Paytm Payments Bank Case Study: RBI Action and Closure

Paytm Payments Bank Case Study

The regulatory action against Paytm Payments Bank Limited, or PPBL, developed over several years rather than arising from one isolated violation. In March 2022, the Reserve Bank of India directed the bank to stop onboarding new customers after identifying material supervisory concerns. A subsequent regulatory penalty in October 2023 documented deficiencies involving customer identification, transaction monitoring, payments-bank restrictions and cybersecurity reporting.

On 31 January 2024, following a comprehensive system audit and compliance-validation report, RBI imposed extensive business restrictions because of what it described as persistent non-compliance and continuing material supervisory concerns. Customers could withdraw or use existing balances, but fresh deposits and most credits were prohibited after 15 March 2024.

The regulatory process culminated on 24 April 2026, when RBI cancelled PPBL’s banking licence. RBI stated that the bank’s affairs and the general character of its management were prejudicial to the interests of the bank, its depositors and the public. The Delhi High Court subsequently ordered the bank’s winding up in July 2026.

The case demonstrates that fintech innovation does not reduce the importance of KYC, transaction monitoring, technology governance, regulatory remediation and board accountability. It also shows why regulated banks and their connected technology platforms must maintain clear legal, operational and customer-facing separation. RMAI’s article on the perils of ignoring operational risk examines this same RBI-PPBL episode in detail and is a useful companion read for the analysis that follows.

Background: the payments-bank model

Payments banks were introduced to expand financial inclusion through small deposits, digital payments and remittance services. Unlike conventional commercial banks, they cannot undertake lending from their own balance sheets. Their operating model therefore depends heavily on payment volumes, customer scale, technology, partnerships and fee-based services.

PPBL operated savings and current accounts, digital wallets, FASTags, National Common Mobility Cards and payment services within the broader Paytm ecosystem. This close customer-facing association created convenience, but it also created significant governance requirements.

Customers might perceive “Paytm” as one unified service even though Paytm Payments Bank Limited and the listed technology company One97 Communications Limited were legally separate entities. Accordingly, the organisations needed effective controls governing:

Allocation of regulated and non-regulated activities; Customer consent and KYC responsibility; Flow of money between entities; Nodal and settlement accounts; Data access and information sharing; Outsourcing and related-party arrangements; Regulatory reporting; and Crisis communication.

In a highly integrated digital ecosystem, weakness in one regulated entity can affect customer confidence in the wider brand. Many of these process and control weaknesses fall within the operational risk discipline; RMAI’s Operational Risk Management article sets out how institutions identify, assess and monitor exactly this kind of process breakdown.

Escalation of regulatory action

New-customer onboarding stopped

On 11 March 2022, RBI directed PPBL to stop onboarding new customers with immediate effect under Section 35A of the Banking Regulation Act, 1949. RBI referred to material supervisory concerns and required the bank to appoint an information-technology audit firm for a comprehensive system audit.

The restriction was not merely an administrative pause. It indicated that the regulator required verified remediation before permitting further customer growth.

₹5.39 crore regulatory penalty

In October 2023, RBI imposed a monetary penalty of ₹5.39 crore following special scrutiny and a comprehensive system audit. The documented deficiencies included PPBL’s failure to:

Identify beneficial owners for entities receiving payout services; Monitor payout transactions and conduct risk profiling; Breach-check the regulatory ceiling applicable to end-of-day customer balances; Report a cybersecurity incident within the required period; and Implement certain device-binding controls associated with mobile-banking access.

RBI clarified that the penalty concerned regulatory-compliance deficiencies and did not invalidate individual customer transactions. One97 Communications’ filing reproducing RBI’s October 2023 order.

Restrictions on deposits and payment services

On 31 January 2024, RBI announced further action after the comprehensive system audit and the external auditors’ compliance-validation report revealed persistent non-compliance and continuing supervisory concerns.

After an extension intended to give customers and merchants more time to make alternative arrangements, the principal restrictions became effective after 15 March 2024. PPBL could no longer accept fresh deposits, credits or top-ups in customer accounts, wallets, FASTags and National Common Mobility Cards, except for permitted items such as interest, refunds, cashbacks and specified sweep-ins.

