The problem with "licence or no licence"
Right now, most financial activity in India sits on either side of a hard line. Either an entity holds a full-fledged licence — a bank licence, an NBFC certificate, a payment aggregator authorisation — or it doesn't, and operates through partnerships and workarounds instead. There is very little in between. A small lending app that processes a few hundred loans a month is bound by nearly the same compliance load as one processing lakhs. A new-age wealth platform testing an idea with a few thousand users faces the same registration hurdles as an established asset manager.
This "zero-or-one" structure sounds fair on paper — same rules for everyone, no special favours. In practice, it does something less obvious: it pushes smaller, genuinely useful fintechs to either avoid regulation altogether by staying tiny and informal, or to attach themselves to a licensed partner bank/NBFC and let that partner carry all the compliance weight. You, the customer, end up dealing with an app whose actual regulatory status is unclear — is it lending its own money, or just running the interface for someone else's balance sheet?
What a "phased" licence would actually look like
The idea being floated is fairly simple: instead of one licence tier, create several, calibrated by scale, risk and the kind of activity involved. Think of it like a learner's licence progressing to a full driving licence, rather than being handed the keys to a truck on day one. A phased fintech licensing regime could look something like this:
- A sandbox or "test" tier with a capped number of users and lower capital requirements, meant purely for piloting a product.
- A limited-operations tier once a fintech crosses a certain user base or loan book size, with proportionately higher disclosure and capital norms.
- A full-scale tier — closer to today's NBFC or payment licence — once the entity reaches systemic scale and needs to be treated like any large financial player.
This kind of graded system already exists in bits and pieces elsewhere in Indian finance — mutual fund AMC categories, NBFC layers (base, middle, upper), even payment bank restrictions. Extending a similar logic to fintech licensing isn't a radical idea; it's catching up with how the sector already works informally.
Why this matters more to you than it sounds
It's tempting to file this under "industry structure, not my problem." But the licensing tier an app operates under quietly shapes several things you experience directly:
- Who you can complain to. A fully licensed NBFC has a defined grievance redressal officer and falls under the RBI Ombudsman scheme. An unlicensed app operating purely as a "technology partner" may leave you bouncing between the app's support chat and a bank's call centre.
- How your data is used. Licensing tiers usually come with matching data-governance obligations — what can be shared with third parties, how long records are kept, consent requirements for pulling your bank statements or credit bureau data.
- What happens if the app shuts down. A properly licensed entity has capital adequacy and exit norms. A loosely regulated one might simply disappear, leaving loan records, KYC documents, or wallet balances in a grey zone.
- Pricing and interest rates. Licensed NBFCs have RBI-mandated fair practice codes on interest rates and recovery methods. Partnerships without clear licensing sometimes blur who is actually setting your loan's interest rate and penalty structure.
A phased system, if designed well, doesn't just make life easier for fintech founders raising funding — it should make the regulatory status of any app you download more legible. In theory, a "Tier 2 lending fintech" badge would tell you more about what protections apply than the current situation, where you often can't tell at all.
The risk: graded doesn't mean loose
The obvious worry with any phased approach is regulatory arbitrage — fintechs deliberately staying just under a threshold to avoid stricter scrutiny, the way some businesses stay under turnover limits to dodge GST registration or audit requirements. A well-designed tiered system needs automatic, hard triggers: cross a certain loan book size or user count, and the higher compliance bar kicks in immediately, with no room to game the numbers through subsidiaries or shell structures.
There's also a sequencing risk. If lower tiers get real regulatory legitimacy — the ability to badge themselves as "RBI-recognised" in marketing — before the underlying supervision is actually built out, you could end up with apps that look more credible than they are. Comfort in labelling only works if enforcement keeps pace.
What to actually check as a user, right now
Until any phased framework is formally in place, the burden of figuring out who you're really dealing with still falls on you. A few habits help regardless of what licensing structure eventually emerges:
- Before taking a loan from any app, check the loan agreement for the name of the actual lender — it's often a partner NBFC or bank, not the app brand you see on your phone screen.
- Look up that lender's name on the RBI's list of registered NBFCs or banks. If you can't find it, treat that as a red flag, not a technicality.
- Read the data-sharing consent screen before you tap "Allow." Note which third parties can access your financial data and for how long.
- Save the grievance redressal contact mentioned in the loan agreement or app terms — you'll need it far more than customer support chat if something goes wrong.
A phased licensing regime, if it arrives, will change the plumbing of how fintech is regulated in India. But plumbing changes don't help you unless you know how to read the pipes — and for now, that still means doing the basic checks yourself before you click "Apply Now."




