RBI Loan Recovery Rules 2027: The Compliance Checklist Every NBFC, HFC and Fintech Must Finish Before January 1, 2027
Quick Summary: The RBI Loan Recovery Compliance Checklist for 2027
- What is happening: On 6 August 2026 the RBI issued nine amendment circulars that insert a single, uniform recovery-conduct code (new Section L, paragraphs 454A to 454AB) across every category of regulated lender. They commence on 1 January 2027, which leaves lenders roughly five months to become compliant.
- Who must act now: Non-Banking Financial Companies, Housing Finance Companies, and the fintech and Digital Lending App platforms that operate on their books. This post is the build checklist for the lender, not the borrower guide. For the borrower-facing summary, see our earlier breakdown linked below.
- The single hardest new item: the technology-based device-locking code. A lender cannot restrict a borrower’s phone until the loan is at least 30 days past due and a notice has been served, must preserve incoming calls, SMS, emergency SOS and government alerts throughout, must unlock within one hour of dues being cleared, and pays the borrower Rs 250 per hour (subject to a cap) for a delay it causes.
- The certification trap: any device-locking technology must be certified by the device manufacturer (OEM) or the operating system platform before deployment. If your DLA vendor cannot produce that certificate, the feature cannot go live on 1 January 2027.
- The deadline to plan around is not 1 January 2027, it is your last board meeting of 2026, because the recovery policy has to be board-approved, the empanelled-agency list has to be published on your website, and your recovery-agent and DLA contracts have to be re-papered before the code applies.
What RBI Actually Issued on August 6, 2026
This was not one circular. It was nine, issued on the same day, each amending the Responsible Business Conduct framework of a different class of regulated entity so that an identical recovery code lands everywhere at once. Structurally, the RBI deleted paragraphs 408 to 416 and 442 to 454 of the Responsible Lending Conduct chapter of the 2025 Directions and inserted a new Section L, titled “Conduct of Banks in Recovery of Loan Dues and Engagement of Recovery Agencies”, running from paragraph 454A to 454AB. All nine circulars come into effect from 1 January 2027.
For our audience the two circulars that matter are the Non-Banking Financial Companies (Third Amendment Directions, 2026) and the Housing Finance Companies (Third Amendment Directions, 2026). The HFC circular takes a shortcut worth knowing: instead of restating the code, it deletes the old recovery-agent sub-section in the Fair Practices Code and simply requires HFCs to comply with the corresponding paragraphs of the NBFC Directions. So an HFC compliance team reads the NBFC code, not a separate one.
We covered what these Directions mean for the person on the receiving end of a recovery call in a separate post. If you want the borrower-rights version first, read RBI’s New Loan Recovery Rules From January 1, 2027: What the August 6, 2026 Directions Mean for Every Borrower. This post is the other side of the same coin: the operational build a lender has to finish before that borrower can invoke any of it.
Who Is Covered, and the Exclusions That Actually Matter
The NBFC recovery code applies to all NBFCs except a short list of entities that do not lend to retail borrowers or have no customer interface. The excluded categories are Mortgage Guarantee Companies, Core Investment Companies, NBFC-Account Aggregators, Standalone Primary Dealers, Non-Operative Financial Holding Companies, and any NBFC that does not have a customer interface. If you run a lending NBFC in the Base, Middle or Upper Layer with borrowers you can call, you are in scope. If you are an Account Aggregator or a CIC, you are not.
A practical warning for fintech founders: being a “technology platform” does not put you outside the code. If the loan sits on the book of a regulated NBFC or HFC and your app is the collections channel, the lender is responsible for your conduct as its Lending Service Provider or DLA. The obligation to police your behaviour is contractual and lands on the regulated entity, so the regulated entity will push it down to you in the re-papered service agreement. Plan for that clause now.
