1. Appnit Technologies Private Limited
Key Details
- Penalty Amount: ₹5.80 lakh
- Date of Order: May 11, 2026
- Violations: Non-compliance with RBI directions on ‘Know Your Customer (KYC)’ and ‘Prepaid Payment Instruments (PPI)’.
- Specific Failures: Allowed PPI accounts opened via Aadhaar OTP-based e-KYC to remain active for over one year without proper identification, and failed to conduct periodic reviews of risk categorisation for accounts.
Root Cause Analysis (RCA)
The primary root cause is a systemic deficiency in the automated lifecycle management of customer accounts. The technology platform lacked hard stops or automated triggers to freeze or restrict Aadhaar OTP-based e-KYC accounts once they breached the regulatory one-year threshold. Furthermore, the absence of an integrated scheduling system for periodic risk reviews indicates a gap between compliance policy formulation and IT system execution.
- Deploy automated IT logic to freeze outgoing transactions on OTP-based e-KYC accounts 15 days prior to the one-year expiry unless full KYC is completed.
- Implement a dynamic risk-scoring engine that forces a periodic review workflow (e.g., every 6 months for high-risk accounts).
Fintech and PPI operators must ensure that regulatory time-limits (like the 1-year e-KYC rule) are hard-coded into their product architecture rather than relying on manual audits or post-facto reviews.
RBI Press Release
2. IIFL Finance Limited
Key Details
- Penalty Amount: ₹3.10 lakh
- Date of Order: May 11, 2026
- Violations: Non-compliance with the ‘Master Direction – Reserve Bank of India (Non-Banking Financial Company – Scale Based Regulation) Directions, 2023’.
- Specific Failures: The company failed to pay the surplus amount realized from the auction of pledged gold articles (over and above the loan outstanding) back to certain borrowers.
Root Cause Analysis (RCA)
The root cause points to ineffective post-auction reconciliation processes. There is a systemic disconnect between the auction recovery accounting module and the customer payout channels. Manual interventions or batch-processing delays in identifying surplus funds and initiating refunds led to omissions in returning excess funds to borrowers after collateral liquidation.
- Automate the auction reconciliation module to immediately trigger surplus refund entries to the borrower’s linked bank account upon final settlement.
- Institute a mandatory monthly reconciliation audit specifically for auctioned portfolios to track and clear unrefunded surplus balances.
Fiduciary responsibility extends beyond loan recovery. NBFCs must treat borrower surplus from liquidated collateral with the highest priority to maintain fair practice standards and avoid regulatory censure.
RBI Press Release
3. Jilla Sahakari Kendriya Bank Maryadit, Seoni
Key Details
- Penalty Amount: ₹1.50 lakh
- Date of Order: May 12, 2026
- Violations: Contravention of the Banking Regulation Act, 1949 (Section 26A and Section 56) and RBI KYC directions.
- Specific Failures: Failed to transfer eligible unclaimed amounts to the Depositor Education and Awareness Fund (DEAF) within the prescribed time, and failed to conduct periodic reviews of risk categorisation at least once every six months.
Root Cause Analysis (RCA)
These failures highlight significant procedural lags within the bank’s operational backbone. The delay in transferring funds to DEAF points to an inadequate monitoring mechanism for long-term dormant accounts in their Core Banking System (CBS). Concurrently, the failure to perform biannual KYC risk categorization updates suggests a lack of automated MIS reporting and insufficient resource allocation for ongoing compliance monitoring.
- Implement CBS alerts that flag accounts 30 days prior to them reaching the 10-year dormancy mark to ensure timely DEAF transfers.
- Establish a dedicated compliance desk responsible for generating and acting upon monthly KYC risk-review schedules.
Cooperative banks must modernize their Core Banking protocols. Manual tracking of account dormancy and KYC refresh cycles is highly error-prone and invites direct statutory penalties.
RBI Press Release
4. Shree Kadi Nagarik Sahakari Bank Ltd.
Key Details
- Penalty Amount: ₹16.30 lakh
- Date of Order: May 06, 2026
- Violations: Non-compliance with directions on ‘Exposure Norms and Statutory / Other Restrictions – UCBs’ and ‘Management of Advances – UCBs’.
- Specific Failures: The bank breached the prudential exposure limits for a group of connected borrowers and failed to ensure the end-use of funds for certain sanctioned loans.
Root Cause Analysis (RCA)
These breaches point toward critical weaknesses in the bank’s credit appraisal and post-disbursement monitoring frameworks. The breach of group exposure limits indicates that the loan origination system failed to properly map and aggregate interconnected entities and their cumulative limits. Furthermore, the inability to ensure the end-use of funds suggests a lack of post-sanction audits, site visits, or controls over direct disbursements.
- Integrate a Universal Entity Mapping (UEM) system at the credit appraisal stage to accurately calculate overall exposure to interconnected groups before sanctioning new limits.
- Mandate staggered loan disbursements directly to suppliers/vendors rather than borrower accounts, coupled with mandatory post-disbursement utilization certificates.
Effective credit risk management requires looking past individual loan applications to understand total group exposure. Post-disbursement vigilance is as crucial as pre-sanction diligence to prevent fund diversion.