RBI master-direction RBI/DoS/2026-27/426 · 31 Jul 2026
Summary
Check the official recordThe Reserve Bank of India establishes a regulatory framework for the compliance function in Payments Banks. Banks must maintain an independent compliance department headed by a Chief Compliance Officer (CCO) to manage compliance risk. The Board of Directors holds ultimate responsibility for oversight, including the approval of a compliance policy and annual reviews. The CCO must meet specific fit and proper criteria, possess at least 15 years of experience, and serve a minimum three-year tenure. Banks must implement enterprise-wide technology solutions for monitoring compliance and ensure the compliance function remains separate from internal audit. These directions apply immediately to all Payments Banks, replacing previous instructions on the subject.
What you must do
Key dates
Who is affected
Thresholds
Exceptions
If you do not comply
RBI/DoS/2026-27/426 DoS.CO.PPG.20/11.01.005/2026-27
July 31, 2026
Reserve Bank of India (Payments Banks - Compliance Function) Directions, 2026
Table of Contents
Introduction
Chapter I - Preliminary
Chapter II - Governance and Oversight
Chapter III - Scope, Structure and Responsibilities
Chapter IV - Chief Compliance Officer
Chapter V - Use of Technology for Monitoring
Chapter VI - Repeal and Other Provisions
Introduction
Compliance function is a key element of a bank’s corporate governance framework and an integral part of assurance, alongside internal audit and risk management processes. The principles governing the Compliance function are aligned with the Basel Committee on Banking Supervision framework, adapted to the Indian operating environment, and extend to bank-led Financial Conglomerates for managing group-wide compliance risk. While minimum standards are prescribed, the bank shall organise its Compliance function and prioritise compliance risk management in a manner commensurate with its size, complexity, risk profile, and organisational structure.
In exercise of the powers conferred by Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues Directions hereinafter specified.
Chapter I - Preliminary
A. Short Title and Commencement
These Directions shall be called the Reserve Bank of India (Payments Banks - Compliance Function) Directions, 2026.
These Directions shall come into effect immediately upon issuance.
B. Applicability
C. Definitions
Chapter II - Governance and Oversight
A. Role of the Board
The Board shall have an overall responsibility for the effective oversight and management of the bank’s Compliance function and compliance risk.
The Board shall ensure that the bank has an appropriate Compliance Policy in place and shall oversee its effective implementation. The Board shall review the policy at least annually.
The Board shall ensure that compliance issues are resolved effectively and expeditiously by senior management with the assistance of compliance staff. If necessary, the Board may delegate these tasks to the Audit Committee of the Board (ACB).
The Board or ACB shall review the Compliance function on a quarterly basis. A detailed annual review should also be placed before the Board / ACB. The Chief Compliance Officer (CCO) should be an invitee to such meetings.
The Board shall ensure that the Compliance function and the Internal Audit function of the bank are kept separate.
B. Role of the Senior Management
The Managing Director and Chief Executive Officer (MD & CEO) shall ensure the presence of an independent Compliance function and adherence to the compliance policy of the bank.
The senior management shall establish a written Compliance policy which should contain the basic principles to be followed by the management and staff and explain the process by which compliance risk shall be identified and managed through all levels of the bank.
The senior management shall ensure that appropriate remedial or disciplinary action is taken if breaches are identified.
Senior management shall, with the assistance of the Compliance Function:
C. Compliance Policy
The Board-approved Compliance policy of the bank should clearly spell out its compliance philosophy, expectations on compliance culture covering tone from the top, accountability, incentive structure, effective communication and challenges thereof, structure and role of the Compliance function, authority, and role of the CCO, processes for identifying, assessing, monitoring, managing, and reporting on compliance risk throughout the bank.
The Compliance policy shall, inter alia, adequately consider the size, complexity, and compliance risk profile of the bank, expectations on ensuring compliance to all applicable statutory provisions, rules, and regulations, various codes of conduct (including the voluntary ones) and the bank’s own internal rules, policies and procedures, and a disincentive structure for compliance breaches. The policy should emphasise building up compliance culture, vetting of the quality of reports provided to RBI by the bank.
The policy should cover the following aspects: