loader image
DPDPA HUB
DPDPA Compliance Deadline: 230 Days Left until 13 May 2027 GET ASSESSED →

RBI’s Dark Pattern Crackdown: What Banks, NBFCs, and FinTechs Need to Know.

A pre-ticked insurance box on a loan form. A countdown timer that resets every time you refresh the page. A “no thanks” link buried three taps below a giant “yes” button. For years, these were treated as clever product design in Indian digital banking. As of 1 January 2027, they’re compliance violations with an audit trail attached.
The Reserve Bank of India (RBI) spent 2026 building one of the most detailed dark-pattern monitoring regimes in financial regulation anywhere not just a ban, but a mechanism for catching violations before they reach customers. Here’s what it actually says, why it exists, and what “avoiding” it really means in practice.

What Are Dark Patterns, and What Do RBI’s Directions Say?

Dark patterns are interface and user-experience choices built to steer someone toward a decision they wouldn’t otherwise make burying the “decline” option, pre-selecting the expensive add-on, or manufacturing urgency where none exists. India first formally regulated the concept in November 2023, when the Central Consumer Protection Authority (CCPA) notified the Guidelines for Prevention and Regulation of Dark Patterns, 2023 under the Consumer Protection Act, 2019. Those guidelines set out 13 specified dark patterns and apply broadly to any platform, seller, or advertiser doing business in India.
What changed in 2026 is that a sector regulator wrote the same prohibition directly into binding banking law, rather than leaving it to general consumer-protection guidance. RBI released a draft on 11 February 2026, the Responsible Business Conduct Amendment Directions, 2026 and, after a public comment window, notified the final version on 15 June 2026 as the Responsible Business Conduct (Second Amendment) Directions, 2026, taking effect 1 January 2027
The Directions apply to commercial banks (excluding Small Finance Banks, Payment Banks, Regional Rural Banks, and Local Area Banks, which sit under related rules), all NBFCs, housing finance companies, urban and rural co-operative banks, and All India Financial Institutions such as NABARD, the National Housing Bank, EXIM Bank, and SIDBI. Oversight doesn’t stop at the regulated entity’s own app, either it extends to Direct Selling Agents (DSAs), Direct Marketing Agents (DMAs), Loan Service Providers, and FinTech partners acting on a bank’s or NBFC’s behalf.
Three things are now explicitly prohibited: dark patterns in any digital interface, “compulsory bundling” (making one product’s availability conditional on buying another), and consent that isn’t explicit, informed, and recorded separately for each product. Pre-ticked boxes are out. The default answer to any consent prompt now has to be “no.”

Why RBI Stepped In?

This wasn’t a preemptive rule — it followed evidence that dark patterns had become routine in Indian digital banking. A 2026 LocalCircles survey of more than 160,000 respondents across nearly 400 districts found that 57% of participants had experienced “basket sneaking” on banking platforms, 51% had been subjected to “forced action,” and 46% reported persistent “nagging” to accept services they’d already declined. Around the same time, India’s finance ministry had been publicly critical of mis-selling in banking questioning, for instance, why a home loan already secured by the property itself so often comes bundled with a fresh insurance policy.
The financial logic behind the behaviour isn’t subtle. Bancassurance the commission banks earn for selling insurers’ products through their own counters and apps has grown into a significant revenue line across the industry over the past decade. RBI’s framework treats that incentive structure itself as a regulatory risk, not just the interface built on top of it.
It also reflects a broader global pattern. Regulators in the EU and US have moved in the same direction over the past few years, treating manipulative interface design as a legal violation rather than a UX quirk. RBI’s move brings Indian financial-sector regulation in line with that shift, and goes further than most by writing specific audit and reporting obligations directly into the rule.

How to Avoid Dark Patterns: Compliance Best Practices

RBI’s Directions are unusually specific about HOW institutions are expected to catch dark patterns, not just that they must avoid them. That gives compliance, product, and design teams a fairly concrete playbook:

  • Audit before you ban: Every new interface has to go through user testing before launch, and existing digital journeys need periodic internal audits specifically looking for unfair or manipulative features — not just legal-disclosure checks.
  • Redesign consent from scratch: One product, one explicit opt-in, unticked by default, with “decline” given equal visual weight to “accept.” Consent for bundled products can no longer be captured in a single click.
  • Build an independent feedback loop: Within 30 days of any sale, a team that had no role in making that sale needs to check by call-back or survey, whether the customer actually understood what they bought. Findings feed a half-yearly report that’s meant to change policy, not just get filed away.
  • Check both lists: CCPA’s 13 specified dark patterns and RBI’s own illustrative examples overlap heavily but aren’t identical, map your interfaces against both rather than assuming compliance with one covers the other.
  • Extend the standard to your agents: DSAs, DMAs, loan service providers, and FinTech partners have to meet the same bar. A dark pattern introduced by an outsourced sales channel is still the regulated entity’s problem.
  • Fix the incentive, not just the screen: Commission structures that reward staff for pushing add-ons are a large part of why dark patterns exist in the first place. Removing the interface trick without touching the incentive rarely holds up.
  • Keep the paper work: Consent logs, audit records, and feedback reports aren’t a formality, they’re what supervisory returns and statutory audits will actually examine.

Example: What This Looks Like in Practice?

The clearest recent illustration doesn’t come from banking, but it shows how India’s dark-pattern enforcement actually plays out. In February 2025, the CCPA issued a notice to ticketing platform BookMyShow after it was found to be automatically adding a small charitable donation to every ticket purchase through a pre-ticked checkbox, a textbook case of “basket sneaking” under the 2023 Guidelines. BookMyShow subsequently updated its interface to make the donation a clear, voluntary opt-in. The CCPA has continued that enforcement pattern into 2026, more recently taking action against several companies across sectors for similar violations.
Now translate that into a banking context under RBI’s rules: a customer applies for a home loan, and a loan-protection insurance policy is pre-selected in the checkout summary, quietly nudging the total EMI upward unless the customer notices and manually removes it. Under the new Directions, that flow isn’t just bad practice anymore, it’s compulsory bundling and a dark pattern at once. What RBI expects instead: the insurance offer shown separately, unticked, with its own explicit “yes,” and never a precondition for loan approval.

Conclusion

The message behind RBI’s Directions is simple, even if the compliance mechanics aren’t there in Indian financial services, the interface is no longer just a design decision, it’s a regulatory one. With an audit trail, a half-yearly report, and refund liability attached if it goes wrong, institutions have until 1 January 2027 to make that shift real rather than cosmetic. The ones that treat this as a chance to rebuild trust (instead of a checklist to route around) are the ones customers are likely to keep choosing.

Sources and further reading

Zorixx Assistant