Lending Infrastructure

Encryption Is Not the LMS Security Question That Matters

Every LMS vendor says the data is encrypted. RBI's cybersecurity direction asks a harder question: who can access it, whether that access is logged, and whether a subcontractor can too.

Encryption Is Not the LMS Security Question That Matters: cover art

Every LMS vendor answers the encryption question the same way: yes, at rest and in transit, with a named standard. It is the easiest security question to ask and the easiest one to get a confident answer to, which is exactly why it is not the question that decides whether a system is actually secure.

Quick answer

Encryption protects data that has already been reached without authorization. It says nothing about who can reach it in the first place. RBI’s cybersecurity direction for NBFCs asks the harder questions instead: whether access is tied to a real role, whether privileged access is logged and supervised, whether multi-factor authentication guards elevated access, and whether a vendor’s own subcontractors are assessed for the same risk. Four controls, none of them encryption, decide the audit.

Ask a vendor “is the data encrypted” and the answer is always yes, because it is the one security claim every platform can make truthfully with no real differentiation between vendors. Ask “who can see this borrower’s data, and can you prove why they were allowed to” and the answers start to differ, because that question exposes whether access control is a real discipline or a default everyone has admin rights to.

Control one: access tied to a role, not a job title

RBI’s cybersecurity direction for NBFCs requires access to be based on well-defined user roles, not on a job title or a standing grant that outlives the reason it was given. The difference matters in practice: a role-based model asks what this specific function needs to see and do, and grants exactly that. A job-title model asks what everyone with this title has always had, and grants the accumulated total, which is how a collections analyst ends up with read access to the entire loan book instead of the accounts assigned to them.

The audit question that exposes the gap is simple: pick five active users and ask why each one has the access they have. A role-based system answers in one sentence per user. A title-based system produces a shrug and a promise to review it.

Control two: privileged access is supervised, not just granted

For NBFCs in the Middle Layer and above, elevated or privileged access, the kind that can change a classification, reverse a posting, or export the full borrower database, needs more than a grant. It needs a documented business reason, logged activity, and active supervision, not a one-time approval that then goes unreviewed for years.

This is where audit trail and access control meet without being the same control: an audit trail records what happened after the fact, and access supervision decides who was allowed to make it happen in the first place. A system can have a flawless edit log and still fail here, if the number of people who could have made that edit was never actually bounded.

Control three: multi-factor authentication for anyone with elevated access

A password alone is not sufficient for anyone with privileged access to a critical system, under RBI’s direction. Multi-factor authentication is required specifically where the access itself is elevated, not necessarily for every borrower-facing login, which is a distinction worth getting right in a vendor conversation: ask specifically whether MFA is enforced for admin, database and configuration-level access, not just whether the platform “supports” MFA somewhere in its settings.

A platform that offers MFA as an optional toggle a lender has to remember to turn on is not the same as one that enforces it for privileged roles by default. The gap between “supports” and “enforces” is where this control quietly fails.

Control four: a vendor’s subcontractor is still your risk

RBI’s direction requires outsourcing contracts to include monitoring provisions confirming the service provider’s own security is adequate, with audit and inspection rights the lender can actually exercise, and separately requires a vendor risk assessment that covers single-point-of-failure and supply-chain exposure. In practice, this means the LMS vendor’s own subcontractors, an infrastructure host, a DR site operator, a payments processor, sit inside the lender’s own accountability, not outside it.

The question worth asking a vendor is not “are you secure.” It is “list your subcontractors with access to our data, and show us how each one is assessed.” A vendor who cannot answer the second question has not actually thought about the first one.

Where encryption actually fits

None of this makes encryption unimportant. It is table stakes: a system without it fails immediately and obviously. But table stakes is exactly the right frame, because a security review that stops at “is it encrypted” has confirmed the one thing every serious vendor already does correctly, and has not touched the four controls where vendors actually differ from each other, and where a real gap actually costs a lender something after go-live.

There are three honest ways to run a security review that catches this. Ask the four questions above directly, in writing, and require specific answers rather than general assurances. Bring in a security-specific reviewer alongside the standard vendor evaluation, which costs time the procurement timeline may not have budgeted. Or treat RBI’s cybersecurity direction itself as the checklist, since it already names the controls a regulator will ask about in an exam, whether or not the vendor volunteers them first.

Frequently asked questions

Is encryption enough to secure a loan management system?

No. Encryption protects data that has already been reached without the right key, which matters, but it answers a narrower question than the one a regulator actually asks. RBI's cybersecurity direction for NBFCs cares more about who can access data in the first place, whether that access is logged and supervised, and whether the people or systems with access authenticate properly. A well-encrypted system with loose access control still fails the security test that matters.

What does RBI's cybersecurity direction require for access control in an NBFC's systems?

Access has to be based on well-defined user roles tied to an actual business need, not a job title or a standing grant. For NBFCs in the Middle Layer and above, elevated or privileged access needs closer supervision: logged activity, a documented reason, and multi-factor authentication for anyone with privileged access to a critical system. The requirement is under the Reserve Bank of India (Non-Banking Financial Companies - Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026.

Is a lender responsible for its LMS vendor's subcontractor's security?

Yes. RBI's cybersecurity direction requires a lender's outsourcing contracts to include monitoring provisions confirming the service provider has adequate security systems and to grant the lender audit and inspection rights, and separately requires vendor risk assessments proportionate to risk, covering single-point-of-failure and supply-chain exposure. A subcontractor the LMS vendor relies on, an infrastructure provider or a DR site operator, sits inside that same obligation.

What security questions should an LMS RFP ask, beyond encryption?

Four, in order of how often they get skipped: how access roles are defined and reviewed, how privileged access is logged and supervised, whether multi-factor authentication is enforced for anyone with elevated access to a critical system, and how the vendor's own subcontractors are assessed and monitored. Encryption at rest and in transit is table stakes and worth confirming, but it is the easiest of the five to verify and the least likely to be the actual gap.

Read next:


Chandramouli is the co-founder and CEO of Lokta, the agentic loan servicing platform. He has spent two decades building AI for decisions that change people’s lives, and has served as an independent director on an NBFC board. He writes here about the security questions a vendor demo never volunteers.

Bring us your live book

See what agents can do after approval.

Talk to us
Founder-led adoption

Adopt the agentic loan servicing platform.

Lokta is built for enterprise deployment, VPC or single-tenant cloud, with an audit trail in every state change. We work with a select group of institutions through a founder-led model: deep adoption, deliberate scope, a delivery window the team commits to in writing.