A practitioner’s guide to the regulatory architecture, the scale-based regulation overlay and the enforcement reality NBFCs; from the smallest base layer lender to upper Layer now operate under : Has Your AML Programme Caught Up?
1. Why NBFCs Can No Longer Treat AML as a Bank Problem
Non-Banking Financial Companies used to sit at the edge of India’s AML/CFT conversation – a compliance obligation copied, often loosely, from bank circulars and adapted after the fact. That framing is now obsolete for two independent reasons.
First, NBFCs are no longer peripheral to the credit system. They collectively account for a substantial and growing share of retail and MSME credit in India, and several among them sit in the Reserve Bank of India’s Upper Layer (NBFC-UL) category, the supervisory tier reserved for NBFCs whose systemic footprint approaches that of a bank. Systemic scale invites systemic scrutiny, and India’s post-2018 shadow-banking stress (IL&FS, DHFL) has left the RBI with little patience for treating NBFC governance as a lighter-touch afterthought.
Second, and more concretely, the RBI has stopped treating NBFC KYC/AML compliance as a shared appendix to bank regulation. On 28 November 2025, as part of a sweeping consolidation of roughly 3,500 circulars and directions into 238 Master Directions, the RBI repealed the unified 2016 Master Direction on KYC and replaced it with ten sector-specific KYC Master Directions – one of them the standalone Reserve Bank of India (Non-Banking Financial Company – Know Your Customer) Directions, 2025. NBFCs now have their own dedicated KYC/AML rulebook for the first time, rather than a document written primarily with banks in mind and extended to NBFCs by cross-reference. That rulebook has already been refined once since: the Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Amendment Directions, 2025 (RBI/2025-26/160), dated 29 December 2025, inserted an explanation into paragraph 63 clarifying that where an NBFC downloads and relies on KYC records from the Central KYC Registry (CKYCR), the identity/address re-verification duty sits with whichever regulated entity last uploaded the record, provided it is current and PML Act/Rules-compliant. This reallocates re-verification risk on CKYCR-sourced onboarding rather than adding a new substantive obligation, and it is worth building into any CDD workflow that leans on CKYCR downloads.
2. RBI’s Internal Risk Assessment Guidance: The Document the Rest of the Programme Should Trace Back To
On 10 October 2024, the RBI issued the Internal Risk Assessment Guidance for Money Laundering/Terrorist Financing Risks, applicable to all its regulated entities – banks, All India Financial Institutions, NBFCs, Authorised Persons and Payment System Operators. It is easy to file this alongside the dozens of guidance notes an NBFC compliance function tracks, but it sits in a different category: it is the methodology document the rest of the AML/CFT programme is meant to be built on, not a peripheral input to it.
The Guidance formalises a dual-level Internal Risk Assessment (IRA): a Business-level IRA, assessing the ML/TF/PF risk inherent in the NBFC’s own business model – its products, customer segments, delivery channels (branch, DSA, LSP/DLA, co-lending), and geographic footprint – and a Customer-level IRA, the individual risk-categorisation exercise applied at onboarding and reviewed periodically under the KYC Directions. The two levels are meant to inform each other: the Business-level IRA should shape what triggers escalate a customer’s risk rating, and patterns emerging from customer-level categorisation should, in turn, sharpen the Business-level assessment over time.
Methodologically, the Guidance directs REs to draw on both internal sources (STR filing history, transaction-monitoring alert patterns, internal audit and inspection findings, customer complaint data) and external sources (FATF statements on jurisdictions, sectoral risk observations the RBI or FIU-IND may share from time to time, publicly available typology reports) to build a Risk-Based Approach that is evidenced rather than templated.
The practical implication for an NBFC building or auditing its AML programme: the Customer Acceptance Policy, the risk-categorisation matrix, the EDD triggers, and the transaction-monitoring rule library should each be traceable to, and defensible against, the institution’s own IRA output – not drafted as free-standing documents into which a risk assessment is retrofitted after the fact. An RBI examiner reviewing an NBFC’s AML policy is, in substance, testing whether it follows from the IRA; a policy that cannot show that lineage is vulnerable on inspection even where every individual control looks reasonable on its own. The IRA is also where Scale-Based Regulation’s proportionality does its real work (see Section 4): a Base Layer NBFC’s Business-level IRA should look different in scope and depth from an Upper Layer NBFC’s, but both are expected to produce one – in writing, board-approved, and revisited as the business or its risk environment changes.
