Three Controversies. One Banking Giant. The HDFC Bank Questions Getting Harder To Ignore: ₹45 Crore, Mis-Sold Investments And Aadhaar On A Marketer’s Phone
HDFC Bank is not facing one uncomfortable question, but several at once. From ₹45 crore allegedly routed through marketing expenses, to investors crying foul over mis-sold products, and founders asking how their Aadhaar landed on a marketer’s phone, the controversies are different. The questions about governance are becoming harder to ignore.

HDFC Bank has spent years building the image of one of India’s most powerful and trusted private-sector lenders, but a series of controversies involving its customers, internal governance and the handling of personal data is now raising questions that extend beyond any single transaction or regulatory episode.
The concerns come from very different corners of the bank’s operations.
- Investors who bought a Carlisle-linked life settlement product through HDFC Bank’s Dubai operations allege that they were sold an investment as a relatively safe, insurance-linked product, only to suffer substantial losses and face years of difficulty in securing redemption.
- In another matter in India, the bank has faced scrutiny over an alleged arrangement involving Maharashtra State Road Development Corporation, in which approximately ₹45 crore in differential interest payments were allegedly routed through marketing expenses.
- And in a separate and broader controversy involving newly incorporated companies, HDFC Bank has been among several private-sector lenders named in allegations concerning the rapid acquisition and use of founders’ personal and corporate information obtained after filings with the Ministry of Corporate Affairs.
The three matters are not the same, and there is no evidence in the material reviewed that they form part of a single coordinated scheme. They do, however, raise a common question about how a bank of HDFC’s size manages conduct, compliance and accountability when commercial objectives collide with regulatory and customer-protection obligations.
The Dubai Investors Who Say HDFC Sold Them Risk As Safety
The first set of questions comes from investors who bought a Carlisle-linked life settlement product through HDFC Bank’s Dubai operations and now say that what they understood to be a relatively secure, insurance-linked investment turned into a prolonged dispute over losses, leverage and liquidity.
More than 75 investors are currently consolidating their complaints, representing more than $13.5 million in principal invested in the Carlisle Luxembourg Life Fund.
The group is preparing to approach the Prime Minister’s Office, the Reserve Bank of India and the Central Bank of Bahrain, while some investors have already independently complained to the Dubai Financial Services Authority. The investors are also considering legal action against HDFC Bank over what they describe as mis-selling and years of denial of redemption.
Hitesh Bhatia, a Dubai-based former banker who invested in the fund in 2019, said the group plans to place its concerns before the authorities, including what it describes as client-suitability failures, questions around leverage and disclosures, investor losses and the denial of liquidity. The investors have also written to HDFC Bank and given the bank until August 31 to respond, after which they say they intend to pursue legal recourse if the response is inadequate.
At the heart of the dispute is how the product was allegedly presented to investors. One investor said the Carlisle-linked investment was described as a capital-protection, insurance-linked product and that historical returns of between 12% and 19% a year were cited while selling the investment. Such a description would have been particularly significant for investors assessing the product on the basis of capital preservation rather than the possibility of substantial market-linked losses.
The investors’ concerns are compounded by allegations surrounding leverage. According to correspondence and records shared with the publication, HDFC Bank allegedly offered leverage of between three and five times the amount of deposits that investors had blocked with the bank for investment in the products. Leverage can materially alter the risk profile of an investment because losses are no longer limited to the investor’s unleveraged exposure.
The dispute therefore goes beyond whether the underlying Carlisle investment performed poorly. The more fundamental issue raised by the investors is whether they were given an accurate understanding of the risks before they committed their money, particularly when leverage was offered alongside the investment.
The timing of the losses is also central to the investors’ account. They allege that the leverage and structure of the investment significantly increased their exposure when markets were hit by the Covid-19 crash. What had allegedly been presented as an insurance-linked investment with a history of strong returns consequently became a source of substantial losses, while investors say they were subsequently unable to obtain the liquidity or redemption they had expected.
For the investors, the dispute has now moved beyond a commercial disagreement with a bank. Their decision to approach multiple regulators reflects their belief that the matter raises questions about suitability, disclosure and the conduct of financial institutions operating across jurisdictions.
The Dubai Financial Services Authority is particularly relevant because it is the independent regulator responsible for financial services conducted through the Dubai International Financial Centre. The investors’ complaints therefore sit within a regulatory environment that already has a recent history of scrutiny involving HDFC Bank’s DIFC operations.
In 2025, the DFSA took action against HDFC Bank’s DIFC branch over allegations concerning the mis-selling of high-risk Credit Suisse AT1 bonds to retail customers. The regulator restricted the branch from onboarding new clients and from conducting specified financial-services activities with them following its concerns.
The AT1 matter and the Carlisle dispute concern different financial products and different circumstances, and the available material does not establish that they are connected. But their proximity raises an obvious question about the standards applied when complex financial products are offered to customers through HDFC Bank’s overseas operations, particularly where the products carry risks that may not be apparent to an investor from the way they are initially presented.
That question becomes more important when the customers involved are not complaining merely about investment losses. They are alleging that the fundamental understanding on which they made the investment was different from the risk they ultimately carried.
The investors are now asking regulators to examine that gap. Whether the allegations ultimately withstand regulatory and legal scrutiny remains to be established, but the scale of the group, the amount of capital involved and the length of the dispute ensure that the Carlisle matter is no longer simply an individual investor grievance.
The First Regulatory Alarm Was Already Ringing
The Carlisle dispute does not exist in isolation from the regulatory history surrounding HDFC Bank’s overseas operations. Before the current group of investors began preparing complaints to Indian and international authorities, the bank’s Dubai operations had already faced regulatory scrutiny over the sale of another complex financial product.
