RBI Penalty Report – 14th August 2026

1. IndusInd Bank Limited

Key Details

  • Date of Order: August 14, 2026
  • Penalty Amount: ₹59.20 Lakh
  • Statutory Basis: Section 47A(1)(c) read with Section 46(4)(i) of the Banking Regulation Act, 1949.
  • Violations: Non-compliance with RBI directions on ‘Interest Rate on Deposits’ and ‘Securitisation of Standard Assets’. Specifically:
    • Paying interest on deposits held in certain current accounts.
    • Undertaking activities in the nature of ‘Synthetic Securitisation’.

Root Cause Analysis (RCA)

The violations suggest potential gaps in the bank’s automated system controls regarding account types and interest calculation logic. The payment of interest on current accounts (which are generally non-interest bearing) indicates a failure in parameterization within the core banking system. The undertaking of ‘Synthetic Securitisation’ points towards a misinterpretation of complex structured finance regulations or a potential override of compliance checks during product structuring.

Preventive Controls

  • System Hardcoding: Implement strict, hardcoded logic in the Core Banking System (CBS) to unequivocally prevent interest accrual and payout on all current account product codes.
  • Enhanced Product Approval Process: Require mandatory, specialized compliance review for all structured finance products, specifically evaluating against securitisation guidelines before launch.
  • Automated Exception Reporting: Develop daily exception reports flagging any current account showing interest accrual for immediate investigation.

Lessons Learnt

Automated systems must be strictly aligned with regulatory definitions of account types. Furthermore, innovation in financial products (like securitisation) must be tightly coupled with rigorous, ongoing regulatory interpretation to prevent inadvertent breaches of complex directives.

RBI Press Release

2. Northern Arc Capital Limited

Key Details

  • Date of Order: August 14, 2026
  • Penalty Amount: ₹6.20 Lakh
  • Statutory Basis: Section 58G(1)(b) read with Section 58B(5)(aa) of the Reserve Bank of India Act, 1934.
  • Violations: Non-compliance with directions on ‘Disclosures in Financial Statements – Notes to Accounts’ and ‘Internal Ombudsman for Regulated Entities’. Specifically:
    • Incorrect and incomplete disclosure of customer complaints in FY 2024-25 Annual Financial Statements.
    • Failure to ensure auto-escalation of rejected/partly rejected complaints to the Internal Ombudsman.

Root Cause Analysis (RCA)

The failure in accurate financial disclosures suggests weaknesses in the data aggregation process between the customer service department and the finance department during audit preparation. The failure in auto-escalation indicates a direct flaw in the workflow configuration of the Customer Relationship Management (CRM) or Grievance Redressal system, likely lacking the necessary conditional logic to trigger escalation upon rejection.

Preventive Controls

  • System Workflow Configuration: Reconfigure the grievance redressal software to automatically mandate escalation to the Internal Ombudsman for any complaint marked with a status of ‘Rejected’ or ‘Partially Rejected’ before it can be closed.
  • Automated Disclosure Reconciliation: Implement a tool that automatically reconciles the complaint data from the CRM system with the figures drafted for the Notes to Accounts, requiring sign-off from both Customer Service and Finance heads.
  • Periodic System Audits: Conduct quarterly audits specifically testing the auto-escalation functionality of the grievance system.

Lessons Learnt

Transparency in reporting and robust grievance redressal are paramount. Manual reliance for escalations or data aggregation for regulatory disclosures is prone to error; these processes must be systematically automated and periodically tested for integrity.

RBI Press Release

3. Muthoot MCred Limited

Key Details

  • Date of Order: August 14, 2026
  • Penalty Amount: ₹3.10 Lakh
  • Statutory Basis: Section 58G(1)(b) read with Section 58B(5)(aa) of the Reserve Bank of India Act, 1934.
  • Violations: Non-compliance with directions on ‘Asset Classification’. specifically:
    • Upgrading ‘non-performing assets’ (NPAs) to ‘Standard’ without the complete repayment of all arrears of interest and principal across all credit facilities.

Root Cause Analysis (RCA)

This violation points to a significant flaw in the Loan Origination/Management System’s asset classification logic. The system either allowed manual override of NPA status without system-verified clearance of dues, or the automated logic evaluated accounts individually rather than aggregating a borrower’s total exposure (all credit facilities) before permitting an upgrade.

Preventive Controls

  • Systematic Upgrade Logic Revision: Modify the core loan management system to strictly automate NPA upgrades. The system must verify zero overdue balance across all linked accounts for a borrower before changing status to ‘Standard’.
  • Removal of Manual Overrides: Disable manual capabilities to change asset classification status for critical transitions (NPA to Standard) without high-level, documented exception approval.
  • Regular Asset Quality Reviews: Implement independent, periodic reviews of a sample of recently upgraded accounts to ensure systemic logic is functioning correctly.

Lessons Learnt

Asset classification must be treated holistically per borrower, not just per account. Automated systems must enforce the “all-or-nothing” rule for clearing arrears before an NPA upgrade, removing ambiguity and the potential for manual error in assessing a borrower’s true financial health.

RBI Press Release

4. Fusion Finance Limited

Key Details

  • Date of Order: August 14, 2026
  • Penalty Amount: ₹2.70 Lakh
  • Statutory Basis: Section 58G(1)(b) read with Section 58B(5)(aa) of the Reserve Bank of India Act, 1934.
  • Violations: Non-compliance with ‘Reserve Bank of India (Know Your Customer (KYC)) Directions’. Specifically:
    • Failure to implement a system for the periodic review of risk categorisation of accounts at least once every six months.

Root Cause Analysis (RCA)

The absence of periodic risk review suggests a lack of automated triggering mechanisms within the company’s KYC/AML compliance systems. The process was likely either non-existent or relied on ad-hoc manual scheduling, which failed to meet the strict six-month regulatory periodicity.

