Annual NBFC Compliance Checklist for RBI-Registered Companies

blog

Non-Banking Financial Companies (NBFCs) play a significant role in India’s financial sector by providing loans, investment services, asset finance, microfinance, housing finance and other financial facilities. Unlike ordinary companies, NBFCs are governed under both the Companies Act, 2013 and the regulatory framework of the Reserve Bank of India (RBI) under the Reserve Bank of India Act, 1934. Therefore, their compliance responsibilities extend beyond normal corporate filings and include maintaining RBI registration conditions, minimum Net Owned Fund, capital adequacy, asset classification, provisioning, statutory reserves and regulatory reporting.

RBI has introduced the Scale Based Regulation (SBR) Framework, under which NBFCs are classified into Base Layer, Middle Layer, Upper Layer and Top Layer according to their size, activities and systemic importance. Accordingly, compliance requirements may differ for each NBFC. Companies must therefore regularly review RBI returns, KYC and AML requirements, governance standards, customer protection, IT controls, audit requirements and other applicable regulations.

In this article, CA Manish Mishra talks about Annual NBFC Compliance Checklist for RBI-Registered Companies.

Legal Structure Governing NBFC Compliance

The legal structure for NBFC compliance is primarily based on the Reserve Bank of India Act, 1934. Section 45-I defines important terms relating to non-banking financial institutions, while Section 45-IA requires an NBFC to obtain a Certificate of Registration (CoR) from the RBI and maintain the prescribed Net Owned Fund (NOF) before carrying on NBFC business. Sections 45JA, 45K, 45L and 45M empower the RBI to issue directions, regulate financial activities, call for information and require submission of returns. The RBI also has powers relating to auditors and regulatory intervention under Sections 45MA, 45MAA, 45MB and 45MC.

NBFCs must also comply with several other laws alongside RBI regulations. These include the Companies Act, 2013, Prevention of Money Laundering Act, 2002, applicable PMLA Rules, Credit Information Companies (Regulation) Act, 2005, Information Technology laws and FEMA provisions for foreign investments or overseas transactions. Compliance therefore requires continuous monitoring of multiple legal and regulatory requirements.

Determine the Correct NBFC Classification Every Year

Under the RBI’s Scale Based Regulation (SBR) Framework, NBFCs are classified into four layers Base Layer, Middle Layer, Upper Layer and Top Layer based on their size, nature of activities and systemic importance. The Base Layer generally includes non-deposit-taking NBFCs with assets below ₹1,000 crore, along with NBFC-P2P platforms, Account Aggregators and certain other specialised entities. The Middle Layer includes all deposit-taking NBFCs, non-deposit-taking NBFCs with assets of ₹1,000 crore or more, and specified categories such as CICs, HFCs, IFCs and IDF-NBFCs. Upper Layer entities are specifically identified by the RBI based on systemic-risk parameters.

NBFC classification should be reviewed every financial year because changes in asset size, business operations or group structure can result in movement to a higher regulatory layer. Group-level assets may also need to be considered where multiple NBFCs belong to the same group. Therefore, classification should be reassessed after finalising the March 31 financial position and whenever significant structural changes occur.

Continued Validity of the RBI Certificate of Registration

Section 45-IA of the RBI Act requires every NBFC carrying on non-banking financial business to hold a valid Certificate of Registration. Registration should not be treated as a one-time formality. The company must continue satisfying the conditions on which its registration was granted. The annual compliance review should therefore confirm that the company continues to conduct its principal business as a financial institution, maintains the prescribed capital and NOF, has adequate management and governance arrangements and complies with RBI directions.

The RBI has statutory authority to cancel an NBFC's Certificate of Registration for failure to comply with registration conditions, regulatory directions or other requirements specified under Section 45-IA. Management should also verify that the activities actually undertaken by the company fall within its registered NBFC category. An NBFC registered as an Investment and Credit Company should not begin a regulated activity requiring a separate category of registration without obtaining the required regulatory approval.

Verification of Principal Business Conditions

An NBFC should annually verify that it continues satisfying RBI's principal-business criteria. RBI supervision generally evaluates whether financial assets constitute more than 50 per cent of total assets and income from financial assets constitutes more than 50 per cent of gross income, commonly referred to as the "50-50 test", except for categories subject to specialised rules.

This is particularly important where the company has expanded into non-financial activities or derived substantial income from sources outside its registered financial business. The statutory auditor's annual certification and the company's RBI reporting should be supported by a documented computation of the principal-business criteria.

