Banking Law

Customer Suitability and Bank Liability: A Review of the RBI’s Marketing Directions

[By Neha Lodha and Vivek Kumar] Ms. Neha Lodha is a Team Lead and Mr. Vivek Kumar is a Research Fellow at the Vidhi Centre for Legal Policy. Introduction In February 2026, the Reserve Bank of India (“RBI”) issued the Draft Amendment Directions for ‘Advertising, Marketing and Sales of Financial Products and Services by Regulated Entities’ (“Directions”) covering various aspects relating to marketing and sale of financial products and services. One of the central goals of these directions is to prevent mis-selling of financial products and services by ensuring the suitability and appropriateness of financial products and services for the customer. Though the Directions are a significant step towards protecting consumer interests in the banking sector, certain provisions may need revisiting in order to ensure a balance between protection of consumer interest and efficient conduct of financial activities by regulated entities (“REs”), which include banks and non-banking financial companies. This article aims to analyse certain provisions of the Directions in light of international practices and the existing jurisprudence around seller liability to suggest a balanced approach to the requirement of customer suitability assessment. The Directions define mis-selling as, inter alia, “sale of a product/service, which is neither suitable nor appropriate in view of the customer’s profile even if with his/her explicit consent;” In pursuance of this, the Directions explicitly require an RE to ensure the suitability and appropriateness of a financial product or service by analysing the features of such products and services against the customers profile, before they are marketed or sold to a customer. The requirement of customer suitability assessment is aimed at addressing the increasing customer complaints around aggressive marketing strategies and mis-selling by REs. However, to adopt a balanced approach, the scope of liability of REs may be circumscribed by providing the following: (i) distinction between retail and non-retail customers to calibrate compliances with the level of customer’s sophistication and knowledge, (ii) a graded approach to suitability assessment to link it with complexity of the product and the risk involved, and (iii) differentiation between solicited and unsolicited sales to recognise a greater reliance of customers on the recommendations or advice provided by an entity. (i)  Distinction between retail and non-retail customers The Directions provide for customer suitability assessment as a blanket requirement across all classes of customers, without regard to the expertise or sophistication of the customer. IOSCO’s Report on Suitability Requirements with Respect to the Distribution of Complex Financial Products (“IOSCO Report”) includes ‘Classification of Customers’ as its first principle and advises regulatory systems to establish a process to distinguish between retail and non-retail customers, in light of the complexity and the relative risk of different products, when assessing suitability. The EU Markets in Financial Instruments Directive 2014 (“MiFID II”) also follows this approach and provides, “Measures to protect investors should be adapted to the particularities of each category of investors (retail, professional and counterparties).” It is also relevant to mention that the distinction between retail and institutional/professional customers is well established in Indian jurisprudence. The Delhi High Court’s judgment in the case of Punjab National Bank v. Kohinoor Foods is a case in point. In this case, the respondent alleged mis-selling of certain derivative transaction by the petitioner on the ground that the said derivative transactions were entered into even though the risks involved were not commensurate with the respondent’s business, financial operations, skill and sophistication, internal policy and risk appetite and that the petitioner failed to carry out a proper due diligence, concerning user appropriateness, or suitability of the product qua the respondent. However, the Delhi HC ruled on the contrary, denying any allegation of mis-selling or fraud on the ground that the respondent was a sophisticated customer who routinely entered into such transactions and that he had consented to the transaction after understanding the impact of the transaction. Past experiences in financial markets also indicate that retail customers are more susceptible to mis-selling than non-retail customers, entailing a greater level of protection. The insurance sector alone saw 1,20,429 grievances regarding unfair business practices by insurance providers in FY24-25. However, a blanket requirement may be too onerous and may lead to high operational costs for REs. Further, the definition of mis-selling under the Directions includes the sale of an unsuitable or inappropriate product, even with the consent of the customer. In essence, this confers upon the RE a veto power, transforming a tool for the protection of retail customers into a restraint on a customer’s freedom to deal with certain financial products, even if they are willing to take the risks associated with such products or services. This is in sharp contrast to the position in the USA, where institutional investors are allowed to waive suitability assessment by indicating that it is exercising independent judgment. Thus, there is a need to recalibrate the requirement for suitability assessment for different categories of customers. (ii) Graded approach to suitability assessment To ensure compliance and avoid onerous obligations on REs, it is necessary that suitability assessment requirements are proportionate to the complexity of the product and the risk involved in dealing with such products. It would not be appropriate to mandate the same suitability assessment requirements for both non-complex products with minimum risk and complex products with high-risk profiles. Therefore, the Directions should provide for a graded approach commensurate with the level of complexity and risk involved in sale of such products, instead of blanket suitability assessment requirements. In contrast to the Directions, MiFID II follows a graded approach concerning suitability assessment. While article 25(2) provides that investment advice or portfolio management services to retail customers have to be suitable, requiring a written statement on suitability, as per article 25(3), other services only entail an assessment of whether a product or service is appropriate. Further, article 25(4) allows firms to skip such assessment entirely for certain non-complex products, including in situations where the service is provided at the initiative of the client or potential client. It is apposite to mention that the RBI (Non-Banking Financial

Customer Suitability and Bank Liability: A Review of the RBI’s Marketing Directions Read More »

Reconciling the Overlap: Sarfaesi’s Sections 13(4) & 13(8) v. Ibc’s Moratorium Under Section 14

