
Banks and non-banking financial companies are undertaking a wholesale reset of their current terms of engagement with financial technology companies following the Reserve Bank of India's comprehensive data governance framework. According to Business Standard, stakeholders have opened talks with top-notch legal, consulting and regulatory technology firms to navigate the new regulatory landscape. The RBI's draft Guidance on Regulatory Expectations for Data Governance and the need to comply with the Digital Personal Data Protection Act 2023 and DPDP Rules 2025 have catalyzed this comprehensive review. The RBI's draft said regulated entities should put in place a data governance framework and align it with their risk management framework, with boards required to oversee the DGF and review reports and metrics annually or more frequently.
The regulatory changes are significantly affecting fintech funding patterns and valuations, with fintechs raising $822.9 million in 2026 to date, compared to $2.2 billion in 2024 and $2.4 billion in 2025. As reported by Business Standard, the number of funding rounds has narrowed from 379 in 2024 to 296 in 2025 and 60 in 2026, indicating that a smaller pool of firms is cornering the available funding. Industry experts note that compliance has become part of the cost of capital, with clean compliance posture now accelerating funding rounds and removing regulatory surprises as a deal-breaker. However, data from Tracxn shows that while funding may appear to be holding up, a granular reading shows the number of rounds lower for these timeframes, indicating investor preference for safe harbors amid the West Asia crisis and AI-driven business model shifts in developed markets.
The regulatory framework is driving fundamental changes in how financial institutions approach fintech partnerships. Sugandh Saxena, CEO of the Fintech Association for Consumer Empowerment (FACE), told Business Standard that "the partnerships between financial entities and fintechs are being revisited, with contracts being reworked." FACE, the first Mint Road-approved SRO for the sector, is engaging with members to support compliance with the DPDP Act. Senior bankers acknowledge that existing arrangements with fintechs have to be reviewed in light of regulatory expectations and the governance premium, which has moved up many notches. A key concern for legacy entities is that their data resides in silos, and reworking this architecture will be time-consuming, along with the challenge of onboarding independent directors. The RBI's outsourcing norms require REs to flow down appropriate risk-based obligations to fintech partners, calibrated to the functions outsourced and the risks involved.
The regulatory changes carry significant financial and reputational consequences for non-compliance. Penalties under the DPDP Rules, 2025, range from ₹50 crore to ₹250 crore and can extract severe costs on the reputational front. As noted by Trilegal partner Jishnu Sanyal, the penalty architecture reinforces the need for stronger internal controls and clearer contractual allocation between data fiduciaries and data processors, although the data fiduciary remains primarily responsible for compliance under the DPDP Act. Rohan Lakhaiyar from Grant Thornton Bharat emphasized that "Many partnerships are undergoing diagnostics and compliance evaluation. It is reset time for the industry, as the stakes are much higher now." The Indian Banks' Association and the Finance Industry Development Council are expected to play a role, as some changes may take time to implement. Raghuveer Kancherla from Sprinto noted that conversations with founders and compliance teams are no longer about navigating regulatory gaps, but about "embedding compliance into the product from day one" to avoid retrofitting costs that impact both operational efficiency and trust-building partnerships.