1. TransUnion CIBIL Limited
Key Violations
- Failure to credit compensation amounts to bank accounts of eligible complainants within the prescribed period for delayed updation/rectification of credit information.
Root Cause Analysis (RCA)
- Inadequate integration between the internal grievance redressal system and automated payout gateways.
- Lack of automated triggers (SLA alerts) ensuring compensation payouts are executed before the regulatory TAT expires.
Preventive Controls
- Implementation of Straight-Through Processing (STP) for dispute compensation payouts.
- Automated daily exception reporting for customer complaints nearing regulatory deadlines.
Lessons Learnt
Customer compensation policies must be supported by agile technological infrastructure. Manual intervention in processing mandatory regulatory payouts creates high compliance risk. Companies must ensure API-driven auto-crediting mechanisms for grievance redressal.
RBI Press Release
2. CRIF High Mark Credit Information Services Pvt Ltd
Key Violations
- Failed to credit compensation amounts to the bank accounts of certain eligible complainants within the prescribed period.
Root Cause Analysis (RCA)
- Inefficient tracking of the lifecycle of credit information disputes.
- Delays in verifying claimant bank account details, leading to breaches in compensation timelines.
Preventive Controls
- Mandating upfront collection or validation of bank account details when a dispute is lodged.
- Setup of a dedicated compliance monitoring dashboard to track TAT for dispute resolution and corresponding compensation.
Lessons Learnt
Regulatory timelines for compensation are absolute. Operational bottlenecks, such as missing bank details, cannot be used as an excuse for non-compliance. Institutions must design proactive data-gathering steps at the initiation of a complaint.
RBI Press Release
3. Hinduja Leyland Finance Limited
Key Violations
- Failure to put in place a Board-approved policy on the pricing of microfinance loans.
- Undertook activities in the nature of ‘Synthetic Securitisation’.
Root Cause Analysis (RCA)
- Oversight at the Board and senior management level regarding specific microfinance regulatory frameworks.
- Inadequate product-level compliance checks allowing complex structures (Synthetic Securitisation) that violate standard asset securitisation norms.
Preventive Controls
- Mandatory vetting of all new financial products and securitisation structures by an independent compliance and legal committee before rollout.
- Annual review calendar for Board-approved policies to ensure no mandated policy is omitted.
Lessons Learnt
Board governance is paramount in pricing strategies, especially in sensitive sectors like microfinance. Furthermore, financial engineering (like synthetic securitisation) must strictly adhere to RBI’s prescriptive boundaries, requiring robust pre-launch regulatory mapping.
RBI Press Release
4. Sammaan Finserve Limited
Key Violations
- Failed to report credit information of its borrowers to the Central Repository of Information on Large Credits (CRILC).
Root Cause Analysis (RCA)
- Breakdown or lack of automated data extraction from the Loan Origination/Management System to the CRILC reporting utility.
- Absence of a secondary reconciliation process to ensure all eligible large exposures are successfully uploaded.
Preventive Controls
- Automating the CRILC data generation and submission process directly from the Core system.
- Implementation of a Maker-Checker process for regulatory submissions with a pre-submission data reconciliation step.
Lessons Learnt
Systemic stability depends on accurate credit reporting. Missing CRILC reports obscure systemic risk visibility for the regulator. Robust data governance and automated reporting pipelines are non-negotiable for NBFCs handling large credit exposures.
RBI Press Release
5. Shri Vijay Mahantesh Co-operative Bank Ltd
Key Violations
- Failed to classify certain loan accounts as Non-Performing Assets (NPAs).
- Sanctioned loans to directors, their relatives, or firms/concerns in which they are interested.
Root Cause Analysis (RCA)
- Manual intervention or overriding of the Core Banking System (CBS) in asset classification (IRAC norms).
- Failure to maintain and validate borrower profiles against a restricted list of directors and their relatives during loan origination.
Preventive Controls
- Implementation of system-driven, automated NPA classification at End of Day (EOD) without manual override capabilities.
- Hard-coding a block in the loan origination system against Customer IDs (CIF) tagged as directors/relatives.
Lessons Learnt
Conflict of interest and evergreening of bad loans remain critical risks in the co-operative banking sector. Banks must eliminate manual discretion in IRAC classifications and strictly enforce connected-lending restrictions through system-level controls.
RBI Press Release
6. Jai Bhawani Sahakari Bank Ltd., Pune
Key Violations
- Failed to report credit information of borrowers to all Credit Information Companies (CICs).
- Failed to review the risk categorization of accounts as per the prescribed periodicity (KYC norms).
Root Cause Analysis (RCA)
- Incomplete system integration with all four licensed CICs, leading to fragmented reporting.