Net Owned Fund Compliance

Minimum Net Owned Fund is a continuing condition of registration under Section 45-IA of the RBI Act. The applicable minimum depends upon the category of the NBFC. Under the Scale Based Regulation, the regulatory minimum NOF for NBFC-ICCs, NBFC-MFIs and NBFC-Factors is being increased to ₹10 crore. Existing NBFC-ICCs were required to reach ₹5 crore by March 31, 2025 and must reach ₹10 crore by March 31, 2027. Existing NBFC-MFIs and NBFC-Factors were required to reach ₹7 crore by March 31, 2025 and ₹10 crore by March 31, 2027. NBFC-P2Ps and NBFC-Account Aggregators continue to have separate prescribed requirements, while specialised categories such as HFCs, IFCs, IDF-NBFCs and Mortgage Guarantee Companies are governed by their respective capital standards.

Accordingly, financial year 2026-27 is particularly important for NBFC-ICCs, NBFC-MFIs and NBFC-Factors that are still operating below ₹10 crore NOF. Such companies should prepare their capital-raising plans sufficiently before the March 31, 2027 deadline. NOF should be calculated according to RBI methodology rather than merely referring to paid-up share capital appearing in the balance sheet. Deductions relating to accumulated losses, intangible assets and specified investments or exposures must be appropriately considered.

Preparation and Approval of Annual Financial Statements

NBFCs must prepare annual financial statements for the financial year ending March 31 in accordance with the Companies Act, applicable Accounting Standards or Indian Accounting Standards and RBI regulatory requirements. Section 134 of the Companies Act requires the financial statements to be approved by the Board of Directors before being signed in the prescribed manner and submitted to the statutory auditor.

The auditor's report must be attached to the financial statements, and the Board's Report must contain the disclosures required under the Companies Act and other applicable regulations. For an NBFC, financial statement preparation should involve detailed reconciliation of the loan book, investment portfolio, borrowings, NPAs, provisions, securitisation transactions, related-party exposures, contingent liabilities and regulatory capital. Figures reported to the RBI through CIMS should be reconciled with the company's accounting records and audited financial statements.

Statutory Audit and RBI-Specific Auditor Responsibilities

Every NBFC must undergo statutory audit in accordance with the Companies Act. In addition to normal company-law audit requirements, the statutory auditor of an NBFC has important responsibilities concerning RBI compliance. The auditor should examine the company's registration status, principal-business criteria, asset and income pattern, NOF, acceptance of deposits, prudential compliance and other matters specified under RBI directions.

Any material regulatory breach discovered during audit should be appropriately dealt with in accordance with the applicable auditor-reporting requirements. NBFCs should therefore maintain a comprehensive regulatory audit file containing RBI returns, CIMS acknowledgements, NOF computations, capital-adequacy calculations, NPA reports, provisioning statements, Board-approved policies and regulatory correspondence.

DNBS10 – Annual Statutory Auditor Certificate

The RBI's current list of supervisory returns identifies DNBS10 Statutory Auditor Certificate Return as an annual return applicable to all NBFCs and ARCs. Its regulatory objective is to ensure continued compliance with the requirements applicable to RBI-regulated entities. Accordingly, every RBI-registered NBFC should coordinate with its statutory auditor for preparation of the prescribed certificate after completion of the annual audit and ensure that the required return is submitted through CIMS within the applicable reporting timeline.

DNBS02 – Annual Important Financial Parameters Return

The current RBI supervisory-return identifies DNBS02 Important Financial Parameters Annual for non-deposit-taking non-NDSI NBFCs falling within the specified reporting category. The return contains important financial information relating to assets and liabilities and compliance with prudential requirements. Because RBI's present Scale Based Regulation terminology uses Base, Middle, Upper and Top Layers while some reporting descriptions continue to use earlier terms such as NDSI, an NBFC should rely on its actual CIMS mapping and RBI reporting applicability rather than assuming that terminology alone determines the return.

Other RBI Supervisory Returns

Annual compliance cannot be completed merely by filing DNBS10 or DNBS02. The RBI's current reporting framework contains numerous periodic returns depending upon the category, asset size and activities of the company. DNBS01 captures important financial parameters on a quarterly basis for specified deposit-taking and larger NBFCs. DNBS03 captures capital adequacy, asset classification, provisioning, NOF and other prudential parameters. DNBS04A deals with short-term dynamic liquidity, while DNBS04B captures structural liquidity and interest-rate sensitivity.

DNBS08 is the monthly CRILC main return for specified NBFCs having reportable large exposures, and DNBS09 concerns weekly reporting of defaults falling within its applicability criteria. DNBS11 and DNBS12 apply to Core Investment Companies, DNBS13 captures overseas investments, and DNBS14 applies to NBFC-P2Ps. Therefore, an annual compliance review should include an audit of every return filed during the year and not merely returns carrying an "annual" frequency.

