Legal Updates (Aug 03 – Aug 08, 2026)

Legal Updates (Aug 03 – Aug 08, 2026)

 

Legal Updates (Aug 03 – Aug 08, 2026)

CASE UPDATES

Weekly Updates (Aug 03 – Aug 08, 2026)

A person who acquires possession of public premises through a statutory auction conducted by a secured creditor under the SARFAESI Act, 2002, and holds a sale certificate, cannot be classified as being in “unauthorised occupation” within the meaning of Section 2(g) of the M.P. Lok Parisar (Bedakhali) Adhiniyam, 1974 

The Madhya Pradesh High Court in the case of Competent Authority-Cum-Executive Director M.P Industrial Development Corporation vs Shri Ramraja Industries PLTO [Writ Petition No. 1771 of 2021] dated July 28, 2026, has held that a person who acquires possession of public premises through a statutory auction conducted by a secured creditor under the SARFAESI Act, 2002, and holds a sale certificate, cannot be classified as being in “unauthorised occupation” within the meaning of Section 2(g) of the M.P. Lok Parisar (Bedakhali) Adhiniyam, 1974, merely because disputes have arisen regarding formal transfer of leasehold rights or liability for past dues of the predecessor-in-interest. 

The Court explained that the summary eviction mechanism under the Adhiniyam is not a remedy available to the lessor-State instrumentality for resolving disputes relating to transfer of leasehold rights or recovery of financial liabilities arising from a SARFAESI auction sale. Such disputes must be adjudicated through appropriate civil or statutory remedies available in law, and the auction purchaser cannot be evicted under the Adhiniyam solely on account of such disputes.

The Court observed that a person who enters possession of industrial land pursuant to a public auction conducted by a secured creditor under the SARFAESI Act, 2002, and holds a sale certificate cannot be equated with a rank trespasser or a person in clandestine occupation. The very foundation of such possession is traceable to a statutory process, and it cannot be brought within the ambit of “unauthorised occupation” as defined under Section 2(g) of the M.P. Lok Parisar (Bedhakli) Adhiniyam, 1974, merely because disputes subsequently arose regarding formal transfer of leasehold rights or liability for earlier dues. 

The Court emphasised that the summary eviction mechanism under the M.P. Lok Parisar (Bedhakli) Adhiniyam, 1974 is confined to eviction of persons in unauthorised occupation of public premises. It cannot be invoked by a State instrumentality to resolve controversies relating to transfer of leasehold rights or determination of financial liabilities arising out of an auction sale. Such disputes must be adjudicated through appropriate civil or statutory remedies and not through the summary eviction route. 

The Court also observed that an auction purchaser in a “free from encumbrance” SARFAESI sale cannot be saddled with past liabilities incurred by the predecessor-in-interest prior to the date of the sale certificate. If the State instrumentality is entitled to recover any amount representing arrears or liabilities attributable to the previous lessee, it must pursue remedies against the person legally liable therefor, including the secured creditor, if permissible in law, and not against the auction purchaser through eviction proceedings.  


Contractual rights available to financial creditors under Debenture Trust Deeds, including escrow arrangements, reserved matter approvals, inspection and monitoring rights, and oversight over fund utilisation, constitute protective covenants intended to safeguard the lenders’ financial exposure, but does not amount to related party control under IBC 

The Delhi Bench of the National Company Law Tribunal (NCLT) in the case of Rishi Gupta vs IDBI Trusteeship Services Limited [I.A. 3699 ND 2024] dated July 10, 2026, has held that contractual rights available to financial creditors under Debenture Trust Deeds, including escrow arrangements, reserved matter approvals, inspection and monitoring rights, and oversight over fund utilisation, constitute protective covenants intended to safeguard the lenders’ financial exposure and ensure completion of the financed project. Such commercial safeguards, without evidence of actual management control over the affairs of the Corporate Debtor, cannot attract the statutory disqualification contained in Section 21(2) read with Section 5(24) of the Insolvency and Bankruptcy Code, 2016. 

The Tribunal observed that although the powers of the Board of Directors stand suspended upon commencement of CIRP, suspended directors do not cease to be participants in the insolvency process. The constitution of the Committee of Creditors is the very foundation of the CIRP, and any allegation that its composition is contrary to the provisions of the Code cannot be rejected solely on the ground that it has been raised by suspended directors. The Applicants were not seeking to interfere with the commercial wisdom of the CoC but were challenging the very constitution of the CoC on the ground of a statutory embargo under Section 21(2) of the Code. 

The Tribunal examined the transaction documents in detail and observed that the rights relied upon by the Applicants substantially relate to safeguarding the utilisation of monies advanced by the financial creditors, ensuring completion of the financed project, monitoring project revenues, and preventing diversion of funds. Such stipulations are commonplace in structured project finance transactions, particularly in the real estate sector where lenders routinely insist upon escrow arrangements, monitoring mechanisms, reporting obligations, and approval requirements for specified financial decisions.  

The Tribunal further observed that the existence of escrow mechanisms or restrictions upon utilisation of project revenues cannot, by themselves, establish management control over the Corporate Debtor. The transaction documents indicated that day-to-day execution of the project, operation of the Project Operating Account, construction activities, and management of the affairs of the Corporate Debtor continued to remain with the management of the Corporate Debtor. The rights retained by the financial creditors were intended to secure repayment of their financial exposure and ensure proper deployment of the funds advanced by them. 

The Tribunal observed that if every lender insisting upon affirmative covenants, reporting obligations, escrow controls, and approval rights were to be treated as exercising management control over the borrower, virtually every secured project finance lender would become disentitled from participating in the Committee of Creditors. Such an interpretation would be wholly inconsistent with the scheme and object of the Code.     


An unsecured loan extended by an entity whose promoter holds shares in the corporate debtor qualifies as “financial debt” under Section 5(8)(f) of the IBC if it carries interest and has the commercial effect of a borrowing 

The Indore Bench of the National Company Law Tribunal (NCLT) in the case of Tanay Securities & Sevices vs Organic World [CP(IB)/60(MP)2024] dated August 03, 2026, has clarified that promoter-shareholder overlap does not disentitle a financial creditor from invoking Section 7 IBC, and oral loan with interest, TDS deposits, and audited acknowledgements are suffice to establish financial debt and default. The Tribunal also held that an unsecured loan extended by an entity whose promoter holds shares in the corporate debtor qualifies as “financial debt” under Section 5(8)(f) of the IBC if it carries interest and has the commercial effect of a borrowing. The source or motivation of the lender is immaterial once money is disbursed against consideration for the time value of money. 

