TL;DR

  • Recovery agent due diligence is no longer a standalone HR checklist item. RBI’s November 2025 NBFC directions tie it directly to the Board-approved outsourcing policy and its review cadence.
  • The obligation traces back to a 2008 RBI circular requiring individual-level verification of agency staff, a stricter standard than agency-level vetting alone. This substance persists into the 2025 framework (paragraph numbers below are secondary-sourced and should be confirmed against primary RBI text before external citation).
  • The NBFC remains responsible for a recovery agent’s conduct even when the agent is a third-party vendor.
  • A draft circular reported to be in circulation between February and June 2026 proposes mandatory IIBF certification for recovery agents. This is not confirmed as finalized as of this writing.
  • What auditors actually flag: due-diligence records that exist but aren’t linked to expiry dates, half-yearly Board reviews, or annual vendor reviews.
  • Compliance software should record due diligence per agency and per individual agent, tie those records to review-cycle dates, and produce an audit trail an examiner can query on demand.

An Auditor Just Flagged Your Recovery Agent Vetting as Undocumented

Nobody is telling you the vetting was bad. That’s the part worth sitting with.

In a growing number of NBFC examinations, the finding isn’t that a recovery agent was under-vetted, that background checks were skipped, or that a red flag went unnoticed. The finding is simpler and harder to argue with: the institution cannot produce, on demand, a record showing when due diligence was completed, when it expires, and when it was last reviewed at the Board level.

That’s a documentation and governance gap. The vetting itself may well have been sound. This distinction matters because the two problems have completely different fixes:

  • A vetting-quality problem gets solved by better background-check vendors or stricter hiring criteria.
  • A documentation problem gets solved by a system of record, one that ties due diligence to dates, to policy, and to a review cycle an examiner can actually trace.

Most NBFCs already have decent vetting practices for the recovery agencies they contract with. What most of them lack is proof, structured and queryable, that the vetting happened on schedule and was reviewed where policy says it should be reviewed. That gap is exactly what recent RBI direction changes are built to close.

The Individual-Level Verification Requirement Has a Longer History Than Most Compliance Teams Realize

The idea that an NBFC has to vet recovery agents individually, beyond the agency they work for, goes back further than most compliance teams assume. It traces to a 2008 RBI circular (reported as DBOD.No.Leg.BC.75/09.07.005/2007-08) that required due diligence and police verification at the level of the individual employees a recovery agency deployed, on the reasoning that a clean corporate entity can still employ agents with a history of misconduct.

That substance is understood to persist into the current framework. Trackers reference this obligation as carried into Paragraph 94 of the RBI (NBFC – Responsible Business Conduct) Directions, 2025, with a cross-reference to Paragraph 74 of the companion RBI (NBFC – Managing Risks in Outsourcing) Directions, 2025. Both sets of directions are reported as dated November 28, 2025.

Regulatory timeline tracing individual-level recovery agent due diligence from the 2008 RBI policy through the 2025 directions, an unconfirmed early 2026 draft, and current recordkeeping expectations.

What the Outsourcing Directions Actually Require, Beyond the Vetting Itself

The RBI (NBFC – Managing Risks in Outsourcing) Directions, 2025 build due diligence into a recurring governance cycle. Based on current secondary-sourced references, the structure looks like this:

  • A Board-approved outsourcing policy is required as the governing document for any outsourcing arrangement, recovery agencies included (reported as Paragraph 10).
  • Service-provider selection criteria must be defined and applied consistently, not decided case by case (reported as Paragraph 20).
  • Due diligence factors explicitly include how the vendor itself vets its own employees and any sub-contractors it uses, meaning the NBFC’s due diligence has to look one layer down into the vendor’s own hiring practices (reported as Paragraphs 29 to 31).
  • The NBFC retains responsibility for recovery agent conduct, even where the agent is engaged through a third-party vendor rather than directly employed (reported as Paragraph 17).
  • A central record of material outsourcing arrangements must exist and go before the Board on a half-yearly basis (reported as Paragraph 36).
  • Individual service providers are subject to a separate annual review (reported as Paragraph 38).