RBI Filing Timelines under the Supervisory Returns Directions

The Master Direction Reserve Bank of India (Filing of Supervisory Returns) Directions, 2024 harmonised the filing framework for supervisory returns. Unless an alternative timeline applies to a particular return, weekly returns are generally due by Wednesday of the following week, fortnightly returns within seven days from the reference date, monthly returns within fifteen days, quarterly and half-yearly returns within twenty-one days and yearly returns referenced to March 31 within twenty-one days.

Audited returns, wherever applicable, are generally required to be filed within five working days from signing of the auditor's report, subject to return-specific requirements. The Directions also require accurate and complete data, reconciliation with accounting records and appropriate data-governance systems. Incorrect or delayed filings may lead to regulatory action and monetary penalties.

Form A Relating to Appointment of Statutory Auditor

The RBI's current return list also contains Form A Certificate, through which NBFCs submit information relating to appointment of their Statutory Central Auditor or Statutory Auditor. The filing is shown as an annual requirement applicable to all NBFCs. Before appointment or reappointment, the NBFC should verify auditor eligibility, independence, tenure and rotation requirements under the Companies Act and RBI guidelines.

Statutory Reserve under Section 45-IC of the RBI Act

Section 45-IC of the Reserve Bank of India Act requires every NBFC, unless specifically exempted, to create a reserve fund and transfer to it not less than twenty per cent of its net profit every year before declaration of dividend. This statutory reserve should be distinguished from an ordinary general reserve. Appropriation from the reserve is restricted, and any permissible withdrawal must be reported to the RBI within the statutory period. Accordingly, the transfer should be calculated before the Board considers the dividend proposal.

Capital Adequacy and Leverage Review

Capital adequacy is a major prudential requirement for larger and specialised NBFCs. NBFCs falling in the Middle and Upper Layers are generally required to maintain the prescribed Capital to Risk-Weighted Assets Ratio and Tier-I capital requirements, subject to activity-specific variations. The Scale Based Regulation requires NBFC-ML and NBFC-UL entities to operate under strengthened capital standards.

Upper Layer NBFCs are also required to maintain Common Equity Tier 1 capital of at least 9 per cent of risk-weighted assets. Capital ratios should be reviewed throughout the year because losses, rapid growth in lending, changes in risk-weighted assets or distributions to shareholders may cause regulatory ratios to fall below prescribed levels even if nominal share capital remains unchanged.

Internal Capital Adequacy Assessment Process

NBFCs in the Middle and Upper Layers are required to undertake an Internal Capital Adequacy Assessment Process proportionate to the scale and complexity of their operations. ICAAP requires management to evaluate whether available capital is adequate to cover not merely minimum regulatory credit risk but also market risk, operational risk and other residual risks. The assessment methodology should be governed by a Board-approved policy.

An annual ICAAP should therefore assess business growth, concentration risk, liquidity risk, cybersecurity risk, operational failures, outsourcing risk and other significant exposures and should be considered as part of the company's capital planning process.

NPA Classification and Income Recognition

Correct classification of stressed assets is fundamental to NBFC prudential compliance. Under the Scale Based Regulation framework, RBI introduced a glide path for Base Layer NBFCs to move to the 90-day NPA classification standard. The final stage of that glide path became effective by March 31, 2026, when applicable Base Layer NBFCs were required to adopt the more-than-90-days overdue NPA criterion.

Consequently, for financial year 2026-27, NBFC systems should already be configured to identify applicable NPAs under the 90-day framework. Annual audit procedures should verify overdue calculations, interest recognition, asset upgrades, restructuring, write-offs and provisioning.

Provisioning Requirements

NBFCs should create provisions for standard assets and non-performing assets in accordance with the regulatory requirements applicable to their layer and category. Provisioning should be calculated on the regulatory classification of the asset rather than merely on the company's internal assessment of recoverability.

Provisioning calculations should be reconciled with the loan management system, general ledger, audited financial statements and prudential returns submitted to the RBI. Any divergence between management classification and auditor or RBI assessment can have implications for profit, capital adequacy and regulatory reporting.

Concentration of Credit and Investment

Middle and Upper Layer NBFCs must monitor exposure concentration under RBI prudential norms. The Scale Based Regulation framework introduced consolidated exposure limits of 25 per cent of Tier-I capital for a single borrower or party and 40 per cent for a single group of borrowers or parties for the relevant NBFC categories, subject to applicable exceptions and specialised regulations.

NBFCs should also maintain Board-approved internal limits for sensitive-sector exposures, particularly capital markets and commercial real estate. Upper Layer NBFCs are subject to enhanced large-exposure requirements. Annual compliance testing should examine whether any exposure became non-compliant because of a fall in capital, restructuring of the borrower group or changes in connected-party relationships.

