NBFCs operate under the RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices (the 'NBFC IT framework') and, where applicable, RBI's Digital Lending Guidelines and DLG framework. Digital Defense provides a single audit engagement covering all of it — including the additional layered supervisory framework applicable to upper-layer NBFCs.
Base, Middle, Upper and Top layer NBFCs
Digital lending NBFCs and their LSP / DLG partners
Microfinance NBFCs (NBFC-MFI)
Housing finance companies (HFCs) under NHB / RBI
Account aggregator (AA) and FIU entities
Repeated RBI inspection findings on IT governance, change and access management
Digital lending app inadequate consent + data-handling under RBI DLG
DLG partner due diligence inadequate; LSP onboarding controls weak
Recovery / collection workflows leaking PII (call recording, OCEN flow)
Loan-origination KYC bypass via mule / synthetic KYC paths
Mapping to the NBFC IT framework + supplementary RBI circulars (DLG, MFI, HFC).
Customer app, agent app, LMS, BRE, KYC, collection, partner integrations.
LSP onboarding, data-flow review, model-risk review, OCEN/AA integration assessment.
AWS/Azure/GCP misconfig review, IAM, secrets, CI/CD supply-chain integrity.
CERT-In Empanelled auditor signed report + RBI evidence matrix + remediation tracker.
RBI IT framework gap-assessment report
VAPT report covering customer/agent/LMS/collection flows
DLG partner risk-review report
Cloud security posture report
Auditor signed audit report + 90-day remediation tracker
Yes — including the additional risk-management, IT-governance and cybersecurity expectations that apply at upper-layer.
Yes. We assess LSP onboarding, data-handling, model risk, consent management, and the audit obligations under DLG including DLG partner due-diligence.
Yes — including the UIDAI AUA/KUA audit if you operate as an AUA/KUA.
We coordinate with your SaaS provider for evidence on their security; we audit the integration boundary, your KYC / consent / data-handling, and your incident response coverage.
Annual minimum under the RBI IT framework; quarterly VA expected; event-driven audits after major changes or incidents.
Talk to Digital Defense — India's CERT-In Empanelled cybersecurity team.
Book a consultationOnline | Typically replies instantly
Hi there! 👋 Welcome to Digital Defense. I'm here to help you with your cybersecurity needs. How can I assist you today?