On-Prem, VPC or Shared Cloud: What RBI Actually Requires You to Prove
NBFCs argue about where the LMS should run. RBI's outsourcing rules do not name a hosting model. They ask whether you can audit the vendor, exit it, and prove disaster recovery works.

Your board asks why the new loan management system will run on shared cloud infrastructure instead of the data centre the NBFC already owns and pays for. The IT head answers with uptime numbers and a migration cost model. The board is not really asking about servers. It is asking whether the lender can still answer to its regulator if something goes wrong on someone else’s infrastructure.
RBI’s outsourcing rules for NBFCs do not name a hosting model. The Managing Risks in Outsourcing Directions, 2025 ask whether the lender can audit the service provider, exit it within a rehearsed timeframe, and prove a tested business continuity and disaster recovery plan. On-prem, a dedicated VPC and shared cloud can each pass or fail that test, on their own contract terms, not on the label.
Most deployment debates get framed as a spectrum: on-prem for control, cloud for cost and speed, a VPC as the compromise in between. That framing answers the wrong question. The direction that actually governs this decision was not written to prefer a location. It was written so a lender stays accountable for its borrowers no matter where the workload runs.
What the RBI direction actually requires
The Reserve Bank of India (Non-Banking Financial Companies - Managing Risks in Outsourcing) Directions, 2025 repeal and consolidate the earlier outsourcing guidance, including the 2023 master direction on IT outsourcing.
Source: RBI, Reserve Bank of India (Non-Banking Financial Companies - Managing Risks in Outsourcing) Directions, 2025, RBI/DOR/2025-26/363, 28 November 2025: paragraph 100 (repeal), paragraphs 34(vii), 74 and 76 (audit rights), paragraphs 40 to 43 and 83 (business continuity and disaster recovery), paragraphs 84 to 89 (exit strategy).
Base layer NBFCs get only the general financial-services-outsourcing chapters. NBFCs in the Middle, Upper and Top layers under Scale Based Regulation get the full direction, including the chapter written specifically for technology outsourcing, which is the chapter that covers a cloud or hosting arrangement.
Inside that chapter, the lender’s obligation is not to pick a location. It is to be able to show three things on demand: that it can audit the provider and any subcontractor the provider uses, that its business continuity and disaster recovery plan has actually been tested against how critical the service is, and that it has an exit strategy covering data removal and an alternative arrangement, not just a termination clause nobody has read since signing.
Test one: can you actually exercise audit rights
A clause that grants the right to audit a vendor is not the same as an audit that has happened. The direction extends this obligation to the vendor’s own subcontractors, which matters more than it sounds: a shared-cloud LMS vendor typically runs on top of an infrastructure provider, a payments processor, sometimes a separate DR site operator, and each of those is a subcontractor the lender’s audit right has to reach too.
The honest version of this test is not “does our contract include an audit clause.” It is “did our internal audit team, or an external auditor acting on our behalf, actually walk through this vendor’s environment in the last cycle, including its subcontractors.” Most lenders on the same shared-cloud vendor cannot each run a full independent audit without duplicating the same work, which is why the direction allows a shared or pooled audit arrangement. Ask a shared-cloud vendor whether they support one before assuming the audit right is theoretical.
An on-prem system does not get a pass here either. Audit-by-design is a property of the system and the process around it, not of where the servers sit. An on-prem LMS with no subcontractor visibility and no audit scheduled this year fails the same test a badly-contracted cloud vendor fails.
Test two: can you exit within a timeframe you have rehearsed
The exit-strategy paragraphs ask for three concrete things: an alternative arrangement the lender could actually move to, a documented protocol for removing or destroying the vendor’s copy of the data, and a cooperation obligation that survives the relationship ending badly, not just ending on good terms.
The test that actually matters is whether any of this has been rehearsed, not just written down. A contract that promises data export “within a reasonable timeframe” has never been tested against what that timeframe means when the vendor is uncooperative, insolvent, or simply slow. Ask when the lender last extracted a full, usable copy of its live loan book from the current vendor, on-prem or cloud, and how long it actually took.
This is where on-prem systems quietly fail the test more often than the label suggests. A heavily customised on-prem deployment, built up over a decade of one-off changes with no one left who fully understands the schema, can be harder to exit than a well-contracted cloud vendor with clean export tooling. Ownership of the hardware is not the same as portability of the data on it.
Test three: can you prove disaster recovery today, not on paper
The direction asks for a business continuity and disaster recovery plan proportional to how critical the service is, tested periodically rather than filed once and forgotten. For a live loan book, that criticality is about as high as it gets: a collections team that cannot see today’s due dates, or a servicing team that cannot post a repayment, has a regulatory problem within hours, not weeks.
The question to ask is narrow and unforgiving: when was the last full failover to the DR site, and did the recovery time and recovery point actually match what was promised on paper. A shared-cloud vendor that runs a documented failover test on a fixed schedule and can show the lender the result outranks an on-prem setup where the DR site has never once taken production traffic. The direction does not care which one it is. It cares whether the test has actually happened.