Corporate Governance and Board Composition

RBI's Scale Based Regulation framework places significant emphasis on governance. At least one director should possess relevant experience of having worked in a bank or NBFC. Risk Management Committees are required under the applicable framework, while larger NBFCs are also subject to enhanced Audit Committee, Nomination and Remuneration Committee and governance requirements. The annual Board review should examine director qualifications, independence, conflicts of interest, attendance, fit-and-proper declarations and committee effectiveness.

Middle and Upper Layer NBFCs must also observe restrictions concerning certain key managerial personnel and independent directors serving on other NBFC boards. The Board should maintain a calendar specifying matters to be reviewed by each committee and should ensure functioning of an effective whistle-blower mechanism.

Chief Compliance Officer and Independent Compliance Function

RBI requires NBFCs in the Middle and Upper Layers to maintain an independent Compliance Function headed by a Chief Compliance Officer. The CCO should occupy an appropriately senior position and the organisation should maintain a Board-approved compliance policy.

The annual compliance exercise should assess the effectiveness and independence of the compliance function, regulatory breaches during the year, status of corrective actions, regulatory-change implementation and communication of significant compliance risks to the Board. Compliance should not operate merely as a return-filing department. The function should participate in new products, outsourcing arrangements, policy changes and regulatory risk assessment.

Companies Act Board Meetings

Section 173 of the Companies Act generally requires every company to hold at least four Board meetings every year with not more than 120 days between two consecutive meetings, subject to statutory exceptions applicable to certain classes of companies. For an NBFC, Board meetings should cover more than ordinary corporate matters. The agenda should periodically include capital adequacy, asset quality, liquidity, regulatory returns, customer grievances, KYC/AML compliance, internal audit, cybersecurity and significant regulatory developments.

Annual General Meeting

Section 96 of the Companies Act requires every company, other than an OPC, to hold an Annual General Meeting within the prescribed period. Ordinarily, the AGM must be held within six months from the end of the financial year, subject to the maximum interval between two AGMs and other statutory requirements. At the AGM, shareholders consider the audited financial statements, Board's Report, auditor matters and other ordinary or special business as applicable.

Filing of Financial Statements through AOC-4

Section 137 of the Companies Act requires a copy of the financial statements and prescribed accompanying documents to be filed with the Registrar within thirty days of the AGM. The applicable AOC-4 form should be determined according to whether the company is subject to Ind AS, consolidated financial statement requirements, XBRL filing or other MCA classification. Because RBI-regulated companies may have extensive financial disclosures, the figures submitted through MCA filings should be consistent with the audited accounts and RBI reporting.

Filing of Annual Return through MGT-7

Section 92 of the Companies Act requires every company to prepare an annual return containing information regarding its registered office, business activities, securities, shareholding, promoters, directors, key managerial personnel, meetings and other prescribed particulars. The annual return must generally be filed with the Registrar within 60 days from the date of the AGM. The appropriate form is ordinarily MGT-7, subject to any specific form permitted for eligible classes of companies. Where the prescribed capital or turnover thresholds are met, certification by a practising company secretary may also be required.

Other MCA Compliance Applicable to NBFCs

Depending on the company's circumstances, other filings may include DPT-3 relating to outstanding money or loans not treated as deposits under the Companies Act framework, MSME-1 for outstanding dues to qualifying micro or small enterprises, PAS-6 for reconciliation of share capital where applicable, BEN-2 for significant beneficial ownership reporting and filings relating to changes in directors, charges, share allotments or registered-office particulars. Such filings are not unique to NBFCs but remain mandatory because RBI registration does not exempt the company from the Companies Act.

Loans to Directors, Senior Officers and Related Parties

The Scale Based Regulation framework imposes restrictions and governance requirements concerning loans and advances to directors, their relatives, senior officers and entities in which such persons have specified interests. Base Layer NBFCs are expected to have a Board-approved policy concerning loans to directors, senior officers, relatives of directors and entities in which directors or their relatives hold major shareholding. Middle and Upper Layer NBFCs are subject to stronger regulatory restrictions. The company must simultaneously consider Sections 184, 185, 186 and 188 of the Companies Act relating to disclosure of interest, loans to directors, loans and investments and related-party transactions.

KYC Compliance

Every customer-facing NBFC is required to comply with the RBI Master Direction on Know Your Customer and the Prevention of Money Laundering. KYC compliance includes Customer Due Diligence, identification of beneficial owners, risk categorisation, periodic updation, sanctions screening, monitoring of transactions, record retention and implementation of appropriate AML controls.