In 2025, the Dubai Financial Services Authority took action against HDFC Bank’s DIFC branch over the alleged mis-selling of Credit Suisse Additional Tier-1 bonds to retail customers. The action included restrictions on the branch’s ability to onboard new clients and conduct specified financial-services activities with them, following regulatory concerns over the manner in which the high-risk securities had been sold.
The significance of the action lies in the nature of the product involved. Additional Tier-1 bonds are complex financial instruments that can carry substantially greater risks than conventional deposits or ordinary fixed-income products, including the possibility of significant losses. The regulatory concerns therefore went directly to the question of whether customers were properly informed about the risks they were assuming when they bought the securities.
The AT1 controversy also resulted in action within HDFC Bank. According to the material reviewed, the bank terminated or penalised multiple executives, including senior employees, over alleged mis-selling of Credit Suisse AT1 bonds to NRI customers through its Dubai and Bahrain operations. Investors had alleged that they were misled into believing that the instruments were comparable to safer deposit products, while the bank’s internal ethics process reportedly acknowledged deliberate lapses.
The Carlisle investors’ allegations now bring a different product into the same broader discussion about customer suitability and disclosure. They are not alleging that Carlisle’s life settlement product was the same as the Credit Suisse AT1 bonds, nor does the available material establish that the two matters involved the same employees or decision-making process. What connects the two controversies is the fact that both involve allegations concerning complex financial products sold through HDFC Bank’s overseas operations and questions about whether customers fully understood the risks attached to what they were buying.
For a bank operating across multiple jurisdictions, that distinction matters. A regulatory breach in one product line cannot automatically establish misconduct in another, but repeated complaints involving customer suitability, product disclosure and the conduct of sales teams can raise questions about the effectiveness of the controls that are supposed to prevent such problems from recurring.
The Carlisle investors are therefore seeking scrutiny not merely of their individual losses but of the manner in which the product was marketed, the risks allegedly communicated to them, the leverage arrangements attached to the investments and the subsequent handling of redemption requests. Their decision to approach the PMO, RBI, Central Bank of Bahrain and DFSA reflects an attempt to move the dispute across the regulatory channels that govern different parts of HDFC Bank’s overseas operations.
The broader question is whether the bank’s response to these episodes has been sufficiently transparent and whether the lessons from earlier regulatory action have been incorporated into the way complex products are sold today. Those questions become even more consequential when the focus shifts from customers outside India to the bank’s own domestic governance and internal controls.
/theprobe/media/media_files/2026/05/28/hdfc-bank-inside-story-behind-the-scandal-2026-05-28-09-49-00.jpg)
When The Problem Moves From The Sales Desk To The Boardroom
The questions surrounding HDFC Bank become more serious when the focus shifts from the conduct of individual sales teams to the bank’s own internal governance.
The controversy involving the Maharashtra State Road Development Corporation, or MSRDC, is significant because the alleged arrangement was not centred on a complex investment product sold to an individual customer. It concerned the way a large institutional deposit relationship was allegedly structured and the manner in which the resulting financial benefit was accounted for.
According to the bank’s internal vigilance investigation, HDFC Bank had entered into a verbal understanding with MSRDC under which the government-owned entity would effectively receive a return of around 6.01% on its savings deposits. The bank’s Asset Liability Committee had approved a rate of approximately 4.5% for such large deposits, creating a gap between the rate that could officially be offered and the return that MSRDC was allegedly promised.
The alleged solution was not to record the difference as additional interest. Instead, the additional amount was allegedly channelled through the bank’s marketing budget. Payments totalling approximately ₹39.7 crore to ₹45 crore across FY24 and FY25 were reportedly made through four local vendors and described as sponsorships or contributions connected to an MSRDC road-safety awareness campaign.
The internal records examined as part of the investigation reportedly contained several warning signs. These included photographs being reused across invoices involving payments worth crores, a lack of adequate documentation relating to the events for which payments were supposedly made, and concerns over vendor due diligence. The bank’s internal audit also reportedly rated the marketing department’s performance as “unsatisfactory”.
The alleged arrangement matters because deposit interest rates are not simply a matter of commercial negotiation between a bank and a large customer. RBI rules governing deposit interest rates are intended to prevent banks from providing preferential treatment to selected depositors and from negotiating differential rates for deposits with comparable characteristics. If a payment that effectively increases the return on a deposit is instead routed through another expense category, the question is whether the structure merely changed the description of the payment while leaving its economic substance intact.
The internal vigilance investigation reportedly examined the role of more than ten senior officials. According to the material reviewed, testimonies indicated that MD and CEO Sashidhar Jagdishan participated in decision-making calls, while CFO Srinivasan Vaidyanathan and CMO Ravi Santhanam were aware of the arrangement. The investigation also reportedly found that the marketing department acted as a facilitator in camouflaging the payments, while compliance and legal functions were sidelined and junior employees were involved in signing documentation.
These allegations make the MSRDC episode different from a straightforward accounting dispute. The central issue is not merely how much money was involved, but whether a commercial objective was pursued through a mechanism designed to avoid the normal regulatory treatment of deposit interest and whether the bank’s internal control structure was capable of stopping that mechanism.
The episode also unfolded during a period of considerable change for HDFC Bank. The merger with HDFC Ltd., completed on July 1, 2023, transformed the bank’s scale and balance sheet and brought with it the challenge of integrating two large financial institutions while maintaining deposit growth, lending momentum and operational discipline. The bank’s pursuit of large institutional deposits consequently became an important part of the post-merger business environment in which the MSRDC arrangement allegedly occurred.
