The build order should follow regulatory risk and state ownership, not UI convenience. A lender can survive a plain-looking UI; it cannot safely book loans without consent, KYC, KFS, disbursement controls, LMS ledger, DPD, audit trail and reporting evidence.
The roadmap below assumes a greenfield modular build using the boundaries in module map. Each slice names the exact entities, states, integrations and tests needed before the slice is considered shippable.
| Principle | Roadmap consequence |
|---|
| One source of truth per domain | Build party, KYC, documents, LOS, LMS and collections ownership before partner/co-lending overlays. |
| Regulatory evidence first | audit_event, consent_artifact, kfs_version, maker-checker and immutable document storage ship before high-volume automation. |
| State machines before dashboards | Implement legal transitions for application_state, loan_account.account_state, delinquency states and collections states before operational MIS. |
| Manual plus controlled automation | MVP may use manual upload or vendor console for some rails, but system must still capture normalized evidence, consent and audit. |
| Co-lending after core loan correctness | Partner shares and escrow split depend on correct sanction, disbursement, schedule, receipts, DPD and closure. |
| Item | Specification |
|---|
| Goal | Establish identity, audit, authorization, configuration and document storage foundations. |
| Modules | IAM, audit service, configuration master, document service/DMS, notification skeleton. |
| Entities | party, natural_person, business_entity, address, document_instance, document_requirement, consent_artifact, audit_event, authority_level, authority_rule, approval_request, approval_decision. |
| Actor roles | system_admin, internal_auditor, sales_ops, kyc_maker, kyc_checker, ops_maker, ops_checker, compliance_officer, system_service. |
| Deliverables | RBAC/ABAC guard engine, maker-checker workflow, immutable audit event writer, encrypted document vault, reason-code master, product/geography/branch masters. |
| Exit tests | User cannot self-grant approver role; document correction creates new document_instance; approval checker cannot be same user as maker; audit event reconstructs before/after hash. |
| Rationale | Every later slice needs audit, documents, roles and approvals. Retrofitting these after loan volume creates unfixable evidence gaps. |
| Item | Specification |
|---|
| Goal | Convert leads into compliant applications through lead_created, prescreen_pending, prescreen_passed, kyc_pending and docs_pending. |
| Modules | Channel CRM, LOS workflow, consent and privacy service, KYC and AML service, BRE basic gates. |
| Entities | application, application_party, kyc_profile, beneficial_owner, screening_hit, external_verification, bre_result, workflow_task, queue_assignment. |
| Integrations | PAN validation, bureau soft/hard enquiry where policy permits, CKYC search, sanctions/PEP/adverse media, Udyam verification optional for MVP but schema-ready. |
| Workflow states | lead_created, prescreen_pending, prescreen_passed, kyc_pending, docs_pending, returned_for_rework, on_hold, rejected, withdrawn, expired. |
| Deliverables | Lead intake, dedupe, consent capture, required-party creation by constitution, BO workflow, screening hit resolution, KYC maker-checker, basic document checklist. |
| Exit tests | Legal entity cannot leave kyc_pending with unverified beneficial_owner; revoked consent blocks bureau pull; sanctions true positive blocks kyc_verified; duplicate lead creates dedupe match rather than duplicate application. |
| Rationale | KYC, consent and eligibility are regulatory entry gates. A lender should reject or rework early before collecting full data or spending credit effort. |
| Item | Specification |
|---|
| Goal | Build complete underwriting evidence and decisioning from data_pending through credit_in_review, deviation_pending and approved. |
| Modules | Integration gateway, BRE and decision service, credit workbench, RCU hooks, financial spreading. |
| Entities | external_verification, credit_assessment, bre_result, deviation, financial_spread, cam, approval_request, approval_decision. |
| Integrations | Consumer/commercial bureaus, Account Aggregator, bank statement analyzer, GST analytics, ITR/upload parser, MCA, Udyam. |
