The Reserve Bank of India on June 15, 2026 issued comprehensive Amendment Directions on Advertising, Marketing and Sale of Financial Products and Services by Regulated Entities, with effect from January 1, 2027. Issued under Press Release 2026-2027/460, these directions significantly strengthen the regulatory framework governing how banks, NBFCs, Housing Finance Companies, and other regulated entities (REs) advertise, market and sell financial products and services — whether their own or third-party — to customers.
The directions had a long gestation: first announced in the Statement on Developmental and Regulatory Policies dated February 6, 2026, draft directions were published on February 11, 2026 for stakeholder consultation. Feedback was examined, modifications incorporated, and the final directions issued on June 15, 2026. A companion set of directions simultaneously amends the Undertaking of Financial Services framework governing agency business and referral services. Together, they cover 17 separate notifications spanning every category of RE — from Commercial Banks to Rural Co-operatives to NBFCs and Housing Finance Companies.
⚡ Key Facts at a Glance
2026-27/460
🏦 Which Regulated Entities Are Covered?
RBI has issued parallel, entity-specific amendment directions across multiple regulated entity categories. Broadly, one set amends the Responsible Business Conduct (RBC) Directions governing advertising, marketing and sale conduct, while the other amends the Undertaking of Financial Services Directions governing agency business and referral-service arrangements. Both sets take effect from January 1, 2027.
🧭 Why RBI Issued Two Parallel Amendment Sets
The June 15, 2026 package is easier to understand if read as a two-layer compliance framework. One set of amendments updates the Responsible Business Conduct (RBC) directions, which govern how regulated entities advertise, market, recommend, sell and service financial products for customers. The second set updates the Undertaking of Financial Services directions, which govern the conditions under which certain regulated entities may undertake agency business, referral arrangements or related financial service activities.
- RBC amendments: customer protection rules — disclosures, dark patterns, mis-selling, bundling, suitability, conduct of DSA/DMA channels, post-sale checks, complaint handling and compensation architecture.
- Undertaking of Financial Services amendments: structural permission framework — what kinds of agency / referral / financial service arrangements are permitted, and on what conditions.
- Read together: the first set tells REs how they must behave while selling; the second tells many REs what kinds of business arrangements they may undertake while doing so.
📖 Section 1 — New Definitions Inserted into Paragraph 4
The Amendment Directions insert six new definitions into the principal Responsible Business Conduct Directions. These definitions are the building blocks for the entire new framework — every operative provision in Sections F.1 through F.7 relies on these terms being precisely defined.
DSA / DMA Sub-Agent [Para 4(10C)]: An individual engaged by a DSA/DMA who is involved in selling/marketing activities on behalf of a bank at the point of customer interface.
Explanation: Where an individual is directly engaged by a bank under an outsourcing arrangement for selling/marketing activities, the instructions applicable to both DSA/DMA and DSA/DMA sub-agent shall apply to such an individual.
📋 Section 2 — F.1: Comprehensive Policy Requirement (Paragraphs 85A & 85B)
Every regulated entity must now put in place a board-level policy covering advertising, marketing, and sale of both own and third-party financial products. This policy is the foundation — all operational requirements in F.2 through F.7 flow from it.
🤝 Section 3 — F.2: Engagement of DSAs / DMAs (Paragraphs 85C–85F)
This is one of the most operationally intensive sections — directly regulating the conduct, identification, and accountability of Direct Selling Agents (DSAs) and Direct Marketing Agents (DMAs) who form the front line of financial product distribution in India.
▸ DSAs/DMAs must provide an undertaking to abide by the Code (before any sale activities begin)
▸ The bank's own employees and TPPS representatives must similarly undertake compliance
▸ The agreement with each DSA/DMA must specify penal/disciplinary actions for Code violations
▸ The Code of Conduct must be displayed on the bank's website for public reference
✅ Section 4 — F.3: Consent Aspects (Paragraphs 85G–85I)
The consent framework is perhaps the most significant structural shift in these directions. It moves away from implied consent and passive acceptance toward a rigorous, documented, explicit-consent architecture.
For forms with multiple products: each product must be clearly enumerated and the customer must have the option to choose only the desired product(s). Consent records must be stored for 1 year after cessation of the contractual agreement.
▸ Fees, charges, and interest rates
▸ Risks involved
▸ Financial commitment required from the customer
▸ Lock-in conditions
▸ Exit terms including penalties
Where RBI or another regulator has prescribed a specific format (such as Key Facts Statement / KFS, or Most Important Terms and Conditions / MITC), the bank must use that prescribed format.
