Early-stage FinTech (seed to Series A)
DPDP consent architecture, buyer-questionnaire readiness, early SOC 2 Type I prep, CERT-In workflow setup, Virtual DPO on retainer. From ₹25k–75k/mo.
RBI master directions, SOC 2 Type II, ISO 27001, CERT-In 6-hour breach reporting, DPDP, capital adequacy, SDF prep for Indian FinTechs and NBFCs. Named DPO + CA + CS on retainer, parallel audit tracks.
Indian FinTech and NBFC operate under the most dense regulatory stack of any sector. RBI master directions (category-specific), SEBI (for AMCs and brokers), IRDAI (for insurance), CERT-In (6-hour breach reporting), DPDP (strict for financial data), SOC 2 Type II and ISO 27001 (demanded by enterprise buyers), FEMA for cross-border flows, Data Protection Board for SDF classification — and all of this is tightening every quarter.
Running this in-house is roughly a Chief Compliance Officer, a Data Protection Officer, a Risk Officer, three analysts, a security engineer, auditor fees and a lot of overtime. Fully loaded ₹60L+ a year before you ship a single feature. For a Series A or Series B FinTech, this is three to five times what the problem is worth.
Running it with a traditional CA firm is worse. They file what they are asked. They do not integrate SOC 2 common controls with ISO 27001 common controls with DPDP ROPA. They do not run CERT-In 6-hour drills. They do not respond to enterprise buyer questionnaires in 24 hours. They are not DPOs.
Cosmoura runs the full FinTech and NBFC compliance stack as one retainer. Named DPO plus named CA plus named CS on your account. Decipher Consultancy Services (our sister concern) builds the automation that handles buyer questionnaires, evidence collection, and RBI reporting workflows. You get regulator-grade compliance without a regulator-grade cost base — and you get your common controls mapped once and run as parallel audit tracks across SOC 2, ISO 27001 and DPDP.
Trigger moment: You are 60 days from a Series B. The lead investor asked for SOC 2 Type II. The co-lead asked for ISO 27001. Your compliance officer resigned. You have a CERT-In reportable incident from last week that nobody has filed yet. Your RBI DNBS return is due Monday. If any of this is true — call us today.
Who this is for
The retainer is tuned to your stage. If you do not fit cleanly, we scope a custom pack.
DPDP consent architecture, buyer-questionnaire readiness, early SOC 2 Type I prep, CERT-In workflow setup, Virtual DPO on retainer. From ₹25k–75k/mo.
RBI master direction mapping, monthly DNBS returns, SOC 2 Type II + ISO 27001 parallel tracks, capital adequacy, PA-PG / PPI / AA compliance, inspection response.
Full DPO (not Virtual), annual DPIA, independent audit, data-flow mapping, breach response SLAs. We prepare SDF-candidate FinTechs ahead of notification.
What this industry faces
NBFC-ICC, NBFC-MFI, NBFC-Factor, HFC, PA-PG, PPI, Account Aggregator — each has its own master direction. We map controls to the rules you actually fall under, not the ones you might one day.
Overlapping controls mapped once, run as parallel audit tracks. Cuts total effort by ~40% versus sequential projects. Common controls include access management, incident response, change management, vendor management.
Breach notification within 6 hours, log retention 180 days, incident response playbooks, VAPT by empanelled testers. We run the full programme including quarterly tabletop exercises and on-call coordination.
NOF, CRAR, PAR, GNPA, NNPA, SMA bucketing. Monthly / quarterly RBI returns (DNBS-01, DNBS-02, DNBS-03, DNBS-10). Zero room for drift. We file within statutory window every month.
Pre-built packs
Each pack pulls from the right pillars. Pick one or bundle all four.
Hero · Compliance
Master direction mapping specific to your NBFC / PA-PG / PPI / AA category. Policy library drafted. CERT-In 6-hour reporting setup. VAPT coordination quarterly. Virtual DPO on retainer with 72-hour rights-request SLA.
Audit-ready
ISMS build-out, 64-control TSC-mapped policies, Type I in 60–75 days + Type II in +90 days, ISO 27001 Statement of Applicability, auditor coordination (Big-4 and boutique), common controls mapped once across SOC 2 + ISO + DPDP.
Finance
Ind-AS books, capital adequacy calcs (CRAR, Tier I, Tier II), PAR / GNPA / NNPA tracking, monthly RBI returns (DNBS series), SMA bucketing, provisioning computation, statutory audit prep with Ind-AS disclosures.