Where on-prem, VPC and shared cloud actually differ
None of this means the three deployment models are interchangeable. They differ in real, operational ways, just not in the way the compliance argument usually claims.
| What you are trading off | On-prem | Shared cloud |
|---|---|---|
| Cost to add capacity | Fixed hardware spend, planned quarters ahead | Variable, scales with usage, no lead time |
| Patch and security cadence | Set by the lender’s own ops team’s bandwidth | Set by the vendor, on a published schedule |
| Latency for field and collections apps | Predictable if the data centre is well placed | Depends on the provider’s regional footprint |
| In-house talent required to run it | Ops, DBA and infra security skills in-house | Contract-management and vendor-oversight skills |
A dedicated VPC sits between the two columns above on every row: closer to on-prem’s control and cost profile, closer to shared cloud’s patch cadence and scaling speed, and carrying the same audit, exit and DR obligations as either. It is a real option, not a compromise chosen to avoid the question.
The assumption that gets NBFCs in trouble
The assumption worth naming directly: on-prem is not automatically compliant, and shared cloud is not automatically a risk. Boards and auditors default to that assumption because it feels intuitively safer to point at hardware the lender owns. The direction does not reward that intuition.
An NBFC running its LMS on-prem, with no subcontractor audit trail, a DR site that has never taken live traffic, and an exit plan nobody has rehearsed, is in a weaker position under the direction than one running on shared cloud with a vendor who supports pooled audits, publishes DR test results, and offers a clean, tested data-export path. The server location was never the variable the regulator was asking about.
The deployment decision is a proof problem, not a location problem
There are three honest paths here, and none of them is free. Stay on-prem, but budget for the audit, DR-testing and exit-rehearsal discipline the direction actually asks for, which usually means dedicated ops headcount the lender has been underfunding. Move to shared cloud with a vendor who already runs pooled audits and published DR tests, which trades away some infrastructure control for a vendor’s existing compliance machinery. Or run in a dedicated VPC, keeping more isolation than shared cloud while still carrying most of the operational weight of on-prem, the defensible middle path for a lender that is not ready to fully hand over infrastructure but wants a cleaner audit and exit story than a decade-old data centre gives it.
Picking the shape is one decision. Finding a vendor whose platform actually runs the same way across all three, instead of forking into separate codebases the moment a lender asks for a different one, is a separate evaluation. Whichever path a lender picks, the work does not go away. It moves from arguing about the label to proving the same three tests, audit, exit, disaster recovery, every year, not just at go-live.
Frequently asked questions
Does RBI require NBFCs to host their loan management system on-premise?
No. The Reserve Bank of India's outsourcing rules do not mandate a hosting model or a server location. What they require, for NBFCs in the Middle, Upper and Top layers, is a board-approved outsourcing policy, real audit rights over the service provider, a business continuity and disaster recovery plan tested to the service's criticality, and an exit strategy the lender has actually rehearsed. On-prem, a dedicated VPC and shared cloud can each satisfy or fail that test on their own contract terms.
What does RBI's outsourcing direction actually require for a cloud-hosted LMS?
The Reserve Bank of India (Non-Banking Financial Companies - Managing Risks in Outsourcing) Directions, 2025 require the lender to retain the right to audit the service provider and its subcontractors, hold a business continuity and disaster recovery plan tested against the service's criticality, and keep a documented exit strategy covering data removal and an alternative arrangement. None of this depends on whether the LMS runs on-prem, in a dedicated VPC, or on shared cloud. It depends on what the contract and the lender's own testing can actually prove.
Which NBFCs does the RBI outsourcing direction's IT chapter apply to?
Base layer NBFCs are covered only by the general financial-services-outsourcing chapters. The IT-specific chapter, which covers technology outsourcing including cloud and hosting arrangements, applies in full to NBFCs in the Middle, Upper and Top layers under the Scale Based Regulation framework.
How should an NBFC actually decide between on-prem, VPC and shared cloud for its LMS?
Score each option against the same three tests: can you exercise a real audit right today, not just a clause in the contract; can you exit within a timeframe you have actually rehearsed, not estimated; and can you prove your business continuity and disaster recovery plan works, not just that one exists on paper. An on-prem stack that fails these tests is not more compliant than a shared-cloud vendor that passes them.
Read next:
- What has to move together when your LMS migrates: once the deployment decision is made, the sequencing that keeps a migration safe.
- What an audit trail actually needs to hold up in an LMS: the audit-by-design question this post’s first test depends on.
- Every Lender Replaces Their LMS Eventually: the five symptoms that put a deployment decision on the table in the first place.
Chandramouli is the co-founder and CEO of Lokta, the agentic loan servicing platform. He has spent two decades building AI for decisions that change people’s lives, and has served as an independent director on an NBFC board. He writes here about the tests a regulator actually applies, not the ones a vendor pitch assumes.


