On August 6, 2026, the Reserve Bank of India issued nine separate circulars in a single day, each amending the Responsible Business Conduct framework for a different category of regulated lender, from commercial banks and small finance banks to NBFCs and housing finance companies. Together, these circulars consolidate what had been scattered, entity specific instructions on loan recovery into a single, consistent standard that will apply across virtually every formal lender in India. The directions come into force on January 1, 2027, giving institutions roughly five months to rewrite policies, renegotiate agency contracts, and in some cases rebuild collections technology altogether.
For risk, compliance, and collections teams, this is not a routine circular update to file away. It touches recovery agent engagement, borrower contact conduct, call recording, device locking technology, and compensation obligations, all areas where gaps have historically translated into regulatory action, reputational damage, and borrower harm. This blog sets out what changed, who is covered, and what banks and NBFCs need to prioritise before the January 2027 deadline.
What RBI Actually Issued
The nine circulars cover commercial banks, small finance banks, local area banks, regional rural banks, urban co-operative banks, rural co-operative banks, all India financial institutions, NBFCs, and housing finance companies. Structurally, the RBI has replaced the earlier recovery related paragraphs in the Responsible Lending Conduct chapter of the 2025 Directions with a new, dedicated section on the conduct of lenders in recovery of loan dues and engagement of recovery agencies. Housing finance companies are now explicitly required to follow the same recovery standard that applies to NBFCs, which means banks, NBFCs, and HFCs are, for practical purposes, being held to one common recovery conduct benchmark.
A Wider Definition of Recovery Agency
One of the more consequential changes is a broadened definition of what counts as a recovery agency. The new framework defines a recovery agency as any entity or individual, other than the lender’s own employees, engaged under an outsourcing arrangement to assist in recovery of loan dues, regardless of the contractual label used for that engagement. This closes a long standing gap where entities performing recovery functions under a different designation, including business correspondents involved in recovery activities, could argue they fell outside the recovery agent framework. Under the revised rules, if the function performed is recovery, the obligations apply, irrespective of what the contract calls the role.
Borrower Contact Rules and Disclosure Requirements
The directions introduce clear, time bound obligations around how and when recovery contact can happen. Recovery calls and visits are permitted only between 8 am and 7 pm, with contact outside these hours allowed only where the borrower or guarantor has expressly requested or authorised it. Before a recovery agency makes its first in-person visit, the lender must inform the borrower of the agency’s details at least one day in advance, and any change of agency or termination of an agency’s engagement must be communicated to affected borrowers immediately.
Lenders are also required to publish and maintain an up to date list of empanelled recovery agencies on their website, including each agency’s name, type, correspondence address, and period of engagement, updated within seven calendar days of any change. Agents visiting a borrower must carry identification, an authorisation letter, and a copy of the prior intimation notice, all of which must display the grievance redressal officer’s contact details.
Harsh Practices Are Explicitly Defined and Prohibited
The revised framework lists specific practices that are now deemed harsh and prohibited outright, including abusive language, use of social media to post a borrower’s personal details or recordings, excessive calling outside permitted hours, threatening or anonymous calls, and intimidation of a borrower’s relatives, referees, or co-workers. This last point is significant, since contacting a defaulter’s employer or extended family as leverage has been a common collections tactic in the past and is now expressly barred.
Recovery targets and incentive structures for staff and agents must also be designed so that they do not induce harsh practices, which brings a lender’s internal compensation design directly within the regulatory perimeter.
Call Recording and Data Handling Requirements
Lenders must document the time and number of recovery calls and record their content, including calls a borrower makes back to a number the lender has provided, with these records preserved for six months. Borrowers must be informed that calls are being recorded. Separately, borrower information shared with employees and recovery agencies must be limited strictly to what is necessary for the recovery task, with penal consequences for misuse.
New Rules on Device Locking Technology
Perhaps the most novel part of the framework addresses technology based device restriction, a practice some digital lenders have used to pressure defaulting borrowers by locking their phones. The default position under the new directions is a prohibition on using device locking as a recovery tool. The narrow exception applies only where the device itself was financed through the loan in question, and even then, four conditions must all be met, including an express contractual clause, prior notice with a clear restriction timeline, a requirement that full restrictions apply only after the loan is 60 days past due, and certification by the device manufacturer or operating system platform where available.
Where permitted, restrictions must be applied gradually, must never block incoming calls, SMS, or emergency services, and must be reversed within one hour of dues being cleared. Where a lender wrongly restricts a device or delays unlocking it, the borrower is entitled to compensation of 250 rupees per hour, capped at the disbursed loan amount. Access to personal data on a borrower’s device, including contacts, messages, and location history, is prohibited for recovery purposes under any circumstances.
Compensation as a Mandatory Policy Element
A structural shift in this framework is that compensation to borrowers and guarantors for losses arising from non-compliant recovery action is now a mandatory element of a lender’s recovery policy, rather than a discretionary gesture. Combined with the specific device locking compensation provision, this gives borrowers a clearer, more enforceable complaint pathway than existed under the earlier rules.
What Banks and NBFCs Must Do Before January 2027
Institutions have a defined but limited window to bring their recovery function into compliance. Key priorities include drafting or updating a board approved recovery policy that incorporates the mandatory compensation provisions and a structured framework for borrowers in financial distress. Recovery agency contracts need to be rewritten to embed the new code of conduct obligations, and the definition change means agreements with business correspondents or similarly labelled partners performing recovery functions need review as well. Institutions need to build and maintain the website disclosure list of empanelled agencies on a seven day update cycle, put call recording and six month retention systems in place, and verify that recovery agents hold the required training and certification. Incentive and target structures for recovery staff and agencies need to be reviewed to ensure they do not inadvertently encourage harsh practices. Any institution using device locking technology outside financed device transactions needs to stop that practice altogether, while those relying on the narrow exception need to rebuild their systems against all four qualifying conditions, including the one hour reversal requirement.
Conclusion
RBI’s August 2026 loan recovery directions represent a substantial tightening of how banks, NBFCs, and housing finance companies are expected to conduct recovery, moving from scattered, entity specific rules to one consistent, more borrower protective standard. The broadened definition of recovery agency, the explicit list of prohibited harsh practices, the near total ban on device locking, and the mandatory compensation obligations together signal that RBI expects recovery to be treated as a governed, auditable process rather than an operational afterthought. With January 1, 2027 less than five months away, institutions that begin policy, contract, and technology review now will be far better positioned than those that wait for the deadline to approach.
Build This Capability with RMAI
Preparing for a regulatory shift of this scale requires risk and compliance teams to move quickly from understanding the rules to embedding them operationally. RMAI’s Online Certificate Course on Governance, Risk and Compliance (GRC) helps professionals translate regulatory change of this kind into board level policy and oversight structures.
For teams responsible for managing the credit and collections lifecycle, the Online Certificate Course in Credit Risk Management builds a stronger foundation in exposure and default management practices that connect directly to recovery process design.
Since the internal controls around call recording, data handling, and agency oversight fall squarely within operational risk, the Online Certificate Course in Operational Risk Management equips professionals to build the audit ready processes this framework now requires.
Given the new device locking rules and the data handling restrictions tied to borrower devices, the Online Course on Cyber Security and Technology Risk Management in Banking helps teams assess the technology risk dimension of recovery operations.
And because harsh recovery practices carry direct fraud and misconduct risk implications, the Online Certificate Course in Fraud Risk Management rounds out the skill set needed to build a compliant, well governed recovery function.
To explore the full range of programmes covering credit, operational, compliance, and enterprise risk, visit RMAI’s complete suite of risk management courses or the risk management courses page for a programme matched to your team’s needs.