[By Nimish Maheshwari] The author is a student of National Law Institute Jodhpur 1.Introduction One of the salient aspects that makes Insolvency and Bankruptcy Code (‘IBC’), 2016 stand out from the other debt recovery mechanisms is its overriding effect over any other law where there is overlap. For instance, the IBC takes precedence over The Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002 (‘SARFAESI’). Consequently, where there are proceedings under the SARFAESI Act and a Corporate Insolvency Resolution Process (‘CIRP’) has commenced under Sections 7, 9, or 10 of the IBC, imposition of the moratorium would lead to suspension of proceedings under SARFAESI. In Rakesh Kumar Gupta v. Mahesh Bansal the court relied on Section 238 of IBC to hold that the pendency of proceedings under the Sarfaesi Act would not obstruct the courts from allowing an application under Section 7 of the IBC. This position has also been consistently upheld in relation to Section 13(4) of the SARFAESI also. It has been recognised that any action to foreclose, recover or enforce a security interest created by the corporate debtor in respect of its property including any action under the SARFAESI Act is prohibited due to the overriding power of Section 14(1)(c) of IBC. For example, even where a bank, in exercise of its power under Section 13(4) of the SARFAESI Act, read with Rule 8 of the Security Interest (Enforcement) Rules, 2002 (‘Rules’) has taken symbolic possession of secured assets mortgaged exclusively with it and proceeded to auction those assets and receive bid amounts, the commencement of CIRP and the resulting moratorium would lead to halting of such SARFAESI proceedings. In Indian Overseas Bank v. M/S R.C.M Infrastructure Ltd. and Anr., (‘Indian Overseas’) the Supreme Court (‘SC’) reaffirmed the settled legal position that once the CIRP is initiated under IBC, any parallel proceedings under the SARFAESI Act must be halted. In this case, a sale certificate has already been issued, and 25% of the bid amount has been paid by the auction purchaser under Section 13(8) of the SARFAESI Act. The court held that the moratorium imposed under Section 14 of the IBC would override such enforcement actions, thereby safeguarding the corporate debtor’s assets for the benefit of all creditors. However, this clarity has recently been disrupted by recent developments of the National Company Law Appellate Tribunal (‘NCLAT’) in Nagpur Nagrik Sahakari Bank Ltd. and Ors. v. Mohanlal Ayyapan Pillai and Ors (‘Nagpur Nagrik Sahakari Bank’) & Pratibha industries v. Yes Bank Ltd. and Anr. (‘Pratibha Industries’). These rulings have carved out exceptions to the SC’s interpretation, introducing a degree of uncertainty into an otherwise well-settled area of law. This article examines the conflicting judicial approaches to the interplay between Section 13(4) and 13(8) of the SARFAESI Act and Section 14 of the IBC. Part II explores what is the question of law that has arisen because of recent cases and what is the core contention. Part III is discussing the conflicting interpretations that have been employed by different cases and how that has led to an interpretative conundrum. It explores the underlying legal rationale for each position and identifies the specific points of divergence. Part IV concludes by providing with recommendation and way forward. Question of law – The Core Contention A significant legal conundrum has emerged at the intersection of the SARFAESI Act and IBC, particularly in cases where proceedings under both statutes appear to overlap. Recently, NCLAT have interpreted Section 13(8) of the SARFAESI Act, to conclude that an auction conducted by a bank under the SARFAESI cannot be set aside if the sale notice had been issued prior to commencement of the CIRP. It held that the relationship between the parties i.e., the mortgagor-mortgagee, for redemption, exists only till the date of issuance of notice of sale of property. The tribunal, relying on Celir LLP v Bafna Motors (Mumbai) Pvt. Ltd (‘Celir LLP’) decided that even if insolvency proceedings are initiated under the IBC and a moratorium is imposed, it would neither revive the mortgagor’s extinguished rights nor would the property form part of the corporate debtor’s asset pool. In Celir LLP, the SC undertook a detailed analysis of the pre- and post-amendment versions of Section 13(8) and concluded that after the 2016 amendment, once the auction notice in accordance with Rule 8(6) and 9(1) of the Security Interest (Enforcement) Rules, 2002, is published and dues remain unpaid, the borrower’s redemption rights are extinguished. On this basis court decided that the sale of an asset even if after the initiation of CIRP is not in violation of Section 14(1)(c) of IBC because there was no relationship between the mortgagor and mortgagee. And no right of redemption exists between them because notice under Section 13(8) was issued much prior to the commencement of CIRP. Court emphasised on the sanctity of public auctions, underscoring the judicial responsibility to protect such processes from unnecessary interference. It cautioned that any other interpretation of Section 13(8) would allow mischievous borrowers to disrupt the auction process. There would be multiple redemption offers from borrowers even after public auction notices, potentially frustrating the auction process and discouraging public participation, thereby defeating the purpose of the Act. In the Pratibha Industries, and the recent Nagpur Nagrik Sahakari Bank case, the tribunal, held that if the property is sold in accordance with Section 13(8), the borrower’s right to redeem the property is extinguished. In both decisions, the court relied heavily on the ratio of Celir, wherein the central question was “what is the impact of the amended Section 13(8) of the Act on the borrower’s right of redemption in an auction conducted under the Act.” Now the core issue that arises is that currently two interpretations are there on the same point of law. Putting simply, the question is that if an auction is conducted under Section 13(8) of SARFAESI & partial bid money has been received. But before the whole money is received, the insolvency proceedings have

Reconciling the Overlap: Sarfaesi’s Sections 13(4) & 13(8) v. Ibc’s Moratorium Under Section 14 Read More »

RBI’s New AePS Guidelines: A Precarious Road Ahead?