RBI amended the KYC framework in June 2025. One important change required regulated entities to send at least three advance intimations before periodic KYC becomes due and at least three reminders after the due date, with at least one communication in each category being sent by letter. These communication requirements were required to be operationalised not later than January 1, 2026. The 2025 amendment also provided specific relief for low-risk individual customers regarding periodic updation of KYC. Since these amendments now form part of the operational compliance environment for FY 2026-27, NBFCs should ensure that their systems maintain proper audit trails for KYC notices and reminders.

Prevention of Money Laundering Act Compliance

NBFCs qualify as reporting entities for relevant purposes under the Prevention of Money Laundering framework. Section 12 of the PMLA requires reporting entities to maintain transaction records, furnish prescribed information and maintain records relating to customer and beneficial-owner identity. Transaction records are required to be maintained for the prescribed statutory period.

NBFCs should have appropriate arrangements for the Principal Officer and Designated Director, transaction monitoring, identification of suspicious transactions and reporting to FIU-IND. Annual testing should assess whether AML alerts were properly investigated, whether suspicious activity was escalated independently and whether prescribed reports were filed within applicable timelines.

Credit Information Company Reporting

Lending NBFCs covered by the Credit Information Companies framework must submit accurate credit information to credit bureaus and establish mechanisms for handling customer disputes. The RBI has moved towards more frequent credit-information updating, requiring credit institutions to submit information on a fortnightly basis, thereby reducing the delay between repayment activity and reflection in the borrower's credit record. Annual compliance should examine rejected records, incorrect reporting of closed accounts, delays in updating borrower status and unresolved CIC-related complaints.

Fair Practices Code

Every lending NBFC should maintain and implement a Board-approved Fair Practices Code appropriate to its business. The code should address transparent loan processing, communication of terms, interest calculation, fees and charges, changes in terms, recovery practices and grievance handling. Loan documents should communicate the annualised rate of interest and other material terms in a language understood by the borrower. The Board should periodically review implementation of the Fair Practices Code and customer complaints rather than merely approving the policy once.

Key Facts Statement for Loans and Advances

RBI's Key Facts Statement applies to specified retail and MSME term loans provided by regulated entities. The KFS is intended to provide borrowers with a simple statement of material loan terms and the all-inclusive cost of borrowing.

RBI's 2024 instructions require applicable regulated entities to provide a KFS containing prescribed information including the Annual Percentage Rate. RBI's Digital Lending Directions, 2025 expressly incorporate the KFS requirement for digital lending. NBFCs should test whether applicable loan files contain a properly issued KFS and whether fees or charges collected from the customer were disclosed upfront.

Penal Charges in Loan Accounts

RBI has prohibited regulated entities from disguising borrower penalties as additional interest. Where a penalty is levied for non-compliance with material loan terms, it should be treated as a penal charge rather than penal interest added to the rate of interest.

There should be no capitalisation of penal charges. The quantum should be reasonable and governed by a Board-approved policy, and the amount and reason should be transparently disclosed in loan documents and the KFS where applicable. An annual sample review of loan accounts should verify that penal charges have not been compounded or imposed contrary to approved policy.

Pre-payment Charges – Important 2026 Update

One of the important developments affecting NBFCs in 2026 is the Reserve Bank of India (Pre-payment Charges on Loans) Directions, 2025, which apply to loans and advances sanctioned or renewed on or after January 1, 2026. Under these Directions, regulated entities cannot levy pre-payment charges on floating-rate loans granted to individuals for non-business purposes. For business-purpose floating-rate loans to individuals and Micro and Small Enterprises, restrictions vary according to the regulatory category of the lender.

NBFC-UL entities cannot levy such charges, while NBFC-ML entities are prohibited from levying them on covered loans with sanctioned amount or limit up to ₹50 lakh. The restrictions operate irrespective of the source from which the borrower obtains the funds used for prepayment and without a minimum lock-in period. The applicability of pre-payment charges must also be transparently disclosed in the sanction letter, loan agreement and KFS where applicable. Accordingly, NBFCs should ensure that loan templates, product policies and system configurations introduced from January 1, 2026 comply with this updated framework.

Digital Lending Compliance – RBI Directions, 2025

NBFCs conducting digital lending must comply with the Reserve Bank of India (Digital Lending) Directions, 2025, issued on May 8, 2025. These Directions apply to digital lending activities of all NBFCs including Housing Finance Companies. Where an NBFC uses a Lending Service Provider, the relationship must be governed by a contractual agreement and the NBFC must conduct enhanced due diligence covering the LSP's technical capability, data privacy, borrower conduct and regulatory compliance. Outsourcing does not reduce the NBFC's regulatory responsibility; the regulated entity remains responsible for acts and omissions of the LSP.