The question that follows is therefore larger than whether an individual payment was correctly classified. It is whether the pressure to secure deposits and maintain growth created an environment in which established controls could be treated as obstacles to be worked around rather than safeguards that had to be followed.
That question became even harder to ignore after the bank’s own Audit Committee ordered a formal investigation and its part-time chairman, Atanu Chakraborty, resigned just six days later, citing practices he had observed within the bank that were inconsistent with his personal values and ethics.
Six Days After The Probe Began, The Chairman Walked Away
The MSRDC controversy took on a different significance when Atanu Chakraborty, HDFC Bank’s part-time chairman and an independent director, resigned just six days after the bank’s Audit Committee ordered a formal investigation into the alleged arrangement.
Chakraborty, a former IAS officer and former Secretary in the Department of Economic Affairs, said in his resignation filing that certain happenings and practices he had observed within the bank over the previous two years were incompatible with his personal values and ethics. He also stated that there were no other material reasons for his resignation.
The timing immediately placed greater attention on what was happening inside the bank. The resignation did not, by itself, establish that Chakraborty had resigned because of the MSRDC matter, and the available material does not establish that the chairman’s decision was directly caused by the investigation. But the sequence was difficult to ignore: the Audit Committee ordered the probe on March 12, 2026, and Chakraborty resigned on March 18.
The market reacted sharply. HDFC Bank’s shares fell by as much as 5% intraday, while the bank’s American depositary receipts also declined. The reaction reflected concerns about what the resignation could mean for the bank’s governance at a time when it was already facing scrutiny over the conduct of its overseas operations and the alleged mis-selling of Credit Suisse AT1 bonds to NRI customers.
The bank subsequently commissioned external legal reviews by Trilegal and Wadia Ghandy to examine governance issues following the chairman’s resignation. Those reviews reportedly found no major governance lapses, allowing the bank to move towards the reappointment of its chief executive. But the later reporting around the MSRDC investigation brought the governance question back into focus.
The contradiction is important.
On one side is a bank maintaining that its governance systems are robust and that the issues under examination do not amount to a material threat to its financial position. On the other is an internal investigation that reportedly examined the involvement of senior officials, questioned how payments were structured and raised concerns about the role played by the marketing function in facilitating the arrangement.
The difference between those two positions is not necessarily proof that one must be wrong. Internal investigations can identify control failures without implying that an institution as a whole is poorly governed, and external legal reviews can reach different conclusions depending on the questions they are asked to examine. But when a chairman resigns citing ethical concerns shortly after a board-level investigation begins, the sequence creates legitimate questions about what the board knew, what it was investigating and what conclusions were ultimately reached.
HDFC Bank’s own response has been that the alleged financial impact is not material and that the bank continues to maintain strong financial and risk-management practices. In a May 29, 2026 regulatory filing, the bank denied any material impact on its financials and said there was no requirement to make a disclosure under the SEBI LODR framework. It also reaffirmed its commitment to sound governance and internal controls.
That response addresses the financial dimension, but it leaves a broader governance question open. A transaction does not have to threaten a bank’s solvency to matter from a regulatory or ethical perspective. If the allegation is that a prohibited or restricted financial benefit was effectively delivered through another expense category, the critical issue is whether the bank’s systems detected and prevented the practice, and if they did not, whether those responsible were held accountable.
The significance of the chairman’s resignation therefore lies less in treating it as a smoking gun and more in recognising it as a governance alarm that demands context. It came at a moment when HDFC Bank was already dealing with questions about customer conduct, overseas operations and internal accountability, and it was followed by an internal investigation that placed the bank’s own processes under scrutiny.
For a financial institution of HDFC Bank’s scale, that is the point at which individual controversies begin to become a governance story. The issue is no longer simply what happened in one transaction or one branch. It is whether the bank’s control architecture is consistently strong enough to identify questionable practices before they become regulatory or reputational crises.
When The Money Is Small But The Governance Question Is Not
The immediate defence available to HDFC Bank in the MSRDC controversy is straightforward: whatever the alleged amount involved, it is immaterial when measured against the size of the bank’s balance sheet. HDFC Bank itself has maintained that the matter has no material impact on its financial position and has reaffirmed the strength of its internal controls and risk-management framework.
But financial materiality and governance materiality are not the same thing.
For a bank of HDFC Bank’s scale, ₹45 crore may not alter its capital position, profitability or ability to meet its obligations. That does not answer the more important question raised by the alleged arrangement: whether a financial benefit that could not ordinarily be provided as deposit interest was instead routed through another part of the bank’s expenditure structure.
If the allegations are correct, the issue is therefore not that HDFC Bank lost ₹45 crore or that the amount itself threatens the institution. The concern is that the bank may have used its marketing machinery to provide an economic benefit that was otherwise constrained by banking regulations.
The internal investigation’s reported findings around vendors, invoices and the structure of the payments make the classification of the expenditure central to the controversy.
This distinction matters because banking regulation is built on the assumption that the largest institutions cannot be allowed to negotiate around rules simply because the amounts involved are commercially insignificant to them. Deposit-rate regulations are intended to create uniformity and prevent banks from offering preferential arrangements to selected customers. If an institution can achieve the same economic outcome by shifting the payment into another budget, the formal classification of the transaction could become more important than the substance of the transaction itself.
There is also a broader internal-control question. A bank does not rely on a single employee or department to prevent such arrangements. Large transactions involving institutional customers ordinarily pass through multiple layers of business, finance, risk, compliance and legal oversight.
If the alleged MSRDC arrangement required several people to participate in, approve or process payments, then the question is how it moved through those layers without being stopped.