The NCLT also clarified that a corporate debtor cannot defeat an admitted debt by unilaterally claiming that repayment of unsecured dues is contingent on prior clearance of secured lender dues, absent any documented covenant, negative lien, or subordination agreement binding the financial creditor. 

The Tribunal noted that the Corporate Debtor did not dispute the factum of disbursement of the principal sums or the repayment of Rs. 45 lakhs. The Corporate Debtor’s own e-mail explicitly acknowledged the “unsecured loan from promoters” and merely sought deferment of repayment, an unambiguous admission of debt. The disbursement, made against payment of interest at 2% per annum, evidenced by consistent TDS deposits and reflection in audited financial statements for three consecutive years, squarely falls within Section 5(8)(f) of the IBC, being “any amount raised under any other transaction… having the commercial effect of a borrowing”. The source or motivation of the lender is immaterial once money has been disbursed against consideration for the time value of money. 

The Tribunal rejected the Corporate Debtor’s defence that there is “no default” because repayment of the unsecured loan is contingent upon prior repayment of secured dues to the Bank. No document was placed on record, nor even alleged, to show that the Bank imposed any covenant or negative lien prohibiting repayment of unsecured dues to third parties. The plea of an internal understanding subordinating repayment of the Applicant’s dues to the Bank’s dues is a unilateral arrangement asserted by the Corporate Debtor and cannot be read into the loan transaction so as to defeat an admitted debt. The Corporate Debtor’s own admission of liability, coupled with the recall notice and the failure to make payment thereafter, establishes default under Section 3(12) of the IBC. 

The Tribunal found the corporate veil-lifting contention unpersuasive. It is an admitted position that the Applicant and its promoters were never members of the Board of Directors of the Respondent, nor involved in its day-to-day management. The doctrine of indoor management operates to protect a third party who has dealt with a company at arm’s length from being saddled with liability for that company’s internal governance. Even if Smt. Shashi Jain holds shares in the Respondent in her individual capacity, that fact alone does not convert the Applicant company into a “promoter” of the Corporate Debtor, nor disentitle it from enforcing an admitted debt. 

As regards the pendency of proceedings under Sections 241-242 of the Companies Act, 2013, the Tribunal noted that these proceedings are directed against a different entity (M/s Mittal Soya Proteins Private Limited) and relate to allegations of oppression and mismanagement, a subject matter entirely distinct from the existence of the admitted Financial Debt. A dispute of an entirely different genre, involving different parties and different reliefs, cannot be pressed into service to defeat an otherwise complete application under Section 7. The IBC, being a special statute, takes precedence over the Companies Act, 2013 by virtue of Section 238 of the IBC, as held by the Supreme Court in Innovative Industries Ltd. v. ICICI Bank. 


Dispute relating to taxation is arbitrable when it falls within the contractual domain, such as determining which party is contractually liable to pay tax, reimbursement of tax paid, or interpretation of contractual tax clauses, but is not arbitrable when it requires statutory determination by taxing authorities, such as determination of tax rates, classification of goods, or challenge to statutory tax arrangements  

The Allahabad High Court in the case of U.P. Public Works Department vs Vriddhi Infratech India [Arbitration Appeal No. – 35 of 2025] dated July 21, 2026, has held that dispute relating to taxation is arbitrable when it falls within the contractual domain, such as determining which party is contractually liable to pay tax, reimbursement of tax paid, or interpretation of contractual tax clauses, but is not arbitrable when it requires statutory determination by taxing authorities, such as determination of tax rates, classification of goods, or challenge to statutory tax arrangements. In the present case, the dispute was arbitrable as it was confined to the manner of GST calculation as per competing guidelines and did not encroach upon the exclusive domain of the taxing authority. 

The Court clarified that borrowing technical specifications from MoRTH in a contract does not automatically import MoRTH’s taxation guidelines or SOP into the contract, especially when the contract contains a separate and specific tax clause. Further, technical, financial, and commercial requirements are treated separately in contract administration, and borrowing one does not implicitly subsume the other unless specifically provided for. A directory SOP framed for EPC contracts cannot be made binding on item rate contracts without cogent evidence or contractual stipulation permitting such extension. 

Government Orders issued by the State Government in the course of its business, partaking the nature of executive instructions, are binding on the government department to which they are addressed, and an arbitral tribunal cannot discard their applicability without recording cogent reasons. An arbitral tribunal, being a creature of contract, cannot re-write the contract or fill in lacunae, and findings based on conjectures and assumptions without backing of cogent evidence render the award susceptible to interference under Section 34 and Section 37 of the Arbitration and Conciliation Act, 1996. 

The Court laid down a comprehensive framework distinguishing arbitrable from non-arbitrable tax disputes. Under “Head-A” fall disputes that can be resolved within the contract, such as determining inter se tax liability between contracting parties, reimbursement of tax paid, tax sharing or indemnity clauses, and interpretation of contractual phrases like “inclusive of all taxes” in the context of a newly introduced tax. Under “Head-B” fall disputes requiring statutory determination through tax laws, such as those encroaching upon the exclusive domain of the taxing authority, challenging statutory tax arrangements, determining classification or entries under a taxing statute, determining rate of taxation, or disputes between a contracting party and the State as sovereign. 

The Court held that the present dispute fell under Head-A, as it was confined to whether GST should be calculated as per the MoRTH SOP or the State Government Orders, it did not involve adjudication of whether a transaction was taxable, nor did it challenge any statutory tax arrangement or require determination of tax rate or classification. The Court also noted that the objection of non-arbitrability was raised for the first time in the Section 37 appeal, never having been raised before the Arbitral Tribunal under Section 16 or before the Commercial Court under Section 34. 

On the issue of penalty and interest, the Court observed that under the GST Act, the liability to pay tax is on the assessee (the contractor), who was required to deposit the tax in time. If the contractor failed to do so, it was the contractor who should bear the interest and penalty. The Sole Arbitrator, without recording a clear finding that a specific tax amount was due and payable within a specified time, that non-payment was solely attributable to the department’s negligence, and that the contractor had actually suffered interest and penalty payable to the GST Department, merely invoked Section 50 of the GST Act to make the department liable for interest and penalty. This amounted to the Arbitrator acting as an Assessing Officer. 


A party cannot unilaterally enlarge the contractual liability of the other party through one-sided correspondence or by reference to obligations arising under an independent contract with a third party, in the absence of a mutually accepted contractual stipulation  

The Delhi High Court in the case of Vantage Integrated Securities Solution vs Spark Technologies [FAO (COMM) 203/2026] dated August 05, 2026, has held that a buyer cannot adjust admitted dues against liquidated damages suffered under a separate contract with a third party absent any mutually accepted contractual stipulation. The Court held that party cannot unilaterally enlarge the contractual liability of the other party through one-sided correspondence or by reference to obligations arising under an independent contract with a third party, in the absence of a mutually accepted contractual stipulation. 

