What changed
RBI has introduced a formal framework for Compliance Function and CCO roles specifically for NBFCs in the Upper and Middle Layers, as part of the Scale Based Regulation (SBR) announced in October 2021. Base Layer NBFCs are excluded from this new mandate and continue under earlier guidelines. The framework sets minimum standards for compliance risk management, board oversight, and annual risk assessments.
What it means for you
NBFC-UL and NBFC-ML must now treat compliance as a core governance function with a dedicated CCO reporting to the board. This elevates compliance risk to the same level as credit and operational risks. Lenders should expect stricter adherence to regulatory norms, market conduct, and customer fairness standards. Non-compliance could lead to reputational and financial penalties.
What you must do
- Appoint a Chief Compliance Officer (CCO) and establish an independent Compliance Function by the respective deadlines (April 1, 2023 for UL; October 1, 2023 for ML).
- Get a Board-approved Compliance Policy in place, covering compliance risk identification, mitigation, and periodic reviews.
- Conduct an annual exercise to identify major compliance risks and submit a detailed review to the Board or its committee.
- Ensure the CCO is a member of relevant committees and reports promptly on any material compliance failures.
Who it affects
NBFCs in Upper Layer (NBFC-UL), NBFCs in Middle Layer (NBFC-ML), Board of Directors and Senior Management of these NBFCs, Chief Compliance Officers (CCOs) to be appointed
Does this circular apply to all NBFCs?
No, it applies only to NBFCs in the Upper Layer (UL) and Middle Layer (ML). Base Layer NBFCs continue under existing guidelines.
What is the deadline for compliance?
NBFC-UL must comply by April 1, 2023, and NBFC-ML by October 1, 2023.
What are the key responsibilities of the Compliance Function?
It must assist the board in implementing the Compliance Policy, identify compliance risks in products/processes, and ensure adherence to all statutory and regulatory requirements.