The Directions also regulate multiple-lender digital platforms. Loan offers displayed to borrowers must contain sufficient information for fair comparison, including lender name, amount, tenor, APR, repayment obligation and penal charges. Platforms must not use dark or deceptive patterns to push borrowers toward a particular lender. Customer data collection must be need-based and supported by prior explicit consent. Access to mobile resources such as contact lists, call logs and files is restricted. The Directions also require grievance-redress arrangements and reporting of Digital Lending Apps to the RBI through CIMS. The CCO or another Board-designated official must certify the correctness and regulatory compliance of DLA information reported to RBI.

Information Technology Governance and Cybersecurity

Technology risk has become a major component of RBI supervision. The RBI's IT Governance, Risk, Controls and Assurance Practices Directions apply to covered NBFCs in the Middle, Upper and Top Layers and prescribe governance standards for information systems, cyber risk, business continuity and IT audit.

Applicable NBFCs should maintain Board-level oversight of IT risk, information-security policies, business-continuity and disaster-recovery arrangements, access controls, cyber-incident response and independent IS audit. Even NBFCs outside the direct applicability of a particular IT Master Direction should maintain security controls proportionate to the sensitivity of customer and financial information handled.

Outsourcing Compliance

NBFCs frequently outsource customer acquisition, collection, technology, verification, call-centre operations and other functions. Regulatory responsibility, however, remains with the NBFC. Contracts with service providers should contain confidentiality, audit access, data security, business continuity, performance and termination provisions.

The NBFC should conduct due diligence before onboarding material service providers and periodically review their performance. Outsourcing arrangements involving recovery agents require particular attention because RBI expects regulated entities to ensure that agents do not engage in intimidation, harassment or inappropriate recovery behaviour.

Fraud Risk Management

RBI issued updated Master Directions on Fraud Risk Management in NBFCs, including Housing Finance Companies, in 2024. The applies according to the categories and asset thresholds prescribed in those Directions and strengthens Board oversight, early-warning arrangements and reporting of fraud. Applicable NBFCs should maintain a Board-approved fraud-risk management policy, examine fraud incidents and early-warning signals, fix staff accountability where necessary and preserve appropriate reporting and investigation records. The annual compliance review should reconcile fraud cases reported to regulators with the company's accounting records and disclosures.

Risk Management Committee

Scale Based Regulation requires NBFCs to maintain an appropriate Risk Management Committee. The committee may exist at Board or executive level according to the applicable requirements and should evaluate the overall risks faced by the NBFC, including liquidity risk. During the year, the RMC should receive meaningful information on credit, concentration, liquidity, market, operational, technology, compliance and fraud risk. Annual review of committee effectiveness should examine whether identified risks actually resulted in corrective actions.

Internal Audit

An effective internal-audit system is an essential component of NBFC compliance. Internal audit should periodically test lending operations, documentation, KYC, AML, asset classification, provisioning, customer complaints, recovery practices, IT controls, outsourcing, regulatory reporting and branch operations. Audit findings should be classified according to risk and tracked until closure. Repeated findings should be escalated to the Audit Committee or Board because persistent control failures may indicate systemic weaknesses.

Customer Grievance Redressal and RBI Ombudsman

NBFCs with customer interface should maintain an effective internal grievance-redress mechanism and designate responsible officers. Where the entity is covered by the Reserve Bank Integrated Ombudsman Scheme, eligible customers may approach the RBI where a complaint is rejected, not satisfactorily resolved or remains unanswered within the prescribed period.

For digital lending, the 2025 Directions specifically require the NBFC and customer-facing LSP to designate nodal grievance-redress officers and make their details prominently available. Where a complaint is not satisfactorily resolved within 30 days, the borrower may access the RBI Complaint Management System subject to the Ombudsman framework.

Acceptance of Public Deposits

An NBFC cannot accept public deposits merely because it holds an RBI Certificate of Registration. Only NBFCs specifically authorised to accept public deposits may do so, and they are governed by the RBI's public-deposit directions.

Deposit-taking NBFCs have additional obligations concerning permissible deposit amounts, maturity periods, interest, credit ratings, liquid assets, advertisements, repayment, nominations and regulatory returns. The RBI's Master Direction on acceptance of public deposits continues to regulate these entities. A non-deposit-taking NBFC should annually examine the nature of all receipts and borrowings to ensure that none has inadvertently become an impermissible public deposit.

Maintenance of Liquid Assets by Deposit-Taking NBFCs

Section 45-IB of the RBI Act and RBI directions impose liquid-asset requirements on NBFCs accepting public deposits. Applicable NBFCs must maintain the required proportion of assets in prescribed forms and should continuously monitor whether those securities remain unencumbered and otherwise compliant. Year-end audit should reconcile the statutory liquid assets with deposit liabilities and relevant RBI returns.