[By Yash Somraj Roy] The author is a student of Hidayatullah National Law University, Raipur.   Introduction Recently, the Reserve Bank of India (“RBI”) under the Payments and Settlements Systems Act, 2007 has issued new due diligence guidelines for its Aadhaar-enabled Payment System (“AePS”) touchpoint operators. Enforceable from 1st January 2026 the guidelines look to reinforce the regulatory oversight of banks, regarding agents transacting with them. The new, stringent directives come as a solution to the high occurrences of identity theft and fraud in the AePS and Business Correspondent Model ecosystem. An AePS touch point operator in brief, is an agent who facilitates banking transactions of customers through their Aadhar number and Biometric data. The RBI to ensure credibility and better functioning of the AePS touchpoint operators, has introduced a new set of guidelines for improved due diligence. The guidelines primarily introduce four significant safeguards as a way to reduce fraudulent attempts. To begin with, the guidelines stipulate for rigorous due diligence methods for AePS touchpoint operators before onboarding them with a bank. Furthermore, the guidelines also advocate for a “one-operator-one-bank” rule establishing that an agent would not be able to operate with multiple banks simultaneously. In addition to this, the guidelines also propose for a constant risk-based monitoring of AePS touchpoint operators by banks as part of their fraud-control framework. Ultimately, the guidelines state that every AePS touchpoint operator (“ATO”), idle for a period of more than three months must undergo Re-Know Your Customer (“KYC”) and must be re-verified subsequently before resuming transactions. Interestingly, while the RBI has taken a positive approach to curb fraudulent practices by reinventing the AePS. It has blindsided several challenges and implications which arise out of the new guidelines. The author through this blog analyses the several shortcomings vis-à-vis the newly issued guidelines and delves into the implications arising out of it. Additionally, the blog analyses the quandary on how the absence of a central registry, indirectly makes it stricter for banks to prove their non-liability. Lastly, the author through this blog recommends several policy responses along with solutions and explores the way ahead for the seamless execution of the newly issued guidelines. The Lack of Centralised Monitoring Platform: A Major Inadequacy As set forth above, there are several lapses and implications which arise out of the newly issued AePS guidelines. One such major implication is the lack of a centralised monitoring platform. In absence of a central database, each bank only has the option of relying on its own modalities even in instances of inadequate competency. One such subsequent major challenge which arises due to the lack of a centralised monitoring platform is duplicate onboarding. Duplicate onboarding is when, an ATO who is already affiliated with one bank, registers themselves with another bank using a slightly altered name or identity. The absence of a centralised platform plays a key role here, as without it there is no automated screening of ATOs, and each bank’s KYC process is forced to evaluate each application independently. Thus, this eventually also acts as a threat to the RBI’s “one-operator-one-bank” policy as the lack of a centralised monitoring system makes it easier for ATOs to commit fraud. Perhaps most consequentially, the lack of a centralised monitoring platform fragments fraud detection and renders it rather ineffective. Although the National Payments Corporation of India (“NPCI”) provides banks with a mechanism to report and flag non-compliant agents. It does little to stop these said agents, to re-enter the AePS with altered identities. Hence, this allows for an ATO to simply function indefinitely by utilising numerous identities in multiple banks. In essence, while the RBI’s newly introduced guidelines take initiative to strengthen the defences of individual banks. The guidelines due to the absence of a nation-wide platform to monitor ATOs, do little to curb fraudulent practices which operate across multiple institutions. Exploring the Lesser-Noticed Implications in the Framework Owing to the centralised monitoring concern, there are several other ramifications which arise, that the RBI might have failed to notice. The absence of specificity vis-à-vis the three-month inactivity rule and the uneven standards of monitoring across banks give rise to several loopholes and legal lacunae which ATOs could use to rationalize acts of fraud. At the outset, the three-month inactivity rule is susceptible to manipulation. An ATO with minimal effort could circumvent this provision by executing dummy transactions once, within an interval of two or three months. This in turn means, that an ingenuous ATO by making a small withdrawal every three months would be able to bypass the Re-KYC protocols. Due to the transactions occurring within the stipulated time, the legitimacy of them are not under suspicion by the banks and no pattern of misuse is detected. Resultantly, ATOs who are practically inactive, could continue to function indefinitely exploiting the aforementioned provision stated by the guidelines. Thereby, this loophole acts as a detrimental force against the AePS and the transparency which the guidelines look to implement. Another subsequent loophole arises from the ambiguity which lies within the standards of monitoring across banks. Although, the new guidelines allow for banks to implement risk-based controls as they deem fit, it fails to consider the dissimilarity in manpower and competency each bank may have. This consequently implies, that while some banks with higher resources and manpower may actively flag anomalies, others would not be able conduct regulatory oversight to that extent. Hence, an operator that does not meet the criteria of one bank would be able to continue operations in another. At its core, the RBI’s new guidelines for ATOs has inadvertently created a disparity which could lead to incorporation of increased fraudulent practices and illicit conduct in the AePS. Who Pays When ATOs Go Rogue? Under Section 7 of the Aadhaar Act, 2016 it is permittable by law to conduct Aadhar-based withdrawals for customer benefits and banking needs. Hence, the need of guidelines for the governance of ATOs is of utmost importance in the AePS. But a major conundrum which arises due to

RBI’s New AePS Guidelines: A Precarious Road Ahead? Read More »

Neo-Banks and Its Regulations: How Long Can the Present Symbiotic Arrangement Sustain

