Skip to content

Part 07 — People & Org

Org Structure

An SME lender’s organisation chart is a control framework, not a PowerPoint shape. In a bank or non-banking financial company (NBFC), the same borrower may touch a relationship manager (RM), direct selling agent (DSA), credit analyst, risk control unit (RCU), operations maker, legal vendor, collections agency and customer service desk before the loan has completed one instalment. The structure has to let business grow without letting sales own credit, credit own operations, or operations conceal ledger problems.

RBI’s scale-based regulation (SBR) makes this separation more than good practice. The Master Direction on NBFC SBR, 2023 consolidates governance and prudential rules for NBFCs by layer. Middle layer and upper layer NBFCs also need an independent compliance function and Chief Compliance Officer (CCO) under RBI’s April 11, 2022 CCO circular. Large NBFCs must think like supervised financial institutions: board committees, risk ownership, documented delegation of authority (DoA), independent audit, and evidence for every outsourced act.

A mid-sized SME lending NBFC usually looks like this:

NBFC organization chart showing board committees, MD and CEO, business functions, risk and compliance functions, and internal audit across three lines of defence.
A practical SME-lending NBFC structure: business execution, independent control functions and audit assurance.
LevelTypical titlesWhat they own
BoardBoard of Directors, Audit Committee, Risk Management Committee, Nomination and Remuneration CommitteeRisk appetite, policies, committee oversight, related-party and governance controls.
ExecutiveManaging Director (MD), Chief Executive Officer (CEO), Chief Business Officer, Chief Risk Officer (CRO), Chief Credit Officer (CCO in credit context), Chief Compliance Officer, Chief Financial Officer, Chief Operations Officer, Chief Technology OfficerStrategy, capital, portfolio quality, regulatory compliance, operating model.
National product/function headsNational Sales Head - MSME, National Credit Head, Head - Policy, Head - RCU/Fraud Control Unit (FCU), Head - Operations, Head - Collections, Head - Legal, Head - PartnershipsProduct P&L, underwriting standards, operational capacity, vendor and partner governance.
Zonal/regional headsZonal Sales Manager, Regional Sales Manager (RSM), Zonal Credit Manager, Regional Credit Manager (RCM), Regional Operations Manager, Regional Collections ManagerGeography performance, TAT, portfolio quality, people and vendor performance.
Cluster/area layerArea Sales Manager (ASM), Cluster Credit Manager, Area Credit Manager, Branch Operations Manager, Area RCU Manager, Agency ManagerBranch-level execution, deviations, field checks, first-line supervision.
FrontlineRM, Sales Manager, DSA Manager, Credit Analyst, Credit Manager, Operations Maker/Checker, Telecaller, Field ExecutiveCustomer acquisition, appraisal, documents, disbursement, service, collection.

Public sector banks use formal officer scales such as Junior Management Grade Scale I (JMGS-I), Middle Management Grade Scale II/III (MMGS-II/III), Senior Management Grade Scale IV/V (SMGS-IV/V) and Top Executive Grade Scale VI/VII/VIII. Bank of Baroda’s MSME recruitment page, for example, listed Manager - Credit Analyst in MMG/S-II, Senior Manager - MSME Relationship and Senior Manager - Credit Analyst in MMG/S-III, and Head - SME Cell in SMG/S-IV (Bank of Baroda MSME recruitment). NBFCs are less standardised, but common ladders are executive/officer, assistant manager, deputy manager, manager, senior manager, chief manager, assistant vice president (AVP), vice president (VP), senior vice president (SVP), executive vice president (EVP), function head and CXO.

The three lines of defence model is the cleanest way to understand accountability:

LineIn SME lendingWhat “good” looks like
First lineSales, branch, credit underwriting, operations, servicing, collections, partnership managersOwns risks created by daily business. Checks documents, follows policy, records exceptions, manages DSAs and vendors.
Second lineRisk policy, portfolio risk, RCU/FCU, compliance, information security, credit control, finance controlSets frameworks, monitors exceptions, challenges first-line decisions, reports to senior management and board committees.
Third lineInternal audit and information systems (IS) auditIndependently tests whether controls actually work. Reports functionally to the Audit Committee.

RBI explicitly describes internal audit as the third line of defence in its Risk-Based Internal Audit circular for select NBFCs and UCBs, February 3, 2021. The same circular says internal audit should assess governance, risk management and control processes, not only transaction accuracy.

In practice, the boundaries are messy. A branch credit manager may report administratively to a regional business head for staffing and locally to credit for decisions. A DSA manager is first line even if the DSA is not on payroll. An RCU manager is usually second line for fraud checks, but field investigation vendors may be managed operationally by credit or operations. The test is simple: who can veto the file, who can approve the exception, and who checks the checker?

Span of control depends on ticket size, channel and underwriting complexity. Useful norms:

RoleTypical spanWhy it matters
ASM / branch sales manager6-10 sales managers or RMs; 25-80 active DSAs/connectors depending on geographyMore than this usually degrades source governance and document quality.
RSM / cluster sales head4-8 ASMs or branchesMust review funnel, sanction pull-through, early delinquency and complaint trend, not just disbursement.
Cluster credit manager3-8 credit analysts/managers; often 2-6 branchesToo wide a span increases template CAM approvals and weak personal discussion discipline.
Regional operations manager5-15 branches/ops desksNeeds maker-checker capacity for disbursement, mandate, charge registration and document vault.
Agency manager - collections3-8 agencies or 10-25 field executivesConduct risk rises sharply if agency visits, cash receipts and call recordings are not sampled.
RCU manager2-5 vendors plus branch samplingSmall teams can work if sampling is risk-based and negative areas are tracked centrally.

These are not statutory ratios. They are operating design norms seen in SME, loan against property (LAP), machinery finance and business-loan businesses. A ₹5 lakh digital merchant loan can run with centralised underwriting and low branch span. A ₹3 crore LAP file in Jaipur or Coimbatore needs local legal, technical and credit judgement; one over-stretched cluster credit manager becomes a bottleneck and a fraud risk.

DoA should name approval authority by product, amount, risk grade, collateral, deviation and exposure group. Typical levels:

AuthorityExample approval
Branch/area credit managerLow-ticket, policy-compliant unsecured or asset-finance cases.
Cluster/regional credit managerMedium-ticket cases, limited deviations, local market judgement.
Zonal credit manager / National Credit HeadLarge tickets, high loan-to-value (LTV), weak bureau mitigated by collateral, complex structures.
Credit committeeExposure concentration, promoter group risk, new-product exceptions, large LAP/working-capital limits.
Board/Risk CommitteePolicy changes, risk appetite, portfolio caps, related-party or unusually large exposures.

The credit committee should not become a place where every incomplete file is rescued. A clean sanction note separates policy deviations, financial assessment, RCU remarks, legal/technical status, pricing, collateral coverage and conditions precedent. The RACI matrix translates that into system ownership.

Indian SME lenders outsource DSAs, call centres, field investigation, technical valuation, title search, legal notices, collections agencies and software-as-a-service platforms. RBI’s Digital Lending Directions, 2025 and NBFC outsourcing provisions keep responsibility with the regulated entity. Therefore, the org chart must include vendor governance: empanelment, training, service-level agreements (SLAs), audit rights, complaint handling, access control and exit plans.

The most reliable structure is boring: sales is hungry, credit is independent, operations is documentary, finance is reconciled, compliance is inconvenient, and audit can see everything. That is what lets the lender grow across branches and partners without pretending that culture alone is a control.