RBI master-direction RBI/DoS/2026-27/417 · 31 Jul 2026
Official title
Reserve Bank of India (Small Finance Banks - Compliance Function) Directions, 2026
Summary
Check the official recordThe Reserve Bank of India establishes a regulatory framework for the compliance function within Small Finance Banks. These directions mandate an independent compliance department headed by a Chief Compliance Officer (CCO) to manage compliance risk. Banks must implement a board-approved compliance policy, conduct annual risk assessments, and maintain a robust compliance culture. The CCO must meet specific fit and proper criteria, including a minimum of 15 years of experience in banking or financial services. The compliance function must remain separate from internal audit and business operations to avoid conflicts of interest. Banks must deploy integrated technology solutions for monitoring and reporting. These directions take immediate effect and supersede previous guidelines regarding the compliance function for Small Finance Banks.
What you must do
Key dates
Who is affected
Thresholds
Exceptions
If you do not comply
RBI/DoS/2026-27/417
DoS.CO.PPG.11/11.01.005/2026-27
July 31, 2026
Introduction
Chapter I - Preliminary
A. Short Title and Commencement
B. Applicability
C. Definitions
Chapter II - Governance and Oversight
A. Role of the Board
B. Role of the Senior Management
C. Compliance Policy
Chapter III - Scope, Structure and Responsibilities
A. Scope
B. Group-wide Compliance
C. Structure
D. Staffing
E. Roles and Responsibilities
F. Compliance Culture
G. Quality Assurance and Internal Audit
Chapter IV - Chief Compliance Officer
A. Appointment
B. Authority, Stature, and Independence
C. Reporting Requirements
D. Roles and Responsibilities
Chapter V - Use of Technology for Monitoring
Chapter VI - Repeal and Other Provisions
A. Repeal and Saving
B. Application of Other Laws Not barred
C. Interpretations
Compliance function is a key element of a bank’s corporate governance framework and an integral part of assurance, alongside internal audit and risk management processes. The principles governing the Compliance function are aligned with the Basel Committee on Banking Supervision framework, adapted to the Indian operating environment, and extend to bank-led Financial Conglomerates for managing group-wide compliance risk. While minimum standards are prescribed, the bank shall organise its Compliance function and prioritise compliance risk management in a manner commensurate with its size, complexity, risk profile, and organisational structure.
In exercise of the powers conferred by Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues Directions hereinafter specified.
These Directions shall be called the Reserve Bank of India (Small Finance Banks - Compliance Function) Directions, 2026.
These Directions shall come into effect immediately upon issuance.
The Board shall have an overall responsibility for the effective oversight and management of the bank’s Compliance function and compliance risk.
The Board shall ensure that the bank has an appropriate Compliance Policy in place and shall oversee its effective implementation. The Board shall review the policy at least annually.
The Board shall ensure that compliance issues are resolved effectively and expeditiously by senior management with the assistance of compliance staff. If necessary, the Board may delegate these tasks to the Audit Committee of the Board (ACB).
The Board or ACB shall review the Compliance function on a quarterly basis. A detailed annual review should also be placed before the Board / ACB. The Chief Compliance Officer (CCO) should be an invitee to such meetings.
The Board shall ensure that the Compliance function and the Internal Audit function of the bank are kept separate.
The Managing Director and Chief Executive Officer (MD & CEO) shall ensure the presence of an independent Compliance function and adherence to the compliance policy of the bank.
The senior management shall establish a written Compliance policy which should contain the basic principles to be followed by the management and staff and explain the process by which compliance risk shall be identified and managed through all levels of the bank.
The senior management shall ensure that appropriate remedial or disciplinary action is taken if breaches are identified.
Senior management shall, with the assistance of the Compliance Function:
The Board-approved Compliance policy of the bank should clearly spell out its compliance philosophy, expectations on compliance culture covering tone from the top, accountability, incentive structure, effective communication and challenges thereof, structure and role of the Compliance function, authority, and role of the CCO, processes for identifying, assessing, monitoring, managing, and reporting on compliance risk throughout the bank.
The Compliance policy shall, inter alia, adequately consider the size, complexity, and compliance risk profile of the bank, expectations on ensuring compliance to all applicable statutory provisions, rules, and regulations, various codes of conduct (including the voluntary ones) and the bank’s own internal rules, policies and procedures, and a disincentive structure for compliance breaches. The policy should emphasise building up compliance culture, vetting of the quality of reports provided to RBI by the bank.
The policy should cover the following aspects: