The NBFC regulatory layers are the four tiers the Reserve Bank of India uses to decide how heavily a non-banking financial company is regulated, and the tier also decides which security rules apply to it.
The short answer
Under the Scale Based Regulation framework the RBI issued on 22 October 2021, every non-banking financial company sits in one of four NBFC regulatory layers: Base, Middle, Upper or Top. Placement follows size, activity and systemic importance. The layer sets capital, governance and disclosure obligations, and it also decides whether the RBI Information Technology Governance Directions apply. Base Layer companies are outside those directions. Middle, Upper and Top Layer companies are inside them.
That last split is the one engineering teams care about. Two lenders doing similar work can sit in different NBFC regulatory layers, and face completely different security obligations, because one crossed an asset threshold.
On this page
What the four layers are
Before 2021 the RBI regulated non-banking financial companies largely by activity type. Scale Based Regulation replaced that with a pyramid of four NBFC regulatory layers. The larger and more interconnected the company, the heavier the rulebook.
How a company lands in each layer
Placement across the NBFC regulatory layers is mostly mechanical. Asset size and whether the company takes deposits do most of the work, with a handful of categories fixed by type.
| Layer | Who sits here |
|---|---|
| Base NBFC-BL | Non-deposit taking companies with assets below 1,000 crore rupees. Also permanently here regardless of size: peer-to-peer lending platforms, account aggregators, non-operative financial holding companies, and companies with no public funds and no customer interface. |
| Middle NBFC-ML | Every deposit-taking company whatever its size, plus non-deposit taking companies with assets of 1,000 crore rupees and above. Standalone primary dealers, infrastructure debt funds, core investment companies, housing finance companies and infrastructure finance companies sit here by category. |
| Upper NBFC-UL | Companies the RBI names each year as warranting closer oversight. Once named, enhanced regulation applies for at least five years and the company must list within three. |
| Top NBFC-TL | Designed to stay empty. A company moves here only if the RBI judges the systemic risk from a specific Upper Layer entity to have become extreme. |
What changed for the Upper Layer
The original method for picking Upper Layer companies combined the ten largest by asset size with a parametric scoring model covering leverage, interconnectedness, complexity and qualitative factors, so companies could not easily predict their own placement. In June 2026 the RBI replaced that with a single absolute test: assets of one lakh crore rupees and above, measured on the latest audited balance sheet. Government-owned companies, previously kept out of the Upper Layer, come inside the same test. The list is still published annually and has grown from fifteen names to seventeen.
Why the threshold matters to smaller companies
Most lenders will never approach the Upper Layer. The line in the NBFC regulatory layers that actually reshapes a growing company is the 1,000 crore rupee threshold between Base and Middle, or the decision to start taking deposits. Either one pulls the full information technology governance regime into scope.
Why NBFC regulatory layers decide your security obligations
The NBFC regulatory layers are not only a prudential device. The RBI Information Technology Governance, Risk, Controls and Assurance Practices Directions came into effect on 1 April 2024 and apply to companies in the Middle, Upper and Top Layers. Base Layer companies are excluded and continue under the lighter 2017 framework. Core Investment Companies are exempted separately.
| What the directions require | What it takes to satisfy it |
|---|---|
| Board-level technology strategy committee and a designated chief information security officer | Named accountability, minuted oversight, and a reporting line that does not sit under the technology delivery team |
| Information security policy and technology risk management | A documented control set and a working risk assessment process, refreshed rather than filed |
| Vulnerability assessment and penetration testing | Scheduled VAPT with retests, not a single report at onboarding |
| Access control and cryptographic controls | Multi-factor authentication, least privilege, and encryption in transit and at rest |
| Audit logging and cyber incident response | Centralised logging with correlation, retention, and a tested response runbook |
| Independent information systems audit | An assurance function separate from the team that built the systems |
| Business continuity and disaster recovery | Documented plans with drills that produce evidence, and recovery targets that were actually measured |
| Third party and vendor risk management | Due diligence, concentration risk analysis and exit planning for every material provider |
Supervisory findings from this regime flow into the RBI’s monitoring systems, including DAKSH, so gaps do not stay local to the company that has them.
If you sell software to a lender
Most technology companies meet the NBFC regulatory layers second-hand. A lender in the Middle or Upper Layer buys your product, and its obligations arrive in your inbox as a vendor security review.
Find out the layer first
Where a prospect sits in the NBFC regulatory layers changes how heavy the review is, what you need ready, and how long the deal takes.
Expect audit rights in the contract
The outsourcing directions push audit access, incident notification timelines and exit provisions down to material service providers.
Evidence beats assertions
A current test report and real logging evidence close reviews faster than a completed questionnaire on its own.
Where the audit is performed by a CERT-In empanelled auditor, material vendors in the flow get looked at too. The same pattern shows up in the payment aggregator regime.
How Osto gets you audit-ready
Osto covers the technical half of the NBFC regulatory layers regime by default rather than as a set of add-ons. Expert-led VAPT and continuous scanning satisfy the testing requirement with retests attached, cloud posture management and API discovery close the configuration gaps that dominate findings, and correlated logging gives you the detection and retention an information systems auditor asks to see.
The evidence layer is purpose-built for this problem. One control set answers an RBI reviewer, a lender’s vendor questionnaire, SOC 2 and ISO 27001 at the same time. Osto prepares your evidence and gets you through the review. The mandated audit itself is performed by the auditor the regulator accepts.
Free security assessment
Stop losing lender deals in security review
Osto finds and fixes what a regulated lender’s reviewer would flag, then holds the evidence. VAPT, cloud posture, code security, logging and compliance in one platform.
Get a free security assessment Book a platform walkthroughAudit-ready in days · RBI, SEBI and DPDP mapped · One platform, everything
Frequently asked questions
What are the NBFC regulatory layers?
The NBFC regulatory layers are four tiers introduced by the Reserve Bank of India under Scale Based Regulation in October 2021: Base Layer, Middle Layer, Upper Layer and Top Layer. Placement depends on size, activity and systemic importance, and it determines the capital, governance, disclosure and technology obligations that apply.
What is the asset threshold between the Base Layer and the Middle Layer?
One thousand crore rupees. A non-deposit taking company below that sits in the Base Layer. At or above it, the company moves to the Middle Layer. Deposit-taking companies are in the Middle Layer regardless of size.
How does the Reserve Bank of India identify Upper Layer companies?
Under the revised norms issued in June 2026, by a single asset size test of one lakh crore rupees and above on the latest audited balance sheet. This replaced the earlier method that combined the ten largest by assets with a parametric scoring model. Government-owned companies are now included in the same test.
Do the Information Technology Governance Directions apply across all NBFC regulatory layers?
No. The 2023 directions, effective 1 April 2024, apply to the Middle, Upper and Top Layers. Base Layer companies continue under the 2017 Master Direction on the information technology framework for the sector. Core Investment Companies are exempted from the 2023 directions separately.
Why do the layers matter if I only sell software to a lender?
Because the lender’s obligations pass down through its vendor and outsourcing controls. A Middle or Upper Layer customer has to run due diligence on material providers, hold audit rights, agree incident notification timelines and plan an exit. That arrives as a security review you have to clear before the contract is signed.

