The Reserve Bank of India (RBI) has imposed a monetary penalty of ₹8.10 lakh on Shri Ram Finance Corporation Pvt. Ltd. for non-compliance with its directions relating to governance and Know Your Customer (KYC) requirements.
While the monetary penalty may appear relatively small, the compliance lessons behind it are significant for every Non-Banking Financial Company (NBFC) in India.
The action followed RBI’s inspection of the company’s financial position as on 31 March 2025. During the inspection, three key compliance lapses were identified involving Board-level governance, customer risk categorisation, and delays in uploading KYC records to the Central KYC Records Registry (CKYCR).
This case is a reminder that NBFC compliance is not just about having policies and procedures in place. It is about ensuring those policies are implemented, monitored, documented, and supported by evidence.
For NBFCs operating in an increasingly regulated and digital financial environment, small compliance gaps can eventually become regulatory findings.
Why the RBI Penalty Matters for NBFCs
Regulatory penalties are often viewed only in terms of their financial impact. But for NBFCs, non-compliance can have consequences beyond the monetary penalty.
A regulatory lapse may lead to:
- Increased scrutiny from regulators
- Reputational concerns
- Additional internal compliance reviews
- Higher operational costs
- Pressure on management and compliance teams
- Greater focus during future inspections
RBI clarified that the action was based on deficiencies in regulatory compliance and did not comment on the validity of any customer transactions.
However, the findings highlight three areas that every NBFC should regularly monitor: governance compliance, risk based KYC, and timely regulatory reporting.
Let’s look at the key lessons.
1. Board and Management Changes May Require Prior RBI Approval
One of the compliance lapses involved the appointment of a director that resulted in a change of more than 30% of the Board, excluding independent directors.
The required prior written approval from RBI was not obtained.
For NBFCs, this is an important governance lesson.
Board appointments, resignations, and restructuring may appear to be internal management decisions. However, once a regulatory threshold is crossed, the change can become a regulatory compliance matter.
The key takeaway is simple:
Regulatory approval should never be treated as a post-event formality.
Before finalising significant changes to the Board, NBFCs should assess:
- Whether the proposed change triggers RBI approval requirements
- How the change affects the overall Board composition
- Whether the relevant regulatory threshold has been crossed
- Whether all required approvals have been obtained before implementation
- Whether supporting documents and approval evidence are properly maintained
A simple internal Board governance compliance checklist can help reduce the risk of missed approvals.
The process should involve governance, legal, compliance, and senior management teams. This ensures that major Board changes are reviewed from both a business and regulatory perspective.
For regulated financial institutions, governance decisions cannot be treated as administrative tasks alone. Every major change should pass through a clear compliance review process.
2. Customer Risk Categorisation Is a Core KYC Requirement
Another major lapse involved the absence of a system to categorise customers into low, medium, and high risk categories.
This highlights a key principle of RBI KYC compliance for NBFCs: not every customer presents the same level of risk.
A risk-based approach allows NBFCs to apply appropriate monitoring and due diligence based on factors such as:
- Customer profile
- Business activity
- Geography
- Transaction behaviour
- Nature of the relationship
- Other relevant risk indicators
However, having a KYC policy alone is not enough.
An NBFC may have a detailed policy document explaining how customers should be classified. But if customers are not actually assigned and monitored according to their risk levels, the policy remains a paper-based control.
NBFCs should ensure that their customer risk categorisation process answers important questions:
- Is every customer assigned a risk category?
- What criteria are used for the classification?
- Who is responsible for assigning the risk level?
- Are risk categories reviewed periodically?
- Are high-risk customers subject to enhanced due diligence?
- Is there a clear audit trail?
This is where many organisations face a gap between documented compliance and actual compliance.
The policy may be compliant. The process may be documented. But if implementation is inconsistent, the organisation can still face regulatory action.
Regulatory compliance requires both policy and proof.
If RBI or an internal auditor asks for evidence, the NBFC should be able to demonstrate how the risk classification was performed and whether the required controls were consistently applied.
3. CKYCR Timelines Must Be Closely Monitored
The third compliance lapse involved delays in uploading KYC records of certain customers to the Central KYC Records Registry (CKYCR).
KYC compliance is often viewed mainly as a customer onboarding requirement. However, collecting and verifying customer documents is only one part of the overall compliance process.
A complete workflow may involve:
- Collecting customer information
- Verifying KYC documents
- Completing customer due diligence
- Assigning the appropriate risk category
- Uploading required KYC information to CKYCR
- Monitoring pending, rejected, or delayed records
A delay at any stage can create a compliance gap.
Common reasons for delayed CKYCR uploads include:
- Manual processes
- Incomplete customer information
- Technology integration issues
- Data mismatches
- Lack of regular reconciliation
- Unclear ownership
- Delayed follow-up on exceptions
These may initially appear to be small operational issues. But when they are not monitored and addressed, they can eventually become regulatory findings.