The internal vigilance investigation reportedly examined more than ten senior officials and raised concerns about the involvement of senior management, the role of the marketing department and the sidelining of compliance and legal functions. Those findings, if accurately reported, suggest that the issue cannot be reduced to an accounting classification error or an isolated lapse by a junior employee.
The bank’s position that the amount is financially immaterial remains relevant, but it does not resolve the governance issue. A financial institution can be financially strong while still having weaknesses in conduct, controls or oversight. In fact, the stronger and larger the institution, the more important those controls become because its decisions affect a much larger depositor base, investor community and financial ecosystem.
The controversy also raises the question of accountability after a control failure is identified.
- If the bank’s internal investigation established that the marketing budget was used to facilitate payments that effectively altered the return available to a major depositor, what corrective action followed?
- Were the employees involved disciplined? Were the vendors reviewed or terminated? Were similar arrangements across other institutional relationships examined?
- Were the bank’s internal approval systems changed to ensure that the same structure could not be replicated?
Those questions are more important than the headline figure because ₹45 crore is only the visible amount in the particular transaction under scrutiny. The governance issue is whether the mechanism that allegedly allowed it could exist elsewhere.
The distinction ultimately comes down to a simple question: if the amount is too small to matter to HDFC Bank financially, why would the bank need to find a way around the normal mechanism for paying it in the first place?
That is the question the ₹45 crore figure leaves behind, and it is also the question that turns the MSRDC episode from a transaction-level controversy into a test of the bank’s governance culture.

When A New Company Is Born, The Bank Calls Before MCA Does
The next set of questions takes the story beyond HDFC Bank’s own internal operations and into a much larger issue involving the Ministry of Corporate Affairs, newly incorporated companies and the private-sector banking industry.
The allegation is strikingly simple: entrepreneurs who submit their personal and corporate information to the MCA while incorporating a company can begin receiving calls from banks almost immediately, sometimes before the Ministry has even issued its own confirmation of the incorporation.
For a founder going through the incorporation process, the sequence can be difficult to explain. The entrepreneur submits information through the MCA’s V3 portal, including details such as name, email address, mobile number and identification documents required for the filing.
The expectation is that the information will remain within the government system for the purposes for which it was submitted. Instead, according to accounts cited in the material, the phone can begin ringing within hours.
HDFC Bank is among a group of private-sector lenders repeatedly named alongside Kotak Mahindra Bank, ICICI Bank, IDFC First Bank, Federal Bank, Axis Bank, IndusInd Bank and others. The calls are described as highly specific rather than generic marketing. The people calling know that a company has just been incorporated, know the founder’s name and contact details, and in some cases are alleged to possess information that the founder had supplied directly to MCA.
The timing is one of the most important elements of the allegation. If a founder receives a marketing call weeks after incorporating a company, the information could potentially have come through a range of legitimate commercial sources. But the accounts described in the underlying material concern calls arriving within hours of the filing, sometimes before the official MCA communication confirming the incorporation has been received.
One account cited in the material involved an ICICI Bank marketer who, when questioned about how the bank had obtained the founder’s number before the official MCA confirmation had been issued, allegedly responded that the information was received from the “back-end”.
The account is significant not because one employee’s statement can establish the source of an entire data pipeline, but because it raises the precise question that the broader pattern demands: what does “back-end” mean, and who has authorised access to the information contained within it?
The concern becomes more serious when the information allegedly extends beyond ordinary company-registration details. The accounts described in the material include founders being approached with personal information such as PAN and Aadhaar details that they had submitted as part of the incorporation process. In one particularly serious allegation, a bank representative allegedly arrived at a founder’s home with the founder’s personal information visible on the employee’s mobile phone.
If accurate, that would take the issue far beyond ordinary unsolicited marketing. It would raise questions about the circulation of sensitive identity information and whether the bank or its representatives had any lawful basis to possess or process it.
The Ministry’s own publicly available data structure is central to that question. An RTI response cited in the material indicates that MCA publishes corporate information through its Monthly Information Bulletin and Master Data Service, with the latter containing registration details, directors’ names and email addresses. According to the same material, directors’ phone numbers are not included in those publicly available channels.
That distinction matters because the mobile number is precisely the information that founders say is being used to contact them. If a personal number submitted during incorporation is not available through MCA’s public-facing data services, then the explanation that the banks are simply using publicly available corporate information becomes considerably less straightforward.
The question is therefore not whether company information can ever be obtained legitimately. Much of the information relating to registered companies is public by design. The question is whether information that MCA does not officially publish is nevertheless moving out of the system, and if so, through which part of the infrastructure.
The allegation also sits within a much larger ecosystem. Newly incorporated companies are valuable leads for banks because the first current account can become the beginning of a long-term commercial relationship. T
he same information is valuable to accounting and compliance firms, company-secretarial service providers, trademark agents, website developers and other businesses seeking customers immediately after incorporation. The material describes a parallel wave of such intermediaries approaching founders with offers ranging from annual filing services to startup assistance and government-scheme access.
That commercial incentive does not establish who is responsible for the alleged leakage. It does, however, explain why newly incorporated companies represent such valuable data. A fresh incorporation list containing the founder’s identity, mobile number, email address and company information is effectively a list of businesses at the precise moment when they are making decisions about banking, compliance, accounting and other services.
The central question is consequently becoming harder to avoid: if banks are receiving this information before it becomes available through MCA’s public channels, where exactly are they getting it from?
And that question leads directly to the infrastructure behind the MCA filing system, because the government portal does not operate as an entirely closed system. Filings pass through technology, service providers, support systems and other layers of infrastructure, creating multiple points at which sensitive information may potentially be accessed.
