RBI master-direction RBI/DOR/2025-26/363 · 28 Nov 2025
Summary
Check the official recordThe Reserve Bank of India issues these Directions to manage risks in outsourcing of financial and IT services by Non-Banking Financial Companies (NBFCs). NBFCs must establish a Board-approved policy for outsourcing, evaluate risks, and maintain oversight of service providers. The Directions mandate specific governance, risk management, and audit requirements for material outsourcing arrangements. NBFCs remain responsible for customer service, data confidentiality, and grievance redressal regardless of outsourcing. Existing IT outsourcing agreements must comply with these provisions by April 10, 2026, or at the time of renewal, whichever is earlier. New IT outsourcing agreements must comply immediately. These Directions apply to various categories of NBFCs based on their regulatory layer.
What you must do
Key dates
Who is affected
Exceptions
If you do not comply
RBI/DOR/2025-26/363 DOR.ORG.REC.No.282/21-04-158/2025-26 November 28, 2025
In exercise of the powers conferred by Section 45L of the Reserve Bank of India Act, 1934 and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues the Directions hereinafter specified.
Provided that for Non-Banking Financial Companies covered under the scope of these Directions, as mentioned in paragraph 3, their existing Information Technology (IT) outsourcing agreements regardless of whether they are due for renewal on or after the effective date of these Directions shall comply with the provisions of these Directions either at the time of renewal or by April 10, 2026, whichever is earlier. However, their new IT outsourcing agreements that come into force on or after the effective date of these Directions, shall comply with the provisions of these Directions from the date of agreement itself.
Provided further that, nothing in the preceding proviso shall be construed as permitting non-compliance with any other extant regulatory instructions or statutory requirements applicable to such arrangements.
(i) NBFC-D registered with the RBI under the provisions of the RBI Act, 1934; (ii) NBFC-ICC registered with the RBI under the provisions of the RBI Act, 1934; (iii) NBFC-Factor registered with the RBI under the provisions of the Factoring Regulation Act, 2011; (iv) NBFC-MFI registered with the RBI under the provisions of the RBI Act, 1934; (v) NBFC-IFC registered with the RBI under the provisions of the RBI Act, 1934; (vi) IDF-NBFC registered with the RBI under the provisions of the RBI Act, 1934; (vii) HFC registered with the RBI under the provisions of the NHB Act, 1987; (viii) SPDs registered with the RBI under the provisions of the RBI Act, 1934; (ix) CICs registered with the RBI under the provisions of the RBI Act, 1934; (x) NBFC-P2P registered with the RBI under the provisions of the RBI Act, 1934; (xi) NBFC-AA registered with the RBI under the provisions of the RBI Act, 1934.
(2) The provisions prescribed in these directions except Chapter IV and IT-specific provisions contained in Chapter II (e.g., Board-level IT outsourcing policy and responsibilities of and reviews by the Board with respect to IT outsourcing) of these Directions shall apply to NBFCs included in Base layer. These directions including Chapter IV and IT-specific provisions contained in Chapter II are applicable for NBFCs in Middle layer and above layers.
(3) The paragraphs contained in Chapter IV and IT-specific paragraphs contained in Chapter II are applicable for an MGC registered with RBI under the scheme of Registration of Mortgage Guarantee Companies, categorized in Middle layer and above layers.
(4) These Directions are not applicable for NOFHC registered with the RBI as NBFC under the provisions of the RBI Act, 1934.
Note: The applicability under these Directions is in line with the regulatory structure for NBFCs as set out in Reserve Bank of India (Non-Banking Financial Companies – Registration, Exemptions and Framework for Scale Based Regulation) Directions, 2025.
(1) The provisions shall apply to material outsourcing arrangements entered into by an NBFC with a service provider which may be either a member of the group / conglomerate to which the NBFC belongs, or an unrelated party which is located in India or elsewhere for outsourcing of financial services like applications processing (loan origination, credit card), document processing, marketing and research, supervision of loans, data processing and back office related activities.
Provided that for outsourced services relating to credit cards, the provisions set out in the Reserve Bank of India (Non-Banking Financial Companies – Credit Cards: Issuance and Conduct) Directions, 2025, as amended from time to time, shall also apply to the applicable entities.
(2) The provisions shall not apply to outsourcing of:
(i) IT services as defined in paragraph 58(1) of these Directions, unless specified otherwise in respective paragraphs of Chapter IV; and (ii) activities unrelated to financial services like usage of courier, catering of staff, housekeeping and janitorial services, security of the premises, movement and archiving of records, etc.
(1) The provisions shall apply to an NBFC’s material outsourcing of IT services, as defined in paragraph 58(2) above. In this context, ‘Outsourcing of IT Services’ shall include outsourcing of the following services:
(i) IT infrastructure management, maintenance and support (hardware, software or firmware); (ii) network and security solutions, maintenance (hardware, software or firmware); (iii) application development, maintenance and testing by Application Service Providers (ASPs) including ATM Switch ASPs; (iv) services and operations related to data centres; (v) cloud computing services; (vi) managed security services; and (vii) management of IT infrastructure and technology services associated with payment system ecosystem.
(2) The provisions shall not apply to the following services / activities,
(i) corporate internet banking services obtained by an NBFC as a corporate customer or sub-member of another Regulated Entity (RE);
Provided that for the purpose of these Directions, the following indicative (but not exhaustive) list of entities shall be considered as REs –Commercial Banks; Local Area Banks; Small Finance Banks; Payments Banks; Regional Rural Banks; other NBFCs in Base Layer (NBFC - BL), Middle Layer (NBFC - ML), and Upper Layer (NBFC – UL); All India Financial Institutions; Credit Information Companies; Urban Co-operative Banks; Rural Co-operative Banks; and Payment System Operators,