Two deadlines define 2026 for fintech apps in India. RBI's Additional Factor of Authentication (AFA) mandate and its paired fraud compensation framework took effect on 1 April 2026, applying broadly across digital payment flows. Digital lending platforms separately face a 30 June 2026 deadline to reach operational compliance with RBI's Digital Lending Guidelines. Neither has a revenue threshold or a "we're pre-seed" exemption — the obligations attach to what your app does, not how big your company is.
Score your app
Tick what's genuinely in place today. The score updates live.
Nothing you tick is sent anywhere — this runs entirely in your browser.
The two deadlines, in plain terms
AFA and fraud compensation — live since 1 April 2026
AFA requires a genuine second authentication factor beyond a password on digital transactions, paired with a fraud compensation framework that puts real obligations on the entity when fraud does occur. If your app initiates or processes payments in any form, treat this as already in force and verify your exact obligations with your payment provider — most licensed aggregators handle the authentication mechanics for you, but the compensation framework is a business process you still own.
Digital lending — operational compliance due 30 June 2026
Any app that originates, facilitates or services loans digitally falls under RBI's Digital Lending Guidelines. There are exactly two legitimate paths: register your own entity as an NBFC (minimum Net Owned Fund of ₹2 crore) or partner with an existing RBI-regulated lender as a Lending Service Provider. There is no third option where an unregistered app quietly does the lending itself.
Do you need a payment aggregator license?
Only if you are collecting and settling funds on behalf of merchants yourself. That path requires RBI authorisation, a minimum net worth of ₹15 crore at the time of application rising to ₹25 crore by the end of the third financial year, PCI-DSS certification, and data localisation — a serious undertaking that takes months. Almost no early-stage app needs to go this route: integrating an already-licensed aggregator like Razorpay, Cashfree or PayU moves the licensing burden onto a provider that already carries it, at the cost of their transaction fee.
| Requirement | What it actually means |
|---|---|
| AFA + fraud compensation | Second authentication factor on transactions; a defined compensation process when fraud occurs. Live since 1 April 2026. |
| Digital lending guidelines | NBFC registration (₹2 crore min. Net Owned Fund) or an LSP partnership with a regulated lender. Compliance due 30 June 2026. |
| Payment aggregator license | Only if you hold and settle merchant funds yourself. ₹15 crore net worth at application, ₹25 crore by year three, PCI-DSS. |
| Data localisation | Payment system data stored only on servers in India. An infrastructure decision, not a policy document. |
| Annual VAPT | Covers app, infrastructure and APIs against the OWASP Top 10 plus business logic flaws, with verified remediation. |
| 5-year record retention | Transaction records, KYC documents and audit logs — enforced by the system, not left to manual discipline. |
The build decisions this actually drives
Choose your cloud region before you choose anything else. Data localisation means payment-related data has to live on Indian servers. Deciding this after the app is built on a foreign-only region is a genuine rebuild, not a settings change — get this right at architecture time.
Integrate, don't build, the licensed pieces. Payment collection and lending origination both have a well-worn path through an already-licensed partner. Building your own version of either means taking on licensing requirements — capital, certification, months of process — that most products never need to touch directly.
Design for the audit you'll eventually get. VAPT, 5-year retention and fraud-window reporting all assume your system can answer questions about what happened and when. Logging and audit trails are cheap to build in from day one and expensive to retrofit after a regulator, or an incident, asks for them.