Skip to content

Part 08 — Credit Risk Deep Dive

Fraud Typologies

Fraud in SME lending is not a single event. It is usually a chain: weak sourcing incentive, fabricated or selectively presented data, superficial verification, rushed sanction, poor disbursement control and delayed detection. The credit loss then looks like “business failure” until a recovery officer discovers that the shop never held the claimed stock, invoices were circular, or the borrower took loans from five lenders in the same week.

RBI’s 2024 fraud-risk directions require applicable NBFCs to have a board-approved fraud risk management policy, early-warning framework, governance forum and timely reporting framework; they apply to Upper Layer, Middle Layer and Base Layer NBFCs with asset size of ₹500 crore and above (RBI Fraud Risk Management in NBFCs Directions, 2024). Banks and AIFIs have parallel fraud-risk directions (RBI Fraud Risk Management in Commercial Banks and AIFIs Directions, 2024). This page is a practitioner map of SME fraud typologies and controls.

The basic pattern is forged or manipulated KYC, bank statements, GST returns, invoices, rent agreements, Udyam certificates, ownership proofs or financial statements. Common variants:

  • edited PDF bank statements where balances and credits are changed;
  • genuine bank statement of one account while main debt servicing happens elsewhere;
  • fake GST return screenshots instead of portal-sourced data;
  • rented premises shown as owned, or temporary signboard placed for field investigation;
  • PAN or GSTIN belonging to a related entity with better vintage;
  • forged partnership deed or board resolution;
  • fake salary or business-income proof for co-borrower.

Controls: source data directly from bank-statement analyzers, Account Aggregator where available, GST-authorised pulls and bureau APIs; match bank account name, PAN, GSTIN, Udyam and constitution; use PDF tamper checks only as secondary; require video or field evidence for premises; and keep maker-checker override logs. A manual document upload should never be treated as equal to source-pulled data.

Banking Inflation and Circular Transactions

Section titled “Banking Inflation and Circular Transactions”

Banking-surrogate programs are vulnerable to artificial credits. A borrower deposits cash, receives friendly transfers, rotates money between own accounts, or takes short-term informal loans to inflate turnover before application. The bank statement shows credits, but not sales.

Red flags:

  • same amount moving in and out within 1-3 days;
  • credits from individuals unrelated to business customers;
  • sudden average balance rise in the three months before application;
  • cash deposits just below internal review thresholds;
  • high cheque returns but strong month-end balance;
  • narration patterns like “self”, “loan”, “adjustment”, “contra”, “IMPS from family”.

Controls: remove inter-account transfers, loan credits and reversals; tag related-party names; compare GST sales and purchase pattern; verify top customers; examine daily balance not just monthly credits; and monitor first 90 days after disbursement for immediate fund diversion. For program design, see cash-flow assessment.

GST data improves underwriting, but it creates its own fraud surface. Fake or accommodation invoices, circular trading, related-party sales, inflated B2B invoices and ITC-driven networks can make a business look larger than it is. E-invoicing helps where applicable because specified documents are reported to the Invoice Registration Portal and get an Invoice Reference Number; however, e-invoice presence does not prove genuine end-use or collectability (GSTN e-invoicing overview).

Typologies:

  • sales booked to shell buyers who never pay;
  • invoices reversed through credit notes after loan sanction;
  • high outward supplies but weak bank collections;
  • ITC mismatch or purchase pattern inconsistent with claimed activity;
  • same buyer-seller group rotating invoices across GSTINs;
  • inflated invoices used for machinery or working-capital disbursement.

Controls: compare GSTR-1, GSTR-3B, e-way bills, e-invoices where available, bank credits and debtor ageing; exclude related-party GSTINs from turnover; check credit-note frequency after sanction; confirm top buyers independently; and use post-disbursement GST monitoring for large unsecured exposures.

In secured SME lending, fraud often moves to collateral or end-use. A machinery loan may finance second-hand equipment billed as new. A loan against property (LAP) may rely on inflated valuation, missing title defect or already-encumbered property. Inventory finance can be supported by stock that is obsolete, borrowed for inspection or pledged elsewhere.