[By Avinash Kumar] The author is a student of Dr. RML National Law University.   INTRODUCTION All it took two and half decades, the internet and digital technology have become the backbone of modern living. Much like the world grew from conventional settings to digital platform-based service, the financial setting worldwide is going through a sweeping revision primarily driven by fast-paced innovation in digital technology. The semblance of conventional brick-mortar banking institutions with the growing distrust ever since the global financial crisis of 2008 is slated to be phased out by advancing FinTech institutions. At the frontline of this changing time are neo-banks, financial service providers breaking new ground in banking services. To grasp what the future of banking will look like in the years to come, this blog points out the current position of neo-banks and a significant opportunity to bridge the credit gap through accessible funding options. It further highlights the current regulation of which neo-banks face operational challenges depending on traditional banks. The paper explores several countries that have dedicated licenses for neo-banks and how the evolution of digital banking has the potential to shape India’s FinTech market. In general terms, neo-banks are not “banks,” but technology driven Financial Service Providers FSPs that rely on relationships with accredited local banks to provide financial services. They are distinct from traditional banking institutions by exhibiting their digitally exclusive operations and carrying out without storefronts i.e., no physical branch presence. The worldwide unfolding of neo-banks, around 2013-2015 in UK and Germany was rooted mainly by advancing technology, changing customer base especially from Gen Z preferring convenience and personalised experiences and a business model focused on lower interest rates. The global neobank market was worth $ 18.6 billion in 2018 and is expected to accelerate at a compounded annual growth rate (CAGR) of around 46.5% between 2019 and 2026, generating around $394.6 billion by 2026. India’s financial landscape also mirrors the dynamics of digital transformation seen in other parts of the world. In India neo-banking sector has gained strong momentum with the presence of competitors like Jupiter, Fi Money, Open and Razorpay X. The early emphasis of these banks is not only a market capture approach but also a sign of systemic weakness within the existing banking structure. Consider the TransUnion findings of 2021 which reports more than 160 million consumers were deemed credit underserved in India lacking access to mainstream financial products due to thin credit files or low formal engagement. The credit inaccessibility is even more burdensome in the Micro Small and Medium Enterprises (MSME) sector. An EY report states that among the 64 million MSMEs, there is an overall finance demand of around $1955 billion. This demand is supported by a leverage ratio of 3.8, i.e, for every $1 they put in equity, they require $3.80 in loans. Yet, only 14% of these MSMEs can secure credit from conventional banking sources. This leaves an estimated $1,544 billion in the form of debt financing of which nearly 47% MSMEs’ debt demand is unaddressable due to low financial viability. The debt leads them to rely on shadow lenders, charging a higher rate of interest. These gaps have created a shortfall of $819 billion, of which $289 billion is currently backed by private banking institutions. There remains an unmet financial debt of $530 billion offering a window entry point for FinTech companies and Non-Banking Financial Companies (NBFCs). REGULATORY MECHANISM- THE PARTNERSHIP MODEL Neobanks in India are not yet licensed by the Reserve Bank of India. Section 22 of the Banking Regulation Act, 1949 stipulates that to conduct bank operations an RBI License is required. With RBI’s “Mobile Banking Transactions in India – Operative Guidelines for Banks (2014)” Circular, the functioning of neobanks is further challenged for Clause 6 specifies physical presence of bank to offer the mobile banking services. These FSPs (neo-banks) partner with RBI-approved banks and NBFCs to deliver banking solutions. Under this mechanism, the core financial services such as accounts, deposits, and savings instruments are provided by the partner bank or NBFC managing customers’ funds under RBI oversight. To go with that, neo-banks technology driven interface offers a user-centric platform leveraging AI and data analytics for financial services like account opening, payments, expense tracking and personalised insights through mobile and online platforms. This Banking-as-a-Service model outlined in Section 4 (Authorization of Payment Systems) as per the Payment and Settlement Systems Act, 2007 ensures customers’ digital interaction through neo-bank with the core banking operations limited under the purview of licensed partner banks. Alongside the sector-specific regulation under the RBI, all of this brings a layered “principal-agent” relationship, complicating the division of regulatory duties and liabilities. The lending service provider (the agent) incurs compliance risk and reputational damage if the licensed partner bank (the principal) faces RBI action, and neo-bank services can be abruptly disrupted. Consider the RBI action against the State Bank of Mauritius back in 2023. The disruption affected Niyo’s international forex services, leaving users stranded without any direct recourse overseas. With the regulatory licensed bank that bore scrutiny, this highlighted neobanks lack direct regulatory oversight for cybersecurity and incident response, relying instead on partner banks, highlighting a compliance and consumer protection gap in the current partnership model. The Information Technology Act, 2000 highlights the legal recognition of electronic records, electronic signatures and electronic contracts (Sections 4, 5, 10) essential to the paperless operations of neo-banks. Section 43A imposes liability on entities for compensation where the failure to implement reasonable security practices results in the misuse or loss of sensitive personal information. The Act also outlines various cybercrimes i.e, identity theft under Section 66C, punishment for information breach of a lawful contract under Section 72A, and liabilities applicable to neo-banks for security lapses. While neo-banks operate as technological innovation agents in this partnership, it is yet to be determined how they will comply with user data privacy, likely the Digital Data Protection Act, 2023 and AML/KYC regulations over time if granted a license. Guidelines on Outsourcing of Financial

Neo-Banks and Its Regulations: How Long Can the Present Symbiotic Arrangement Sustain Read More »

