
The Reserve Bank of India has rolled out a new Supervisory Non-Financial Accountability (SNFA) framework, aiming to fix accountability for governance, compliance, and operational failures at banks and financial institutions. The move comes after repeated lapses in areas like data privacy, anti-money laundering controls, and board-level oversight.
Until now, the RBI’s supervisory focus has been largely financial—capital adequacy, asset quality, and liquidity. The SNFA framework shifts attention to non-financial risks. These include cyber security breaches, fraud, mis-selling, and poor internal controls.
The central bank has made it clear: senior management will be held personally responsible for such failures. This is a significant departure from earlier approaches, where blame often got diffused across layers.
The framework covers all entities regulated by the RBI—scheduled commercial banks, urban cooperative banks, non-banking financial companies (NBFCs), and payment system operators. The central bank has not exempted small lenders.
For large banks and NBFCs, the compliance burden will be heavier. They will need to appoint a designated officer responsible for non-financial risk management. That officer must report directly to the board.
Smaller entities, however, may struggle. Many lack the in-house expertise to build the kind of internal audit and compliance systems the framework demands. Industry insiders say the RBI is expected to issue detailed implementation guidelines soon.
Under the SNFA framework, regulated entities must identify and document all material non-financial risks. They need to assign clear ownership for each risk category. Boards must review these risks at least once a quarter.
Entities also have to set up a whistleblower mechanism that protects reporters of non-financial misconduct. The framework mandates that the audit committee, not just the management, must handle whistleblower complaints.
A key feature is the 'accountability map'—a document that names every senior executive and their specific responsibilities for non-financial risks. If something goes wrong, the map will show who was in charge.
The RBI plans to introduce the framework in phases. A pilot phase will begin in October 2026, covering a select group of large banks and NBFCs. Full implementation across all regulated entities is expected by April 2027.
During the pilot, the RBI will collect feedback and tweak the guidelines. The central bank has not yet disclosed which entities will be part of the pilot. Observers expect the largest public and private sector banks to be included.
Non-compliance during the pilot will attract supervisory action. The RBI has warned that it could impose penalties, restrict business activities, or even bar errant executives from holding key positions.
Regulated entities have until September 2026 to submit their accountability maps and risk documentation to the RBI. The next few months will be crucial as banks and NBFCs scramble to set up compliance systems. Industry experts are watching to see if the framework leads to a real shift in risk culture or remains a box-ticking exercise.