FinTech Partnerships Between Banks and NBFCs: Legal and Regulatory Issues

Introduction

India’s credit delivery architecture has undergone a quiet but far-reaching transformation over the last decade. Where banks and Non-Banking Financial Companies (NBFCs) once operated largely as competitors, they are today frequently found as collaborators, with financial technology (FinTech) platforms acting as the connective tissue between them. Co-lending arrangements, digital lending apps operating as Lending Service Providers (LSPs), embedded finance products, and Banking-as-a-Service (BaaS) models have together enabled banks to expand their reach into underserved segments, and NBFCs and FinTechs to access the low-cost capital that banks command. This convergence has undeniably improved credit access, particularly for micro, small and medium enterprises (MSMEs) and first-time borrowers with thin credit files. However, it has also created a layered ecosystem of contractual relationships, technology intermediaries, and regulatory touchpoints that raises complex legal questions around accountability, consumer protection, data governance, and systemic risk. This article examines the regulatory framework governing bank-NBFC-FinTech partnerships in India, identifies the principal legal issues arising from such arrangements, and considers the direction in which regulation is likely to evolve.

The Structure of Modern FinTech Partnerships

Three broad models dominate the Indian market. First, the co-lending model, formalised by the Reserve Bank of India (RBI) through its November 2020 circular on “Co-Lending by Banks and NBFCs to Priority Sector,” permits banks to co-originate loans with NBFCs, sharing risk and reward in a predetermined ratio, typically 80:20, with the bank taking the larger share of exposure. Second, the digital lending model, in which a FinTech entity operates as an LSP or a Digital Lending App (DLA) on behalf of a Regulated Entity (RE), handling customer sourcing, underwriting support, and disbursement facilitation, while the actual lending remains on the books of the bank or NBFC. Third, the BaaS model, under which FinTechs offer branded financial products, such as prepaid cards, current accounts, or lending products, built on the regulatory licence of a partner bank or NBFC, with the FinTech providing the technology layer and customer interface. Each of these structures distributes functions across multiple entities while concentrating regulatory responsibility on the licensed institution, a mismatch that lies at the heart of many of the legal issues discussed below.

Regulatory Framework

The RBI has been the primary architect of the regulatory response to this ecosystem, proceeding largely through circulars, master directions, and guidelines rather than primary legislation.

Co-Lending Model (2020). The co-lending circular requires the bank and NBFC to enter into a formal ex-ante agreement covering the terms of co-origination, blended interest rate methodology, grievance redressal, and escrow arrangements for fund flows. The NBFC is required to retain a minimum share of individual loans on its own books, ensuring “skin in the game,” and the arrangement must not be structured in a manner that transfers the entire credit risk to the smaller partner while the larger institution merely provides funding.

Digital Lending Guidelines (2022) and Related Directions. Following the recommendations of the Working Group on Digital Lending, the RBI issued its Digital Lending Guidelines in September 2022, later consolidated into related master directions on digital lending. These guidelines mandate that all loan disbursements and repayments flow directly between the borrower’s bank account and the account of the RE, without pass-through accounts operated by the LSP; that the RE bear full responsibility for the conduct of its LSPs and DLAs, including outsourced recovery agents; that borrowers receive a Key Fact Statement disclosing the annual percentage rate and all charges before loan execution; and that data collection by DLAs be need-based, with explicit borrower consent and a prohibition on accessing device contacts, media, or location data except with specific permissions tied to defined purposes.

First Loss Default Guarantee (FLDG) Guidelines (2023). Recognising that many FinTech-originated co-lending and digital lending arrangements involved the FinTech providing a guarantee against borrower default, the RBI issued specific guidance permitting FLDG arrangements between REs and LSPs, subject to a cap of five per cent of the underlying loan portfolio and a requirement that such guarantees be treated as an off-balance sheet exposure of the RE, disclosed accordingly.

Outsourcing and Governance Guidelines. The RBI’s longstanding framework on managing risks in outsourcing of financial services, along with its directions on outsourcing of IT services, requires REs to conduct due diligence on their FinTech partners, maintain board-approved outsourcing policies, and retain ultimate responsibility for outsourced functions, a principle often summarised as the RE being unable to outsource its accountability even where it outsources its operations.

NBFC Scale-Based Regulation (2021). The Scale Based Regulation framework, which reorganised NBFCs into a four-layered structure based on size and systemic importance, has particular relevance for NBFCs that partner extensively with FinTechs, since upper-layer NBFCs face bank-like governance, disclosure, and capital requirements that shape the terms on which they can enter such partnerships.

