Skip to content

Part 10 — System Blueprint

Build Roadmap

The build order should follow regulatory risk and state ownership, not UI convenience. A lender can survive a plain-looking UI; it cannot safely book loans without consent, KYC, KFS, disbursement controls, LMS ledger, DPD, audit trail and reporting evidence.

The roadmap below assumes a greenfield modular build using the boundaries in module map. Each slice names the exact entities, states, integrations and tests needed before the slice is considered shippable.

PrincipleRoadmap consequence
One source of truth per domainBuild party, KYC, documents, LOS, LMS and collections ownership before partner/co-lending overlays.
Regulatory evidence firstaudit_event, consent_artifact, kfs_version, maker-checker and immutable document storage ship before high-volume automation.
State machines before dashboardsImplement legal transitions for application_state, loan_account.account_state, delinquency states and collections states before operational MIS.
Manual plus controlled automationMVP may use manual upload or vendor console for some rails, but system must still capture normalized evidence, consent and audit.
Co-lending after core loan correctnessPartner shares and escrow split depend on correct sanction, disbursement, schedule, receipts, DPD and closure.
ItemSpecification
GoalEstablish identity, audit, authorization, configuration and document storage foundations.
ModulesIAM, audit service, configuration master, document service/DMS, notification skeleton.
Entitiesparty, natural_person, business_entity, address, document_instance, document_requirement, consent_artifact, audit_event, authority_level, authority_rule, approval_request, approval_decision.
Actor rolessystem_admin, internal_auditor, sales_ops, kyc_maker, kyc_checker, ops_maker, ops_checker, compliance_officer, system_service.
DeliverablesRBAC/ABAC guard engine, maker-checker workflow, immutable audit event writer, encrypted document vault, reason-code master, product/geography/branch masters.
Exit testsUser cannot self-grant approver role; document correction creates new document_instance; approval checker cannot be same user as maker; audit event reconstructs before/after hash.
RationaleEvery later slice needs audit, documents, roles and approvals. Retrofitting these after loan volume creates unfixable evidence gaps.
ItemSpecification
GoalConvert leads into compliant applications through lead_created, prescreen_pending, prescreen_passed, kyc_pending and docs_pending.
ModulesChannel CRM, LOS workflow, consent and privacy service, KYC and AML service, BRE basic gates.
Entitiesapplication, application_party, kyc_profile, beneficial_owner, screening_hit, external_verification, bre_result, workflow_task, queue_assignment.
IntegrationsPAN validation, bureau soft/hard enquiry where policy permits, CKYC search, sanctions/PEP/adverse media, Udyam verification optional for MVP but schema-ready.
Workflow stateslead_created, prescreen_pending, prescreen_passed, kyc_pending, docs_pending, returned_for_rework, on_hold, rejected, withdrawn, expired.
DeliverablesLead intake, dedupe, consent capture, required-party creation by constitution, BO workflow, screening hit resolution, KYC maker-checker, basic document checklist.
Exit testsLegal entity cannot leave kyc_pending with unverified beneficial_owner; revoked consent blocks bureau pull; sanctions true positive blocks kyc_verified; duplicate lead creates dedupe match rather than duplicate application.
RationaleKYC, consent and eligibility are regulatory entry gates. A lender should reject or rework early before collecting full data or spending credit effort.

Slice 2: Data Pack, BRE And Credit Workbench

Section titled “Slice 2: Data Pack, BRE And Credit Workbench”
ItemSpecification
GoalBuild complete underwriting evidence and decisioning from data_pending through credit_in_review, deviation_pending and approved.
ModulesIntegration gateway, BRE and decision service, credit workbench, RCU hooks, financial spreading.
Entitiesexternal_verification, credit_assessment, bre_result, deviation, financial_spread, cam, approval_request, approval_decision.
IntegrationsConsumer/commercial bureaus, Account Aggregator, bank statement analyzer, GST analytics, ITR/upload parser, MCA, Udyam.
Workflow statesdata_pending, credit_in_review, deviation_pending, approved, rejected, returned_for_rework, on_hold.
DeliverablesData requirement matrix by product and constitution, provider retry engine, normalized underwriting variables, CAM builder, rule versioning, scorecard placeholder, DoA resolution.
Exit testsProvider retry exhaustion emits provider_retry_exhausted; non-waivable hard policy fail moves to rejected; deviation approval requires resolved authority; CAM freezes data pack version.
RationaleThis slice produces defensible credit decisions. It can initially support one product, but must use versioned rules and evidence from day one.

