
The Reserve Bank of India (RBI) has, from time to time, issued guidelines governing digital lending with an objective to ensure transparency, customer protection, and responsible conduct by regulated entities. In light of the increasing adoption of digital channels for loan origination and servicing, it is imperative for the Company to establish a comprehensive framework governing its digital lending operations.
This Policy has been formulated to lay down the principles, processes, and controls to be followed by the Company in respect of loans sourced, processed, and serviced through Digital Lending Applications (DLAs) and/or through Lending Service Providers (LSPs). The Policy aims to ensure compliance with applicable regulatory requirements, safeguard customer interests, and promote ethical and transparent lending practices.
This Policy shall apply to all digital lending activities undertaken by the Company, whether directly through its own Digital Lending Applications or indirectly through third-party Lending Service Providers engaged for customer acquisition, onboarding, underwriting support, servicing, or recovery.
The provisions of this Policy shall cover the entire lifecycle of a digital loan, including customer sourcing, onboarding, credit assessment, loan disbursement, servicing, repayment, recovery, and closure. All employees, agents, and service providers involved in digital lending shall be governed by this Policy
The Company shall ensure that its digital lending operations are conducted in strict compliance with the guidelines issued by the Reserve Bank of India, including the Digital Lending Guidelines, 2022, as amended from time to time, and the Master Direction – NonBanking Financial Company – Scale Based Regulation Directions, 2023.
In addition, the Company shall comply with all other applicable laws and regulations, including Know Your Customer (KYC) Directions, Fair Practices Code, Information Technology Act, and applicable data protection and privacy laws.
The Company shall ensure that all digital lending interfaces, including mobile applications and web-based platforms, clearly disclose the identity of the Company as the lender, along with its registered address and contact details.
Prior to the execution of any loan agreement, the borrower shall be provided with a Key Fact Statement (KFS) containing all essential terms of the loan, including the annual percentage rate, all applicable fees and charges, repayment schedule, penal charges, and details of the cooling-off period. The Company shall ensure that such disclosures are made in a clear, simple, and understandable manner
The Company shall not levy any charges that have not been explicitly disclosed to the borrower. All advertisements and digital communications shall be fair, transparent, and not misleading.
The Company shall undertake appropriate due diligence before sanctioning any loan through digital channels. This shall include proper identiϐication and veriϐication of the borrower in accordance with KYC norms, as well as an assessment of the borrower’s creditworthiness based on available data and internal risk models.
Where automated underwriting models are used, the Company shall ensure that such models are subject to periodic validation and review. The Company shall ensure that its lending decisions are fair, non-discriminatory, and based on objective criteria
The Company shall ensure that all loan disbursements are made directly into the bank account of the borrower. Similarly, all repayments shall be made directly into the Company’s designated bank account. Under no circumstances shall any third party, including any Lending Service Provider, be permitted to handle or intermediate the ϐlow of funds.
This arrangement shall ensure transparency and prevent any misuse or diversion of funds.
The Company may engage Lending Service Providers to assist in digital lending operations. However, such LSPs shall act strictly as agents of the Company and shall not, at any point, be considered as lenders.
The Company shall enter into formal agreements with all LSPs, clearly deϐining the scope of services, responsibilities, data protection obligations, conϐidentiality requirements, and audit rights. The Company shall remain fully responsible for all actions of the LSPs and shall ensure that they comply with all applicable regulatory requirements.
The Company shall ensure that customer data is collected only with the explicit consent of the borrower and only to the extent necessary for the purpose of lending. The Company shall not access or collect data unrelated to the lending process, such as contact lists, media ϐiles, or personal information not required for credit assessment.
All data shall be stored securely and shall be protected against unauthorized access. The Company shall implement appropriate cybersecurity measures and ensure that customer data is not shared with third parties without explicit consent.
The Company shall provide a cooling-off period to the borrower, during which the borrower shall have the option to exit the loan without incurring any penalty. In such cases, the borrower shall be required to repay the principal amount along with proportionate charges, if any.
The details of the cooling-off period shall be clearly disclosed in the Key Fact Statement.
The Company shall establish a robust grievance redressal mechanism for addressing customer complaints arising out of digital lending operations. The contact details of the grievance redressal ofϐicer shall be prominently displayed on the Company’s website and digital platforms.
All complaints shall be addressed within the prescribed timelines. In case the borrower is not satisϐied with the resolution, the borrower shall have the right to escalate the matter under the RBI Ombudsman Scheme.
The Company shall ensure that all recovery activities are conducted in a fair, transparent, and ethical manner. The Company and its agents shall strictly adhere to the applicable RBI guidelines on recovery practices.
The Company shall ensure that no coercive, abusive, or harassing methods are used during the recovery process. Recovery agents, if engaged, shall be properly trained and shall follow the approved code of conduct.
The Company shall ensure that all Digital Lending Applications and Lending Service Providers are disclosed on its ofϐicial website. The Company shall also comply with all reporting requirements prescribed by the Reserve Bank of India from time to time.
The Company shall conduct periodic audits of its digital lending operations, including the activities of Lending Service Providers. The objective of such audits shall be to ensure compliance with regulatory requirements and internal policies
Any deviations or deϐiciencies identiϐied during such audits shall be promptly addressed and reported to the senior management and the Board, as may be required.
This Policy shall be approved by the Board of Directors of the Company. The Board shall periodically review the effectiveness of the Policy and the Company’s digital lending operations.
The senior management shall be responsible for implementing the Policy and ensuring compliance across all levels of the organization.
This Policy shall be reviewed at least annually or earlier, if required, to incorporate changes in regulatory requirements or business practices. Any modiϐications to the Policy shall be approved by the Board of Directors