Part 10 — System Blueprint
Actors Permissions
Access control in SME lending is a credit control, not an admin screen. The model below combines role-based access control (RBAC), attribute-based conditions, maker-checker and Delegation of Authority (DoA). It assumes outsourced DSAs, LSPs, field agents, legal vendors and valuers can access only narrow portals. The regulated entity remains responsible for outsourced acts under RBI’s Digital Lending Directions and recovery-agent conduct instructions, so vendor permissions must be auditable and revocable.
Actor Catalogue
Section titled “Actor Catalogue”| Actor code | Human role | Employment boundary | Typical scope | Never allowed |
|---|---|---|---|---|
borrower_user | Borrower/proprietor/promoter/authorised signatory | External customer | Own applications, consents, KFS, documents, service requests, payment links | Internal scorecards, bureau variables, CAM, deviation notes |
guarantor_user | Guarantor/security provider | External customer | Own KYC, guarantee documents, notices, NOC status after release | Borrower financial data beyond guarantee documents |
dsa_user | DSA/connector | External channel partner | Submit leads, upload documents, view coarse status, view eligible payout | Bureau report, CAM, RCU findings, sanction authority, collections notes |
partner_api_client | LSP/anchor/co-lender system | External system | API-scoped application, status, repayment, partner-share exchange | Direct DB access, unapproved personal data, hidden offer manipulation |
sales_rm | Relationship manager/sales officer | First line | Leads, application capture, document collection, customer follow-up | Credit approval, KYC approval, DPD edit, charge waiver approval |
sales_manager | ASM/RSM/DSA manager | First line | Source governance, source-code exceptions, DSA payout holds, funnel oversight | Final credit approval unless separately assigned credit authority |
sales_ops | CRM/login operations | First line/control ops | Lead dedupe, login completeness, checklist generation, source lock | KYC override, credit deviation approval |
kyc_maker | KYC processing officer | Operations/control | CDD data entry, CKYC retrieval, document checks | Final KYC approval of own work |
kyc_checker | KYC verifier/AML ops | Control | KYC approval/rejection, BO checks, periodic KYC closure | Credit approval, disbursement approval |
aml_compliance | AML/compliance officer | Second line | Sanctions/PEP/adverse media resolution, high-risk KYC approval | Booking payment or waiving dues |
credit_analyst | Analyst/credit processing officer | First line credit | CAM, financial spreading, ratios, recommendation | Final approval above assigned authority; disbursement release |
credit_manager | Branch/area/regional credit manager | First line credit with DoA | Approval within DoA, deviations within level, conditions | Own-source application approval where conflict rule applies |
credit_committee_member | Committee approver | Committee | Vote/comment/approve cases routed to committee | Editing application evidence after vote |
national_credit_head | National credit authority | Senior management | High-value and high-severity approvals, DoA exceptions | Operations maker action on approved case |
policy_risk | Credit policy/portfolio risk | Second line | Policy rules, BRE versions, monitoring triggers, portfolio caps | Individual loan disbursement approval |
rcu_officer | Risk/fraud control | Second line | FI/RCU case review, fraud flags, negative clearance | Credit approval of file cleared by self |
legal_user | Legal officer | Control/vendor manager | Legal opinion review, document format, litigation and charge release checks | Valuation value edit, cash receipt posting |
valuer_vendor | Technical valuer | External vendor | Assigned collateral inspection and valuation report upload | Application data unrelated to assigned asset |
legal_vendor | Empanelled advocate | External vendor | Assigned title search/legal report upload | Credit decision, customer contact outside assignment |
ops_maker | Loan operations maker | Operations | CP checklist, documentation verification, disbursement request preparation | Check own disbursement request |
ops_checker | Loan operations checker | Operations | Documentation approval, CP clearance, booking approval within ops authority | Credit approval, own maker action approval |
treasury_finance | Treasury/finance user | Control | Payment funding, GL posting, reconciliation, DSA payout, provisions | Change sanction terms or KYC status |
servicing_agent | Customer service/servicing officer | Operations | Statements, SRs, mandate change intake, NOC workflow | Waive charges beyond permitted service-error grid |
collections_agent | Tele/field collector | Collections/vendor | Assigned case contact, PTP, visit disposition, payment link | Edit DPD, negotiate waiver without approval, access non-assigned cases |
collections_manager | Bucket/agency manager | Collections | Allocation, escalation, settlement proposal, agency governance | Approve own negotiated settlement above DoA |
legal_recovery | Recovery legal manager | Collections/legal | Notices, litigation, enforcement, repossession, security sale | Change LMS dues |
compliance_officer | Compliance/grievance | Second line | Regulatory holds, complaint review, policy attestations, audit exports | Book or reverse loan transactions |
internal_auditor | Internal audit/IS audit | Third line | Read-only audit, evidence export, access review | Maker/checker/approval in live workflow |
system_admin | IAM/platform admin | Technology | User provisioning, role assignment, secrets/config under break-glass | Business approval or customer data export without ticket |
system_service | Batch/integration service | Non-human | Scheduled events, API callbacks, DPD computation, notifications | Human-only approvals |
Capability Matrix
Section titled “Capability Matrix”Legend: C create, R read, U update, A approve/check, X execute/post, V vendor-scoped, O own-record only, N no access.
