcing an unrelated purchase, sign-up or data-sharing to get the thing actually wanted, e.g. unclosable pop-ups that redirect to a loan page.
Subscription Trap
Easy to sign up, hard to cancel: hidden or multi-step cancellation, or demanding card details for a "free" subscription.
Interface Interference
Highlighting the entity's preferred option and burying the rest: bold "Yes", defaulted consent, account-closure buried deep.
Bait and Switch
Advertising one outcome and delivering another: a low headline rate that climbs at application, undisclosed processing fees.
Drip Pricing
Revealing charges late or post-purchase, or advertising "free" when continued use needs payment.
Disguised Advertisement
Ads dressed as alerts, updates or content: a "push notification" that is really a promotion, or self-serving search ranking.
Nagging
Repeated, persistent prompts after a refusal: re-asking for cookie consent, blocking exit until an option is chosen.
Trick Wording
Confusing language or double negatives that misdirect: "Uncheck this box if you do not want to receive offers".
What changed from the 2025 Directions
If your framework was built on the Responsible Business Conduct Directions, 2025, these are the moves that matter:
- Advertising, marketing and sale rules, previously sitting under the Undertaking of Financial Services Directions, 2025, are now consolidated into the RBC Directions as a new section (Para 85A to 85ZA for banks).
- New definitions of Dark pattern, Compulsory bundling, Mis-selling, Explicit consent, DSA/DMA & sub-agent and Third-party Product or Service are inserted into the definitions paragraph.
- A brand-new Annex IIA sets out the eleven illustrative dark patterns relevant to banks.
- A companion amendment to the Undertaking of Financial Services Directions redraws agency business and referral services (decoded separately); the two were issued together on 15 June 2026.
- Everything takes effect on 1 January 2027, a runway, not an immediate switch.
What RBI has penalised on conduct & mis-selling
This Amendment takes effect on 1 January 2027, so there is no enforcement under it yet. RBI has, however, long penalised regulated entities under the broader fair-practices and customer-conduct umbrella: mis-selling of third-party products, opaque charges and conduct of recovery/marketing agents. As the tracker fills with FY-relevant actions, the ones citing these failures will appear here.
Background & lineage
RBI has been consolidating entity-wise rulebooks; the Responsible Business Conduct framework is where customer-facing conduct now lives.
- 2023CCPA Guidelines for Prevention and Regulation of Dark Patterns, the consumer-protection baseline RBI now points banks to.
- 2025RBI (Responsible Business Conduct) Directions, 2025 and the companion Undertaking of Financial Services Directions, 2025, issued entity-class-wise.
- 15 Jun 2026RBC Second Amendment Directions, 2026: advertising, marketing, sale, DSA/DMA, dark patterns and mis-selling, across all ten classes; effective 1 Jan 2027.
Knowing the rule is step one
A Code of Conduct, a consent SOP and an agent-handling policy only work if every branch, agent and sub-agent has actually received and acknowledged them.