3. The Regulatory Foundation
| Instrument | What It Establishes for NBFCs |
| PMLA, 2002 and PML Rules, 2005 | NBFCs are “financial institutions” under Section 2(1)(l) of the PMLA and are reporting entities in their own right – obligated to maintain records, verify client identity, and file Cash Transaction Reports (CTRs) and Suspicious Transaction Reports (STRs) with FIU-IND |
| RBI (NBFC – Know Your Customer) Directions, 2025 | The new standalone KYC/AML rulebook for NBFCs, replacing the 2016 Master Direction from 28 November 2025; sets out Customer Due Diligence, risk categorisation, PEP and sanctions screening, and record-keeping obligations specific to the sector |
| UAPA, 1967, Section 51A | Requires NBFCs, like every other RE, to screen against UNSC and MHA-designated lists and freeze matched assets without delay |
| WMD Act, 2005 | Extends targeted financial sanctions obligations to proliferation-financing designations |
| Master Direction – RBI (NBFC – Scale Based Regulation) Directions, 2023 | Classifies every NBFC into Base, Middle, Upper or Top Layer and sets the governance intensity – committee structures, independent oversight – that wraps around the AML/KYC obligation |
| Guidelines on Digital Lending, 2022/2025 | Fixes accountability for KYC and AML performed through Lending Service Providers (LSPs) and Digital Lending Apps squarely on the regulated NBFC, not the outsourced partner |
Every NBFC, regardless of size, is required to have a board-approved KYC/AML policy, a Customer Acceptance Policy that names prohibited customer categories rather than relying on generic risk language, a Principal Officer responsible for AML/KYC matters, and a Designated Director with board-level accountability. None of this is optional or size-contingent – a point worth dwelling on in the next section.
One provision in the KYC Directions that is easy to under-read is the requirement for a Group-Wide AML/CFT Policy. Where an NBFC is part of a group – a bank-NBFC combine, an NBFC with a housing finance or broking subsidiary, or a group that also runs a Prepaid Payment Instrument (PPI) issuing entity – it is required to implement a group-wide AML/CFT policy and to share customer due diligence and risk information across the regulated entities within that group, subject to confidentiality and data-protection safeguards. The obligation runs between the group’s regulated entities; it does not extend to unregulated entities within the same corporate structure, but it does mean an NBFC cannot treat its AML programme as siloed from what a sibling regulated entity in the same group knows about a shared customer.
This matters more than it might first appear for NBFC groups that also run a PPI-issuing entity. PPI risk is often assessed as comparatively low at the individual-instrument level – small wallet limits, minimum-KYC variants, and closed-loop use cases limit exposure per instrument – but the aggregate picture across a large, low-friction wallet base is a different question, and RBI’s own supervisory experience (restrictions placed on a major payments bank’s PPI and wallet operations in 2024, driven substantially by accounts that lacked proper identification) is a reminder that the risk is real even where it is individually small. A group-wide AML policy is precisely the mechanism that should catch a customer who looks low-risk in the NBFC’s lending book but shows a very different pattern in the group’s PPI wallet – an NBFC that has not built that cross-entity visibility into its group AML policy is leaving a gap examiners increasingly know to look for.
4. Scale-Based Regulation: What Actually Scales, and What Doesn’t
Since October 2022, the RBI’s Scale-Based Regulation (SBR) framework has sorted every NBFC into one of four layers based on size, activity and systemic importance: Base Layer (NBFC-BL, non-deposit-taking entities with assets under ₹1,000 crore, along with lighter categories such as P2P platforms and account aggregators), Middle Layer (NBFC-ML, every deposit-taking NBFC regardless of size, plus non-deposit-taking NBFCs above ₹1,000 crore in assets), Upper Layer (NBFC-UL, systemically significant NBFCs identified by RBI scoring methodology, subject to bank-like supervisory intensity for a minimum of five years once classified), and Top Layer (NBFC-TL, reserved for NBFCs the RBI judges to pose outsized systemic risk even within the Upper Layer). Bajaj Finance Limited has featured on RBI’s published Upper Layer list since the framework’s first classification cycle in 2023-24, alongside names like LIC Housing Finance.