Section 17 of SARFAESI and Breach of OTS Agreements: A Legal Conundrum

[By Upanshu Shetty] The author is a student of Dr. Ram Manohar Lohiya National Law University, Lucknow.   Introduction The Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002 (SARFAESI Act), was enacted to empower financial institutions with a framework to recover non-performing assets without resorting to time-consuming litigation. A key feature of the SARFAESI Act is Section 17, which grants borrowers the right to challenge enforcement actions taken by secured creditors under Section 13(4). Over the years, judicial interpretations of Section 17 have evolved, particularly in the context of One-Time Settlement (OTS) agreements, where borrowers often seek relief when banks revoke settlement offers or enforce security interests after an alleged breach.  While OTS schemes are designed to facilitate amicable resolution between lenders and borrowers, disputes often arise when borrowers fail to comply with the settlement terms, leading banks to cancel OTS agreements and proceed with asset recovery. In such cases, borrowers have sought to invoke Section 17 before the Debts Recovery Tribunal (DRT) to challenge the enforcement of security interests. However, the judiciary has taken a nuanced approach to these cases, weighing the contractual nature of OTS agreements against the statutory framework of SARFAESI. The evolving jurisprudence suggests that while borrowers can approach the DRT to challenge wrongful enforcement, they cannot use Section 17 to seek enforcement of an OTS agreement itself.  The Role and Scope of Section 17 under SARFAESI Section 17 of SARFAESI provides an appellate remedy to any person aggrieved by measures taken under Section 13(4), which empowers secured creditors to take possession of secured assets or manage them in a manner they deem fit. The provision is intended as a safeguard against arbitrary or unlawful enforcement, ensuring that creditors act within the bounds of the law while exercising their rights. In Hindon Forge Private Limited v. State of Uttar Pradesh, the Supreme Court reaffirmed that a borrower can approach the DRT at the stage of the possession notice itself, thereby ensuring a fair opportunity to challenge enforcement proceedings.  However, a fundamental question remains: does Section 17 apply to disputes concerning OTS agreements? Courts have generally held that DRT jurisdiction is limited to reviewing measures taken under Section 13(4) and does not extend to general contractual disputes between banks and borrowers. In Bijnor Urban Co-operative Bank Ltd. v. Meenal Agarwal, the Supreme Court categorically ruled that a borrower cannot claim OTS as a matter of right and that no writ of mandamus can be issued directing a bank to grant such a settlement. This principle suggests that an aggrieved borrower cannot invoke Section 17 solely to enforce an OTS agreement but may do so if the revocation of an OTS results in wrongful enforcement under SARFAESI.  The Enforceability of OTS Agreements and Borrower Rights OTS agreements are contractual arrangements governed by the policies of individual banks and subject to the regulatory framework set by the Reserve Bank of India (RBI). While they provide borrowers an opportunity to settle dues at a reduced amount, they do not confer an absolute right to settlement. Courts have consistently upheld the discretionary nature of OTS schemes, emphasizing that banks must be allowed commercial autonomy in deciding whether to accept or reject a settlement proposal.  In Amrik Singh v. DCB Bank Ltd., the High Court held that once a bank frames an OTS policy in compliance with RBI guidelines, it must act in good faith while considering applications. Arbitrary rejection or revocation of an OTS offer, particularly if the borrower has demonstrated bona fide intent to comply, may invite judicial scrutiny. However, this does not imply that a borrower can force the bank to accept an OTS or claim an automatic extension of time to make payments. In State Bank of India v. Arvindra Electronics Pvt. Ltd., the Supreme Court ruled that borrowers cannot demand an extension of OTS terms as a matter of right, reaffirming the principle that OTS agreements remain subject to mutual agreement rather than legal compulsion.  OTS Breach and the Availability of Remedies Under Section 17 A key legal question arises when a borrower defaults on an OTS agreement, and the bank, consequently, proceeds with SARFAESI enforcement. In such instances, the borrower may attempt to challenge the action under Section 17, arguing that the bank’s revocation of the OTS was unjustified. However, the judiciary has generally restricted the scope of Section 17 to reviewing enforcement measures rather than adjudicating contractual disputes.  The Supertech Realtors Pvt. Ltd. v. Bank of Maharashtra, decision underscores this principle by holding that OTS agreements are purely contractual in nature and that disputes concerning their breach should be adjudicated through civil proceedings rather than writ petitions or SARFAESI appeals. However, there have been exceptions. In Anu Bhalla v. District Magistrate, Pathankot, the High Court exercised its writ jurisdiction to extend the OTS period based on the borrower’s bona fide intent to pay. This ruling highlights the judicial balancing act between upholding contractual obligations and ensuring fairness in lender-borrower relationships.  While the courts have largely maintained that Section 17 does not provide recourse for enforcing OTS agreements, they have recognized limited exceptions where the borrower can demonstrate that the bank acted in bad faith or violated due process. If the revocation of an OTS is arbitrary and is immediately followed by disproportionate enforcement under SARFAESI, the borrower may have grounds to challenge the action before the DRT. However, such challenges must be rooted in procedural violations rather than the mere expectation that an OTS should have been granted.  The Interplay Between Section 17 and Writ Jurisdiction Under Article 226 A significant aspect of this debate is whether borrowers can bypass the limitations of Section 17 by invoking Article 226 of the Constitution. The Supreme Court has consistently discouraged the use of writ jurisdiction in SARFAESI matters, emphasizing that statutory remedies under the Act must be exhausted before approaching the High Courts. In G. Vikram Kumar v. State Bank of Hyderabad, the Court ruled that challenges to e-auction notices must

Section 17 of SARFAESI and Breach of OTS Agreements: A Legal Conundrum Read More »

Regulatory Harmonization: Strengthening HFC and NBFC Frameworks

[By Shriyansh Singhal] The author is a student of National Law University Odisha.   Introduction The Reserve Bank of India (‘RBI’) has initiated a new regulation aimed at aligning the regulatory frameworks of Housing Finance Companies (HFCs) with Non-Banking Finance Companies (NBFCs) to ensure greater consistency and financial stability. The RBI decision align with the guidelines stated in paragraph 4 of the dated 22nd October 2020 which recommended gradually harmonizing the regulations governing HFC and NBFC entities over the next two years, for a smoother transition. Changes of significance have been implemented in the following areas; (a) guidelines for receiving deposits that HFC registered certificate holders can receive or retain; (b) guidelines for accepting public deposits by NBFC holding certificate holders; and (c) additional significant directives, to both HFC and NBFC entities.  Rationale Behind the Proposal The Reserve Bank assumed the responsibility of overseeing HFC operations from the National Housing Bank (‘NHB’) starting on 09 October 2019. It had implemented different guidelines treating HFC as a subset of NBFC entities. The rules governing both HFC and NBFC sectors were reviewed to ensure alignment in regulations while considering the features of HFC operations.  After reviewing the current regulations given to HFCs, RBI decided to release updated guidelines. Some of the laws related to NBFCs have also been looked into and a few changes have been made to them and the same will come into force from 1st January 2025. At present, NBFCs and HFCs which are allowed to accept deposits from the public are under higher measures on prudential regulation of deposits. This shift toward a unified regulatory regime is intended to address potential risks, ensure the safety of public deposits, and maintain financial stability.  Introduction of Key Changes Increased Liquid Assets and Safe Custody   Earlier, the HFCs had to maintain 13% of the public deposits in the form of liquid assets as per Section 29B of the NHB Act, 1987. The previous regulations have set this requirement at 10% while the new regulations have increased the same to 15% which is to be implemented gradually by July 2025. This moderated rise starting from 13% on January 1, 2025, and 15% in July is targeted to ensure that HFCs have adequate cash flows to fulfill their obligations. This change aligns HFCs with the NBFC liquid assets regulation and is expected to improve the liquidity profile of the housing finance sector.  The regulation concerning the safety of liquid asset custody has been revised to be comparable to the regulation of NBFCs. It is now compulsory for the HFCs to park their liquid funds with the entities as mentioned in the Master Direction – Non-Banking Financial Companies Acceptance of Public Deposits (Reserve Bank) Directions, 2016. This change enhances the definition and safeguards in liquid asset management, ensuring that HFCs have a sound mechanism for protecting the depositors’ funds. According to the new guidelines, HFCs are also required to sustain complete asset coverage for the public deposits that are made.  This stipulation, which was previously enforced for NBFCs, ensures that HFCs possess sufficient assets to support their held deposits, thereby lowering the risk of financial failure. In situations where the asset coverage falls below the required level, HFCs must promptly notify the NHB, enabling regulatory supervision and reducing potential threats to depositors’ funds.  Stricter Credit Rating & Deposit Ceiling  HFCs now must have a minimum credit rating of investment grade to accept public deposits. This explicitly annual review means that a lower rating during the year would render the HFC ineligible to accept any new deposits or renew existing ones until the rating is regained. Through this means, the central bank is ensuring that the firms are of reasonable financial integrity. Since HFCs are public deposit-taking institutions to that extent, the safety aspect of the public’s money is secure. Concurrent with this, the leverage of HFCs has been brought down hugely by not allowing them to take in public deposits in 1995, they could accept up to 300 percent of their net worth in public deposits but by mid-1996 they were forced to cut this limit down to 150 percent.  Terms of public deposits have been reduced from a maximum of 120 months to 60 months. This adjustment is intended to enhance asset-liability management by reducing the long-term interest rate risk on HFCs and achieving a better maturity match between assets and liabilities.  Restriction on Investments in Unquoted Shares  The modified regulations bring HFCs in line with NBFC rules, whereby there were pre-existent limits on unquoted shares that the housing sector lender could invest in. Said investments are also considered a part of the HFC’s overall exposure to the capital market and they need to set their internal limits accordingly. This will ensure that HFCs do not have undue exposure to completely illiquid and volatile investments, putting their financial stability at risk.  The new rules for HFCs have been modified in line with NBFC regulations as there were already limits on unquoted shares an entity could invest, the people said. These investments are also deemed to be part of the overall capital market exposure weathered by HFCs and they must fix internal limits for these as well. This would help HFCs not have full domestic exposure and reduce the chances of them having high levels of completely illiquid (and now volatile) investments that could jeopardize their financial stability.  Impact of the Amendment The convergence of regulations is anticipated to have several effects on the housing finance system and the financial services industry as a whole since the New Depository and Asset cover norms are expected to enhance the liquidity position of HFCs. Aggregated excess liquidity would make HFCs more efficient and well capable of withstanding depositors’ demands as regards funds even during enhanced financial stress.  This will bring a ceiling on the excessive deposit mobilization by HFCs due to reasons such as being able to reduce the end deposit ceiling from three times to 1.5 times the Net Owned Fund (‘NOF’) and the