| Capability | Borrower | DSA | Sales RM | Sales mgr | KYC maker | KYC checker | AML/compliance | Credit analyst | Credit approver | RCU | Legal | Ops maker | Ops checker | Finance | Servicing | Collections | Audit |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Lead capture | O | C/O | C/U | R/A | R | R | R | R | R | R | R | R | R | R | N | N | R |
| Source-code lock/change | N | N | C | A | N | N | R | R | R | R | N | R | R | R | N | N | R |
| Consent capture | C/O | C/O | C | R | R | R | R | R | R | R | N | R | R | N | R | R | R |
| Application edit before lock | O | C/O | C/U | R | R | R | R | R | R | R | R | U | R | N | R | N | R |
| KYC data entry | C/O | N | C | R | C/U | R | R | R | R | R | N | R | R | N | R | N | R |
| KYC approval/rejection | N | N | N | N | N | A | A high-risk | N | N | R | N | N | R | N | N | N | R |
| BO waiver | N | N | N | N | N | Request | A | N | R | R | N | N | R | N | N | N | R |
| Document upload | C/O | C/O | C | R | C | R | R | R | R | R | C/V | C/U | R | N | C | R | R |
| Document verification | N | N | N | N | A KYC docs | A KYC docs | R | R | R | R | A legal docs | U | A | N | U service docs | R | R |
| Bureau/data pull request | Consent only | N | Request | R | N | R | R | C | R | R | N | N | R | N | N | N | R |
| View bureau report | N | N | N | N | N | R limited | R limited | R | R | R fraud vars | N | N | N | N | N | N | R masked |
| BRE rule edit | N | N | N | N | N | N | C policy attest | R | R | R | N | N | N | N | N | N | R |
| BRE rule publish | N | N | N | N | N | N | A compliance | N | N | C/U policy | N | N | N | N | N | N | R |
| CAM prepare | N | N | N | N | N | N | R | C/U | R | R | R | N | N | N | N | N | R |
| Credit approve | N | N | N | N | N | N | R | Recommend | A within DoA | R | R | N | N | N | N | N | R |
| Deviation approve | N | N | N | N | N | N | A regulatory only | Request | A within DoA | A fraud clearance | A legal | N | N | N | N | N | R |
| Sanction issue | R/O | R coarse | R | R | N | R | R | C draft | A | R | R | R | A ops pack | R | R | N | R |
| KFS accept | C/O | N | Assist | R | N | N | R | R | R | N | N | R | R | N | R | N | R |
| Documentation execution | C/O | N | Assist | R | N | R | R | R | R | R | C/A legal | C/U | A | N | R | N | R |
| CP clearance | N | N | Request | R | R | R | R | R | R | R | A legal CP | C/U | A | R | N | N | R |
| Disbursement request | N | N | N | N | N | N | R | N | R | N | R | C | A | R/X funding | N | N | R |
| Payment posting/reversal | N | N | N | N | N | N | R | N | R | N | N | Request | A ops | X/A finance | N | N | R |
| Loan schedule view | O | N | R | R | N | N | R | R | R | N | R | R | R | R | R | R assigned | R |
| DPD/SMA/NPA edit | N | N | N | N | N | N | R | N | R | N | N | N | N | N | N | N | R |
| DPD/SMA/NPA recompute | N | N | N | N | N | N | R | N | R | N | N | N | N | R | N | R | R |
| Service request action | C/O | N | C | R | R | R | R complaints | R | R | N | R legal SRs | U | A | R | C/U | R | R |
| Mandate/bank change | C/O | N | Assist | R | N | N | R | N | N | N | N | C | A | R | C | N | R |
| Collections contact | N | N | R relationship | R | N | N | R complaints | N | R | R fraud | R | N | N | R | R | C/U assigned | R |
| PTP record | N | N | N | N | N | N | R | N | N | N | N | N | N | R | N | C/U assigned | R |
| Settlement proposal | N | N | N | N | N | N | R | R | R | N | R | N | N | R | N | C | R |
| Settlement/waiver approval | N | N | N | N | N | N | A conduct | R | A credit | N | A legal | N | N | A finance | N | A within DoA | R |
| Collateral release | R/O | N | Request | R | N | N | R | R | A credit if condition | N | A legal | C | A | A finance | C | R | R |
| User/access administration | N | N | N | N | N | N | Request | N | N | N | N | N | N | N | N | N | R |
| Audit export | N | N | N | N | N | N | R | N | N | N | N | N | N | R | N | N | C/R |
Maker-Checker Rules
Section titled “Maker-Checker Rules”| Action | Maker role | Checker/approver role | Separation rule | Mandatory evidence | Regulatory/control reason |
|---|---|---|---|---|---|