The Court emphasised that the defence of adjustment of admitted dues against alleged losses fails where there is no contractual provision or subsequent mutual agreement incorporating such liability, and reliance on Sections 55, 73 and 74 of the Indian Contract Act, 1872 cannot substitute for the absence of a foundational contractual obligation. The Court found no infirmity in the Sole Arbitrator’s conclusion that the Purchase Order did not contain any stipulation declaring time to be of the essence. The Court noted that although specific delivery dates were mentioned, there was no contractual provision making delayed delivery a ground for fastening liability upon the Respondent or requiring it to bear liquidated damages. 

The Court further observed that merely because the supplies were intended for use in another contract awarded by the RBI would not, by itself, alter or rewrite the contractual relationship between the Appellant and the Respondent, and that the obligations and liabilities of the parties must be gathered from the terms of the contract between them and not from conditions in a separate agreement with a third party. The Appellant was unable to point to any clause in the Purchase Order whereby the Respondent agreed that time would be the essence or that it would be liable for liquidated damages incurred under the Appellant’s independent contract with the RBI.

On the plea of adjustment of outstanding dues against liquidated damages, the Court noted that the Sole Arbitrator found no contractual stipulation or mutually accepted arrangement entitling the Appellant to recover alleged damages from the Respondent or to unilaterally adjust the admitted amount payable. The communication dated Aug 26, 2015 merely conveyed the Appellant’s apprehension that liquidated damages might be imposed by the RBI and its intention to recover the same from the Respondent, but neither formed part of the Purchase Order nor constituted a contractual stipulation, and there was nothing on record to indicate that the Respondent accepted the said stipulation or that the parties mutually agreed to modify the contractual terms. 

The Court held that the reliance on Sections 73 and 74 of the Contract Act did not advance the Appellant’s case because the very foundation for claiming compensation, namely a contractual obligation making the Respondent liable for the alleged losses, was found to be absent by the Sole Arbitrator upon interpretation of the Purchase Order and appreciation of evidence. 

 

REGULATORY UPDATES

RBI Mandates Comprehensive Digital Payment Security Controls for Commercial Banks 

The Reserve Bank of India has issued the RBI (Commercial Banks – Digital Payment Security Controls) Directions, 2026, bearing reference number RBI/DoS/2026-27/411, dated July 31, 2026. These Directions come into effect immediately upon issuance and are applicable to Commercial Banks, meaning banking companies (other than Small Finance Banks, Payments Banks, and Local Area Banks), corresponding new banks, and the State Bank of India, as defined under clauses (c), (da), and (nc) of Section 5 of the Banking Regulation Act, 1949. The scope extends to any digital payment product or service offered by the bank for financial or non-financial transactions, including balance enquiry, PIN set/change, mobile banking registration, OTP generation, mini-statement, transaction status checking, and dispute/grievance raising, whether offered directly by the bank or through systems operated by RBI or RBI-authorised Payment System Operators, along with associated IT assets. 

The Directions adopt definitions sourced from the Financial Stability Board (FSB) Cyber Lexicon unless otherwise specified, covering key terms such as Availability, Confidentiality, Cyber, Cybersecurity, Cyber-attack, Distributed Denial of Service (DDoS), Framework (adapted from ISACA glossary), Information System, Integrity, Malware, Penetration Testing, Phishing, Vulnerability, and Vulnerability Assessment. All other undefined expressions bear the meanings assigned under the RBI Act, 1934, Banking Regulation Act, 1949, Payment and Settlement Systems Act, 2007, Information Technology Act, 2000, Companies Act, 2013, or any statutory modification, re-enactment, or RBI-issued regulation or glossary. The Board of Directors of the bank shall approve policies related to digital payment products and services, and such policies shall be reviewed at least annually by the Board. 

 

Key issues: 

Governance and Management of Security Risks: The bank shall formulate a Board-approved policy for digital payment products and services addressing Functionality, Security, and Performance (FSP) parameters, including controls for confidentiality and integrity of customer data, availability of requisite infrastructure with backup, secure build with robust performance, capacity building with scalability, minimal customer service disruption, efficient dispute resolution, and adequate review mechanisms with swift corrective action. Foreign Banks need not maintain a separate local policy if the prescribed aspects are appropriately covered in their global policy. The Board and Senior Management shall be responsible for implementation, with the policy reviewed at least annually. The policy shall require every digital payment product to address the mechanics of the payment cycle, security aspects, validations till settlement, pictorial representation of the digital path, exception handling, UAT in multiple stages before roll-out, sign-off from multiple stakeholders, and data archival requirements. The bank shall articulate the need for external assessment of the entire process including logic, build, and security aspects, and shall incorporate processes for identifying, analysing, monitoring, and managing specific risks including compliance and fraud risk on a continual and holistic basis. 

Senior Management shall maintain performance monitoring systems and key performance indicators, define product-level limits on acceptable security risk, document specific security objectives and performance criteria with quantitative benchmarks, compare actual results with projections periodically, and modify business plans based on security performance. The bank shall have trained resources with necessary expertise, and where dependent on third-party service providers, shall maintain adequate oversight and controls. Risk assessments shall be conducted both prior to establishing services and regularly thereafter, factoring in the technology stack, known vulnerabilities at each touchpoint, third-party dependence, integration risks, customer experience, reconciliation, interoperability, data storage and privacy, operational and fraud risk, business continuity, cybersecurity compliance, and compatibility aspects. The risk assessment shall cover the surrounding ecosystem, protect payment data, evaluate system resilience, and include Risk and Control Self-Assessment (RCSA) exercises to arrive at residual risk. The bank shall maintain a database of all systems storing customer data and compliance with PCI standards, evaluate risks of chosen technology platforms and application architecture, review risk scenarios before major infrastructure changes, develop sound internal control systems, ensure robust and scalable digital payment architecture, and periodically test backed-up data and applications at least on a half-yearly basis. 

Other Generic Security Controls: The communication protocol in digital payment channels shall adhere to secure standards with appropriate encryption. Web applications shall not store sensitive information in HTML hidden fields, cookies, or client-side storage. The bank shall implement Web Application Firewall (WAF) solutions and DDoS mitigation techniques. Key lengths, algorithms, cipher suites, digital certificates, and applicable protocols shall be strong, adopting internationally accepted and published standards that are not deprecated or insecure. Digital certificates shall be renewed well in time. Mobile and internet banking applications shall have effective logging and monitoring capabilities to track user activity, security changes, and identify anomalous behaviour and transactions. 

