DSA Compliance in 2026 means following 5 non-negotiable rules: never touch or deduct loan funds before disbursal, always deliver the Key Fact Statement (KFS) before signing, deduct TDS correctly under Section 393(1) of the Income Tax Act 2025, protect customer data under the DPDP Act, and contact customers only within RBI-approved hours. The 5 most common mistakes loan DSAs make are accepting commission by deduction from the loan amount, skipping KFS delivery, misapplying TDS rules, mishandling customer data, and contacting borrowers outside the 9 AM to 6 PM window. Any one of these can trigger DSA Code suspension, financial penalties, or permanent delisting by a bank or NBFC partner.
What Is DSA Compliance and Why Does It Matter in 2026?
DSA Compliance is the set of RBI, Income Tax, and data protection rules a Direct Selling Agent must follow while sourcing, processing, and getting paid for loan referrals. It matters because non-compliance now carries direct financial penalties, TDS disallowance, and DSA Code cancellation, not just warning letters.
DSA Compliance used to mean little more than collecting a borrower’s PAN and Aadhaar copy correctly. That changed with the RBI (Digital Lending) Directions, 2025 (RBI/2025-26/36, effective May 8, 2025), which fully came into force through 2026 and reshaped how every loan DSA operates. On top of this, the draft RBI (Commercial Banks – Responsible Business Conduct) Amendment Directions, 2026, introduced Sections 85B and 85C, which formally establish a DSA Code of Conduct requiring banks to supervise DSA and DMA behaviour, publish an updated public list of empanelled agents, and take penal action against non-compliant agents. For a DSA working across 275+ bank and NBFC partners, this means one DSA Compliance failure with one lender can now surface on a public, auditable record.
The financial services regulator is not issuing symbolic warnings anymore. In one recent enforcement action, RBI fined a private sector bank ₹2.27 crore for non-compliance with its outsourcing code of conduct and recovery agent norms, a direct signal of how seriously RBI DSA Guideline violations are treated across the lending chain. Every bank and NBFC now passes this scrutiny down to its DSA network, which is exactly why a documented DSA Compliance checklist has become essential operating infrastructure rather than a nice-to-have.
| Do You Know? The RBI’s draft DSA/DMA conduct rules proposed on February 11, 2026 were not left as a draft. RBI finalised them as the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Second Amendment Directions, 2026 (RBI/2026-27/115, dated June 15, 2026), which will come into effect from January 1, 2027, not July 1, 2026 as originally proposed. The final rules expand DSA/DMA conduct requirements, ban dark patterns in digital sales journeys, and mandate explicit customer consent for every product. (Source: Reserve Bank of India, Notification RBI/2026-27/115) |
Also Read: The 2026 RBI DSA Guidelines: An Operational Compliance Blueprint for Loan Agents
Earn ₹2 Lakh+ a Month Without Investment
Join Ruloans as a DSA partner — refer loans, help customers get funded, and earn on every disbursal. Zero investment to start.
- 275+ banks & NBFCs to offer
- Attractive payouts on every disbursal*
- Quick, paperless onboarding
Zero investment to start • Trusted by DSA partners across 4,000+ cities
*Earnings vary based on effort, referrals & loans disbursed. Payout depends on product, lender & loan amount. T&C apply.
What Do RBI DSA Guidelines Actually Require From a Loan DSA?
RBI DSA Guidelines require a DSA to work only with RBI-regulated entities, never hold or route loan funds, ensure the Key Fact Statement is delivered before signing, respect the borrower’s cooling-off period, and maintain complete digital records of consent, commission, and communication for every loan file.
