MODULE 1 — ACADEMIC NOTES
WEEK 3: REGULATORY ARBITRAGE, INNOVATION–STABILITY–
CONSUMER PROTECTION TENSIONS, AND REGULATORY
RESPONSES
Understanding the core tensions FinTech creates for regulators and how India is responding
Primary Sources: T Rabi Sankar — "FinTech Innovation and Approach to Regulation" (2023) | RBI Report on
Currency and Finance, Chapter V — "Digitalisation: Tackling Emerging Risks and Challenges" (2024)
QUICK ORIENTATION: What Week 3 Is About
Weeks 1 and 2 established what FinTech is (products, ecosystem) and how RBI thinks about
regulation (objectives, principles, challenges). Week 3 deepens the analysis on the specific
frictions FinTech creates. Three interrelated tensions dominate this week:
TENSION THE CORE PROBLEM WHY IT MATTERS
Regulatory Arbitrage FinTechs doing bank-like Creates an unlevel playing field;
activities without bank-like endangers systemic stability;
regulation — exploiting gaps hollows out regulatory
between regulatory regimes frameworks over time
Innovation vs. Stability Fast-moving FinTech innovation Too cautious = stifled
outpaces regulatory frameworks innovation; too permissive =
— speed and scope of change accumulated risks. Neither
is qualitatively different from extreme is acceptable
earlier financial technology
Consumer Protection Digital financial products create Consumer harm erodes public
new categories of consumer trust in digital finance; without
harm: dark patterns, data trust, digital inclusion goals are
exploitation, algorithmic bias, undermined
BNPL debt traps, social
contagion
📌 HOW THE TWO READINGS DIVIDE THE LABOUR
Rabi Sankar (2023): The analytical framework — WHY these tensions exist, how
FinTech's nature creates them, and what regulatory philosophy India needs. Framed as a
practitioner-policymaker's diagnosis of the problem and prescription for the approach.
RBI Report on Currency and Finance, Chapter V (2024): The evidence base — empirical
data on risks actualised, emerging consumer behaviour patterns, RBI's specific policy
responses, and survey data from banks/NBFCs on how they are experiencing these
tensions.
PART A: THE NATURE OF FINTECH INNOVATION —
WHY IT IS DIFFERENT
T Rabi Sankar opens his 2023 GFF keynote with a foundational question that shapes everything
that follows: What is actually new about FinTech innovation? Financial innovation is not new —
wire transfers, ATMs, electronic stock exchanges are all technological innovations. So what
makes current FinTech qualitatively different?
A.1 Innovation as a Cumulative, Collective Process — Schumpeter
and Mazzucato
Before diagnosing the problem, Rabi Sankar grounds his analysis in innovation theory. Drawing
on Joseph Schumpeter and Mariana Mazzucato's work, he makes three foundational points
about innovation:
• Innovation is cumulative: What appears as a radical discovery today is the fruit of years of
prior work building on each other. Innovation is rarely a sudden breakthrough; it is
accumulated investment in ideas and infrastructure.
• Innovation is collective: Many researchers, institutions, and investors contribute before a
breakthrough emerges commercially. No single actor creates major innovations alone.
• Innovation has long lead-times: What looks instantaneous from the outside may represent
a decade or more of prior investment.
💡 EXAMPLE: UPI as Cumulative Innovation
Rabi Sankar cites UPI — which processed over 340 million transactions daily as of 2023
— as the clearest proof of this theory. UPI did NOT emerge suddenly. It is the outcome of
cumulative investments over 15+ years: IMPS (2010), Aadhaar (2009), NPCI's
infrastructure, RBI's Payment System Vision documents, the JAM trinity architecture, and
countless iterations of API development and bank integration. It only appears "overnight"
to outsiders. The lesson: do not mistake visibility for speed of creation.
A.2 What Is Genuinely Different: Speed and Scope
Previous financial innovations (wire transfers, ATMs, algorithmic trading) were gradual in two
senses: they were introduced slowly, and they enabled the financial system to adapt without
disruption. The financial system absorbed them without fundamental stress.
Current FinTech innovations are different on both dimensions. Rabi Sankar identifies the critical
distinction as speed and scope:
EARLIER FINANCIAL INNOVATIONS CURRENT FINTECH INNOVATIONS
Gradual introduction over years/decades Rapid adoption — can go from launch to millions
of users in months
Narrow scope — served one function (e.g., cash Broad scope — one platform may offer payments,
dispensing) lending, investment, insurance simultaneously
Financial system had time to adapt its regulatory Regulatory frameworks are outpaced —
framework regulation lags significantly behind deployment
Operated within a clearly identifiable regulatory Operate across multiple regulatory perimeters
perimeter simultaneously
Risk profiles were familiar and manageable with New risk profiles emerge faster than regulators
existing tools can measure and manage them
📌 THE KEY DIAGNOSTIC: REGULATORY LAG
"Rapid technology changes can outpace regulatory frameworks, and raise issues about
market integrity, consumer protection, data privacy, and fair market practices. The agility
of new age fintech firms can challenge traditional regulatory models, making it difficult to
ensure compliance at all times and maintain stability." — Deputy Governor T Rabi Sankar,
GFF 2023. This is not a solvable problem — regulatory lag is inherent when innovation
moves faster than the legislative and regulatory process. The question is: how do you
design a regulatory approach that minimises the lag and its consequences? This is
precisely what Week 3 examines.
PART B: REGULATORY ARBITRAGE — The Unlevel
Playing Field
B.1 What is Regulatory Arbitrage?
Regulatory arbitrage occurs when an entity structures its activities to take advantage of gaps,
inconsistencies, or differences between regulatory regimes — obtaining the economic benefits
of a regulated activity while avoiding the costs (compliance, capital, consumer protection
obligations) that regulated entities must bear.
💡 EXAMPLE: Classic Regulatory Arbitrage — Shadow Banking
Traditional example: Before 2008, investment banks used off-balance-sheet vehicles
(Special Purpose Vehicles) to hold mortgage-backed securities. These were economically
similar to deposits funding loans, but they avoided the capital and reserve requirements
that applied to regular banking. The bank enjoyed the economic upside while the
regulatory costs were avoided. When the housing market collapsed, the systemic risk
materialised without the regulatory cushion that would have existed for a proper bank.
This is regulatory arbitrage producing systemic harm.