Application Security Life Cycle: The bank shall implement multi-tier application architecture segregating application, database, and presentation layers, and follow a ‘secure by design’ approach embedding security within the development lifecycle. Security objectives shall be explicitly defined across requirements gathering, designing, development, testing (including source code review), implementation, maintenance, monitoring, and decommissioning phases. The bank shall adopt threat modelling during application lifecycle management. For third-party licensed applications, source code escrow arrangements shall be put in place. Security testing including source code review, Vulnerability Assessment (VA), and Penetration Testing (PT) shall be conducted — VA at least half-yearly, PT at least annually, and additionally whenever new infrastructure or applications are introduced or major changes are performed. Testing shall cover OWASP standards, and where source code is not owned by the bank, a certificate from the developer shall be obtained confirming freedom from known vulnerabilities, malware, and covert channels. Penal provisions shall be included in third-party contracts for non-compliance. The bank shall compare vulnerability scan results to verify remediation, perform authenticated-mode scanning, test functionality and security controls before launch, monitor for non-genuine or malicious applications on app stores, ensure server-side checks against unauthorised applications, implement secure APIs referencing OWASP-MASVS, OWASP-ASVS, ISO 12812, and NIST standards, and redact or mask customer information transmitted via SMS or emails. 

Authentication Framework: The bank shall implement multi-factor authentication for payments through electronic modes and fund transfers, including cash withdrawals from ATMs, micro-ATMs, and business correspondents through digital payment applications, with at least one authentication methodology being dynamic or non-replicable (e.g., OTP, device binding and SIM, biometric, PKI, hardware tokens, EMV chip card with server-side verification). The authentication methods shall act as a strong fraud deterrent, be difficult to compromise, protect confidentiality of payment data, and address cyber-attack mechanisms like phishing, keylogging, spyware, and malware. The bank may adopt adaptive authentication based on risk assessment, user risk profile, and behaviour. Implementation shall be based on assessment of risks posed by the products, considering customer type, transactional requirements, sensitivity of information, and volume and value of transactions. Multi-factor authentication and alerts (via SMS and email) shall be implemented for all payment transactions, creation of new account linkages, change in account details, and revision of fund transfer limits. Alerts and OTPs shall identify the merchant name wherever applicable. The bank shall implement measures against man-in-the-middle, man-in-the-browser, and man-in-the-application attacks, ensure authenticated sessions remain intact throughout interaction with automatic termination on interference or closure, set maximum failed login or authentication attempts after which access is blocked, and have a secure procedure for re-activation with customer notification. 

Fraud Risk Management: The bank shall document and implement configuration requirements for identifying suspicious transactional behaviour, including rules, preventive and detective controls, alert mechanisms for failed authentication attempts, and applicable time frames. System alerts shall be parameterised and monitored across various parameters including transaction velocity, high-risk merchant category codes, counterfeit card parameters, new account parameters, time zones, geo-locations, IP address origin, behavioural biometrics, transactions to mobile wallets or VPAs associated with vishing fraud, declined transactions, and transactions without approval codes. The bank shall conduct fraud analysis to identify reasons and prevention mechanisms, educate and train staff in fraud control tools, investigative techniques, cardholder and merchant education, scheme operating regulations, data processing, and liaison with law enforcement. The bank shall maintain updated contact details of service providers, intermediaries, and stakeholders for incident response coordination, and formulate Standard Operating Procedures (SOPs) for handling payment ecosystem incidents. 

Reconciliation Mechanism: A real-time or near-real-time (not later than 24 hours from receipt of settlement files) reconciliation framework shall be put in place for all digital payment transactions between the bank and all other stakeholders including payment system operators, business correspondents, card networks, payment system processors, payment aggregators, payment gateways, third-party technology service providers, and other participants, with a mechanism to monitor implementation and effectiveness. 

Customer Protection, Awareness and Grievance Redressal Mechanism: The bank shall incorporate secure, safe, and responsible usage guidelines and training materials within digital payment applications, making it mandatory for customers to go through such guidelines (in their preferred language) during on-boarding and first use after each update. The application shall clearly specify the process and procedure for lodging customer grievances, with defined timelines for the bank’s response. The bank shall be guided by RBI’s circular on Online Dispute Resolution (ODR) System for Digital Payments dated August 6, 2020, as updated from time to time. Customers shall be educated about maintaining physical and logical security of devices, provided information about risks, benefits, and liabilities before subscribing, and informed of their rights, obligations, and responsibilities. Terms and conditions including privacy and security policy shall be readily available within the product, and all digital channels shall be offered on express willingness of customers without bundling. The bank shall provide clear communication on new security features, create public awareness on threats and attacks, caution customers against phishing, vishing, reverse phishing, and remote access of mobile devices, provide digital payment products only at the customer’s option based on specific written or authenticated electronic requisition with positive acknowledgement, and provide a mechanism on mobile and internet banking applications for customers to identify or mark a transaction as fraudulent for seamless and immediate notification, with capability for instant reporting to the corresponding beneficiary or counterparty entity. 

Internet Banking Security Controls: In addition to Chapter III controls, banks offering internet banking shall implement additional authentication levels such as adaptive authentication and strong CAPTCHA with anti-bot features and server-side validation against brute force and DoS attacks, prevent DNS cache poisoning attacks, ensure secure handling of cookies, provide a virtual keyboard option, automatically terminate sessions after fixed inactivity periods, ensure secure delivery of passwords with limited validity and compulsory change on first login, and maintain uniform authentication procedure and appearance when accessed through external websites. 

Mobile Payments Application Security Controls: In addition to Chapter III controls, banks offering mobile banking or mobile payments shall direct customers to reinstall the application on detection of anomalies, verify application version before enabling transactions, implement device policy enforcement with baseline requirements, ensure secure download and installation, deactivate older application versions in a phased but time-bound manner not exceeding six months, identify and block remote access applications, enforce device or application encryption, ensure minimal data collection and app permissions, implement application sandbox or containerisation and code obfuscation, validate device and operating system security and compatibility, check for rooted or jailbroken devices, host checksums of the current active version on public platforms, implement device binding through hardware, software, and service information with multi-device registration notifications and disablement facility, explore alternatives to SMS-based OTP, require re-authentication after designated inactivity periods and on each launch, identify unsecured network connections, prohibit storage of sensitive authentication information on the device with secure wiping on exit, limit writing of sensitive information to temp files with encryption, consider anti-malware capabilities, avoid raw SQL queries, secure against SQL injection vulnerabilities, encrypt sensitive data in the mobile application database, prevent loading web content on SSL/TLS negotiation errors, and display certificate errors to the user. 