Slice 3: Sanction, KFS, Documentation And CPs

Section titled “Slice 3: Sanction, KFS, Documentation And CPs”
ItemSpecification
GoalMove approved cases to borrower-accepted sanction and executed documentation.
ModulesCredit workbench, KFS archive, documentation and execution service, document service, customer portal/DLA.
Entitiessanction, sanction_condition, kfs_version, document_checklist, stamp_certificate, signature_event, guarantee, documentation_exception, mandate.
IntegrationsDigiLocker, eSign, eStamp, eNACH/NACH mandate registration, bank account verification/penny drop.
Workflow statesapproved, sanctioned, sanction_accepted, documentation_pending, on_hold, returned_for_rework, expired.
DeliverablesSanction template, KFS APR computation, KFS validity/acceptance, execution checklist, CP/CS tracking, eSign/eStamp callbacks, mandate setup.
Exit testsKFS change supersedes old version and requires fresh acceptance; staff cannot accept KFS on borrower behalf; mandate rejection blocks disbursement unless approved exception exists; document hash mismatch invalidates eSign completion.
RationaleRBI KFS and digital disclosure duties are borrower-protection controls. They must be complete before the first production booking.
ItemSpecification
GoalBook a loan safely with payment, schedule, GL event and borrower communication.
ModulesDisbursement service, LMS core, Finance and GL adapter, notification service.
Entitiesloan_account, facility, disbursement, schedule_version, repayment_due, loan_transaction, appropriation_allocation, bank_account_verification, payment_instruction, accounting_event, gl_posting.
IntegrationsNEFT/RTGS/IMPS/UPI/bank host-to-host disbursement rail, payment status enquiry, bank reconciliation feed.
Workflow statesdisbursement_pending, pending_booking, active_undisbursed, partially_disbursed, active_current, cancelled.
DeliverablesDisbursement maker-checker, direct beneficiary rules, LMS account creation, schedule generation, first due date, GL posting, welcome communication, idempotent payment callbacks.
Exit testsDisbursement to LSP account is rejected; duplicate callback does not duplicate loan_transaction; failed payment triggers booking_failed; account cannot be active_current without valid schedule.
RationaleLoan booking is the point of no return. Correct ledger, schedule and fund-flow behavior must precede scale, partner APIs or collections automation.

Slice 5: Servicing, Dues, Receipts And Delinquency

Section titled “Slice 5: Servicing, Dues, Receipts And Delinquency”
ItemSpecification
GoalGenerate demands, post receipts, calculate DPD/SMA/NPA and open collections cases.
ModulesLMS core, servicing, payment collection, collections platform intake, finance reconciliation.
Entitiesrepayment_due, loan_transaction, appropriation_allocation, asset_classification, mandate, service_request, delinquency_snapshot, collection_case.
IntegrationsNACH debit, UPI collect/payment links, bank virtual account, payment gateway status, CIC file skeleton.
StatesLoan: active_current, active_overdue, frozen, preclosed, matured_pending_closure, closed; delinquency: current, x_bucket, dpd_1_30, dpd_31_60, dpd_61_90, npa_90_plus, closed; collections: not_open, open_unallocated.
DeliverablesDemand batch, receipt posting, bounce events, appropriation rules, DPD recomputation, SMA/NPA mapping, pre-due reminders, case creation, statement/NOC requests.
Exit testsPartial payment leaves state in correct DPD band; NPA upgrade only after all arrears clear; collections cannot edit DPD; same-day cash recovery reflection control exists.
RationaleThe lender’s risk, accounting, CIC reporting and collections all depend on objective LMS-driven delinquency.
ItemSpecification
GoalOperate tele/field collections, PTPs, escalations, settlements and legal readiness without changing LMS truth.
ModulesCollections platform, agency portal, legal recovery workflow, approval service.
Entitiescollection_case, case_allocation, contact_attempt, ptp, settlement_proposal, workflow_task, approval_request, approval_decision, loan_transaction for waiver/write-off posting.
Statesopen_unallocated, allocated_tele, allocated_field, ptp_active, ptp_broken, escalated_hard_bucket, legal_review, settlement_review, restructure_review, repossession_or_enforcement, terminal closure states.
IntegrationsPayment links, call/SMS/WhatsApp logs, field visit evidence, legal notice document generation, NeSL default evidence optional.
DeliverablesStrategy allocation, agent scope, borrower recovery-agent notification, PTP tracking, field visit evidence, settlement DoA, write-off maker-checker, conduct audit.
Exit testsRecovery agent assignment notification precedes first contact; broken PTP escalates; OTS approval cannot be done by negotiator alone; settlement funds must be posted by LMS before closed_settled.
RationaleCollections adds conduct risk. Build it after DPD truth exists so agents cannot manipulate classification.

