Fintech door. RBI + CERT-In + DPDP.

Every regulator a fintech lives under. In one platform.

RBI Cybersecurity Framework, CERT-In Directions, DPDP customer data, outsourcing register, STR/CTR. Ship fast, stay inspection-ready. No consultant on retainer. dcomply unifies every regulator into a single compliance calendar, one evidence locker, and a set of pre-built modules that fintechs and NBFCs actually operate day to day.

RBI CSF + DPDP + CERT-In in one vDPO addon from ₹2,499/mo No credit card to start
Live Fintech Compliance Snapshot
Acme Lending Pvt Ltd · NBFC-ICC
Compliance Score: 78/100 AMBER
───────────────────────────────
DPDP Act 2023 ............... 82%
RBI Cybersecurity Framework . 71%
CERT-In Directions .......... 88%
Outsourcing Register ........ 94%
Digital Lending Norms ....... 63%
───────────────────────────────
Open DSRs: 2 · Breach window: closing in 1h 12m
Powered by dcomply
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.

You have three regulators watching, one compliance hire, and a board that wants a monthly report.

The last CERT-In incident took 14 hours to file because nobody was sure of the format.

Your outsourcing register lives in the same spreadsheet as your vendor invoices.

You raised your Series B on the strength of "compliance-ready" but you don't have the evidence to prove it in an audit.

For a pure regulator view, the RBI door and CERT-In door cover the specifics.

Your regulator stack

Here's what sits above the foundation.

A licensed fintech typically lives under five overlapping regulators at once. dcomply ships modules for each layer of the stack.

SEBI (if listed)
CSCRF for cybersecurity, LODR quarterly disclosures, PIT for insider list.
PMLA (STR / CTR)
Suspicious and Cash Transaction Reports, AI-drafted narratives, PMLA format.
RBI Digital Lending / PA-PG (sector-specific)
Consent-based data access, key fact statement, cool-off period, no third-party servers outside India.
DPDP Act 2023
Customer data workflows, DSR portal, breach notification, 22 Indian language consent.
CERT-In Directions
6-hour incident reporting, 180-day log retention, KYC on VPN and crypto users.
RBI Cybersecurity Framework
The foundation for regulated entities. Base/mid/top layer classification, control library, inspection archive.
₹250 Cr
Max DPDP fine per violation
6 hours
CERT-In breach window
72 hours
DPB breach notification
55+
RBI CSF controls
Why Fintech Compliance is Brutal Right Now

Four Overlapping Frameworks, One Audit Trail Required

The DPDP Act doesn't replace RBI rules. It adds to them. Most fintechs run a separate tool, person, or consultant for each.

DPDP Act 2023

Consent, DSR, breach notification, DPIA, cross-border transfers. All for the very same customer data your RBI rules govern.

RBI Cybersecurity Framework

55+ controls across NBFC-IT, KYC, outsourcing, digital lending, account aggregator and prepaid instrument norms.

CERT-In 6-hour Rule

Any cyber incident must reach CERT-In in 6 hours. Most teams find out 4 hours in.

Vendor / TPRM Push

RBI now expects an active sub-processor register, contract clauses, and an annual audit for every vendor touching customer data.

In Your Tenant On Day One

Every Fintech Module. Pre-Wired and DPDP-Mapped

Subscribe to dcomply Professional or above with the Finance & Tax pack and you get all of these. No three-month onboarding.

DPDP Act
Consent Management

Multi-language consent, withdrawals, DSR portal with WhatsApp channel, breach log auto-graded for fines.

DPDP Act
DPIA + Gap Assessment

Risk-scored DPIA generator, current-state gap assessment with ₹250 Cr exposure quantification.

RBI
RBI Cybersecurity Framework

All 55+ controls split by NBFC-IT, KYC, outsourcing, AA, digital lending. Scored, evidence-tracked, audit-ready.

RBI
NBFC Compliance Calendar

Auto-deadline tracker for monthly/quarterly/annual NBFC returns and statutory filings.

RBI
Outsourcing Register

Vendor list with sub-processor traceability, contract clauses, audit schedule.

CERT-In
44 Directions Library

Searchable database of 44 CERT-In directions with applicability flags and a 6-hour breach intake form.

CERT-In
Pentest Records

Track penetration tests, remediation status, retest cycles per CERT-In requirements.

SEBI
SEBI CSCRF

Entity classification + 100+ control framework (where applicable to listed fintechs).

Vendor
Vendor Risk + TPRM

Sub-processor register, processor audit log, contract DPA tracker.

Security
Phishing + Awareness

Track staff phishing campaigns required by RBI CSF and ISO 27001.

ISO/SOC
ISO 27001 + SOC 2

Both control frameworks scored against your evidence locker.

Audit
Evidence Locker

One vault: policies, training records, incident logs, vendor reports. Linked to every control above.

A Day in The Compliance Officer's Life

From Surprise to Filing in 4 Hours

What happens when a breach hits, the regulator asks, or a quarterly audit lands.