Card Payment Security Controls: In addition to Chapter III controls, banks issuing cards (credit, debit, or prepaid, physical or virtual) shall follow various PCI standards including PCI-PIN, PCI-PTS, PCI-HSM, and PCI-P2PE, over and above PCI-DSS and PCI-SSF, holistically as per applicability in both issuer and acquirer capacities, with appropriate confirmation from third parties on compliance and status reports to the IT Strategy Committee. Terminals at merchants shall be validated against PCI-P2PE, and PoS terminals with PIN entry shall be approved under PCI-PTS, with new terminals certified accordingly. The bank as an Acquirer shall secure its card payment infrastructure (UKPT or DUKPT/TLE). HSMs shall have tamper-proof logging enabled, clustering for high availability, access through ACLs with application-level isolation, privileged identity and access management, decryption and validation of keys and PIN at HSM, card PIN generation and printing at HSM-connected systems, CVV generation and validation at HSM, secure PIN block format, secure key management including Local Master Keys, and proper security for physical keys. ATMs shall have BIOS passwords, disabled USB ports, disabled auto-run, latest OS and software patches, terminal security solutions, time-based admin access, anti-skimming and whitelisting solutions, and supported OS versions. Card transactions shall be subject to robust surveillance and monitoring (especially overseas cash withdrawals), transaction limits at card, BIN, and bank levels set at the card network switch, transaction control mechanisms with caps on breach, 24×7 monitoring including weekends and holidays with incident response, no storage of card details in plain text, and secure processing of card details in readable format. Card data scanning tools shall be tested in test environments first, installed only on the bank’s premises and devices, not used remotely, with discovered data residing in the scanning tool, exportable data appropriately masked, and service providers given limited access only on the bank’s devices.  

Click here to read/ download the original direction  


RBI institutionalises IT governance structures through ITSCs and ISCs, requires independent CISO oversight for larger NBFCs, prescribes time-bound cyber incident reporting, and enforces rigorous BCP/ DR testing with defined RTO and RPO targets 

The Reserve Bank of India vide the RBI (NBFC – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026, bearing reference number RBI/DoS/2026-27/461, dated July 31, 2026, has adopted a scale-based regulatory approach with distinct chapters catering to different categories of NBFCs. Chapter III applies to NBFCs-Base Layer with asset size below 500 crore and Core Investment Companies. Chapter IV applies to NBFCs-Base Layer with asset size 500 crore and above. Chapter V applies to NBFCs-Top Layer, NBFCs-Upper Layer, and NBFCs-Middle Layer, excluding CICs. 

This layered structure ensures that the cybersecurity and technology governance obligations are calibrated to the size, complexity, and systemic significance of the NBFC. The Board of Directors of every NBFC shall approve the strategies and policies related to Technology and Cybersecurity frameworks, which shall be reviewed at least annually by the Board. This provision applies across all layers, establishing the Board as the primary accountability holder for the technology and cybersecurity posture of the NBFC. 

 

Key factors: 

Requirements for NBFCs-Base Layer (Below 500 Crore) and CICs: NBFCs-Base Layer with asset size below 500 crore and CICs shall prioritise implementation of basic IT systems to digitise and secure primary business databases and put in place a Board-approved IT/IS policy incorporating basic security aspects such as physical and logical access controls, well-defined password policy, well-defined user roles, maker-checker concept, robust information security and cybersecurity controls, requirements regarding Digital Signature Certificates, Mobile Financial Services, and Social Media, system-generated reports for Senior Management, adequacy to file regulatory returns with RBI, a Board-approved Business Continuity Plan with periodic Board oversight, and arrangements for data backup with periodic testing. These NBFCs shall progressively scale up their IT systems as the size and complexity of operations increase. 

Requirements for NBFCs-Base Layer (500 Crore and Above): NBFCs-Base Layer with asset size 500 crore and above shall establish a robust IT Governance framework integrated with their overall corporate governance structure, built upon the principles of value delivery, IT risk management, IT resource management, and performance management. The NBFC shall form an IT Strategy Committee chaired by an independent director, with the CIO and CTO as members, meeting at an appropriate frequency with no more than six months between two meetings. The NBFC shall formulate a Board-approved IT policy, put in place a robust Information Security framework with a Board-approved Information Security policy covering confidentiality, integrity, availability, and authenticity, and a Board-approved cybersecurity policy. The NBFC shall establish a vulnerability management process, develop cybersecurity preparedness indicators, and put in place a Cyber Crisis Management Plan addressing detection, response, recovery, and containment. Cyber incidents shall be reported on the DAKSH platform within six hours of detection. The NBFC shall undertake comprehensive IT risk assessment at least annually, develop safeguards for mobile financial services, handle social media risks, and establish ongoing information security training programs. 

For IT operations, the NBFC shall have a Board-approved change management policy and a robust IT-enabled MIS with system-generated dashboards, NPA identification, product pricing, regulatory compliance capture, financial reports, treasury reports, fraud analysis, and incident reporting, with all regulatory returns being system-driven and ‘read-only’ access provided to RBI supervisors. IS Audit shall form an integral part of the Internal Audit system, conducted at least once a year, preferably prior to statutory audit, using a mix of manual techniques and Computer-Assisted Audit Techniques. The NBFC shall have a Board-approved BCP policy with Business Impact Analysis, recovery strategy, backup sites, annual testing using worst-case scenarios, and mechanisms to support testing of cyber resilience among vendors. For IT services outsourcing, the NBFC shall undertake comprehensive risk assessment prior to outsourcing, ensure contracts are vetted by legal counsel with provisions for monitoring, access to books and records, audit and inspection rights, and RBI access, with the Board or ITSC being ultimately responsible for outsourcing operations. 

Requirements for NBFCs-Middle Layer and Above (Excluding CICs): NBFCs in the Middle Layer, Upper Layer, and Top Layer shall put in place a robust IT Governance Framework with key focus areas including strategic alignment, risk management, resource management, performance management, and Business Continuity/DR Management. The Board shall approve strategies and policies related to IT, information assets, business continuity, information security, and cybersecurity, reviewed at least annually. The ITSC shall have a minimum of three directors, be chaired by an independent director with substantial IT expertise (minimum seven years’ experience), and meet at least quarterly. An IT Steering Committee at Senior Management level shall meet quarterly, and an Information Security Committee under the oversight of the ITSC, headed by a representative from the risk management vertical, shall manage cyber and information security. The NBFC shall appoint a Head of IT Function as first line of defence and a senior-level CISO (preferably General Manager rank) who shall not have any direct reporting relationship with the Head of IT Function, shall not be given business targets, and shall directly report to the Executive Director or equivalent overseeing risk management. The CISO shall place a review of cybersecurity risks before the Board/RMCB/ITSC at least quarterly. 

