RBI Digital Lending Rules: Designing the Key Fact Statement, Cooling-Off and Consent Screens

By September 20th, 2026No Comments

A borrower in Indore opens a lending app at 11 pm, taps through six screens in ninety seconds and has ₹40,000 in her account before midnight. Somewhere in those six screens the app told her the annual percentage rate, the processing fee, the penal charges, the name of the actual lender, the cooling-off window and the grievance officer’s phone number. She did not read any of it. RBI’s digital lending rules exist because of that ninety seconds. The rules say what the app must show her. Design decides whether she can see it.

The short answer: RBI’s digital lending framework puts five things in front of the borrower: a Key Fact Statement with the all-inclusive APR and every charge, a cooling-off period in which she can exit by repaying principal and proportionate interest without penalty, explicit and revocable consent for each piece of data the app collects, clear disclosure of who the lender is and who the app operator is, and a visible grievance officer. Each maps to a screen with a defined place in the flow. Designed well, the sequence is KFS before agreement, consent before data, lender name before the offer, and exit before repayment, with no dark pattern in any of them.

What does RBI’s digital lending framework require the borrower to see?

RBI issued its guidelines on digital lending in September 2022 and consolidated them into the Digital Lending Directions in 2025. They apply to every regulated entity that lends through an app or website, whether a bank, an NBFC or a small finance bank, and to the lending service providers (LSPs) and digital lending apps (DLAs) that operate on their behalf. The customer-facing obligations are the ones that turn into screens.

  • Key Fact Statement (KFS). A standardised statement given before the loan agreement is executed, in a language the borrower understands, showing the loan amount, tenor, interest rate, all fees and charges, the annual percentage rate (APR) as the all-inclusive cost, the repayment schedule, penal charges, the recovery mechanism, the cooling-off period and the grievance redressal contact. Any charge not in the KFS cannot be levied. The KFS has a validity period during which the borrower can accept the terms as stated.
  • Cooling-off (look-up) period. A window after disbursal, set by the lender’s board with a floor of three days for loans with a tenor of seven days or more and one day for shorter loans, in which the borrower can exit by repaying the principal and the proportionate APR with no penalty.
  • Explicit, need-based consent. The app may collect only the data it needs, with the borrower’s explicit prior consent for each purpose, the option to deny consent for specific data, and the ability to revoke consent and have data deleted. Apps cannot access the phone’s file and media, contact list, call logs or telephony functions. One-time access to camera, microphone and location is allowed only for onboarding and KYC, with consent.
  • Lender and LSP disclosure. The name of the regulated entity actually lending must be disclosed upfront, on the app, on the KFS and in the loan agreement, along with the LSP’s role. Where an LSP shows offers from several lenders, it must present a digital view of all matching offers with the lender’s name, amount, tenor, APR, monthly repayment and penal charges, in a consistent and unbiased order, with a link to each KFS.
  • Grievance officer. The nodal grievance redressal officer’s name and contact details must be displayed prominently on the app, the website and the KFS, along with the route to RBI’s Integrated Ombudsman if the complaint is not resolved.
  • Direct disbursal and repayment. Money moves only between the borrower’s bank account and the lender’s, never through the LSP’s account, and credit limits cannot be raised without the borrower’s explicit request.

The framework also uses the term “penal charges” rather than “penal interest”, following RBI’s 2023 instruction that penalties for non-compliance must be a charge, not a rate compounded into interest. That word choice has to be reflected on screen.

In what order should the screens appear?

Most compliance failures we see are sequencing failures. The disclosure exists, but it appears after the decision it was meant to inform. The rules imply an order, and the order is the design.

  1. Who is lending. Before any offer, the app states the regulated entity’s name and the LSP’s role. On a multi-lender platform, the offer list itself carries the lender name on every row.
  2. What data, and why. Consent screens appear before the permissions are requested, one purpose per request, with a deny option that does not end the journey unless the data is required for KYC.
  3. The offer. Amount, tenor, APR and monthly repayment, presented together. Not “₹40,000 approved” with the cost hidden behind a tap.
  4. The KFS. A single, scrollable statement in the prescribed format, with the APR computation visible, before the agreement. The borrower must be able to save or download it.
  5. The agreement and e-sign. After the KFS, never combined with it.
  6. Disbursal confirmation with the cooling-off notice. The confirmation screen states the cooling-off end date and how to exit, with the same prominence as the “money credited” message.
  7. Repayment and grievance, always reachable. Repayment schedule, prepayment, cooling-off exit and the grievance officer live in the persistent navigation, not in a settings sub-menu.

