The Reserve Bank of India’s (RBI) Draft Master Direction on Prepaid Payment Instruments (PPIs), 2026 is more than a consolidation of regulations governing digital wallets and prepaid instruments. It indicates a significant shift in regulatory philosophy towards the principle of “same activity, same risk, same regulation”.
In the growing Indian economy, financial technology (fintech) firms have benefited from regulatory exceptionalism owing to limited functions compared with traditional financial institutions. Acknowledged as drivers of innovation, they were often subject to lighter compliance requirements and bespoke regulatory frameworks. However, as digital payment systems have become integral to the financial ecosystem, the distinguished treatment continues to fade.
Non-bank PPIs face bank-style rules

Associate partner
SNG & Partners
The draft subjects non-bank PPI issuers to governance standards traditionally associated with regulated financial institutions. Promoters and directors must satisfy stringent “fit and proper” criteria, while customer onboarding is brought directly within the RBI’s know your customer (KYC) framework.
The emphasis is no longer on the technological identity of the service provider but on the risks arising from customer onboarding, anti-money laundering compliance, and payment activities.
The same convergence is visible in customer protection and prudential regulation by mandating the PPI issuers to maintain mechanisms to redress grievances, provide ombudsman access, comply with dispute resolution and compensation frameworks, and safeguard customer funds through segregated escrow accounts subject to auditor oversight. Full KYC PPIs must also operate through interoperable payment networks such as unified payments interface (UPI), a popular QR code-based online payment mechanism and card systems.
Same activity, same regulation now

Senior associate
SNG & Partners
The RBI’s approach mirrors a broader global shift towards activity-based supervision and away from what may be termed “fintech exceptionalism”.
The Financial Stability Board (FSB), in its report on fintech and market structure in financial services, observed how technological innovation has aided fintech firms and large technology companies to perform functions traditionally associated with banks and financial institution. The report advocated a technology-neutral framework that classifies activities according to their primary economic function, enabling regulators to assess the risks generated by such activities and their implications for financial stability.
The Bank for International Settlements (BIS) has advanced a similar position, arguing that comparable activities generating comparable risks should not escape regulatory oversight merely because they are conducted by non-traditional actors.
European regulators have embraced a similar philosophy. The European Central Bank (ECB) expressly states that it follows the principle of “same business, same risks, same supervision”.
The draft fits squarely within this global trajectory. The RBI is not regulating wallet issuers more rigorously because they are fintech companies. Rather, it is recognising that activities involving customer funds, payment execution, operational resilience and consumer protection generate risks comparable to those associated with regulated financial intermediaries.
The significance of the draft therefore extends beyond digital wallets. They signal the ripening of India’s fintech ecosystem with stern answerabilities. Once an activity becomes integral to the functioning of the financial system, the rationale for differentiated treatment weakens considerably.
India ends fintech regulatory exceptionalism
Regulatory exceptionalism may be justified when a technology is nascent. However, India approaches and reduces exceptionalism in its own way while devising its own strategies and establishing and attaching its ecosystems of UPIs, Aadhar (UID or unique identification most commmonly used for KYC), BHIM (Bharat Interface for Money, a UPI app developed by the government), etc., with the world players of PPIs.
The draft PPI directions thus reveal a broader transformation in Indian financial regulation. The relevant question is no longer whether an entity is a fintech company, a bank or a technology platform, but if it is equivalent in its own working atmosphere. The relevant questions are what function it performs, what risks it creates, and what safeguards are necessary to address those risks. The “end of exceptionalism” clearly shows the RBI’s push to phase out relaxed rules, explicitly categorising all PPIs and strictly enforcing full-scale banking compliance.
This marks India’s move towards a regulatory philosophy shaping financial regulation worldwide: Similar risks demand similar safeguards, irrespective of the identity of the entity performing the activity.
Lokesh Malik is an associate partner and Samarjeet Deo is a senior associate at SNG & Partners

One, Bazar Lane, Bengali
Market, New Delhi – 110001
Contact details:
T: +91 11 43582000
