The table below breaks down what RBI DSA Guideline compliance looks like in practical terms for a working DSA in 2026.
| Compliance Area | RBI DSA Guideline Requirement | Typical DSA Mistake |
| Fund flow | Loan amount moves directly from lender to borrower’s verified bank account | DSA deducts commission before crediting the loan |
| Disclosure | Key Fact Statement (KFS) delivered before loan execution, showing APR, fees, and penal charges | KFS shared after signing, or not at all |
| Cooling-off | Borrower can exit within a lender-defined window (commonly 1 to 3 days) by repaying principal plus proportionate APR | DSA discourages or blocks a borrower’s cooling-off exit |
| Data privacy | Only loan-relevant data collected, with explicit and revocable consent under the DPDP Act | Collecting contact list, gallery, or storage access; reusing data without consent |
| Contact conduct | Customer contact restricted to reasonable hours under the 2026 draft advertising and marketing amendment | Calling or visiting borrowers before 9 AM or after 6 PM |
| Public listing | Bank must display an updated list of empanelled DSAs/DMAs, updated within 7 calendar days of any change | DSA unaware their empanelment status has lapsed or changed |
| Record-keeping | Digital, auditable trail of consent, commission, and communication per loan file | Manual, incomplete, or missing documentation |
This table itself functions as a working DSA Compliance checklist. If any row is unchecked for a live loan file, that file is a DSA Compliance gap waiting to be flagged in a bank audit.
Also Read: Why Institutional Compliance Is the New Competitive Advantage for Digital DSAs
What Is a DSA Code and Why Is Compliance Tied to It?
A DSA Code is the unique identifier a bank or NBFC assigns to a Direct Selling Agent, used to track every loan application, disbursal, and commission payout back to that specific agent. Compliance failures are recorded against this code, and repeated violations can lead to code suspension or permanent delisting.
Think of the DSA Code as a DSA Compliance ledger. Every loan sourced under Loan DSA Guidelines is tagged to this code at the point of application, so a lender can trace the entire lifecycle of a file, from lead generation to disbursal to commission payout, back to one agent. This is precisely why RBI’s 2026 amendment requires banks to maintain a public, updated list of empanelled DSAs and DMAs on their websites, refreshed within 7 calendar days of any change in status.
For a DSA working with multiple lenders under a single roof, such as through the Ruconnect App‘s one-DSA-code-to-275+-lenders model, this traceability cuts both ways. It simplifies commission tracking and payout claims, but it also means a DSA Compliance lapse flagged by one bank can affect standing with the wider network. A DSA Code in good standing is now a business asset. A DSA Code flagged for repeated Loan DSA violations can quietly shut a DSA out of new empanelments across the industry.
Also Read: How Corporate DSA Code Registration Helps You Earn Higher Commission as a Loan Agent
Mistake 1: Deducting Commission Before Loan Disbursal
The single most common DSA Compliance mistake is adjusting or deducting commission from the loan amount before it reaches the borrower. Under RBI Digital Lending Guidelines, loan funds must move directly from the lender’s account to the borrower’s verified bank account, with zero intermediary pass-through.
Before 2025, it was routine for a DSA to help a borrower “net off” the processing fee or commission from the disbursed amount. Under the current RBI (Digital Lending) Directions, this is now a direct rule violation. Loan money must flow lender-to-borrower with no DSA, no Loan Service Provider (LSP), and no pooled account sitting in between, with the only permitted exceptions being co-lending structures and specific end-use disbursals such as builder or dealer payments.
The financial cost of this mistake compounds quickly. RBI has actively suspended co-lending arrangements at two mid-sized NBFCs in late 2025 specifically for violating the direct disbursal requirement, and banks are now running dedicated audits on DSA files to catch this exact pattern. A single flagged file can trigger a review of every loan the DSA has sourced with that lender in the preceding 12 months.
How to fix it: Commission must be credited separately by the lender into the DSA’s own registered bank account, after disbursal, never adjusted out of the borrower’s loan amount. Every payout should have a documented, lender-generated statement, not a manual calculation.
Mistake 2: Skipping or Delaying KFS Delivery
DSAs frequently share the Key Fact Statement after the loan is signed, or skip it entirely for smaller ticket sizes. RBI DSA Guidelines require KFS delivery before execution for every digital loan, regardless of loan amount.