Overseas Investment and FEMA Compliance

NBFCs having overseas investments are subject to additional RBI reporting. The current supervisory return list includes DNBS13 – Overseas Investment Details, which is filed quarterly by NBFCs having overseas investment. Companies should also comply with the applicable Overseas Investment framework under FEMA, including approval, reporting, valuation, guarantees and funding conditions. Foreign investment received by the NBFC should likewise be examined under India's foreign investment policy and FEMA reporting requirements.

Related Party and Group Exposure Review

NBFCs frequently operate within large corporate or financial groups. Group exposures can create concentration and connected-lending risk. Annual compliance should identify related parties under both accounting and company-law standards and reconcile them with RBI definitions applicable to connected entities, borrowers and counterparties. Board approval, disclosure and exposure limits should be examined independently rather than assuming that compliance under the Companies Act automatically satisfies RBI requirements.

Policy Review

An NBFC typically maintains several Board-approved policies, including its Credit Policy, Fair Practices Code, Interest Rate Policy, KYC/AML Policy, Risk Management Policy, Asset-Liability Management Policy, Recovery Policy, Outsourcing Policy, IT and Information Security Policy, Fraud Risk Management Policy, Related Party Policy and Customer Grievance Policy. The annual compliance exercise should verify whether each policy was reviewed within the frequency prescribed by the applicable regulation or the policy itself. Regulatory amendments should be incorporated promptly rather than waiting for the next scheduled annual review.

Maintenance of Statutory and Regulatory Records

Proper documentation is critical during RBI inspection. The NBFC should maintain evidence of regulatory compliance including Board and committee minutes, CIMS acknowledgements, audit reports, NOF calculations, CRAR workings, provisioning schedules, KYC files, FIU acknowledgements, credit-bureau reports, complaint registers, outsourcing agreements and policy approvals. The RBI's Supervisory Returns Directions specifically emphasise accuracy, reconciliation and proper data architecture for regulatory reporting.

Regulatory Change Management

NBFC regulation is continuously evolving. A compliance calendar prepared several years earlier cannot safely be reused without review. A regulatory-change register should record every relevant RBI circular, notification or Master Direction amendment, its effective date, applicability, responsible department and implementation status. During 2025 and 2026, particularly important developments included the Digital Lending Directions, the KYC amendments, the new pre-payment charge framework and full transition of applicable Base Layer NBFCs to the 90-day NPA classification norm.

Annual Compliance Review for FY 2026-27

For financial year 2026-27, RBI-registered companies should give particular attention to several regulatory milestones. Applicable NBFC-ICCs, NBFC-MFIs and NBFC-Factors should ensure readiness to meet the ₹10 crore NOF requirement by March 31, 2027. Base Layer NBFCs covered by the NPA transition should already be operating under the 90-day overdue standard following completion of the glide path on March 31, 2026.

Lending NBFCs should also ensure that loans sanctioned or renewed from January 1, 2026 comply with the RBI's 2025 Pre-payment Charges Directions. Digital lenders must ensure full implementation of the 2025 Digital Lending Directions, including LSP governance, DLA reporting, borrower disclosures and data controls. KYC systems should incorporate the enhanced communication and audit-trail requirements introduced through the June 2025 amendment.

Penalties of Non-Compliance

Failure to comply with RBI requirements can have significantly greater consequences than ordinary corporate filing defaults. The RBI may impose monetary penalties for violations of supervisory-return requirements and other directions. The Supervisory Returns Directions expressly require regulated entities to furnish correct and true information within the prescribed timelines and permit RBI to take action for violations.

Serious or repeated non-compliance may result in supervisory restrictions, limitations on lending or expansion, requirements to strengthen capital or governance, prohibition on acceptance of deposits, regulatory directions to management and, in extreme cases, cancellation of the Certificate of Registration. Separate penalties may arise under the Companies Act, PMLA, FEMA, CICRA and other applicable laws.

Importance of an Annual NBFC Compliance Checklist

A properly designed NBFC compliance checklist creates accountability within the organisation. Every regulatory requirement should have an identified compliance owner, reviewer, filing frequency, statutory deadline and documentary evidence. The compliance calendar should cover annual, half-yearly, quarterly, monthly, fortnightly, weekly and event-based requirements.

This is important because many serious NBFC obligations, including credit reporting, CRILC reporting, liquidity reporting and AML monitoring, occur more frequently than once a year. Management should receive periodic compliance dashboards showing completed filings, upcoming deadlines, breaches, audit observations and regulatory changes. Material compliance failures should be escalated promptly rather than waiting for the year-end audit.

