RBI Digital Lending Guidelines Audit
FLDG, DLG, LSP and DLA audit — disbursement-to-collection trail RBI inspectors actually read.
End-to-end audit against the RBI Digital Lending Guidelines (DLG) — covering Regulated Entities, Lending Service Providers (LSPs), Digital Lending Apps (DLAs), the First Loss Default Guarantee (FLDG) framework, Key Facts Statement, cooling-off, customer redressal and data-localisation obligations.
- RBI Guidelines on Digital Lending (RBI/2022-23/111 dated 02-Sep-2022)
- RBI Default Loss Guarantee in Digital Lending (RBI/2023-24/41 dated 08-Jun-2023)
- Working Group on Digital Lending Report (Nov 2021) — annexed expectations
- RBI Master Direction on Outsourcing of IT Services (2023)
- RBI Master Direction on IT Governance (2024)
- RBI Storage of Payment System Data (Apr 2018) — data localisation
- Fair Practices Code + SBR for NBFCs
- DPDP Act 2023 — overlap on consent + data principal rights
What is RBI Digital Lending compliance?
RBI's Digital Lending Guidelines govern how lending apps and their partners handle data, disclosures, and customer protection. Macksofy audits lending platforms and lending service providers against the guidelines, covering data localization, app security, and DPDP alignment for fintech across India.
RBI DLG is leverage, not paperwork.
RBI's Digital Lending Guidelines (Sep 2022) and the subsequent FLDG circular (Jun 2023) re-wrote how every RE, fintech, NBFC and bank-LSP must operate. Disbursement and repayment must flow only between the borrower's and the RE's bank account — no LSP pass-through. The FLDG cap of 5% of the loan portfolio, DLA registration and Key Facts Statement requirements are now active enforcement triggers; RBI has already debarred multiple LSPs and barred new customer onboarding for non-compliant REs. Macksofy's audit produces the disbursement-vs-collection trail, FLDG ledger reconciliation and DLA artefact pack RBI inspections demand on day one.
- Scheduled Commercial Banks + Small Finance Banks running digital lending
- NBFCs (Upper / Middle / Base layer) with own or partner-app lending
- Lending Service Providers (LSPs) sourcing for an RE
- Digital Lending App (DLA) operators — owned or white-labelled
- FLDG-receiving REs + FLDG-providing LSPs
- Payment Aggregators routing loan disbursement / repayment flows
Aligned to the regulations that matter.
How we run a RBI DLG engagement.
Interactive walkthrough — every phase clickable, every activity documented, every artefact regulator-ready.
1 · RE-LSP-DLA mapping
- Inventory of LSPs, DLAs, co-lending and FLDG partners
- Loan-product classification (own-book / co-lend / FLDG)
- Customer journey + data-flow walk-through
- Board-approved digital-lending policy review
- 011 · RE-LSP-DLA mapping
- Inventory of LSPs, DLAs, co-lending and FLDG partners
- Loan-product classification (own-book / co-lend / FLDG)
- Customer journey + data-flow walk-through
- Board-approved digital-lending policy review
- 022 · Disbursement & collection audit
- Direct RE-to-borrower disbursement trail (no LSP pass-through)
- Repayment routing into RE account only
- Reconciliation against bank statements + payment-aggregator MIS
- Cooling-off / look-up period evidence
- 033 · FLDG framework audit
- FLDG cap test — 5% of outstanding portfolio per arrangement
- Eligible FLDG instruments (cash, FD lien, BG) verification
- FLDG invocation triggers + ageing ledger
- Disclosure to credit-information companies
- 044 · Customer-protection controls
- Key Facts Statement (KFS) format + APR disclosure
- Grievance redressal + nodal-officer SLA
- Recovery-agent code of conduct audit
- Cooling-off cancellation flow testing
- 055 · Data & technology controls
- DLA permissions audit — only need-to-know access (contacts/SMS/gallery prohibited)
- Data localisation evidence per RBI Apr-2018 directive
- Encryption-in-transit + tokenisation review
- Cyber-security + outsourcing controls (cross-mapped to IT Governance MD)
- 066 · Reporting & submission pack
- DLA registration + Sachet portal submission readiness
- CSITE / DoS submission pack
- Inspector Q&A walk-through deck
- Remediation tracker + 30-day retest
What your RBI DLG engagement puts on the table.