The Key Fact Statement is a single-page, standardised summary showing the Annual Percentage Rate (APR), total repayment amount, processing fees, and penal charges in one place, and it must reach the borrower before, not during and not after, the loan contract is executed. Banks are treating KFS timing as one of the top enforcement priorities of 2026, running specific audits on DSA files to check whether the KFS timestamp precedes the signature timestamp.
This mistake is easy to make under pressure. A borrower wants funds urgently, the DSA wants to close the file fast, and KFS delivery gets treated as a formality to backfill later. That sequencing alone is a DSA Compliance breach, independent of whether the loan terms themselves were fair.
How to fix it: Always request the exact KFS template used by the lender and retain a digital, timestamped copy in the loan file before the borrower signs anything. If a lender cannot produce a standard KFS template, that itself is a red flag worth escalating before sourcing further business through them.
Mistake 3: Getting TDS on Commission Wrong Under Section 393
From April 1, 2026, TDS on DSA commission is governed by Section 393(1) Sl. No. 1(ii) of the Income Tax Act, 2025 (formerly Section 194H), at a flat 2% rate once cumulative commission from one payer crosses ₹20,000 in a financial year. The common mistake is continuing to reference the old Section 194H code or missing the aggregate threshold tracking.
Section 393(1) Sl. No. 1(ii) of the Income Tax Act, 2025 governs TDS on commission or brokerage payments at a 2% rate, and this deduction applies only once such payments exceed ₹20,000 in the financial year. This is a direct continuation of the old Section 194H rule, just renumbered and re-coded under the new Act. The table below summarises the numbers a DSA and their finance team need to track.
| TDS Parameter | Detail (FY 2026-27) |
| Governing section | Section 393(1), Sl. No. 1(ii), Income Tax Act 2025 |
| Old section replaced | 194H, Income Tax Act 1961 |
| TDS rate | 2% on commission or brokerage |
| Annual threshold | ₹20,000 cumulative per payer, per financial year |
| Effective from | April 1, 2026 |
| TDS deposit deadline | 7th of the following month |
| Quarterly return | Form 140 |
| TDS certificate to DSA | Form 16A, within 15 days of return filing due date |
| Penalty for late deposit | 1.5% interest per month of delay |
| Penalty for late return filing | ₹200 per day |
| Consequence of non-deduction by payer | 30% of the commission expense disallowed in the payer’s books |
A DSA earning commission from multiple banks and NBFCs under one DSA Code must track this ₹20,000 threshold separately per lender relationship, not in aggregate across all of them, since each payer deducts TDS independently. Missing this distinction is the most frequent bookkeeping error found in DSA Compliance checklist audits during tax season.
How to fix it: Update accounting software to the new Section 393 payment code, reconcile Form 16A received from every lender against actual commission credited, and flag any lender still filing under the old 194H code after April 2026 for correction.
Mistake 4: Mishandling Customer Data Under the DPDP Act
DSAs routinely over-collect customer data (contact lists, gallery access, storage permissions) or fail to honour consent withdrawal requests. Under the DPDP Act, this is a DSA Compliance violation carrying penalties that can run into crores, independent of any RBI action.
A DSA touches sensitive personal data every single day: PAN, Aadhaar, bank statements, income proof, and increasingly, Account Aggregator (AA) consent for faster underwriting. RBI DSA Guidelines are explicit that a DSA must never ask a customer to share an AA app OTP or login credentials directly, since that defeats the entire purpose of consent-based data sharing and is treated as a serious violation on its own. Apps and workflows that request phonebook, photo gallery, or file storage access without a clear purpose are being actively removed from app stores for exactly this reason.
The consequences are steep and separate from RBI enforcement. Non-compliance with data protection norms can carry penalties running up to ₹250 crore for serious violations, alongside reputational damage that is often harder to recover from than the fine itself. For a small or mid-sized Loan DSA operation, a single data mishandling complaint escalated to the regulator can end the business relationship with every lender partner simultaneously.
How to fix it: Collect only the data a specific loan application genuinely requires, obtain explicit and revocable consent for each use, delete data immediately upon a withdrawal request, and never request AA credentials or OTPs on a customer’s behalf.
