Every regulator a fintech lives under. In one platform.
RBI Cybersecurity Framework, CERT-In Directions, DPDP customer data, outsourcing register, STR/CTR. Ship fast, stay inspection-ready. No consultant on retainer. dcomply unifies every regulator into a single compliance calendar, one evidence locker, and a set of pre-built modules that fintechs and NBFCs actually operate day to day.
If any of this sounds familiar, you're in the right place.
These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.
You have three regulators watching, one compliance hire, and a board that wants a monthly report.
The last CERT-In incident took 14 hours to file because nobody was sure of the format.
Your outsourcing register lives in the same spreadsheet as your vendor invoices.
You raised your Series B on the strength of "compliance-ready" but you don't have the evidence to prove it in an audit.
For a pure regulator view, the RBI door and CERT-In door cover the specifics.
Here's what sits above the foundation.
A licensed fintech typically lives under five overlapping regulators at once. dcomply ships modules for each layer of the stack.
Four Overlapping Frameworks, One Audit Trail Required
The DPDP Act doesn't replace RBI rules. It adds to them. Most fintechs run a separate tool, person, or consultant for each.
DPDP Act 2023
Consent, DSR, breach notification, DPIA, cross-border transfers. All for the very same customer data your RBI rules govern.
RBI Cybersecurity Framework
55+ controls across NBFC-IT, KYC, outsourcing, digital lending, account aggregator and prepaid instrument norms.
CERT-In 6-hour Rule
Any cyber incident must reach CERT-In in 6 hours. Most teams find out 4 hours in.
Vendor / TPRM Push
RBI now expects an active sub-processor register, contract clauses, and an annual audit for every vendor touching customer data.
Every Fintech Module. Pre-Wired and DPDP-Mapped
Subscribe to dcomply Professional or above with the Finance & Tax pack and you get all of these. No three-month onboarding.
Consent Management
Multi-language consent, withdrawals, DSR portal with WhatsApp channel, breach log auto-graded for fines.
DPIA + Gap Assessment
Risk-scored DPIA generator, current-state gap assessment with ₹250 Cr exposure quantification.
RBI Cybersecurity Framework
All 55+ controls split by NBFC-IT, KYC, outsourcing, AA, digital lending. Scored, evidence-tracked, audit-ready.
NBFC Compliance Calendar
Auto-deadline tracker for monthly/quarterly/annual NBFC returns and statutory filings.
Outsourcing Register
Vendor list with sub-processor traceability, contract clauses, audit schedule.
44 Directions Library
Searchable database of 44 CERT-In directions with applicability flags and a 6-hour breach intake form.
Pentest Records
Track penetration tests, remediation status, retest cycles per CERT-In requirements.
SEBI CSCRF
Entity classification + 100+ control framework (where applicable to listed fintechs).
Vendor Risk + TPRM
Sub-processor register, processor audit log, contract DPA tracker.
Phishing + Awareness
Track staff phishing campaigns required by RBI CSF and ISO 27001.
ISO 27001 + SOC 2
Both control frameworks scored against your evidence locker.
Evidence Locker
One vault: policies, training records, incident logs, vendor reports. Linked to every control above.
From Surprise to Filing in 4 Hours
What happens when a breach hits, the regulator asks, or a quarterly audit lands.
What dcomply Replaces
| Regulator / Framework | Why It Hits You | dcomply Module |
|---|---|---|
| DPDP Act 2023 | You process personal data of Indian customers | Data Privacy pack (11 modules) |
| RBI CSF | NBFC, payment gateway, prepaid instrument, AA | RBI Compliance + CSF controls |
| RBI Outsourcing | Any vendor touching customer data | Outsourcing Register + Vendor TPRM |
| CERT-In | Cyber incident in any sector | 44 Directions + 6-hour intake |
| SEBI CSCRF | Listed fintechs + intermediaries | SEBI CSCRF module (100+ controls) |
| SEBI LODR | Listed company filings | SEBI LODR module |
| ISO 27001 | Investor + customer DD asks | ISO 27001 control assessment |
| SOC 2 | US enterprise customers | SOC 2 readiness module |
Don't have a DPO? Get a Virtual One.
DPDP Section 10 needs Significant Data Fiduciaries to appoint a DPO. Most fintechs don't have one full-time, and they don't want to.
dcomply vDPO bolts onto your tenant from ₹2,499/mo with AI Q&A, monthly DPO PDF, auto-DPIA triggers, and DSR auto-drafts. Standard tier adds a human checkpoint each month. Premium gives you a dedicated retained advocate-DPO.
See vDPO tiersAI for the daily work, monthly human checkpoint.
- Plain-English Q&A with DPDP/RBI/SEBI citations
- Monthly DPO PDF report
- DSR auto-draft
- Auto-DPIA trigger
- Breach triage assistant
- Monthly 30-min checkpoint with a vDPO consultant
Connectors that fit your stack.
Razorpay and LeadSquared run most Indian fintechs. dcomply plugs in on day one.
Questions fintech founders and CTOs actually ask.
The overlap between RBI, CERT-In, DPDP and SEBI creates specific edge cases. These are the ones we resolve on almost every fintech implementation.
"Compliance was one person plus a lawyer."
"We hit Series C at 14 people. Compliance was one person plus a lawyer. dcomply replaced eight tools and let us pass the RBI supplementary audit without hiring a second compliance manager."
Start Free. Scale When You're Ready.
Pay-per-module from ₹1,499. Finance & Tax pack from ₹9,999. vDPO from ₹2,499.