RBI Regulatory Sandbox Advisory

Structured support for fintech innovators and regulated entities preparing to test new financial products under the Reserve Bank of India’s Enabling Framework for Regulatory Sandbox.
RBI Regulatory Sandbox Advisory

What Is the RBI Regulatory Sandbox?

The RBI Regulatory Sandbox is a live testing framework operated by the Reserve Bank of India that allows fintech companies, banks and other eligible entities to test innovative financial products with real customers in a controlled environment. The RBI may permit limited regulatory relaxations for the purpose of testing. The framework has operated since 2019 and now accepts theme-neutral applications on an on-tap basis.

Who Can Apply

Criterion Requirement
Entity type Fintech companies including startups, banks, NBFCs, and financial institutions incorporated or constituted in India under applicable law
Incorporation Incorporated and registered in India
Net worth Minimum net worth as prescribed under the current Enabling Framework, evidenced by the latest audited balance sheet
Promoters and directors Must satisfy the fit and proper criteria set out in the framework
Technology readiness Product or solution must be sufficiently developed for live deployment on a limited scale
Consumer protection Robust IT systems, data privacy safeguards, and grievance redress arrangements must be in place
Testing plan Clearly defined test scenarios, outcome metrics, boundary conditions, and an exit and transition strategy
Entities whose applications are rejected may reapply in a later window, subject to the conditions in the framework.

RBI Regulatory Sandbox: Benefits, Eligibility and Cohorts

A regulatory sandbox produces first-hand evidence on how new financial technology behaves in live conditions. Regulators use that evidence to shape rules, service providers use it to test viability before a full rollout, and customers gain access to a wider range of products at lower cost.
Benefit What it delivers Who it benefits most
Learning by doing Empirical evidence on the benefits and risks of emerging technology is gathered in live conditions rather than in theory Regulator, service providers, innovators
Evidence-led rulemaking The regulator identifies where new regulation is genuinely required to support useful innovation while containing risk Regulator
Two-way understanding Incumbent providers learn how new technology integrates into existing services, while fintech firms learn how the regulatory environment shapes product design Banks, NBFCs, fintech firms
Product viability testing Viability is proven without an expensive large-scale rollout, and modifications are made before the wider market launch Service providers
Customer feedback loop Feedback from test customers informs both regulators and providers on which features deliver real value All participants
Financial inclusion Accelerates deployment of financial products into underserved segments including microfinance, small savings, mobile banking, remittances, and digital payments by providing a regulated testing route before full rollout. Underserved customer segments
Reduced consultation dependence A structured, evidence-based testing route gives the regulator direct data on product behaviour, supplementing stakeholder consultation with empirical findings rather than replacing it. Regulator
Better consumer outcomes A wider range of products and services, lower costs, and improved access to financial services End customers

Eligibility for the Regulatory Sandbox

Target Applicants
Applicant type Notes
Startups Fintech firms developing new financial products or delivery models
Banks Including partnerships with technology providers
Financial institutions Including those constituted under a statute in India
Support and partner companies Entities partnering with or providing support to financial services businesses
Innovation Focus Test
An application is intended to address at least one of the following conditions in the Indian market.
Condition What the applicant must demonstrate
Regulatory gap Governing regulations are absent for the proposed innovation
Regulatory friction Existing regulation needs to be temporarily eased for the innovation to be tested
Material impact The innovation shows promise of easing or significantly improving the delivery of financial services

How Cohorts Work

Attribute Detail
Structure A cohort is an end-to-end sandbox process run with a limited number of entities
Intake Narrow by design, both in areas of innovation and in number of participants
Basis Theme-based, covering areas such as financial inclusion, digital KYC, payments and lending, with theme-neutral cohorts also possible
Testing window Each entity tests its product during a stipulated period

Indicative Scope for Testing

Category Examples
Payments and transfers Retail payments, money transfer services
Credit Marketplace lending
Identity and onboarding Digital KYC, digital identification services
Wealth and advisory Wealth management services, financial advisory services
Inclusion Financial inclusion products
Security Cyber security products
Contracting Smart contracts
RegTech and SupTech Regulatory compliance automation, supervisory reporting tools, risk monitoring systems

Cohorts Announced to Date

Cohort Theme Status
First Retail Payments Completed, on-tap applications subsequently permitted
Second Cross Border Payments Completed, on-tap applications subsequently permitted
Third MSME Lending Completed, on-tap applications subsequently permitted
Fourth Prevention and Mitigation of Financial Frauds Completed, on-tap applications subsequently permitted
Fifth Theme Neutral Completed
Current position Theme-neutral applications accepted on an on-tap basis through the PRAVAAH portal. Current Status to be verified at time of filing. Open

Indicative Areas for Theme-Neutral Applications

Area Examples of eligible innovation
Digital lending Alternate credit scoring, cash-flow based underwriting, embedded credit
Identity and onboarding e-KYC, video KYC enhancements, identity verification and de-duplication
Emerging technologies Artificial intelligence, machine learning, blockchain, smart contracts, tokenisation applied to financial services
Financial inclusion Products serving underbanked segments, rural credit delivery, assisted digital channels
Fraud prevention Mule account identification and tracking, transaction monitoring, authentication innovation
Financial literacy Digital financial literacy and customer education tools
The list is illustrative rather than exhaustive. Any innovative product falling within the RBI’s regulatory ambit may be proposed.