B.2 How FinTech Creates Regulatory Arbitrage
FinTech regulatory arbitrage is more subtle and more pervasive than classic shadow banking
because it exploits definitional and jurisdictional gaps in the regulatory architecture. The RBI
Annual Report on Currency and Finance (2024) and Rabi Sankar (2023) identify several specific
mechanisms:
MECHANI HOW IT WORKS EXAMPLE IN INDIA REGULATORY
SM CONCERN
Activity- Performing the economic Pre-2017: P2P lenders No capital adequacy;
Entity Gap function of a bank (taking collected funds from lenders no CRR/SLR; no
funds, extending credit) and deployed as loans — deposit insurance;
through a non-banking entity effectively bank-like lighter consumer
not subject to banking intermediation without bank protection
regulation regulation
Sectoral Offering financial services Payment app adds a lending Jurisdictional grey
Boundary across regulatory feature — RBI regulates zones; no single
Gap boundaries — paying part payments but who regulates regulator has full
from one regulator's domain, the lending feature? visibility; consumer
lending from another protection
inconsistency
Entity Structuring the business to Buy-Now-Pay-Later Same economic
Classificatio avoid classification as a schemes structured as function (deferred
n Gap regulated entity merchant cash advances payment with interest),
rather than loans to avoid different regulatory
credit regulation treatment
Intermediatio Splitting the regulated Lending Service Providers Credit risk
n Chain activity into multiple steps, (LSPs) source customers; management split from
Fragmentati each performed by a Regulated Entity the regulated entity;
on different entity, so no single (bank/NBFC) funds loans; accountability gaps
entity triggers full regulation LSP takes the spread. LSP
avoids RE-level regulation
but influences credit
decisions
📌 THE RBI REPORT's FORMULATION (2024)
"Not aligning the regulation of non-bank FinTechs to that of banks offering similar services
may create inefficiencies, amplify risks of regulatory arbitrage, and create an uneven
playing field." — RBI Report on Currency and Finance, 2024 (citing Sankar, 2022). The
report further notes that globally, the growth of non-bank institutions in the lending
business adds a dimension that could raise regulatory arbitrage. FinTech firms have
complex and less transparent funding structures, making it harder to assess their risk
transmission on overall stability. India-specific mitigation: In India, non-bank entities in
lending are regulated as NBFCs by RBI; FinTechs cannot lend on their own balance
sheet and only act as Lending Service Providers (loan sourcing agents).
B.3 Deposit Disintermediation — A Specific Arbitrage Risk
One of the most significant arbitrage concerns Rabi Sankar highlights is the risk of deposit
disintermediation. This deserves special treatment because it strikes at the foundational model
of bank funding.
📌 WHAT IS DEPOSIT DISINTERMEDIATION?
Banks fund themselves primarily through deposits — money entrusted to them by
individuals and businesses. Banks pay low interest on deposits, lend at higher rates, and
earn the spread (Net Interest Margin). Regulatory requirements (CRR, SLR, capital
adequacy) attach to this deposit-funded model. Deposit disintermediation occurs when
alternative savings/investment vehicles draw funds away from bank deposits. If
consumers move money from bank accounts to payment wallets, money market funds,
investment apps, or other digital products, banks lose their low-cost funding base. Banks
must then fund lending from more expensive sources — reducing their profitability and
potentially their lending capacity. The regulatory framework built around bank deposits
becomes less effective.
The FinTech dimension: Payment wallets (Paytm, PhonePe, Google Pay) hold customer
balances. Investment apps (Zerodha, Groww) divert savings to mutual funds. Digital gold and
similar instruments absorb savings. Each individually may be well-regulated within its own
framework. But collectively, they can shift the funding composition of the financial system in
ways no single regulator is monitoring. Rabi Sankar explicitly identifies "unregulated non-bank
payment services could disadvantage traditional banks, leading to regulatory arbitrage and
deposit disintermediation" as a key supervisory challenge (cited in RBI 2024).
PART C: RABI SANKAR's REGULATORY
FRAMEWORK — THREE PRINCIPLES AND THE
SWEET SPOT
C.1 RBI's Three Regulatory Principles for FinTech (Sankar 2022, cited
in 2024 Report)
Rabi Sankar articulates a clear three-principle framework that underpins RBI's approach to
regulating FinTech. These principles appear across multiple speeches and are directly quoted in
the 2024 RBI Report:
RBI's regulation of FinTech is premised on three principles: (1) Encouragement of
innovation (2) Assimilation of innovation in the financial system in a non-disruptive
manner (3) Customer protection — Sankar (2022), cited in RBI Report on Currency
and Finance (2024)
PRINCIPLE WHAT IT MEANS HOW RBI
OPERATIONALISES IT
1. Encouragement of Innovation Create enabling conditions for Regulatory Sandbox (live
FinTech to develop, test, and testing); Hackathons (including
scale products. Do not pre- HaRBInger); FinTech
emptively block experimentation Department within RBI; Reserve
through overly restrictive rules. Bank Innovation Hub (RBIH);
Public Tech Platform for
Frictionless Credit (now ULI)
2. Non-Disruptive Assimilation Bring innovations into the NBFC-P2P classification (2017)
financial system in a managed, — brings P2P inside the
ordered way so that the system perimeter. Account Aggregator
absorbs them without framework. Digital Lending
threatening stability. "Regulation Guidelines (2022) — guardrails
plays a crucial role in managing without banning digital lending.
the pace of change." (Sankar) SRO-FT framework (2024)
3. Customer Protection Protect consumers at every Digital Lending Guidelines focus
stage of the innovation cycle — on fair treatment (key fact
not as an afterthought, but as an statement, grievance redress,
integral design parameter. no coercive recovery). DPDP
Focus on fair treatment, Act 2023 for data protection.
transparency, and recourse. RB-IOS (Integrated
Ombudsman Scheme).
Consumer education
programmes (RBI Kehta Hai, e-
BAAT)
⚠️ IMPORTANT FOR EXAMS
EXAM ESSENTIAL: These three principles (Encourage Innovation + Non-Disruptive
Assimilation + Customer Protection) are Rabi Sankar's core framework and must be
known precisely. They appear directly in the RBI Report on Currency and Finance (2024)
and represent the authoritative RBI position on FinTech regulation. Note that they are
different from (but complementary to) Malhotra's five regulatory principles from Week 2 —
those are general principles for all RBI regulation; these three are specific to FinTech.
C.2 The Innovation-Stability Tension: Why It Cannot Be Resolved,
Only Managed
Rabi Sankar is clear that the tension between innovation and stability is not a policy failure — it
is inherent in the nature of financial innovation itself. He identifies three dimensions of this
tension:
C.2.1 The Speed Problem
The pace of FinTech innovation structurally outpaces regulatory frameworks. Regulation
requires: consultation, drafting, stakeholder feedback, legal review, issuance, compliance
periods. This can take 1–3 years minimum. A FinTech product can go from concept to millions
of users in 6–12 months. By the time regulation catches up, the product may already have
caused harm — or may already be obsolete.
C.2.2 The Knowledge Problem
Regulators face a fundamental information asymmetry: FinTech companies know their products
far better than regulators do. A digital lending platform's credit algorithm may process thousands
of variables — a regulator cannot assess its risks without deep technical expertise that is
expensive and rare in the public sector. This is why Rabi Sankar emphasises the role of SROs:
industry participants "possess the deepest understanding of the processes and practices within
the trade." They are "best-suited to establish common rules, enforce them, and effectively
handle disputes that may arise from non-compliance with these rules."
C.2.3 The Systemic Risk Accumulation Problem
Individual FinTechs may be small enough to fail without systemic consequences. But the
collective adoption of similar technologies, similar business models, and similar data providers
creates correlated risks that can be systemic even if no single FinTech is "too big to fail."
💡 EXAMPLE: Concentration Risk from Third-Party Providers
If 80% of Indian banks and FinTechs use the same cloud provider (e.g., AWS or Azure), a
failure or cyberattack on that provider creates systemic disruption even though no
individual bank is directly linked to the others. The RBI 2024 Report notes: "Dominance of
a few technology service providers, outages or cyber incidents could give rise to macro-
financial stability risks (IMF, 2024)." This is concentration risk through infrastructure, not
through financial inter-linkages — a genuinely new form of systemic risk that existing
regulatory frameworks were not designed to address.
C.3 The "Sweet Spot" — Competition AND Collaboration Between
FinTechs and Banks
One of the most practically important ideas in Rabi Sankar's 2023 speech is his articulation of
the optimal relationship between FinTechs and traditional financial institutions. He rejects the
binary framing of FinTechs as either competitors OR collaborators — and argues for both
simultaneously.
