Who Regulates What: RBI, SEBI, IRDAI, NPCI
Four bodies regulate Indian fintech and they do not divide the ground neatly. Which one owns the question you are asking, which products answer to more than one, and why NPCI is not a regulator at all.
Four bodies regulate Indian fintech and they do not divide the ground neatly. Which one owns the question you are asking, which products answer to more than one, and why NPCI is not a regulator at all.
Knowing who regulates you is half of it. Regulatory Changelog → records when each rule arrived, and which are still ahead.
Four bodies regulate Indian fintech and they do not divide the ground neatly. This page answers one question: whose rules govern the thing you are building?
The list is derived from the guides themselves. Each product guide cites the instruments it rests on; this page reads those citations rather than restating them, so it cannot drift from what the guides actually say. A guide citing a regulator this page does not describe stops the build — a map whose job is completeness should fail loudly rather than quietly omit something.
Three things worth knowing before reading the list, because each one catches people out:
| The trap | What is actually true |
|---|---|
| “NPCI is my regulator” | NPCI is a counterparty, not a regulator. It operates UPI and CTS and sets scheme rules you must follow — but it does not license you. Your licence comes from the RBI, and your access usually comes through a sponsor bank |
| “One product, one regulator” | 10 of the 19 guides cite more than one. Embedded insurance sits under the RBI and IRDAI, with both changing the same checkout screen on the same day |
| “I am not regulated, I only supply software” | A supplier can become a regulated entity by putting its name on the product, materially modifying it, or using it beyond its intended purpose. Covered on the AI regulation page |
Banking, payments, lending, and anyone holding customer money. 17 guides.
The rails — UPI, CTS, and the schemes that run on them. 4 guides.
Investment advice, securities, and anything sold as a market product. 3 guides.
Insurance, and everyone who distributes it. 2 guides.
Money-laundering reporting, under the PMLA. 2 guides.
Aadhaar: who may use it, and how it must be stored. 2 guides.
These sit under more than one at once. That is where compliance work is usually underestimated, because each regulator has its own timetable and they rarely coincide.
| Guide | Regulators |
|---|---|
| Video KYC | RBI · UIDAI |
| Recurring Payments | RBI · NPCI |
| Cross-Border Payments | RBI · FIU-IND |
| Embedded Insurance | RBI · IRDAI |
| UPI Switch Infrastructure | RBI · NPCI |
| SME Treasury | RBI · SEBI |
| Government ID Masking | RBI · SEBI · IRDAI · UIDAI |
| Cheque Reading | RBI · NPCI |
| AML Monitoring Systems | RBI · FIU-IND |
| Agentic Payments | RBI · NPCI |
And 1 guide cites no regulator at all: Document AI. That is correct rather than an omission — it is a capability rather than a regulated activity, and the rules that apply come from whatever you use it for.
All nineteen, sorted by what you are trying to do.
Which licence you need, what it costs, how long it takes.
Which APIs are self-serve and which are gated.
The instruments themselves, in depth.
This page maps products to regulators as the guides cite them. It does not tell you which regulator applies to your business, which depends on what you do rather than what you build. Nothing here is legal advice, and Indian financial regulation changes by notification. Confirm your own position with qualified counsel.
This page is a map rather than a source of claims. Each guide it points at carries its own dated, typed sources.
Checked September 2026. The mapping is regenerated from the guides by gen_regulator_map.py.
Opens your assistant with this page as the source, and a question rather than a summary. It will ask what you are building before it answers.
Nothing is sent from here. The link carries only this page’s title and address.