What the SBR framework changes as an NBFC moves up the layers is governance intensity: Middle and Upper Layer NBFCs must constitute a Risk Management Committee, appoint an independent Chief Compliance Officer, and include at least one board member with genuine banking or financial sector experience. At the Upper Layer specifically, the RBI has gone further still on the technology dimension – model risk management for any AI or statistical model influencing collections prioritisation, contact strategy or account resolution is now an explicit board-level obligation, not an internal data-science practice the compliance function merely signs off on.
What does not change across layers is the core KYC/AML floor. No asset-size threshold reduces the core compliance obligation: a single-license NBFC with modest assets carries the same Customer Identification Procedure and ongoing monitoring duties as a large, systemically significant lender. The practical implication for a Base Layer NBFC is important and frequently missed: SBR proportionality applies to governance architecture – committee structures, independence requirements, board composition – not to whether CDD, risk categorisation, or STR filing can be done more lightly. A ten-person NBFC-BL gold-loan lender and Upper layer NBFC are answering to the same underlying AML rulebook; they differ in the seniority and formality of the oversight wrapped around it, not in the substance of what must be checked.
5. Risk Categorisation, EDD, and the Periodic Review Cycle
NBFCs are required to categorise every customer into low, medium or high risk at onboarding, with the categorisation reviewed periodically rather than fixed permanently at account opening. This is not a paperwork formality: risk-categorisation failure – accounts left in an outdated tier, or never re-reviewed after onboarding – features repeatedly among the violations cited in RBI’s supervisory actions against NBFCs, often alongside inadequate systems for identifying and reporting suspicious transactions.
Periodic KYC updation is where NBFCs have historically struggled operationally, given large low-ticket retail books with high customer turnover. The RBI’s most recent relief measure – extending the KYC updation deadline for low-risk customers to one year from their KYC due date or 30 June 2026, whichever is later comes with a specific procedural condition: NBFCs must send at least three advance reminder notifications before restricting an account, including at least one by physical letter, not solely digital channels. Missing that structured communication sequence is, under current guidance, a distinct compliance failure from the KYC updation lapse itself – a distinction worth building into any periodic-review workflow rather than treating the two as a single checkbox.
Enhanced due diligence obligations – source of wealth and source of funds verification, senior management approval, more frequent monitoring applies to high-risk customers, PEPs, and customers onboarded through non-face-to-face or simplified channels in the same manner as for banks, discussed at length elsewhere in this series. What is distinctly NBFC-relevant is the next section’s concern: what happens when the customer relationship itself runs through a technology partner the NBFC does not directly employ.
6. The NBFC-Specific Complication: Digital Lending and LSP Accountability
A meaningful share of new-to-credit NBFC customers today are onboarded through Digital Lending Apps (DLAs) operated by Lending Service Providers (LSPs) – fintech partners that source borrowers, assist with KYC data capture, support underwriting, and sometimes manage collections, without themselves holding a lending licence. The RBI’s Digital Lending Directions, most recently consolidated in 2025, establish a principle that should anchor every NBFC’s outsourcing risk assessment: outsourcing does not dilute responsibility. The regulated NBFC remains fully accountable for every act and omission of its LSPs and DLAs, regardless of how much it delegates.
Two specific requirements follow directly from this principle and deserve to sit inside the NBFC’s own AML policy, not just its vendor contracts:
- The KYC process itself must be completed by the regulated entity, not outsourced wholesale to the LSP. An LSP may capture documents, run liveness checks, or facilitate Aadhaar e-KYC or Video-KYC, but the compliance determination – whether CDD is complete, whether the customer clears screening, whether the risk category is correctly assigned, remains the NBFC’s own act, attributable to its Principal Officer.