| Source-code change after login | Sales RM or sales ops | Sales manager | Checker cannot be same user or subordinate DSA | Old source, new source, reason, customer consent timestamp | Prevents payout disputes and channel manipulation. |
| KYC approval | KYC maker | KYC checker | Checker cannot verify own entry | OVD/entity docs, BO records, screening status | RBI KYC requires CDD, BO and ongoing due diligence evidence. |
| High-risk KYC/PEP/sanctions clearance | KYC checker | AML/compliance officer | AML officer independent of sales and credit | Screening report, false-positive rationale, enhanced due diligence note | AML/CFT control under RBI KYC Master Direction. |
| Document waiver | Sales/ops requester | Ops checker plus function owner | Waiver authority must differ from requester | Requirement, reason, alternate evidence, expiry | Prevents silent missing documents. |
| Credit deviation | Credit analyst | Credit approver at resolved DoA level | Approver cannot be application maker; sales cannot approve credit | Rule breached, mitigant, severity, DoA level | Board-approved credit policy and auditability. |
| RCU negative clearance | RCU officer | RCU manager or fraud head | Credit/sales cannot close RCU negative | FI/RCU report, fraud signal, closure rationale | Fraud-control independence. |
| Sanction approval | Credit analyst | Credit approver/committee | Recommender cannot be sole approver above self-approval band | CAM, rule results, deviations, conditions | Credit approval trail. |
| KFS generation and acceptance | System/sales assist | Borrower or authorised signatory; ops verifies where assisted | Staff cannot accept on borrower behalf | KFS version, APR inputs, OTP/e-sign/click evidence | RBI KFS and Digital Lending disclosure duties. |
| CP clearance | Ops maker | Ops checker/function owner | Maker cannot clear own CP | Condition evidence and waiver if applicable | Disbursement control. |
| Disbursement posting | Ops maker | Ops checker plus finance release | Checker cannot be maker; finance funds only approved instruction | Verified beneficiary, mandate, CP status, payment instruction | Digital lending fund-flow and wrong-beneficiary control. |
| Bank account change after booking | Servicing/ops maker | Ops checker; fraud/compliance for high-risk | Maker cannot check; borrower verification required | Request, penny-drop, cancelled cheque/statement, OTP | Fraud and repayment diversion control. |
| Manual DPD/classification override | LMS support/risk maker | Risk head plus finance/compliance checker | No branch/sales override | System computation, correction reason, before/after values | IRAC and CIC reporting impact. |
| Charge waiver | Servicing/collections maker | Authority by amount and reason | Negotiator cannot approve beyond small service-error grid | Dues breakup, reason, customer communication | Penal charges/KFS conduct control. |
| OTS/settlement | Collections maker | DoA authority plus finance/legal where required | Negotiator cannot approve own OTS | Recovery estimate, waiver split, source of funds, OTS letter | Governance over compromise settlements. |
| Write-off | Collections/finance maker | Finance head/credit committee/board per DoA | Collections collector cannot approve | Provision, recovery history, legal status, approval note | Accounting and audit control. |
| Collateral release | Servicing/ops maker | Legal plus ops checker plus finance no-dues | Release checker cannot be same maker | No-dues, CERSAI/ROC satisfaction task, vault packet | Security release control. |
| Role assignment | System admin | IAM approver or role owner | Admin cannot self-grant business approver roles | Ticket, manager approval, expiry | Privileged access control. |
Delegation Of Authority Model
Section titled “Delegation Of Authority Model”DoA must be data, not a PDF. The approval service resolves authority from amount, product, collateral, risk grade, unsecured exposure, deviation severity, source channel, group exposure, restructuring/settlement haircut and conflict flags.