09:14 AM
Detection Slack alert. SOC tool flags a payment-gateway misconfiguration leaking 4,200 customer records to a Slack webhook. dcomply opens a Breach Notification draft automatically (event ingested via webhook).
10:30 AM
CERT-In window open · 5h 30m left AI Triage Assistant scores severity, classifies the data principals, suggests Section 2 of CERT-In Form, prefills the 6-hour intake form. CISO reviews and submits in 12 minutes.
11:45 AM
DPB notification draft 72-hour clock countdown shown on dashboard. Auto-drafted DPB notice cites Section 8(6) and Rule 7. DPO reviews legal language, signs, sends.
12:30 PM
RBI parallel filing For Scheduled NBFCs: dcomply fires the RBI-CSF parallel notification draft (cyber incident reporting per master direction). Founder approves.
01:00 PM
Affected customer comms Mass-mailer pulls the 4,200 records, sends a localized email + WhatsApp notice with rights summary. All sends logged in Consent Withdrawal & DSR module for audit.
01:15 PM
Board pack One-click board update PDF: timeline, mitigation, financial exposure (₹17 Cr theoretical max), counsel notes, next-step checklist. CFO has it before the 2 PM board call.
Coverage By Regulator

What dcomply Replaces

Regulator / Framework Why It Hits You dcomply Module
DPDP Act 2023 You process personal data of Indian customers Data Privacy pack (11 modules)
RBI CSF NBFC, payment gateway, prepaid instrument, AA RBI Compliance + CSF controls
RBI Outsourcing Any vendor touching customer data Outsourcing Register + Vendor TPRM
CERT-In Cyber incident in any sector 44 Directions + 6-hour intake
SEBI CSCRF Listed fintechs + intermediaries SEBI CSCRF module (100+ controls)
SEBI LODR Listed company filings SEBI LODR module
ISO 27001 Investor + customer DD asks ISO 27001 control assessment
SOC 2 US enterprise customers SOC 2 readiness module
vDPO Addon

Don't have a DPO? Get a Virtual One.

DPDP Section 10 needs Significant Data Fiduciaries to appoint a DPO. Most fintechs don't have one full-time, and they don't want to.

dcomply vDPO bolts onto your tenant from ₹2,499/mo with AI Q&A, monthly DPO PDF, auto-DPIA triggers, and DSR auto-drafts. Standard tier adds a human checkpoint each month. Premium gives you a dedicated retained advocate-DPO.

See vDPO tiers
vDPO Standard ₹7,999/mo

AI for the daily work, monthly human checkpoint.

  • Plain-English Q&A with DPDP/RBI/SEBI citations
  • Monthly DPO PDF report
  • DSR auto-draft
  • Auto-DPIA trigger
  • Breach triage assistant
  • Monthly 30-min checkpoint with a vDPO consultant
Built for fintech

Connectors that fit your stack.

Razorpay and LeadSquared run most Indian fintechs. dcomply plugs in on day one.

Razorpay
Customer + payment PII discovery
LeadSquared
Lead module PII map
Zoho CRM
Indian DC supported
MySQL
Production DB scan
WhatsApp Business
DSR + reconsent outreach
Tally
GST + ledger compliance
Fintech compliance FAQs

Questions fintech founders and CTOs actually ask.

The overlap between RBI, CERT-In, DPDP and SEBI creates specific edge cases. These are the ones we resolve on almost every fintech implementation.

Indian fintechs and NBFCs face overlapping obligations across DPDP Act 2023 (data protection), RBI Cybersecurity Framework for NBFCs, RBI Digital Lending Guidelines 2022, SEBI CSCRF for market intermediaries, PMLA/KYC rules, and CERT-In's 6-hour breach reporting directive. dcomply unifies all of these into a single compliance calendar and evidence locker.

A layered IT security requirement issued by RBI in 2017 that classifies NBFCs into base, mid and top layers and prescribes controls proportional to size and risk, including a board-approved cybersecurity policy, VAPT twice a year, incident reporting to RBI within 2 to 6 hours, and a Cybersecurity Operations Centre for top-layer NBFCs.

When a triggering event occurs, dcomply's breach module pre-fills the CERT-In incident report format, timestamps the discovery moment for the 6-hour clock, routes it for CISO approval, and generates the submission-ready email with all mandatory fields including IP/URL, malware hashes and affected systems.

Yes. Every digital lender collecting borrower KYC, income proof, contact list access, location, SMS metadata or bank statement data is a Data Fiduciary under DPDP. RBI Digital Lending Guidelines add specific requirements: consent for storage on borrower devices, no third-party servers outside India, and audit trails for every field accessed.

RBI KYC Master Direction requires 5-year retention post account closure and 10-year for suspicious transactions. DPDP requires deletion when purpose is exhausted. The reconciliation is that dcomply flags accounts as legally retained under RBI post-closure but blocks any secondary use (marketing, profiling), a partial-anonymisation posture. Razorpay's DPDP loop in dcomply reflects this pattern.

Yes. dcomply supports AA participants with consent artefact templates aligned to ReBIT specifications, purpose-scoped consent tracking, and audit-log export in the AA-standard JSON schema. FIP and FIU roles are configurable per tenant.

If you are RBI-regulated, no. The CSF and CERT-In obligations apply from the day you are licensed. The Starter tier is designed for early-stage fintechs.

Yes. SEBI CSCRF and LODR are native modules.

Yes. The Vendor Risk module ships with the RBI-required fields and generates the register in the format inspectors expect.

dcomply's SOC 2 Readiness and ISO 27001 modules run in parallel, feeding the same evidence library. Common for fintechs raising international capital.

Modular. You pay for the modules you activate. Typical fintech setup: RBI plus CERT-In plus Vendor Risk plus DPDP plus STR/CTR.
Real teams, real programmes

"Compliance was one person plus a lawyer."

"We hit Series C at 14 people. Compliance was one person plus a lawyer. dcomply replaced eight tools and let us pass the RBI supplementary audit without hiring a second compliance manager."
CTO, a Bengaluru NBFC.

Start Free. Scale When You're Ready.

Pay-per-module from ₹1,499. Finance & Tax pack from ₹9,999. vDPO from ₹2,499.