If The Data Is Not Public, Someone With Access Is Letting It Out
The Ministry of Corporate Affairs portal does not operate in isolation. The MCA V3 system is supported by technology infrastructure, external service providers, validation systems, customer-support functions and data-management layers through which information submitted by companies and their directors necessarily passes. That creates a series of access points between the moment a founder uploads information and the moment that information is ultimately stored within the government’s systems.
The existence of those access points does not, by itself, establish that the alleged leakage is taking place through any particular vendor, employee or contractor. But it does explain why the question cannot be answered simply by looking at what appears on the public MCA website. The information being used by the banks may not be coming from the public-facing database at all.
A newly incorporated company, together with its founder’s name, mobile number, email address, registered address and other information submitted during incorporation, has obvious commercial value. For a bank trying to acquire a new current-account customer, the timing is especially valuable because the company has just been created and is likely to need banking services immediately. The same information is commercially useful to accounting firms, compliance providers, company-secretarial businesses, trademark agents and other service providers that target companies during the first months of their existence.
That creates an unusually attractive data product: a list of newly incorporated businesses, complete with the identity and contact details of the people behind them, available at precisely the moment when those businesses are beginning to make commercial decisions.
The material reviewed points to the possibility that such information could be accessed at several points in the technical and administrative chain surrounding MCA filings. Engineers, database administrators, customer-support personnel, vendor employees and contractors could, depending on their authorised level of access, potentially come into contact with raw registrant information. But that possibility is not evidence that any particular category of employee has actually leaked information, and identifying the precise point of leakage requires an investigation capable of examining access logs, vendor permissions, contractual arrangements and data movement.
That is precisely why the source of the information matters.
If a founder’s mobile number is absent from MCA’s public data services but appears in a bank’s lead-generation system within hours of the founder submitting it through the incorporation process, there are only a limited number of broad explanations. The information could have been obtained through a legitimate channel that has not been publicly identified, it could have been supplied by an intermediary, or it could have been accessed somewhere within the chain through which the MCA filing was processed.
The material cites an investigation into the alleged data pipeline and notes that MCA officials have reportedly been alerted and that an internal investigation is under way. As of the latest reporting reflected in the draft, however, no public findings had identified a specific vendor, no contract had been publicly suspended and no prosecution had been announced.
That absence is important. It means the strongest version of the allegation cannot yet be presented as an established fact. The evidence supports a serious question about the origin and circulation of the data, but it does not, on its own, establish which individual or organisation is responsible for removing information from the MCA system.
What can be established from the reported accounts is the extraordinary consistency of the commercial response to new incorporations. Founders describe receiving calls from multiple banks and service providers shortly after filing, with the callers already aware that a company has been incorporated and possessing information that the founder had recently submitted.
The issue is therefore not simply that entrepreneurs are receiving unwanted calls. It is that the speed, specificity and apparent source of those calls raise questions about whether information supplied to the government for a defined statutory purpose is being transformed into a private lead-generation pipeline.
That distinction is crucial because the commercial value of the information creates an incentive for every participant in the chain. A bank can acquire a potentially valuable customer before a competitor does. A compliance firm can reach a company before it has selected an accountant or filing provider. A service intermediary can sell access to the same prospect repeatedly.
The more valuable the information becomes, the greater the need for strict controls over who can access it, what they can extract, where it can be transferred and whether those transfers are recorded.
For MCA, the question is therefore not merely whether its public database contains a founder’s mobile number. It is whether the wider system through which that number entered the government’s possession has sufficient controls to ensure that the information cannot be diverted into a commercial pipeline without authorisation.
For the banks, the question is different but equally important: if a lead arrives carrying information that appears to have originated inside a government filing system, what checks are performed before that information is entered into the bank’s customer-acquisition machinery?
Those questions become even more serious when the information allegedly includes Aadhaar and PAN documents, because at that point the issue moves beyond the aggressive pursuit of a business lead and into the handling of highly sensitive identity information.

A Bank Calling Is One Thing. A Bank Arriving With Your Aadhaar Is Another
There is a significant difference between receiving an unsolicited sales call and discovering that a bank employee appears to possess personal identification documents that were never provided to the bank. The accounts surrounding the MCA data controversy cross that line when founders allege that bank representatives have approached them with information they had submitted to the government during the incorporation process.
In one of the most serious accounts cited in the material, a founder said that a bank employee arrived at his home the morning after incorporation and had the founder’s PAN, Aadhaar, name, email address and mobile number visible on the employee’s phone. The founder said those details had never been provided to the bank and corresponded to information submitted to the MCA portal.
If that account is established, the issue is qualitatively different from ordinary telemarketing. A bank employee possessing another person’s identity documents without an existing banking relationship raises questions about the source of the information, the purpose for which it was obtained and the safeguards applied before it entered the bank’s customer-acquisition process.
The legal framework governing such information is also more demanding than the rules governing ordinary marketing communications. The Aadhaar Act contains restrictions around the use and disclosure of Aadhaar information, while the Information Technology Act contains provisions concerning the disclosure of personal information in breach of lawful obligations and the protection of sensitive personal data.
The draft also identifies Section 72A of the IT Act, which deals with disclosure of personal information in breach of a lawful contract, and Section 43A, which concerns compensation and reasonable security practices in relation to sensitive personal data.
The Digital Personal Data Protection Act, 2023 adds another layer. Under the framework described in the draft, a private bank processing personal information would operate as a Data Fiduciary and would be expected to have a lawful basis for processing personal data, maintain appropriate security safeguards and respect the purpose for which the information was collected. The Act also establishes additional obligations for entities designated as Significant Data Fiduciaries.