Principal Legal Issues

Allocation of Liability and the “Skin in the Game” Problem. A recurring legal difficulty concerns the true allocation of credit risk. Where an NBFC’s balance sheet exposure is structured to be nominal while a FinTech absorbs risk through an FLDG or similar arrangement, regulators and courts may look through the contractual form to the economic substance of the transaction. Loan agreements, co-lending agreements, and FLDG arrangements must therefore be drafted with care to reflect a risk allocation that is defensible on a substance-over-form analysis, failing which the arrangement may be recharacterised or penalised as a circumvention of capital adequacy and licensing norms.

Outsourcing Accountability and Vicarious Responsibility. Because the RBI holds the RE responsible for the conduct of its outsourced partners, banks and NBFCs face potential liability for the acts of FinTech LSPs, including improper recovery practices, mis-selling, or data misuse, even where the underlying conduct is directly attributable to the FinTech. This has significant contract-drafting implications: indemnity clauses, audit rights, service-level agreements, and termination triggers within the RE-LSP contract become the primary mechanism by which the RE can allocate downstream liability back to the FinTech, since regulatory liability towards the borrower and the regulator cannot itself be contracted away.

Consumer Protection and Unfair Practices. Digital lending has attracted regulatory and judicial scrutiny over aggressive and, in some instances, coercive recovery practices by FinTech-linked recovery agents, unauthorised access to borrower data, and non-transparent pricing. The RBI’s Fair Practices Code, the Key Fact Statement mandate, and the Reserve Bank – Integrated Ombudsman Scheme collectively aim to address these concerns, but enforcement against unlicensed or offshore-linked lending apps operating outside the regulated co-lending or LSP structure remains an ongoing challenge, particularly where such apps falsely project an association with a licensed bank or NBFC.

Data Protection and Cross-Entity Data Flows. FinTech partnerships inherently involve the transfer of borrower data across multiple entities, the FinTech’s app, the NBFC’s underwriting systems, and the bank’s core banking platform, raising questions under the Digital Personal Data Protection Act, 2023 (DPDP Act) regarding the identification of the data fiduciary, the scope of consent obtained, and the permissible extent of data sharing with sub-processors. Since the DPDP Act imposes obligations on the data fiduciary that determines the purpose and means of processing, tripartite arrangements must clearly designate which entity bears fiduciary responsibility, and data processing agreements between the parties must align with both the DPDP Act and the RBI’s digital lending data-minimisation requirements, which are, in places, more stringent.

Interest Rate and Charge Structuring. In co-lending arrangements, the blended interest rate charged to the borrower must be transparently computed and disclosed, and RBI guidance requires that the methodology not be manipulated to disguise excessive charges recovered by the FinTech intermediary through processing fees or other heads that fall outside the disclosed annual percentage rate.

Regulatory Arbitrage and the “Rent-a-Licence” Concern. A structural concern that regulators have flagged is the risk of FinTechs using a lightly capitalised NBFC partner primarily to access a lending licence, while the FinTech itself performs functions, sourcing, underwriting, pricing, and recovery, that are effectively those of the lender. The RBI’s insistence on minimum NBFC risk retention and its scrutiny of algorithmic underwriting arrangements are direct responses to this concern, and NBFCs entering such partnerships should be alert to the reputational and regulatory risk of appearing to be a mere licence conduit.

Grievance Redressal and Jurisdictional Complexity. Where a borrower has a grievance, determining the correct forum, and the correct respondent among the bank, NBFC, and FinTech, can be complicated by the multi-entity structure. RBI guidelines require REs to appoint a nodal grievance redressal officer and to resolve complaints even where the underlying cause lies with the LSP, but borrowers pursuing remedies before consumer fora or through litigation may still face difficulty establishing which entity bears primary responsibility, particularly where the FinTech is not itself an RBI-regulated entity and falls outside the direct jurisdiction of the RBI Ombudsman Scheme.