Customers could continue withdrawing or using existing balances. However, salaries, subsidies and ordinary transfers could no longer be credited to PPBL accounts. FASTags and mobility cards could be used only until their existing balances were exhausted.

The nodal accounts of One97 Communications and Paytm Payments Services maintained with PPBL were required to be terminated, while pipeline transactions had to be settled within the prescribed period. RBI published a detailed customer FAQ explaining the practical consequences for account holders, wallet users and merchants. RBI’s PPBL customer FAQs.

Verified timeline

Date Development
11 March 2022 RBI stopped PPBL from onboarding new customers and required a comprehensive system audit.
10 October 2023 RBI imposed a ₹5.39 crore monetary penalty.
31 January 2024 RBI announced extensive restrictions following persistent non-compliance and supervisory concerns.
16 February 2024 RBI extended the principal customer-transition deadline to 15 March 2024.
26 February 2024 Vijay Shekhar Sharma resigned from PPBL’s board, and the bank announced board reconstitution.
March 2024 One97 discontinued major business arrangements with PPBL and shifted services to other banking partners.
24 April 2026 RBI cancelled PPBL’s banking licence with immediate effect from close of business.
25 April 2026 PPBL’s board and shareholders approved resolutions enabling its winding up.
July 2026 Delhi High Court ordered PPBL’s winding up and appointed an official liquidator.

Licence cancellation and winding up

On 24 April 2026, RBI cancelled PPBL’s banking licence under Section 22(4) of the Banking Regulation Act. The bank was prohibited from conducting banking business from the close of business that day.

RBI provided four principal grounds:

The bank’s affairs had been conducted in a manner detrimental to the interests of the bank and its depositors. The general character of its management was prejudicial to depositor and public interests. No useful purpose or public interest would be served by permitting the bank to continue. The bank had failed to comply with conditions attached to its payments-bank licence.

RBI also stated that PPBL had sufficient liquidity to repay its entire deposit liability. This is an important distinction: the licence was cancelled on regulatory, governance and public-interest grounds, not because RBI said that the bank lacked the liquidity to repay depositors. RBI’s licence-cancellation announcement.

On 25 April 2026, PPBL’s board and shareholders approved resolutions to enable winding up, subject to the required regulatory and legal proceedings. One97’s winding-up disclosure.

In July 2026, the Delhi High Court ordered the winding up of PPBL and appointed an official liquidator. The order converted the earlier regulatory decision into a formal closure process. Reuters’ report on the Delhi High Court order.

Distinguishing PPBL from the Paytm platform

The case must distinguish Paytm Payments Bank from One97 Communications and its continuing services.

One97 disclosed that it had discontinued major business arrangements with PPBL, withdrawn its nominee director and transitioned its UPI operations to a multi-bank third-party application provider model. Following the licence cancellation, One97 stated that Paytm UPI, QR, Soundbox, card machines, payment gateway and other services would continue because they were no longer dependent on PPBL.

It also reported that its investment in PPBL had already been fully impaired by 31 March 2024. One97’s April 2026 clarification.

Therefore, the correct formulation is not that “Paytm was shut down.” PPBL lost its banking licence and entered winding up; the wider Paytm platform continued through other regulated banking partners.

Risk and control-failure analysis

1. KYC and customer-due-diligence risk

Digital onboarding enables rapid scale, but it must still establish the customer’s identity, beneficial ownership and risk profile. Customer acquisition cannot be treated as complete merely because identity documents have been collected electronically.

A regulated entity must determine who ultimately owns or controls an institutional customer, understand the expected purpose of the account and apply enhanced due diligence where risk is higher. RMAI’s KYC and AML risk-management guide sets out the risk-based onboarding, beneficial-ownership checks and continuous monitoring practices that this section describes.

2. Transaction-monitoring risk

RBI’s penalty identified deficiencies in monitoring payout transactions and risk profiling. This illustrates the difference between onboarding compliance and lifecycle compliance.

