Advertisement
Advertisement
Skip to content
Follow Us on
Advertisement
TOP STORIES
Fema / RBI

Six Orders in Ten Days: What RBI’s July 2026 NBFC Penalties Actually Test

Advertisement

Summary: This is a Regulatory Update analysing six Reserve Bank of India monetary penalty orders issued between 10 and 17 July 2026 against six NBFCs following statutory inspections based on their financial position as on 31 March 2025. The penalties, ranging from Rs. 2.70 lakh to Rs. 6.20 lakh, related to regulatory compliance and, as stated in each order, did not affect the validity of customer transactions or agreements. The findings covered four recurring areas: KYC risk categorisation, asset classification, governance, and concentration risk. Muthoot Finance and Muthoot Vehicle & Asset Finance were penalised for not carrying out six-monthly customer risk categorisation reviews, with Muthoot Finance also cited for inadequate suspicious-transaction monitoring software. Satya MicroCapital and Dhani Loans and Services were penalised for certain accounts not being classified as NPAs, including restructured accounts in Satya MicroCapital’s case. Avail Financial Services was penalised for governance and single-party exposure issues, while PAN Emami Cosmed was penalised for exceeding prescribed credit exposure limits to a single group of parties. The article also outlines audit checks corresponding to these findings and notes that the six orders represent a sample of publicly penalised compliance gaps rather than a complete picture of supervisory findings.

Introduction: Between 10 and 17 July 2026, the Reserve Bank of India imposed monetary penalties on six NBFCs, ranging from Rs. 2.70 lakh to Rs. 6.20 lakh. None of the amounts made headlines on their own – these are the kind of orders that get a single paragraph in a roundup and are forgotten by the next news cycle. But read together, the six orders line up almost exactly against the four areas an internal auditor is expected to test in any NBFC engagement: KYC risk categorisation, asset classification, governance, and concentration risk. That is worth pausing on, because it means these orders are less a list of scandals and more a diagnostic – a free, RBI-authored account of where control gaps actually occur in practice, as opposed to where an audit programme assumes they might.

The Six Orders

All six penalties followed statutory inspections referenced to each company’s financial position as on 31 March 2025, and in each case RBI issued a show-cause notice, considered the company’s reply, and clarified that the penalty relates only to regulatory compliance and does not affect the validity of any transaction or agreement with customers – the standard language RBI attaches to every such order.

Entity Penalty Order dated Finding
Avail Financial Services Rs. 6.20 lakh 10 Jul 2026 MD held directorships in two other Middle Layer NBFCs; single-party exposure limit exceeded
Muthoot Finance Rs. 5.80 lakh 10 Jul 2026 No six-monthly review of customer risk categorisation; inadequate software for suspicious-transaction monitoring
Muthoot Vehicle & Asset Finance Rs. 2.70 lakh 13 Jul 2026 Six-monthly customer risk-categorisation review not carried out
Satya MicroCapital Rs. 3.10 lakh 13 Jul 2026 Certain restructured accounts not classified as NPA
PAN Emami Cosmed (formerly Midkot Investments) Rs. 3.10 lakh 13 Jul 2026 Credit exposure to a single group of parties exceeded the prescribed limit
Dhani Loans and Services Rs. 2.70 lakh 15 Jul 2026 Certain accounts not classified as NPA

The Pattern Behind the Six

Group the findings by subject and a four-way split appears. Two orders – Muthoot Finance and Muthoot Vehicle & Asset Finance, both group entities – turn on the same gap: risk categorisation of customer accounts not reviewed at the mandated six-month interval under the KYC Directions. Two more – Satya MicroCapital and Dhani Loans and Services – turn on the same gap from the other end of the KYC/IRAC relationship: accounts that should have moved to NPA and did not – in Satya’s case, specifically accounts that had been restructured. The remaining two – Avail Financial Services and PAN Emami Cosmed – are concentration and governance findings: exposure to a single party or a single group beyond the prescribed limit, and, in Avail’s case, a Managing Director holding directorships in two other Middle Layer NBFCs at the same time.

None of these are exotic failures. They are the four tests that sit on page one of any NBFC internal audit programme: periodic KYC re-categorisation, NPA/IRAC classification discipline, single-party and group exposure limits, and key managerial personnel conflict checks. What the July batch shows is that these ordinary tests are exactly where established, well-capitalised NBFCs – not just small or distressed ones – are still failing. Muthoot Finance is one of the largest gold-loan NBFCs in the country; the size of the entity did not prevent the gap.

A Checklist Drawn From the Six Orders

  • KYC risk re-categorisation: confirm, with dated evidence, that every customer account was re-assessed for risk category at the RBI-mandated six-month interval – not just that a policy document says it should be. Two of six orders turned on this exact gap.
  • NPA and restructured-account classification: test restructured accounts as a separate population from the general IRAC review. One of the two classification failures in this batch (Satya MicroCapital) specifically involved accounts that had been restructured – precisely the point where reclassification is easiest to defer; the other (Dhani) was a general classification lapse not specified as restructuring-related in RBI’s order.
  • Single-party and single-group exposure: recompute exposure limits independently rather than relying on the company’s own MIS figure, and specifically check group-level aggregation, not just single-borrower exposure – PAN Emami Cosmed’s finding was exposure to a single group of parties, not one obvious borrower.
  • KMP directorship conflicts: verify, from each director’s DIN filings rather than from company records alone, whether an MD or director also sits on the board of another Middle Layer or Upper Layer NBFC. This is a five-minute MCA check that Avail’s own governance review evidently missed.
  • Suspicious-transaction monitoring software: don’t just confirm that AML/transaction-monitoring software exists – test whether it flags the scenarios it is supposed to. Muthoot Finance’s finding was inadequate software, not absent software.

What the Pattern Doesn’t Tell You

It’s worth being honest about the limits of reading tea leaves from six orders. RBI publishes penalties, not the full population of what its inspections turn up – many findings are resolved through supervisory letters or corrective action plans without a public order. Six orders in ten days is a sample of what became severe enough, or persistent enough, to reach a penalty, not a ranked list of the sector’s most common gaps. A control area absent from this batch – say, Fair Practices Code disclosures, or digital lending KFS compliance – is not thereby validated as low-risk; it simply didn’t produce a penalty this fortnight. Treat this batch as confirmation that four specific tests deserve attention, not as a complete substitute for the rest of the audit programme.

The six orders share one more thing worth noting for a CA’s own signing practice: RBI’s press language in each case is careful and narrow – a specific control that was missing or a specific limit that was breached, stated once, without embellishment. It is, in its own dry way, a model of how a finding should be written: precise enough to be independently verified, narrow enough not to overreach. An internal audit observation that borrows that discipline – stating exactly what evidence was reviewed and exactly what gap that evidence disclosed – travels better through a client’s audit committee than one dressed up with adjectives.

******

The author is a practising Chartered Accountant advising clients on internal audit, regulatory, and tax matters. Views are personal.

Advertisement

Author Info

Kartik Sharma FCA
Qualification: CA in Practice
Company: Saxena Singhal & Vaid
Location: Delhi, Delhi
Articles Published: 3

Join TaxGuru's Network for the latest updates on Income Tax, GST, Company Law, Corporate Laws and other related subjects.

Leave a Reply

Your email address will not be published. Required fields are marked *