Conclusion

Annual compliance for RBI-registered NBFCs is a continuous regulatory responsibility that extends beyond ROC filings and preparation of audited financial statements. Every NBFC must maintain the conditions of its Certificate of Registration, prescribed Net Owned Fund (NOF), capital adequacy, proper NPA classification and provisioning, RBI reporting, governance standards and customer-protection requirements. Under the Scale Based Regulation Framework, compliance obligations increase according to the NBFC’s size and systemic importance, with Middle and Upper Layer NBFCs facing stricter requirements relating to ICAAP, risk management, governance, technology and supervisory controls.

For FY 2026-27, NBFCs should closely monitor important regulatory developments, including the ₹10 crore NOF requirement applicable to specified NBFC categories by March 31, 2027, the 90-day NPA classification standard, updated KYC requirements, the RBI Digital Lending Directions, 2025, and the Pre-payment Charges on Loans Directions applicable from January 1, 2026. Regular audits, Board oversight and continuous monitoring of RBI updates are essential for effective compliance.

Frequently Asked Questions (FAQs)

Q1. What is annual NBFC compliance?

Ans. Annual NBFC compliance refers to the regulatory, financial and corporate obligations that an RBI-registered NBFC must fulfil each year. It includes RBI returns, statutory audit, financial statements, Net Owned Fund requirements, prudential norms, KYC compliance, governance and Companies Act filings.

Q2. Which laws primarily govern NBFC compliance in India?

Ans. NBFCs are primarily governed by the Reserve Bank of India Act, 1934, Companies Act, 2013, RBI Master Directions and Scale Based Regulation framework. Depending on activities, PMLA, FEMA, CICRA, Information Technology laws and other sector-specific regulations may also apply.

Q3. What is the Scale Based Regulation framework for NBFCs?

Ans. The Scale Based Regulation framework classifies NBFCs into Base, Middle, Upper and Top Layers based on size, activities and systemic risk. Regulatory requirements become progressively stricter for higher layers, particularly regarding capital adequacy, governance, risk management and supervisory oversight.

Q4. Is maintaining Net Owned Fund mandatory for NBFCs?

Ans. Yes. An NBFC must continuously maintain the minimum Net Owned Fund prescribed by the RBI for its category. Certain NBFC-ICCs, NBFC-MFIs and NBFC-Factors are required to achieve the applicable ₹10 crore NOF requirement by March 31, 2027.

Q5. What is DNBS10 and who is required to file it?

Ans. DNBS10 is the Statutory Auditor Certificate return prescribed under the RBI supervisory reporting framework. It helps confirm continued regulatory compliance of the NBFC. RBI-registered NBFCs should determine the applicable filing requirements and submit the return through the prescribed RBI reporting system.

Q6. Are NBFCs required to create a statutory reserve?

Ans. Yes. Under Section 45-IC of the RBI Act, an NBFC generally must transfer at least 20% of its net profit to a statutory reserve before declaring dividend, subject to applicable exemptions. Withdrawal from this reserve is also subject to RBI conditions.

Q7. What is the NPA classification requirement for NBFCs?

Ans. NBFCs must classify loan accounts as non-performing assets according to RBI prudential norms. Applicable Base Layer NBFCs have transitioned to the 90-day overdue standard. Correct classification is important because it directly affects income recognition, provisioning, profitability and regulatory capital calculations.

Q8. What KYC and AML compliances must NBFCs follow?

Ans. NBFCs must comply with RBI KYC Directions and the Prevention of Money Laundering framework. They must undertake customer due diligence, identify beneficial owners, conduct risk categorisation, monitor transactions, maintain records, update KYC information periodically and report prescribed transactions to FIU-IND.

Q9. What annual Companies Act filings are applicable to an NBFC?

Ans. An NBFC must comply with normal corporate annual filings under the Companies Act, including filing financial statements through the applicable AOC-4 form and annual return through MGT-7 or another applicable form. Other filings may apply depending on company circumstances.

Q10. Why should an NBFC maintain a compliance calendar?

Ans. A compliance calendar helps an NBFC track annual, quarterly, monthly, fortnightly, weekly and event-based obligations. It assigns responsibilities, monitors deadlines and ensures proper documentation. Continuous monitoring reduces filing delays, regulatory breaches, penalties and the risk of adverse RBI supervisory action.

CA Manish Mishra is the Co-Founder & CEO at GenZCFO. He is the most sought professional for providing virtual CFO services to startups and established businesses across diverse sectors, such as retail, manufacturing, food, and financial services with over 20 years of experience including strategic financial planning, regulatory compliance, fundraising and M&A.