Not legal advice. This is an engineering-side readiness guide written by an app development studio, not a law firm or compliance consultancy. RBI's rules carry real legal and licensing complexity. Use this to understand what your product and infrastructure need to support, then take the specifics — especially licensing — to a qualified fintech compliance lawyer.

Two deadlines define 2026 for fintech apps in India. RBI's Additional Factor of Authentication (AFA) mandate and its paired fraud compensation framework took effect on 1 April 2026, applying broadly across digital payment flows. Digital lending platforms separately face a 30 June 2026 deadline to reach operational compliance with RBI's Digital Lending Guidelines. Neither has a revenue threshold or a "we're pre-seed" exemption — the obligations attach to what your app does, not how big your company is.

Score your app

Tick what's genuinely in place today. The score updates live.

Interactive · 10-point RBI readiness check
We know exactly which RBI category we fall underPayment aggregator, lending service provider, NBFC partner, or none of the above
Payments run through an already-licensed aggregatorRazorpay, Cashfree or similar — not a payment flow we built and hold ourselves
Every transaction has a genuine second authentication factorAFA-compliant — not a single password or OTP alone where two factors are required
Payment and transaction data is stored on servers located in IndiaData localisation — not a foreign-only cloud region for anything payment-related
If we lend money, we have NBFC registration or an LSP partnershipNot applicable if you don't originate or facilitate loans
KYC and AML checks run on every user per RBI's Master DirectionAutomated, not a manual process someone can skip under pressure
We've had an annual VAPT covering the app, infrastructure and APIsAddressing the OWASP Top 10 plus business logic flaws, with remediation verified
Transaction records, KYC documents and audit logs are retained for 5 yearsWith a system that actually enforces the retention, not a policy on paper
We could detect a fraud incident and report it to RBI within the required windowLogging and alerting good enough to know it happened and notify on time
Our DPDP Act consent and data-handling obligations are handled separatelyRBI compliance does not replace India's data protection law — both apply

Nothing you tick is sent anywhere — this runs entirely in your browser.

The two deadlines, in plain terms

AFA and fraud compensation — live since 1 April 2026

AFA requires a genuine second authentication factor beyond a password on digital transactions, paired with a fraud compensation framework that puts real obligations on the entity when fraud does occur. If your app initiates or processes payments in any form, treat this as already in force and verify your exact obligations with your payment provider — most licensed aggregators handle the authentication mechanics for you, but the compensation framework is a business process you still own.

Digital lending — operational compliance due 30 June 2026

Any app that originates, facilitates or services loans digitally falls under RBI's Digital Lending Guidelines. There are exactly two legitimate paths: register your own entity as an NBFC (minimum Net Owned Fund of ₹2 crore) or partner with an existing RBI-regulated lender as a Lending Service Provider. There is no third option where an unregistered app quietly does the lending itself.

Do you need a payment aggregator license?

Only if you are collecting and settling funds on behalf of merchants yourself. That path requires RBI authorisation, a minimum net worth of ₹15 crore at the time of application rising to ₹25 crore by the end of the third financial year, PCI-DSS certification, and data localisation — a serious undertaking that takes months. Almost no early-stage app needs to go this route: integrating an already-licensed aggregator like Razorpay, Cashfree or PayU moves the licensing burden onto a provider that already carries it, at the cost of their transaction fee.

RequirementWhat it actually means
AFA + fraud compensationSecond authentication factor on transactions; a defined compensation process when fraud occurs. Live since 1 April 2026.
Digital lending guidelinesNBFC registration (₹2 crore min. Net Owned Fund) or an LSP partnership with a regulated lender. Compliance due 30 June 2026.
Payment aggregator licenseOnly if you hold and settle merchant funds yourself. ₹15 crore net worth at application, ₹25 crore by year three, PCI-DSS.
Data localisationPayment system data stored only on servers in India. An infrastructure decision, not a policy document.
Annual VAPTCovers app, infrastructure and APIs against the OWASP Top 10 plus business logic flaws, with verified remediation.
5-year record retentionTransaction records, KYC documents and audit logs — enforced by the system, not left to manual discipline.

The build decisions this actually drives

Choose your cloud region before you choose anything else. Data localisation means payment-related data has to live on Indian servers. Deciding this after the app is built on a foreign-only region is a genuine rebuild, not a settings change — get this right at architecture time.

Integrate, don't build, the licensed pieces. Payment collection and lending origination both have a well-worn path through an already-licensed partner. Building your own version of either means taking on licensing requirements — capital, certification, months of process — that most products never need to touch directly.

Design for the audit you'll eventually get. VAPT, 5-year retention and fraud-window reporting all assume your system can answer questions about what happened and when. Logging and audit trails are cheap to build in from day one and expensive to retrofit after a regulator, or an incident, asks for them.

Where founders actually get this wrong: not by ignoring RBI entirely, but by assuming a payment gateway integration handles all of it. AFA and PCI-DSS obligations are largely covered by a licensed aggregator. Data localisation, audit logging, retention and your DPDP Act obligations are not — those are your application's responsibility regardless of which payment provider you use.

Frequently asked questions

Only if you are collecting and settling funds on behalf of merchants yourself — a non-bank payment aggregator needs RBI authorisation, a minimum net worth of ₹15 crore at application rising to ₹25 crore by the end of the third financial year, and PCI-DSS certification. Most apps instead integrate an already-licensed aggregator like Razorpay or Cashfree, which avoids this requirement entirely.
AFA (Additional Factor of Authentication) is RBI's requirement for a second authentication factor beyond a password on digital transactions, paired with a fraud compensation framework. It took effect 1 April 2026 and applies broadly across digital payment flows — if your app initiates or processes payments, assume it applies and verify with your payment provider.
Any app that originates, facilitates or services loans digitally. To operate legally you need either your own NBFC registration (minimum Net Owned Fund ₹2 crore) or a partnership with an RBI-regulated lender as a Lending Service Provider. Digital lending platforms face a 30 June 2026 deadline for operational compliance with RBI's guidelines.
Yes. RBI's data localisation requirement means payment system data must be stored only on servers located in India, for entities the requirement covers. This affects your infrastructure choice from day one — retrofitting data residency into an app built on a foreign-only cloud region is a significant rebuild, not a config change.
Yes — we build the technical side: data localisation, AFA-compliant auth flows, audit logging, and integration with licensed payment aggregators and lending partners so you are not carrying regulatory scope you do not need. Book a free call to scope yours; the legal and licensing work itself should go to a qualified fintech compliance lawyer.