Regulation WatchAug 27, 2024 · 3 min read

RBI Names FACE as Fintech's First Self-Regulatory Body: What It Means for App Teams

In August 2024, the RBI granted self-regulatory-organisation status to FACE. It's an industry-body announcement, not a direct app requirement — but it usually ends up in your onboarding and grievance flows anyway.


In August 2024, the Reserve Bank of India granted self-regulatory-organisation (SRO) status to the Fintech Association for Consumer Empowerment (FACE) — the first body of its kind recognised for the fintech sector. It read, on the day, like a B2B industry announcement with nothing to do with a mobile team's sprint board. In practice, SRO frameworks have a habit of showing up in app UX within a year or two of being announced, so it's worth understanding what one actually is before it does.

What an SRO actually does #

An RBI-recognised SRO sits between the regulator and its member companies. Instead of the RBI writing and enforcing every operational rule directly, the SRO is trusted to set a code of conduct for its members, run a grievance-redressal mechanism, and act as a first line of standard-setting — with the regulator stepping back in when self-governance isn't enough.

For member fintechs, that typically translates into a handful of concrete obligations over time:

  • A published code of conduct covering things like fair lending practices, marketing claims, and dark-pattern restrictions in onboarding flows.
  • A grievance-redressal mechanism — often a defined escalation path and response-time commitment that has to be visible and accessible inside the app, not just on a website.
  • Baseline data-handling and consent standards that tend to run ahead of, and later converge with, whatever statutory data protection law is in force (India's DPDP framework among them).

Why a mobile team should care now, not later #

None of this is a direct legal requirement on day one — SRO status is about industry self-governance, not a new RBI circular with a compliance deadline. But the pattern with self-regulatory bodies is consistent: standards they publish tend to get referenced in the RBI's own guidance within a release cycle or two, at which point they stop being optional. Teams that treat the SRO's code of conduct as a preview of where requirements are headed — and build the grievance-redressal entry point, the consent language, the marketing-copy review step now — spend a lot less time retrofitting later.

Compliance note

If your app operates in India's digital lending or payments space, it's worth checking whether your backend/compliance partner is a FACE member and, if so, actually reading their published member code — not just filing it away. The parts that touch UX (grievance visibility, consent clarity, marketing claims) are the parts a mobile team implements, and they're usually more specific than the underlying RBI circular.

The practical checklist #

  1. Confirm whether your organisation (or your lending/BNPL partner) is a FACE member, and if so, get the current code of conduct in front of whoever owns your onboarding flow.
  2. Make sure there's a real, reachable grievance path inside the app — not just a support email buried three menus deep.
  3. Treat this as a leading indicator, not a deadline. The teams caught scrambling later are usually the ones who waited for a specific circular instead of reading the direction of travel.

This is the first post in an ongoing regulation-watch series — the goal is to flag what's changing while there's still runway to act on it, not after.

Stuck on this in your own app?

This is the kind of problem I help fintech teams get right the first time — see how App Architecture & Consulting engagements work, or just tell me what you're building.