"Perhaps the sweet spot lies in fintechs acting as both competitors as well as
collaborators. The existence of competition is necessary to create incentives for
fintechs to invest in innovations as well as pushing traditional entities to stay on their
toes. At the same time, collaboration is essential for innovations to be absorbed into
the financial systems." — Deputy Governor T Rabi Sankar, GFF 2023
FinTechs COMPETING WITH BANKS FinTechs COLLABORATING WITH BANKS
Creates incentives for FinTechs to keep Essential for innovations to be absorbed into the
innovating (without competition pressure, mainstream financial system at scale
innovation can stagnate)
Pushes traditional banks to stay competitive and Banks provide balance sheets, capital base,
improve customer experience regulatory standing, and risk management
practices
Drives down costs through price competition in FinTechs provide agility, digital capabilities,
payments, lending, investment customer experience, lower-cost delivery
Delivers new services to consumers that banks Collaboration allows innovations to reach all
were not providing consumers through banks' established distribution
network
May create regulatory arbitrage if FinTechs avoid May reduce competitive pressure if too cozy —
regulation while competing raises cartel/anti-competition concerns
Rabi Sankar notes that what determines the boundary between competition and collaboration
"will eventually be determined by market forces" — but this is also an area where regulators
need to create a regulatory framework that continues to spur innovation while managing the
risks. The Digital Lending Guidelines (2022) structure is a direct embodiment: banks remain the
regulated lenders, but FinTechs (as LSPs) can source customers and provide technology —
competing on service while collaborating on the actual credit function.
PART D: SELF-REGULATION — THE ROLE OF SROs
IN MANAGING THE INNOVATION-STABILITY TENSION
Section 9 of Rabi Sankar's 2023 speech is dedicated to self-regulatory organisations (SROs) as
a key mechanism for bridging the knowledge gap between regulators and the FinTech industry.
This is highly exam-relevant as it directly previews the Week 4 SRO Framework.
D.1 Why SROs Are Needed — The Knowledge Argument
Rabi Sankar's argument for SROs rests on a specific information asymmetry claim: in a new
and evolving sector like FinTech, industry participants possess the deepest understanding of
the processes and practices within the trade. This makes them best-suited to:
• Establish common rules that are practical and workable — because they understand the
operational realities
• Enforce those rules effectively — because peer enforcement from industry bodies is often
more credible and better-informed than remote regulatory supervision
• Handle disputes arising from non-compliance — because industry participants understand
technical nuances that regulators may miss
D.2 What SROs Do — Their Functions
• Promote responsible practices and maintain ethical standards: Industry-led bodies
establish guidelines and codes of conduct that foster transparency, fair competition, and
consumer protection.
• Facilitate collaboration: Between FinTech firms, regulators, and stakeholders — creating a
framework for innovation with guardrails.
• Proactively address issues: Market integrity, conduct, data privacy, cybersecurity, and risk
management — before they become regulatory crises.
• Build trust: Among consumers, investors, and regulators — through voluntary compliance
and transparent self-governance.
• Bridge information gap: SROs can give regulators valuable signal on what is happening in
the industry — "on the ground" intelligence that formal supervision may miss.
📌 RABI SANKAR's FORMULATION ON SROs
"As regulators continue to contemplate, implement, and refine regulations for the orderly
development of the FinTech sector, self-regulatory organizations (SROs) could play a
pivotal role in the fintech industry by promoting responsible practices and maintaining
ethical standards. These industry-led bodies establish guidelines and codes of conduct
that foster transparency, fair competition, and consumer protection. SROs can facilitate
collaboration between fintech firms, regulators, and stakeholders, creating a framework
for innovation with guardrails." — T Rabi Sankar, GFF 2023. Note: RBI subsequently
issued the Framework for Self-Regulatory Organisation(s) for FinTech Sector (SRO-FT) in
May 2024 — studied in detail in Week 4.
PART E: RBI REPORT ON CURRENCY AND FINANCE
2024 — CHAPTER V: DIGITALISATION: TACKLING
EMERGING RISKS AND CHALLENGES
The RBI's Annual Report on Currency and Finance (2024), Chapter V, titled "Digitalisation:
Tackling Emerging Risks and Challenges," provides an empirically grounded, comprehensive
analysis of how digitalisation is reshaping the Indian financial system — its benefits, risks, and
regulatory responses. This chapter is the most data-rich of this week's readings.
📌 CHAPTER STRUCTURE AND SCOPE
Chapter V covers: (1) Digital adoption by Indian banks and NBFCs; (2) Regulatory
challenges from FinTech; (3) Digitalisation and customer behaviour; (4) Financial stability
and macroeconomic implications; (5) Policy initiatives by RBI. It draws on an RBI survey
of 25 banks and 58-64 NBFCs, plus international research and regulatory data.
E.1 How Banks and NBFCs Are Experiencing Digital Transformation
The RBI survey (25 banks, 58–64 NBFCs) captures the ground-level experience of regulated
entities navigating digital transformation:
• Benefits of digital adoption banks/NBFCs report: Reduced costs for customer acquisition,
transactions, and employees; FinTech collaboration to maximize gains.
• Primary challenges hindering adoption: Cybersecurity threats, implementation costs,
legacy core banking applications (CBAs), and customer unwillingness (particularly among
older and rural populations).
• Key risks identified: Cybersecurity risk, data privacy risk, and third-party risk are the top
three — all consistent with Rabi Sankar's analysis.
• Attitude toward FinTech regulation: Most respondent banks and NBFCs FAVOURED
regulation of FinTech firms — recognising that unregulated competition from FinTechs
creates an unfair playing field and systemic risk.
• Collaboration preference: Most banks/NBFCs preferred incentives to collaborate with
FinTechs rather than pure competition.
💡 EXAMPLE: India's Bank-Led Digital Lending Model
The RBI 2024 Report makes a crucial India-specific clarification: In India, FinTech entities
do NOT lend on their own balance sheets. They act as Lending Service Providers (LSPs)
— loan sourcing agents. The actual lending is done by regulated entities (banks and
NBFCs). This means India has largely avoided the regulatory arbitrage problem that
afflicts digital lending globally. The bank or NBFC remains responsible for credit risk,
capital requirements, and consumer protection obligations. The FinTech LSP provides
origination, technology, and customer acquisition services. This model is reinforced by the
2022 Digital Lending Guidelines.
E.2 Digital Lending: Risks and the 2022 Guidelines
The boom in digital lending (primarily personal loans through FinTech apps) surfaced a distinct
set of conduct and consumer harm issues that required specific regulatory intervention:
• Unbridled engagement of third parties: FinTech apps sourcing loans had no direct
accountability to the regulator; they could externalise harms onto borrowers without
consequence.
• Mis-selling: Borrowers not fully informed of all charges, fees, and terms. Products sold
without adequate suitability assessment.
• Breach of data privacy: Loan apps requesting access to contacts, photos, location data far
beyond what loan underwriting requires — used for coercive recovery (threatening to
contact family/employers).
• Exorbitant interest rates: Digital lending platforms charging effective annual rates far
exceeding usurious levels, with rates buried in complex fee structures.
• Unethical recovery practices: Harassment, threatening messages, public shaming using
data obtained from borrowers' phones — leading to multiple reported suicides of
borrowers.
• Algorithmic bias and financial exclusion: AI-driven credit decisions may systematically
exclude certain demographics without explicable justification.
