Skip to main content
NSWS
Case study · NBFC Lending

A compliance-grade NBFC lending platform now in its fourth release with the same team.

We engineered a custom Loan Origination + Loan Management platform for Unnatti Finserv, and stayed on as their platform partner through four releases. Credit policy now sits in a visual rulebook their own risk team edits, the books balance inside the platform rather than after an export, and RBI Digital Lending Guidelines and DPDP Act controls run through origination, servicing, and reporting.

Unnatti FinservClient
Challenge

The starting state.

Every product or workflow change required vendor involvement. Nothing was self-configurable. New loan variants, fee structures, or approval stages meant paid change requests with a weeks-long queue.
Credit rules were hardcoded. When underwriting policy needed to change (tighter bureau cutoffs, new deviation rules, product-level exceptions), the system didn't follow without a full engineering engagement.
Loan origination workflows were fixed in code. Adding an approval stage, a document checkpoint, or a compliance step meant raising a ticket, not making a configuration change.
Our approach

How we engineered it.

01

Compliance-first architecture

RBI DLG, DPDP, and IT Outsourcing constraints baked into the LOS schema, cloud topology, document service, and disbursement state machine, not bolted on at audit time.

02

Rules the client owns

The problem that started the engagement was that credit policy could not move without a vendor. So we built the answer to it: a visual rulebook where the risk team lays out bureau cutoffs, deviation tiers and product exceptions themselves. Every version is kept, and any past application can be re-run against the rules that were live the day it was decided.

03

Policy-aware workflow design

Multi-stage deviation workflows and a credit review committee surface engineered into the underwriting flow, with AA-driven bank statement analysis and offer generation tied back to the same audit trail.

04

Sequenced migration

Stood up new platform alongside legacy, mirrored disbursements for parity, sunset legacy origination per loan product without disrupting servicing.

05

Productized accelerators

LOS module skeleton + adapter library for bureaus, BSA, eKYC, eSign, and payment rails, compressed a 12–18 month vendor timeline into 8–16 weeks.

06

Senior ownership

Architects in the UAT room, integration contracts reviewed before code, failure modes named before QA found them, production support through first 90 days.

What we built

Architecture and the systems it talks to.

Credit policy held in a visual decision table the risk team edits directly, versioned on every change, with each application's rule outcome retained so a decision can be replayed years later
Every application locked to the exact product, fee and policy configuration in force on the day it was submitted, so a rate change today cannot rewrite a loan sanctioned last month
A double-entry sub-ledger inside the platform: journals that must balance before they post, accounting periods that lock, and a second approver required on every manual entry
Tamper-evident audit trail, where each event is sealed into a cryptographic chain with periodic integrity checkpoints, carrying who acted, in what role, and whether it was a person, a schedule, or a connected system
Every view, download and export of borrower data logged with actor, role, IP and record count, so a DPDP question about who saw a customer's file is answered by a query
Collections built for how repayment actually happens: EMI presentation and scheduled re-presentation, payment before due date, part, full and excess payment, foreclosure and write-off, penal and bounce charges, cash collection with sequenced receipting and UTR-based deduplication, and a maker-checker on every fee change, correction, or deletion of a cash entry
Product-agnostic rails: a new financial product is defined as configuration, with its own eligibility, fee, schedule and charge behaviour, rather than as a fresh build against the same code
API-first, event-driven LOS with DPD tracking as a first-class event consumed by collections and GL in real time
Multi-stage deviation workflows with configurable approval tiers, exception rules per product, and full deviation history retained for audit
Credit review committee surface with case file aggregation, deviation log, and decision evidence tied back to the underwriting trail
AA-driven bank statement analysis as a first-class underwriting input, sitting alongside Perfios and Finbox in the analysis layer
Offer generation engine producing eligibility-bound offers with expiry, customer acceptance log, and amendment trail
Cooling-off periods modeled as state transitions in the disbursement engine, audit-logged per change
KFS document service emitting regulator-format documents with versioning and customer acceptance log
Borrower data localization via cloud topology aligned to RBI residency clauses
Per-loan history queryable and replayable for inspection, down to the configuration and rules that were live at each step
Live on this platform
CRIF HighmarkAccount AggregatorDigioDigitapSurepassCKYCPenny-dropAadhaar eSignNPCI eMandateTransBnkNACHRazorpayPhonePe QRUPIIMPSTata Teleservices
Adapter built · switched on per engagement
CIBILExperianEquifaxPerfiosFinboxHyperverge
Accounting / GL
In-platform double-entry ledgerTally
Outcomes

Quantified impact.

Client-run
Credit policy changes

Bureau cutoffs, deviation tiers, and product exceptions changed by the risk team in an afternoon, with no release and no change request.

Configured
New products, not rebuilt

A new financial product is set up as configuration, with its own eligibility, fees, schedule and charges, rather than another engineering cycle.

In-platform
Balanced books

Double-entry ledger with period locks and a second approver on manual entries, so month-end reconciles without an export step.

6-sprint
Compliance-grade UAT cadence

Formal sprint-to-sprint UAT with audit-traceable acceptance per release.

11 blocks
RBI + DPDP rules implemented

Across origination, servicing, collections, and reporting modules.

0
Missed disbursement windows

Zero servicing disruption during sequenced migration from legacy LOS.

Real-time
DPD tracking

Days past due tracked per account; collections queue updated on each payment event, not overnight.

T+0
GL posting

Sub-ledger reconciliation with NACH bounce auto-reversal.

4 releases
Still the platform partner

Architects stayed past the 90-day stabilization window and through three further releases, with the backlog still running.

RBI DLG
DPDP Act 2023
IT Outsourcing
Tamper-evident audit chain
Personal-data access logging
Maker-checker on entries
RBAC
KYC orchestration
In the words of the team
The quality of delivery has been impressive, with a strong focus on NBFC processes, compliance, and scalability. The team remained responsive and committed to timelines, adapting well to evolving requirements. The project offers excellent value for the investment.
· IT Head, Unnatti Finserv
Let's talk

Ready to start your project?

30-minute call with our team. Bring your project context and we'll map a clear path forward. No decks, no demos.