Licence, Recognition and What Makes a Firm Regulated
A firm is regulated when it carries on an activity that requires permission and holds that permission from the body empowered to grant it. The permission takes different forms: a licence to carry on a business, recognition of an institution, or registration as an intermediary. A permission for one activity says nothing about another. So what matters to somebody dealing with the firm is which activity the permission actually covers.
Start with the sentence that does the damage. A screen says regulated entityA phrase meaning that a firm holds some permission from some body. The phrase never says which activity the permission covers.. The sentence is usually true, so a reader reads it, believes it, and is usually right to believe it. The missing half is which activity that permission covers, and that half is not on the screen at all. In Indian regulation the permission and the activity are welded together. A firm can hold a permission that is real, current and checkable, and be carrying on something beside it that the permission never touched.
Here is the everyday version. A shop across the road holds a permit to serve food. The permit is genuine, the inspection paper is on the wall, and it says nothing whatsoever about whether the shop may also run a bus to the railway station from the pavement outside. The permit names food and everyone can see what it names, so nobody is confused. Finance is the same idea with the name of the activity quietly dropped from the sentence, leaving only the adjective behind. The whole skill is putting the activity back into the sentence and then checking it at the source.
Every requirement in this subject is a figure somebody could look up and somebody could change: an eligibility bar, a period, a fee, a limit, a date from which something applies. Each requirement is carried by a named body in a named document, and the figure itself is read at the source. A printed requirement is right until the morning it is amended and wrong every day afterwards, with nothing on its face to tell a reader which day it is.
What is the perimeter drawn around, companies or activities?
Around activities. The perimeterThe line between activity that requires a permission from somebody and activity that requires none. The line runs around the activity, not around the firm doing it. is the line between activity that may not be carried on without permission and activity that may be carried on without asking anybody. Lending money to the public as a business sits on one side of that line. Writing software, printing brochures, running a call centre and building an application for a phone sit on the other side of it, and no permission exists for a firm to hold in respect of any of them.
Once that idea is held, the phrase regulated entity stops sounding like an answer and starts sounding like an unfinished question. Regulated for what? Because the line encloses activity, a single company with one registered name and one office can be inside the line for the first thing it does and outside it for the second, at the same moment, with nothing dishonest happening anywhere. A company is not inside or outside the perimeter; each of the things it does is. The split is not a loophole and it was not an accident. Drawing the line around activity is how the law reaches what it cares about without having to license every business in the country.
The regulatory perimeter is drawn around what?
What is a Licence, and what does holding one permit?
A licenceA permission to carry on a defined business, granted by the body the law empowers to grant it. Holding one permits the business it names and nothing beyond that. is a permission to carry on a defined business, granted by the body that the law empowers to grant it and by nobody else. The two words that carry the weight are defined and empowered. Defined does real work. A licence always names the business it permits, and the naming is the substance of it rather than a formality on the certificate. Empowered does the same. A permission is only worth something when it comes from the body the statute appointed. A document from a body nobody appointed is paper rather than permission.
A licence permits the business it names. A licence does not permit its holder to carry on a second business that some other body licenses. Nor does it make the holder trustworthy in the ordinary human sense. Trustworthiness is a separate matter a licence was never designed to answer. A licence is a statement about permission to do a named thing, and it is silent on every other question anybody might want it to answer.
What is Recognition, and which institutions need it rather than a licence?
RecognitionThe status the law confers on an institution that may not operate at all unless it has been recognised. Stock exchanges and clearing corporations are recognised rather than licensed. is a different shape of permission, and the difference is not decorative. Some institutions are the place where other people's transactions happen, and the law will not let a body of that kind exist unrecognised at all. A stock exchange is the standing example. An exchange does not carry on a business alongside other businesses in the ordinary way; it is the venue, and if it operates badly, everybody who trades on it is affected at once rather than one customer at a time.
So the law does not licence the exchange to trade, it recognises the institution. The status attaches to the institution itself and to its continuing fitness to be that institution, rather than to a business line inside it. A licence permits an activity; recognition permits an institution to exist as that institution and to open its doors. The practical consequence for a reader is a checking habit rather than a definition: when a market body says it is recognised, the question is which body recognised it, and the answer is read on the recognising body's own site, exactly as it would be for a licence.