📌 DIGITAL LENDING GUIDELINES (September 2022) — KEY PROVISIONS
(1) Regulated Entities (REs) remain fully accountable even when using LSPs —
outsourcing to a FinTech LSP does not reduce the RE's regulatory obligations. (2) Key
Fact Statement (KFS): Borrowers must receive a standardised, plain-language disclosure
of all charges, interest rates, and terms before loan disbursal. (3) No collection by third
parties: Digital lending apps cannot collect loan repayments directly — all money flows
through the RE's account. (4) Data minimisation: LSPs can only collect data strictly
necessary for credit assessment; excessive permissions (contacts, photos etc.) are
prohibited. (5) Grievance redress: Dedicated nodal officer for digital lending complaints;
clear escalation mechanism. (6) Default Loss Guarantee (DLG) cap: DLG (first-loss
guarantee by LSPs to incentivise banks) capped at 5% of loan portfolio — prevents over-
concentration of credit risk in the LSP layer.
E.3 Digitalisation and Consumer Behaviour — New Risks
Chapter V introduces important analysis of how digitalisation changes consumer behaviour in
ways that create new regulatory challenges. These are genuinely novel risks — not covered
adequately by traditional consumer protection frameworks.
E.3.1 Social Contagion and Herd Behaviour in Digital Finance
Digital platforms enable rapid dissemination of financial trends through social networks, peer
influence, and viral content. The RBI 2024 Report identifies this as a genuinely new systemic
risk vector:
• Social contagion: Consumers are influenced by the financial actions of peers, influencers,
and trending topics on social media platforms. This is faster and more potent than
traditional word-of-mouth.
• Herd behaviour in investment: Mass buying or selling of stocks driven by viral social media
posts (example: meme stocks, crypto pump-and-dump schemes) — leading to asset price
volatility disconnected from fundamentals.
• Digital bank runs: Sentiments in social media can amplify classic bank run dynamics.
Negative viral posts about a bank's solvency can trigger mass withdrawals faster than a
regulator can respond — amplifying the classic bank run risk factors studied in Week 2
(Diamond-Dybvig model).
• Collective shifts amplify volatility: The combination of social contagion and herd behaviour
can lead to rapid, correlated changes in customer financial behaviour — affecting market
liquidity, asset prices, and deposit stability simultaneously.
💡 EXAMPLE: Silicon Valley Bank (SVB) — Digital Bank Run (2023)
SVB's collapse in March 2023 was the first major "Twitter bank run" in history. Negative
social media posts about SVB's losses spread virally on 9 March 2023. Within 24 hours,
customers attempted to withdraw $42 billion — more than 20% of SVB's deposit base.
The speed was unprecedented: traditional bank runs unfolded over days; the SVB run
was driven to crisis within hours by social media amplification. This validates the RBI
2024 Report's concern that "sentiments in social media amplify the classic bank run risk
factors." Supervisory monitoring of social media for early warning signs is now being
considered globally.
E.3.2 Buy-Now-Pay-Later (BNPL) — A New Debt Risk
BNPL schemes allow consumers to buy goods and defer payment, typically with zero or low
upfront interest but late fees, instalment charges, or deferred high interest rates. The RBI 2024
Report provides detailed data and analysis:
• Global BNPL market: Transactions projected to grow from USD 309 billion (2023) to USD
566 billion (2026).
• India context: BNPL constitutes ~3% of e-commerce finance by value (vs 5% globally);
India is among top five countries in terms of BNPL users.
• Key risk: BNPL lenders typically do not perform detailed credit checks or rigorous
assessment of ability to repay. Consumers using multiple BNPL services concurrently can
easily overextend themselves. The business model has a high dependence on late fees —
which can become predatory.
• Digital amplification: The seamless, frictionless nature of digital technology facilitates
impulsive purchasing and debt accumulation. The psychological effort of a FinTech
transaction is far lower than traditional debt — reducing natural inhibitions against
borrowing.
• India's regulatory response: RBI treats BNPL as a credit product requiring similar due
diligence and credit appraisal standards as other loans. This closes the regulatory gap that
exists in many other jurisdictions where BNPL is treated as a merchant credit product and
avoids credit regulation.
⚠️ IMPORTANT FOR EXAMS
EXAM IMPORTANT: BNPL is a highly topical example of the consumer protection
tension. Key exam points: (1) What makes it risky (no credit check, multiple concurrent
use, late fee profitability model, impulsive spending facilitation); (2) How India is different
(treated as credit product = credit regulation applies); (3) The broader principle it
illustrates (same economic function as credit = same regulation should apply).
E.3.3 Dark Patterns — Invisible Risks in Digital Design
Dark patterns are one of the most conceptually important new consumer harm categories
introduced in the RBI 2024 Report. They represent a genuinely new form of risk that did not
exist in traditional financial services.
📌 WHAT ARE DARK PATTERNS?
"Dark patterns refer to deceptive practices or design patterns in user interface or user
experience/interactions that are designed to mislead users to do something they originally
did not intend to do, by subverting or impairing consumer autonomy, decision making or
choice." — CCPA, 2023; cited in RBI Report on Currency and Finance, 2024. In other
words, dark patterns manipulate the user's decision-making process not through outright
lies but through design choices — making it visually or cognitively difficult to choose the
option that serves the consumer's interest.
Key examples of dark patterns in financial services:
• Forced continuity: Free trials that automatically convert to paid subscriptions without
prominent notification; cancellation made deliberately difficult.
• Hidden charges: Fees disclosed only at the final confirmation step after the consumer has
invested time completing the application — exploiting the "sunk cost" psychology.
• False urgency: "Offer expires in 10 minutes!" counters displayed to rush decision-making,
preventing proper comparison or consideration.
• Misdirection: Important terms (like the actual APR on a loan) displayed in small, grey text
while attractive terms (like "0% interest") displayed prominently in bold.
• Confirmshaming: Opt-out buttons labelled humiliatingly ("No, I don't want to save money")
to make consumers feel foolish for opting out.
• Pre-selected options: Insurance, add-on credit protection, or other paid products pre-
checked in application forms — consumers must actively uncheck to decline.
Regulatory response: The Central Consumer Protection Authority (CCPA) issued the
"Guidelines for Prevention and Regulation of Dark Patterns, 2023" — applicable to advertisers,
sellers, and platforms. This is India's first dedicated dark pattern regulation. RBI has also
incorporated prohibitions on misleading design in digital lending guidelines.
💡 EXAMPLE: Data Over-Collection — Privacy as Dark Pattern
Three-fourths of B2C FinTech applications in India request permission to access camera,
photos/media, location, and storage. These permissions far exceed what is needed for
financial services. The real purpose is typically to build richer user profiles for targeted
advertising or, in the case of unscrupulous lenders, to harvest contacts for coercive debt
recovery. RBI's Digital Lending Guidelines (2022) explicitly prohibit digital lending apps
from accessing data not strictly necessary for credit assessment. DPDP Act 2023 further
enshrines data minimisation as a legal principle.
E.4 FinTech and Financial Stability — The Dual Face
The RBI 2024 Report contains a structured analysis of how FinTech affects financial stability —
presenting both the stabilising and destabilising effects. This is the most academically rigorous
section of Chapter V.
