
For any fintech startup in India, RBI compliance is not a back-office task you bolt on after product-market fit. It is the first architectural decision you make, because the Reserve Bank of India regulates by activity, not by branding. The moment your product touches customer money, credit, or financial data, a specific licence category attaches to it, and that category dictates your minimum capital, your fund-flow design, your reporting stack, and even the entity you incorporate. Founders who treat the licence as a later problem routinely rebuild their product twice. This playbook maps the main fintech models to their RBI licence, explains what each demands, lays out the compliance timeline, and shows why regulation, done deliberately, becomes one of the hardest moats to copy in Indian financial services.
Fintech startup India: why the RBI perimeter is your first product decision
The RBI does not issue a single generic fintech licence. It authorises named activities under specific frameworks: issuing prepaid instruments, lending as a non-bank, aggregating merchant payments, or sharing financial data on consent. Your job is to identify which regulated activity your product actually performs and build to that framework from day one. Two rules make this urgent. First, capital requirements are staged over the first three financial years, so the clock starts at authorisation, not at scale. Second, many obligations, such as escrow segregation, KYC and anti-money-laundering controls, board-level fit-and-proper standards and regulatory reporting, are structural. They cannot be retrofitted cheaply onto a product designed to ignore them.
Map your model to an RBI licence
Below are the core direct-licence routes. Match your product to one before you write a line of go-to-market copy.
Wallets and prepaid payment instruments (PPI)
If you store value that customers load and spend, you are issuing a Prepaid Payment Instrument and fall under the RBI Master Directions on Prepaid Payment Instruments, 2021. A non-bank PPI issuer must be a company incorporated in India and hold a minimum positive net worth of Rs 5 crore at the time of application, rising to Rs 15 crore by the end of the third financial year from final authorisation, to be maintained thereafter. The directions distinguish minimum-detail (small) PPIs, which carry low limits, from full-KYC PPIs, which permit higher balances and have been made interoperable, including across UPI. The practical takeaway: a wallet is a capital-intensive, fully authorised business, not a feature you sprinkle onto an app.
Lending as a non-bank (NBFC)
If you lend from your own balance sheet, you need to register as a Non-Banking Financial Company. Under the Scale Based Regulation framework the RBI introduced in October 2021, the minimum Net Owned Fund for an NBFC-Investment and Credit Company (NBFC-ICC) was raised from the old Rs 2 crore to Rs 10 crore, phased in as Rs 5 crore by 31 March 2025 and Rs 10 crore by 31 March 2027. Two specialised categories keep the lower Rs 2 crore floor: NBFC-Peer-to-Peer lending platforms and NBFC-Account Aggregators. An NBFC licence is the most demanding retail-facing route because it layers prudential norms, fair-practice codes, and the full digital-lending rulebook on top of the capital requirement, but it also gives you the most control over economics and underwriting.
Payment aggregator and payment gateway (PA/PG)
If you collect money from customers on behalf of merchants and settle it to them, you are a Payment Aggregator. The RBI consolidated this space in the Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025, which superseded the original March 2020 guidelines and folded in cross-border aggregation. A PA must be a company incorporated in India with a minimum net worth of Rs 15 crore at the time of application and Rs 25 crore by the end of the third financial year, maintained thereafter. Crucially, collected funds must sit in an escrow account with a scheduled commercial bank, cannot be commingled with the PA's own money, and this escrow is maintained under the Payment and Settlement Systems Act, with settlement to merchants on defined timelines. A Payment Gateway, by contrast, only provides the technology rails and does not handle funds. Gateways are treated as technology providers or outsourcing partners and are not separately authorised, which is why many technical players choose to remain a PG and partner a licensed PA rather than raise Rs 25 crore of net worth.
Account aggregator (AA)
If your value proposition is moving a customer's financial data between institutions on consent, that is a regulated activity too. The RBI created the Account Aggregator class through the NBFC-Account Aggregator Directions dated 2 September 2016. An AA is a consent-based data intermediary: it retrieves financial information from Financial Information Providers such as banks and NBFCs and delivers it to Financial Information Users, and it may not see, store, or use the data for anything beyond that consented transfer. The Net Owned Fund floor is Rs 2 crore. Most fintechs do not become an AA. Instead they plug into the AA network as a Financial Information User to pull consented bank statements and cash-flow data for underwriting, which is one of the cheapest compliance upgrades available to an Indian lender today.
The partnership and co-lending routes: regulation-light market entry
You do not always need your own licence. The fastest legitimate route to market is to partner a regulated entity and operate as a service provider, and the RBI has spent the last three years defining exactly how that partnership must work.
