Concentration Risk Management: Key Regulatory Changes Explained

Concentration Risk Management

Concentration risk management has moved from being a routine prudential check to one of the most actively regulated areas of Indian banking and NBFC supervision. Over the past year, the Reserve Bank of India has substantially reworked the rules governing how much exposure a lender can carry towards a single borrower, group, sector, or category of activity, and how that exposure must be defined, computed, and reported. For risk and compliance teams, keeping pace with these changes is no longer a periodic exercise but an ongoing requirement.

The scale of the overhaul is significant. Commercial banks now operate under a materially rewritten concentration risk framework, while NBFCs have seen their own directions amended more than once within a short span. Both sets of changes reflect a common regulatory intent, to bring more precision to how concentration is defined, to close gaps that allowed exposures to escape proper classification, and to align concentration norms more closely with related frameworks such as credit facilities and capital adequacy directions.

This blog walks through the key regulatory changes reshaping concentration risk management in 2026 and explains what they mean in practice for banks, NBFCs, and the professionals who manage credit and capital market exposure on their behalf.

The New Concentration Risk Management Framework for Commercial Banks

The Reserve Bank of India issued the Commercial Banks Concentration Risk Management Amendment Directions in February 2026, and followed this with a revised version in March 2026 that superseded the earlier amendment. Together, these changes represent one of the most detailed reworkings of capital market exposure rules in recent years.

At the centre of the revision is an expanded definition of Capital Market Exposure, commonly referred to as CME. The updated framework now brings a much wider set of direct and indirect exposures within its scope, including acquisition finance, bridge finance, credit extended to capital market intermediaries, underwriting commitments, exposure to non-debt mutual funds, and irrevocable payment commitments. This is a marked shift from a narrower, more restrictive treatment of share linked and capital market related lending that Indian banks operated under for years.

Revised Prudential Ceilings on Exposure

Alongside the expanded definition, the revised directions introduce specific prudential ceilings that banks must observe. Aggregate CME is now capped at 40 percent of a bank’s eligible capital base. Within this, direct investment exposure is separately capped at 20 percent, and acquisition finance exposure is capped at a further 20 percent, with both ceilings applying on solo and consolidated bases. These tiered limits give banks a defined boundary within which they can support activities such as corporate acquisitions and capital market financing, while still preserving overall concentration discipline.

The framework also sets out detailed computation norms, treatment of intraday exposures, permissible offsets, and specific exclusions for critical financial infrastructure entities, giving risk teams much more granular guidance than the earlier regime provided.

Alignment with the Credit Facilities Framework

One of the more structurally important aspects of the 2026 changes is the deliberate alignment between the concentration risk directions and the Reserve Bank’s revised Credit Facilities Directions. Key definitions such as acquisition finance, bridge finance, capital market intermediaries, collateral, and primary security have been imported directly from the credit facilities framework into the concentration risk rules. This is a meaningful shift for concentration risk management because it removes the possibility of a term being interpreted differently across two related regulatory frameworks, and it signals that the regulator now expects banks to treat concentration risk, credit risk, and capital adequacy as an integrated compliance exercise rather than three separate silos.

Changes to the NBFC Concentration Risk Framework

NBFCs have seen their own version of this recalibration. The Reserve Bank had already issued the Master Direction on Concentration Risk Management for NBFCs in late 2025, and this has since been amended more than once. One amendment revised the definition of infrastructure lending under the framework, while a further amendment reviewed the definition of Tier 1 capital being used for compliance with credit and investment concentration norms.

These NBFC specific changes matter because concentration ceilings are calculated as a percentage of capital, so any change to how that capital base is defined has a direct bearing on how much headroom an NBFC actually has for a single exposure. The amendment also requires an external auditor’s certificate on completion of capital augmentation for purposes of concentration norm compliance, adding a documentation and assurance layer that NBFC finance and risk teams need to build into their processes.

Why This Matters for Risk and Compliance Teams

For institutions, these changes carry implications well beyond a compliance checklist update. Concentration risk management now requires closer coordination between credit, treasury, capital planning, and compliance functions, since exposure classification, capital computation, and prudential ceilings are now tightly interlinked across multiple regulatory directions. Institutions need to revisit their exposure tracking systems to ensure that newly included categories, such as bridge finance or irrevocable payment commitments, are correctly captured and reported. Capital planning teams need to build the revised ceilings into stress testing and internal limit setting, rather than relying on legacy thresholds. Governance and audit functions need to prepare for closer scrutiny given the explicit mention of external auditor certification requirements for NBFCs.

Institutions that treat this only as a legal or compliance update, without updating internal systems, risk appetite statements, and reporting templates, are likely to find themselves out of step with supervisory expectations well before the next audit cycle.

Build This Capability with RMAI

Staying current with concentration risk management and its evolving regulatory landscape requires structured, up to date learning rather than one time reading of circulars. RMAI’s Online Certificate Course in Market Risk Management covers exposure measurement, stress testing, and capital charge implications that connect directly to how concentration limits are applied in practice.

For professionals responsible for building and maintaining exposure tracking and escalation processes, the Online Certificate Course in Mastering Risk Registers offers practical tools for centralising and monitoring concentration related exposures across an organisation.

To explore the full range of programmes covering credit, market, operational, and enterprise risk, visit RMAI’s complete suite of risk management courses or the risk management courses page for a programme matched to your team’s regulatory and functional needs.

Conclusion

Concentration risk management in India has entered a phase of significant regulatory recalibration, with commercial banks and NBFCs both operating under substantially revised frameworks within the same year. The expanded definition of capital market exposure, the introduction of tiered prudential ceilings, the deliberate alignment with credit facilities directions, and the changes to capital definitions for NBFCs collectively signal a regulator that wants concentration risk treated with far greater precision than before. Institutions that update their systems, governance structures, and staff capability in step with these changes will be far better placed to meet supervisory expectations and manage exposure concentration as a genuine risk discipline rather than a compliance formality.

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.