top of page

Legal issues in fintech partner onboarding

  • Aug 6
  • 8 min read

Introduction : The expansion of fintech has revolutionized the financial services industry by allowing financial institutions, including banks and Non-Banking Financial Companies (NBFCs) to engage with technology companies to provide digital payments, lending, embedded finance, and other financial innovations. While such alliances promote innovation and enhance the customer experience, they also bring in legal, regulatory, and operational challenges. As regulated entities have continued to be responsible for ensuring compliance despite outsourcing of services, fintech partner onboarding has evolved beyond a mere business transaction to its becoming a key element in risk management.


Before starting operations, financial institutions must evaluate the regulatory compliance, governance measures, cybersecurity measures, data protection protocols, financial stability, and contractual agreements of a fintech partner for effective onboarding. The aspects of Know Your Customer (KYC) compliance, outsourcing, data sharing, liability issues, and consumer protection, in particular, need special attention. In this article, the authors focus on the legal landscape for fintech partnerships in India, explore the key risks from a regulatory and Contractual perspective when onboarding a partner, and identify the major legal considerations that need to be addressed prior to any fintech partnership. 


Legal Framework


There is a well-established legal and regulatory framework in India that regulates fintech partnerships, including banking regulations, payment system laws, data protection laws, anti-money laundering laws, and contractual laws. Fintech companies are not regulated financial institutions and hence, regulatory compliance is mostly the responsibility of the partnering bank/Non-Banking Financial Company (NBFC). As a result, financial institutions need to make sure fintech partners adhere to all relevant legal requirements throughout the entire partnership.


The Reserve Bank of India (RBI) is the primary regulator of banks, NBFCs, payment system operators and other regulated entities under the Reserve Bank of India Act, 1934, the Banking Regulation Act, 1949, and the Payment and Settlement Systems Act, 2007. In spite of these technology-driven solutions being offered by fintech companies, regulated entities are responsible for their operational resilience, RBI directions, and customer protection.


One of the critical regulatory guidelines while partner onboarding is the RBI Master Direction – Know Your Customer (KYC), 2016 as amended. The Master Direction places a strong emphasis on the need for regulated entities to implement proper customer identification, Customer Due Diligence (CDD) and Anti-Money Laundering (AML) processes. Regardless of the banks or NBFCs outsourcing the function to fintech partners, they will be held accountable for compliance with the KYC requirements, suspicious transactions monitoring and record-keeping.


The financial institutions are also obliged to implement risk - based AML measures, confirm the identity of their customer, keep the prescribed records and report on suspicious transactions as required by the Prevention of Money Laundering Act, 2002 (PMLA) to the Financial Intelligence Unit - India (FIU-IND). Hence, fintech partners with responsibility for customer onboarding or payment processing need to have systems in place that can assist them with these statutory obligations.


With the enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act), data governance has become a prominent feature. When organizations join through fintech, they often have access to personal and financial data, which can be sensitive. For this reason, institutions need to have proper lawful processing, valid consent (where necessary), appropriate technical and organisational security measures and make the responsibilities for processing data clear through contractual provisions.


Legal Analysis


The KYC and Customer Due Diligence (CDD) risks are managed. There is risk management of KYC and Customer Due Diligence (CDD).


Among the biggest legal hurdles in the fintech partner onboarding process is ensuring compliance with Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements. A number of fintech companies are involved in customer acquisition, Digital onboarding, e-KYC, document verification or transaction facilitation. These functions could be contractually delegated, but the responsibility still lies with the partnering bank or NBFC. This means the financial sector will not be able to simply accept the word of their fintech partners and will have to independently determine the compliance of their partners' onboarding process with the RBI's.


Financial institutions should hence put in place continuous monitoring mechanisms instead of due diligence just at the time of onboarding. Through regular compliance audits, periodic reporting requirements, employee training, and contractual provisions for regulatory inspections, banks and NBFCs can be assured of ongoing compliance with changing laws by fintech partners during the course of a partnership. This continued monitoring indicates the RBI's consistent stance that outsourcing the operational aspects does not affect the duties of the supervised entities.


