Skip to content
💳 Industry pack · FinTech · NBFC · Payment aggregator

RBI, SOC 2, ISO 27001.
All at once.

RBI master directions, SOC 2 Type II, ISO 27001, CERT-In 6-hour breach reporting, DPDP, capital adequacy, SDF prep for Indian FinTechs and NBFCs. Named DPO + CA + CS on retainer, parallel audit tracks.

RBIMaster directions mapped
SOC 2Type I + Type II prep
27001ISMS + certification
48hQuery SLA

Indian FinTech and NBFC operate under the most dense regulatory stack of any sector. RBI master directions (category-specific), SEBI (for AMCs and brokers), IRDAI (for insurance), CERT-In (6-hour breach reporting), DPDP (strict for financial data), SOC 2 Type II and ISO 27001 (demanded by enterprise buyers), FEMA for cross-border flows, Data Protection Board for SDF classification — and all of this is tightening every quarter.

Running this in-house is roughly a Chief Compliance Officer, a Data Protection Officer, a Risk Officer, three analysts, a security engineer, auditor fees and a lot of overtime. Fully loaded ₹60L+ a year before you ship a single feature. For a Series A or Series B FinTech, this is three to five times what the problem is worth.

Running it with a traditional CA firm is worse. They file what they are asked. They do not integrate SOC 2 common controls with ISO 27001 common controls with DPDP ROPA. They do not run CERT-In 6-hour drills. They do not respond to enterprise buyer questionnaires in 24 hours. They are not DPOs.

Cosmoura runs the full FinTech and NBFC compliance stack as one retainer. Named DPO plus named CA plus named CS on your account. Decipher Consultancy Services (our sister concern) builds the automation that handles buyer questionnaires, evidence collection, and RBI reporting workflows. You get regulator-grade compliance without a regulator-grade cost base — and you get your common controls mapped once and run as parallel audit tracks across SOC 2, ISO 27001 and DPDP.

Trigger moment: You are 60 days from a Series B. The lead investor asked for SOC 2 Type II. The co-lead asked for ISO 27001. Your compliance officer resigned. You have a CERT-In reportable incident from last week that nobody has filed yet. Your RBI DNBS return is due Monday. If any of this is true — call us today.

Three profiles we build the pack around.

The retainer is tuned to your stage. If you do not fit cleanly, we scope a custom pack.

01

Early-stage FinTech (seed to Series A)

DPDP consent architecture, buyer-questionnaire readiness, early SOC 2 Type I prep, CERT-In workflow setup, Virtual DPO on retainer. From ₹25k–75k/mo.

02

Scale-stage NBFC + payment aggregator

RBI master direction mapping, monthly DNBS returns, SOC 2 Type II + ISO 27001 parallel tracks, capital adequacy, PA-PG / PPI / AA compliance, inspection response.

03

Significant Data Fiduciary (SDF) candidates

Full DPO (not Virtual), annual DPIA, independent audit, data-flow mapping, breach response SLAs. We prepare SDF-candidate FinTechs ahead of notification.

Four regulatory realities we solve for.

RBI master directions + category-specific rules

NBFC-ICC, NBFC-MFI, NBFC-Factor, HFC, PA-PG, PPI, Account Aggregator — each has its own master direction. We map controls to the rules you actually fall under, not the ones you might one day.

SOC 2 + ISO 27001 + DPDP in parallel

Overlapping controls mapped once, run as parallel audit tracks. Cuts total effort by ~40% versus sequential projects. Common controls include access management, incident response, change management, vendor management.

CERT-In 6-hour breach reporting

Breach notification within 6 hours, log retention 180 days, incident response playbooks, VAPT by empanelled testers. We run the full programme including quarterly tabletop exercises and on-call coordination.

Capital adequacy + statutory returns

NOF, CRAR, PAR, GNPA, NNPA, SMA bucketing. Monthly / quarterly RBI returns (DNBS-01, DNBS-02, DNBS-03, DNBS-10). Zero room for drift. We file within statutory window every month.

The retainer, mapped to FinTech & NBFC.