Co-lending. Under the original 2020 Co-Lending Model, banks and NBFCs jointly funded priority-sector loans, with the NBFC required to retain a minimum 20 percent share on its books. The RBI has now issued the Co-Lending Arrangements Directions, 2025, effective from 1 January 2026, which reshape this. Each regulated entity, bank or NBFC, must retain a minimum 10 percent share of every loan, the scope expands beyond priority-sector lending to cover lending broadly, loans must be transferred within 15 calendar days, and a blended interest rate must be disclosed to the borrower. The discretionary rejection model of the earlier structure has been removed. For a fintech, co-lending means you can originate and service at scale while a bank supplies most of the capital, provided you accept genuine, retained risk-sharing rather than pushing all risk off-balance-sheet.
Digital lending and default loss guarantees. If you run a lending app or act as a Lending Service Provider (LSP) for a bank or NBFC, you live under the RBI (Digital Lending) Directions, 2025, dated 8 May 2025, which consolidated the September 2022 digital-lending guidelines and the June 2023 Default Loss Guarantee rules into one code. The non-negotiables: loan disbursal and repayment must flow directly between the borrower and the regulated lender, not through the LSP's pool account; all fees and the annual percentage rate must be disclosed up front through a Key Fact Statement; and any Default Loss Guarantee (also called a First Loss Default Guarantee or FLDG) you offer is capped so that total DLG cover cannot exceed 5 percent of the underlying loan portfolio. The directions also require regulated entities to report every Digital Lending App they or their LSPs run on the RBI's Centralised Information Management System (CIMS) portal, with that reporting requirement live from 15 June 2025. Being listed there is fast becoming a trust signal borrowers check.
The compliance timeline: what to build and when
Sequence your compliance the way the RBI sequences its requirements.
- Before incorporation: lock the licence category, then incorporate the right vehicle. Almost every direct route requires a company incorporated in India under the Companies Act, and promoters must satisfy fit-and-proper criteria.
- Capital build-up: raise to the entry net worth for your category (Rs 5 crore for a non-bank PPI, Rs 15 crore for a PA, the applicable Net Owned Fund for an NBFC) and plan the runway to hit the third-year threshold, since these are maintained continuously, not one-time tests.
- Authorisation and structural controls: file the application while standing up escrow segregation, KYC and anti-money-laundering processes under the Prevention of Money Laundering Act and the RBI KYC directions, data-storage arrangements that keep payment data in India, grievance redressal, and a nodal compliance officer.
- Go-live and ongoing: once authorised, the calendar fills with periodic reporting (including CIMS filings for digital lenders), audits, cyber-security and system audits, and prompt disclosure of material changes. A designated compliance official must certify certain filings.
Two lower-friction on-ramps are worth building into this timeline. The RBI's Enabling Framework for Regulatory Sandbox, first issued in 2019, lets an India-registered company, bank, or LLP live-test an innovative product with real customers under supervision, in time-bound thematic cohorts. Separately, the RBI finalised its framework for Self-Regulatory Organisations in the FinTech sector in 2024 and has recognised the Fintech Association for Consumer Empowerment (FACE) as an SRO in the FinTech sector. Engaging with the sandbox and the SRO early gives you regulatory visibility and a seat at the table long before you are large enough to be on the RBI's radar involuntarily.
How regulation becomes a moat
Founders instinctively see compliance as a tax. In Indian fintech it is closer to a fortification. The Rs 15 crore to Rs 25 crore net worth for a payment aggregator, the phased Rs 10 crore Net Owned Fund for an NBFC, and the three-year maintenance obligations are barriers that filter out under-capitalised imitators. Escrow discipline, direct borrower-to-lender fund flows, and CIMS listing are trust primitives that banks and enterprise customers now demand before they will partner you, so being clean is a distribution advantage, not just a legal one. The 10 percent co-lending retention and the 5 percent FLDG cap force you to hold real skin in the game, which means the fintechs that survive are the ones whose underwriting genuinely works. And a licence, once earned, compounds: it lets you add adjacent products, plug into the AA network as a Financial Information User, and negotiate co-lending capital from a position of regulatory standing. The competitors who cut corners on any of this are one supervisory action away from losing their banking partners overnight.
The founder's sequencing checklist
- Name the regulated activity first. Wallet, lending, payment aggregation, or data-sharing each maps to a different framework and a different balance sheet.
- Decide own-licence versus partnership. If your capital or timeline cannot support a direct licence, launch as an LSP, a PG, or a co-lending originator with a regulated partner, and design for the direct rules from the start.
- Model the three-year capital ramp, not just the entry ticket. The maintained thresholds are what actually gate scale.
- Treat escrow, fund flow, KYC/AML, data localisation and reporting as product, not paperwork. They are load-bearing.
- Use the sandbox and the SRO to build regulatory relationships before you need them.
- Verify every rule against the current RBI direction before you act. These frameworks were materially revised in 2025 and the perimeter keeps moving.
Get the licence question right and the rest of the go-to-market, distribution, pricing, and product, is built on solid ground. Get it wrong and you will be re-architecting under a regulator's deadline, which is the most expensive way any Indian fintech has ever shipped.