The NBFC shall establish a robust IT and Information Security Risk Management Framework, with the RMCB in consultation with the ITSC reviewing IT-related risks at least annually. Baseline cybersecurity and resilience requirements include a data migration policy with audit trails and signoffs, an enterprise data dictionary, physical and environmental controls for DC and DR sites with geographic separation and e-surveillance, application security with source code escrow arrangements and vendor certificates confirming freedom from vulnerabilities, capacity management with annual assessments, comprehensive audit trail capabilities, documented change and patch management policies, access controls with two-factor or multi-factor authentication for privileged users, controls on teleworking, third-party risk assessment, cryptographic controls using internationally accepted non-deprecated standards, and Straight Through Processing for critical applications. Vulnerability Assessment shall be conducted at least every six months and Penetration Testing at least once in 12 months for critical information systems and DMZ systems with customer interface, by independent experts, with identified vulnerabilities fixed in a time-bound manner. 

BCP and DR policy shall adopt best practices such as ISO 22301, with DR drills for critical information systems conducted at least half-yearly, involving switchover to the DR site for at least a full working day. The NBFC shall achieve minimal RTO (as approved by ITSC) and near-zero RPO for critical information systems, with identical configurations and security patches at DC and DR. Cyber incident response and recovery management policy shall address classification, communication, and containment, with cyber incidents reported to RBI within six hours of detection on DAKSH and CERT-In notified proactively. Housing Finance Companies shall continue to report to NHB. The NBFC shall define suitable metrics including RPO and RTO for critical systems, implement scorecards for IT performance and maturity, and maintain a separate IS Audit function within Internal Audit with risk-based audit planning and ACB oversight. 

Repeal and Saving: With the issuance of these Directions, all existing directions, instructions, and guidelines relating to Information Technology Framework and IT Governance applicable to NBFCs stand repealed, as communicated vide circular no. DoS.CO.PPG.66/11.01.005/2026-27 dated July 31, 2026. Notwithstanding such repeal, any action taken or purported to have been taken under the repealed directions shall continue to be governed by the provisions thereof, and all approvals or acknowledgments granted under the repealed directions shall be deemed as governed by these Directions. The repeal shall not prejudicially affect any right, obligation, or liability acquired, accrued, or incurred; any penalty, forfeiture, or punishment incurred; or any investigation, legal proceeding, or remedy in respect thereof. 

Click here to read/ download the original direction  


RBI New Directions Replace All Prior Fraud Risk Management Guidelines for Payments Banks, Introducing Board-Level Governance, Natural Justice Safeguards, and Strict Reporting Timelines 

The Reserve Bank of India vide its RBI (Payments Banks – Fraud Risk Management) Directions, 2026 Notification No. RBI/DoS/2026-27/430, dated July 31, 2026, has consolidated and replaced all prior fraud risk management instructions applicable to Payments Banks under a single, unified framework issued under Section 35-A of the Banking Regulation Act, 1949. The core regulatory intent is to embed fraud risk management into the governance architecture of Payments Banks through Board-level ownership, mandatory committee oversight, and a dedicated organisational structure led by an officer of at least General Manager rank. The framework operationalises the Supreme Court’s natural justice mandate by requiring SCN, reasoned orders, and minimum response periods before any fraud classification that carries civil consequences. The Directions also introduce a calibrated reporting regime i.e., 14-day FMR filing, tiered LEA reporting by amount, CPFIR reporting for payment system frauds, and RBR reporting for physical security incidents, while simultaneously streamlining compliance by dispensing with monthly and flash reports. The five-year debarrment provision, extending to associated entities and persons, serves as a deterrent mechanism. 

 

Key changes: 

Preliminary (Chapter I): These Directions are issued by the Reserve Bank of India under Section 35-A of the Banking Regulation Act, 1949, and all other enabling provisions, in public interest. They are titled the Reserve Bank of India (Payments Banks – Fraud Risk Management) Directions, 2026, come into effect immediately upon issuance, and are applicable to all Payments Banks (collectively ‘PBs’, individually ‘PB’). They provide a framework for prevention, early detection, and timely reporting of incidents of fraud by Payments Banks to Law Enforcement Agencies (LEAs) and to RBI, and dissemination of information by RBI on matters connected therewith or incidental thereto. Key definitions include ‘Central Fraud Registry (CFR)’ as a web-based searchable database maintained by RBI where fraud-related data flows directly from online reporting by the PB through Fraud Monitoring Returns (FMRs); ‘Date of Classification’ as the date when due approval from the competent authority has been obtained and a reasoned order is passed; ‘Date of Detection’ as the actual date when the fraud came to light in the concerned branch, audit, or department of the PB, and not the date of approval by the competent authority; ‘Date of Occurrence’ as the date when the actual misappropriation of funds has started taking place or the event occurred, as evidenced or reported in audit or other findings; and ‘Red Flagged Account’ as one where suspicion of fraudulent activity is thrown up by the presence of one or more Early Warning Signal (EWS) indicators, alerting deeper investigation from a potential fraud angle and requiring initiation of preventive measures by all banks. 

Governance and Oversight (Chapter II): The PB shall put in place a Board-approved Fraud Risk Management Policy delineating roles and responsibilities of the Board, Board Committees, and Senior Management, covering prevention, early detection, investigation, staff accountability, monitoring, recovery, and reporting of frauds, along with a framework for EWS and Red Flagging of Accounts (RFA). The policy shall incorporate measures for ensuring compliance with the principles of natural justice in a time-bound manner, which at a minimum shall include: issuance of a detailed Show Cause Notice (SCN) to the Persons (including Third Party Service Providers, Professionals, Entities, and their Promoters or Whole-time and Executive Directors) against whom allegation of fraud is being examined, providing complete details of transactions, actions, or events on the basis of which declaration and reporting of a fraud is being contemplated; providing a reasonable time of not less than 21 days to respond to the SCN; having a well-laid-out system for issuance of SCN and examination of responses prior to declaring such Persons or Entities as fraudulent; and serving a reasoned Order conveying the decision regarding declaration or classification of the account as fraud or otherwise, containing relevant facts, submissions made against the SCN, and reasons for classification. This requirement of natural justice is applicable in all cases of fraud classification which may have civil consequences such as penal measures or caution listing, as observed in the judgement of the Hon’ble Supreme Court dated March 27, 2023 in the matter of State Bank of India and Others vs. Rajesh Agarwal and Others. Non-whole-time directors such as nominee directors and independent directors, who are normally not in charge of or responsible for the conduct of business of the company, may be taken into consideration before proceeding against them. 

