The RBI digital lending security requirements decide whether a digital lender can operate at all. This guide breaks down the security rules every regulated entity, lending service provider, and digital lending app must meet, and how a lean team can comply without a large security function.
TL;DR
The RBI digital lending security requirements make the regulated entity responsible for security across the whole lending stack. The core rules: encrypt borrower data, store it in India, run ongoing VAPT, collect data need-based with logged consent, vet partners, and register every digital lending app on the CIMS portal. Accountability never transfers to a partner.
On this page
What the RBI digital lending security requirements cover
These requirements are set out in the Digital Lending Directions, 2025, a consolidated framework the Reserve Bank of India issued to replace a scattered set of earlier circulars. The central idea behind the RBI digital lending security requirements is simple: the regulated entity, the licensed lender, is responsible for the security and privacy of borrower data across the whole lending chain, including any lending service provider and any digital lending app operating on its behalf. Every entity in that chain must meet RBI-specified technology and cybersecurity standards, and those standards are expected to evolve, so compliance is continuous rather than one-time.
The six RBI digital lending security requirements that matter most
While the directions are broad, the rules come down to a recognisable set of security controls in day-to-day practice. These are the six that most often decide whether a digital lender passes scrutiny.
In practice that means encrypting borrower data at rest and in transit, storing all borrower data on servers located in India, running vulnerability assessment and penetration testing on an ongoing basis with experienced professionals, collecting data only on a need-based footing with prior explicit consent and an audit trail, conducting enhanced security due diligence on every lending service provider before contracting, and registering every digital lending app on the RBI CIMS portal. A structured VAPT programme is usually the fastest way to demonstrate the testing leg of the RBI digital lending security requirements.
What borrower data you can store
Data minimisation is a large part of the framework. Lending service providers may store only the minimal customer data necessary to run the loan, and there is an explicit privacy-policy obligation covering how long data is kept, how it is destroyed, and how breaches are handled.
Crucially, lending service providers are prohibited from storing sensitive borrower data such as Aadhaar numbers or bank passwords on their own servers, they may hold only minimal data like name, address, and contact details. All of it must be stored in India, and it cannot be transferred outside the country without explicit RBI approval. Handling this correctly is one of the most scrutinised parts of these rules.
Who is accountable for security
One point runs through the whole framework: accountability sits with the regulated entity and does not transfer to partners. The framework defines three roles, but the liability is not evenly shared.
Within the RBI digital lending security requirements, the regulated entity is the lender of record and remains fully accountable for data security, even when a lending service provider or digital lending app performs the customer-facing work. That is why the directions require enhanced due diligence on partners, assessing technical capability, data-handling practices, and storage systems before any contract is signed, and reviewing that relationship periodically. Outsourcing the work never outsources the responsibility here.
Registration, whitelisting, and blocking
A distinctive feature of these rules is enforcement through visibility. Regulated entities must report every digital lending app, their own and their partners’, on the RBI CIMS portal, and a designated official must certify the accuracy of that data. The RBI publishes a whitelist of registered apps, and unregistered apps face blocking. An app that is not properly registered and compliant can be pushed out of the ecosystem, which makes registration and a demonstrable security posture inseparable. For vendors selling into this space, the pressure mirrors what startups face preparing for a SOC 2 audit before a first enterprise deal.
The lean-team path to meeting the requirements
Meeting all of this, encryption, localisation posture, ongoing VAPT, consent and audit trails, partner due diligence, and organised evidence, is a heavy lift for a lean digital-lending team without a dedicated security function. Assembling it from separate tools and consultants is slow and hard to keep audit-ready. The efficient path is a single platform that runs the security work and organises the evidence together.
Meet the RBI digital lending security requirements without a big team.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups and lean lending teams. Run VAPT, secure and localise borrower data, and keep audit-ready evidence, on one platform. No security team required.
Book a Demo →Frequently asked questions
What are the RBI digital lending security requirements?
They are the security and data-protection obligations in the Digital Lending Directions, 2025: encryption of borrower data, data localisation in India, ongoing VAPT, need-based collection with logged consent, enhanced due diligence on partners, and registration of every digital lending app on the RBI CIMS portal.
Does borrower data have to be stored in India?
Yes. All borrower data must be stored on servers located within India, and it cannot be transferred outside the country without explicit RBI approval. Data localisation is one of the hardest lines in the requirements.
Can a lending service provider store Aadhaar or bank passwords?
No. Lending service providers are prohibited from storing sensitive borrower data such as Aadhaar numbers or bank passwords on their own servers. They may hold only minimal data like name, address, and contact details needed to run the loan.
Is VAPT required for digital lending?
Yes. RBI expects vulnerability assessment and penetration testing on an ongoing basis, conducted by experienced professionals, as part of the technology and cybersecurity standards that apply to regulated entities and their lending service providers.
Who is responsible if a partner mishandles borrower data?
The regulated entity. It is the lender of record and remains fully accountable for security even when a lending service provider or digital lending app does the customer-facing work. That is why enhanced due diligence on partners is mandatory.
What happens if a digital lending app is not registered?
Regulated entities must register every digital lending app on the RBI CIMS portal, with accuracy certified by a designated official. The RBI publishes a whitelist, and unregistered apps face blocking, so registration and a demonstrable security posture go together.