📢 Section 5 — F.4: Advertisement & Marketing (Paragraphs 85J–85O)
F.4.1 — Promotional Materials / Communications (Paras 85J–85M)
F.4.2 — Conduct of Bank Employees, DSAs/DMAs and Sub-Agents (Paras 85N–85O)
Banks must ensure that all employees, DSAs/DMAs, sub-agents, and TPPS representatives deployed for sale/marketing in bank premises comply with all of the following ten obligations:
💼 Section 6 — F.5: Sale of Financial Products / Services (Paragraphs 85P–85X)
F.5.1 — Suitability and Appropriateness (Para 85P)
Product factors: Features, risk-return attributes, time horizon, complexity, fee structure
vs.
Customer factors: Age, income, level of financial literacy, risk tolerance
Where any financial sector regulator (SEBI, IRDAI, PFRDA) has prescribed a specific suitability assessment methodology for a product regulated by it, the bank must adhere to that prescribed methodology.
F.5.2 — Application Forms and Documentation (Paras 85Q–85T)
F.5.3 — Measures for Prevention of Mis-Selling (Paras 85U–85X)
🔁 Section 7 — F.6: Feedback and Compensation to Customers (Paragraphs 85Y & 85Z)
A bank must establish a mechanism to seek customer feedback within 30 days of the sale of any financial product/service. The mechanism must verify that customers have understood both the features and the risks of what they purchased. It may include random-sample call-backs or surveys conducted by a department/vertical not associated with product sales (ensuring independence). A half-yearly report on feedback findings must be prepared and used for reviewing existing policies and product features.
Customers may lodge a mis-selling complaint within: (a) the timeline prescribed by the relevant regulator, or (b) 30 days of receiving the signed copy of T&Cs/agreement (where no regulator timeline is specified). Where mis-selling is established, the bank must: (i) refund the entire amount paid for the financial product/service; (ii) intimate the customer of cancellation (where applicable); and (iii) compensate the customer for any loss arising from mis-selling, as per its approved policy.
🔗 Section 8 — F.7: Adherence to Other Regulations (Paragraph 85ZA)
🕵️ Section 9 — Annex IIA: 11 Dark Patterns Prohibited in Banking
The most vivid and practically impactful part of these directions is Annex IIA — the illustrative list of 11 dark patterns specifically relevant to banks. Each is defined precisely, with banking-specific illustrations so there is no room for ambiguity about what is prohibited.
Falsely stating or implying urgency or scarcity to push an immediate purchase. Examples: fake countdown timers, "offer ends soon" messages, pre-approved loans with falsely imminent interest rate hike warnings.
Adding products/services, charity payments, or insurance to a checkout without customer consent. Example: defaulting loan protection insurance or online fraud protection to "selected" during a loan application.
Using guilt, fear, ridicule, or shame to prevent a customer from opting out. Example: "No, I don't want extra security for my account" as the decline button text when opting out of a service.
Forcing a user to buy/subscribe to an unrelated service or share personal data to access what they originally wanted. Example: pop-ups that redirect to loan section even when user clicks the close/exit button.
Making cancellation of a paid subscription impossible, hidden, ambiguous, or requiring pre-loaded payment authorisation for a "free" trial. Example: credit card or insurance sign-up is easy; cancellation buried behind multiple confirmation steps.
Manipulating UI to highlight preferred options and obscure others. Examples: bank-preferred option in bright colour; default consent as "Yes"; account-closure option buried deep in navigation.
Advertising one outcome and delivering another. Examples: lower interest rate advertised, higher rate charged at application; savings account rate without minimum balance disclosure; lifetime-free credit card with undisclosed transaction minimum.
Concealing price elements, revealing them post-confirmation, advertising as "free" without disclosing in-app purchase requirements, or blocking use of paid services unless extra purchases are made. Example: not disclosing processing fees upfront.
Masking ads as news, user content, or urgent account alerts. Examples: push notifications disguised as "Important: Your account might benefit from this" but actually promoting a new product.
Repeated, persistent interruptions to push a transaction after the customer has already declined. Examples: repeatedly asking to enable non-essential cookies; mandatory dialogue boxes requiring selection before leaving an app.
Deliberately confusing language, double negatives, or ambiguous choices to misdirect the customer. Example: "Uncheck this box if you do not want to receive offers" — double negative designed to confuse.
🏢 Section 10 — Companion Directions: Agency Business & Referral Services
Alongside the Responsible Business Conduct Amendment Directions, RBI simultaneously issued a second batch of directions amending the Undertaking of Financial Services Directions, 2025. These cover the regulatory framework governing agency business arrangements and referral services offered by REs — the legal backbone through which TPPS distribution is structured. The feedback received on the draft directions has been incorporated into these final directions, which also take effect from January 1, 2027.
📊 Section 11 — Impact Analysis: Who Is Affected and How
🏦 Banks & NBFCs
Must revamp all digital UIs for dark pattern compliance; update consent flows to default-no; publish DSA/DMA lists; create or overhaul sales policies by January 1, 2027. Major operational and technology work required.
🤝 DSAs / DMAs
Subject to Code of Conduct requirements, cannot falsely represent as bank employees, must hold relevant certifications, and face formal accountability through bank agreements including penal clauses. Business correspondent organisations face the highest scrutiny.
👤 Bank Customers
Strongest consumer protection framework since the Banking Ombudsman Scheme. Right to suitability assessment; full refund + compensation for mis-selling; default-no consent; product documents in regional language; easy unsubscription; and a 30-day feedback check-in.
🏢 TPPS Providers (Insurers, AMCs, etc.)
Cannot offer direct/indirect incentives to bank employees for their products' sale. Banks must not advertise TPPS as their own products. Clearer separation between the bank's role and the TPPS Provider's role must be communicated to customers.
💻 Fintech / Digital Lending Platforms
UX/UI teams must audit every user flow for dark patterns. Default-yes consent boxes, forced pop-up redirects, pre-selected add-on products, and manipulative "decline" button text are all now explicitly prohibited under named categories.
⚖️ Legal & Compliance Teams
New definitions of mis-selling (5 limbs), dark patterns (11 types), explicit consent, and compulsory bundling must be embedded in legal review processes. Mis-selling liability now extends to unsuitable sales even with customer consent.
✅ Section 12 — Compliance Action Checklist (For Banks & NBFCs)
- ✅ Board-approved Advertising & Sale Policy (Para 85A/85B): Draft or update a comprehensive policy covering suitability criteria, feedback mechanisms, customer compensation for mis-selling, and DSA/DMA governance — by December 31, 2026
- ✅ DSA/DMA Public List on Website (Para 85C): Build and publish the full DSA/DMA list with name, type, address, engagement period, and products dealt with — and implement a 7-calendar-day update process
- ✅ Code of Conduct (Para 85F): Publish Code of Conduct on website; obtain signed undertakings from all DSAs/DMAs; ensure agreement with each DSA/DMA specifies penal provisions for Code violations
- ✅ Consent Infrastructure Overhaul (Paras 85G–85I): Audit all consent flows — physical and digital — to ensure explicit consent mechanisms; default-no UI design; enumeration of individual products in multi-product forms; and 1-year consent record retention
- ✅ Dark Pattern UI Audit (Para 85X): Commission an internal or external audit of all digital interfaces (website, mobile app, internet banking) against the 11 prohibited dark pattern categories in Annex IIA; remediate all identified issues before January 1, 2027
- ✅ Sales Staff & DSA/DMA Conduct Training (Para 85N): Train all employees, DSA/DMA sub-agents, and TPPS representatives on the 10-point conduct code, calling-hours restrictions (09:00–19:00), and identification requirements
- ✅ Incentive Structure Review (Para 85U): Audit all commission and incentive structures for bank employees involved in TPPS sales — eliminate any direct or indirect compensation from TPPS Providers to bank employees
- ✅ Bundling Policy Review (Para 85V): Identify all product bundles and verify: voluntary bundles have explicit consent; mandatory risk-mitigant products (e.g., home loan insurance) give customer free choice of provider; complimentary services are genuinely at no cost
- ✅ Post-Sale Feedback Mechanism (Para 85Y): Establish a 30-day post-sale feedback process (call-backs or surveys) run by a department independent of sales; set up a half-yearly feedback report to senior management/board
- ✅ Mis-Selling Complaint & Compensation Mechanism (Para 85Z): Update grievance redressal procedures to handle mis-selling complaints within the 30-day window; implement a full-refund + loss-compensation policy; train customer care teams on the new mis-selling definition (all 5 limbs)
These amendments do not operate as a standalone code for every possible customer-facing interaction by all financial-sector participants. They amend specific RBI directions applicable to specified categories of regulated entities. For compliance purposes, each institution should read the relevant entity-specific amendment notification together with its principal directions, outsourcing / digital lending / fair practices requirements, sectoral conduct rules, and applicable consumer-protection or telecom-consent frameworks.
This article is for informational and educational purposes only and does not constitute legal or compliance advice. Verify all requirements with the official RBI notifications before relying on this content for compliance purposes. The directions quoted above apply to Commercial Banks; parallel directions with equivalent provisions have been issued for all other regulated entity categories.


