FINTECH · SANDBOX

RBI Regulatory Sandbox 2025: Who’s Testing Now & How to Enter

Themes in flight, selection patterns, and a four-week application sprint plan—so your fintech can clear screening and hit UAT fast.
By bataSutra Editorial · October 10, 2025
In this piece:
  • The short — where the bar sits now
  • Where the sandbox stands (clean snapshot)
  • Eligibility matrix & red lines
  • Week-by-week application plan
  • Graduation paths & what “success” looks like
  • FAQ

The short

  • Momentum: Recent cohorts skew toward risk, compliance automation, and MSME credit pipes.
  • What wins: Clear customer harm reduction, measurable compliance lift, and tight data-risk controls.
  • What stalls: Weak KYC/consent posture, synthetic data without provenance, and bank-less pilots.

Where the sandbox stands

ItemEarly-Oct status (indicative)Operator read
Active theme mixRegtech/KYC · MSME credit rails · Cross-border LRS UXBias to supervision & inclusion
Selection rate~10–20% of complete applicationsQuality over volume
Time to onboarding~8–12 weeks from complete packFront-load due diligence
PSU/private bank partnersGrowing pool; NDA heavySecure at least one LoI before filing
GraduationsIncremental, theme-dependentDefine success metrics up front

Eligibility matrix & red lines

Must-haves

  • Incorporated Indian entity (or recognized academic/consortium arm).
  • Working prototype; reproducible test plan; UAT-ready builds.
  • Data rights and consent flows mapped; PII minimization plan.

Red lines

  • Unlicensed deposit-taking, leverage, or shadow bank behavior.
  • Crypto exposure that bypasses extant frameworks.
  • Weak AML/CFT controls; no audit trails.

Week-by-week application plan

  1. Week 1 — Fit & partner: Lock theme, draft “harm reduced” statement, secure a bank/NBFC LoI.
  2. Week 2 — Data & risk: Publish data provenance, consent logs, and retention schedule; DPIA signed.
  3. Week 3 — Tech pack: Reproducible Docker image, API spec, test cases, rollback/runbooks.
  4. Week 4 — Submission: Cover note (metrics, cohorts, safeguards), founder KYC, cap table, incident policy.
Attach Bank/NBFC LoI · DPIA · InfoSec controls · Customer communication templates · MIS dashboards

Graduation paths & “success” metrics

PathMetricThreshold (illustrative)Why it matters
Pilot → Scale with partnerRisk event rate< 5 bps vs baselineDemonstrates harm reduction
Policy note/clarificationAudit coverage> 95% events loggedSupervisory visibility
Multi-bank rolloutTime-to-KYC−30–50% vs controlReal customer benefit

FAQ

  • Can pre-revenue startups apply? Yes, if prototype, partner LoI, and data governance are strong.
  • Is production data required? Prefer test datasets; if production is needed, add consent and masking plans.
  • What if the partner backs out? Keep a backup LoI; disclose promptly and propose revised timelines.