[By Avinash Kumar]
The author is a student of Dr. RML National Law University.
INTRODUCTION
All it took two and half decades, the internet and digital technology have become the backbone of modern living. Much like the world grew from conventional settings to digital platform-based service, the financial setting worldwide is going through a sweeping revision primarily driven by fast-paced innovation in digital technology. The semblance of conventional brick-mortar banking institutions with the growing distrust ever since the global financial crisis of 2008 is slated to be phased out by advancing FinTech institutions. At the frontline of this changing time are neo-banks, financial service providers breaking new ground in banking services. To grasp what the future of banking will look like in the years to come, this blog points out the current position of neo-banks and a significant opportunity to bridge the credit gap through accessible funding options. It further highlights the current regulation of which neo-banks face operational challenges depending on traditional banks. The paper explores several countries that have dedicated licenses for neo-banks and how the evolution of digital banking has the potential to shape India’s FinTech market.
In general terms, neo-banks are not “banks,” but technology driven Financial Service Providers FSPs that rely on relationships with accredited local banks to provide financial services. They are distinct from traditional banking institutions by exhibiting their digitally exclusive operations and carrying out without storefronts i.e., no physical branch presence. The worldwide unfolding of neo-banks, around 2013-2015 in UK and Germany was rooted mainly by advancing technology, changing customer base especially from Gen Z preferring convenience and personalised experiences and a business model focused on lower interest rates. The global neobank market was worth $ 18.6 billion in 2018 and is expected to accelerate at a compounded annual growth rate (CAGR) of around 46.5% between 2019 and 2026, generating around $394.6 billion by 2026.
India’s financial landscape also mirrors the dynamics of digital transformation seen in other parts of the world. In India neo-banking sector has gained strong momentum with the presence of competitors like Jupiter, Fi Money, Open and Razorpay X. The early emphasis of these banks is not only a market capture approach but also a sign of systemic weakness within the existing banking structure. Consider the TransUnion findings of 2021 which reports more than 160 million consumers were deemed credit underserved in India lacking access to mainstream financial products due to thin credit files or low formal engagement.
The credit inaccessibility is even more burdensome in the Micro Small and Medium Enterprises (MSME) sector. An EY report states that among the 64 million MSMEs, there is an overall finance demand of around $1955 billion. This demand is supported by a leverage ratio of 3.8, i.e, for every $1 they put in equity, they require $3.80 in loans. Yet, only 14% of these MSMEs can secure credit from conventional banking sources.
This leaves an estimated $1,544 billion in the form of debt financing of which nearly 47% MSMEs’ debt demand is unaddressable due to low financial viability. The debt leads them to rely on shadow lenders, charging a higher rate of interest. These gaps have created a shortfall of $819 billion, of which $289 billion is currently backed by private banking institutions. There remains an unmet financial debt of $530 billion offering a window entry point for FinTech companies and Non-Banking Financial Companies (NBFCs).
REGULATORY MECHANISM- THE PARTNERSHIP MODEL
Neobanks in India are not yet licensed by the Reserve Bank of India. Section 22 of the Banking Regulation Act, 1949 stipulates that to conduct bank operations an RBI License is required. With RBI’s “Mobile Banking Transactions in India – Operative Guidelines for Banks (2014)” Circular, the functioning of neobanks is further challenged for Clause 6 specifies physical presence of bank to offer the mobile banking services. These FSPs (neo-banks) partner with RBI-approved banks and NBFCs to deliver banking solutions.
Under this mechanism, the core financial services such as accounts, deposits, and savings instruments are provided by the partner bank or NBFC managing customers’ funds under RBI oversight. To go with that, neo-banks technology driven interface offers a user-centric platform leveraging AI and data analytics for financial services like account opening, payments, expense tracking and personalised insights through mobile and online platforms. This Banking-as-a-Service model outlined in Section 4 (Authorization of Payment Systems) as per the Payment and Settlement Systems Act, 2007 ensures customers’ digital interaction through neo-bank with the core banking operations limited under the purview of licensed partner banks.
Alongside the sector-specific regulation under the RBI, all of this brings a layered “principal-agent” relationship, complicating the division of regulatory duties and liabilities. The lending service provider (the agent) incurs compliance risk and reputational damage if the licensed partner bank (the principal) faces RBI action, and neo-bank services can be abruptly disrupted.
Consider the RBI action against the State Bank of Mauritius back in 2023. The disruption affected Niyo’s international forex services, leaving users stranded without any direct recourse overseas. With the regulatory licensed bank that bore scrutiny, this highlighted neobanks lack direct regulatory oversight for cybersecurity and incident response, relying instead on partner banks, highlighting a compliance and consumer protection gap in the current partnership model.
The Information Technology Act, 2000 highlights the legal recognition of electronic records, electronic signatures and electronic contracts (Sections 4, 5, 10) essential to the paperless operations of neo-banks. Section 43A imposes liability on entities for compensation where the failure to implement reasonable security practices results in the misuse or loss of sensitive personal information. The Act also outlines various cybercrimes i.e, identity theft under Section 66C, punishment for information breach of a lawful contract under Section 72A, and liabilities applicable to neo-banks for security lapses. While neo-banks operate as technological innovation agents in this partnership, it is yet to be determined how they will comply with user data privacy, likely the Digital Data Protection Act, 2023 and AML/KYC regulations over time if granted a license.