The Board shall review the Fraud Risk Management Policy at least once in three years, or more frequently as prescribed. The PB shall constitute a Special Committee of the Board for Monitoring and Follow-up of cases of Frauds (SCBMF) with a minimum of three members, consisting of a whole-time director and a minimum of two independent or non-executive directors, headed by one of the independent or non-executive directors. The SCBMF shall oversee the effectiveness of Fraud Risk Management, review and monitor cases of frauds including root cause analysis, and suggest mitigating measures. The Board shall decide the coverage, periodicity, and threshold amount of fraud cases to be placed before the SCBMF. The Senior Management shall be responsible for implementation of the policy and shall place a periodic review of incidents of fraud before the Board or the Audit Committee of Board (ACB). The PB shall put in place a transparent mechanism for Whistle Blower complaints on possible fraud cases or suspicious activities, and shall set up an appropriate organisational structure for institutionalisation of Fraud Risk Management within its overall risk management functions, with a senior official in the rank of at least a General Manager or equivalent responsible for monitoring and reporting of frauds. 

Early Detection of Frauds – EWS and RFA Framework (Chapter III): The PB shall have a framework for EWS and RFA under the overall Fraud Risk Management Policy approved by the Board. The Risk Management Committee of the Board (RMCB) shall oversee the effectiveness of this framework, approve EWS indicators for monitoring banking transactions, and prescribe appropriate Turnaround Time (TAT), preferably not more than 30 days, for examination of EWS alerts or triggers. The RMCB shall review the status of red flagged accounts at periodic intervals as approved by the Board. The framework shall provide for a robust EWS integrated with the Core Banking Solution (CBS) or other operational systems; timely initiation of remedial action on alerts; periodic review of internal controls and systems; and effective use of the CFR. The PB shall develop or strengthen its EWS system by identifying suitable indicators and parameterising them for monitoring banking transactions, and shall continuously upgrade the system for enhancing its integrity and robustness. The design and specification of the EWS system shall ensure that personal and financial data of customers are secure and transaction monitoring for prevention or detection of potential fraud is on a real-time basis or with a minimum time lag. The PB shall remain vigilant in monitoring transactions in non-KYC compliant and money mule accounts. The Data Analytics and MI Unit or other dedicated analytics set up in the PB shall extensively monitor and analyse banking transactions, more specifically through digital platforms and applications, to identify unusual patterns and activities. 

General Instructions (Chapter IV): The PB may incorporate necessary terms and conditions in its agreements with third-party service providers to hold them accountable where wilful negligence or malpractice by them is found to be a causative factor for fraud. After complying with the principles of natural justice, the PB shall report to the Indian Banks’ Association (IBA) the details of such third parties or professionals involved in frauds, and the IBA would prepare caution lists of such third parties for circulation among banks. The PB shall initiate and complete the examination of staff accountability in all fraud cases in a time-bound manner. In cases involving very senior executives (MD and CEO, Executive Director, or Executives of equivalent rank), the ACB shall initiate examination of their accountability and place it before the Board, and such executives shall not participate in the meeting of the Board, ACB, or SCBMF in which their accountability is to be considered. Persons or Entities classified and reported as fraud by the PB, and also Entities and Persons associated with such Entities, shall be debarred from raising of funds and/or seeking additional credit facilities from financial entities regulated by RBI, for a period of five years from the date of full repayment of the defrauded amount or settlement amount agreed upon in case of a compromise settlement. An Entity will be deemed to be associated with another Entity if it is a subsidiary company as defined under clause 2(87) of the Companies Act, 2013, or falls within the definition of a ‘joint venture’ or an ‘associate company’ under clause 2(6) of Section 2 of the Companies Act, 2013. In case of a Natural Person, all entities in which she or he is associated as promoter, director, or as one in charge and responsible for the management of the affairs of the entity shall be deemed to be associated. 

Reporting of Frauds to Law Enforcement Agencies (Chapter V): The PB shall immediately report incidents of fraud to LEAs, subject to applicable laws. For frauds involving amounts below 1 crore, the complaint shall be lodged with the State or Union Territory (UT) Police. For frauds involving 1 crore and above, in addition to the State or UT Police, the complaint shall also be lodged with the Serious Fraud Investigation Office (SFIO), Ministry of Corporate Affairs, Government of India, and details are to be reported to SFIO in the FMR format. Although under Section 33 of the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS), a person is not mandatorily required to report to LEAs information on commission of all offences but only on those listed in that Section, the PB is advised to mandatorily report incidents of fraud involving an amount of 1 lakh or more to LEAs. The PB shall establish suitable nodal points or designate officers for reporting incidents of fraud to LEAs and for proper coordination to meet the requirements of the LEAs. 

Reporting to Reserve Bank of India (Chapter VI): The PB shall report incidents of fraud to RBI through FMRs using the online portal, choosing the most appropriate category from among the prescribed categories, which include misappropriation of funds and criminal breach of trust; fraudulent encashment through forged instruments; manipulation of books of accounts or through fictitious accounts and conversion of property; cheating by concealment of facts and cheating by impersonation; forgery with the intention to commit fraud; wilful falsification, destruction, alteration, or mutilations of any book, electronic record, paper, writing, valuable security, or account with intent to defraud; cash shortages on account of frauds; fraudulent transactions involving foreign exchange; fraudulent electronic banking or digital payment related transactions committed on banks; and other types of fraudulent activity not covered under any of the above. The PB shall put in place systems and procedures to ensure that the information available in the CFR is used for credit risk and fraud risk management effectively. The PB is required to report payment system related disputed, suspected, or attempted fraudulent transactions to the Central Payments Fraud Information Registry (CPFIR), as required under the RBI Circular dated December 26, 2022. However, such transactions, if subsequently concluded as fraud committed on the PB, shall invariably be reported through FMR so as to be reflected in the CFR. 

The PB shall furnish FMR in individual fraud cases, irrespective of the amount involved, immediately, but not later than 14 days from the date of classification of an incident or account as fraud. Updates to the FMR shall be provided through the FMR Update Application (FUA). Filing or reporting of the Monthly Certificate on Frauds, Monthly CFR Certificate, and Flash Report by the PB to RBI is not required. The PB shall also report frauds perpetrated in its group entities to RBI separately through e-mail, if such entities are not regulated or supervised by any financial sector regulatory or supervisory authority. Group entities mean both domestic and overseas subsidiaries, affiliates, and joint ventures as defined under applicable accounting standards, whether engaged in financial or non-financial services. The PB shall adhere to the prescribed timeframes for reporting, and delay in reporting could result in similar frauds being perpetrated elsewhere. The PB shall examine and fix staff accountability for delays in identification of fraud cases and in reporting to RBI. While reporting frauds, the PB shall ensure that persons or entities not involved or associated with the fraud are not reported in the FMR. The PB may, under exceptional circumstances, withdraw FMR or remove names of perpetrators from FMR, with due justification and with the approval of an official at least in the rank of a whole-time director. In cases where withdrawal or removal is necessitated due to Court directions, the PB may arrange to do so immediately, and such cases shall subsequently be placed before the official in the rank of Whole-time Director for information. 