Controls:

  • legal search and title-chain review for LAP;
  • valuation by empanelled valuer with rotation and quality review;
  • CERSAI and ROC charge checks where applicable;
  • direct-to-supplier disbursement for machinery where possible;
  • serial-number and installation verification;
  • insurance endorsement;
  • surprise stock checks for high-value working-capital facilities;
  • independent confirmation from valuers, advocates and other third-party service providers.

RBI’s wilful-defaulter directions also focus on accountability for third parties such as valuers and advocates where they play a vital role in credit sanction or disbursement and are negligent or facilitate wilful default (RBI Treatment of Wilful Defaulters and Large Defaulters Directions, 2024).

SME fraud is frequently enabled by channel pressure. DSA, connector, branch sales, field investigator, borrower and sometimes internal staff collude to create a file that passes policy. Warning signs:

  • one DSA has unusually high approval rate and early delinquency;
  • repeated same addresses, references, valuers or CA firms across files;
  • field investigation photos with similar angles or metadata anomalies;
  • borrower phone switched off after disbursement;
  • first EMI default concentrated in one channel;
  • repeated policy deviations approved by the same manager.

Controls: DSA-level vintage dashboards, clawback on first-payment default and fraud, independent RCU sampling, geo-tagged and timestamped visits, staff rotation, dual reporting for risk control unit (RCU), and whistle-blower route. RBI’s fraud directions require governance, early-warning and root-cause review structures; they should be operational dashboards, not annual policy documents (RBI NBFC Fraud Directions, 2024).

Digital SME lending makes loan stacking easy. A proprietor can apply to multiple NBFCs, fintech platforms and credit-card lenders in a short window. Bureau may not show the newest loans immediately. The borrower appears affordable at application and over-leveraged by first EMI.

Controls:

  • bureau enquiry velocity and recent sanction checks;
  • bank-statement detection of new EMI credits and mandate debits;
  • cooling period after recent unsecured loan;
  • exposure cap by borrower, promoter and group;
  • post-disbursement bureau monitoring;
  • decline or cutback where multiple enquiries have no clear business purpose.

This is not always intentional fraud. Sometimes it is distress borrowing. Credit policy should separate fraud, over-leverage and genuine liquidity shock, but all three require fast response.

Alternate data such as GST, bank statements, UPI settlements, marketplace sales, point-of-sale data, logistics data and mobile metadata can improve access for thin-file SMEs. It can also be gamed. Marketplace sellers can route fake orders, cancel after disbursement, manipulate reviews or shift sales to another account. Payment data can be inflated through friendly swipes or circular UPI. Device and contact data can create privacy and conduct risk if collected without clear consent.

The RBI Digital Lending Directions place responsibility on the regulated entity for digital lending arrangements, including data collection with borrower consent and lending service provider oversight (RBI Digital Lending Directions, 2025). A lender should therefore ask three questions before using alternate data:

  1. Can the borrower manipulate it cheaply?
  2. Can the lender verify it independently?
  3. Is the data necessary and consented for this credit purpose?
Fraud typeEarly signalPrimary controlPost-disbursement control
Fake bank statementPDF metadata, mismatch with analyzerSource-pulled statement, penny-drop account matchFirst 30-day banking review
Circular bankingSame-party in/out transfersRelated-party and narration rulesWatch fund diversion
Inflated GST salesGST above bank collectionsBuyer confirmation, credit-note checksMonthly GST sales and collection tie-back
Collateral overvaluationValue outlier versus localityDual valuation, valuer auditInsurance, periodic revaluation for large exposure
DSA collusionHigh FPD by sourceDSA scorecard, RCU sampleClawback and suspension
Loan stackingHigh recent enquiriesBureau and bank obligation refresh before disbursalBureau monitoring after disbursement

When fraud is suspected, do not quietly classify it as delinquency to avoid reporting discomfort. Preserve documents, freeze further disbursement, separate collection from investigation, follow show-cause and natural-justice requirements where applicable, and escalate under the fraud-risk policy. The difference between a weak loan and a fraudulent loan matters for reporting, staff accountability, third-party accountability, recovery strategy and future model training.