The challenges of Sharing and Privacy Risks


Where fintech firms are either onboarding customers or facilitating payment transactions, credit assessment, fraud checks and/or analytics tools, data sharing is a key aspect of most fintech partnerships. Data protection is one of the most important legal issues to address when a partner is brought on board, with lots of personal and financial information being collected, processed, stored and transferred in these activities.


The Digital Personal Data Protection Act, 2023 (DPDP Act) is the law that was passed to regulate the processing of digital personal data in India. The Act requires organisations to ensure that the processing is lawful, transparent and is only for limited purposes, in accordance with the conditions for which a valid consent has been granted, or the other conditions for lawful processing. For banks and NBFCs joining a fintech partnership, it is therefore crucial to ensure their partners have the right data governance policies, security protocols, consent management systems and processes in place to respond to data principal requests.


The outsourcing industry and Third Party Risk Management


For banks and NBFCs, the RBI's Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services have mandated the banks to undertake in-depth due diligence before outsourcing the material functions. Institutions need to evaluate the financial strength, structure of governance, technical competence, cybersecurity protections, disaster recovery plans, and the business continuity program of the fintech partner, and check its track record of regulatory compliance.


Regulated entities should not outsource any strategic decision-making, internal audit or regulatory compliance oversight function. For banks and NBFCs, where the operational activities are outsourced, the responsibility for ensuring compliance to all relevant regulatory requirements lies with them. As a result, adequate monitoring systems should be in place, including regular audits, compliance certification, performance assessments and reporting to regulatory authorities.


Another major consideration for outsourcing due diligence is technology risk. Financial institutions need to consider whether fintech partners meet industry best practices for information security, have the correct encryption systems, regularly test for vulnerabilities, and have solid incident response procedures. 


Head of Contractual Risk Allocation and Liability


One of the best methods for dealing with legal risks in fintech partnerships is to have a careful contract drawn up. Due to the nature of financial services, contractual obligations should lay out the responsibilities of each party with regard to regulatory compliance, operational performance, cybersecurity, customer complaints, ownership of any intellectual property, confidentiality and dispute resolution.


It is important to have specific service level agreements with measurable performance standards, system availability requirements, response times, reporting requirements and escalation procedures that are included in service agreements. These stipulations offer objective standards with which service performance can be assessed and help to eliminate ambiguity around contractual requirements.


Regulatory compliance, data protection, cybersecurity, intellectual property, fraud, employee misconduct, and third-party claims are often the areas from which financial institutions are seeking comprehensive indemnities based upon regulatory violations, data protection violations, cyber incidents, IP violations, fraud, employee misconduct and third-party claims stemming from the fintech partner's activities. On the other hand, when it comes to commercial risk, fintech providers often negotiate limitations of liability. As with most things involving business decisions, a balance has to be struck, and the nature of outsourced services and the potential for regulatory issues due to a failure in operations must be assessed.


Before the launch, these are required to be tested


Banks and NBFCs should carefully evaluate the legal, regulatory, operational and technical aspects of the proposed solution with a fintech company before beginning operations with them to ensure that the solution meets the legal and regulatory requirements and expectations. Post-deployment compliance failures, operational issues, cybersecurity breaches and customer complaints are reduced as a result of effective pre-launch testing. Institutions need to ensure that the fintech partner's customer onboarding process adheres to the RBI Master Direction - Know Your Customer (KYC), 2016, which includes KYC processes, Customer Due Diligence (CDD), sanctions screening, record keeping and Anti-money laundering (AML) compliance. If digital onboarding/e-KYC solutions are being used, then institutions must make sure their identity verification processes meet the RBI guidelines and have suitable audit trails.


