Digital banking platform for small finance banks, with UPI and IMPS switching

By LCode Technologies · Updated

In short

Small finance banks are licensed to serve underserved customers through high technology, low cost operations, so digital channels and secure mobile apps sit at the centre of their model. LCode Technologies offers an omni-channel digital banking platform, an NPCI-connected UPI & IMPS switch, the mPassbook app and D-Secure mobile app security for banks.

Key facts

Licensing frameworkRBI (Small Finance Banks – Licensing) Guidelines, 2025 [1]
Minimum paid-up capital or net worth₹300 crore, with different starting requirements for banks that transitioned from other entities [1]
Cybersecurity rulesRBI (Small Finance Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 [2]
Mobile app security rulesRBI (Small Finance Banks – Digital Payment Security Controls) Directions, 2026 [3]
Relevant LCode productsDigital Banking – Omni Channel, UPI & IMPS Switch, mPassbook, D-Secure

Which LCode products fit small finance banks?

NeedLCode productWhat it provides
Mobile, internet and agency banking with digital onboardingDigital Banking – Omni ChannelMobile, Web, Agency and USSD channels with self-registration, KYC/AML identity verification, Video KYC and maker-checker controls.
A UPI switch, IMPS switch and UPI PSP app for customersUnified Payment Interface (UPI) & IMPS SwitchConnects the bank to NPCI for real-time IMPS and UPI payments, with a Version 2.0 certified UPI switch and PSP app, merchant payments and collect requests.
A digital passbook for deposit and loan customersmPassbookA view-only app for savings, recurring deposit, fixed deposit and loan accounts, with statement generation and offline access.
Mobile app controls expected by RBID-Secure Mobile App SecurityRuntime application self-protection with root, jailbreak, tampering and debugger detection, SSL pinning and protection against man-in-the-middle and replay attacks.

What does RBI expect of a small finance bank's technology?

RBI's licensing guidelines say a small finance bank's operations should be technology driven from the beginning, conforming to generally accepted standards, and that a detailed technology plan should be furnished to RBI [1].

The guidelines describe small finance banks as serving small business units, small and marginal farmers, micro and small industries and other unorganised sector entities "through high technology-low cost operations" [1].

  • The minimum paid-up voting equity share capital or net worth is ₹300 crore [1].
  • A small finance bank that transitioned from an urban co-operative bank starts with a minimum net worth of ₹150 crore and must reach ₹300 crore within five years of commencing business [1].

What cybersecurity testing and incident reporting apply to small finance banks?

Under RBI's 2026 cybersecurity Directions for small finance banks, critical and customer-facing systems need vulnerability assessment at least every six months and penetration testing at least every 12 months, and cyber incidents must be reported within six hours of detection [2].

  • For critical information systems and systems in the DMZ with a customer interface, vulnerability assessment at least once every six months and penetration testing at least once every 12 months [2].
  • For non-critical systems, a risk-based approach decides whether and how often to test [2].
  • Cyber incidents are reported within six hours of detection on RBI's DAKSH platform, and the bank also notifies CERT-In [2].

What mobile app controls do RBI's Digital Payment Security Controls Directions require?

Device binding is mandatory, older app versions must be deactivated within six months of a new release and the app checksum must be published, while checking for rooted or jailbroken devices is optional [3].

  • The bank shall enforce a device policy so the app installs or runs only after baseline checks, including for a vulnerable operating system, malicious apps and insecure Wi-Fi configurations [3].
  • The bank shall deactivate older app versions in a phased but time-bound manner, within six months of releasing a newer version [3].
  • The bank shall ensure device binding of the mobile application through a combination of hardware, software and service information [3].
  • The bank shall host the checksum of the current app version on a public platform so users can verify it [3].
  • The bank may explore disallowing the app from installing or functioning on rooted or jailbroken devices [3].

This summary is for general information and is not legal or compliance advice. Always refer to the current text of the RBI Directions for small finance banks.

What should a small finance bank check when choosing a digital banking platform?

Check channel coverage for your customer base, digital onboarding, how the platform connects to NPCI and your core banking system, and whether its mobile app security and testing support match RBI's Directions.

  • Reach: mobile, web, agency and low-end channels suited to customers in rural and semi-urban areas.
  • Onboarding: KYC and identity verification that works without a branch visit.
  • Payments: UPI and IMPS connectivity, merchant payments and a customer UPI app.
  • App security: device binding, old-version deactivation and a published checksum [3].
  • Assurance: support for six-monthly vulnerability assessment and annual penetration testing of customer-facing systems [2].

Frequently asked questions

Why is technology central to small finance banks?

RBI's Small Finance Banks Licensing Guidelines, 2025 describe them as serving underserved segments through high technology, low cost operations, and say their operations should be technology driven from the beginning, with a detailed technology plan furnished to RBI.

How quickly must a small finance bank report a cyber incident?

Within six hours of detection, on RBI's DAKSH platform, under RBI's 2026 cybersecurity Directions for small finance banks. The bank also notifies CERT-In.

How often must small finance banks run vulnerability assessments and penetration tests?

For critical information systems and customer-facing systems in the DMZ, vulnerability assessment at least once every six months and penetration testing at least once every 12 months. Non-critical systems follow a risk-based approach.

Is device binding mandatory for a small finance bank's mobile banking app?

Yes. RBI's Digital Payment Security Controls Directions for small finance banks say the bank shall ensure device binding of the mobile application. Blocking rooted or jailbroken devices is optional.

Which LCode products are relevant for small finance banks?

Digital Banking – Omni Channel for mobile, web, agency and USSD banking; the UPI & IMPS Switch for NPCI payments; mPassbook for a digital passbook; and D-Secure for mobile banking app security.

Book a demo

See how LCode's software works for small finance banks. Tell us about your institution and the products you are evaluating.

Related guides

Sources

  1. Reserve Bank of India (Small Finance Banks – Licensing) Guidelines, 2025 (RBI/DOR/2025-26/175, 28 Nov 2025)Reserve Bank of India
  2. Reserve Bank of India (Small Finance Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 (RBI/DoS/2026-27/419, 31 Jul 2026)Reserve Bank of India
  3. Reserve Bank of India (Small Finance Banks – Digital Payment Security Controls) Directions, 2026 (RBI/DoS/2026-27/420, 31 Jul 2026)Reserve Bank of India