Regulatory Harmonization: Strengthening HFC and NBFC Frameworks Read More »

Unlocking Credit With Digital Payments: Analyizing NPCI’s Proposed Digital Payment Scores

[By Aryan Dash & Debasish Halder] The authors are students of National Law University Odisha.   FROM UPI TO DPS: NPCI’S JOURNEY TOWARDS FINANCIAL INCLUSION India has witnessed a remarkable rise in digital payments over the past decade, facilitated by the National Payments Corporation of India (NPCI). NPCI, an umbrella organization for retail payments in India, has played a pivotal role in developing and promoting digital payment systems such as Unified Payments Interface (UPI), Bharat Interface for Money (BHIM), RuPay cards, and others. These initiatives have significantly reduced the dependence on cash transactions, fostering financial inclusion and digital literacy across the country.  NPCI has recently proposed the concept of Digital Payment Scores (DPS) as a tool for lenders to assess the creditworthiness of borrowers. DPS would analyse an individual’s digital payment behaviour, including factors like transaction frequency, volume, and patterns. This data-driven approach aims to provide lenders with an alternative risk assessment mechanism, supplementing traditional credit scoring models.  This blog examines NPCI’s role in advancing financial inclusion through DPS. It addresses key questions about how DPS can assess creditworthiness beyond traditional models, the necessary legal frameworks for privacy and fairness, and how to mitigate challenges like data security and algorithmic bias while promoting inclusivity in India’s financial landscape.  RETHINKING CREDIT ASSESSMENT BEYOND TRADITIONAL MODELS India’s credit scoring relies heavily on past credit history, leaving rural or underbanked populations without access to loans. Digital payments offer new avenues for creditworthiness assessment. Transaction data reveals income levels, spending habits, and financial stability. Timely bill payments and engagement with savings platforms demonstrate financial discipline. However, using alternative data sources raises privacy and bias concerns, necessitating robust ethical and regulatory frameworks. Fair and non-discriminatory lending practices require careful integration of such data.  LEGAL AND REGULATORY CONSIDERATIONS The implementation of DPS would require a robust legal and regulatory framework to address concerns related to data privacy, consent, and fair lending practices. Authorities would need to establish clear guidelines for data collection, usage, and security to ensure consumer protection and prevent discriminatory lending practices. Additionally, measures would be required to safeguard against potential biases and ensure transparency in the scoring methodology.  Data Privacy The implementation of DPS raises important data privacy considerations, particularly within the framework of the Information Technology Act, 2000, which includes provisions like the Right to be Forgotten. User consent is crucial, requiring clear and informed agreement from individuals regarding the collection and utilization of their digital transaction information. Clear communication regarding the purpose, scope, and potential consequences of DPS calculations is essential. Furthermore, data anonymization is critical to safeguard individual privacy. Robust anonymization techniques should be employed to ensure that transaction data used for DPS calculations undergo thorough anonymization, removing or obfuscating personally identifiable information while preserving relevant behavioral patterns.   To implement DPS effectively while ensuring data privacy, several techniques can be employed. Differential privacy adds randomness to data queries, preventing anyone from inferring personal information even if they know some details about an individual. Synthetic data generation creates fake datasets that replicate real transaction behavior, allowing safe analysis without exposing actual personal information.  Data masking replaces sensitive details with random values, protecting user data from unauthorized access. Pseudonymization substitutes real names with artificial identifiers, making it challenging to link transactions back to individuals while still enabling necessary analysis. Lastly, local suppression and global partitioning control data visibility, minimizing the risk of revealing identities while still allowing for meaningful insights. Together, these strategies enhance privacy protection in the context of DPS.   Additionally, stringent measures for secure storage and processing are imperative to maintain the confidentiality and integrity of the transaction data. This entails implementing strict data security measures, including secure storage, access controls, and rigorous encryption protocols during both data processing and transmission.  Fair Lending Practices The DPS model must be meticulously crafted and audited to mitigate potential biases stemming from factors such as income levels, geographic location, or digital literacy. These biases could inadvertently create unfair disadvantages for specific population segments, thereby undermining the overarching goal of financial inclusion. Transparency and explainability are paramount to ensure equitable lending practices. Thus, the DPS algorithm should be transparent and explainable, providing both lenders and borrowers with clear insights into how scores are calculated and the factors influencing the final assessment.   To reduce bias in the DPS model, several strategies can be employed. First, ensuring diverse data collection is key; datasets should include information from underrepresented groups to promote fair representation. Utilizing bias detection tools helps identify and correct any unfair patterns before they impact lending decisions.  Regular evaluation and monitoring of the scoring model can track fairness across different demographic groups, allowing for timely interventions when biases emerge. Involving human oversight in the development process ensures that diverse perspectives are considered, helping to identify issues that automated systems might overlook. Establishing clear ethical guidelines for data use further promotes responsible practices and compliance with legal standards.  However, legal challenges may arise, particularly if the DPS is categorized as a credit scoring system subject to regulations like the Fair Credit Reporting Act or similar laws in India. Such classification could lead to legal disputes, particularly if the scoring methodology is perceived as discriminatory or lacks adequate consumer protection measures.  Regulatory Framework for Credit Scoring At the heart of credit information regulation in India lies the CIRC Act, a legislative cornerstone that casts a wide net in defining credit information. Its expansive purview encompasses various financial transactions, from conventional loans to digital payment footprints. This broad definition, notably captured in Section 2d, sets the stage for integrating digital transactions—such as utility payments and e-commerce purchases—into the fabric of creditworthiness assessment. However, NPCI, as the vanguard of DPS provision, must tread cautiously, ensuring compliance with registration mandates under Section 5 of the CIRC Act and meticulous adherence to privacy guidelines outlined in the Credit Information Companies (Regulations), 2006.  Navigating the Privacy Paradox: Insights from the DPDP Act Amidst the regulatory tapestry, the DPDP Act emerges as a critical arbiter, safeguarding the sanctity of sensitive personal