Slice 7: Compliance Reporting And Regulatory Ops

Section titled “Slice 7: Compliance Reporting And Regulatory Ops”
ItemSpecification
GoalProduce KFS archive, CIC submissions, DLA inventory, regulatory return runs and consent/audit evidence.
ModulesCompliance, audit and reporting; Finance and GL adapter; consent service.
Entitiesaudit_event, regulatory_report_run, cic_submission, kfs_version, complaint, access_review, consent_artifact.
IntegrationsCIC reporting exchange, RBI CIMS return metadata, CKYC upload/update, CERSAI/NeSL where enabled.
DeliverablesReporting calendar, file generation, reject correction, DQI tracking, complaint SLA, access review, evidence pack export.
Exit testsCIC rejected record creates correction task; DLA cannot go live without CIMS inventory data; audit export is read-only; access review identifies dormant and conflicting roles.
RationaleReporting can be built after core events exist, but before high volume. The first audited period should not require manual reconstruction.
ItemSpecification
GoalSupport LAP, machinery, stock/book-debt security and charge perfection.
ModulesCollateral and security service, legal/valuation vendor portals, documentation, LMS servicing.
Entitiescollateral_asset, collateral_owner, valuation_report, legal_opinion, security_charge, cersai_filing, roc_charge_filing, insurance_policy, executed_document, vault_packet.
IntegrationsCERSAI search/filing/satisfaction, MCA charge lookup, eStamp/eSign, insurance verification, valuer/legal vendor upload.
StatesApplication: credit_in_review, documentation_pending, disbursement_pending; collateral: proposed, documents_pending, under_legal_review, under_valuation, approved, approved_with_conditions, charged, released; loan closure states.
DeliverablesCollateral checklist, title/valuation workflow, charge creation/perfection, insurance tracking, original document vault, secured closure and release workflow.
Exit testsSecured loan cannot disburse without security_charge.perfection_status acceptable under policy; CERSAI rejection creates legal/ops task; collateral release requires no-dues, legal and finance checks.
RationaleSecured products add legal, valuation and registry dependencies. They should not block unsecured MVP but must be first-class before LAP launch.

Slice 9: Partner, LSP And Co-Lending Extension

Section titled “Slice 9: Partner, LSP And Co-Lending Extension”
ItemSpecification
GoalAdd partner APIs, anchor programs, co-lending shares, escrow split, DLG ledger and partner reconciliation.
ModulesPartner API gateway, co-lending and partner ledger, Finance and GL adapter, compliance reporting.
Entitiespartner_profile, partner_program, api_client, partner_application_ref, co_lending_arrangement, partner_share, escrow_movement, partner_ledger, dlg_set, dlg_portfolio_loan, dlg_invocation, partner_status_event, payout_ledger.
IntegrationsPartner APIs/webhooks, escrow bank statement, partner statement import, CIC per-share reporting, DLG provider acknowledgement.
StatesApplication channel_type=co_lending, lsp, anchor; loan states from booking through closure; collections partner sync events.
DeliverablesPartner onboarding, API auth/scopes, dual-decisioning, blended KFS, partner share booking within 15 calendar days, escrow reconciliation, DLG cap checks, payout and clawback.
Exit tests95:5 CLA rejected; partner share missing after 15 days creates break; partner cannot see raw CAM/bureau data; DLG invocation cannot exceed 5 percent cap; SMA/NPA event delivered by next working day.
RationaleCo-lending depends on correct core loan, KFS, payment, DPD, GL and reporting. Building it earlier creates duplicate ledgers and reconciliation debt.

