Reserve Bank of India (Local Area Banks – Miscellaneous) Supervisory Directions, 2026
The Reserve Bank of India has issued comprehensive supervisory directions for Local Area Banks (LABs) covering fair practices in interest charging, management of inoperative accounts, fraud prevention, protected disclosure schemes, vigilance, network management, and cybersecurity for third-party ATM switch providers. Banks are required to ensure transparency in loan interest calculations, actively reduce inoperative accounts, and implement robust internal vigilance and fraud prevention mechanisms. Additionally, banks must ensure their third-party ATM switch service providers adhere to stringent cybersecurity controls, including vulnerability assessments, incident response, and data protection. These directions are effective immediately and supersede previous instructions on these subjects.
AI-prepared change brief
Check the official recordWhat changed
The Reserve Bank of India has issued comprehensive supervisory directions for Local Area Banks (LABs) covering fair practices in interest charging, management of inoperative accounts, fraud prevention, protected disclosure schemes, vigilance, network management, and cybersecurity for third-party ATM switch providers. Banks are required to ensure transparency in loan interest calculations, actively reduce inoperative accounts, and implement robust internal vigilance and fraud prevention mechanisms. Additionally, banks must ensure their third-party ATM switch service providers adhere to stringent cybersecurity controls, including vulnerability assessments, incident response, and data protection. These directions are effective immediately and supersede previous instructions on these subjects.
- Who is affected
- Local Area Banks
- Third-party ATM Switch Application Service Providers
- Required action
- Review and correct unfair interest charging practices.
- Report progress on reduction of inoperative accounts and KYC updation to RBI.
- Frame a Board-approved Protected Disclosure Scheme.
- Designate a Chief of Internal Vigilance (CIV).
- Key dates
- Effective date of the Directions — 30 Jul 2026
- Exceptions
- Anonymous or pseudonymous complaints are not entertained under the Protected Disclosure Scheme.
- Consequences
- Action against complainants for motivated or vexatious complaints.
- Inclusion of loan officials in the list of officers with doubtful integrity.
Source details
- Source
- Reserve Bank of India
- Type
- master-direction
- Published by source
- 30 Jul 2026
- Document number
- RBI/DoS/2026-27/450
- Issuing division
- Department of Supervision
- Effective date
- 30 Jul 2026
- Coverage area
- banking
Document text
RBI/DoS/2026-27/450 DoS.CO.PPG.44/11.01.005/2026-27 July 31, 2026
Reserve Bank of India (Local Area Banks – Miscellaneous) Supervisory Directions, 2026
Table of Contents
- Chapter I - Preliminary
- A. Short Title and Commencement
- B. Applicability
- C. Definitions
- Chapter II - Fair Practices Code - Charging of Interest
- Chapter III - Inoperative Accounts / Unclaimed Deposits
- Chapter IV – Fraud Prevention Measures
- A. Frauds due to Collusion of the bank Officials
- B. Large Value Frauds
- C. Frauds by Deposit of Fake Title Deeds of Property
- D. Safe Custody of Critical Documents
- E. Accounts opened by Employees
- F. Other Instructions
- Chapter V - Protected Disclosure Scheme
- A. Scope and Coverage
- B. Procedure for Lodging the Complaint under the Scheme
- C. Protected Disclosure Policy
- Chapter VI – Vigilance
- A. Preamble
- B. Introduction
- C. Vigilance Angle
- D. Chief of Internal Vigilance
- D.1 Appointment
- D.2 Tenure
- D.3 Association with Sensitive Matters
- D.4 Submission of Reports and Returns - Review
- E. Preventive Vigilance
- F. Staff Rotation and Mandatory Leave
- G. Complaints
- H. Investigation Agency for Conducting Investigations
- I. Review of Cases entrusted to Investigating Agencies
- J. Action against Persons making False Complaints
- K. Liaison with Agencies
- Chapter VII - Network Management
- Chapter VIII - Cyber Security controls for Third party ATM Switch Application Service Providers
- Chapter IX - Repeal and Other Provisions
- A. Repeal and Saving
- B. Application of Other Laws Not Barred
- C. Interpretations
In exercise of the powers conferred by Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues Directions hereinafter specified.
Chapter I - Preliminary
A. Short Title and Commencement
- These Directions shall be called the Reserve Bank of India (Local Area Banks – Miscellaneous) Supervisory Directions, 2026.
- These Directions shall come into effect immediately upon issuance.
B. Applicability
- These Directions shall be applicable to Local Area Banks (hereinafter collectively referred to as 'banks' and individually as 'bank').
