Every regulated entity's Digital Lending App must be listed in RBI's Digital Lending Apps (DLA) directory, and must be able to show a loan application came from a genuine device — not a repackaged clone or a device farm. The compliance date was 1 July 2025.
The directions apply to regulated entities (banks and NBFCs) and the Lending Service Providers (LSPs) and Digital Lending Apps (DLAs) that originate or service a loan on their behalf.
| Requirement | What It Means in the App | What Satisfies It in NonaShield |
|---|---|---|
| DLA directory listing | Your app must appear in RBI's published directory of genuine Digital Lending Apps, so a borrower can verify it's authorised. | Directory listing is your compliance filing, not a technical control — NonaShield doesn't touch this step. |
| Genuine-device verification | A directory listing doesn't stop a repackaged clone of your app, or a device farm, from originating loans at scale. | RASP and hardware attestation detect repackaging, rooted devices and emulator farms at the moment of onboarding. |
| Device binding at disbursal | The device that applies for the loan should be the device that receives disbursal — not a second, substituted handset. | Device fingerprint and identity binding tie the application and disbursal to the same recognised, attested device. |
| Evidence for regulator review | If a loan is disputed or flagged, the lender needs to show what the app actually saw at the moment of application — not a reconstruction. | A signed, tamper-evident evidence record for every loan application, generated at the moment it happened. |
Instrument: RBI Digital Lending Directions 2025 and the DLA directory, as published by RBI. This maps the directions to a shipped control — it is not legal advice; confirm current requirements with your compliance counsel.
The compliance date for the DLA directory requirement. Dates are compliance dates, not issue dates, as published by RBI.
A directory entry tells a borrower your app is genuine. It doesn't tell you whether the loan application in front of you came from a real person on a real phone, or a script running across a rack of emulators. That check has to run on every application, not once at listing time. See the zero-spoof architecture case study.
The RBI Digital Lending Directions are one of seven compliance instruments NonaShield maps to on day one — alongside RBI's Digital Payment Security Controls, the RBI Authentication Directions, NPCI's UPI MASF, PCI DSS v4.0.1, CERT-In's retention rules and DPDP Rule 6. See the full compliance mapping →
Every regulated entity's Digital Lending App must be listed in RBI's Digital Lending Apps (DLA) directory, and the app must be able to show it is running on a genuine device — not a repackaged clone or a device farm used to originate loans at scale. The compliance date was 1 July 2025.
NBFCs, banks and their Lending Service Providers (LSPs) that originate or service loans through a mobile app or a digital lending app operated on their behalf.
No. The directory tells a borrower which apps are genuine; it does not verify that any single loan application on that app came from a real device rather than a repackaged clone or an emulator farm. That verification is a separate, ongoing technical control.
NonaShield's RASP, device fingerprint and hardware-attestation layers detect repackaged apps, rooted devices and device-farm patterns at onboarding, and produce a signed evidence record for every loan application — control-mapped on day one, not a compliance roadmap.
Twelve controls, mapped to RBI's Digital Lending Directions, for your app.