RBI outsourcing rules for NBFCs: what you may outsource, and what stays yours
CS Sushil Choudhary · Compliance · 2026-08-11 · 5 min read (estimated)
An NBFC may outsource the work; it may not outsource the decision, the custody, or the accountability. Credit appraisal and sanction, asset classification, internal audit, compliance and grievance redressal stay with the regulated entity — and the entity remains responsible for the acts of its service providers as if they were its own.
NBFCs outsource a great deal — sourcing, collections, valuation, verification, technology. The regulatory position has been consistent throughout: outsourcing does not diminish the regulated entity's obligations, and the entity remains responsible for the acts of its service providers as if they were its own.
That principle sounds obvious until it meets a specific arrangement.
What the gold loan review made concrete
The September 2024 review of gold loan practices found valuation being carried out without the customer present, credit appraisal and valuation handled entirely by business correspondents, gold held in the BC's custody, and transported to branches without adequate security.
Each of those is an outsourced activity that had, in practice, taken the decision with it. The lender had not merely delegated the work; it had stopped being the party that decided.
Where is the line actually drawn?
Core decisions stay with the lender. Credit appraisal, sanction, and the classification of an asset are the lender's. A vendor may gather, verify and present; it may not decide.
Custody of security is the lender's problem whoever is holding it. A pledge in a third party's custody is still the lender's pledge, and the borrower's recourse is to the lender.
Grievance redressal cannot be delegated away. The borrower's complaint is against the regulated entity.
Three questions to ask about any outsourced function
For any outsourced function, three things should be answerable without reading the contract:
- If this vendor stopped tomorrow, could the lender continue? Access to data, in a usable form,
held where the lender can reach it.
- Is there a record of what the vendor did, on the lender's systems? A verification that exists
only in the vendor's system is a verification the lender cannot evidence.
- Who at the lender reviewed the vendor's output before it was acted on? If the answer is
"nobody, it flows straight through", the decision has been outsourced too.
What can and cannot be outsourced
| Activity | Position |
|---|---|
| Sourcing and lead generation | Outsourceable |
| Document collection and verification support | Outsourceable |
| Valuation | Outsourceable, but the lender owns the standard and the record |
| Collections and recovery | Outsourceable, conduct remains the lender's |
| Technology and hosting | Outsourceable, subject to the IT outsourcing directions |
| Credit appraisal and sanction | Not outsourceable |
| Asset classification | Not outsourceable |
| Internal audit | Not outsourceable |
| Compliance function | Not outsourceable |
| Grievance redressal | Not outsourceable |
The distinction that decides the row is whether the activity involves judgement the regulator holds the lender to. A vendor may assemble, verify and present. It may not conclude.
What the IT outsourcing directions add
Where the arrangement involves technology or data — which now means most arrangements — the RBI's directions on outsourcing of information technology services impose contractual requirements:
- Audit and inspection rights for the lender and for the regulator, over the provider's records
relating to the lender.
- Data localisation and clarity on where data is held.
- Incident and breach reporting, with timelines.
- Business continuity and disaster recovery commitments.
- Exit management — the data returned in a usable form and erased afterwards.
- Sub-contracting transparency and consent.
These are contract terms with a systems consequence: the data has to be identifiable, extractable and auditable for any of them to be deliverable.
Common mistakes
- Treating a business correspondent as the credit function. The gold review found exactly this.
- Security in a third party's custody with no lender record of it. The pledge is still the
lender's.
- Grievances routed to the agency. The complaint is against the regulated entity.
- A vendor contract without audit and inspection rights. Unremediable after signature.
- No exit plan. Discovered at the worst moment.
- Assuming a SaaS platform is not outsourcing. If it holds your data or supports a material
function, it is.
Frequently asked questions
Can an NBFC outsource credit appraisal?
It can outsource the gathering and verification that supports appraisal. The appraisal and the sanction decision themselves stay with the lender, and an arrangement where a partner effectively decides is one where the lender has stopped being the party the regulator holds responsible.
Is a cloud lending platform an outsourcing arrangement?
Where it holds the lender's data or supports a material function, yes — and the RBI's directions on outsourcing of IT services shape what the contract must contain. It is worth asking a prospective vendor for those clauses during evaluation rather than at contracting.
Who is responsible for a recovery agent's conduct?
The lender. Outsourcing does not diminish the regulated entity's obligations, so the record of who was allocated an account, when they contacted the borrower and what was said needs to be in the lender's own system rather than only the agency's.
Can grievance redressal be handled by a partner?
The handling can be supported, but the obligation is the lender's and the borrower's complaint is against the regulated entity. The grievance officer named to the borrower is the lender's officer.
What should be in an outsourcing contract for an NBFC?
Audit and inspection rights extending to the regulator, data localisation, incident reporting with timelines, business continuity commitments, exit management with data return and erasure, and sub-contracting consent. A vendor who has sold to Indian NBFCs will have these ready.
Related reading: Digital lending for NBFCs · What the 2024 gold review found · How to choose loan management software · Co-lending: what each side owns
Ask for a walk-through — and ask for the outsourcing clauses before the demo.
Read next
- Books of account: what has to exist, in what form, and for how long
What an NBFC must keep, in what form, and for how long. Electronic records carry conditions that are easy to fail without noticing.
- An audit trail is not a log file
The statutory requirement is an edit log of every change, with the prior value, that cannot be switched off. How to test yours in ten minutes.
- What is a loan origination system, and what does an NBFC need one to do?
What a loan origination system is, what each stage owns, and what separates an LOS an NBFC can be audited on from one it cannot.
From the people who wrote this
Run your lending on Lenviq
Seeing it run on your own book is faster than reading about it — a demo works through your products, your schemes and your classification rules, not a generic tour.
Lenviq is loan origination, servicing and accounting for NBFCs, built by FastLegal Technologies.