The central issue, therefore, is not simply whether a bank received a lead from an outside marketing agency. If the underlying data includes personal information supplied to MCA for incorporation purposes, the bank would need to be able to establish where that information came from and on what basis it was processed.
That responsibility becomes particularly important when banks use third-party lead-generation networks. A bank cannot necessarily treat an external marketing intermediary as a black box and assume that the data supplied by the intermediary was lawfully collected.
The regulatory framework governing banks’ outsourcing arrangements places obligations around due diligence and oversight of third-party service providers, while data-protection principles increasingly require organisations to consider not only what information they possess but why they possess it and whether they are entitled to use it for the purpose in question.
The draft therefore raises a question that extends beyond the individual employee who allegedly arrived at the founder’s home.
- If a bank’s marketing machinery receives personal information from a third party, what verification is carried out before that information is accepted into the bank’s systems?
- Does the bank record the source of each lead?
- Can it trace the information back through the intermediary that supplied it? Does it know whether the intermediary obtained the information with the necessary authority?
- And what happens when the data includes identity documents rather than ordinary contact details?
- These are not abstract compliance questions. They go to the basic distinction between information that a person voluntarily gives to a bank and information that a bank obtains about a person who has never agreed to become its customer.
The distinction is particularly important for newly incorporated founders because the initial banking relationship can be commercially valuable. A bank that reaches an entrepreneur before competitors have done so has an obvious advantage in acquiring the current account, payments relationship, payroll business, credit relationship and other financial services that may follow. That commercial incentive, however, cannot by itself create a lawful basis for acquiring or processing personal information.
The allegations also raise a question for the regulators. If multiple banks are receiving apparently similar information about newly incorporated companies within hours of MCA filings, the matter cannot be resolved simply by asking each individual founder to complain about each individual call. The pattern itself requires examination of the data supply chain.
That means identifying how the information moves from MCA to any external service provider, how access is controlled, whether information can be exported, whether those exports are logged, and whether banks and their intermediaries can demonstrate a lawful provenance for the leads they receive.
Until those questions are answered, the most troubling element of the MCA controversy remains unresolved: whether information submitted by citizens to the State for one specific purpose is being quietly converted into a commercial asset for institutions that those citizens never approached.

“We Got It From A Vendor” Is Not The End Of The Question
If the banks named in the MCA controversy received founders’ information through marketing agencies, direct-selling agents or other intermediaries, the next question is whether that explanation is sufficient.
For regulated financial institutions, outsourcing a customer-acquisition activity does not necessarily outsource responsibility for the way personal information is obtained and used.
Banks operate within a framework that requires them to exercise oversight over third-party service providers involved in their business. The Reserve Bank of India’s directions on KYC and the management of risks arising from outsourced financial services place emphasis on due diligence, controls and oversight of external parties working on behalf of regulated entities.
That becomes important in the context of the alleged MCA data pipeline because the banks are not being accused merely of making unsolicited calls. The more serious allegation is that some of the information being used to make those calls may have originated from a government filing system and may include information that was never made publicly available through MCA’s ordinary data channels.
If a bank receives such information from an intermediary, it should be possible to establish the provenance of the data. A properly controlled lead-generation system should be able to answer basic questions about where a customer lead came from, which intermediary supplied it, what information was obtained, when it was obtained and what authority existed for using it.
The same principle applies to direct-selling agents and other customer-acquisition partners. The fact that an individual making the call is not technically employed by the bank does not automatically remove the bank from the chain of responsibility. If the individual is acquiring customers on the bank’s behalf, the bank has an interest in ensuring that the methods used to generate those customers comply with the rules governing its operations.
The Digital Personal Data Protection Act adds another dimension to that responsibility. The framework requires personal data to be processed for a lawful purpose and places obligations on Data Fiduciaries concerning security and the handling of personal information. The draft also notes that Significant Data Fiduciaries face additional obligations under the Act, including requirements relating to impact assessments and data-protection oversight.
The question for banks is consequently straightforward. If an entrepreneur has never approached the bank, never consented to receive its marketing communications and has only recently submitted personal information to MCA, what is the lawful basis on which the bank is processing that information?
A second question follows immediately. If the bank says that the information came from a third-party lead generator, can the bank demonstrate that the lead generator obtained it lawfully?
Those questions become even more important when the information includes Aadhaar or PAN details. The more sensitive the information, the harder it becomes to treat the source of that information as an ordinary marketing detail that does not require scrutiny.
The issue also exposes a potential weakness in the way customer acquisition is treated within the financial sector.
Banks have sophisticated systems for assessing the creditworthiness of customers, conducting KYC checks and monitoring transactions, but the process through which the customer first enters the bank’s marketing funnel can occur through a much more fragmented ecosystem of agencies, vendors and lead generators.
That creates an obvious risk. The bank may know exactly how to verify a customer once that person formally applies for an account, while having considerably less visibility into how the person’s name first appeared on a sales representative’s list.
The MCA controversy turns that weakness into a much more consequential question because the alleged source is not an ordinary commercial database. It is a government filing system containing information submitted by citizens and businesses under a statutory process.
If the information is being extracted without authorisation, the responsibility cannot rest entirely with the person who happened to receive the data. There has to be accountability across the chain, including at the point where the information enters the commercial ecosystem and at the point where a regulated bank decides to use it.
This is also where the issue becomes relevant to the RBI. The regulator does not need to establish that every bank named in the allegations participated in obtaining the information unlawfully before asking how those banks source newly incorporated-company leads. It can ask a more basic supervisory question: can each bank demonstrate the provenance of the customer data entering its acquisition systems?
If the answer is yes, the banks should be able to show the records. If the answer is no, the absence of those records becomes a governance problem in its own right.