Each pack pulls from the right pillars. Pick one or bundle all four.

Hero · Compliance

RBI + CERT-In compliance pack

Compliance & Risk

Master direction mapping specific to your NBFC / PA-PG / PPI / AA category. Policy library drafted. CERT-In 6-hour reporting setup. VAPT coordination quarterly. Virtual DPO on retainer with 72-hour rights-request SLA.

  • RBI master direction mapping (category-specific)
  • Policy library + control-to-rule map
  • CERT-In 6-hour reporting + tabletop drills
  • Virtual DPO + rights-request SLA
Regulator-grade compliance · zero drift Explore →

Audit-ready

SOC 2 + ISO 27001 pack

Compliance & Risk

ISMS build-out, 64-control TSC-mapped policies, Type I in 60–75 days + Type II in +90 days, ISO 27001 Statement of Applicability, auditor coordination (Big-4 and boutique), common controls mapped once across SOC 2 + ISO + DPDP.

  • ISMS build-out + risk register + SoA
  • 64 TSC-mapped policies drafted
  • Type I + Type II audit prep in parallel
  • Common controls mapped across frameworks
Clean audit report · enterprise sales unlocked Explore →

Finance

NBFC finance pack

Finance & Accounting

Ind-AS books, capital adequacy calcs (CRAR, Tier I, Tier II), PAR / GNPA / NNPA tracking, monthly RBI returns (DNBS series), SMA bucketing, provisioning computation, statutory audit prep with Ind-AS disclosures.

  • Ind-AS books with NBFC-specific disclosures
  • CRAR + Tier I + Tier II calcs
  • Monthly DNBS returns + reconciliation
  • Provisioning + SMA bucket tracking
RBI returns on time · clean Ind-AS audit Explore →

Secretarial

NBFC secretarial + cap-table

Secretarial & Corporate

Multi-round cap table with convertible instruments (CCPS, SAFEs, CCDs), ESOP for engineering and risk teams, board resolutions for capital raises, auditor rotations as per NBFC norms, FEMA for foreign investment, FC-GPR filing.

  • Multi-round cap table with CCPS / SAFE / CCD
  • ESOP for eng + risk + ops teams
  • FC-GPR + FEMA for FDI rounds
  • NBFC auditor rotation + board support
Cap table + governance that lead investors will accept Explore →

Four weeks to a clean back-office.

Most new fintech & nbfc clients come to us mid-mess. Clean-up is a one-time cost; everything else is monthly cadence.

01

Regulatory + security audit

Week 1–2

We map your exact RBI category and the master direction that applies. We walk your SOC 2 / ISO / DPDP posture, review your last 6 months of DNBS returns and CERT-In readiness. Written gap report with risk heat-map and multi-framework common-controls matrix.

  • RBI category + master direction mapping
  • SOC 2 / ISO / DPDP gap audit
  • Common-controls matrix drafted
02

Policy + evidence buildout

Week 2–8

64 TSC-mapped policies drafted for SOC 2 + 45 ISO 27001 policies with SoA + 15 DPDP policies — common controls written once, mapped to all three frameworks. Risk register populated. Evidence collection started on dcomply platform.

  • 124 total policies drafted (common controls shared)
  • Risk register + treatment plan
  • Evidence collection via dcomply
03

Audit + regulator engagement

Week 8–18

SOC 2 Type I audit, Type II observation window opened. ISO 27001 Stage 1 and Stage 2 audits. DPDP posture report filed. CERT-In registration confirmed. RBI inspection prep (if due). Buyer questionnaire response library populated.

  • SOC 2 Type I + Type II audit
  • ISO 27001 Stage 1 + 2 audit
  • DPDP posture + CERT-In + RBI prep
04

Live + monthly cadence

Ongoing

Monthly DNBS returns, monthly compliance calendar, quarterly VAPT, quarterly tabletop exercise, annual ISO 27001 surveillance audit, annual SOC 2 Type II report, continuous Virtual DPO coverage.