- Every RE-LSP engagement must run on a formal contract defining roles, responsibilities and liabilities, with enhanced due diligence conducted on each LSP covering its technical capability, data-handling practices, conduct history and regulatory record – reviewed periodically, not once at onboarding. Non-adherence to KYC/AML norms in this chain can trigger action under Section 47A of the RBI Act, 1934, including fines or suspension of operations, quite separately from any DPDP Act data-localisation exposure the same LSP relationship may also carry.
A practical consequence: an NBFC’s vendor due diligence and right-to-audit discipline for its screening and KYC technology vendors – covered at length elsewhere in this series – applies with even greater force to LSPs, because an LSP failure surfaces as the NBFC’s own KYC/AML violation in an RBI inspection, not as a third-party incident the NBFC can distance itself from.
7. Sector-Specific Money Laundering Vectors
NBFC business models create typology patterns that differ meaningfully from a bank’s deposit-and-payments book, and a transaction-monitoring programme copied wholesale from banking practice will miss several of them:
- Structuring through top-up and repeat loans: rapid, repeated small-ticket disbursals and prepayments – particularly in consumer durable and personal loan books – can be used to cycle funds through a lending relationship rather than a deposit account, since repayment sources are rarely scrutinised with the same rigour as disbursal sources.
- Third-party loan repayment: repayments funded from accounts unconnected to the declared borrower, a pattern more structurally common in NBFC retail lending (family members, employers, or unrelated third parties settling installments) than in banking, which can mask the true source of funds behind an otherwise legitimate-looking loan account.
- Gold loan and asset-backed lending anonymity: gold loan NBFCs handle high transaction volumes against a physical asset with limited documentary trail on the seller/source side, a vector, regulators have flagged repeatedly in enforcement commentary on the sector.
- Group-lending and MFI household-verification gaps: microfinance NBFCs (NBFC-MFI) rely on group-based verification and household income assessment rather than the individual documentary trail a bank would require, creating scope for identity layering across group members if verification discipline slips.
- Co-lending and pass-through structures: co-lending arrangements between banks and NBFCs, and pass-through structures with LSPs, can obscure which entity actually performed CDD on a given borrower unless the arrangement explicitly allocates and documents that responsibility.
- PPI and wallet-linked flows within NBFC groups: where the NBFC’s group includes a PPI issuer, small-value, minimum-KYC wallets can be used to layer or fragment value that would trigger scrutiny in the lending book – multiple wallets linked to related mobile numbers, rapid load-and-drain cycles, or wallets funded from third-party sources unconnected to the declared customer. The risk per instrument is low; the risk across an unmonitored wallet base is not, and it is a typology that transaction-monitoring rules built around the lending book alone will typically miss.
None of these require an NBFC to build an entirely new detection framework from scratch but they do require the transaction-monitoring rule library and alert-typology tagging to be built around actual NBFC product behaviour, not imported unchanged from a bank’s rulebook.
8. The Enforcement Reality: What RBI Is Actually Penalising
The clearest signal of where NBFC AML/KYC compliance is falling short comes from RBI’s own recent enforcement orders, which have arrived in a steady drumbeat through mid-2026:
- A NBFC was penalised in mid-2026 for failing to regularly review customer risk categorisation and for not implementing an adequate system to identify and report suspicious transactions.
- A NBFC was penalised around the same period for KYC norm violations and failure to conduct mandated periodic account reviews, following a statutory inspection.
- Two smaller NBFCs were penalised in the same window for non-compliance with the RBI’s KYC Directions.
- A NBFC was penalised separately in the same period for governance and credit-concentration norm breaches rather than KYC specifically – a reminder that AML/KYC penalties typically arrive alongside, not instead of, other supervisory findings.
At the aggregate level, RBI’s supervisory activity against NBFCs has intensified through late 2025 and into 2026, with monetary penalties, and in more serious cases suspension of business activity or cancellation of the Certificate of Registration under the RBI Act, 1934, following recurring findings of weak customer verification, failure to file Suspicious Transaction Reports, and inadequate FIU-IND compliance – alongside, in a number of cases, unrelated findings such as net-owned-fund shortfalls and operational dormancy.