The larger concern is that a bank’s customer-acquisition process should not become the weakest link in an otherwise tightly regulated financial institution. The KYC process may begin only after a customer chooses to open an account, but the obligation to know where the information used to target that customer came from begins much earlier.
Everyone Has A Piece Of The Puzzle. Nobody Appears To Own The Whole Picture
The MCA data controversy exposes a regulatory problem that is almost as complicated as the data trail itself. Several institutions have jurisdiction over different parts of the issue, but the alleged conduct crosses boundaries between corporate registration, banking, telecommunications, data protection and government information systems.
The result is a situation in which responsibility can become fragmented even when the underlying problem is systemic.
For the Reserve Bank of India, the immediate concern is the conduct of regulated banks. If HDFC Bank or any other lender is receiving personal information about newly incorporated companies through third-party marketing channels, the RBI has a clear interest in understanding how those leads are sourced and whether the banks have adequate controls over their acquisition partners.
The existing banking complaints framework, however, is primarily designed around relationships between customers and their banks. A person who already has an account with a bank can raise a complaint about the bank’s conduct through established channels.
The situation is less straightforward when the complainant has never been the bank’s customer in the first place and is instead alleging that the bank obtained his personal information without permission and used it to solicit his business.
That distinction matters because the alleged MCA leak begins before the banking relationship exists. The entrepreneur has not applied for an account, has not submitted a KYC application to the bank and may never have spoken to anyone at the bank. Yet the bank allegedly has enough information about the entrepreneur to initiate the relationship itself.
The Telecom Regulatory Authority of India also has a role because unsolicited commercial communications fall within the framework governing commercial communications and customer preferences. The TCCCPR framework provides mechanisms for dealing with unwanted marketing communications and requires banks and their telemarketing partners to operate within prescribed consent and registration arrangements.
But the telecom framework does not answer the most important question in this case. It can address the fact that a call was made, but it does not necessarily establish how the caller obtained the information that made the call possible in the first place.
That leaves the data-protection framework. The Digital Personal Data Protection Act was intended to create a more comprehensive system governing the collection and processing of personal information, including obligations on entities that determine why and how personal data is processed. The Data Protection Board is intended to provide the institutional mechanism for handling breaches and imposing penalties under the new framework.
Yet the framework is still relatively new, and the institutional machinery required to enforce it is developing. The draft notes that significant enforcement actions against named private banks under the new law had not yet established a meaningful body of precedent at the time of writing. That creates a gap between the theoretical penalties available under the law and the practical certainty of enforcement.
The Ministry of Corporate Affairs occupies another critical position because the alleged data originates from information submitted through its own systems.
According to the material, MCA officials have been informed about the issue and an internal investigation is under way, but no public findings had yet identified the source of the alleged leakage, named a responsible vendor or announced a prosecution.
This leaves a particularly awkward accountability structure. MCA controls the filing environment in which the information is submitted. The banks allegedly receive the information and use it for customer acquisition. Marketing intermediaries may sit between the two. TRAI regulates commercial communications. The RBI regulates the banks. MeitY administers the broader data-protection framework. The Data Protection Board is expected to enforce the DPDP regime.
Each institution can therefore point to a different part of the problem.
The entrepreneur, however, experiences the problem as a single event.
![]()
Different Episodes, Different People, But The Same Question About Controls
The three controversies examined in this article involve different products, different parts of HDFC Bank’s operations and different sets of customers.
- The Carlisle dispute concerns investment products sold through the bank’s overseas operations.
- The MSRDC matter concerns an alleged arrangement involving institutional deposits and marketing expenditure.
- The MCA controversy concerns the sourcing and use of personal information by banks and their marketing networks. There is no evidence in the material reviewed that these matters form part of one coordinated scheme.
- What they do have in common is the question they place before the bank: how effectively do its controls operate when there is a strong commercial incentive to acquire a customer, retain a relationship or meet a business target?
None of these questions automatically establishes institutional misconduct. A complaint is not a finding, an allegation is not a regulatory determination and a reported internal finding still needs to be understood in its proper context. That distinction is particularly important when discussing a bank whose operations involve millions of customers, thousands of employees and a vast network of external service providers.
But the purpose of examining the controversies together is not to declare that every allegation has already been proven. It is to ask whether the bank’s response to each episode is sufficient to address the underlying control question.
The episodes therefore raise different versions of the same governance question: when commercial incentives collide with customer protection, regulatory restrictions or data safeguards, which side ultimately wins?
That is the question that cannot be answered simply by looking at the size of HDFC Bank’s balance sheet or the profitability of the institution. Financial strength can demonstrate that a bank is capable of absorbing losses. It cannot, on its own, demonstrate that every internal process is functioning properly.
HDFC Bank’s post-merger scale makes the issue more important. The merger with HDFC Ltd. created a financial institution with enormous reach and a significantly larger operating structure, while also creating pressure to integrate businesses, maintain growth and mobilise deposits. The MSRDC controversy emerged within that broader environment of deposit mobilisation, while the overseas disputes involved the bank’s efforts to serve customers through international operations.
The danger in such an environment is not necessarily that commercial targets exist. Every large bank has targets. The danger arises if employees, departments or external partners begin to treat regulatory requirements and control mechanisms as obstacles to those targets rather than boundaries within which the targets must be achieved.
The Questions HDFC Bank Cannot Answer With A Balance Sheet
The controversies surrounding HDFC Bank ultimately come down to questions that cannot be answered by pointing to the size of the bank, the immateriality of an individual transaction or the existence of internal control frameworks on paper. The relevant issue is whether those controls worked when they were actually needed, and whether the bank can demonstrate what it did when they did not.