The 12-Point Implementation Checklist
Here is the build, in the order a compliance team should tackle it. Everything below has to be finished, tested and board-noted before 1 January 2027.
| # | Action item | What “done” looks like |
|---|---|---|
| 1 | Rewrite the recovery policy and get it board-approved | A standalone, board-approved Recovery and Recovery-Agent policy that maps to Section L, replacing the old Fair Practices Code sub-section |
| 2 | Publish the empanelled recovery-agency list on your website | A current, dated list of every empanelled agency, live on the site and kept updated as agencies are added or dropped |
| 3 | Configure contact hours | Recovery contact to borrowers and guarantors restricted to 08:00 to 19:00, enforced in the dialer and field-app scheduling |
| 4 | Build the prior-intimation workflow | At least one day’s prior intimation to the borrower before a recovery agent’s first physical visit, logged and auditable |
| 5 | Enable call recording with a six-month retention | All recovery calls recorded and preserved for a minimum of six months, retrievable on a complaint |
| 6 | Draft the borrower and guarantor compensation policy | A written policy providing compensation to borrowers and guarantors for losses caused by non-compliant recovery, with an owner and a payout process |
| 7 | Build the device-locking code (if you use it) | The full graded framework below, or a documented decision not to use device locking at all |
| 8 | Obtain OEM or OS certification for any locking technology | A certificate from the device manufacturer or operating system platform, held on file before the feature is switched on |
| 9 | Re-paper recovery-agent and DLA contracts | Every agency and technology-vendor agreement updated to pass down the Section L obligations and the compensation liability |
| 10 | Apply data minimisation | Borrower and guarantor information shared with staff or agencies limited strictly to what the recovery task requires |
| 11 | Train staff and empanelled agents | Documented training on the new code for internal collections staff and every empanelled agency |
| 12 | Wire the grievance and audit trail | A grievance route for recovery complaints, plus the logs that let you prove compliance on any one of the above |
The Device-Locking Code: The One Item That Can Delay Your Launch
This is the genuinely new part of the framework and the one most likely to trip up a digital lender. The RBI has barred lenders from disabling or restricting a borrower’s mobile phone, tablet or laptop as a recovery measure, with a narrow exception where the loan was taken specifically to finance that device. Where device locking is permitted, it is heavily conditioned.
- No restriction before 30 days past due. A lender cannot impose any device restriction until the loan is at least 30 days past due and a formal notice has been served.
- Graded curbs between 30 and 60 days. In this window a lender may introduce graded curbs on device functionality, but outgoing calls cannot be blocked.
- Full contractual restriction only after 60 days past due. The full set of contractually agreed restrictions can be enforced only once the loan crosses 60 days past due.
- Essential functions must always survive. Incoming calls, SMS, emergency SOS services and government or public-safety notifications must remain accessible at every stage.
- Unlock within one hour. Once dues are realised, the device must be unlocked within one hour.
- Rs 250 per hour for a delay you cause. If the lender is responsible for a delay in unlocking, compensation is payable to the borrower at Rs 250 per hour, subject to the prescribed cap.
- OEM or OS certification is mandatory. The lender and any third-party service provider offering the locking solution must obtain certification from the device manufacturer or the operating-system platform before deploying the technology.
The certification requirement is the sleeper. A large share of device-locking software in the Indian market has never been certified by an OEM or an OS platform. If that is your vendor, item 8 above is not a paperwork step, it is a go or no-go gate for the entire feature. Start that conversation with the vendor in this quarter, not in December.
What To Do By When: A Working Backwards Timeline
The commencement date is 1 January 2027, but the real internal deadlines sit earlier because several items need governance sign-off and third-party cooperation.
- By end of September 2026: finish the gap assessment against Section L, open the OEM or OS certification conversation with your device-locking vendor, and start the recovery-agent contract re-papering.
- By end of November 2026: table the rewritten recovery and compensation policy at the board, finalise agency and DLA contracts, and complete the dialer and field-app configuration for the 08:00 to 19:00 window and call recording.