- Lack of a dynamic AML/KYC alert mechanism in the CBS to prompt periodic risk reviews (e.g., high-risk, medium-risk, low-risk timelines).
Preventive Controls
- Establish uniform automated data pipelines to all CICs using the uniform reporting format.
- Deploy an automated KYC review calendar that flags and restricts accounts non-compliant with periodic updation.
Lessons Learnt
Credit discipline and Anti-Money Laundering (AML) frameworks require constant upkeep. Periodic KYC review is not a one-time onboarding activity but an ongoing risk management process that must be technologically enforced.
RBI Press Release
7. The Pragathi Co-operative Bank Limited
Key Violations
- Sanctioned director-related loans.
- Breached prescribed regulatory limits for single borrower exposure.
- Breached prudential inter-bank (gross) exposure limits and counter-party limits.
Root Cause Analysis (RCA)
- Systemic failure of credit risk management frameworks and bypassing of capital-linked exposure limits in the CBS.
- Poor treasury management oversight resulting in excessive funds parked in single counter-party banks.
Preventive Controls
- System-level hard stops for loan sanctions exceeding 15% (single) or 25% (group) of capital funds.
- Daily treasury monitoring dashboards triggering alerts when inter-bank deposits reach 80% of the prescribed regulatory threshold.
Lessons Learnt
Concentration risk is a severe threat to bank solvency. Breaching exposure norms—whether to borrowers or other banks—indicates a weak credit appraisal and treasury governance culture. Automated limit management is essential.
RBI Press Release
8. Equifax Credit Information Services Pvt Ltd
Key Violations
- Failure to credit compensation amounts to the bank accounts of certain eligible complainants within the prescribed period.
Root Cause Analysis (RCA)
- Inadequate post-resolution audit mechanisms to ensure that resolved complaints seamlessly trigger the financial compensation workflow.
Preventive Controls
- Integration of compensation processing directly into the core grievance redressal module to remove manual handover delays.
Lessons Learnt
The consistent penalization across major CICs (CIBIL, CRIF, Equifax) for the same violation highlights an industry-wide gap in automating grievance compensation. Institutions must view compensation as an integral part of dispute resolution, not a secondary administrative task.
RBI Press Release
9. Vikas Souharda Co-operative Bank Limited
Key Violations
- Failed to classify certain loan accounts as Non-Performing Assets (NPAs).
Root Cause Analysis (RCA)
- Ineffective parameters set within the CBS for identifying 90-day overdue accounts, or manual circumvention of system alerts to suppress NPA levels.
Preventive Controls
- Mandatory concurrent audit of IRAC classifications and strict restriction on manual alterations of asset classification codes in the database.
Lessons Learnt
Accurate asset quality reporting is the bedrock of banking transparency. Suppressing NPAs through system loopholes or manual workarounds ultimately invites regulatory action and damages institutional credibility.
RBI Press Release
10. Jalna District Central Co-operative Bank Ltd
Key Violations
- Failed to report credit information of borrowers to all CICs.
- Failed to carry out periodic reviews of risk categorisation of accounts (at least once in six months).
Root Cause Analysis (RCA)
- Lack of technical bandwidth to generate and upload data formats required by multiple CICs.
- Total absence of an ongoing risk-monitoring mechanism for existing customer profiles.
Preventive Controls
- Outsourcing or upgrading CBS capabilities to enable one-click generation of CIC reporting files.
- Instituting a bi-annual automated sweep of customer accounts to flag and enforce KYC/risk categorization reviews.
Lessons Learnt
Even basic foundational compliances (KYC updation and credit reporting) require dedicated IT infrastructure. District co-operative banks must prioritize technology upgrades to stay compliant with standard regulatory guidelines.
RBI Press Release
11. The Mumbai District Central Co-operative Bank Ltd., Maharashtra
Key Violations
- Failed to upload the KYC records of customers onto the Central KYC Records Registry (CKYCR) within the prescribed timeline.
Root Cause Analysis (RCA)
- Lack of automated API integration between the bank’s core customer onboarding module and the CKYCR portal.
- Heavy reliance on manual, periodic batch uploads, resulting in operational backlogs and breaches of regulatory timelines.
Preventive Controls
- Deploy an automated daily synchronization mechanism (API or STP) to push new/updated KYC records directly to CKYCR.
- Develop an internal exception monitoring dashboard to proactively flag records pending CKYCR upload nearing the regulatory deadline.
Lessons Learnt
Centralized KYC registries are critical for the national Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT) framework. Timely submission of KYC data is a strict compliance requirement, and banks must ensure their IT infrastructure can support seamless, automated data transmission to regulatory registries without manual delays.