FINTECH — STABILISING EFFECTS FINTECH — DESTABILISING EFFECTS
Decentralisation/diversification: Greater variety of Cyber risk: Interconnected network of FinTechs
institutions and instruments dampens and banks increases susceptibility to cyber-
concentration of financial shocks attacks; weaker institutions are vulnerabilities
Efficiency: Financial innovations improve Third-party reliance: Heavy dependence on cloud
efficiency in decision-making and risk models providers, payment processors, and data
used by institutions analytics firms creates operational risk
concentration
Transparency: Better data use reduces Contagion: Greater automation and more
information asymmetries between lenders and sophisticated algorithms may create new,
borrowers, between regulators and regulated unpredictable sources of contagion
Financial inclusion: Reduces transaction costs Pro-cyclicality and concentration risk: Amplifies
and information barriers; reaches previously traditional financial risks when digital channels
underserved populations concentrate activity in single platforms
Liquidity enhancement: Digital payment systems Algorithmic correlation: If many institutions use
and e-trading platforms improve market liquidity similar AI/ML models, they may make correlated
decisions during stress — amplifying rather than
dampening shocks
India-specific stability assessment: The RBI 2024 Report notes that in India, the adoption of
digital technologies by banks appears to drive down (not up) risk taken by banks. The bank-led
model (where FinTechs act as LSPs, not direct lenders) and NBFC regulation of non-bank
lenders means India has partially mitigated the stability risks that have materialised in other
jurisdictions.
E.5 Cyber Risk — The Dominant Emerging Threat
Cyber risk receives the most extensive treatment in Chapter V — reflecting RBI's view that it is
the single most pressing risk from digitalisation.
• Systemic risk surveys: RBI's systemic risk surveys (financial professionals and academics)
show cyber risks have been increasing consistently since 2020.
• BFSI sector targeted: India's BFSI (Banking, Financial Services, Insurance) sector is
among the highest-targeted sectors for cyber-attacks — second only to IT/ITES
companies (India Cyber Threat Report 2023).
• Data breach costs: Global average data breach cost was USD 4.45 million per incident
(IBM 2023 Cost of Data Breach Report) — among the highest ever recorded.
• Concentration risk: Dominance of a few cloud providers means a single incident could
affect multiple regulated entities simultaneously.
• UPI downtime declining: Despite rising cyber risk concern, actual UPI downtime has been
falling — indicating India's payment infrastructure reliability is improving even as threat
volumes rise.
RBI's specific cyber-policy responses (as listed in Chapter V):
• Digital Lending Guidelines (2022): Cybersecurity requirements for lending apps.
• IT Risk Guidelines (2023): Enhanced frameworks for banks' IT systems and fraud
prevention.
• Outsourcing Master Directions (April 2023): REs must report cyber incidents at third-party
providers within 6 hours of detection.
• Operational Resilience Guidance Note (April 2024): Strengthening banks' ability to identify,
mitigate, and recover from cyber incidents; ensuring delivery of critical operations.
• Cyber Range: Setting up a dedicated environment for cyber drills and simulation
exercises.
• Cyber Sectoral Security Operations Centre (S-SOC): Examining feasibility of a shared
SOC for the financial sector.
• Phishing simulation exercises: Testing staff awareness and resilience.
• Digital Payments Intelligence Platform (DPIP) (June 2024): Network-level intelligence and
real-time data sharing across the payments ecosystem for fraud detection.
• HaRBInger 2024 hackathon themes: "Zero Financial Frauds" and "Being Divyang
Friendly."
E.6 RBI's Balanced Regulatory Approach — The Policy Philosophy
Chapter V articulates RBI's overarching regulatory approach to the digital transformation,
consistent with the three principles from Rabi Sankar but adding operational detail:
• Balance, not barrier: "Strike a balance between mitigating the potential risks without
impeding financial innovations." This means using multiple tools — not a simple on/off
regulatory switch.
• Multiple tools: Research on FinTech developments; proactive engagement with existing
and new-entrant FinTechs; clear communication with stakeholders; risk mitigation
strategies; modifications to supervisory processes; guidelines or regulations.
• Nuanced and anticipatory: "The regulation of this dynamic sector needs to be balanced,
nuanced, and reasonably anticipatory." Anticipatory regulation means watching for
emerging risks before they fully materialise — not waiting for harm to occur before acting.
• Self-regulation as supplement: RBI has "encouraged self-regulation in the FinTech sector"
— the SRO-FT framework (May 2024) is the structural embodiment of this approach.
PART F: CROSS-CUTTING ANALYSIS — HOW THE
TWO READINGS REINFORCE EACH OTHER
F.1 The Master Analytical Framework for Week 3
The two primary readings for Week 3 operate at different levels of abstraction but are deeply
complementary. Together they provide a complete picture of the regulatory challenge:
RABI SANKAR (2023) — THE RBI REPORT CH. V (2024) — THE
ANALYTICAL LENS EMPIRICAL EVIDENCE
Innovation is cumulative/collective — shows why Survey data: 25 banks + 58–64 NBFCs reporting
it is fast and hard to predict actual experience of digital transformation
Speed and scope distinguish current FinTech Specific data: BNPL growth projections, cyber risk
from earlier financial technology survey trends, UPI downtime statistics
Three regulatory principles: Innovation + Non- Specific policy responses mapping to each
Disruptive Assimilation + Consumer Protection principle (DLG cap, KFS, SRO-FT, cyber range)
"Sweet spot" of competition + collaboration as the Bank-led model data: FinTechs as LSPs —
optimal FinTech-bank relationship India's mechanism for achieving the sweet spot
structurally
SROs as solution to the knowledge gap between SRO-FT Framework (May 2024): operationalises
regulators and industry Rabi Sankar's prescription
Regulatory arbitrage and deposit NBFC regulation of non-banks; bank-led lending
disintermediation as structural risks model — India's structural mitigants
Consumer protection as core principle alongside Dark patterns, BNPL risks, social contagion — the
innovation empirical evidence for why CP cannot be an
afterthought
F.2 Connecting Week 3 to Weeks 1 and 2
WEEK 1 CONCEPT WEEK 2 CONCEPT WEEK 3 DEVELOPMENT
FinTech's 5-category taxonomy RBI's financial stability as north Stability vs. innovation tension:
(products) star how specific FinTech products
(P2P, digital lending, BNPL,
payment wallets) threaten
stability if unregulated
P2P lending — disintermediates Tiered regulatory approach P2P → NBFC-P2P classification
banks (disclosure → supervision) (2017): the tiered approach in
practice
Regulatory perimeter problem Boundary problem as regulatory Regulatory arbitrage: the
(FinTech beyond perimeter) challenge concrete consequences of
FinTech operating beyond the
perimeter
India's FinTech opportunity: Financial inclusion as socio- Consumer protection risks
unbanked, 87% cash economic objective specific to newly included
populations: dark patterns,
BNPL, digital fraud — the
inclusion-protection tension
Blockchain/DLT potential Innovation-stability trade-off Concentration risk via third-party
(Malhotra) providers: new systemic risk
channel created by shared
infrastructure
Big Data and AI in FinTech Evidence-based regulation Algorithmic bias and financial
principle exclusion: AI creates new
consumer protection problems
that regulation must address
PART G: EXAMINATION PREPARATION
G.1 Key Definitions and Concepts to Master
• Regulatory Arbitrage: Structuring activities to exploit gaps, inconsistencies, or differences
between regulatory regimes — obtaining the economic benefits of a regulated activity
while avoiding its costs and obligations.
• Deposit Disintermediation: The process by which funds move away from bank deposits
into alternative digital savings, investment, or payment instruments — reducing banks'
low-cost funding base and the effectiveness of deposit-based regulatory frameworks.
• Three Principles of RBI FinTech Regulation (Sankar): (1) Encouragement of innovation;
(2) Assimilation of innovation in a non-disruptive manner; (3) Customer protection.
