NBFC & Digital Lending · Compliance

RBI Digital Lending Directions 2025: what it requires of your app.

Every regulated entity's Digital Lending App must be listed in RBI's Digital Lending Apps (DLA) directory, and must be able to show a loan application came from a genuine device — not a repackaged clone or a device farm. The compliance date was 1 July 2025.

Who This Binds

NBFCs, Banks, and Their Lending Service Providers.

The directions apply to regulated entities (banks and NBFCs) and the Lending Service Providers (LSPs) and Digital Lending Apps (DLAs) that originate or service a loan on their behalf.

RequirementWhat It Means in the AppWhat Satisfies It in NonaShield
DLA directory listing Your app must appear in RBI's published directory of genuine Digital Lending Apps, so a borrower can verify it's authorised. Directory listing is your compliance filing, not a technical control — NonaShield doesn't touch this step.
Genuine-device verification A directory listing doesn't stop a repackaged clone of your app, or a device farm, from originating loans at scale. RASP and hardware attestation detect repackaging, rooted devices and emulator farms at the moment of onboarding.
Device binding at disbursal The device that applies for the loan should be the device that receives disbursal — not a second, substituted handset. Device fingerprint and identity binding tie the application and disbursal to the same recognised, attested device.
Evidence for regulator review If a loan is disputed or flagged, the lender needs to show what the app actually saw at the moment of application — not a reconstruction. A signed, tamper-evident evidence record for every loan application, generated at the moment it happened.

Instrument: RBI Digital Lending Directions 2025 and the DLA directory, as published by RBI. This maps the directions to a shipped control — it is not legal advice; confirm current requirements with your compliance counsel.

The Deadline

1 July 2025. Already Behind You.

1 Jul 2025

The compliance date for the DLA directory requirement. Dates are compliance dates, not issue dates, as published by RBI.

Common Mistake

A Directory Listing Isn't a Fraud Control.

What teams treat as "done"

  • Getting the app listed in RBI's DLA directory.
  • Publishing the required disclosures in-app.
  • Assuming app-store review catches repackaged clones.

What actually stops the fraud pattern

  • Detecting a repackaged APK before it can originate a loan.
  • Telling a device farm from a genuine, individual applicant.
  • Binding the application and the disbursal to the same attested device.
  • Producing a signed record of what the app saw, per application, not after the fact.

A directory entry tells a borrower your app is genuine. It doesn't tell you whether the loan application in front of you came from a real person on a real phone, or a script running across a rack of emulators. That check has to run on every application, not once at listing time. See the zero-spoof architecture case study.

The Full Picture

One Platform, Twelve Controls, Every Sector.

The RBI Digital Lending Directions are one of seven compliance instruments NonaShield maps to on day one — alongside RBI's Digital Payment Security Controls, the RBI Authentication Directions, NPCI's UPI MASF, PCI DSS v4.0.1, CERT-In's retention rules and DPDP Rule 6. See the full compliance mapping →

Questions People Ask

RBI Digital Lending, Answered.

What do the RBI Digital Lending Directions 2025 require of a mobile app?

Every regulated entity's Digital Lending App must be listed in RBI's Digital Lending Apps (DLA) directory, and the app must be able to show it is running on a genuine device — not a repackaged clone or a device farm used to originate loans at scale. The compliance date was 1 July 2025.

Who do the RBI Digital Lending Directions apply to?

NBFCs, banks and their Lending Service Providers (LSPs) that originate or service loans through a mobile app or a digital lending app operated on their behalf.

Does listing an app in the DLA directory make it secure?

No. The directory tells a borrower which apps are genuine; it does not verify that any single loan application on that app came from a real device rather than a repackaged clone or an emulator farm. That verification is a separate, ongoing technical control.

How does NonaShield map to the RBI Digital Lending Directions?

NonaShield's RASP, device fingerprint and hardware-attestation layers detect repackaged apps, rooted devices and device-farm patterns at onboarding, and produce a signed evidence record for every loan application — control-mapped on day one, not a compliance roadmap.

Ask Us for the Coverage Report.

Twelve controls, mapped to RBI's Digital Lending Directions, for your app.