- By mid-December 2026: publish the empanelled-agency list on the website, complete staff and agent training, and run an end-to-end test of the prior-intimation and device-unlock workflows.
- 1 January 2027: the code applies. Every borrower can now invoke it, and every non-compliant recovery act carries a compensation exposure and a supervisory one.
Lenders that also fund working capital through the TReDS ecosystem should read this alongside our note on the RBI TReDS Directions 2026, and forex-facing entities should keep the parallel conduct expectations under the FEMA (Authorised Persons) Regulations 2026 in view. The common thread across all three is that the RBI is standardising conduct obligations and expecting board-owned policies, not ad hoc practice.
Frequently Asked Questions
Do these recovery rules apply to my fintech app if the loan is on a partner NBFC’s books?
Yes, indirectly and enforceably. The regulated NBFC or HFC remains responsible for the conduct of its Lending Service Providers and Digital Lending Apps. In practice the NBFC will pass the Section L obligations and the compensation liability down to you through the service agreement, so you should treat the code as binding on your operations and expect a contract update.
Can we keep using our existing device-locking software after January 1, 2027?
Only if it satisfies the full framework: no restriction before 30 days past due, no blocking of outgoing calls between 30 and 60 days, essential functions preserved, unlock within one hour of payment, Rs 250 per hour compensation for lender-caused delays, and above all a certification from the device manufacturer or the operating-system platform. Without that certificate the feature cannot be deployed.
What is the penalty for getting recovery conduct wrong?
There are two exposures. The first is the direct compensation the policy must provide to borrowers and guarantors for losses caused by non-compliant recovery, including the specific Rs 250 per hour device-unlock compensation. The second is supervisory: these are Directions issued under the RBI’s statutory powers, so non-compliance is a conduct and regulatory-action risk, not merely a customer-service lapse.
We are a Core Investment Company. Do we need to do any of this?
No. Core Investment Companies, along with Mortgage Guarantee Companies, Account Aggregators, Standalone Primary Dealers, Non-Operative Financial Holding Companies and any NBFC without a customer interface, are outside the recovery code because they do not carry out retail loan recovery.
Is 1 January 2027 a hard date or is a phase-in likely?
Treat it as hard. The circulars specify commencement on 1 January 2027 with no transitional relaxation of the conduct obligations. The roughly five-month runway from the 6 August 2026 issuance is itself the phase-in period the RBI has allowed.
The Bottom Line for Compliance Teams
The recovery framework is not conceptually hard, but it is broad, it is board-owned, and two of its items depend on parties outside your control: the recovery agencies you empanel and the OEM or OS platform that must certify your device-locking technology. Those are the items to start on first. Everything else, the contact-hour configuration, the call recording, the website list, the training, is inside your own build. Sequence the external dependencies now and the internal ones will fall into place before 1 January 2027.
Need help mapping your recovery operations to the new Section L framework, or reviewing whether your DLA and device-locking vendors will clear the certification test? Talk to an expert at Tax Update India and get a clear, prioritised compliance plan before the January 2027 clock runs out.
Disclaimer: This post is a general summary of the RBI amendment Directions dated 6 August 2026 and is for information only. It is not legal, financial or regulatory advice. The operative text is the RBI circulars themselves (RBI/2026-2027/223 to 231) and the Responsible Business Conduct Directions, Section L, paragraphs 454A to 454AB. Verify the exact paragraphs applicable to your entity category against the relevant circular and take professional advice before changing policies or contracts.
- FAST-DS 2026 Valuation Rules: How to Value Each Foreign Asset for Form 1 (Bank Accounts, Shares and Property) - August 21, 2026
- RBI Loan Recovery Rules 2027: The Compliance Checklist Every NBFC, HFC and Fintech Must Finish Before January 1, 2027 - August 21, 2026
- GST Registration Cancelled After a Field Visit? Two 2026 High Court Rulings on Rule 25, REG-30 and Section 30 Revocation - August 18, 2026