C. Definitions
-
In Chapter VIII of these Directions, unless the context states otherwise, the terms therein shall bear the meanings assigned to them below, which are sourced from FSB Cyber Lexicon unless explicitly mentioned otherwise: (1) ‘Audit Trail’ - A chronological record that reconstructs and examines the sequence of activities surrounding or leading to a specific operation, procedure, or event in a security-relevant transaction from inception to result. (Source: NIST SP 800-53r5 on Security and Privacy Controls for Information Systems and Organizations) (2) ‘Cyber’ - Relating to, within, or through the medium of the interconnected information infrastructure of interactions among persons, processes, data, and information systems. (3) ‘Cybersecurity’ - Preservation of confidentiality, integrity, and availability of information and / or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non-repudiation, and reliability can also be involved. (4) ‘Cyber Incident’ - A cyber event that adversely affects the cybersecurity of an information asset whether resulting from malicious activity or not. (Source: Cyber incident definition is adapted from FSB Cyber Lexicon. By the definition, it includes cybersecurity as well as IT incident) (5) ‘Cyber Resilience’ - The ability of an organisation to continue to carry out its mission by anticipating and adapting to cyber threats and other relevant changes in the environment and by withstanding, containing, and rapidly recovering from cyber incidents. (6) ‘Cyber-attack’ - Malicious attempt(s) to exploit vulnerabilities through the cyber medium to damage, disrupt, or gain unauthorised access to assets. (7) ‘Cyber Threat’ - A circumstance with the potential to exploit one or more vulnerabilities that adversely affects cybersecurity. (8) ‘De-militarized Zone (DMZ)’ - A perimeter network segment that is logically between internal and external networks. (Source: NIST SP 800-82 Rev. 2) (9) ‘Distributed Denial of Service (DDoS)’ - A denial of service that is carried out using numerous sources simultaneously. (10) ‘Framework’ - A structured set of strategies, policies, processes, methods, and best practices that guides organisational activities, enables governance and control, and supports the achievement of defined objectives. (Source: adapted from ISACA glossary and ISO 22340:2024) (11) ‘Information Asset’ - Any piece of data, device, or other component of the environment that supports information-related activities. Information Assets include information system, data, hardware, and software. (Source: Information Asset definition is adapted from “Guidance on cyber resilience for financial market infrastructures” publication of Bank for International Settlements and International Organization of Securities Commissions of June 2016) (12) ‘Information System’ - Set of applications, services, information technology assets, or other information-handling components, which includes the operating environment and networks. (13) ‘Malware’ - Software designed with malicious intent containing features or capabilities that can potentially cause harm directly or indirectly to entities or their information systems. (14) ‘Penetration Testing’ - A test methodology in which assessors typically working under specific constraints, attempt to circumvent or defeat the security features of an information system. (15) ‘Privileged User’ - A user who, by virtue of function, and / or role, has been allocated powers within an information system, which are significantly greater than those available to the majority of users. (Source: adapted from ISO/IEC 24775-2:2021) (16) ‘Vulnerability’ - A weakness, susceptibility, or flaw of an asset or control that can be exploited by one or more threats. (17) ‘Vulnerability Assessment (VA)’ - Systematic examination of an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures and confirm the adequacy of such measures after implementation.
-
All other expressions unless defined herein shall have the same meaning as have been assigned to them under the Reserve Bank of India Act, 1934, the Banking Regulation Act, 1949, the Companies Act, 2013, or any statutory modification or re-enactment thereto or other regulations issued by the RBI or the Glossary of Terms published by the RBI, or as used in commercial parlance, as the case may be.
Chapter II - Fair Practices Code - Charging of Interest
-
The bank, in the interest of fairness and transparency, shall review its practices regarding mode of disbursal of loans, application of interest and other charges, charging of Equated Monthly Instalments (EMIs), and take corrective action, including system level changes, as may be necessary, to address unfair practices, some of which are briefly explained below: (1) Charging of interest from the date of sanction of loan or execution of loan agreement and not from the date of actual disbursement of funds to the customer. For loans disbursed by cheque, charging interest from the cheque date while handing over the cheque to the customer several days later. (2) Charging of EMIs on the sanctioned loan amount rather than on the actual disbursed amount, without the knowledge or consent of the borrower. (3) Any changes in the amortisation schedule originally provided in the Key Facts Statement (KFS), with each part-disbursement of loan, not being communicated to the borrowers. (4) In case of disbursal or repayment of loans during a month, charging interest for the entire month rather than charging interest only for the period for which the loan was outstanding. (5) Collecting one or more instalments in advance but reckoning the full loan amount for charging interest.
-
These and other such non-standard practices of charging interest are not in consonance with the spirit of fairness and transparency while dealing with customers. These are matters of serious concern to the RBI.
-
The bank may use online account transfers in lieu of cheques for loan disbursal.
Research the source law
Find the provision behind this update.
No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source lawsRelated RBI updates
- Governor’s Statement: August 5, 2026
- Monetary Policy Statement, 2026-27 Resolution of the Monetary Policy Committee August 3 to 5, 2026
- Money Market Operations as on August 4, 2026
- Statement on Developmental and Regulatory Policies
- Directions under Section 35A read with Section 56 of the Banking Regulation Act, 1949 – The Pusad Urban Co-operative Bank Ltd., Pusad, Dist. Yavatmal, Maharashtra – Extension of Period