Transaction-monitoring systems should identify unusual volumes, rapid movement of funds, multiple related accounts, inconsistent customer behaviour and activities outside the declared account purpose. Alerts must be investigated rather than closed mechanically.

3. Regulatory-remediation risk

The progression from a customer-onboarding restriction to a penalty, severe business restrictions and eventual licence cancellation suggests that regulatory remediation must be treated as an enterprise-level programme.

Every supervisory finding should have:

A named senior owner; A board-approved deadline; A documented root-cause analysis; Independent testing; Evidence supporting closure; and Formal challenge from compliance and internal audit.

Closing an action in an internal tracker is not equivalent to proving sustainable compliance.

4. Technology and cybersecurity risk

A payments bank depends on always-available mobile infrastructure, secure device registration, access controls and timely incident reporting. Cybersecurity-reporting delays are particularly significant because they may prevent regulators and management from assessing customer impact quickly.

Technology teams should not decide alone whether an incident is reportable. Compliance, information security, legal and senior management must participate in a predefined escalation process. RMAI’s Cybersecurity-risk article on top cyber risk failures in banking examines how weak governance and oversight gaps, rather than technology alone, tend to drive these failures.

5. Governance and ecosystem risk

When a bank is embedded within a larger technology platform, boards must examine whether commercial objectives can influence regulated activities. Related-party arrangements, data flows, brand use, customer communication and service dependencies require independent oversight.

Legal separation is necessary, but operational separation must also be demonstrable. RMAI’s banking corporate-governance case study on NPA management and stressed asset governance illustrates a comparable escalation and governance discipline applied within a regulated banking institution, and is a useful companion read for this analysis.

6. Conduct and customer-communication risk

The 2024 restrictions affected salary credits, subsidies, wallet top-ups, FASTags, mobility cards and merchant collections. Customers needed accurate information about what remained available and what required migration.

The broader risk lesson is that regulatory crisis plans must include product-level customer mapping, alternative arrangements, refund procedures and communications in language customers can understand.

Lessons for boards and risk professionals

The PPBL case provides six important lessons:

Compliance capacity must grow before customer and transaction volumes expand. Repeated supervisory findings should be reported to the board as strategic threats, not routine compliance items. Remediation should remain open until its effectiveness has been independently demonstrated. KYC must cover beneficial ownership, risk classification and continuing transaction monitoring. Regulated entities within technology groups require demonstrable governance and operational independence. Exit and migration plans are essential where millions of customers depend on digital financial products.

Professionals looking to build this kind of cross-functional governance, risk and compliance capability can explore RMAI’s Governance, Risk & Compliance Certificate Course, which covers the regulatory frameworks and practical tools referenced throughout this analysis.

Practical compliance checklist

Does the board receive an ageing report for all open regulatory findings? Are repeated findings automatically escalated to the risk and audit committees? Can every customer and beneficial owner be identified from current records? Are transaction-monitoring scenarios periodically reviewed against emerging risks? Are balance limits and product restrictions enforced automatically? Are cybersecurity incidents escalated and reported within prescribed timelines? Are related-party and group-service arrangements independently reviewed? Can the institution operate critical services if a group entity or banking partner becomes unavailable? Does an independent function validate remediation before closure? Is there a tested customer-migration plan for severe regulatory restrictions?

Key takeaways

The Paytm Payments Bank case was not a sudden regulatory intervention. It was an escalation from supervisory concern to onboarding restrictions, monetary penalty, severe operating restrictions, licence cancellation and winding up.

Its most important lesson is that regulatory trust depends on sustained evidence. Strong technology, a recognisable brand and extensive customer reach cannot compensate for weaknesses in KYC, transaction monitoring, cybersecurity reporting, licence compliance or governance.

The case also shows the importance of precision in crisis communication. Paytm Payments Bank entered winding up, but the broader Paytm platform continued through other banking partners. For boards and risk professionals, the priority is to identify such dependencies before a crisis and build governance, remediation and customer-protection controls capable of surviving regulatory scrutiny.

Risk professionals who want ongoing access to case studies like this one, regulatory updates and peer discussion can learn more through RMAI Membership.

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.