A bank of HDFC Bank’s scale should be able to answer them with records rather than assurances. It should be able to show how a product was sold, how a payment was approved, how a customer lead was sourced and how a complaint was investigated.
That is ultimately the standard that matters. The strength of a governance system is not demonstrated by saying that controls exist. It is demonstrated by showing what those controls did when a potentially problematic transaction, customer complaint or data source entered the system.
Three Controversies, One Uncomfortable Question: Who Is Watching The Watchers?
The most consequential issue raised by the HDFC Bank controversies is not whether the bank can absorb the financial impact of an individual dispute. It is whether the layers of oversight surrounding a bank of its size are working effectively enough to identify problems before customers, regulators or the public are forced to do so.
In the Carlisle matter, investors say they have spent years attempting to resolve concerns over the way the investment was sold, the risks associated with it and their subsequent inability to secure redemption. The fact that the group is now preparing complaints to multiple regulators suggests that, from the investors’ perspective, the ordinary mechanisms for resolving the dispute have not produced a satisfactory outcome.
The earlier regulatory action involving the sale of Credit Suisse AT1 bonds adds another layer to that question. The DFSA had already restricted HDFC Bank’s DIFC operations after concerns over the alleged mis-selling of high-risk securities to retail customers. The bank also took action against employees in connection with the episode.
The issue for regulators is therefore not simply whether individual employees understood the rules. It is whether the institution had sufficient systems to ensure that those rules were being followed consistently across its sales operations.
The MSRDC controversy presents the same question from a different direction. The alleged arrangement involved a large institutional customer, a significant amount of money and multiple internal functions. The Audit Committee ultimately ordered a formal investigation, and the resulting vigilance process reportedly examined the conduct and knowledge of senior officials.
If an arrangement of that nature could move through a major bank’s business, marketing and payment processes, then the question is not merely who approved the individual invoices. It is why the bank’s systems did not identify the underlying economic purpose of the payments earlier.
The MCA allegations take the oversight problem outside the traditional boundaries of banking. A bank may insist that a marketing agency supplied a lead, while the agency may say that it obtained the information from another source. The source may in turn point to publicly available corporate information or another intermediary. Without an auditable chain showing where the data originated, responsibility can disappear into the gaps between organisations.
That is precisely where governance is supposed to operate.
A sophisticated institution should not merely have policies stating that customer data must be lawfully sourced or that deposit arrangements must comply with applicable regulations. It should have systems capable of demonstrating that those policies were followed in practice.
That means maintaining records, creating audit trails, monitoring unusual transactions, scrutinising third-party vendors and escalating anomalies before they become controversies.
The three matters also raise a question about the role of the board. Boards are ultimately responsible for ensuring that management operates within an appropriate governance framework, but they depend on internal audit, compliance, risk management, vigilance mechanisms and external reviews to identify where that framework may be failing.
When a chairman resigns after citing practices inconsistent with his values and ethics, when an Audit Committee subsequently orders a formal investigation, and when separate controversies continue to generate regulatory scrutiny, the board’s role becomes particularly important.
The objective should not be to manufacture a connection between unrelated controversies. It should be to determine whether the institution is learning from each one.
If the answer is yes, the evidence should be visible in stronger controls, clearer accountability and fewer opportunities for the same weaknesses to recur.
If the answer is no, then the problem is no longer the individual controversy. It becomes the governance system itself.
And that is why the questions surrounding HDFC Bank are becoming harder to ignore. A bank can dismiss one complaint as a dispute, one payment as immaterial, one employee as an exception and one data lead as the responsibility of a vendor. But when questions begin appearing across customer conduct, institutional transactions, internal controls and personal data, the institution has to do more than answer each allegation separately.
It has to demonstrate that the system connecting all those activities is actually under control.

The Last Bit, The Final Question Is Not Whether HDFC Bank Is Too Big To Fail, But Whether It Is Big Enough To Be Held To A Higher Standard
HDFC Bank is one of India’s most important private-sector financial institutions, and that status makes the questions raised by these controversies more consequential, not less. A bank of this scale does not operate only for its shareholders. Its decisions affect depositors, borrowers, investors, employees, corporate customers and the wider financial system.
That is why the standard applied to its conduct cannot be limited to whether a particular episode caused a material financial loss.
These are different questions, but each ultimately concerns trust.
A customer buying an investment trusts the bank to explain the risks accurately. An institutional depositor trusts the bank to apply its rules consistently. A founder submitting personal information to the government trusts that the information will not simply become a commercial lead for companies he or she never approached.
That trust is not created by advertising or balance-sheet size. It is created by the systems operating behind the institution.
HDFC Bank has an opportunity to demonstrate that those systems are stronger than the controversies currently surrounding them. It can show what happened, establish what did not happen, identify where controls failed if they did, and demonstrate what has been changed as a result.
The bank can also allow regulators and investigators to establish the facts independently where allegations remain disputed.
That is the appropriate standard because neither extreme is useful. Treating every allegation as proof of systemic misconduct would be irresponsible. Treating every controversy as an isolated inconvenience would be equally inadequate.
The material available at present does not establish that the three controversies are part of a single coordinated operation. It does, however, show that very different parts of HDFC Bank’s business and governance structure have faced serious questions at different points, including questions that have attracted regulatory scrutiny, internal investigations and complaints from customers or other stakeholders.
The responsibility now is to determine whether those questions reveal isolated failures or recurring weaknesses.
That answer will not come from the bank’s size. It will come from the records, the investigations, the regulators and the actions that follow.
And perhaps that is the most important question HDFC Bank now faces: not whether it can withstand another controversy, but whether it can demonstrate that its systems are strong enough to prevent the next one.