| Workflow states | data_pending, credit_in_review, deviation_pending, approved, rejected, returned_for_rework, on_hold. |
| Deliverables | Data requirement matrix by product and constitution, provider retry engine, normalized underwriting variables, CAM builder, rule versioning, scorecard placeholder, DoA resolution. |
| Exit tests | Provider retry exhaustion emits provider_retry_exhausted; non-waivable hard policy fail moves to rejected; deviation approval requires resolved authority; CAM freezes data pack version. |
| Rationale | This slice produces defensible credit decisions. It can initially support one product, but must use versioned rules and evidence from day one. |
| Item | Specification |
|---|
| Goal | Move approved cases to borrower-accepted sanction and executed documentation. |
| Modules | Credit workbench, KFS archive, documentation and execution service, document service, customer portal/DLA. |
| Entities | sanction, sanction_condition, kfs_version, document_checklist, stamp_certificate, signature_event, guarantee, documentation_exception, mandate. |
| Integrations | DigiLocker, eSign, eStamp, eNACH/NACH mandate registration, bank account verification/penny drop. |
| Workflow states | approved, sanctioned, sanction_accepted, documentation_pending, on_hold, returned_for_rework, expired. |
| Deliverables | Sanction template, KFS APR computation, KFS validity/acceptance, execution checklist, CP/CS tracking, eSign/eStamp callbacks, mandate setup. |
| Exit tests | KFS change supersedes old version and requires fresh acceptance; staff cannot accept KFS on borrower behalf; mandate rejection blocks disbursement unless approved exception exists; document hash mismatch invalidates eSign completion. |
| Rationale | RBI KFS and digital disclosure duties are borrower-protection controls. They must be complete before the first production booking. |
| Item | Specification |
|---|
| Goal | Book a loan safely with payment, schedule, GL event and borrower communication. |
| Modules | Disbursement service, LMS core, Finance and GL adapter, notification service. |
| Entities | loan_account, facility, disbursement, schedule_version, repayment_due, loan_transaction, appropriation_allocation, bank_account_verification, payment_instruction, accounting_event, gl_posting. |
| Integrations | NEFT/RTGS/IMPS/UPI/bank host-to-host disbursement rail, payment status enquiry, bank reconciliation feed. |
| Workflow states | disbursement_pending, pending_booking, active_undisbursed, partially_disbursed, active_current, cancelled. |
| Deliverables | Disbursement maker-checker, direct beneficiary rules, LMS account creation, schedule generation, first due date, GL posting, welcome communication, idempotent payment callbacks. |
| Exit tests | Disbursement to LSP account is rejected; duplicate callback does not duplicate loan_transaction; failed payment triggers booking_failed; account cannot be active_current without valid schedule. |
| Rationale | Loan booking is the point of no return. Correct ledger, schedule and fund-flow behavior must precede scale, partner APIs or collections automation. |
| Item | Specification |
|---|
| Goal | Generate demands, post receipts, calculate DPD/SMA/NPA and open collections cases. |
| Modules | LMS core, servicing, payment collection, collections platform intake, finance reconciliation. |
| Entities | repayment_due, loan_transaction, appropriation_allocation, asset_classification, mandate, service_request, delinquency_snapshot, collection_case. |
| Integrations | NACH debit, UPI collect/payment links, bank virtual account, payment gateway status, CIC file skeleton. |
| States | Loan: active_current, active_overdue, frozen, preclosed, matured_pending_closure, closed; delinquency: current, x_bucket, dpd_1_30, dpd_31_60, dpd_61_90, npa_90_plus, closed; collections: not_open, open_unallocated. |
| Deliverables | Demand batch, receipt posting, bounce events, appropriation rules, DPD recomputation, SMA/NPA mapping, pre-due reminders, case creation, statement/NOC requests. |
| Exit tests | Partial payment leaves state in correct DPD band; NPA upgrade only after all arrears clear; collections cannot edit DPD; same-day cash recovery reflection control exists. |
| Rationale | The lender’s risk, accounting, CIC reporting and collections all depend on objective LMS-driven delinquency. |
| Item | Specification |
|---|
