{"id":959,"date":"2026-08-23T20:26:27","date_gmt":"2026-08-23T20:26:27","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=959"},"modified":"2026-08-23T20:26:27","modified_gmt":"2026-08-23T20:26:27","slug":"nbfc-regulatory-layers","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/nbfc-regulatory-layers\/","title":{"rendered":"NBFC Regulatory Layers"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: NBFC REGULATORY LAYERS\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">The NBFC regulatory layers are the four tiers the Reserve Bank of India uses to decide how heavily a non-banking financial company is regulated, and the tier also decides which security rules apply to it.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">India<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Under the Scale Based Regulation framework the RBI issued on 22 October 2021, every non-banking financial company sits in one of four NBFC regulatory layers: Base, Middle, Upper or Top. Placement follows size, activity and systemic importance. The layer sets capital, governance and disclosure obligations, and it also decides whether the RBI Information Technology Governance Directions apply. Base Layer companies are outside those directions. Middle, Upper and Top Layer companies are inside them.<\/p>\n<\/div>\n\n<p>That last split is the one engineering teams care about. Two lenders doing similar work can sit in different NBFC regulatory layers, and face completely different security obligations, because one crossed an asset threshold.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">What the four layers are<\/a><\/li>\n    <li><a href=\"#place\">How a company lands in each layer<\/a><\/li>\n    <li><a href=\"#upper\">What changed for the Upper Layer<\/a><\/li>\n    <li><a href=\"#security\">Why NBFC regulatory layers decide your security obligations<\/a><\/li>\n    <li><a href=\"#vendor\">If you sell software to a lender<\/a><\/li>\n    <li><a href=\"#osto\">How Osto gets you audit-ready<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">What the four layers are<\/h2>\n\n<p>Before 2021 the RBI regulated non-banking financial companies largely by activity type. Scale Based Regulation replaced that with a pyramid of four NBFC regulatory layers. The larger and more interconnected the company, the heavier the rulebook.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 320\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The four NBFC regulatory layers: Base, Middle, Upper and Top, with the security regime that applies to each.\">\n  <rect x=\"14\" y=\"16\" width=\"470\" height=\"52\" rx=\"13\" fill=\"#6b4576\"\/>\n  <text x=\"40\" y=\"40\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">Top Layer<\/text>\n  <text x=\"40\" y=\"58\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#e3d4e8\">Intended to stay empty<\/text>\n\n  <rect x=\"14\" y=\"78\" width=\"470\" height=\"52\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"40\" y=\"102\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">Upper Layer<\/text>\n  <text x=\"40\" y=\"120\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Identified annually by the RBI<\/text>\n\n  <rect x=\"14\" y=\"140\" width=\"470\" height=\"52\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"40\" y=\"164\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#4a52a8\">Middle Layer<\/text>\n  <text x=\"40\" y=\"182\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Deposit taking, or assets of 1,000 crore and above<\/text>\n\n  <rect x=\"14\" y=\"202\" width=\"470\" height=\"52\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"40\" y=\"226\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#3a6f5d\">Base Layer<\/text>\n  <text x=\"40\" y=\"244\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Non-deposit taking, assets below 1,000 crore<\/text>\n\n  <line x1=\"498\" y1=\"16\" x2=\"498\" y2=\"192\" stroke=\"#4a52a8\" stroke-width=\"2\"\/>\n  <line x1=\"498\" y1=\"16\" x2=\"512\" y2=\"16\" stroke=\"#4a52a8\" stroke-width=\"2\"\/>\n  <line x1=\"498\" y1=\"192\" x2=\"512\" y2=\"192\" stroke=\"#4a52a8\" stroke-width=\"2\"\/>\n  <rect x=\"518\" y=\"66\" width=\"228\" height=\"76\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"632\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">IT Governance Directions<\/text>\n  <text x=\"632\" y=\"113\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Board committee, CISO, audit,<\/text>\n  <text x=\"632\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">testing, continuity planning<\/text>\n\n  <line x1=\"498\" y1=\"202\" x2=\"498\" y2=\"254\" stroke=\"#3a6f5d\" stroke-width=\"2\"\/>\n  <line x1=\"498\" y1=\"202\" x2=\"512\" y2=\"202\" stroke=\"#3a6f5d\" stroke-width=\"2\"\/>\n  <line x1=\"498\" y1=\"254\" x2=\"512\" y2=\"254\" stroke=\"#3a6f5d\" stroke-width=\"2\"\/>\n  <rect x=\"518\" y=\"200\" width=\"228\" height=\"56\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"632\" y=\"224\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">2017 IT Framework<\/text>\n  <text x=\"632\" y=\"242\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">The lighter, older rulebook<\/text>\n\n  <rect x=\"14\" y=\"268\" width=\"732\" height=\"38\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"292\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Crossing from Base to Middle changes the security regime, not just the capital rules.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>The four NBFC regulatory layers and the rulebook attached to each. Amounts are in rupees crore. Core Investment Companies are carved out of the 2023 directions separately.