Skip to content

Part 07 — People & Org

RACI Matrix

A RACI matrix makes hand-offs explicit. R = Responsible, A = Accountable, C = Consulted, I = Informed. In SME lending, the same person should not be accountable for every step. The relationship manager (RM) can source and explain the customer story, but cannot be accountable for credit approval. Credit can approve risk, but cannot release money without operations and finance controls. Compliance can challenge the process, but should not run the business.

This matrix uses the 15 Part 5 pages as the lifecycle map: overview, sourcing, pre-screening, KYC onboarding, application documents, underwriting data, underwriting decisioning, due diligence, collateral valuation/legal, sanction, documentation/security, disbursement, servicing, monitoring/EWS and special workflows.

The matrix is for a mid-sized Indian non-banking financial company (NBFC) or bank SME vertical. It assumes outsourced vendors may perform field investigation, legal search, valuation, telecalling or collections, but the regulated entity keeps accountability. RBI’s Digital Lending Directions, 2025 state that regulated entities remain responsible for lending service provider (LSP) acts and omissions, and the same accountability logic should be applied to DSAs and other outsourced vendors. Internal audit is shown as informed or consulted because audit should not become an operating approver; RBI’s Risk-Based Internal Audit circular treats internal audit as the third line of defence.

RoleOverviewSourcingPre-screenKYCApp docsUW dataUW decisionDue diligenceCollateralSanctionDocs/securityDisbursementServicingMonitoring/EWSSpecial workflows
Board / Risk CommitteeAICIIICIIAIIIAA
CEO / Business HeadAACIIICIICIIICA
RM / Sales / DSA ManagerCRRCRCICCICICIC
Sales Operations / CRMRRRCRIIIIICIIII
KYC / AML OperationsCICA/RCCICICCCCCC
Credit Analyst / Credit ManagerCCA/RCCA/RRCCRCCICC
Credit Committee / National Credit HeadAICIICACCA/RCCICA
Policy / Portfolio RiskACACICCCCCIICA/RA
RCU / Fraud Control UnitCCCCCCCA/RCCCIICC
Legal / Technical / ValuationCIICCCCCA/RCA/RCCCA/R
Loan Operations / CPUCIICA/RCIICCA/RA/RRCR
Treasury / FinanceCIIIIICIICCA/RCCA/R
Collections / RecoveryCIIIIIICCICICA/RA/R
Compliance / GrievanceACCCIICCCCCCCCA
Technology / DataRCCCCCCCCCCCCCR
Internal AuditIIIIIIIIIIIIICI
Partner / Co-lender / Anchor ManagerCA/RCCCCCIICCCCCA/R

Overview. Accountability sits with the board/risk committee and executive leadership because the lifecycle defines risk appetite, operating model, policy ownership and system controls. Technology is responsible for maintaining the workflow map in loan origination system (LOS), loan management system (LMS), business rules engine (BRE) and partner APIs. Compliance must sign off that the model covers fair practices, outsourcing, digital lending, data retention and grievance obligations.

Sourcing. Sales is responsible, but the business head is accountable for channel strategy. A DSA manager can run empanelment and activation, but the lender remains accountable for mis-selling and outsourced acts. For LSP-fronted flows, the partner manager becomes accountable for partner readiness and offer-display controls, while sales operations owns source attribution.

Pre-screening. Credit policy should be accountable for cut-offs, negative lists, geography, product eligibility and dedupe rules. Sales may run the customer conversation, but it should not be able to bypass bureau consent, blacklist, existing delinquency or product-ineligible pincode rules.

KYC. KYC/anti-money laundering (AML) operations is accountable for customer due diligence, beneficial ownership and screening. Sales can collect documents and explain constitution type, but KYC exceptions should route to compliance or AML, not to the ASM.

Application documents. Operations or sales operations should own checklist completeness. The RM is responsible for collecting originals/copies from the borrower, but operations must check document version, legibility, stamping, signatures and constitution-specific requirements.

Underwriting data and decisioning. Credit owns data interpretation and recommendation. The credit committee or delegated credit authority is accountable for approval, rejection and deviations. RCU is consulted when authenticity or fraud signals matter. Portfolio risk should see policy exceptions and override trends.

Due diligence. RCU/FCU is accountable for fraud and verification outcomes. Credit remains consulted because PD and appraisal may need clarification, but sales should not clear negative findings. Field investigation vendors are responsible only under the lender’s supervision.

Collateral valuation/legal. Legal and technical teams are accountable for title, valuation and enforceability. Credit is consulted for LTV and structure. Operations should not disburse until required legal/technical conditions are complete or formally waived by the right authority.

Sanction. Delegated credit authority is accountable. Credit prepares the recommendation and sanction terms. Compliance is consulted where disclosure, pricing, Key Facts Statement (KFS), fair practices or digital lending rules are affected.

Documentation/security and disbursement. Operations is accountable for execution, security creation, mandate setup and booking. Treasury/finance is accountable for funds release and reconciliation. Legal is accountable for enforceable documents and charge perfection. A disbursement checker should be able to stop a fully approved file if conditions precedent are unmet.

Servicing. Operations/customer service is responsible for borrower requests, statements, foreclosure, mandate changes and NOC. Compliance is consulted for complaint categories and regulatory timelines. Credit and sales are informed unless the request changes risk.

Monitoring/EWS. Portfolio risk is accountable for early-warning signals (EWS), covenant tracking and stress reporting. Collections becomes responsible when delinquency appears. Credit is consulted for renewals, enhancements and restructuring screens. See collections operations for bucket execution.

Special workflows. This includes restructuring, settlements, promoter death, insolvency, co-lending split corrections, subvention disputes and fraud-confirmed cases. Accountability depends on type: credit for restructuring, legal/collections for recovery, finance for accounting, compliance for customer/regulatory impact, and partner manager for co-lending/embedded cases. The table marks several roles as accountable/responsible because one blanket owner would be false.

The system should store RACI, not just display it. Each stage needs an accountable owner, responsible queue, consulted roles, informed roles, escalation timer and override authority. Maker-checker should be configured by role and event: source-code change, KYC override, credit deviation, RCU negative clearance, title-risk waiver, disbursement approval, bank-account change, charge waiver, settlement, write-off and collateral release.

Role permissions should follow the actors and permissions blueprint later in this guide. The operating test is simple: if a file goes bad, the audit trail should show who sourced it, who checked it, who approved it, who waived what, who released money, who monitored stress and who handled recovery.