| Goal | Operate tele/field collections, PTPs, escalations, settlements and legal readiness without changing LMS truth. |
| Modules | Collections platform, agency portal, legal recovery workflow, approval service. |
| Entities | collection_case, case_allocation, contact_attempt, ptp, settlement_proposal, workflow_task, approval_request, approval_decision, loan_transaction for waiver/write-off posting. |
| States | open_unallocated, allocated_tele, allocated_field, ptp_active, ptp_broken, escalated_hard_bucket, legal_review, settlement_review, restructure_review, repossession_or_enforcement, terminal closure states. |
| Integrations | Payment links, call/SMS/WhatsApp logs, field visit evidence, legal notice document generation, NeSL default evidence optional. |
| Deliverables | Strategy allocation, agent scope, borrower recovery-agent notification, PTP tracking, field visit evidence, settlement DoA, write-off maker-checker, conduct audit. |
| Exit tests | Recovery agent assignment notification precedes first contact; broken PTP escalates; OTS approval cannot be done by negotiator alone; settlement funds must be posted by LMS before closed_settled. |
| Rationale | Collections adds conduct risk. Build it after DPD truth exists so agents cannot manipulate classification. |
| Item | Specification |
|---|
| Goal | Produce KFS archive, CIC submissions, DLA inventory, regulatory return runs and consent/audit evidence. |
| Modules | Compliance, audit and reporting; Finance and GL adapter; consent service. |
| Entities | audit_event, regulatory_report_run, cic_submission, kfs_version, complaint, access_review, consent_artifact. |
| Integrations | CIC reporting exchange, RBI CIMS return metadata, CKYC upload/update, CERSAI/NeSL where enabled. |
| Deliverables | Reporting calendar, file generation, reject correction, DQI tracking, complaint SLA, access review, evidence pack export. |
| Exit tests | CIC rejected record creates correction task; DLA cannot go live without CIMS inventory data; audit export is read-only; access review identifies dormant and conflicting roles. |
| Rationale | Reporting can be built after core events exist, but before high volume. The first audited period should not require manual reconstruction. |
| Item | Specification |
|---|
| Goal | Support LAP, machinery, stock/book-debt security and charge perfection. |
| Modules | Collateral and security service, legal/valuation vendor portals, documentation, LMS servicing. |
| Entities | collateral_asset, collateral_owner, valuation_report, legal_opinion, security_charge, cersai_filing, roc_charge_filing, insurance_policy, executed_document, vault_packet. |
| Integrations | CERSAI search/filing/satisfaction, MCA charge lookup, eStamp/eSign, insurance verification, valuer/legal vendor upload. |
| States | Application: credit_in_review, documentation_pending, disbursement_pending; collateral: proposed, documents_pending, under_legal_review, under_valuation, approved, approved_with_conditions, charged, released; loan closure states. |
| Deliverables | Collateral checklist, title/valuation workflow, charge creation/perfection, insurance tracking, original document vault, secured closure and release workflow. |
| Exit tests | Secured loan cannot disburse without security_charge.perfection_status acceptable under policy; CERSAI rejection creates legal/ops task; collateral release requires no-dues, legal and finance checks. |
| Rationale | Secured products add legal, valuation and registry dependencies. They should not block unsecured MVP but must be first-class before LAP launch. |
| Item | Specification |
|---|
| Goal | Add partner APIs, anchor programs, co-lending shares, escrow split, DLG ledger and partner reconciliation. |
| Modules | Partner API gateway, co-lending and partner ledger, Finance and GL adapter, compliance reporting. |
| Entities | partner_profile, partner_program, api_client, partner_application_ref, co_lending_arrangement, partner_share, escrow_movement, partner_ledger, dlg_set, dlg_portfolio_loan, dlg_invocation, partner_status_event, payout_ledger. |
| Integrations | Partner APIs/webhooks, escrow bank statement, partner statement import, CIC per-share reporting, DLG provider acknowledgement. |
| States | Application channel_type=co_lending, lsp, anchor; loan states from booking through closure; collections partner sync events. |