A stock exchange operates under recognition rather than under a licence. What does that indicate about what recognition is for?
Registration vs Certification: what does each one actually attach to?
RegistrationThe permission an intermediary holds from its regulator for one defined activity. The permission sits with the firm or the person carrying on that activity. is the third form and the one this subject uses most, because most of the intermediaries an ordinary person deals with are registered rather than licensed or recognised. A registration attaches to a defined activity carried on by an intermediary, and the entry that records it names that activity. Sarvodaya Capital Advisors Private Limited, the invented nine person firm this sequence follows, seeks registration for the activities it intends to carry on and for no others. Working out which registrations those intended activities need was real work rather than a form.
Certification is a different animal wearing similar clothes. A certification is held by a person and is obtained by passing an examination. A certification says that one individual sat a test on a body of knowledge and reached the standard on the day. Certification is about competence, it is about a human being, and it is not a permission for anybody to do anything. A registration belongs to a firm and covers an activity, a certification belongs to a person and covers knowledge, and neither one implies the other in either direction.
Take Sarvodaya as the test case. Suppose every one of its nine people, both founders, all three in research, both in advisory, the compliance officer and the one person in operations, held a current certification. The firm would still hold exactly no registration until a regulator granted it one. Run it the other way and the same independence holds: a registered firm can employ somebody whose certification has quietly lapsed. Two certifications at Sarvodaya expired in the same month, both having been taken in the same week years earlier. A register caught it. Nobody's memory would have.
Every person at a firm holds a current certification. What follows about whether the firm is registered?
Digital Lending App vs Lending Service Provider: which of them is lending?
Now put the idea to work where it costs money. Somebody opens Kalpavriksha Credit, an invented lending application, on their phone. On the screen there is one name. Behind that one name, in an arrangement of this shape, there are usually several entities, and the borrower can see exactly the first of them.
An application is software with a brand on it. The software is not an entity, cannot hold a permission, and cannot lend anybody anything, in the same way that a shop sign cannot sell rice. Some company operates it, and here that company is Kalpavriksha Technologies Private Limited, a technology company. A lending service providerAn entity that performs part of a lending process, such as sourcing borrowers or servicing an account, on behalf of the entity that is actually lending. is an entity that performs part of a lending process on behalf of somebody else: finding borrowers, collecting documents, servicing an account afterwards. Doing that work is not lending, and an entity doing it is not the source of the money.
The money in this invented arrangement comes from Rewa Finance Limited, and that is the entity carrying the credit risk. Three names stand behind one screen, and the permission that matters belongs to only the third of them. Each of the first two is entirely ordinary. A brand is a normal commercial thing. A technology company operating an application under contract is a normal commercial thing. Neither is doing anything untoward, and that is exactly why the arrangement is invisible: there is nothing odd to notice.
Of the three parties in that chain, whose permission is the one that has to be checked?
Who is actually the lender, and why is that the only question that matters?
Because the permission to lend is held by whoever is lending, and by nobody standing next to them. In a layered arrangementAn arrangement where the firm a customer sees on the screen is not the firm taking the risk or holding the permission behind the transaction. the parties can multiply while the number of lending permissions stays stubbornly at one. One name appeared and no arrangement announced itself, so readers reliably assume the number of parties is one.
The everyday version is a wedding. The person booked is the wedding planner. The food comes from a caterer the couple never met, the lights come from somebody else again, and the hall belongs to a fourth party. If the food goes wrong, the answer to who is responsible is not the person whose card the couple holds. Nobody deceived anybody, but the caterer's name is still worth knowing before the day rather than after it.
A borrower takes a loan through an application on a phone. How many separate parties would be expected to be involved?
Add layers between the borrower and the money, and watch the chain grow while the permissions do not.
One control moves: the number of parties standing between the borrower and the entity whose money is being lent, from none up to three. Everything else is held still. At every setting, exactly one party at the far right of the chain is the one doing the lending, and it is that party whose permission has to be looked up. The panel opens on the case described above: two layers, being the brand, the company operating the application, and the lender. The second row of buttons shows what the borrower can read straight off the screen, and walks the three checks set out below one at a time.
