News Analysis4 min read

Finch Innovate Launches FinchSCAN: What Global AML SaaS Means for DPDP Vendor Oversight

The launch of FinchSCAN's global digital onboarding platform highlights the intersection of AML compliance and DPDP Act 2023 obligations. We analyze the contingent liability and vendor oversight implications for fintech CFOs.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

According to a report by BFSI Elets, Finch Innovate has announced the global launch of FinchSCAN, a digital onboarding and Anti-Money Laundering (AML) screening SaaS platform. The new platform handles Know Your Customer (KYC) and identity verification workflows for financial institutions. Finch Innovate states the platform architecture is designed to support global data protection frameworks. This specifically includes India's Digital Personal Data Protection Act, 2023, the European Union's GDPR, and applicable Gulf market regulations. The rollout introduces another global vendor option for fintech companies looking to streamline their digital onboarding cycles.

Does The DPDP Act Apply Here?

Yes, the DPDP Act 2023 applies directly to the usage of such platforms by Indian fintechs. Under Section 3, the Act covers the processing of digital personal data within the territory of India. It also applies to processing outside India if connected to offering goods or services to Data Principals in India. In this scenario, a fintech utilizing FinchSCAN acts as the Data Fiduciary, while FinchSCAN operates as a Data Processor. The platform inherently processes large volumes of identity and financial data, which triggers full compliance obligations for the Data Fiduciary under the Act and the DPDP Rules, 2025.

Legal Implications Under DPDP

Utilizing a third-party SaaS for AML processing requires strict adherence to Section 4 of the Act. For onboarding, consent is the primary basis for processing, except where Section 7 legitimate uses apply. The fintech must ensure the platform can present itemised notices and capture verifiable consent before any KYC data is ingested. Furthermore, cross-border transfers to a global SaaS are generally permitted unless the Central Government restricts transfer to notified countries or territories. Under the DPDP Rules, 2025, if the vendor experiences a security incident, the Data Fiduciary must still provide intimation to affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours.

Could This Happen To You

For a fintech CFO, adopting a global SaaS vendor without rigorous DPDP alignment represents a massive contingent liability. If your onboarding vendor fails to secure data or cannot execute data erasure requests, your organization bears the primary penalty exposure of up to 250 crore rupees per breach under the DPDP Act. This directly impacts your EBITDA and will likely trigger hikes in cyber insurance premiums. Rapid product cycles in lending and payments often outpace legal review, leading to hidden vendor sprawl. When auditors or the DPBI investigate an incident, they will demand evidence of your Data Fiduciary to Data Processor contracts, security safeguards, and the 72-hour breach reporting workflow. Relying solely on a vendor's general compliance marketing is insufficient for Indian regulatory requirements.

What Companies Should Do In The Next 30 Days

1. Finance and Legal must review all existing AML and onboarding SaaS contracts to ensure explicit DPDP Rules, 2025 indemnity clauses and 72-hour breach notification SLAs are codified.

2. Procurement should map the total cost of ownership (TCO) for vendor consolidation, ensuring selected platforms can natively support itemised notices and consent artifact generation.

3. Information Security teams must map the exact geographical flow of the vendor's KYC data to ensure no data is routed through or stored in Central Government restricted territories.

4. Compliance heads must verify that the vendor's architecture allows for automated data erasure once the specific AML regulatory retention period expires.

What To Watch

We are closely monitoring the establishment of the Data Protection Board and its initial audit guidelines for Data Processors operating in the financial sector. Fintech CFOs must watch how third-party breach liabilities will impact cyber insurance underwriting criteria over the next fiscal year. Exactly 269 days remain until the DPDP hard compliance deadline of 13 May 2027. To assess your organization's exposure to vendor data risks and evaluate your onboarding flows, use the assessment at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act apply to global AML and KYC SaaS vendors?

Yes. If the platform processes the digital personal data of Data Principals in India, or processes data outside India in connection with offering services to them, the DPDP Act 2023 applies. The fintech utilizing the platform remains the Data Fiduciary and holds primary liability.

What is our financial liability if our onboarding vendor suffers a data breach?

Under the DPDP Act 2023, the Data Fiduciary faces penalty ceilings of up to 250 crore rupees for failing to take reasonable security safeguards. The DPDP Rules, 2025 also require the Fiduciary to report the breach to the DPBI within 72 hours, regardless of the vendor's location.

Are cross-border data transfers to a global SaaS platform permitted under DPDP?

Yes, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories via a negative list. Fintechs must still ensure their data processing contracts enforce adequate security and breach reporting standards.

How can a fintech CFO manage DPDP compliance costs for onboarding vendors?

CFOs should prioritize vendor consolidation and evaluate platforms based on their total cost of ownership, including DPDP feature readiness. Proper vendor contracts and automated consent record workflows will help control audit fees and protect cyber insurance premiums.

How long do we have to ensure our vendors comply with the DPDP Rules 2025?

Organizations must complete their compliance programs and vendor contract updates prior to the enforcement date. Exactly 269 days remain until the DPDP hard compliance deadline of 13 May 2027.