Mistake 5: Violating the DSA Code of Conduct on Contact Hours and Record-Keeping
DSAs who call or visit borrowers before 9 AM or after 6 PM, or who cannot produce a documented consent and communication trail on demand, are now flagged under the RBI’s 2026 DSA Code of Conduct for DSAs and DMAs.
The draft RBI amendment Directions on Advertising, Marketing and Sales of Financial Products and Services, issued on February 11, 2026, specifically tighten scrutiny of DSA and DMA conduct, including a proposed rule restricting telephonic contact and customer visits to between 9:00 AM and 6:00 PM. The comment window on this draft closed March 4, 2026, with a proposed effective date of July 1, 2026, so DSAs should treat this as the operating standard even while final notification status is confirmed against the RBI website.
Layered on top of this, Sections 85B and 85C of the Commercial Banks Responsible Business Conduct Amendment Directions require banks to maintain due diligence, training records, and performance evaluation standards for every DSA and DMA they engage, alongside a control mechanism for penal action against non-compliant agents. A DSA who cannot produce a clean consent and communication trail for a given loan file, when the bank’s DSA Compliance team asks for one, is now the exception being actively hunted for in audits, not the rule being assumed.
How to fix it: Restrict all outbound calls and field visits to the 9 AM to 6 PM window as a default policy, log every customer interaction with a timestamp, and store consent records digitally so they can be produced within hours, not days, if a lender’s DSA Compliance team requests them.
| Do You Know? The Data Protection Board of India (DPBI) is not a future body, it is already active. Following the DPDP Rules 2025 notification on November 13, 2025, the DPBI began accepting complaints and opening inquiries immediately, even though full “hard enforcement” of all obligations is set for May 13, 2027. This means a customer data complaint filed against a DSA or its lender partner today can trigger a live investigation well before the 2027 deadline most DSAs assume they have time against. (Source: India Briefing, “India’s DPDP Timeline: Critical Compliance Deadlines for 2026-27”) |
Also Read: Challenges and Solutions for Bank DSAs: A Guide to Success
Earn ₹2 Lakh+ a Month Without Investment
Join Ruloans as a DSA partner — refer loans, help customers get funded, and earn on every disbursal. Zero investment to start.
- 275+ banks & NBFCs to offer
- Attractive payouts on every disbursal*
- Quick, paperless onboarding
Zero investment to start • Trusted by DSA partners across 4,000+ cities
*Earnings vary based on effort, referrals & loans disbursed. Payout depends on product, lender & loan amount. T&C apply.
What Does a Complete DSA Compliance Checklist Look Like?
A working DSA Compliance checklist covers registration status, fund flow, disclosure timing, tax deduction, data handling, and communication conduct, verified for every single loan file before it is closed.
| # | Checklist Item | Verified Before |
| 1 | DSA Code active and empanelment status current with the lender | Sourcing any new lead |
| 2 | Loan amount will disburse directly to borrower’s account, no deduction | Loan application submission |
| 3 | KFS shared with borrower and digitally timestamped | Loan contract signing |
| 4 | Cooling-off period terms explained to the borrower in writing | Loan disbursal |
| 5 | Consent for data collection is explicit, purpose-specific, and revocable | Any data collection step |
| 6 | AA-based data sharing done without requesting OTP or login credentials | Underwriting stage |
| 7 | TDS threshold tracked per lender under Section 393(1) | Commission invoicing |
| 8 | Customer contact logged, restricted to 9 AM to 6 PM under the DSA Code of Conduct | Every call or visit |
| 9 | Complete digital file: KYC, consent, KFS copy, commission statement | Loan closure and archiving |
| 10 | DSA training and performance records updated per lender’s due diligence policy | Quarterly review |
Running this DSA Compliance checklist against every open file, rather than treating it as an onboarding-day exercise, is what separates a DSA who survives a lender audit from one who gets delisted.
Also Read: How to Hire, Train, and Manage a High-Performing Team of DSA Loan Agents
How Do Compliance Mistakes Impact DSA Commission Across Different Loan Amounts?