The Sandbox Process, Stage by Stage

Entry into the sandbox follows five prescribed stages, from preliminary screening through to exit evaluation. Each stage places a specific obligation on the applicant, and an incomplete deliverable at any point stalls progression to the next.
01
Stage 1

Preliminary screening

The RBI's fintech team reviews applications against eligibility criteria and shortlists applicants

Key deliverable from the applicant: Complete application with supporting documents

02
Stage 2

Test design

Structured engagement with the RBI's fintech team to develop and refine the test design, define outcome metrics, and identify any regulatory relaxations required for the test period.

Key deliverable from the applicant: Draft test plan, target customer segment, risk controls

03
Stage 3

Application assessment

The test design is vetted and regulatory relaxations, if any, are proposed

Key deliverable from the applicant: Response to regulator queries, revised design

04
Stage 4

Testing

The product is deployed live with a defined cohort of customers under monitoring

Key deliverable from the applicant: Periodic progress reporting on the agreed schedule

05
Stage 5

Evaluation

Final test report and evidence pack supporting the exit decision, including outcomes against agreed metrics and a post-sandbox transition plan.

Key deliverable from the applicant: Final test report and evidence pack

Stage durations are prescribed in the Enabling Framework and are subject to extension at the regulator’s discretion.

What Sandbox Entry Does and Does Not Provide

Sandbox entry does Sandbox entry does not
Permit live testing with real customers under supervision Amount to a licence, authorisation or registration
Allow specific, limited regulatory relaxations for the test period Waive statutory obligations such as customer protection or data privacy duties
Provide structured regulator engagement and feedback Limit or waive the entity's liability towards its test customers, full customer protection obligations apply throughout the testing period
Generate evidence supporting later adoption by regulated entities Guarantee approval, adoption or commercial rollout

Where Applications Commonly Fall Short

Weakness Consequence
Screened out at preliminary review, the framework requires genuine novelty or an identified regulatory friction. Incremental improvements to existing products are unlikely to qualify. Screened out for lack of genuine novelty
Application does not satisfy the innovation focus test, one of the three qualifying conditions (regulatory gap, regulatory friction, or material impact) must be met. Application may be treated as unnecessary for sandbox testing
Vague outcome metrics or undefined boundary conditions Test design cannot be finalised
Product not ready for live deployment Rejected at preliminary screening
Weak data protection, IT security or grievance redress architecture Fails fit and proper and consumer protection assessment
No credible exit and transition strategy Application incomplete under the framework

Documentation Checklist

Document Purpose
Certificate of incorporation and constitutional documents Establishes Indian incorporation and entity type
Latest audited financial statements Evidences the prescribed net worth
Promoter and director declarations Supports the fit and proper assessment
Product and technology documentation Demonstrates deployment readiness
Proposed test plan Sets out scenarios, metrics and customer cohort
Risk assessment and mitigation plan Addresses consumer, operational and technology risk
Data protection and information security policy Supports privacy and security review
Grievance redress framework Demonstrates customer protection arrangements
Exit and transition strategy Required under the framework
PRAVAAH portal application form The primary application submitted through RBI's online portal, covering entity details, innovation description, and sandbox objectives
Applications and supporting material are subject to size and format limits specified by the RBI at the time of submission.

Advisory Support from IMC Group

IMC Group supports fintech businesses, banks and NBFCs across the full RBI Regulatory Sandbox journey, from the first eligibility question through to exit and commercial scale-up.

Eligibility and Readiness Assessment

Every engagement begins with an honest view of whether an application is worth filing. The review covers entity structure, net worth position, product maturity, and the fit and proper standing of promoters and directors.

Regulatory Gap Mapping

A sandbox application succeeds when it points to a specific provision standing in the way of a genuinely new product. The team isolates the provisions creating friction and frames the relaxation sought in terms the regulator can assess.

Application Preparation

Support covers drafting of the application, the innovation narrative, the risk assessment, and the supporting annexures for PRAVAAH submission. IMC assembles documentation to the format and size conditions specified by RBI at the time of filing, reducing the risk of rejection on procedural grounds before the substantive application is reviewed.

Test Design Support

Test design determines what the sandbox can actually prove. Work at this stage defines the test scenarios, customer cohort, outcome metrics, boundary conditions and monitoring cadence.

Data Protection and IT Governance Review

Consumer protection and technology readiness are assessed closely during screening. The review examines privacy arrangements, information security controls, systems resilience and the grievance redress framework ahead of filing.

Regulator Engagement Support

Screening and assessment involve iterative engagement with the regulator. Support covers responses to queries raised at each stage and consistency of position across the full sequence of exchanges.

Reporting During Testing

Once live testing begins, reporting obligations run against an agreed schedule. The team structures periodic progress reports and flags deviations from the approved test parameters as they arise.

Exit and Scale-Up Planning

Sandbox exit is the start of the commercial path rather than the end of the process. IMC supports the transition strategy, readiness of any partner regulated entity required for full-scale deployment, and the licensing or authorisation pathway relevant to the product's commercial launch.

FAQs
It is a framework operated by the Reserve Bank of India that allows eligible entities to test innovative financial products live with a limited set of customers in a controlled environment, with regulatory relaxations that may be granted for the limited purpose of testing.
Fintech companies including startups, banks, NBFCs and financial institutions constituted under a statute in India, provided they are incorporated in India, meet the prescribed minimum net worth, and satisfy the fit and proper criteria.
Theme-neutral applications are accepted on an on-tap basis, which removes the need to wait for a specific cohort window. Applications are submitted through the RBI’s PRAVAAH portal.
A cohort is ordinarily expected to complete within around nine months from receipt of complete and eligible applications, excluding the preliminary screening period. Individual timelines vary with test complexity. Individual timelines vary with test complexity and the regulatory relaxations sought. Applicants should confirm current timelines with the RBI’s fintech department at the time of filing.
No. Participation does not confer any licence, authorisation or registration, and does not exempt the entity from statutory obligations or from liability towards its customers.
After a successful test, the entity exits the sandbox. Products found viable may be adopted by regulated entities and taken to market, subject to meeting applicable regulatory requirements and, where necessary, obtaining the relevant licence or authorisation for full-scale operations.
Yes. An entity whose application is rejected may apply again in accordance with the conditions set out in the Enabling Framework.
Insufficient differentiation from existing products, absence of a genuine regulatory friction to be tested, weak test design, inadequate technology or data protection readiness, and the absence of a credible exit strategy.
The IoRS is a common window that allows innovators to test hybrid financial products falling within the regulatory ambit of more than one financial sector regulator. It removes the need to engage each regulator separately, which simplifies testing and supports innovation across the financial ecosystem.
An individual sandbox caters to solutions that sit within the purview of a single regulator. The IoRS supports innovation that requires collaboration between multiple regulators, bridging the differences between their separate sandbox frameworks through one unified mechanism.
Five authorities are involved: the Reserve Bank of India for banking and payment systems, the Securities and Exchange Board of India for securities markets, the Insurance Regulatory and Development Authority of India for insurance products, the Pension Fund Regulatory and Development Authority for pension-related innovation, and the International Financial Services Centres Authority for testing at GIFT IFSC in the domain areas specified in its framework for fintech entities. PFRDA does not run a standalone sandbox but takes part in the IoRS.
Financial institutions, fintech companies, RegTech providers, startups, and other innovators offering products relevant to more than one financial sector regulator may apply. Eligibility is determined by the Principal Regulator’s own sandbox framework, based on the dominant feature of the product.
Eligibility is not set by the IoRS itself. The criteria and net worth requirement of the Principal Regulator’s own sandbox framework apply, determined by the dominant feature of the product.
The Principal Regulator is the regulator under whose remit the dominant or majority feature of the product falls, and its sandbox framework governs the application. Any regulator whose remit covers the remaining features of the product acts as an Associate Regulator.
Two factors are assessed: the nature of the financial product being enhanced, whether it is primarily a loan, deposit, insurance, or pension product and the number of regulatory relaxations being sought from each regulator during testing. The second factor carries greater weight in determining which regulator leads the application.
No. Any relaxation is considered by the Principal Regulator or Associate Regulator on a case-by-case basis, and that decision is final and binding.
Products whose features fall within the remit of more than one regulator. Examples include RegTech and SupTech solutions, digital payment and cross-border payment solutions, InsurTech, WealthTech, and cross-sectoral products such as insurance features linked to banking services.
Testing takes place in a controlled, low-risk environment, compliance across domains is addressed through a single window, products are refined using regulator feedback and test results, and time to market is reduced compared with approaching each regulator in sequence.