At the two layer setting the panel opens on, there are 3 parties to identify, 1 of them is named on the screen, 2 have to be found off it, and exactly 1 of the 3 holds the lending permission. With no layers at all there is 1 party, it is named on the screen, and it is the lender itself. At 3 layers there are 4 parties, still 1 name on the screen, 3 to be found elsewhere, and still exactly 1 lending permission. The last row carries the whole teaching point: adding parties adds names to find, and never adds a second lender.
How to Verify a Digital-Lending Entity: what runs first, and where does it end?
Three steps, in order, and every one of them is public and free. First, find the entity that operates the application. The application itself is required to make that entity findable, and it usually sits on an about screen or in the terms. Second, find the lender the operator names. The operator is not the lender. Third, and this is the step that carries all the weight, look that lender up on the regulator's own registerThe regulator's own public list of the entities it has permitted, published by the regulator itself rather than by any of the entities on it., published by the Reserve Bank of India at rbi.org.in, rather than believing the application's own account of it.
The order matters because the first two steps read what the arrangement says about itself and only the third reads what somebody outside the arrangement says about it. Anything an application prints about its own permissions costs nothing to print and is not evidence of anything. The register entry is the evidence. If the two disagree, the register is the one that decides, and if step three cannot be reached at all because no lender is named anywhere, that is itself the most informative outcome of the three.
A register entry looks like a search result and a search result feels like a verdict, so step three is where most readers stop too early. An entry is not a verdict. An entry is a row with fields, and the fields are the point. An entry names the entity, states the category of permission it holds, and shows the status of that permission. Reading past the name to the category is the entire skill. The name only says that something was found; the category says what was found. Two entities with equally respectable names can carry different categories, and one entity can appear under a category that has nothing to do with the transaction in front of the reader.
The application states clearly on its own screen that it is a regulated entity. Is step three a step that can be skipped?
What do the three common forms of that phrase leave out?
The phrase arrives in three shapes, and it is worth learning all three, because they are usually accurate and they leave out different things. Each row below is a sentence that could appear on any screen without a word of it being untrue.
| The sentence on the screen | What is usually true about it | What it leaves out |
|---|---|---|
| We are a regulated entity | Some permission from some body is very likely held | Which activity that permission covers, the only part that was needed |
| Registered with the authorities | Every company in India is registered as a company somewhere | That registering a company is not a permission to carry on any particular activity |
| In partnership with a regulated lender | There probably is such a partner, and it probably does hold a permission | Which entity the contract is with, and what the partner has agreed to do |
| One question fixes all three rows | Regulated by whom, and permitted for which activity? | Answered on the regulator's site, not on the screen making the claim |
The second row is the quiet one. A company registered under company law is registered, in the plain English sense, and saying so is not a lie. Being incorporated says a company exists and can be found in a public record of companies. Incorporation is proof of existence, not permission for an activity, and the same English word covers both. The overlap is not somebody's clever trick but a genuine ambiguity sitting in ordinary language, and an ambiguity is hard to notice while reading quickly on a phone.
A company holds a genuine permission for one activity and is offering something else. Is the phrase regulated entity false?
Checking, finding something real, and coming away confident about the wrong thing
The failure worth studying happens to the reader who did the work. The reader saw the words, did not simply believe them, went and looked, and found something: a real entity, a real permission, a real entry on a real register. Everything they found was accurate. The permission covered an activity other than the one they were about to sign up for, and nothing in what they found said so out loud.
The wrong reading underneath it is small and completely reasonable: that the word regulated describes the company. It does not. The word describes a relationship between one activity and one body, and it says nothing about the activity in front of the reader unless the named activity is checked. So the check succeeded and answered a question the reader had not asked, and produced the one thing worse than no confidence: confidence pointed at the wrong object.
The cost lands on somebody who behaved exactly as they were told to, and that is worth saying plainly. Nobody in this failure was careless, and a reader who was misled by an accurate sentence was not failing to be clever enough. The fix is one extra question rather than more suspicion: not is this firm regulated, but regulated by which body and permitted for which activity. Two words added to a question already being asked, and the check lands on the right thing.
Does sitting outside the perimeter mean doing something unlawful?
No, and this is where readers who have just learned all of the above go wrong in the opposite direction. The perimeter marks where a permission is required. The perimeter does not mark a line between honest and dishonest, and a great deal of entirely lawful commercial activity has never needed a permission from anybody. A firm building software, a firm running a call centre, a shop selling rice: none of them is inside a financial perimeter and none of them is doing anything wrong by being outside it.