authority_level
Section titled “authority_level”| Field | Type | Constraints | Nullable | References |
|---|---|---|---|---|
authority_level_id | uuid | Primary key | No | None |
level_code | text | Unique: L1_BRANCH_CREDIT, L2_REGIONAL_CREDIT, L3_ZONAL_CREDIT, L4_NATIONAL_CREDIT, L5_CREDIT_COMMITTEE, L6_BOARD_RISK | No | None |
level_rank | int | Higher rank means higher authority | No | None |
description | text | Human-readable | No | None |
active_flag | boolean | Default true | No | None |
authority_rule
Section titled “authority_rule”| Field | Type | Constraints | Nullable | References |
|---|---|---|---|---|
authority_rule_id | uuid | Primary key | No | None |
rule_version | int | Immutable version | No | None |
business_line | enum | unsecured_bl, lap, machinery, working_capital, invoice_finance, collections, servicing, co_lending | No | None |
action_type | enum | credit_approval, pricing_deviation, policy_deviation, document_waiver, disbursement_exception, settlement, writeoff, restructure, collateral_release, partner_onboarding | No | None |
min_amount | numeric(18,2) | Inclusive lower bound | No | None |
max_amount | numeric(18,2) | Inclusive upper bound | Yes | None |
max_unsecured_amount | numeric(18,2) | Applies to unsecured exposure | Yes | None |
risk_grade_set | text[] | Applicable grades; empty means all | No | None |
collateral_type_set | text[] | Applicable collateral types; empty means all | No | None |
max_ltv_percent | numeric(9,6) | Null if not applicable | Yes | None |
deviation_severity | enum | none, low, medium, high, critical | No | None |
required_authority_level_id | uuid | Output level | No | authority_level.authority_level_id |
requires_committee_flag | boolean | True when quorum/voting is mandatory | No | None |
effective_from | date | Required | No | None |
effective_to | date | Null for active | Yes | None |
approval_request
Section titled “approval_request”| Field | Type | Constraints | Nullable | References |
|---|---|---|---|---|
approval_request_id | uuid | Primary key | No | None |
subject_type | enum | application, sanction, deviation, disbursement, service_request, settlement, writeoff, restructure, collateral_release, partner | No | None |
subject_id | uuid | Id of subject record | No | None |
action_type | enum | Same as authority_rule.action_type plus kyc_high_risk_clearance, access_grant | No | None |
requested_by | uuid | Maker | No | user.user_id |
required_authority_level_id | uuid | Resolved by approval service | No | authority_level.authority_level_id |
amount_basis | numeric(18,2) | Exposure, waiver or transaction amount | Yes | None |
severity_basis | enum | none, low, medium, high, critical | No | None |
status | enum | draft, submitted, approved, rejected, returned, expired, cancelled | No | None |
submitted_at | timestamptz | Required when submitted | Yes | None |
decision_at | timestamptz | Required when terminal | Yes | None |
approval_decision
Section titled “approval_decision”| Field | Type | Constraints | Nullable | References |
|---|---|---|---|---|
approval_decision_id | uuid | Primary key | No | None |
approval_request_id | uuid | Parent request | No | approval_request.approval_request_id |
approver_user_id | uuid | Approver | No | user.user_id |
approver_authority_level_id | uuid | Approver level at decision time | No | authority_level.authority_level_id |
decision | enum | approve, reject, return, abstain | No | None |
decision_note | text | Required except abstain | Yes | None |
decision_at | timestamptz | Required | No | None |
conflict_checked_flag | boolean | Must be true | No | None |
Sample DoA Resolution Tables
Section titled “Sample DoA Resolution Tables”Credit Approval
Section titled “Credit Approval”| Condition | Required level | Additional rule |
|---|---|---|
| Unsecured business loan up to ₹10 lakh, risk grade A/B, no deviation | L1_BRANCH_CREDIT | Single approver allowed if not sales-linked. |
| Unsecured ₹10-50 lakh or risk grade C | L2_REGIONAL_CREDIT | RCU status must be clear. |
| Unsecured above ₹50 lakh or any high-severity policy deviation | L4_NATIONAL_CREDIT | Committee may be required by policy. |