These also need to be thoroughly tested before launching the data governance initiative. The banks and NBFCs need to ensure that the mechanisms adopted by customers, privacy notices, data processing activities, retention policies and cyber security measures are in accordance with the provisions of the Digital Personal Data Protection Act, 2023 (DPDP Act). 


Before hiring a fintech partner, regulated entities need to consider the following:


  • Regulatory Compliance

  • Ensure licences/registrations and regulatory approvals are in place.

  • Ensure RBI compliance with KYC/AML and digital lending.

  • Review past regulatory actions, investigations, or enforcement actions.

  • Analyze ownership and beneficial ownership.

  • Review Board composition/gov. policies.

  • Assess internal controls and risk management activities.

  • Audit financial statements.

  • Analyze sources of funding and financial viability.

  • Assess cyber & operational insurance cover.

  • Conduct cybersecurity assessments.

  • Check the security of encryption methods and access control.

  • Examine vulnerability assessments and penetration testing reports.

  • Ensure that business continuity and disaster recovery are in place.

  • Examine the provisions of the Digital Personal Data Protection Act, 2023.

  • Review consent management procedures.

  • Discuss data retention and data deletion policies.

  • Confirm that the procedures for breach notification are correct.

  • Examine procedure for customer sign-up.

  • Conduct a risk assessment of fraud detection and transaction monitoring programmes.

  • Review the processes for handling customer complaints.

  • Ensure that system is scalable and resilient to operations.

  • Make sure that the scope of services is clearly defined.

  • Allocate regulatory responsibilities.

  • Make sure to have confidentiality and intellectual property clauses included.

  • Set up auditing authority and reporting requirements.

  • Use indemnities and limitation of liability clauses.

  • Give a comprehensive termination/exit management process.


Practical Implications


As partnerships between banks, NBFCs and fintech firms grow, effective onboarding for partners is a key aspect of enterprise risk management. There is a growing trend in regulatory requirements to financial institutions to have continual oversight of outsourced functions, as opposed to simply relying on contractual assurances. As a result, those institutions that have established effective due diligence practices, contracts, and continuous monitoring practices are better equipped to manage regulatory, operational, and reputational risks. 


From a commercial perspective, effective governance structures can ensure that customers have greater confidence in the organization, enhance operational resilience, facilitate regulatory compliance, and help minimise the risk of disputes escalating as a result of data breaches, service failures, or regulatory investigations. On the other hand, the failure to conduct proper due diligence can cost institutions a lot of money, lead to legal actions, have the potential to attract their customers' claims, and damage their reputation. Structured induction procedures are therefore important in both the area of regulatory compliance and to achieve sustainable commercial partnerships.


Conclusion


In a digital financial services landscape, Fintech partnerships are essential to help banks and NBFCs drive innovation, enhance digital products and services, and enrich customer experience. But there are a lot of legal and regulatory issues with such partnerships involving compliance with know your customer regulations, outsourcing, data protection, cyber security, and risk allocation in the contracts. Having a good partner onboarding program involves more than just the commercial discussion—it needs to include a detailed legal, operational and compliance evaluation.


An effective onboarding process should have a strong DDD, contractual protections, cybersecurity checks, and ongoing monitoring as part of the process throughout the life of the partnership. Institutions must ensure the strong governance of their fintech partners, their adherence to relevant RBI regulations and data protection laws and their operational resiliency to support critical financial services.


Author: Suresh Kanna in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at  Khurana & Khurana, Advocates and IP Attorney.


References


  1. Reserve Bank of India Act, 1934.

  2. Banking Regulation Act, 1949.

  3. Payment and Settlement Systems Act, 2007

  4. Indian Contract Act, 1872

  5. Digital Personal Data Protection Act, 2023

  6. Prevention of Money Laundering Act, 2002

  7. RBI Master Direction – Know Your Customer (KYC), 2016

  8. RBI Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services by Banks and NBFCs.

  9. RBI Guidelines on Digital Lending, 2022


Recent Posts

See All

Comments


bottom of page