This sequence is slower than the ninety-second flow the growth team wants. It is also the flow that survives an RBI inspection and, in our experience, the flow that produces fewer first-EMI defaults, because the borrower understood the cost. The brand argument for this is in our post on lending app branding that reads as trustworthy, not predatory; this post is the screen-level version of it.

How should each screen be designed?

Below is the screen-by-screen table we use when we audit or design a lending flow. The right-hand column is the test the screen must pass.

Screen Must show Hierarchy and microcopy Passes if
Lender disclosure Regulated entity’s full name, LSP name and role Lender name in the same type size as the app’s brand on the first offer screen; “Loans provided by [NBFC], [App] is a lending service provider” A borrower can name the lender without scrolling
Consent (per purpose) What data, why, for how long, and how to revoke One request per screen or card; “Allow” and “Don’t allow” as equal-weight buttons; plain reason: “We use your location once to confirm your address for KYC” Denying non-essential data does not block the journey
Offer Amount, tenor, APR, monthly repayment, total repayable APR and monthly repayment in the same visual tier as the amount; the interest rate never shown alone; the tenor slider updates all four figures together Cost is legible on a 5-inch phone without a tap
Key Fact Statement The prescribed KFS format: all charges, APR computation, repayment schedule, penal charges, recovery mechanism, cooling-off, grievance contact Native scrollable screen, not a PDF thumbnail; section headers; a “Download KFS” action; a checkbox that is unchecked by default Every charge the lender will ever levy appears here
Agreement and e-sign Loan agreement, sanction letter, terms Separate from the KFS; the primary button reads “Sign agreement”, not “Get money” Signing cannot occur before the KFS is shown
Disbursal confirmation Amount credited, bank account, cooling-off end date and exit route Two messages of equal weight: “₹40,000 credited to your account ending 4821” and “You can exit this loan without penalty until [date]” The exit option is as visible as the credit message
Cooling-off exit Principal plus proportionate APR, computed; no penalty Reachable in two taps from home; the amount is calculated on screen, not “contact support”; confirmation is a single step Exiting is not harder than borrowing
Repayment Schedule, next due date, prepayment option, penal charges if any Penal charges named as charges with the amount; no “penal interest”; prepayment costs stated before confirmation No charge appears that was not in the KFS
Grievance Nodal officer name, phone, email; escalation to RBI Ombudsman Persistent “Help and complaints” entry in the main navigation; officer details as text, not an image; complaint reference number issued on submission Reachable from every screen in two taps
Data and consent management Every consent given, with revoke and delete options A single “Your data” screen listing each permission with a toggle and a “Delete my data” action with a plain explanation of consequences Revocation works and is confirmed on screen

What must not be dark-patterned?

RBI’s rules and the Central Consumer Protection Authority’s 2023 guidelines on dark patterns overlap on lending flows. The CCPA list names patterns such as false urgency, confirm-shaming, forced action, interface interference, drip pricing, nagging and trick questions. In a lending app, these show up in predictable places, and each one is a design decision that can go the other way.

  • Pre-ticked consent. The KFS acknowledgement and every data consent must be unchecked by default. A pre-ticked box is not explicit consent.
  • Unequal buttons. “Allow” in a filled brand-colour button and “Don’t allow” as grey 10-pt text is interface interference. Both options get the same visual weight.
  • Drip pricing. Showing “₹40,000 at 1.5% per month” and revealing the processing fee, GST and insurance add-on at the signing step. The APR exists precisely to prevent this; show it on the offer screen.
  • False urgency. “Offer expires in 09:59” countdowns on a credit offer. The KFS has a genuine validity period; a countdown that resets is a fabricated one.
  • Buried exit. The cooling-off right hidden in the agreement PDF and absent from the app. If exit takes more taps than borrowing, it is a dark pattern by design.
  • Confirm-shaming. “No, I don’t want to protect my family” as the decline copy on an optional insurance add-on. Decline copy is neutral: “Skip”.
  • Bundled optionals. Insurance or a subscription pre-selected inside the loan amount. Optional add-ons are opt-in, priced separately and excluded from the loan unless chosen.
  • Consent as a wall. Requesting contacts or SMS access “to speed up approval” and blocking the journey on refusal. Contacts and call logs cannot be accessed at all; other non-essential data cannot gate the loan.
  • Silent limit increases. A “Your limit has been raised to ₹1,00,000” push notification with the increase already applied. Limit increases need the borrower’s explicit request.
What we’ve learned across 320+ projects: the cooling-off screen is the truest test of a lending brand. Teams that design the exit with the same care as the offer end up with a flow regulators trust and borrowers return to; teams that hide it are usually hiding something else too.

