Regulatory Compliance

RBI & CERT-In Compliance
Built Into Every Feature

vcurd is engineered from the ground up for India's financial regulatory landscape — meeting RBI Digital Payment Security Controls, CERT-In cybersecurity guidelines, NPCI UPI reporting requirements, and NBFC-specific compliance mandates.

Regulatory frameworks covered

Regulatory Framework Coverage

vcurd maps every product feature to the specific clauses of Indian financial regulation — so you can demonstrate compliance without guesswork.

RBI

RBI Digital Payment Security Controls

vcurd's real-time scoring, audit trail, and FMR reporting module directly address the RBI Master Direction on Digital Payment Security Controls (January 2021), which mandates transaction monitoring, anomaly detection, and systematic fraud reporting for all regulated payment entities.

  • Transaction velocity limits & rule-based blocking
  • Real-time anomaly detection with ML scoring
  • FMR JSON export for quarterly submission
  • RBI reporting deadline countdown dashboard
  • 2FA trigger rules for high-value transactions
CERT-In

CERT-In Cybersecurity Guidelines

CERT-In's empanelment requirements for information security auditors and the CERT-In Directions 2022 mandate incident reporting, access controls, log retention, and encrypted storage. vcurd's architecture satisfies every technical requirement in this framework.

  • Immutable decision logs retained for 5 years
  • Role-based access control (viewer/analyst/admin)
  • Encrypted data storage and transmission
  • Breach notification workflow with alert escalation
  • Full audit trail with user attribution
NPCI

NPCI UPI Fraud Reporting

NPCI's UPI Procedural Guidelines require member banks to report fraud cases, maintain risk thresholds, and implement velocity controls. vcurd's rule engine and reporting module are purpose-built to fulfil NPCI's operational requirements for UPI fraud management.

  • VPA-level blacklist management
  • Per-transaction fraud probability scoring
  • Velocity controls: 1-hour and 24-hour windows
  • Alert linkage to fraud report submissions
  • New device and new beneficiary risk signals
NBFC

RBI Master Directions for NBFCs

NBFCs face specific obligations under RBI Master Directions — including gold loan LTV compliance under Circular No. RBI/2021-22/119, escrow account monitoring for payment aggregators, and bureau pull velocity controls to prevent loan-stacking fraud.

  • Gold loan LTV monitoring with 75% RBI threshold
  • Escrow balance variance detection (15% breach alert)
  • Bureau velocity: PAN-level 72h hard-pull tracking
  • Loan-stacking pattern detection across FIs
  • NBFC-specific risk scoring parameters

Financial Monitoring Report — Ready for Submission

vcurd generates RBI-compliant Financial Monitoring Reports with one click — structured, linked to source alerts, and exportable in the exact JSON format expected by RBI.

📑

FMR Export Module

Automated Financial Monitoring Report generation with deadline tracking and alert linkage

⏱️

Reporting Deadline Countdown

A persistent dashboard widget displays the days, hours, and minutes remaining until the next RBI FMR submission deadline. Compliance teams always know where they stand without checking external calendars.

📤

One-Click JSON Export

The FMR export generates a structured JSON payload conforming to RBI's prescribed format — covering transaction counts, flagged amounts, rule triggers, and ML verdicts — ready for direct submission or review.

🔗

Alert Linkage

Every line item in the FMR is hyperlinked to the originating alert record, including the rule that triggered it, the ML probability score, SHAP feature attribution, and the analyst who reviewed it.

Immutable Audit Logs — Always Inspection-Ready

Every decision, rule change, and model score is permanently recorded with full context. No retroactive editing. No gaps. Exactly what CERT-In and RBI examiners require.

🔒

Immutable Log Records

Audit log entries are write-once. No user — including administrators — can modify or delete a decision record after it is written.

👤

User Attribution

Every manual override, alert disposition, rule change, and LLM configuration update is attributed to the authenticated user who made it.

🕐

Timestamped Decisions

All transactions, rule evaluations, ML scores, and alert actions carry microsecond-precision UTC timestamps — traceable to the originating API call.

📥

CSV & JSON Export

Export any date range of audit logs in CSV or JSON format. Directly shareable with RBI examiners, CERT-In auditors, and internal compliance teams.

Gold Loan & Escrow Monitoring

Specialist compliance modules for NBFCs, payment aggregators, and lending platforms — monitoring the exact thresholds RBI has prescribed.

⚖️ RBI Threshold: 75% LTV

Gold Loan LTV Monitoring

vcurd monitors loan-to-value ratios for gold-backed lending in real time. When the LTV of any loan account breaches the RBI-mandated 75% ceiling — due to gold price fluctuations or additional drawdowns — the system raises an immediate alert with full breach context.

  • Real-time LTV calculation against current gold prices
  • Automatic breach alert when LTV exceeds 75%
  • Breach history log with recalculation timestamps
  • Supports manual LTV recalculation with updated valuations
  • Exportable breach report for RBI NBFC submissions
🏛️ Variance Alert: 15% Breach

Escrow Balance Compliance

Payment aggregators under RBI's PA-PG guidelines must maintain escrow accounts within prescribed balance tolerances. vcurd performs daily reconciliation between actual escrow balances and expected amounts, flagging variances above 15% for immediate compliance review.

  • Daily actual vs expected balance reconciliation
  • 15% variance breach detection with instant alerting
  • Consecutive breach auto-escalation to compliance lead
  • Breach timeline history for regulatory reporting
  • Configurable variance threshold per account

CERT-In Requirements — All Met

CERT-In Directions 2022 set a high bar for cybersecurity infrastructure. vcurd satisfies every requirement relevant to financial transaction monitoring systems.

Incident Logging

Every fraud event, rule trigger, and model decision is logged as a structured incident record with full context, preservable for 5 years as required by CERT-In Directions 2022.

Access Controls (RBAC)

Three-tier role-based access control — viewer, analyst, admin — limits data exposure and action permissions. No over-permissioned service accounts.

Audit Trail

Immutable, timestamped, user-attributed logs of all decisions and administrative actions. Exportable in CSV and JSON for examiner review at any time.

Encrypted Storage

All transaction data, alert records, and user credentials are stored encrypted at rest. Data in transit is protected via TLS 1.2+. JWT tokens for API authentication are signed with a configurable secret key.

Real-Time Alerting

Fraudulent transactions trigger instant alerts broadcast via WebSocket to all connected dashboard clients — with no polling delay. Alert severity escalation is automated.

Breach Notification Workflow

Consecutive breach detection triggers an automated escalation workflow — notifying compliance leads and generating a structured breach report ready for CERT-In submission within the 6-hour reporting window.

Ready to meet your compliance obligations?

Talk to us about deploying vcurd's compliance modules for your institution.