Unlocking Credit With Digital Payments: Analyizing NPCI’s Proposed Digital Payment Scores Read More »

Expanding Horizons: Payment Banks and Strategic Partnerships

[By Dhawni Sharda & Anshika Agarwal] The authors are students of National Law University Odisha.   INTRODUCTION   Through Budget 2024, the Government of India has pioneered an ambitious objective to set up over a hundred Payment banks as a significant step towards financial inclusion and security. These banks have been a modicum between the formal banking institutions and the unbanked population. This fosters greater financial literacy, encouraging savings and ensuring economic security amongst the economically weaker sections of society.   However, whether an increase in the number of these payment banks would provide the solution for the problems plaguing  them is a question to be addressed. The authors, through this article, aim to highlight the strategic importance of partnerships between payment banks and institutions like Micro Finance Institutions (MFIs) and Business Correspondents (BCs) . While BCs enable access to unbanked areas, MFIs provide financial services like microcredit, micro-insurance, and savings, etc. This is done.to overcome the inherent barriers in their performance.  Starting with the rationale behind setting up such banks to analysing the recent actions faced by such banks for the failure of compliances, the authors adopt such an approach concerning how the lacuna of these banks can be resolved through strategic partnerships and tie-ups which can further broaden the understanding of such payment banks as beyond the digital wallets and can lead to being a host of variety of services.   TRACING THE ORIGIN AND AFTERMATH   Given the significant risks associated with Prepaid Payment Instrument(PPI) model such as concerns around KYC compliance, and the need for quick access to payment services at the grassroots level, a recommendation was made to establish the payment banks. These banks provide their essential payment services and function such as a digital wallet wherein the customers like MSME’s and low-income individuals can maintain their bank balance and use it to serve their needs.   With all this in process, payment banks started functioning as a miniature model of scheduled commercial banks. These banks were required to follow certain mandates as prescribed by RBI in the same way as Scheduled Commercial Banks do. Alongside, these banks were granted rights and privileges which came with the grant of the license.   Their performance was further enhanced by their strategy of branchless banking wherein the network of such banks was spilled over semi-urban, and rural areas. This phenomenon got fillip when these banks started entering into strategic partnerships.   STRATEGIC TIE-UPS   In recent years, the financial infrastructure of the underbanked areas has been boosted by the various deals between traditional banks, fintech companies, and payment banks. Doing so would ultimately broaden the horizon of the payment banks and help them to overcome their limitations which they would otherwise encounter if they would operate solely.   Microfinance institutions have already an established customer base in the low-income regions. Payments banks can use these channels to venture into new markets thereby leading to reduced cost, financial inclusion, and efficiency in operations.   In a deal, Multilink announces tie-up with NSDL payments bank. This move would contribute to financial services to all societal sections. To elaborate it further Multilink has around 3000 distributors, 200 mass distributors, and 60 API distributors. They even have strong associations with  renowned platforms like IRCTC, Yes Bank, TATA AIG, Kotak Life, and so on. This NSDL-Multilink partnership would help customers perform all banking facilities around the clock through BC agent points.  Such partnerships are entered not only to avail the benefits of a well-established clientele base created by the MFIs/BCs, but also to avail the advantage of merging resources leading to efficiency in operations. Additionally, established monitoring and audit regulations are available to the payment bank.  SPOT ON ANALYSIS   Going Beyond the Conventional Perspective.   Going beyond the brick-and-mortar aspect of payment banks wherein they function as digital wallets, such collaborations with BCs or MFIs would become a good source of lending, thus fulfilling the debt gaps or the cash crunch requirements in the lower segment areas. If these two entities join hands, the issue of such operational needs of the banks would also be fulfilled.   Improved Market Offerings   The host of activities undertaken by the BCs can prove to be catalysts in the performance of the payment banks through their aid and assistance considering the low-cost model of BCs in branchless banking. So, these BCs can act as nodes to the branchless banking model of the payment banks, thereby amplifying the scope of financial activities.    Additionally, Payments banks can use MFIs’ strategic partners which have an established base in providing cross-banking marketing services to their clients, besides their experience in providing financial services to the low-income segment. This can work as a win-win situation for both the parties.   Plugging the Internal Problems   The abovementioned problems relate to the external issues which can be resolved through such alliances. However, certain internal issues are barriers to their expansion.   Payment banks in their initial years of set-up need to meet the high fixed costs leading to elevated break-even points. This further leads to the higher need for significant transactional volumes and substantial scale. In the process of doing the same, payment banks spend a considerable amount of time and resources in increasing profitability. Consequently, they miss on their sole purpose of creating better market offerings and attaining RBI’s objective of financial inclusion.   Need for Diversification   These payment banks fulfill the dire needs of the micro-finance institutions wherein these institutions plan to makeover their negative image of being involved in the unethical practices used in lending activities. In the wake of this situation, the state government came up with laws that completely put a halt to their operations. Given such a payment bank with a strong government and institutional support at the backend, the MFIs would get a relaxation in terms of regulatory oversight permitting their free and fair operations.   WAY FORWARD   Strategic partnerships are not an easy path to tread since these payment banks can’t enter such strategic alliances as independent entities because they are subsidiaries implying that they are controlled and influenced by their