How do you write the microcopy?

Compliance teams write disclosures as they appear in the Directions. Product teams rewrite them as marketing. Neither is right for a screen. The rule for lending microcopy is plain language, specific numbers and no persuasion in a disclosure.

  • Name the number. “APR 28.4%” beats “competitive rates”. “Processing fee ₹999 + GST” beats “nominal fee”.
  • Say who. “This loan is from Piramal Finance” rather than “your loan partner”. The borrower must be able to name the lender in a complaint.
  • Say when. “You can exit without penalty until 24 September” rather than “a cooling-off period applies”.
  • Explain the purpose of each permission in one line. The Directions expect need-based, purpose-specific consent; a generic “to serve you better” fails that.
  • Keep disclosures neutral. No “Great news!”, no exclamation marks, no emoji on the KFS, the consent screens or the penal charges section. Enthusiasm in a disclosure reads as persuasion.
  • Use the borrower’s language. The KFS must be in a language the borrower understands. If the app offers Hindi, Tamil or Marathi in onboarding, the KFS and the consent screens are translated too, not only the marketing screens.

For how these screens sit within a broader identity system, our brand guidelines for fintech startups post covers the component library; the disclosure screens should be components in it, not one-off layouts.

In a lending app the disclosure screens are the product; the marketing screens are the wrapper.

How do you review a lending flow for compliance before launch?

Run the flow on a real phone, as a borrower, and answer these questions with screenshots rather than opinions.

  1. Can you name the lender before you see the offer?
  2. Does the offer screen show APR and monthly repayment in the same tier as the amount?
  3. Is the KFS shown, in the prescribed format, before the agreement, with a download action?
  4. Are all consent boxes unchecked by default, with equal-weight allow and deny buttons?
  5. Does the app request contacts, call logs or media at any point? It should not.
  6. Does the disbursal confirmation state the cooling-off end date and the exit route?
  7. Can you find the grievance officer’s details in two taps from any screen?
  8. Does any charge appear during repayment that was not in the KFS?
  9. Is there a countdown, a pre-selected add-on or a shaming decline anywhere in the flow?

If any answer is wrong, the fix is a screen, not a policy. That is the point of designing to the rule rather than documenting around it.

People also ask

What is a Key Fact Statement in digital lending?

A Key Fact Statement is a standardised document RBI requires lenders to give borrowers before a loan agreement is signed. It sets out the loan amount, tenor, interest rate, all fees and charges, the all-inclusive annual percentage rate, the repayment schedule, penal charges, the cooling-off period and the grievance redressal contact. A lender cannot charge anything that is not in the KFS.

What is the cooling-off period for digital loans in India?

RBI requires a cooling-off or look-up period after disbursal, set by the lender’s board, with a minimum of three days for loans of seven days’ tenor or more and one day for shorter loans. During this window the borrower can exit by repaying the principal and the proportionate APR without any penalty.

Can a lending app access my contacts or call logs?

No. RBI’s digital lending rules prohibit apps from accessing a borrower’s file and media, contact list, call logs or telephony functions. One-time access to camera, microphone or location is permitted only for onboarding and KYC, with the borrower’s explicit consent, and consent for any data can be denied or revoked.

Do RBI’s digital lending rules apply to apps that are not lenders?

Yes, indirectly. Lending service providers and digital lending apps operate on behalf of a regulated entity, and that entity is responsible for the app’s conduct. The lender’s name must be disclosed to the borrower, and multi-lender platforms must show all matching offers fairly with each lender identified.

If your lending flow hides the APR until the last screen, the problem is not the rule.

Get a free Fintech Brand Audit across 8 dimensions, plus 3 fixes. No pitch. Run the free Brand Audit →

Leave a Reply

Share