The financial impact of a DSA Compliance mistake scales directly with loan amount and commission size. On a ₹10 lakh personal loan at 2% commission, a TDS or disclosure error affects ₹20,000 in payout; on a ₹75 lakh home loan, the same mistake affects commission running into lakhs.
DSA Compliance is not an abstract legal concern when real commission money is on the line. The table below shows how loan amount, typical commission percentage, and TDS interact across common loan products, so a DSA can see exactly what a compliance slip actually costs.
| Loan Product | Typical Loan Amount | Typical DSA Commission %* | Gross Commission | TDS at 2% (Sec 393) | Net Commission Payout |
| Personal Loan | ₹10,00,000 | 1.5% | ₹15,000 | ₹300 | ₹14,700 |
| Home Loan | ₹40,00,000 | 0.4% | ₹16,000 | ₹320 | ₹15,680 |
| Business Loan | ₹20,00,000 | 1.2% | ₹24,000 | ₹480 | ₹23,520 |
| Working Capital Loan | ₹25,00,000 | 1.0% | ₹25,000 | ₹500 | ₹24,500 |
| Loan Against Property | ₹50,00,000 | 0.6% | ₹30,000 | ₹600 | ₹29,400 |
| Machinery Loan | ₹15,00,000 | 1.3% | ₹19,500 | ₹390 | ₹19,110 |
| Car Loan | ₹8,00,000 | 2.0% | ₹16,000 | ₹320 | ₹15,680 |
| Education Loan | ₹12,00,000 | 1.0% | ₹12,000 | ₹240 | ₹11,760 |
| Gold Loan | ₹3,00,000 | 1.0% | ₹3,000 | Below ₹20,000 threshold** | ₹3,000 |
| Solar Panel Loan | ₹4,00,000 | 1.5% | ₹6,000 | ₹120 | ₹5,880 |
*TDS applies only once cumulative commission from a single lender crosses ₹20,000 in a financial year, so a single small-ticket gold loan payout may fall under the threshold on its own, but still counts toward the annual aggregate.
Notice that even a modest commission percentage error, a missed disclosure, or a wrongly timed KFS delivery on a high-ticket home loan or loan-against-property file can put ₹25,000 to ₹30,000 of commission on a single file at risk of being withheld or clawed back pending a DSA Compliance review. Across a DSA’s full monthly file volume, that is why a documented DSA Compliance checklist protects real income, not just regulatory standing.
Also Read: Top 10 Banks/NBFCs Offering Highest DSA Commission in India 2026
What Happens If a DSA Fails RBI DSA Guidelines?
Consequences range from DSA Code suspension and loss of empanelment with a specific lender, to TDS disallowance and interest penalties, to DPDP Act fines running into crores, and in serious cases, permanent removal from a lender’s public DSA list.
Enforcement is no longer theoretical. RBI’s own precedent shows a penalty of ₹2.27 crore levied on a bank for failures including code of conduct in outsourcing of financial services and recovery agent management, which is the exact category DSA conduct falls under. Banks facing this level of regulatory exposure have every incentive to push DSA Compliance obligations down to their agent network and enforce them strictly, since the bank, not the individual DSA, carries the primary regulatory liability.
For an individual Loan DSA, the practical consequences typically escalate in this order: a formal DSA Compliance query on a specific file, a temporary hold on new loan sourcing under that DSA Code, mandatory retraining or documentation submission, and finally, delisting from the lender’s publicly displayed DSA roster. Because RBI now requires this roster to be public and updated within 7 calendar days of any change, a delisting is no longer a quiet internal matter. It becomes visible and can affect empanelment conversations with other lenders as well.
Also Read: How to Build a High-Performing Loan Sales Network Under Your DSA Code
Conclusion
DSA Compliance protects your DSA Code, your commission, and your standing with every lender you work with, and getting it right from day one is far easier than fixing a violation after the fact. If you’re ready to operate under a compliant, transparent structure without juggling separate registrations for every bank, become a DSA partner and get one DSA code, access to 275+ bank and NBFC partners, 100% on-time payouts, and built-in compliance support across 4,000+ cities in India.