• Dark Patterns: Deceptive design practices in user interfaces or user experiences that
mislead users into making decisions detrimental to their interests — subverting consumer
autonomy, decision-making, or choice without outright lying.
• Social Contagion in Finance: The rapid viral spread of financial trends, recommendations,
or panic through social media platforms — leading to herd behaviour, amplified market
volatility, and accelerated bank run dynamics.
• Buy-Now-Pay-Later (BNPL): Digital deferred payment product allowing consumers to
purchase goods and pay in instalments — risks include no credit check, multiple
concurrent use, late-fee dependency, and impulsive spending facilitation.
• Lending Service Provider (LSP): A FinTech entity that sources loan customers and
provides loan origination technology, but does NOT fund loans on its own balance sheet
— the funded lending is done by a Regulated Entity (bank/NBFC). India's key structural
mechanism to prevent digital lending regulatory arbitrage.
• Concentration Risk: Systemic risk arising not from financial inter-linkages but from shared
technological infrastructure (e.g., cloud providers) — a single failure can cascade across
multiple regulated entities.
• Algorithmic Bias: Systematic, unjustifiable discrimination in AI/ML credit or pricing
decisions that disadvantages certain demographic groups — without the transparent
human judgment that traditional underwriting provides.
• Operational Resilience: The ability of a financial institution to identify, protect against,
detect, respond to, and recover from technology and cyber incidents while continuing to
deliver critical operations.
G.2 Likely Exam Questions and Approaches
Q1: "What is regulatory arbitrage in the context of FinTech? How does it arise and what
are its consequences?"
Approach: Define regulatory arbitrage. Explain the four specific mechanisms (activity-entity gap,
sectoral boundary gap, entity classification gap, intermediation chain fragmentation) with
examples. Discuss consequences: unlevel playing field for banks; systemic risk accumulation
without regulatory buffer; consumer protection gaps; deposit disintermediation. Discuss India's
mitigants: NBFC classification, bank-led lending model (LSP structure), tiered regulation.
Q2: "Critically examine the three tensions FinTech creates for financial regulators."
Approach: Structure around three tensions. (1) Innovation vs. Stability: Speed/scope problem;
regulatory lag; knowledge asymmetry; concentration risk via third-party providers. Use Rabi
Sankar + RBI Report data. (2) Regulatory Arbitrage: Mechanisms; consequences; India's
structural responses. (3) Consumer Protection: Dark patterns, BNPL, social contagion, data
over-collection — each with specific India data. Conclude with Rabi Sankar's three-principle
framework as the regulatory response architecture.
Q3: "What is meant by the 'sweet spot' in FinTech regulation? Discuss with reference to
the competition-collaboration relationship between FinTechs and banks."
Approach: Define the sweet spot (Rabi Sankar's concept). Explain why pure competition is
insufficient (FinTechs can take regulatory shortcuts; banks face unfair competition; systemic risk
if FinTechs are unregulated). Explain why pure collaboration is insufficient (reduces competitive
pressure; may lead to cartelisation; FinTech innovation may be absorbed rather than
transformative). Use India's LSP model as the structural embodiment of the sweet spot. Use
Digital Lending Guidelines as the regulatory framework enabling this balance.
Q4: "Discuss the consumer protection challenges arising from FinTech digitalisation.
How has RBI responded?"
Approach: Identify four categories of challenge: (1) Conduct harms (dark patterns, mis-selling,
data over-collection); (2) Debt traps (BNPL, digital lending with exorbitant rates, coercive
recovery); (3) Behavioural risks (social contagion, herd behaviour, impulsive spending); (4) Data
risks (excessive data collection, privacy breaches). For each, give specific India data from RBI
2024 Report. Regulatory responses: Digital Lending Guidelines 2022 (KFS, data minimisation,
grievance redress); DPDP Act 2023; CCPA Dark Patterns Guidelines 2023; SRO-FT; RB-IOS
Ombudsman Scheme.
Q5: "How does digitalisation affect financial stability? What specific risks has the RBI
identified, and how are they being addressed?"
Approach: Present the dual face — stabilising effects (diversification, efficiency, transparency,
liquidity, inclusion) AND destabilising effects (cyber risk, third-party concentration, contagion,
algorithmic correlation, pro-cyclicality). Use the RBI 2024 Report's Table V.1 structure. Focus
particularly on: (a) cyber risk (consistently rising since 2020 per systemic risk surveys, BFSI as
major target); (b) concentration risk via cloud providers; (c) social media amplification of bank
runs (SVB example). RBI policy responses: Outsourcing Master Directions (6-hour cyber
incident reporting), Operational Resilience Note, Digital Payments Intelligence Platform, cyber
range.
G.3 Common Misconceptions to Avoid
• ❌ "Regulatory arbitrage is illegal" — WRONG. It is often entirely legal — entities structure
activities within the law to minimise regulatory burden. The problem is not illegality but the
systemic consequences of regulatory gaps being exploited.
• ❌ "FinTechs in India lend on their own balance sheets like P2P platforms do globally" —
WRONG. In India, FinTechs act as LSPs (Lending Service Providers). Only Regulated
Entities (banks and NBFCs) fund loans. FinTechs cannot lend on their own balance sheets
— this is a critical India-specific regulatory design choice.
• ❌ "Dark patterns are just about bad UX design" — WRONG. Dark patterns are specifically
designed to subvert consumer decision-making. They exploit cognitive biases deliberately.
They are a consumer protection and regulatory compliance issue, not just a design quality
issue.
• ❌ "BNPL is unregulated in India" — WRONG. RBI treats BNPL as a credit product
requiring similar due diligence and credit appraisal as other loans. This is different from
many other jurisdictions where BNPL operates outside credit regulation.
• ❌ "Rabi Sankar says FinTechs should replace banks" — WRONG. He explicitly argues for
the "sweet spot" of FinTechs acting as both competitors AND collaborators — with
traditional banks remaining the core of regulated financial intermediation (balance sheets,
capital, risk management), while FinTechs provide agility and innovation.
• ❌ "Cyber risk only affects individual institutions" — WRONG. The RBI 2024 Report
specifically identifies macro-financial stability risks from shared third-party infrastructure. A
single cloud provider failure can create systemic disruption — a new category of systemic
risk.
PART H: VIDEO NOTES — HKU FinTech, "India: The
Regulatory Landscape for FinTech, Digital Assets &
Payment Systems" (2023)
📺 VIDEO REFERENCE: HKU FinTech — "India: The Regulatory Landscape for FinTech,
Digital Assets & Payment Systems" (2023) | YouTube: [Link]
This video is produced by HKU FinTech — the University of Hong Kong's FinTech research and
education centre led by Professor Douglas Arner, one of the world's foremost scholars on
FinTech regulation. The video provides an external, comparative perspective on India's FinTech
regulatory landscape — viewing India's regulatory architecture from the vantage point of
international FinTech law scholars. This gives it a distinct value compared to the RBI speeches
in this week's primary readings, which are from regulators themselves. The HKU lens highlights
how India's approach looks from a comparative regulatory law standpoint.
📌 WHY THIS VIDEO MATTERS FOR WEEK 3
The HKU FinTech video provides the comparative and international dimension that the
Indian regulatory speeches (Rabi Sankar, RBI Report) do not supply. It places India's
regulatory landscape in global context — showing how India's multi-regulator structure, its
digital assets/crypto approach, and its payment system architecture compare with
international norms. This comparative lens is essential for answering exam questions that
ask how India's FinTech regulation compares globally, or what lessons India can learn
from (or offer to) other jurisdictions.