The pattern across these orders is instructive: the violations cited are rarely exotic. Stale risk categorisation, missed periodic reviews, and inadequate suspicious-transaction detection systems recur far more often than novel typology failures – which means the highest-value compliance investment for most NBFCs is disciplined execution of well-understood basics, not acquisition of ever more sophisticated detection technology layered on top of a periodic-review process that is quietly falling behind.
9. Beyond the Checklist: Screening Rigour, Alert Quality and the Case for Industry Collaboration
Sections 2 and 8 between them make the point that the obligation is well defined and the enforcement pattern is well documented. What separates NBFCs that pass inspection from those that build a genuinely effective programme is less about which controls exist on paper and more about how rigorously three things are actually done: screening, transaction monitoring, and what happens after an alert fires.
Screening rigour: list-based screening against UN/OFAC/EU/MHA/UAPA designations is often treated as a solved problem once a vendor tool is switched on, but match-quality and false-positive discipline are where the real work sits. Fuzzy-matching thresholds tuned only to minimise analyst workload will also minimise true-positive capture; thresholds tuned only to catch every possible match will bury real hits under noise the team stops reading carefully. Getting this calibration right – and revisiting it as name variations, transliteration issues, and list updates accumulate – is a screening-quality exercise, not a one-time configuration task.
Transaction-monitoring rigour: a rule library imported from a bank’s playbook (see Section 7) and never re-tuned against the NBFC’s own transaction data drifts into two failure modes at once – missing the product-specific typologies particular to lending while generating high volumes of low-value alerts on ordinary retail repayment behaviour that only looks unusual because the rule was never calibrated to it.
Alert triage and STR quality: volume is not the same as value. An STR that restates a system-generated alert without adding investigative substance – the analyst’s own review of the customer relationship, why the pattern is inconsistent with the declared profile, and what was checked and ruled out – gives FIU-IND less to work with than a smaller number of well-reasoned filings, and RBI’s enforcement pattern (Section 8) suggests examiners can tell the difference. Alert disposition deserves the same rigour as the STR itself: a closed alert with no rationale on file is, in substance, an unreviewed alert.
Typology-building from experience: the typologies in Section 7 are not exhaustive and should not be treated as a fixed list. Every closed investigation, every STR that FIU-IND or RBI follows up on, and every near-miss an alert-triage analyst catches is a data point that should feed back into the rule library and the risk-categorisation criteria – an NBFC’s own case history is, over time, a better predictor of its actual risk exposure than any generic typology list, including this one.
Cross-industry collaboration: NBFC business models are heterogeneous enough – gold loans, MFI, digital lending, housing finance, PPI – that no single institution sees the full typology picture, and a pattern one NBFC’s alert-triage team has learned to recognise may be entirely novel to another. Structured information-sharing, whether through FIU-IND’s own engagement channels or an industry-convened forum, is where that experience compounds instead of staying siloed within each institution.
This is where FIDC’s new role is worth watching. The RBI recognised the Finance Industry Development Council (FIDC) as the NBFC sector’s first Self-Regulatory Organisation in October 2025, under RBI’s Omnibus Framework for SRO recognition, with an initial mandate centred on a code of conduct covering governance, responsible lending and customer protection, member monitoring, and acting as an early-warning channel to the RBI. AML/CFT standard-setting is not yet an explicit part of that mandate, but it is a natural extension of it – and there is a working template close at hand. AMFI, the mutual fund industry’s own SRO, has for several years published Recommended Minimum Standards on AML/CFT and KYC Policy for its Asset Management Company members, setting a common risk-categorisation and EDD baseline across the industry rather than leaving each AMC to build one independently, and the KYC Registration Agency (KRA) infrastructure the mutual fund industry built collectively has materially reduced duplicated KYC effort while keeping the underlying due-diligence standard uniform. An FIDC that took on a comparable role for NBFCs – a common AML/CFT minimum-standards document, and a structured channel for typology-sharing across member NBFCs – would do for the sector’s screening and monitoring maturity what AMFI’s initiative has done for the mutual fund industry: raise the floor for smaller members who lack the resources to build sophisticated detection capability independently, without waiting for each individual RBI enforcement order to teach the same lesson to the next NBFC in line.
