RBI Digital Lending Guidelines: What They Mean for Bank Statement Analysis
28 Sep 2026 — PRODUCT
SIGNALIQ

Article Overview:
The RBI digital lending guidelines, issued as the Reserve Bank of India (Digital Lending) Directions, 2025, came into force on 8 May 2025 and fold every digital lending circular since 2022, including the default loss guarantee norms, into one rulebook. The DLA reporting requirement on the CIMS portal applied from 15 June 2025, and the multi-lender rules from 1 November 2025. Three provisions land directly on bank statement analysis. Data collection through a digital lending app must be need-based, with prior explicit borrower consent and an audit trail. A lending service provider may store only minimal basic data, such as name, address and contact details. All borrower data must sit on India-based servers, and anything processed abroad must be deleted and repatriated within 24 hours. Apps can no longer read files or call logs, so pulling statements off a borrower device is out. Lenders must also assess age, occupation and income before approval, which makes income detection accuracy a compliance question. SignalIQ reads the full statement, including UPI narrations, to close that gap.
RBI Digital Lending Guidelines and What They Mean for Bank Statement Analysis#
Bank statement analysis used to be an operations problem. It is now a compliance one. The RBI digital lending guidelines, formally the Reserve Bank of India (Digital Lending) Directions, 2025, took effect on 8 May 2025 and repealed the 2022 digital lending framework along with the 2023 default loss guarantee guidelines. Two clauses matter more than the rest if you underwrite on transaction data. Data collection has to be need-based, consented and auditable. Income has to be assessed before you approve. Most parsers in production were built for neither, and the gap shows up in the bank statement analysis report an underwriter actually reads.
What is digital lending under the 2025 Directions?#
Short answer: the RBI defines digital lending as a remote, automated lending process covering customer acquisition, credit assessment, loan approval, disbursement, recovery and associated service. Asking what is digital lending in a regulatory sense now means asking which entity is accountable, because the answer is always the regulated entity.
- Applies to banks, NBFCs and other regulated entities lending through any digital channel
- Covers digital lending apps run by the regulated entity or by a lending service provider on its behalf
- The digital lending guidelines 2025 repeal and replace the 2022 framework, the outsourcing and fair practices instructions, and the 2023 DLG guidelines
- The RBI digital lending directions 2025 phased in DLA reporting on the CIMS portal by 15 June 2025 and multi-lender rules from 1 November 2025
- The regulated entity stays responsible for everything its LSP does, including how borrower data is handled
How does digital lending work under the new consent rules?#
If you are mapping how does digital lending work post-May 2025, the sequence is tighter than it was.
- The borrower makes a formal request, rather than the lender inferring intent from a blanket consent
- The app collects only need-based data, with prior explicit consent captured at every stage and logged as an audit trail
- Consent is granular and revocable, including a right to deletion
- The Key Fact Statement goes to the borrower before sanction, with APR and all charges stated
- A cooling-off period applies, reduced to one day under the 2025 Directions Nothing in that sequence rewards a pipeline that hoovers up data first and decides later what it needed.
Why bank statement analysis is now a compliance surface?#
The Directions set a floor for creditworthiness assessment: a regulated entity must collect age, occupation and income before approving a loan. That turns bank statement analysis for loan decisions into evidence, not a convenience. If your parser misses a rental credit or a UPI salary transfer, you have not just declined a good borrower, you have assessed income on partial data. The second constraint is how you get the statement. Lending apps are barred from reading files and call logs on a borrower device, which removes phone-side scraping as a route. Consented pulls and borrower-initiated uploads are what remains. This is why bank statement analysis in india is converging on consented data flows through Account Aggregator.
What changes inside a bank statement analysis report?#

The FOIR line is where this bites hardest. Anyone asking what is foir in loan terms is asking about the ratio of fixed obligations to income, and both sides of that ratio come from the statement. Miss income and FOIR inflates. Miss an obligation and it deflates.
Where legacy parsers fall short?#
Setu puts the number plainly: roughly 80% of a modern Indian bank statement is unstructured UPI narration that legacy parsers cannot read. Everything below follows from that single gap. A rent credit or freelance inflow arriving over UPI gets filed as TRANSFER/OTHERS, so income reads low An EMI paid through UPI to a lender handle is not recognised as an obligation, so risk reads low FOIR computed on that pair can swing past 100% on a borrower who is comfortably serviceable Thin-file and new-to-credit applicants lose the only evidence they had, which is behaviour rather than bureau history The fix is not more manual review. It is reading the whole statement, which is the argument for alternative data in credit decisions.
How SignalIQ works and helps with this situation?#
SignalIQ is Setu’s bank statement analyser, built to read the unstructured UPI narrations that make up most of the statement and turn them into structured credit insight. It works across three points in the lending lifecycle.
- Precision underwriting: granular categorisation separates true income from internal transfers, and tags secondary income such as rent, freelance payments and business inflows with recurrence, so income is assessed on the full picture rather than salary alone
- Predictive collections: pre-delinquency signals such as low-balance patterns, bounce charges and penalties surface before a default, along with the collection window where funds are actually present
- Personalised cross-sell: real payment behaviour drives offers, rather than a segment guess For compliance, the point is narrower. Need-based collection only works if the data you do collect is read completely, and an audit trail is only useful if the categorisation behind the decision can be explained. SignalIQ sits on Setu’s data and insights stack for exactly that.
See what your current parser is missing in every statement it reads. Explore SignalIQ
Conclusion#
The 2025 Directions did not ask lenders to collect less and decide worse. They asked for need-based collection, explicit consent, Indian data residency, and income assessed before approval. Each of those raises the cost of reading a bank statement badly, because partial data is no longer just a lost approval, it is a documented compliance gap. If your parser files most of the statement under other, that gap is already in your loan book. SignalIQ reads the full transaction set, including UPI narration, and returns income, obligations and early risk signals your credit team can actually defend in an audit. Visit the SignalIQ page to see how it fits your stack.