[Register as a Ruloans DSA Partner today.]
Earn ₹2 Lakh+ a Month Without Investment
Join Ruloans as a DSA partner — refer loans, help customers get funded, and earn on every disbursal. Zero investment to start.
- 275+ banks & NBFCs to offer
- Attractive payouts on every disbursal*
- Quick, paperless onboarding
Zero investment to start • Trusted by DSA partners across 4,000+ cities
*Earnings vary based on effort, referrals & loans disbursed. Payout depends on product, lender & loan amount. T&C apply.
FAQ
1. How do I become a DSA in India?
Any Indian resident aged 18+ (most lenders prefer 25+) with a valid PAN, Aadhaar, and bank account can register as an individual DSA. The process is fully digital: KYC upload, e-KYC via Aadhaar OTP, and a paperless agreement, usually completed within a few days through a bank, NBFC, or a multi-lender platform.
2. What is the difference between a DSA and a DMA?
A DSA (Direct Selling Agent) sources and processes loan applications for commission, while a DMA (Direct Marketing Agent) is typically restricted to marketing and lead generation only, without handling the full loan processing cycle. RBI’s 2026 conduct amendments regulate both under the same due-diligence and disclosure framework.
3. Is DSA commission income taxable, and under which head?
Yes. DSA commission is classified as business income under “Profits and Gains of Business or Profession” (PGBP), not salary or other income. This means DSAs typically file ITR-3 or ITR-4, and can claim legitimate business expenses before computing tax, unlike salaried income.
4. Do DSAs need GST registration?
It depends on structure. An individual DSA earning commission solely from banks/NBFCs generally falls under GST reverse charge, where the lender pays GST, so no individual registration is required for that income stream. Corporate or LLP DSAs must register once commission crosses ₹20 lakh annually (₹10 lakh in special category states), and any inter-state commission removes the threshold benefit entirely from the first rupee.
5. Can one person work as a DSA for multiple banks and NBFCs at the same time?
Yes, a DSA can hold empanelment with multiple lenders simultaneously, each assigning its own DSA Code. Corporate dsa platforms like Ruloans consolidate this into one DSA code across 275+ partners instead of separate registrations with each lender.
6. Does a DSA need a separate RBI license to operate?
No. RBI does not license individual DSAs directly. Compliance obligations flow through the bank or NBFC that empanels the DSA, which is regulatorily responsible for that agent’s conduct.
7. How much can a DSA earn per loan or per month?
Commission typically ranges from 0.4% to 2% of the loan amount depending on the product (lower for secured loans like home loans and LAP, higher for personal and business loans). Monthly earnings depend entirely on file volume and loan ticket sizes closed, not a fixed salary structure.
8. Can a bank terminate a DSA agreement without notice?
Most DSA agreements include a notice period clause (commonly 30 days) for termination without cause, but immediate termination without notice is typically allowed for compliance violations, fraud, or misconduct, since these are treated as breach of contract.
9. Is being a DSA a full-time career or only a side income option?
Both models exist. Many DSAs start part-time alongside salaried jobs (common among insurance agents, CAs, and tax consultants) and later scale into full-time, corporate DSA operations once volume and compliance systems justify it.
10. What documents are required to register as an individual DSA?
PAN card, Aadhaar card, a cancelled cheque or bank passbook, a passport-size photo, and address proof (utility bill, voter ID, or passport). Corporate DSAs additionally need incorporation documents, GST number, and entity PAN.

Every article on Ruloans is researched, written, and verified by a team of former bankers, certified financial planners, DSA industry veterans, and lending compliance specialists with over 25 years of hands-on experience in India’s loan distribution landscape. From decoding home loan eligibility and EMI planning for borrowers, to guiding DSA partners on commissions, registrations, and building a lending business — our content is grounded in real industry expertise, fact-checked against live RBI guidelines and current bank and NBFC policies, and built to help you make confident financial decisions.
