RBI Digital Lending Security Requirements: A Complete Guide

RBI digital lending security requirements guide
RBI Digital Lending Security Requirements: 6 Essential Rules | Osto

The RBI digital lending security requirements decide whether a digital lender can operate at all. This guide breaks down the security rules every regulated entity, lending service provider, and digital lending app must meet, and how a lean team can comply without a large security function.

Osto Security Team10 min readRBI Compliance

TL;DR

The RBI digital lending security requirements make the regulated entity responsible for security across the whole lending stack. The core rules: encrypt borrower data, store it in India, run ongoing VAPT, collect data need-based with logged consent, vet partners, and register every digital lending app on the CIMS portal. Accountability never transfers to a partner.

What the RBI digital lending security requirements cover

These requirements are set out in the Digital Lending Directions, 2025, a consolidated framework the Reserve Bank of India issued to replace a scattered set of earlier circulars. The central idea behind the RBI digital lending security requirements is simple: the regulated entity, the licensed lender, is responsible for the security and privacy of borrower data across the whole lending chain, including any lending service provider and any digital lending app operating on its behalf. Every entity in that chain must meet RBI-specified technology and cybersecurity standards, and those standards are expected to evolve, so compliance is continuous rather than one-time.

The six RBI digital lending security requirements that matter most

While the directions are broad, the rules come down to a recognisable set of security controls in day-to-day practice. These are the six that most often decide whether a digital lender passes scrutiny.

The requirements
What the rules actually demand
These security rules sit inside the Digital Lending Directions, 2025, which make the regulated entity responsible for security across the whole lending stack. Six requirements matter most in practice, and they apply whether you lend directly or through a partner.
The core security requirements to meetEncryptionProtect borrower data at restand in transitData localisationStore all borrower data onservers in IndiaOngoing VAPTRegular testing by experiencedprofessionalsConsent and audit trailNeed-based collection, loggedconsentLSP due diligenceVet partner security beforecontractingCIMS registrationRegister every DLA, certified asaccurate

In practice that means encrypting borrower data at rest and in transit, storing all borrower data on servers located in India, running vulnerability assessment and penetration testing on an ongoing basis with experienced professionals, collecting data only on a need-based footing with prior explicit consent and an audit trail, conducting enhanced security due diligence on every lending service provider before contracting, and registering every digital lending app on the RBI CIMS portal. A structured VAPT programme is usually the fastest way to demonstrate the testing leg of the RBI digital lending security requirements.

Security is now a precondition, not a nice-to-have
Under these rules, weak security is not just a risk, it is a compliance failure. The regulated entity must be able to show, with evidence, that these controls are actually in place across itself and its partners.

What borrower data you can store

Data minimisation is a large part of the framework. Lending service providers may store only the minimal customer data necessary to run the loan, and there is an explicit privacy-policy obligation covering how long data is kept, how it is destroyed, and how breaches are handled.

Data rules
What you may keep, and what you may not
A large part of the framework is about data minimisation. Lending service providers may hold only the minimal borrower data needed to run the loan, and sensitive identifiers are off limits on their own servers.
What borrower data can be stored Minimal data, allowed NameAddressContact detailsMinimal data to run the loan Prohibited on LSP servers Aadhaar numbersBank passwordsBiometric dataAnything beyond need-based

Crucially, lending service providers are prohibited from storing sensitive borrower data such as Aadhaar numbers or bank passwords on their own servers, they may hold only minimal data like name, address, and contact details. All of it must be stored in India, and it cannot be transferred outside the country without explicit RBI approval. Handling this correctly is one of the most scrutinised parts of these rules.

Localisation is a hard line
All borrower data must reside on servers in India, with no cross-border transfer without explicit RBI approval. For a digital lender built on global cloud infrastructure, this is an architecture decision to make early, not a setting to flip later.

Who is accountable for security

One point runs through the whole framework: accountability sits with the regulated entity and does not transfer to partners. The framework defines three roles, but the liability is not evenly shared.

Accountability
The regulated entity owns the risk
The rules assign clear roles, but accountability does not transfer. The regulated entity remains responsible for security even when a lending service provider or a digital lending app does the customer-facing work.
Who is accountable for security Regulated Entity The lender of record. Remains fully accountable for data security, even when work is outsourced. Lending Service Provider The partner or agent. Must meet security standards and store only minimal borrower data. Digital Lending App The borrower interface. Must be registered on the CIMS portal and operate in a secure environment.

Within the RBI digital lending security requirements, the regulated entity is the lender of record and remains fully accountable for data security, even when a lending service provider or digital lending app performs the customer-facing work. That is why the directions require enhanced due diligence on partners, assessing technical capability, data-handling practices, and storage systems before any contract is signed, and reviewing that relationship periodically. Outsourcing the work never outsources the responsibility here.

Registration, whitelisting, and blocking

A distinctive feature of these rules is enforcement through visibility. Regulated entities must report every digital lending app, their own and their partners’, on the RBI CIMS portal, and a designated official must certify the accuracy of that data. The RBI publishes a whitelist of registered apps, and unregistered apps face blocking. An app that is not properly registered and compliant can be pushed out of the ecosystem, which makes registration and a demonstrable security posture inseparable. For vendors selling into this space, the pressure mirrors what startups face preparing for a SOC 2 audit before a first enterprise deal.

The lean-team path to meeting the requirements

Meeting all of this, encryption, localisation posture, ongoing VAPT, consent and audit trails, partner due diligence, and organised evidence, is a heavy lift for a lean digital-lending team without a dedicated security function. Assembling it from separate tools and consultants is slow and hard to keep audit-ready. The efficient path is a single platform that runs the security work and organises the evidence together.

Meet the RBI digital lending security requirements without a big team.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups and lean lending teams. Run VAPT, secure and localise borrower data, and keep audit-ready evidence, on one platform. No security team required.

Book a Demo →

Frequently asked questions

What are the RBI digital lending security requirements?

They are the security and data-protection obligations in the Digital Lending Directions, 2025: encryption of borrower data, data localisation in India, ongoing VAPT, need-based collection with logged consent, enhanced due diligence on partners, and registration of every digital lending app on the RBI CIMS portal.

Does borrower data have to be stored in India?

Yes. All borrower data must be stored on servers located within India, and it cannot be transferred outside the country without explicit RBI approval. Data localisation is one of the hardest lines in the requirements.

Can a lending service provider store Aadhaar or bank passwords?

No. Lending service providers are prohibited from storing sensitive borrower data such as Aadhaar numbers or bank passwords on their own servers. They may hold only minimal data like name, address, and contact details needed to run the loan.

Is VAPT required for digital lending?

Yes. RBI expects vulnerability assessment and penetration testing on an ongoing basis, conducted by experienced professionals, as part of the technology and cybersecurity standards that apply to regulated entities and their lending service providers.

Who is responsible if a partner mishandles borrower data?

The regulated entity. It is the lender of record and remains fully accountable for security even when a lending service provider or digital lending app does the customer-facing work. That is why enhanced due diligence on partners is mandatory.

What happens if a digital lending app is not registered?

Regulated entities must register every digital lending app on the RBI CIMS portal, with accuracy certified by a designated official. The RBI publishes a whitelist, and unregistered apps face blocking, so registration and a demonstrable security posture go together.