  • Monthly DNBS + compliance cadence
  • Quarterly VAPT + tabletop
  • Annual ISO + SOC 2 + DPO coverage

Generic CA firm. Self-run team. Cosmoura.

Honest comparison on cost, coverage and the parts most firms quietly skip.

Generic CA firm Self-run team Cosmoura retainer
DPO + CPO + CRO coverage Not offered ₹60L+/yr fully loaded Virtual DPO from ₹2,499/mo
Multi-framework parallel audit Sequential projects 18+ months Parallel — 6–9 months
RBI DNBS returns Separate CA for RBI In-house CA In-house, monthly cadence
CERT-In 6-hour SLA Not covered Business hours only On-call 24×7
Buyer questionnaire turnaround Case-by-case 2–3 days typical 24-hour answer library
Total cost (3-framework readiness) ₹35–50L one-time + hourly ₹60L+/yr fully loaded ₹25–35L one-time + ₹5L/yr retainer
SDF classification prep Not offered Reactive Proactive · pre-notification

Eight things we handle, every month.

Named DPO + CA + CS lead on your account
RBI master direction mapping (specific to your category)
SOC 2 + ISO 27001 + DPDP common controls library
CERT-In 6-hour breach reporting workflow
Monthly RBI DNBS returns + reconciliation
Ind-AS books + capital adequacy calcs
VAPT coordination with CERT-In empanelled testers
Dedicated channel with 48-hour SLA

Questions fintech & nbfc teams ask us.

01 Which NBFC categories do you work with — NBFC-ICC, PA-PG, PPI, AA? +

All of them — NBFC-ICC, NBFC-MFI, NBFC-Factor, HFC, AA, PA-PG, PPI, cross-border. We map the specific master direction and build your controls against those exact rules. Each category has a different return calendar — we run yours.

02 How do you handle SOC 2 + ISO 27001 + DPDP overlap? +

We map common controls once (access management, incident response, change management, vendor management) and run them as parallel audit tracks. Typically cuts total compliance effort by 40% versus running three sequential projects. 60% of SOC 2 controls overlap with ISO 27001; 40% of DPDP controls overlap with both.

03 Can you handle CERT-In 6-hour breach reporting? +

Yes. We set up detection and escalation workflows, run tabletop exercises quarterly, and are on-call to coordinate the actual report when something fires. VAPT scheduled quarterly with CERT-In empanelled testers.

04 What about Significant Data Fiduciary (SDF) classification under DPDP? +

DPDP Act requires SDFs to appoint a DPO (not a Virtual DPO), conduct DPIAs, and run annual audits. Most mid-size and larger FinTechs will be classified as SDFs. We prepare you ahead of the notification — SDF retrofit after notification is painful and expensive.

05 Who sits on the DPO seat — in-house or your bench? +

Virtual DPO from our bench until you cross the SDF threshold. On SDF notification, you need a dedicated DPO — we recruit for the role (included in retainer) and continue to provide bench support for leave and specialist cover.

06 Can you handle PA / PA-PG / PPI / AA licence application and ongoing compliance? +

Yes. Pre-application diagnostic, application file preparation, RBI query response, post-licence operational compliance including monthly returns and audit. For category changes (PA to PA-PG, PPI to small-value PPI etc.) we handle the application and transition.

07 What about buyer questionnaire response — VSAQ, CAIQ, SIG, SIG-Lite? +

Yes. We maintain your answer library, updated after every audit cycle. New questionnaires turn around in 24 hours. Named engineering + security signoffs routed digitally. This single service is what unlocks enterprise sales for most FinTech clients.

08 How do you handle incident response if something actually breaks? +

On-call rota. On breach detection: 1-hour internal assessment, 6-hour CERT-In report, 72-hour DPDP affected-data-principal notification, 24-hour RBI reportable incident (where applicable). Communications pack drafted for your board and legal counsel. Tabletop exercises run quarterly so this is muscle memory, not panic.

A retainer built for fintech & nbfc.
Live in two weeks.

Free 30-minute discovery call. We map your current compliance + finance posture, then come back with a sequenced plan.