1. Hero Fincorp Limited
Key Details
- Penalty Amount: ₹10 Lakh
- Date of Order: September 22, 2026
- Statutory Basis: Section 58G(1)(b) read with Section 58B(5)(aa) of the RBI Act, 1934
- Inspection Period: As on March 31, 2025
The Violation
Non-compliance with directions on ‘Fair Practices Code for Lenders – Charging of Interest’. Specifically, the company was found to have collected excess interest from certain loan accounts.
Root Cause Analysis (RCA)
- Potential flaws or misconfigurations in the core lending system’s interest calculation logic.
- Lack of robust automated controls to flag deviations between the contracted interest rate and the actual rate applied.
- Inadequate periodic reconciliation processes to identify and rectify overcharges before regulatory scrutiny.
- Possible misinterpretation of the ‘Fair Practices Code’ guidelines regarding interest application methodologies during varying loan lifecycles.
Preventive Controls Recommended
- System Audit: Conduct an immediate, comprehensive audit of the Loan Management System (LMS) interest calculation algorithms.
- Automated Alerts: Implement system-level alerts that trigger if the calculated interest deviates from the agreed-upon rate parameter.
- Maker-Checker Validation: Enforce strict maker-checker protocols for any manual adjustments to interest rates or loan terms.
- Regular Reconciliation: Institute mandatory monthly reconciliations between contracted terms and actual billing statements.
Lessons Learnt
Customer centricity must be hardcoded into systems, not just policies. Even minor systemic calculation errors, when applied across a large customer base, compound into significant regulatory violations. Continuous monitoring of IT systems for compliance with Fair Practices Code is non-negotiable.
RBI Press Release
2. Ola Financial Services Private Limited
Key Details
- Penalty Amount: ₹3.10 Lakh
- Date of Order: September 24, 2026
- Statutory Basis: Section 30(1) read with Section 26(6) of Payment and Settlement Systems Act, 2007
- Inspection Period: January 2025 to November 2025
The Violation
Non-compliance with ‘Know Your Customer (KYC)’ directions. Specifically, the entity failed to carry out the necessary risk categorisation for certain customers.
Root Cause Analysis (RCA)
- Gaps in the customer onboarding workflow where risk categorisation (Low, Medium, High) was not a mandatory, hard-stop requirement before account activation.
- Inadequate integration between the KYC data collection module and the risk assessment engine.
- Potential over-reliance on manual risk profiling without sufficient automated rules-based assessment.
- Lack of periodic review mechanisms to ensure all existing customers have an assigned and updated risk category.
Preventive Controls Recommended
- System Hard-Stops: Configure the onboarding platform to prevent the creation of a customer ID unless a risk categorization is assigned based on RBI parameters.
- Automated Risk Engine: Deploy a rules-based engine that automatically assigns a preliminary risk score based on demographic and transactional inputs during onboarding.
- Compliance Dashboards: Create real-time dashboards for the compliance team highlighting any accounts missing risk categorization or overdue for periodic KYC updates.
- Data Cleansing: Conduct a one-time exercise to identify and categorize all legacy accounts missing this critical metadata.
Lessons Learnt
KYC is not merely about document collection; it is fundamentally about risk assessment. Failing to categorize customer risk undermines the entire Anti-Money Laundering (AML) framework, as transaction monitoring thresholds cannot be effectively applied without it.
RBI Press Release
3. KLM Axiva Finvest Limited
Key Details
- Penalty Amount: ₹2.70 Lakh
- Date of Order: September 22, 2026
- Statutory Basis: Section 58-G(1)(b) read with Section 58-B(5)(aa) of the RBI Act, 1934
- Inspection Period: As on March 31, 2025
The Violation
Non-compliance with directions on ‘Auction’ procedure. The company failed to pay the surplus amount realised from the auction of pledged gold articles (over and above the outstanding loan) back to certain borrowers.
Root Cause Analysis (RCA)
- Process breakdown in the post-auction settlement phase, failing to identify and segregate surplus funds from the company’s general accounts.
- Lack of clear, automated workflows to trace the original borrower and initiate a refund of the surplus amount.
- Inadequate communication protocols to inform borrowers about the auction outcome and any resulting surplus.
- Possible weak oversight by the internal audit team regarding auction settlements and compliance with the Fair Practices Code for gold loans.
Preventive Controls Recommended
- Automated Escrow/Suspense Account: Configure the system to automatically route any auction realization exceeding the total dues (principal + interest + charges) into a designated suspense account meant strictly for customer refunds.
- Mandatory Refund Workflow: Establish a tracked workflow requiring branch managers or central operations to clear items from the suspense account by refunding the borrower within a strict, predefined SLA (e.g., 7-15 days).
- Enhanced Audit Scope: Mandate internal auditors to specifically sample auction records to verify the timely refund of surplus funds.
- Transparent Communication: Automate post-auction SMS/Email and physical letters to borrowers detailing the auction price, dues settled, and the surplus amount available for claim.
Lessons Learnt
In asset-backed lending, the lender’s right over the pledged asset is strictly limited to the recovery of dues. Retaining surplus from an auction is a severe breach of trust and regulatory guidelines. Robust post-auction accounting practices are essential to protect borrower interests.