RBI’s 2026 Responsible Business Conduct Directions for Banks: Detailed Compliance Overview
The Reserve Bank of India has significantly overhauled the regulatory framework governing how commercial banks advertise, market, and sell financial products and services. Through the “Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Second Amendment Directions, 2026”, the RBI has laid down a uniform conduct framework for banks, emphatically targeting mis-selling, dark patterns in digital interfaces, compulsory product bundling, and lax oversight of DSAs / DMAs.
These Amendment Directions, issued under Section 35A of the Banking Regulation Act, 1949, modify the existing “Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Directions, 2025” and will apply to all Commercial Banks (other than Small Finance Banks, Payments Banks, Regional Rural Banks, and Local Area Banks) from January 1, 2027.
1. Statutory Basis, Scope and Effective Date
1.1 Legal Authority
The Reserve Bank has invoked powers under Section 35A of the Banking Regulation Act, 1949, being satisfied that such measures are required in the public interest. The amendments are binding Directions on all covered commercial banks.
1.2 Applicability
The Directions apply to:
- All Commercial Banks
- Excluding:
- Small Finance Banks
- Payments Banks
- Regional Rural Banks
- Local Area Banks
These entities are collectively referred to as “banks” and individually as a “bank” in the Directions.
1.3 Commencement
- The instrument is titled:
“Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Second Amendment Directions, 2026”. - The Directions take effect from January 1, 2027.
They modify and supplement the framework first laid down in the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Directions, 2025, and sit alongside the Reserve Bank of India (Commercial Banks – Undertaking of Financial Services) Directions, 2025.
2. Key New Definitions Introduced
Several critical definitions are inserted into paragraph 4 of the 2025 Directions to clarify the regulatory expectations.
2.1 Compulsory Bundling – 4(6A)
“Compulsory bundling” refers to a situation where a bank makes the availability of one product or service contingent on the customer agreeing to purchase another product or service (whether the bank’s own or a third-party product) offered through the bank.
This directly targets practices where customers are forced to buy insurance, add-on services, or allied products as a pre-condition to availing core banking products.
2.2 Dark Pattern – 4(10.1A)
“Dark pattern” is defined as any deceptive design in the user interface or user experience on any platform that:
- Misleads or tricks a user into an action they did not intend,
- Undermines or impairs customer autonomy, choice or decision-making, and
- Amounts to misleading advertisement, unfair trade practice, or violation of consumer rights.
This definition is broad and explicitly aligns with consumer protection concepts around unfair digital practices.
2.3 DSA / DMA and Sub-agents – 4(10B) and 4(10C)
4(10B)Direct Selling Agent (DSA) / Direct Marketing Agent (DMA)Any non-employee entity or individual engaged by a bank—regardless of contractual label such as Business Correspondent (BC), Loan Service Provider (LSP), etc.—to sell, market, promote or influence customers to purchase the bank’s own or third-party products or services.
4(10C)DSA / DMA sub-agentAny individual appointed by a DSA / DMA who directly interacts with customers for selling or marketing on behalf of the bank.
Explanation: If a bank directly outsources selling / marketing activities to an individual, that person is treated the same as both DSA / DMA and DSA / DMA sub-agent for the purpose of these Directions.
2.4 Explicit Consent – 4(13A)
“Explicit consent” means a clear, specific and informed indication of a customer’s choice, expressed through:
- A recorded statement, or
- A clear affirmative act (digitally or physically)
which authorises a particular action by or arrangement with a bank.
2.5 Mis-selling – 4(20A)
“Mis-selling” is expansively defined to cover sale of own or third-party financial products/services where:
- The product or service is neither suitable nor appropriate for the customer’s profile at the time of sale, even if explicit consent exists; or
- Incorrect, incomplete, or misleading information is provided; or
- The sale occurs without explicit consent; or
- There is compulsory bundling with another product/service; or
- Any other element designated as “mis-selling” by the relevant financial sector regulator is involved.
This definition makes it clear that explicit consent alone is not sufficient; suitability and transparency are equally critical.
2.6 Third-party Product or Service (TPPS) – 4(26A)
“Third-party Product or Service (TPPS)” covers products or services offered by a bank to its customers on behalf of an external provider (TPPS Provider) under permitted agency or referral arrangements under the Reserve Bank of India (Commercial Banks – Undertaking of Financial Services) Directions, 2025.
3. New Chapter IV Insert: Customer Guidance & Protection – Section F
A comprehensive new section, “F. Advertising, Marketing and Sale of Financial Products / Services by Banks”, is introduced after paragraph 85.
3.1 Policy Framework – 85A – 85B
85A – Board-approved policy
Each bank must frame a thorough policy on advertising, marketing and sale of its own and third-party financial products, covering at least:
- Criteria for assessing suitability and appropriateness of products for customers,
- Structured customer feedback mechanisms, and
- Defined compensation framework for instances of mis-selling.