NBFCs should consider building automated workflows and exception-monitoring mechanisms. Any delayed, rejected, or incomplete KYC submission should be identified quickly and assigned to the responsible team.
Regular reconciliation between internal customer records and CKYCR submission status can also help identify gaps before they accumulate.
The Bigger Problem: Compliance Gaps Often Hide Between Teams
One of the biggest challenges in NBFC compliance is that responsibilities are often spread across multiple departments.
The Board may assume the compliance team has reviewed the requirement.
The compliance team may assume the legal team has obtained the necessary approval.
Operations may assume the technology team has completed the required CKYCR integration.
The technology team may assume operations are manually tracking pending cases.
And eventually, a small gap becomes a regulatory issue.
This is why compliance cannot operate in silos.
NBFCs need clear answers to four critical questions:
What needs to be done?
Who is responsible?
When does it need to be completed?
What evidence proves compliance?
Without clear ownership and monitoring, even well-designed compliance frameworks can fail during execution.
Moving From Compliance on Paper to Compliance in Practice
The RBI penalty highlights an important lesson for the entire NBFC sector.
The goal should no longer be to simply ask:
“Do we have a policy?”
The better questions are:
“Is the policy being followed?”
“Are the controls working?”
“Can we identify compliance gaps early?”
“Can we prove compliance when required?”
This requires a more proactive approach to NBFC governance and compliance management.
Periodic reviews are important, but organisations also need continuous visibility into high-risk compliance activities.
A central monitoring process can help track areas such as:
- Board composition and approval requirements
- KYC policy implementation
- Customer risk categorisation
- High-risk customer monitoring
- CKYCR submission status
- Pending or rejected records
- Compliance exceptions
- Internal audit findings
- Corrective action status
Such visibility can help NBFCs identify problems before they turn into regulatory findings.
What Every NBFC Should Review Right Now
The recent RBI action provides a good opportunity for NBFCs to review their own compliance framework.
Board and Governance Compliance
Review recent and upcoming Board changes.
- Have any regulatory thresholds been crossed?
- Were all required approvals obtained?
- Is approval evidence properly documented?
Customer Risk Categorisation
Test whether the risk-based KYC framework is actually working in practice.
- Is every customer assigned a risk category?
- Are the classifications based on documented criteria?
- Are customer risk levels periodically reviewed?
CKYCR Compliance
Review the complete KYC submission workflow.
- Are records uploaded within the required timelines?
- Are failed or delayed submissions identified quickly?
- Is regular reconciliation being performed?
- Are pending cases tracked until closure?
Internal Compliance Audits
Do not wait for an RBI inspection to identify gaps.
Conduct periodic internal audits focused on high-risk compliance areas. These audits should test whether controls are actually working not simply whether a policy document exists.
How Technology Can Help Strengthen NBFC Compliance
As NBFCs become more digital, technology plays an increasingly important role in supporting compliance.
Manual processes, disconnected systems, and limited visibility can increase the risk of missed deadlines, incomplete records, and inconsistent execution.
The right technology environment can help organisations:
- Automate compliance workflows
- Improve visibility into critical processes
- Secure customer and financial data
- Identify vulnerabilities across digital systems
- Strengthen cybersecurity controls
- Monitor infrastructure risks
- Reduce dependence on manual processes
For financial institutions, compliance and cybersecurity are becoming increasingly connected.
A strong compliance framework can be weakened by poor technology controls, while strong cybersecurity practices can help protect the systems and data that support critical regulatory processes.
How Evvo Technology Can Support NBFCs
Evvo Technology helps organisations strengthen their digital infrastructure, cybersecurity, and technology capabilities.
For NBFCs operating in a highly regulated digital environment, the right technology and security foundation can support stronger operational resilience and reduce potential gaps across critical systems.
From cybersecurity assessments and infrastructure security to governance support and technology solutions, Evvo Technology helps organisations identify vulnerabilities, strengthen security controls, and build a more resilient digital environment.
As financial institutions continue to digitise customer onboarding, KYC processes, data management, and internal operations, cybersecurity should remain an important part of the broader compliance conversation.
Final Thoughts
The RBI penalty of ₹8.10 lakh is more than a story about one NBFC and three compliance lapses.
It is a reminder that compliance is a continuous operational responsibility.
The strongest NBFC compliance programmes combine people, processes, technology, monitoring, and accountability.
Having a policy is important.
Implementing the policy is essential.
Monitoring the process is critical.
And being able to provide evidence of compliance is what helps organisations stay prepared for regulatory scrutiny.
For NBFCs, the focus should be on moving from:
“Do we have a policy?”
to:
“Is the policy being followed, monitored, and supported by evidence?”
Because in a highly regulated industry, compliance is not just about knowing the rules. It is about consistently proving that the rules are being followed.