Guidelines on Outsourcing of Financial Services by Banks (e.g., Circular dated November 3, 2006) by the RBI mandates licensed banks to retain the responsibility for all outsourced activities i.e., sanctioning loans, investment portfolio management and KYC policy decisions. This regulation delineates the neo-banks’ functioning in the partnership models to the extent that enhancements in service and technology do not compromise the control over key banking decisions and compliance obligations which remain with the licensed institution. The licensed banks are to conduct due diligence through service providers, monitoring their performance and ensuring the confidentiality and security of customer data. The customers’ privacy-centred DPDPA as per Section 8 (obligations of data fiduciaries) also stipulates that FSPs securely safeguard the customers’ data to prevent data breach.
Neo-banks would be required to implement strict data governance frameworks including explicit user consent mechanisms, data localisation where applicable and security protocols to prevent breaches. AML/KYC are traditionally designed around physical documentation and in-person verification, which may pose operational challenges for neo-banks relying heavily on digital onboarding.
HOW THE WORLD IS GRAPPLING WITH REGULATION OF NEO-BANKS?
Europe stands out with a market share of 30% of global neo-banks in 2024. The regulatory structure is built upon the framework mainly of the Payment Services Directive (PSD2) and the General Data Protection Regulation (GDPR) focusing on Strong Customer Authentication (SCA) and secure APIs (e.g., OAuth 2.0, OpenID Connect). This ensures neo-banks offer safe, compliant and user-friendly experience preventing fraud and enabling secure third-party integrations.
The regions in Asia-Pacific are severely underbanked ranging up to 70%. MSMEs comprise 97% of all regional enterprises and employ over 69% of the labour force in these regions. Against this backdrop, this sets the stage for neo-banks to tailor the model to finance the unmet demand and expand financial access.
The State Bank of Pakistan introduced the “Licensing and Regulatory for Digital Banks”. The framework for digital banks outlines the two types of licenses digital banks can be granted, Digital Retail Bank (DRB) caters to only retail customers, offering services like deposits, payments and personal loans restricted to 50% of total bank deposits. Digital Full Bank (DFB) extends its services primarily offering business account and credit facilities to MSMEs and other sectors. The institution must go through the pilot stage (3–9 months) and transitional stage (up to 3 years) securing a minimum capital to apply for DRB license. Upon successful completion of the stages and maintaining a minimum capital threshold of $10 million the financial institution can then attain the status of DFB-certified license. This, in return, ensures financial stability by enforcing strict rules on liquidity, capital adequacy and risk management for digital banks.
Monetary Authority of Singapore has also incorporated the provision of credit serving to individual and businesses under the licensing of Digital Full Bank and Digital Wholesale Bank offering services spanning from retail and corporate banking services to the financial needs of SMEs and wholesale banking clients respectively.
Similarly the Bank of Thailand issued the Virtual Bank Licensing Framework in 2023 for fully virtual banks. The circular sets forth these banks to be registered and headquartered in Thailand undergoing the restricted phase for 3-5 years and grow up to $274 million in assets. These bank functions are split into the categories of Green Line and Red Line. The Green Line refers to the bank operations wholly through technology processing user data especially to tailoring financial service to underserved retail customers and SMEs. Red Line practices are services that these institutions must avoid such as unstable business models or aggressive competition that threatens financial stability.
STRATEGIC OUTLOOK TO THE CURRENT STRUCTURE
Any rapidly evolving FinTech platform as a part of phased assessment has to undergo the RBI’s “Enabling Framework for Regulatory Sandbox”, allowing innovators, FSPs and end users to assess product feasibility by collecting the evidence and monitoring the benefits and risks of these new programs. Even after a successful exit from the sandbox, the final product is not instantly deployed for market adoption. And so the absence of a direct licensing system is a significant challenge for neo-banks. This has been highlighted as a “regulatory vacuum” by policy bodies advocating for a specific digital bank licensing regime.
“Digital Banks- A Proposal for Licensing and Regulatory Regime for India” a report by NITI Aayog proposed a structured three-stage phase against “regulatory vaccum” for licensing digital banks: (i) issuance of a restricted digital bank license (with limitations on on customer volume; (ii) enlistment of these restricted licensees in the RBI’s regulatory sandbox for testing; and (iii) issuance of a full-scale digital bank license based satisfactory performance in the sandbox.” The report also draws a tiered approach to minimum paid-up capital, for example, INR 20 crore for a restricted Digital Business Bank, rising to INR 200 crore for a full-scale license. This risk-based licensing system by the RBI, if followed, would balance innovation with systemic caution through minimum capital thresholds and operational restrictions for neo-banks.
The present partnership model for neo-banks involves high capital costs and does not guarantee entry in the market landscape as fintech service providers. With no clear direction and rationale to independent license, neo-banks may be phased out from making heavy investments in developing their own cutting-edge core banking infrastructure and instead remain reliant on the potential legacy systems of their partner banks. This risks the neo-banks capacity for deep product differentiation constraining their scalability and profitability.
Cybersecurity is also jeopardised in this setup. Neo-banks, not being directly licensed banks, do not fall squarely under the RBI’s comprehensive cybersecurity framework designed for traditional banks. Their heavy reliance on Application Programming Interfaces (APIs) for various services (payments, credit scoring, KYC verification) and the security standards of their numerous vendors (third party bodies mainly data processors) create other vulnerability points. The RBI should consider taking preemptive measures clarifying the roles, responsibilities and liabilities of both licensed banks and neo-bank partners. With the advancing technology at a rapid pace, as we approach toward a future where digital connectivity is universal and banks can operate without their conventional infrastructure, the necessity has grown for regulatory frameworks that is free from the limited standards of brick-and-mortar financial institution. The RBI must come up with a transparent licensing framework for neobanks will account for almost 9% of India’s total fintech market estimated to reach $2 trillion by 2030, empowering them to stay innovative, robust and responsive to the evolving needs of the digital economy.