Slice 10: Monitoring, EWS, Renewal And Portfolio Risk

Section titled “Slice 10: Monitoring, EWS, Renewal And Portfolio Risk”
ItemSpecification
GoalAdd post-booking risk monitoring, early-warning signals, covenant tracking, renewals and portfolio analytics.
ModulesMonitoring/EWS, BRE monitoring, risk analytics, servicing, credit workbench.
Entitiessanction_condition, credit_assessment, bre_result, external_verification, service_request, schedule_version, asset_classification, monitoring trigger records.
IntegrationsAA periodic consent, GST monitoring, bureau refresh where consent/policy permit, stock statement upload, insurance renewal.
DeliverablesCovenant calendar, stock statement tracker, GST/banking drop alerts, renewal/top-up workflow, risk-grade migration, portfolio caps.
Exit testsMonitoring fetch blocked without active consent; covenant breach creates task and may freeze facility; renewal starts fresh application or approved renewal workflow, not silent limit extension.
RationaleMonitoring improves portfolio quality but requires live loan data and consent controls already present.
DimensionMVP choiceReason
ProductUnsecured business loan or small ticket machinery/term loan without collateral charge automationExercises KYC, bureau, bank/GST/ITR data, KFS, sanction, eSign, mandate, disbursement, LMS, DPD and collections without CERSAI/ROC complexity.
ChannelBranch/digital direct plus controlled DSATests customer, sales and DSA permissions while avoiding partner API/co-lending complexity.
Borrower constitutionsProprietorship, partnership, LLP, private limitedCovers natural person, business entity, BO, promoter/director/partner and guarantor paths.
IntegrationsPAN, bureau, CKYC, sanctions, bank statement/AA, GST, eSign/eStamp, eNACH, payment railCovers core underwriting and booking evidence. ITR, Udyam, DigiLocker can be added if vendor/onboarding is ready.
CollectionsTele, PTP, field allocation, settlement proposalEnough to prove DPD-driven operations and conduct controls.
GateMust pass before production
Regulatory gateKYC, consent, KFS, fund-flow, audit, DPD/NPA and grievance controls pass compliance test cases.
Ledger gateDisbursement, schedule, receipt, reversal, waiver, GL and bank reconciliation are idempotent and balanced.
Security gateRBAC/ABAC tests, maker-checker, encryption, secrets, log redaction, partner scope and vulnerability checks pass.
Data gateMandatory fields for party, application, loan_account, repayment_due, loan_transaction, asset_classification, kfs_version and audit_event are complete.
Reporting gateCIC extract dry run, KFS evidence pack, DLA inventory, access review and audit export work without manual spreadsheet patching.
Operations gateQueue SLAs, rework, holds, escalations, failure retries and support runbooks are tested.
OrderSliceWhy now
0Platform and control spineShared audit, IAM, approvals and document vault are prerequisites.
1Lead, consent, prescreen and KYCEstablish regulated borrower onboarding and early rejection.
2Data pack, BRE and creditCreate defensible underwriting and approval evidence.
3Sanction, KFS and documentationMeet borrower disclosure and execution requirements.
4Disbursement and LMS bookingCreate account, schedule, ledger and direct fund flow.
5Servicing and delinquencyGenerate dues, receipts, DPD, SMA/NPA and case triggers.
6Collections operationsOperational recovery using LMS truth.
7Compliance reportingGenerate reports from source events before scale.
8Secured SMEAdd collateral, legal, valuation and charge perfection.
9Partner/co-lendingAdd partner shares, escrow, DLG and reconciliation after core loan correctness.
10Monitoring/EWSAdd portfolio defence and renewal intelligence.