Read as a moral line, it gives wrong answers in both directions, and the two mistakes cost differently. Reading unregulated as dishonest rules out ordinary businesses that never required a permission, and treats the absence of an entry as a finding when the absence of an entry means only that the search was run in a list this activity was never on. Reading regulated as safe is the mistake in the other direction, and it is the one that costs money: a narrow statement about permission for one activity gets converted into a broad reassurance about conduct that nobody ever made. Unregulated does not mean illegitimate, and regulated does not mean protected in whatever way was hoped for. The perimeter answers one question only: is a permission required here, and does this entity hold it for this activity.
A firm carries on an activity that requires no permission from anybody. Is it doing something wrong?
Who actually runs this check, and what do they do with the answer?
Four people use the same idea in four different rooms, and it is worth seeing all four, because the idea looks like consumer advice until a professional puts it to work.
A household uses it before borrowing. The Bhoite household, Sarvodaya's invented advisory client, running on one salary with two dependants and a home loan, asked Kamala Ravindran whether a particular application was safe. An answer about that application would have been worth nothing the following month, so she did not give them one. She gave them the three steps instead, and they can run those steps themselves on the next application and the one after that. Handing over a procedure outlasts handing over a verdict, and the difference matters most to the people who get asked for verdicts.
A compliance officer uses it before the firm connects a client to anybody. Devaki Suresh at Sarvodaya, who keeps the rule change register and the enforcement update log, does not ask whether a counterparty is regulated. She asks which body permitted it, for which activity, and where that is published, and she writes the answer into a file rather than into her memory. Of the 11 entries her rule change register logged in one year, 7 were circulars issued after the last consolidation, 3 required a change to a written process and 1 required a communication to every client. Asking the question on a schedule rather than after something has gone wrong produces exactly that kind of list.
An analyst uses it when a company describes itself in a document. A firm that says it is regulated has told the reader almost nothing, and a firm that names its permission, the body and the activity has told the reader something checkable. The analyst asks which of a company's revenue lines sit inside a perimeter and which sit outside. Two kinds of revenue face different risks and are not comparable simply because they arrive in the same account.
And a lender uses it about itself. When a lender engages a service provider to source or service borrowers, the permission does not travel to the service provider along with the work. The permission stays where it is, with the entity lending, and so does the responsibility that comes with it. Outsourcing a step in a process never outsources the permission that made the process lawful. One sentence explains why a technology company in one of these chains can be a perfectly ordinary business and still not be the answer to the question being asked.
Where each rule named here is actually read
Digital lending in India is addressed by the Reserve Bank of India, whose directions on digital lending are published and kept current at rbi.org.in. An instrument on this subject can be reissued and consolidated, so its current title and text are read at that address alongside the requirements themselves, including anything about what an application or its operator must disclose to a borrower. The Reserve Bank of India also publishes lists of the entities it has permitted, at rbi.org.in. Step three of the check above is carried out on those lists. For intermediaries in the securities market the corresponding public list is published by the Securities and Exchange Board of India at sebi.gov.in. All three were read on 18 August.
Every interest rate, fee, charge, threshold, limit, period and effective date on this subject is read at the source. Any of them can be amended without notice to whoever is relying on it. The procedure itself is public and free, and the person about to borrow is the one who runs it.
References
| Source | Document | Where |
|---|---|---|
| Reserve Bank of India | The directions on digital lending issued by the Reserve Bank of India, published in the notifications listing and setting requirements for digital lending arrangements and for the disclosure of the entities within them | rbi.org.in |
| Reserve Bank of India | The public lists of entities permitted by the Reserve Bank of India, the register at which a reader looks up an entity said to be lending | rbi.org.in |
| Securities and Exchange Board of India | The public lists of registered intermediaries, the corresponding register for the securities market, at which a permission granted by that body is verified | sebi.gov.in |
Sarvodaya Capital Advisors Private Limited, Kamala Ravindran, Devaki Suresh, the Bhoite household, Kalpavriksha Credit, Kalpavriksha Technologies Private Limited and Rewa Finance Limited are invented.
Educational material. Not advice on any investment, tax, budget or market position.