The Way Forward

The regulatory trajectory suggests continued tightening rather than relaxation. The RBI’s approach of holding REs accountable for outsourced functions, while imposing progressively more detailed disclosure, data-minimisation, and FLDG norms, reflects a deliberate strategy of channelling FinTech innovation through the accountability structures of licensed entities rather than permitting a parallel, lightly regulated lending ecosystem to develop. For banks and NBFCs, this means that partnership agreements with FinTechs must be treated as core regulatory documents, not mere commercial contracts, incorporating robust audit rights, data governance clauses, risk-retention mechanisms, and clearly defined grievance escalation pathways. For FinTechs, the direction of travel points towards eventual direct regulation, whether through the RBI’s evolving stance on payment aggregators, its self-regulatory organisation framework for the FinTech sector, or targeted legislative intervention, particularly if instances of consumer harm continue to surface despite the current outsourcing-based accountability model. A coherent legal strategy for any bank-NBFC-FinTech partnership therefore requires anticipating this regulatory direction, rather than merely complying with the guidelines as they stand today.

Conclusion

FinTech partnerships between banks and NBFCs have meaningfully expanded India’s credit frontier, but they operate within a regulatory framework that is still maturing and that places disproportionate accountability on the licensed entity at the apex of the arrangement. The legal issues that arise, spanning liability allocation, outsourcing accountability, consumer protection, data governance, and the risk of regulatory arbitrage, are not incidental to these partnerships but structural to their design. As the RBI continues to refine its guidelines and as the DPDP Act’s implementation matures, banks, NBFCs, and FinTechs alike will need to move towards partnership structures where legal and compliance considerations are embedded from the outset, rather than retrofitted in response to regulatory action.

Endnotes

  1. Reserve Bank of India, Co-Lending by Banks and NBFCs to Priority Sector (Nov. 5, 2020), https://www.rbi.org.in.
  2. Reserve Bank of India, Guidelines on Digital Lending (Sept. 2, 2022), https://www.rbi.org.in.
  3. Reserve Bank of India, Digital Lending – Transparency in Aggregation of Loan Products from Multiple Lenders (Apr. 26, 2024), https://www.rbi.org.in.
  4. Reserve Bank of India, Guidelines on Default Loss Guarantee (DLG) in Digital Lending (June 8, 2023), https://www.rbi.org.in.
  5. Reserve Bank of India, Master Direction – Reserve Bank of India (Outsourcing of Information Technology Services) Directions, 2023 (Apr. 10, 2023), https://www.rbi.org.in.
  6. Reserve Bank of India, Master Direction – Reserve Bank of India (Non-Banking Financial Company – Scale Based Regulation) Directions, 2023, https://www.rbi.org.in.
  7. Reserve Bank of India, Master Direction – Reserve Bank of India (Digital Lending) Directions, 2025, https://www.rbi.org.in.
  8. Reserve Bank of India, The Reserve Bank – Integrated Ombudsman Scheme, 2021 (Nov. 12, 2021), https://www.rbi.org.in.
  9. Reserve Bank of India, Master Direction – Know Your Customer (KYC) Direction, 2016 (as amended), https://www.rbi.org.in.
  10. Reserve Bank of India, Master Direction – Non-Banking Financial Company – Fair Practices Code Directions, 2016 (as amended), https://www.rbi.org.in.
  11. Reserve Bank of India, Working Group on Digital Lending including Lending through Online Platforms and Mobile Apps: Report (Nov. 18, 2021), https://www.rbi.org.in.
  12. Digital Personal Data Protection Act, No. 22 of 2023, India Code (2023).
  13. Information Technology Act, No. 21 of 2000, India Code.
  14. Payment and Settlement Systems Act, No. 51 of 2007, India Code.
  15. Reserve Bank of India Act, No. 2 of 1934, India Code.
  16. Banking Regulation Act, No. 10 of 1949, India Code.
  17. Consumer Protection Act, No. 35 of 2019, India Code.
  18. Reserve Bank of India, Framework for Self-Regulatory Organisation(s) for the FinTech Sector (May 30, 2024), https://www.rbi.org.in.
  19. Reserve Bank of India, Master Direction – Managing Risks and Code of Conduct in Outsourcing of Financial Services by NBFCs (Nov. 9, 2017), https://www.rbi.org.in.
  20. Reserve Bank of India, Master Circular – Prudential Norms on Income Recognition, Asset Classification and Provisioning pertaining to Advances (as amended), https://www.rbi.org.in.

 

 

Utkarsh Singh
Author: Utkarsh Singh

Utkarsh Singh is a Final Year B.A. LL.B. student with a keen interest in constitutional law, corporate law, technology law, aviation law, media and entertainment law, labour law, and emerging legal issues. His research focuses on analysing contemporary legal developments, regulatory frameworks, and judicial trends through a practical and interdisciplinary approach. He is committed to producing well-researched, accessible, and academically rigorous legal scholarship that contributes to informed legal discourse.