H.1 India's Multi-Regulator Landscape — The Institutional
Architecture
The foundational premise of the HKU video is that India's FinTech regulatory landscape is
uniquely complex because no single regulator has jurisdiction over all FinTech activities. The
regulatory architecture is built around multiple sector-specific regulators, each with statutory
authority over a distinct domain:
REGUL STATUTORY FINTECH KEY FINTECH ACTIONS
ATOR AUTHORITY JURISDICTION
Reserve RBI Act 1934; Payments, digital Digital Lending Guidelines (2022); NBFC
Bank of Banking lending, NBFCs, P2P Scale-Based Regulation; P2P Master
India Regulation Act lending, Account Directions; Regulatory Sandbox; UPI
(RBI) 1949; Payment Aggregators, CBDC, oversight via NPCI
and Settlement cross-border payments
Systems Act
2007
SEBI SEBI Act 1992; Investment platforms, Execution-Only Platform framework (2023);
(Securitie Securities robo-advisors, Algo trading guidelines; mutual fund
s and Contracts crowdfunding (equity), distribution digitisation
Exchang Regulation Act securities exchanges,
e Board algo-trading, digital
of India) brokers
IRDAI Insurance Act InsurTech, digital Insurance Web Aggregators Regulations;
(Insuranc 1938; IRDAI Act insurance distribution, digital health insurance; IoT-based
e 1999 web aggregators, insurance products
Regulator embedded insurance
y and
Develop
ment
Authority)
PFRDA PFRDA Act Digital pension e-NPS (electronic National Pension
(Pension 2013 management, NPS System); digital pension statements
Fund technology platforms
Regulator
y and
Develop
ment
Authority)
NPCI Operates under UPI, RuPay, IMPS, Manages the technical infrastructure for
(National RBI oversight AePS, BBPS, NACH, India's retail payment systems; not a
Payment NETC (National statutory regulator
s Electronic Toll
Corporati Collection)
on of
India)
MeitY IT Act 2000; Data governance, DPDP Act 2023; IT Security Rules; Digital
(Ministry DPDP Act 2023 cybersecurity, digital India programme
of identity (Aadhaar)
Electronic
s and
Informati
on
Technolo
gy)
CCI Competition Act Anti-trust in digital Digital Markets and Data Unit (2023);
(Competit 2002 payments, data investigation into UPI concentration;
ion markets monitoring BigTech in payments
Commissi
on of
India)
📌 THE MULTI-REGULATOR COORDINATION PROBLEM
India's multi-regulator structure creates a specific coordination challenge for FinTechs: a
single FinTech platform may simultaneously require RBI authorisation (for payment
functions), SEBI registration (if it distributes securities/mutual funds), IRDAI approval (if it
distributes insurance), and compliance with MeitY/DPDP Act (for data). There is no single
FinTech licence or "one-stop" authorisation. The FSDC (Financial Stability and
Development Council), chaired by the Finance Minister with all regulators as members,
provides the inter-regulatory coordination forum — but does not substitute for each
individual regulator's requirements.
H.2 Payment Systems Regulation — India's Foundational Strength
The HKU video identifies India's payment system regulatory architecture as one of its greatest
comparative strengths. The Payment and Settlement Systems Act (PSSA) 2007 gives RBI clear
statutory authority to regulate and supervise all payment systems — providing a solid legal
foundation that many developing countries lack.
Key layers of India's payment system regulatory architecture:
• PSSA 2007 (statutory foundation): Provides RBI with explicit authority to authorise,
regulate, and supervise payment systems. All payment system operators (banks and non-
banks) must obtain RBI authorisation.
• NPCI (National Payments Corporation of India): A non-profit company promoted by RBI
and major Indian banks. Manages retail payment infrastructure — UPI, RuPay, IMPS,
NACH, AePS, BBPS. Operates as an "infrastructure as a public good" model.
• Payment Aggregators (PAs): Entities that collect payments from customers on behalf of
merchants and settle with them. Subject to RBI's Payment Aggregator Guidelines (2020)
— licensed, minimum net worth ₹25 crore (rising to ₹100 crore).
• Payment Gateways (PGs): Provide technical infrastructure for routing payment
transactions. Do not hold funds. Lighter regulation than PAs.
• Cross-Border PA Framework (October 2023): New RBI framework liberalising cross-
border e-commerce payments through licensed Cross-Border Payment Aggregators —
replacing the earlier OPGSP framework.
• Prepaid Payment Instruments (PPIs): Wallets and prepaid cards regulated by RBI.
Interoperability mandated — all full-KYC wallets must allow UPI-based transactions.
• UPI's global expansion: RuPay cards and UPI accepted in UAE, Singapore, Bhutan,
Mauritius, Nepal, France, UK and other countries — India's payment infrastructure being
internationalised.
H.3 Digital Assets and Cryptocurrency — India's Cautious and
Evolving Stance
The HKU FinTech video gives significant attention to India's approach to digital
assets/cryptocurrencies — which represents one of the most contested and complex areas of
India's FinTech regulatory landscape. This contrasts with the RBI primary speeches that are
more focused on the payments/lending/DPI dimensions.
India's cryptocurrency regulatory journey — a timeline of contested positions:
• 2018 (RBI Circular): RBI issued a circular directing all regulated entities to stop providing
services to cryptocurrency businesses — effectively cutting off crypto exchanges from the
banking system.
• 2020 (Supreme Court): Internet and Mobile Association of India v. RBI — the Supreme
Court struck down the 2018 RBI circular as unconstitutional (disproportionate), holding that
it violated the right to practise any trade or profession. Banking services to crypto
exchanges were restored.
• 2022 (Taxation): Union Budget 2022 introduced a 30% flat tax on income from "Virtual
Digital Assets" (VDAs) and a 1% Tax Deducted at Source (TDS) on all VDA transactions
above a threshold. This signalled the government's de facto acceptance of crypto as a
taxable asset class — even without formal regulatory legalisation.
• 2023 (PMLA): From March 2023, entities dealing in VDAs (crypto exchanges, custodians,
wallet providers) were brought under the Prevention of Money Laundering Act (PMLA)
2002. This requires mandatory registration with the Financial Intelligence Unit (FIU), KYC
compliance, transaction record maintenance, and suspicious transaction reporting. This
was a major step toward formalising crypto oversight.
• 2021 (Crypto Bill never tabled): A "Cryptocurrency and Regulation of Official Digital
Currency Bill, 2021" was listed for introduction in Parliament — which reportedly proposed
banning private cryptocurrencies — but was never tabled. No formal crypto legislation has
been enacted.
• Current position: No comprehensive crypto regulation exists. The government has
indicated future legislation may depend on the development of a global regulatory
consensus. India is waiting for multilateral coordination (G20, FSB, IMF) before committing
to a domestic crypto framework.
💡 EXAMPLE: India's VDA Tax as Regulatory Signal
India's 30% flat tax on VDA income is globally one of the harshest crypto tax regimes.
The 1% TDS created such significant friction that crypto trading volumes on Indian
exchanges reportedly dropped by 90%+ in the months after implementation (2022). This
is an example of using tax as a de facto regulatory tool — neither banning nor formally
regulating, but creating strong economic disincentives. The HKU comparative lens helps
understand this approach: India is using fiscal policy to create a "managed tolerance" of
crypto rather than either the permissive approach (El Salvador making Bitcoin legal
tender) or the prohibitive approach (China's outright ban).
