The Reserve Bank of India has issued new guidelines effective January 1, 2027, prohibiting lenders from remotely locking devices to force EMI payments. This rule, which limits recovery tools for consumer lenders, requires companies to adjust their collection strategies and compliance frameworks to avoid potential penalties for delayed unlocking.
The Reserve Bank of India (RBI) has introduced significant regulatory changes regarding the use of technology for loan recovery. Starting January 1, 2027, lenders will no longer be able to use remote software to disable consumer devices like smartphones, tablets, or laptops as a standard practice for missed Equated Monthly Installments (EMIs).
Impact on Lending Business Models
Many non-banking financial companies (NBFCs) and fintech lenders have historically used remote locking as a tool to ensure payment discipline, particularly in the consumer durable financing sector. By disabling features on devices, lenders could encourage borrowers to clear overdue payments quickly. The new mandate restricts this practice significantly. Lenders are now prohibited from using these tools for general personal, car, or home loans. Even for loans where the device itself is the financed asset, locking is only permitted under a strictly defined, gradual timeline.
New Rules for Financed Devices
For devices explicitly financed by a loan, the RBI has mandated a tiered approach to recovery. Lenders cannot initiate any device restrictions if a payment is less than 30 days overdue. Between 30 and 60 days, only partial restrictions are allowed. Full restrictions are only permissible after a loan has been overdue for more than 60 days.
Furthermore, essential device functions, including incoming calls, SMS, and emergency services, must remain fully operational at all times. Lenders are also strictly barred from accessing a user's personal data, such as photos, contacts, and location history. These changes effectively remove a key automated recovery tool that many lenders relied upon to maintain low delinquency rates.
Compliance and Operational Risks
For lenders, the new framework introduces both operational and financial risks. The central bank has instituted a penalty mechanism, requiring lenders to unlock devices within one hour of receiving a payment. Failure to do so will result in a compensation of ₹250 per hour payable to the borrower, capped at the total loan amount.
This creates a need for robust, real-time integration between payment gateways and device-management software. Lenders may need to invest in upgrading their technology systems to ensure 24/7 compliance. Failure to comply or wrongful restrictions on a borrower's device could lead to reputational damage and regulatory scrutiny, which are critical factors for investors to monitor when analyzing the operational efficiency of consumer lending firms.
Investors may track how this regulation influences the asset quality of lenders who heavily rely on small-ticket consumer durable loans. The shift may require these companies to re-evaluate their risk assessment models or adjust their collection strategies, which could have implications for their profit margins and overall recovery efficiency in the coming quarters.