- Digital-lending policy + procedure gap report
- Disbursement-vs-collection reconciliation ledger
- FLDG cap + ageing dashboard
- Key Facts Statement template pack (per loan product)
- DLA permission & data-localisation evidence pack
- Sachet / DLA registration submission bundle
- RBI inspector Q&A walk-through deck
- Free retest within 30 days + closure letter
DLG + FLDG audit across 4 LSP partners
Outcome: FLDG portfolio re-cut to within the 5% cap; two non-compliant LSPs offboarded ahead of RBI thematic inspection
DLA permission + customer-protection audit
Outcome: Permission set reduced from 17 to 4; KFS rolled out across loan products and cooling-off cancellation rate validated
The shape of a RBI DLG engagement.
Every number below is grounded in how Macksofy actually runs the engagement — not aspirational marketing copy.
What we actually examine.
Each pillar is a distinct workstream inside the engagement — scoped, evidenced, and signed off independently before the audit pack is assembled.
- RE accountability & policy3 pts
- Money-flow integrity3 pts
- FLDG governance3 pts
- Customer-protection stack3 pts
- DLA & data hygiene3 pts
- Inspector-ready submission pack3 pts
RBI holds the Regulated Entity — not the LSP — liable. The audit starts there.
- Board-approved digital-lending policy currency
- LSP / DLA appointment due-diligence pack
- Quarterly digital-lending review at board level
Disbursement and collection routing is the single most-tested control by RBI.
- Direct RE-borrower flow (no LSP pool account)
- Pass-through nostro / escrow exception ledger
- Reconciliation evidence with PA + bank MIS
The 5% cap, eligible instruments and invocation audit-trail.
- FLDG cap test per arrangement + portfolio
- Eligible instrument (cash / FD lien / BG) validation
- Invocation + CIC-reporting ageing ledger
What every borrower must see, sign and be able to walk away from.
- Key Facts Statement + APR disclosure evidence
- Cooling-off cancellation tested end-to-end
- Grievance redressal + Sachet integration
Permissions, localisation, DPDP overlap — where most LSP enforcement actions land.
- DLA permission audit (no contacts / SMS / gallery)
- Payment-data localisation evidence
- DPDP consent + data-principal-rights overlap
The artefact bundle a CSITE / DoS inspection actually consumes.
- DLA registration & Sachet-portal pack
- Control-to-evidence map per DLG clause
- Remediation tracker + retest letter
From kick-off to regulator-ready report.
The horizontal flow below shows the typical week-by-week shape of a RBI DLG engagement. Click any station for detail in the methodology section above.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
RBI DLG — what compliance leads ask before signing.
RBI Cyber Security Framework Audit
End-to-end RBI CSF audit — control assessment, SAR drafting, inspector defence.
Learn moreSEBI CSCRF Audit
CSCRF audit for stock brokers, depository participants, AMCs.
Learn moreSEBI System Audit Report (SAR)
The half-yearly / annual SAR your stock broker or DP can submit on the first read.
Learn moreRBI DLG evidence starts with hands-on testing.
A clean RBI DLG report rests on real technical assurance. These Macksofy assessments generate the vulnerability, penetration and control-effectiveness evidence your auditor expects to see.
Penetration Testing
Find what attackers will. Before they do.
Explore serviceVulnerability Assessment & Penetration Testing (VAPT)
VAPT done properly — not a scan with a cover page.
Explore serviceWeb Application Security Testing
Test web apps the way attackers (and bug bounty hunters) do.
Explore serviceMacksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