10. Governance: Making the Obligation Durable, Not Just Documented
Consistent with the SBR framework’s own logic, governance expectations should scale with an NBFC’s size and complexity – but a defensible AML programme at any layer needs the following in place and demonstrably operating:
- A board-approved KYC/AML policy, reviewed at least annually and updated whenever the RBI’s KYC Directions are amended – not left to track the version the NBFC happened to adopt at incorporation.
- A Principal Officer with genuine authority to escalate and act, and a Designated Director carrying board-level accountability for the AML/CFT programme as a whole, consistent with PMLA Rule requirements.
- For Middle and Upper Layer NBFCs specifically: a functioning Risk Management Committee, an independent Chief Compliance Officer (not doubling as a business-facing role), and at least one board member with substantive banking or financial-sector experience, per the SBR governance overlay.
- Documented, periodic ML/TF risk assessment at the institutional level – a standing RBI requirement since an April 2020 KYC Master Direction amendment that applies to banks, All India Financial Institutions, NBFCs and payment system providers alike, with the assessment’s frequency delegable to a board committee such as the Risk Management Committee since an October 2023 amendment, and now operationalised through RBI’s Internal Risk Assessment Guidance for Money Laundering/Terrorist Financing Risks, issued 10 October 2024, which sets out the dual-level Business-IRA/Customer-IRA methodology and the risk-based approach NBFCs are expected to apply in practice.
- Vendor and LSP governance embedded in the NBFC’s own third-party risk framework – enhanced due diligence at onboarding, periodic reassessment, and contractual clarity on where KYC accountability sits – rather than treated as a one-time procurement decision.
- For Upper Layer NBFCs deploying AI or statistical models in collections or transaction monitoring: a live model inventory, validation history and monitoring records maintained against RBI’s explicit expectation that model risk management be a board-level, not purely technical, obligation.
- Independent testing of the AML/KYC function – distinct from the general internal audit cycle – given how directly RBI’s recent enforcement pattern traces failures back to periodic-review and risk-categorisation processes that looked adequate on paper but had drifted in practice.
Summary
The regulatory architecture for NBFC AML/CFT compliance has shifted twice in ways that matter for anyone building or auditing a programme today: NBFCs now answer to their own dedicated KYC rulebook rather than a shared banking document, and the Scale-Based Regulation framework has made explicit what was previously implicit – that governance intensity should track size and systemic footprint, while the underlying duty to know the customer, categorise risk honestly, and monitor transactions does not shrink for smaller entities. Bajaj Finance’s presence on the Upper Layer list is a useful marker of how far NBFC scale has grown; the steady stream of penalty orders against far smaller NBFCs through mid-2026 is the more useful reminder that the core obligation – current risk categorisation, working suspicious-transaction detection, disciplined periodic review is what RBI is actually testing, at every layer of the framework.
References
Reserve Bank of India (2025) Reserve Bank of India (Non-Banking Financial Company – Know Your Customer) Directions, 2025. RBI/DOR/2025-26/36111, dated 28 November 2025.
Reserve Bank of India (2025) Reserve Bank of India (Non-Banking Financial Companies – Know Your Customer) Amendment Directions, 2025. RBI/2025-26/160, dated 29 December 2025.
Reserve Bank of India (2023) Master Direction – Reserve Bank of India (Non-Banking Financial Company – Scale Based Regulation) Directions, 2023. RBI/DoR/2023-24/106, DoR.FIN.REC.No.45/03.10.119/2023-24, dated 19 October 2023 (as updated).
Reserve Bank of India (2024) Internal Risk Assessment Guidance for Money Laundering/Terrorist Financing Risks. Issued 10 October 2024.
Reserve Bank of India (2025) Press Release: Recognition of Finance Industry Development Council (FIDC) as Self-Regulatory Organisation for the NBFC Sector. 3 October 2025.
Association of Mutual Funds in India (2023) Recommended Minimum Standards on Anti-Money Laundering (AML), Combating the Financing of Terrorism (CFT), and Know Your Customer (KYC) Policy. Available at: https://www.amfiindia.com/Themes/Theme1/downloads/circulars/SEBI/CU152-Ch1Minimum%20(12-Mar-24).pdf