RBI says fintech rules should track risk, not mirror bank regulation

RBI Deputy Governor Shirish Chandra Murmu said fintech oversight should be proportionate to underlying risks, while calling for stronger governance, fraud resilience, AI accountability, inclusion and quantum-ready payments infrastructure.

— Source publishedFri, 11 Sept, 2026, 17:20 IST·First seen Fri, 11 Sept, 2026, 17:23 IST·Source Business Standard · Companies

What happened

Reserve Bank of India · RBI Deputy Governor Shirish Chandra Murmu said fintech regulation should match risks rather than replicate banking rules, while

Why this matters

Corporate development teams should prioritize regulatory diligence on target risk controls, payment resilience and AI accountability, especially for fintech, NBFC and payments acquisitions or partnerships.

What to watch

  • RBI consultations or circulars defining risk tiers for payment aggregators, NBFC-fintech partnerships, digital lenders or account aggregators.
  • New mandates on AI governance, explainability, human oversight, model validation or reporting of automated fraud and credit decisions.
  • Tighter requirements for operational resilience, cyber incident disclosure, cloud outsourcing, concentration risk and business-continuity testing.
  • Higher enforcement activity involving payment fraud, mule accounts, KYC failures, data misuse, grievance redressal or merchant onboarding controls.
  • Policy guidance, standards or pilots relating to quantum-safe cryptography for payment infrastructure.
  • Evidence of increased merchant discount rates, reserve requirements, onboarding delays or exits among smaller payment providers.
  • Map payment, lending, wallet and embedded-finance partners by customer-fund exposure, transaction value, fraud loss history, AI usage and critical outsourcing dependencies.
  • Require partners to provide board-level governance ownership, fraud-response SLAs, incident-notification procedures, model-risk controls and independent assurance evidence.
  • Reassess checkout routing and fallback arrangements to reduce reliance on a single payment aggregator or high-failure payment rail.
  • Build procurement scorecards that weight regulatory maturity, cyber resilience, dispute handling, data controls and continuity capability alongside transaction pricing.
  • Prepare for higher compliance costs in payment acceptance contracts, especially for high-risk merchant categories, cross-border flows, credit-linked payments and AI-driven fraud decisioning.