Secretarial
Multi-round cap table with convertible instruments (CCPS, SAFEs, CCDs), ESOP for engineering and risk teams, board resolutions for capital raises, auditor rotations as per NBFC norms, FEMA for foreign investment, FC-GPR filing.
How we onboard
Most new fintech & nbfc clients come to us mid-mess. Clean-up is a one-time cost; everything else is monthly cadence.
Week 1–2
We map your exact RBI category and the master direction that applies. We walk your SOC 2 / ISO / DPDP posture, review your last 6 months of DNBS returns and CERT-In readiness. Written gap report with risk heat-map and multi-framework common-controls matrix.
Week 2–8
64 TSC-mapped policies drafted for SOC 2 + 45 ISO 27001 policies with SoA + 15 DPDP policies — common controls written once, mapped to all three frameworks. Risk register populated. Evidence collection started on dcomply platform.
Week 8–18
SOC 2 Type I audit, Type II observation window opened. ISO 27001 Stage 1 and Stage 2 audits. DPDP posture report filed. CERT-In registration confirmed. RBI inspection prep (if due). Buyer questionnaire response library populated.
Ongoing
Monthly DNBS returns, monthly compliance calendar, quarterly VAPT, quarterly tabletop exercise, annual ISO 27001 surveillance audit, annual SOC 2 Type II report, continuous Virtual DPO coverage.
How we compare
Honest comparison on cost, coverage and the parts most firms quietly skip.
| Generic CA firm | Self-run team | Cosmoura retainer | |
|---|---|---|---|
| DPO + CPO + CRO coverage | Not offered | ₹60L+/yr fully loaded | Virtual DPO from ₹2,499/mo |
| Multi-framework parallel audit | Sequential projects | 18+ months | Parallel — 6–9 months |
| RBI DNBS returns | Separate CA for RBI | In-house CA | In-house, monthly cadence |
| CERT-In 6-hour SLA | Not covered | Business hours only | On-call 24×7 |
| Buyer questionnaire turnaround | Case-by-case | 2–3 days typical | 24-hour answer library |
| Total cost (3-framework readiness) | ₹35–50L one-time + hourly | ₹60L+/yr fully loaded | ₹25–35L one-time + ₹5L/yr retainer |
| SDF classification prep | Not offered | Reactive | Proactive · pre-notification |
What's included
FAQ
All of them — NBFC-ICC, NBFC-MFI, NBFC-Factor, HFC, AA, PA-PG, PPI, cross-border. We map the specific master direction and build your controls against those exact rules. Each category has a different return calendar — we run yours.
We map common controls once (access management, incident response, change management, vendor management) and run them as parallel audit tracks. Typically cuts total compliance effort by 40% versus running three sequential projects. 60% of SOC 2 controls overlap with ISO 27001; 40% of DPDP controls overlap with both.
Yes. We set up detection and escalation workflows, run tabletop exercises quarterly, and are on-call to coordinate the actual report when something fires. VAPT scheduled quarterly with CERT-In empanelled testers.
DPDP Act requires SDFs to appoint a DPO (not a Virtual DPO), conduct DPIAs, and run annual audits. Most mid-size and larger FinTechs will be classified as SDFs. We prepare you ahead of the notification — SDF retrofit after notification is painful and expensive.
Virtual DPO from our bench until you cross the SDF threshold. On SDF notification, you need a dedicated DPO — we recruit for the role (included in retainer) and continue to provide bench support for leave and specialist cover.
Yes. Pre-application diagnostic, application file preparation, RBI query response, post-licence operational compliance including monthly returns and audit. For category changes (PA to PA-PG, PPI to small-value PPI etc.) we handle the application and transition.
Yes. We maintain your answer library, updated after every audit cycle. New questionnaires turn around in 24 hours. Named engineering + security signoffs routed digitally. This single service is what unlocks enterprise sales for most FinTech clients.
On-call rota. On breach detection: 1-hour internal assessment, 6-hour CERT-In report, 72-hour DPDP affected-data-principal notification, 24-hour RBI reportable incident (where applicable). Communications pack drafted for your board and legal counsel. Tabletop exercises run quarterly so this is muscle memory, not panic.
Ready to run cleaner?
Free 30-minute discovery call. We map your current compliance + finance posture, then come back with a sequenced plan.