| Deliverables | Partner onboarding, API auth/scopes, dual-decisioning, blended KFS, partner share booking within 15 calendar days, escrow reconciliation, DLG cap checks, payout and clawback. |
| Exit tests | 95:5 CLA rejected; partner share missing after 15 days creates break; partner cannot see raw CAM/bureau data; DLG invocation cannot exceed 5 percent cap; SMA/NPA event delivered by next working day. |
| Rationale | Co-lending depends on correct core loan, KFS, payment, DPD, GL and reporting. Building it earlier creates duplicate ledgers and reconciliation debt. |
| Item | Specification |
|---|
| Goal | Add post-booking risk monitoring, early-warning signals, covenant tracking, renewals and portfolio analytics. |
| Modules | Monitoring/EWS, BRE monitoring, risk analytics, servicing, credit workbench. |
| Entities | sanction_condition, credit_assessment, bre_result, external_verification, service_request, schedule_version, asset_classification, monitoring trigger records. |
| Integrations | AA periodic consent, GST monitoring, bureau refresh where consent/policy permit, stock statement upload, insurance renewal. |
| Deliverables | Covenant calendar, stock statement tracker, GST/banking drop alerts, renewal/top-up workflow, risk-grade migration, portfolio caps. |
| Exit tests | Monitoring fetch blocked without active consent; covenant breach creates task and may freeze facility; renewal starts fresh application or approved renewal workflow, not silent limit extension. |
| Rationale | Monitoring improves portfolio quality but requires live loan data and consent controls already present. |
| Dimension | MVP choice | Reason |
|---|
| Product | Unsecured business loan or small ticket machinery/term loan without collateral charge automation | Exercises KYC, bureau, bank/GST/ITR data, KFS, sanction, eSign, mandate, disbursement, LMS, DPD and collections without CERSAI/ROC complexity. |
| Channel | Branch/digital direct plus controlled DSA | Tests customer, sales and DSA permissions while avoiding partner API/co-lending complexity. |
| Borrower constitutions | Proprietorship, partnership, LLP, private limited | Covers natural person, business entity, BO, promoter/director/partner and guarantor paths. |
| Integrations | PAN, bureau, CKYC, sanctions, bank statement/AA, GST, eSign/eStamp, eNACH, payment rail | Covers core underwriting and booking evidence. ITR, Udyam, DigiLocker can be added if vendor/onboarding is ready. |
| Collections | Tele, PTP, field allocation, settlement proposal | Enough to prove DPD-driven operations and conduct controls. |
| Gate | Must pass before production |
|---|
| Regulatory gate | KYC, consent, KFS, fund-flow, audit, DPD/NPA and grievance controls pass compliance test cases. |
| Ledger gate | Disbursement, schedule, receipt, reversal, waiver, GL and bank reconciliation are idempotent and balanced. |
| Security gate | RBAC/ABAC tests, maker-checker, encryption, secrets, log redaction, partner scope and vulnerability checks pass. |
| Data gate | Mandatory fields for party, application, loan_account, repayment_due, loan_transaction, asset_classification, kfs_version and audit_event are complete. |
| Reporting gate | CIC extract dry run, KFS evidence pack, DLA inventory, access review and audit export work without manual spreadsheet patching. |
| Operations gate | Queue SLAs, rework, holds, escalations, failure retries and support runbooks are tested. |
| Order | Slice | Why now |
|---|
| 0 | Platform and control spine | Shared audit, IAM, approvals and document vault are prerequisites. |
| 1 | Lead, consent, prescreen and KYC | Establish regulated borrower onboarding and early rejection. |
| 2 | Data pack, BRE and credit | Create defensible underwriting and approval evidence. |
| 3 | Sanction, KFS and documentation | Meet borrower disclosure and execution requirements. |
| 4 | Disbursement and LMS booking | Create account, schedule, ledger and direct fund flow. |
| 5 | Servicing and delinquency | Generate dues, receipts, DPD, SMA/NPA and case triggers. |
| 6 | Collections operations | Operational recovery using LMS truth. |
| 7 | Compliance reporting | Generate reports from source events before scale. |
| 8 | Secured SME | Add collateral, legal, valuation and charge perfection. |
| 9 | Partner/co-lending | Add partner shares, escrow, DLG and reconciliation after core loan correctness. |
| 10 | Monitoring/EWS | Add portfolio defence and renewal intelligence. |