<\/figcaption>\n<\/figure>\n\n<h2 id=\"place\" class=\"c-sage\">How a company lands in each layer<\/h2>\n\n<p>Placement across the NBFC regulatory layers is mostly mechanical. Asset size and whether the company takes deposits do most of the work, with a handful of categories fixed by type.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Layer<\/th><th>Who sits here<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Base<\/strong><br><span class=\"pill p-exp\">NBFC-BL<\/span><\/td><td>Non-deposit taking companies with assets below 1,000 crore rupees. Also permanently here regardless of size: peer-to-peer lending platforms, account aggregators, non-operative financial holding companies, and companies with no public funds and no customer interface.<\/td><\/tr>\n    <tr><td><strong>Middle<\/strong><br><span class=\"pill p-exp\">NBFC-ML<\/span><\/td><td>Every deposit-taking company whatever its size, plus non-deposit taking companies with assets of 1,000 crore rupees and above. Standalone primary dealers, infrastructure debt funds, core investment companies, housing finance companies and infrastructure finance companies sit here by category.<\/td><\/tr>\n    <tr><td><strong>Upper<\/strong><br><span class=\"pill p-req\">NBFC-UL<\/span><\/td><td>Companies the RBI names each year as warranting closer oversight. Once named, enhanced regulation applies for at least five years and the company must list within three.<\/td><\/tr>\n    <tr><td><strong>Top<\/strong><br><span class=\"pill p-req\">NBFC-TL<\/span><\/td><td>Designed to stay empty. A company moves here only if the RBI judges the systemic risk from a specific Upper Layer entity to have become extreme.<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"upper\" class=\"c-apri\">What changed for the Upper Layer<\/h2>\n\n<p>The original method for picking Upper Layer companies combined the ten largest by asset size with a parametric scoring model covering leverage, interconnectedness, complexity and qualitative factors, so companies could not easily predict their own placement. In June 2026 the RBI replaced that with a single absolute test: assets of one lakh crore rupees and above, measured on the latest audited balance sheet. Government-owned companies, previously kept out of the Upper Layer, come inside the same test. The list is still published annually and has grown from fifteen names to seventeen.<\/p>\n\n<div class=\"callout\">\n  <p class=\"k\">Why the threshold matters to smaller companies<\/p>\n  <p>Most lenders will never approach the Upper Layer. The line in the NBFC regulatory layers that actually reshapes a growing company is the 1,000 crore rupee threshold between Base and Middle, or the decision to start taking deposits. Either one pulls the full information technology governance regime into scope.<\/p>\n<\/div>\n\n<h2 id=\"security\" class=\"c-plum\">Why NBFC regulatory layers decide your security obligations<\/h2>\n\n<p>The NBFC regulatory layers are not only a prudential device. The RBI Information Technology Governance, Risk, Controls and Assurance Practices Directions came into effect on 1 April 2024 and apply to companies in the Middle, Upper and Top Layers. Base Layer companies are excluded and continue under the lighter 2017 framework. Core Investment Companies are exempted separately.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>What the directions require<\/th><th>What it takes to satisfy it<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Board-level technology strategy committee and a designated chief information security officer<\/td><td>Named accountability, minuted oversight, and a reporting line that does not sit under the technology delivery team<\/td><\/tr>\n    <tr><td>Information security policy and technology risk management<\/td><td>A documented control set and a working <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment<\/a> process, refreshed rather than filed<\/td><\/tr>\n    <tr><td>Vulnerability assessment and penetration testing<\/td><td>Scheduled <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> with retests, not a single report at onboarding<\/td><\/tr>\n    <tr><td>Access control and cryptographic controls<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">Multi-factor authentication<\/a>, least privilege, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">encryption in transit and at rest<\/a><\/td><\/tr>\n    <tr><td>Audit logging and cyber incident response<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">Centralised logging with correlation<\/a>, retention, and a tested response runbook<\/td><\/tr>\n    <tr><td>Independent information systems audit<\/td><td>An assurance function separate from the team that built the systems<\/td><\/tr>\n    <tr><td>Business continuity and disaster recovery<\/td><td>Documented plans with drills that produce evidence, and recovery targets that were actually measured<\/td><\/tr>\n    <tr><td>Third party and vendor risk management<\/td><td>Due diligence, concentration risk analysis and exit planning for every material provider<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Supervisory findings from this regime flow into the RBI&#8217;s monitoring systems, including <a href=\"https:\/\/www.osto.one\/resources\/glossary\/rbi-daksh\/\">DAKSH<\/a>, so gaps do not stay local to the company that has them.<\/p>\n\n<h2 id=\"vendor\">If you sell software to a lender<\/h2>\n\n<p>Most technology companies meet the NBFC regulatory layers second-hand. A lender in the Middle or Upper Layer buys your product, and its obligations arrive in your inbox as a vendor security review.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Find out the layer first<\/p>\n    <p>Where a prospect sits in the NBFC regulatory layers changes how heavy the review is, what you need ready, and how long the deal takes.