The PB shall close fraud cases using the ‘Closure Module’ where the fraud cases pending with LEAs or Court are disposed of and the examination of staff accountability has been completed. The PB is allowed, for limited statistical or reporting purposes, to close reported fraud cases involving amounts up to 1 crore where examination of staff accountability and disciplinary action, if any, have been taken, and either the investigation is going on or charge-sheet has not been filed in the Court by the LEA for more than three years from the date of registration of the FIR, or the charge-sheet is filed by the LEAs in the trial court and the trial has not commenced or is pending for more than three years from the date of registration of the FIR. In all closure cases, the PB shall maintain details of such cases for examination by auditors. 

Cheque Related Frauds (Chapter VII): To ensure uniformity and avoid duplication, reporting of frauds involving forged instruments, including fake or forged instruments sent in clearing in respect of truncated instruments, shall continue to be done by the paying banker and not by the presenting banker. The presenting bank shall immediately hand over the underlying instrument to the drawee or paying bank, as and when demanded, to enable them to inform LEAs for investigation and further action under law and to report the fraud to RBI. However, in the case of presentment of an instrument which is genuine but payment has been made to a person who is not the true owner, or where the amount has been credited before realisation and subsequently the instrument is found to be fake or forged and returned by the paying bank, the presenting bank which is defrauded or is put to loss shall file the fraud report with RBI and inform the LEAs for investigation and further action under law. 

Role of Auditors (Chapter VIII): During the course of the audit, auditors may come across instances where the transactions in the account or the documents point to the possibility of fraudulent transactions. In such a situation, the auditor should immediately bring it to the notice of the senior management and, if necessary, to the ACB of the PB for appropriate action. Internal Audit in the PB shall cover controls and processes involved in prevention, detection, classification, monitoring, reporting, closure, and withdrawal of fraud cases, as well as weaknesses observed in the critical processes in the fraud risk management framework of the PB, including delay in reporting, non-reporting, conduct of staff accountability examination, and prudential provisioning. 

Reporting Cases of Theft, Burglary, Dacoity and Robbery (Chapter IX): The PB shall report instances of theft, burglary, dacoity, and robbery (including attempted cases) to the Fraud Monitoring Group (FMG), Department of Supervision, Central Office, Reserve Bank of India, immediately, not later than seven days from their occurrence, in the prescribed ‘Return on Bank Robberies, Dacoities, Thefts and Burglaries (RBR)’ format through e-mail. The PB shall also submit a quarterly Return (RBR) to RBI using the online portal, covering all such cases during the quarter, within 15 days from the end of the quarter to which it relates. 

Repeal and Other Provisions (Chapter X): With the issue of these Directions, the existing directions, instructions, and guidelines relating to Fraud Risk Management as applicable to Payments Banks stand repealed, as communicated vide the circular dated July 31, 2026. Notwithstanding such repeal, any action taken or purported to have been taken, or initiated under the repealed directions, instructions, or guidelines shall continue to be governed by the provisions thereof. All approvals or acknowledgments granted under the repealed lists shall be deemed as governed by these Directions. The repeal shall not in any way prejudicially affect any right, obligation, or liability acquired, accrued, or incurred thereunder; any penalty, forfeiture, or punishment incurred in respect of any contravention committed thereunder; or any investigation, legal proceeding, or remedy in respect of any such right, privilege, obligation, liability, penalty, forfeiture, or punishment. The provisions of these Directions shall be in addition to, and not in derogation of, the provisions of any other laws, rules, regulations, or directions for the time being in force. For giving effect to the provisions of these Directions or to remove any difficulties in application or interpretation, RBI may issue necessary clarifications, and the interpretation of any provision given by RBI shall be final and binding. 

Click here to read/ download the original direction  

 

Voluntary issuance of a security cheque as part of a commercial loan transaction does not create a fiduciary relationship between a creditor and a debtor

Payment of matured deposit to ‘either’ or ‘surviving’ joint account holder constitutes valid discharge of bank’s liability

RBI Rolls out consolidated Master Directions

Voluntary issuance of a security cheque as part of a commercial loan transaction does not create a fiduciary relationship between a creditor and a debtor

Payment of matured deposit to ‘either’ or ‘surviving’ joint account holder constitutes valid discharge of bank’s liability

RBI Rolls out consolidated Master Directions

Internship & Articleship

Error: Contact form not found.

Disclaimer

By proceeding further and clicking on the “I ACCEPT” button below, you acknowledge that you of your own accord wish to know more about SNG & Partners (“The Firm”) for your own information and use. You further acknowledge that there has been no solicitation, invitation or inducement of any sort whatsoever from SNG & Partners or any of its employees, partners, associates or members to create an attorney-client relationship through this website. You further acknowledge having read and understood this Disclaimer.

This website is a resource for informational purposes only and is intended, but not promised or guaranteed, to be correct, complete, and up-to-date. While SNG & Partners has taken utmost care to ensure accuracy and completeness of the information contained on this website, the Firm does not warrant that the information contained on this website is accurate or complete, and hereby disclaims any and all liability for any loss or damage caused or alleged to have been caused to any person by relying on any information contained on this website. The contents of this website should not be construed as an opinion, legal or otherwise, on any issue or subject. 

SNG & Partners further assumes no liability for the interpretation and/or use of the information contained in this website, nor does it offer a warranty of any kind, either expressed or implied. The owner of this website does not intend links from this site to other Internet websites to be referrals to, endorsements of, or affiliations with the linked entities. The Firm is not responsible for, and makes no representations or warranties about the contents of websites to which links may be provided from this website.

Furthermore, the owner of this website does not wish to represent anyone desiring representation based solely upon viewing this website or in a Country/State where this website fails to comply with local laws and ethical rules of that state. You may note that the use of the internet or email for conveying confidential or sensitive information is susceptible to risks of disclosure associated with sending email over the internet.

The Firm advises against the use of the communication platform provided on this website for exchange of any confidential, business or politically sensitive information. User is expected to use his or her judgment and such information shared will be solely at the user’s risk.

Communication through this website in any form shall be for the purpose of enquiries only and shall not hold good for service of any kind of court proceedings, summons, advance notice, pleadings etc. For service of any such document and/or notice to the Firm and/or to any of its partners under the act or rules including under CPC, Cr. PC and/or any other law shall be served at our concerned office or to the concerned advocate dealing with the matter.