The pattern across all six of these is the same: due diligence is a recurring obligation with dates attached, half-yearly at the Board level, annually at the vendor level, verified again on schedule rather than filed away once.

Infographic outlining six recurring outsourcing obligations for NBFCs, including board-approved policies, service-provider selection, employee vetting, recovery agent conduct, central records, and annual reviews.

A Draft Circular Nobody Should Build Controls Around Yet

Separately from the confirmed November 2025 directions, a draft circular reportedly circulated between February and June 2026 proposes that recovery agents hold a certification issued by the Indian Institute of Banking and Finance (IIBF) before they can be deployed on collections work.

If finalized, this would add a fourth layer to the due diligence stack: agency-level vetting, individual-level vetting, ongoing conduct monitoring, and a portable, third-party-issued credential.

It hasn’t been confirmed as finalized. There’s no confirmed effective date, no confirmed final text, and no confirmed grace period for existing agents. The right posture here is to watch it, not to build compliance workflows or vendor contract clauses around it as though it were settled. Institutions that lock in operational controls against a draft risk building the wrong control twice.

What Compliance Software Actually Needs to Record

This is where recovery agency due diligence compliance software either earns its place in the audit or becomes one more system an examiner has to work around.

Given what’s outlined above, a system supporting recovery agency due diligence needs to do three specific things, well beyond storing documents:

  1. Record due diligence at both the agency and the individual agent level, with expiry dates attached. A single “vendor approved” flag isn’t enough when the obligation runs down to individual agents and their own re-verification cycles. Each agent-level record needs a completion date and a re-verification due date, not a static pass or fail.
  2. Tie those records to the institution’s actual review cadence. A due-diligence record sitting in a folder, disconnected from the half-yearly Board review or the annual vendor review it feeds, doesn’t help when an examiner asks whether the Board actually reviewed it on schedule. The record needs to be linked to the calendar event that policy requires, not just to the vendor file.
  3. Produce an audit trail an examiner can query on demand, instead of one compliance has to reconstruct from email threads and spreadsheets after the fact.

This is precisely what iTuring’s Model Governance module is built to do for the decisioning side of collections, and the same underlying architecture applies to agency oversight records. An immutable audit trail means once a due-diligence record and its review date are logged, they can only be appended to with a visible history, never quietly edited. 

Maker-checker approval means no single person can log a due-diligence review as complete without a second party confirming it, which is exactly the control gap that shows up when an auditor asks who signed off on this, and when.

 Together, this answers all three requirements above: agent-level and agency-level records with dates, records linked to review cadence, and a trail that can be queried rather than reconstructed. The same governance layer carries SOC 2 Type II and ISO 27001 controls, so the audit trail itself is independently attestable, not just internally asserted.

Banks and NBFCs Are Working From Different Clauses

Everything above, specifically Paragraph 94 and its cross-reference to Paragraph 74, sits in the RBI (NBFC – Responsible Business Conduct) Directions, 2025. That’s an NBFC-specific instrument.

Banks operate under their own outsourcing and recovery-agent conduct guidance, structured differently and issued through a separate set of RBI directions. A bank compliance team reading this piece should confirm its own applicable directions rather than assume its obligations mirror the NBFC paragraph numbering above. The underlying principle, dated, individual-level due diligence tied to a recurring Board review, is reasonable good practice regardless of institution type. But the specific clause references here are NBFC-scoped.

Building the Audit Trail Before the Examiner Asks for It

The institutions that struggle in examination aren’t usually the ones with weak recovery agent vetting. They’re the ones who vetted properly and can’t prove it on the schedule RBI now expects: agency and agent level, dated, tied to a half-yearly Board review and an annual vendor review, retrievable without a scramble.

That’s a governance and record-keeping problem, and it has a governance and record-keeping fix. Whatever comes of the 2026 IIBF draft, the underlying expectation, dated, queryable, Board-linked due diligence, isn’t going away.