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Expect audit rights in the contract<\/p>\n    <p>The outsourcing directions push audit access, incident notification timelines and exit provisions down to material service providers.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Evidence beats assertions<\/p>\n    <p>A current test report and real logging evidence close reviews faster than a completed questionnaire on its own.<\/p>\n  <\/div>\n<\/div>\n\n<p>Where the audit is performed by a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cert-in-empanelment\/\">CERT-In empanelled auditor<\/a>, material vendors in the flow get looked at too. The same pattern shows up in the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/payment-aggregator\/\">payment aggregator<\/a> regime.<\/p>\n\n<h2 id=\"osto\" class=\"c-sage\">How Osto gets you audit-ready<\/h2>\n\n<p>Osto covers the technical half of the NBFC regulatory layers regime by default rather than as a set of add-ons. Expert-led <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> and continuous scanning satisfy the testing requirement with retests attached, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture management<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API discovery<\/a> close the configuration gaps that dominate findings, and correlated logging gives you the detection and retention an information systems auditor asks to see.<\/p>\n\n<p>The evidence layer is purpose-built for this problem. One control set answers an RBI reviewer, a lender&#8217;s vendor questionnaire, <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-for-startups\/\" target=\"_blank\" rel=\"noopener\">SOC 2<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> at the same time. Osto prepares your evidence and gets you through the review. The mandated audit itself is performed by the auditor the regulator accepts.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Stop losing lender deals in security review<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto finds and fixes what a regulated lender&#8217;s reviewer would flag, then holds the evidence. VAPT, cloud posture, code security, logging and compliance in one platform.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Audit-ready in days &middot; RBI, SEBI and DPDP mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What are the NBFC regulatory layers?<\/summary>\n  <p>The NBFC regulatory layers are four tiers introduced by the Reserve Bank of India under Scale Based Regulation in October 2021: Base Layer, Middle Layer, Upper Layer and Top Layer. Placement depends on size, activity and systemic importance, and it determines the capital, governance, disclosure and technology obligations that apply.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the asset threshold between the Base Layer and the Middle Layer?<\/summary>\n  <p>One thousand crore rupees. A non-deposit taking company below that sits in the Base Layer. At or above it, the company moves to the Middle Layer. Deposit-taking companies are in the Middle Layer regardless of size.<\/p>\n<\/details>\n\n<details>\n  <summary>How does the Reserve Bank of India identify Upper Layer companies?<\/summary>\n  <p>Under the revised norms issued in June 2026, by a single asset size test of one lakh crore rupees and above on the latest audited balance sheet. This replaced the earlier method that combined the ten largest by assets with a parametric scoring model. Government-owned companies are now included in the same test.<\/p>\n<\/details>\n\n<details>\n  <summary>Do the Information Technology Governance Directions apply across all NBFC regulatory layers?<\/summary>\n  <p>No. The 2023 directions, effective 1 April 2024, apply to the Middle, Upper and Top Layers. Base Layer companies continue under the 2017 Master Direction on the information technology framework for the sector. Core Investment Companies are exempted from the 2023 directions separately.<\/p>\n<\/details>\n\n<details>\n  <summary>Why do the layers matter if I only sell software to a lender?<\/summary>\n  <p>Because the lender&#8217;s obligations pass down through its vendor and outsourcing controls. A Middle or Upper Layer customer has to run due diligence on material providers, hold audit rights, agree incident notification timelines and plan an exit. That arrives as a security review you have to clear before the contract is signed.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> RBI DAKSH &middot; Payment Aggregator &middot; CERT-In Empanelment &middot; VAPT &middot; SIEM &middot; Risk Assessment &middot; ISO 27001 &middot; DPDP Act<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The NBFC regulatory layers are the four tiers the Reserve Bank of India uses to decide how heavily a non-banking\u2026<\/p>\n","protected":false},"author":8,"featured_media":960,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[423,424],"class_list":["post-959","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-nbfc-regulatory-layers","tag-scale-based-regulation-nbfc"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/959","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=959"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/959\/revisions"}],"predecessor-version":[{"id":961,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/959\/revisions\/961"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/960"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=959"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=959"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=959"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}