Expanding Horizons: Payment Banks and Strategic Partnerships Read More »

RBI’s Regulatory Clampdown: Navigating the Paytm Saga

[By Manav Pamnani & Teesha Arora] The authors are students of NALSAR University of Law, Hyderabad and Symbiosis Law School, Pune respectively.   Introduction and Background  In a recent move, the Reserve Bank of India (RBI) has imposed restrictions on Paytm Payments Bank, prohibiting it from accepting fresh deposits in its accounts, facilitating credit transactions, and offering fund transfers, including the Unified Payment Interface (UPI) facility, after March 15, 2024. This has emerged in light of the multiple violations on the part of the bank to meet the regulatory requirements and directions given by the RBI.    Paytm Payments Bank, an associate of One 97 Communications Limited (OCL), is an Indian Payments Bank founded in 2017. It is a part of the financial network of one of India’s largest payment companies, Paytm. In fact, on October 7, 2021, it was officially added to the second schedule of the RBI Act of 1934. In its press release on March 11, 2022, the RBI directed the Paytm Payments Bank to stop onboarding new customers. It further added a condition that such onboarding would only be permissible if the bank appointed an Information Technology (IT) audit firm to conduct a comprehensive system audit of its IT system and if, after a thorough review, the audit report seemed satisfactory. This audit report would comprise compliance checks with reference to Section 43A and Section 79 of the IT Act. The reason for ensuring compliance with the aforementioned provisions of the IT Act can be inferred from the preamble of the Act itself which lays down its objective, which is to facilitate lawful digital transactions while mitigating cybercrimes and other potential non-compliances. Since the operations of Paytm involve digital transactions and storage of data, these provisions become relevant. In this regard, Section 43A deals with compensation for failure to protect data. It requires a body corporate to uphold acceptable security standards and procedures while managing, dealing with, or having any sensitive personal data or information on a computer resource that it owns, controls, or manages, failing which, it would have to compensate the affected people who have incurred wrongful loss. On the other hand, Section 79 encompasses an exception, according to which, intermediaries may be immune from liability if they operate as mere middlemen in the transmission, storage, or exchange of third-party information or data.   The audit report, however, indicated persistent non-compliance on the part of the bank coupled with material supervisory concerns. It reflected that lakhs of accounts had not followed the mandatory Know Your Customer (KYC) procedure. Adhering to KYC guidelines is non-negotiable due to the significant purpose it serves which mainly includes verifying the identities of customers in order to prevent money laundering activities. The omission on part of Paytm thus violated Section 12 of the Prevention of Money Laundering Act, 2002 which mandates the verification of the identities of clients before entering into financial transactions. The importance of the KYC procedure leads financial institutions and conventional banks to strictly follow it. In the given case, since Paytm has repeatedly violated this crucial norm, RBI’s clampdown is justified. The exacerbating factor in this case is that the transactions in the non-KYC accounts exceeded millions of rupees, far beyond the prescribed regulatory limits, as specified in the Reserve Bank of India (Know Your Customer) Directions, 2016.   Moreover, over a thousand users had the same Permanent Account Number (PAN) linked to their accounts which further raised money laundering concerns. This led the RBI to utilise its power under Section 35A of the Banking Regulation Act, 1949 and issue the aforementioned directions. It also passed an order on October 10, 2023, imposing a monetary penalty of rupees 5.39 crore on Paytm Payments Bank for breaching the several regulatory requirements.   Justification of the Action in light of Section 35A of the Banking Regulation Act, 1949   Section 35A of the Banking Regulation Act provides for the power of the RBI to give directions. This power extends not only to specific banking companies in cases of non-compliance but also to general guidelines or circulars issued in interest of the overarching banking framework. For example, in 2016, the RBI issued the Master Directions on Fraud to consolidate and update seven earlier circulars on the classification, reporting and monitoring of fraud. Thus, the power enshrined under this section has a wide ambit and can be utilised in any scenario right from breaches pertaining to banking norms to introducing guidelines or amendments to upkeep the integrity of the banking sector. In this regard, Section 35A states, “(1) Where the Reserve Bank is satisfied that – (a) in the public interest; or (aa) in the interest of banking policy; or (b) to prevent the affairs of any banking company being conducted in a manner detrimental to the interests of the depositors or in a manner prejudicial to the interests of the banking company; or (c) to secure the proper management of any banking company generally, it is necessary to issue directions to banking companies generally or to any banking company in particular, it may, from time to time, issue such directions as it deems fit, and the banking companies or the banking company, as the case may be, shall be bound to comply with such directions.” This implies that the RBI has the power to issue such directions if any of the three conditions specified in this Section are met. These conditions are disjunctive, and even if only one among them is fulfilled, the RBI can utilise this power. The present situation entails an overlap of all the stated requirements. Adherence to the regulatory requirements and guidelines is paramount to the effective functioning of the financial ecosystem, and any form of deviance affects the confidence of the investors and affiliated business entities, thus negatively affecting the public interest. Non-compliance also indicates that the management of the banking company is not being conducted properly. Therefore, since the conditions mentioned in this Section (at least one) are fulfilled, the utilisation of the power prescribed is

RBI’s Regulatory Clampdown: Navigating the Paytm Saga Read More »

Scroll to Top