Preventive Controls

  • Automated Risk Review Triggers: Implement an automated module within the KYC system that flags accounts for mandatory risk categorisation review 30 days before the six-month deadline expires.
  • Account Restriction Logic: Introduce system logic that restricts certain account functionalities (e.g., limits on transactions) if the risk review is not completed by the stipulated deadline.
  • Compliance Dashboards: Deploy real-time dashboards for compliance officers showing upcoming, pending, and overdue risk categorisation reviews.

Lessons Learnt

KYC is an ongoing process, not a one-time event at onboarding. Financial institutions must leverage automation to manage the lifecycle of customer risk profiles, ensuring timely reviews to mitigate emerging money laundering or terrorist financing risks.

RBI Press Release

5. Jilla Sahakari Kendriya Bank Maryadit, Bhind, MP

Key Details

  • Date of Order: August 11, 2026 (Published Aug 13)
  • Penalty Amount: ₹2.50 Lakh
  • Statutory Basis: Section 47A(1)(c) read with Sections 46(4)(i) and 56 of the Banking Regulation Act, 1949.
  • Violations: Contravention of Section 26A read with Section 56 of the BR Act. Specifically:
    • Failure to transfer eligible unclaimed amounts to the Depositor Education and Awareness (DEA) Fund within the prescribed period.

Root Cause Analysis (RCA)

The failure to transfer funds to the DEA Fund indicates a breakdown in identifying dormant accounts that have crossed the 10-year threshold. This is likely due to inadequate tracking mechanisms within the core banking system or a failure in the manual process responsible for executing the transfer once accounts are identified.

Preventive Controls

  • Automated Identification and Alerting: Configure the CBS to automatically identify accounts approaching the 10-year inactivity mark and generate alerts for the operations team well in advance.
  • Streamlined Transfer Protocol: Establish a clear, documented Standard Operating Procedure (SOP) with designated responsibilities for the timely calculation and transfer of eligible funds to the RBI.
  • Reconciliation Checks: Implement monthly reconciliation between identified dormant accounts and actual transfers made to the DEA Fund to ensure no accounts are missed.

Lessons Learnt

Managing unclaimed deposits requires proactive tracking. Banks must rely on system-generated reports rather than manual reviews to ensure statutory timelines for transferring funds to the DEA Fund are strictly met.

RBI Press Release

6. Valuefin India Credit Services Private Limited

Key Details

  • Date of Order: August 11, 2026 (Published Aug 13)
  • Penalty Amount: ₹1.80 Lakh
  • Statutory Basis: Section 58G(1)(b) read with Section 58B(5)(aa) of the RBI Act, 1934.
  • Violations: Non-compliance with directions on ’Acquisition of Shareholding or Control’. Specifically:
    • Failure to obtain prior written permission from RBI for a change in shareholding exceeding 26% of paid-up equity capital.

Root Cause Analysis (RCA)

This violation stems from a governance failure, specifically within the company’s secretarial and legal departments. The required prior approval process was either overlooked during the transaction structuring or there was a misunderstanding of the regulatory thresholds that trigger mandatory RBI notification and consent.

Preventive Controls

  • Mandatory Regulatory Checklists: Institute a mandatory regulatory checklist for all corporate actions, specifically highlighting shareholding changes and control acquisitions, requiring sign-off from external legal counsel.
  • Board-Level Oversight: Ensure that any proposed capital raise or share transfer nearing the 20% mark triggers an immediate board review specifically focused on RBI compliance requirements.
  • Enhanced Secretarial Training: Provide regular training to the company secretary and legal team on the latest RBI master directions concerning NBFC governance and ownership changes.

Lessons Learnt

Significant changes in ownership structure are highly sensitive regulatory events. Prior approval is non-negotiable; seeking post-facto approval indicates a failure in corporate governance and invites regulatory action. Robust internal legal checks must precede any such transaction.

RBI Press Release

7. The Amravati District Central Co-operative Bank Ltd., Maharashtra

Key Details

  • Date of Order: August 6, 2026 (Published Aug 10)
  • Penalty Amount: ₹50,000
  • Statutory Basis: Section 47A(1)(c) read with Sections 46(4)(i) and 56 of the Banking Regulation Act, 1949.
  • Violations: Non-compliance with directions on ‘Know Your Customer (KYC)’ and ‘Ensuring Reasonableness of Bank Charges and Charges Levied for Sending SMS Alerts’. Specifically:
    • Allotting multiple customer identification codes to customers instead of a Unique Customer Identification Code (UCIC).
    • Levying SMS alert charges without actually sending SMS alerts to certain customers.

Root Cause Analysis (RCA)

The multiple UCIC issue indicates poor data de-duplication logic during customer onboarding or legacy data migration issues within the CBS. The erroneous SMS charges point to a disconnect between the billing module and the actual SMS gateway delivery logs; the system charged based on subscription rather than successful service delivery.

Preventive Controls

  • Systematic Deduplication Engine: Implement a robust de-duplication engine at the point of data entry (using parameters like PAN, Aadhaar, DOB, Name) to prevent the creation of new IDs for existing customers. Conduct a one-time clean-up of existing duplicate records.
  • Usage-Based Billing Integration: Link the charge-levying module directly to the SMS gateway logs. Charges should only be applied upon confirmation of successful SMS delivery, not merely on service activation.
  • Routine Data Integrity Checks: Run periodic scripts to identify potential duplicate customer profiles for manual review and merging.

Lessons Learnt

A single view of the customer (via UCIC) is fundamental for risk management and KYC compliance. Furthermore, customer charges must be fair, transparent, and directly correlated to the actual provision of services, requiring synchronized IT systems to ensure accuracy.

RBI Press Release

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top