| LAP or secured term loan up to ₹1 crore, LTV within policy, clean legal/valuation | L2_REGIONAL_CREDIT | Legal and valuation must be accepted. |
| LAP ₹1-5 crore or LTV/pricing deviation | L3_ZONAL_CREDIT | Legal exception routes to legal approver too. |
| Exposure group above ₹5 crore, related-party exposure, new product exception | L5_CREDIT_COMMITTEE | Committee quorum and minutes mandatory. |
| Board policy breach, portfolio cap breach, unusually large exposure | L6_BOARD_RISK | Board/risk committee record required. |
Settlement, Waiver And Write-Off
Section titled “Settlement, Waiver And Write-Off”| Condition | Required level | Required co-approval |
|---|---|---|
| Service-error charge waiver up to ₹5,000 | Servicing checker | Compliance sample review. |
| Penal/bounce/legal charge waiver up to ₹50,000 | Collections manager | Finance if income reversal is needed. |
| OTS waiver up to ₹2 lakh or up to 10 percent of dues | Regional collections head | Finance sign-off. |
| OTS waiver ₹2-25 lakh or 10-25 percent of dues | Zonal collections/credit committee | Legal and finance sign-off. |
| OTS waiver above ₹25 lakh or above 25 percent of dues | Stressed asset/credit committee | Legal, finance and compliance visibility. |
| Technical write-off | Finance head plus credit/recovery committee | Board reporting as policy requires. |
| Collateral release after settlement | Legal plus ops checker plus finance no-dues | Partner approval if co-lent. |
Attribute-Based Guards
Section titled “Attribute-Based Guards”| Guard | Expression | Applies to |
|---|---|---|
| Own work cannot be checked | maker_user_id != checker_user_id | All maker-checker approvals |
| Sales conflict | approver.function != sales unless role has separate credit authority and did not source file | Credit approvals |
| Branch/geography limit | approver.allowed_branch_codes contains application.assigned_branch_code or national scope | Credit, ops, collections |
| Amount authority | approval.amount_basis <= authority_rule.max_amount and above lower bound | Credit, settlement, write-off, disbursement exception |
| Severity authority | approver.level_rank >= required_authority.level_rank | Deviations and exceptions |
| Vendor assignment scope | vendor_user.assigned_case_ids contains subject_id | Legal vendor, valuer, field agency |
| Partner data scope | api_client.partner_id == application.source_partner_id and endpoint scope includes action | Partner APIs |
| Regulatory hold block | No approval if screening_hit.true_positive_open or compliance_hold.active unless action is hold resolution | KYC, disbursement, booking |
| Co-lending partner consent | Required when action changes borrower economics, settlement, restructure, DPD correction or collateral release on CLA account | Co-lending accounts |
Audit And Access Review
Section titled “Audit And Access Review”| Control | Requirement |
|---|---|
| Immutable audit events | Every approval, rejection, waiver, override, DPD correction, settlement, write-off, bank-account change and role grant writes an immutable audit_event. |
| Privileged access | system_admin cannot grant business approval roles to self; break-glass access expires automatically and is reviewed. |
| Vendor expiry | DSA, valuer, legal vendor, field agency and LSP users require contract, geography, product scope and expiry date. |
| Data masking | Borrower PAN, Aadhaar last four, bank account, bureau details and phone/email are masked by default outside need-to-know roles. |
| Quarterly review | Active users, dormant users, high-risk roles, maker-checker conflicts and vendor accounts are reviewed at least quarterly. |
| Audit read-only | Internal audit receives read-only evidence export. Audit users cannot operate workflow actions. |
Sources
Section titled “Sources”- RBI, Reserve Bank of India (Digital Lending) Directions, 2025
- RBI, Outsourcing of Financial Services - Responsibilities of regulated entities employing Recovery Agents, August 12, 2022
- RBI, Master Direction - Know Your Customer (KYC) Direction, 2016
- RBI, Reserve Bank of India (Co-Lending Arrangements) Directions, 2025
- RBI, Compliance Function and Role of Chief Compliance Officer - NBFCs, April 11, 2022