Central Bank Digital Currency (CBDC) — Digital Rupee (e₹):
India's approach to CBDC is clearly differentiated from its approach to private crypto. The Digital
Rupee is actively promoted as the sovereign alternative to private cryptocurrencies — offering
the digital convenience of crypto with full regulatory backing and legal tender status. This
dichotomy (cautious on private crypto, proactive on CBDC) reflects RBI's concern about
monetary sovereignty and financial stability.
• Wholesale CBDC (e₹-W) pilot: Launched November 2022; used for settling government
securities transactions between banks.
• Retail CBDC (e₹-R) pilot: Launched December 2022; 19 banks; 7 million users by October
2025; P2P and P2M transactions; interoperable with UPI.
• RBI's stated objective: Reduce costs of physical cash management; provide a legal tender
digital option; enable programmable payments; improve cross-border payment efficiency.
H.4 India's Digital Lending Regulatory Framework — A Comparative
View
The HKU video contextualises India's digital lending regulation within global standards — noting
that India's bank-led (LSP) model is actually more conservative and more protective than
approaches in many other jurisdictions.
GLOBAL DIGITAL LENDING MODELS INDIA's SPECIFIC APPROACH
Some jurisdictions allow FinTechs to lend directly FinTechs CANNOT lend on their own balance
on their own balance sheets (US marketplace sheets — they act only as Lending Service
lenders, Chinese P2P) Providers (LSPs). Only RBI-regulated entities
(banks and NBFCs) can fund loans.
P2P lending operates with relatively light NBFC-P2P classification (2017) — India was
regulation in many countries among first major economies to comprehensively
regulate P2P within an existing framework. Cap
on lending per lender per platform: ₹50 lakh.
BNPL often avoids credit regulation by being RBI treats BNPL as a credit product requiring full
structured as merchant credit credit appraisal — closing the BNPL regulatory
arbitrage.
Data access by lending apps often poorly Digital Lending Guidelines (2022) explicitly
governed prohibit access to data not strictly necessary for
credit assessment; all money flows through RE
accounts; KFS mandatory.
Account Aggregator equivalent in EU (PSD2 India's AA framework is consent-based with
Open Banking) gives data access to anyone who stronger privacy protections; AAs cannot read
registers data, only route it; FIU must be regulated entity.
H.5 Key Observations from the HKU Comparative Lens
The HKU FinTech perspective adds value by situating India's regulatory choices in a global
comparative context. Key observations the video-level analysis provides:
• India as a regulatory laboratory: India's scale (1.4 billion people, 490 million UPI users, 20
billion monthly transactions) means its FinTech regulatory experiments are watched
globally. The account aggregator model, NBFC-P2P structure, and bank-led lending model
are being studied by regulators in Southeast Asia, Africa, and Latin America.
• "Same activity, same risk, same regulation" principle: The HKU research tradition
(particularly from Professor Douglas Arner and colleagues) strongly advocates this
principle — that regulatory treatment should follow economic function, not legal form.
India's NBFC-P2P rules and Digital Lending Guidelines are consistent with this principle;
the BNPL-as-credit-product treatment is another example.
• India's approach to crypto vs. global norms: Globally, two models are emerging —
comprehensive licensing (UK, EU MiCA, Singapore) or de facto prohibition (China). India
sits in an unclear middle position: taxing crypto, applying AML rules, but having no
licensing framework. This creates regulatory uncertainty that may constrain legitimate
innovation while not effectively preventing misuse.
• Internationalisation of India's payment infrastructure: UPI's expansion to 10+ countries and
RuPay's international acceptance are making India's payment infrastructure a de facto
regional standard. This creates new regulatory questions: how should cross-border
payment disputes be resolved? What data flows across borders? How does
interoperability with foreign systems affect India's data localisation policy?
• Absence of single FinTech legislation: Unlike some jurisdictions that have created
omnibus FinTech acts, India's regulation is composed of multiple sector-specific laws. This
creates flexibility but also fragmentation, overlap, and compliance complexity. Whether
India needs a "Unified FinTech Act" is an active policy debate.
📌 CONNECTING THE HKU VIDEO TO THE PRIMARY READINGS
The HKU video provides the institutional map (who regulates what in India); the primary
readings (Rabi Sankar + RBI Report) provide the regulatory philosophy (why regulation
works the way it does) and the evidence base (what risks have emerged and how they
are being managed). Together they give: (a) the structural architecture (HKU); (b) the
regulatory principles and tensions (Rabi Sankar); (c) the empirical experience (RBI 2024
Report). All three are needed for a complete understanding of India's FinTech regulatory
landscape.
PART I: QUICK REVISION SUMMARY
WEEK 3 IN ONE VIEW: THREE TENSIONS + THREE PRINCIPLES + KEY EMPIRICAL
EVIDENCE
WHY CURRENT FINTECH IS DIFFERENT → Speed + Scope (Rabi Sankar); Regulation
lags structurally THREE TENSIONS → Regulatory Arbitrage | Innovation vs. Stability |
Consumer Protection THREE RBI FINTECH PRINCIPLES (Sankar) → Encourage
Innovation | Non-Disruptive Assimilation | Customer Protection REGULATORY
ARBITRAGE → Activity-entity gap; sectoral boundary gap; entity class gap;
intermediation chain fragmentation. India mitigant: NBFC/LSP model DEPOSIT
DISINTERMEDIATION → Wallets/MFs drawing funds from banks; structural threat to
bank funding model "SWEET SPOT" → FinTechs as competitor AND collaborator; banks
= balance sheet + risk mgmt; FinTechs = agility + UX CONSUMER RISKS (RBI 2024) →
Dark Patterns (CCPA Guidelines 2023) | BNPL debt traps | Social contagion + digital
bank runs | Data over-collection DIGITAL LENDING GUARDRAILS → Digital Lending
Guidelines 2022: KFS, data minimisation, no coercive recovery, DLG cap 5%, RE
remains accountable STABILITY RISKS (RBI 2024) → Cyber risk (rising since 2020);
third-party concentration; contagion via algorithms; social media bank runs (SVB) SROs
→ Knowledge gap solution; industry sets own rules; SRO-FT Framework (May 2024) —
preview of Week 4 MULTI-REGULATOR LANDSCAPE (HKU) → RBI
(payments/lending/NBFCs) | SEBI (securities/investment) | IRDAI (insurance) | PFRDA
(pensions) | NPCI (infrastructure) | MeitY (data) | CCI (competition). FSDC = coordination
forum DIGITAL ASSETS INDIA (HKU) → No comprehensive crypto law. Taxed at 30% +
1% TDS; PMLA applies since March 2023. Supreme Court 2020 struck down RBI's 2018
banking ban. CBDC (Digital Rupee) actively promoted as sovereign alternative "SAME
ACTIVITY, SAME RISK, SAME REGULATION" → Principle from HKU research tradition
(Arner et al.); embodied in India's NBFC-P2P rules, Digital Lending Guidelines, BNPL-as-
credit treatment
Academic Notes | Module 1 — Week 3 | Primary Sources: T Rabi Sankar, "FinTech Innovation and Approach to
Regulation," GFF Keynote (September 5, 2023) | RBI Report on Currency and Finance 2023–2024, Chapter V:
"Digitalisation: Tackling Emerging Risks and Challenges" | HKU FinTech, "India: The Regulatory Landscape for
FinTech, Digital Assets & Payment Systems" (2023)