| PAN validation | pan_nsdl | Validate PAN format, name match and active status for borrower, proprietor, promoter, director, partner, guarantor and beneficial owner. | kyc_pending, prescreen_pending | party_id, primary_pan or natural_person.pan, display_name, date of birth/incorporation when available, consent_id if journey uses consented fetch. | PAN status, name match score, masked name, category, last updated date, mismatch reason. | Success supports kyc_verified; mismatch creates returned_for_rework; fraud mismatch can trigger fraud_confirmed. | Format/checksum failure no retry; provider 5xx retry; mismatch requires corrected PAN or KYC rejection. |
| Consumer credit bureau | bureau | Pull individual bureau report for proprietors, promoters, co-applicants and guarantors. | prescreen_pending, data_pending, monitoring | party_id, application_id, PAN, name, DOB, gender, mobile, address, enquiry purpose, consent_id with consent_type=bureau_pull. | Score, enquiry id, tradelines, DPD history, suit-filed/wilful default flags where reported, write-off/settlement flags, active obligations, score reason codes. | pre_screen_passed, hard_reject_triggered, data_pack_finalized, deviation_raised. | No-hit is valid response; do not retry. Identity mismatch returns to KYC. Provider failure retries; exhausted required bureau pull routes to on_hold. |
| Commercial credit bureau and CMR | bureau | Pull entity report, Commercial Credit Information Report and rank/band for business_entity. | data_pending, credit_in_review, renewal | Entity PAN, GSTIN, legal name, address, constitution, CIN/LLPIN where available, enquiry purpose, consent_id. | Commercial score/rank, active credit facilities, sanctioned limits, overdue/NPA flags, related-party links, suit-filed/wilful default, bureau reference number. | data_pack_finalized; adverse finding can create deviation or credit_rejected. | No-hit allowed for new micro entity; mismatch requires corrected identifiers; provider failure retries. |
| Account Aggregator consent creation | aa | Create AA consent artefact for bank account data or periodic monitoring. | data_pending, monitoring, renewal | party_id, application_id, FIU id, AA handle, purpose code, data range, fetch type, frequency, consent validity, data life, account type. | Consent handle/id, status, linked account references, expiry, rejection reason. | Active consent permits AA data fetch; rejection keeps data_pending. | Consent rejection no retry; borrower may initiate new consent. AA technical failure retries. ReBIT defines AA, FIP and FIU callback API groups for consent and data flow (ReBIT AA API specifications). |
| Account Aggregator data fetch | aa | Fetch bank transactions, balances and account profile from FIPs through AA. | data_pending, monitoring | Consent handle, session id, FI data range, account link reference, request timestamp, encryption key material as per AA spec. | Account profile, balances, transactions, masked account, fetch status, data range served, FIP id. | Parsed BSA variables support data_pack_finalized; missing required account may create returned_for_rework. | Retry data fetch on pending/temporary failure until consent expires; do not fetch beyond consent scope. |
| Bank statement analyzer | internal or vendor-specific extension | Parse uploaded PDF/CSV/netbanking/AA statements into underwriting variables. | data_pending, credit_in_review | document_id or AA payload URI, account number masked, statement period, bank name, password metadata where borrower provided. | ABB, monthly credits/debits, bounce count, EMI detection, counterparty concentration, circular transaction flags, fraud/tamper flags. | Success supports data_pack_finalized; tamper flag can trigger fraud_confirmed or deviation_raised. | Parser failure returns to document rework; tamper suspicion routes RCU, not silent waiver. |
| GST return and GSTIN analytics | gstn_vendor | Verify GSTIN status and derive turnover, filing regularity, customer/supplier and e-way/e-invoice signals. | data_pending, monitoring, working-capital renewal | primary_gstin, party_id, application_id, consent/OTP artefact, date range, return types requested: GSTR-1, GSTR-3B, e-invoice, e-way bill where available. | GSTIN status, legal/trade name, registration date, cancellation status, filing periods, taxable value, tax paid, top counterparties, nil months, variance flags. | data_pack_finalized, deviation_raised, hard_reject_triggered for cancelled GSTIN policy. | OTP/consent expiry requires borrower action; provider 5xx retries; GSTIN cancelled is business result. GST API availability usually runs through GSP/ASP/vendor or consented rails, not arbitrary public lender access (GSTN e-invoice APIs). |
| ITR/financial tax data | itr_eri_vendor or internal for uploaded ITR | Validate ITR acknowledgements, income, turnover, tax paid and financial statement consistency. | data_pending, credit_in_review | PAN, assessment years, acknowledgement numbers, borrower-authorised ERI/vendor consent, uploaded ITR document_id, audited financials document_id. | ITR filing status, gross receipts, total income, tax paid/refund, balance sheet extracts where available, acknowledgement hash, mismatch flags. | data_pack_finalized; mismatch with GST/banking can create deviation_raised. | No generic unauthorised ITR pull is allowed. Income Tax ERI specs require taxpayer-authorised client/prefill flows (Income Tax API specifications); consent expiry requires re-consent; parse failure returns to documents. |
| Udyam verification | udyam | Verify MSME registration, classification and enterprise details. | kyc_pending, data_pending, PSL tagging | Udyam Registration Number, PAN/GSTIN where available, enterprise name, consent_id with consent_type=udyam_verify. | Udyam number, enterprise name, type, classification micro/small/medium, NIC codes, registration date, address, QR/verification evidence. | Updates business_entity.udyam_registration_number and msme_classification; success supports data_pack_finalized. | Not-found returns to rework or unverified; no official arbitrary lender API was verified in the domain docs, so store portal/vendor evidence. |
| CKYC search/download/upload | ckyc | Reuse or submit KYC records for individuals and legal entities. | kyc_pending, periodic KYC | PAN, CKYC id, name, DOB/incorporation, mobile, address, consent_id with consent_type=ckyc_fetch, KYC template fields. | CKYC id, KYC type, masked identifiers, address, OVD details, image/document references where permitted, match confidence. | Success updates kyc_profile.ckyc_id; supports kyc_verified only after BO and screening checks are complete. | No-hit means fresh CDD; mismatch routes KYC rework; provider failure retries. RBI operationalised CKYCR through CERSAI from July 15, 2016 (RBI CKYCR circular). |
| DigiLocker document pull | digilocker | Fetch authentic issued documents with user consent. | kyc_pending, docs_pending, documentation_pending | OAuth/OpenID request, scopes, document type, issuer id, borrower identifier, consent_id, redirect/callback id. | Document URI, issuer, document type, issue date, XML/PDF metadata, hash, signer/certificate metadata. | Creates document_instance; verified documents can move docs_pending to data_pending. | Consent denial no retry; token expiry re-authenticates; document not available returns to manual upload. DigiLocker Requesters use OAuth 2.0/OpenID and user consent (DigiLocker Requester integration). |
| MCA/company master | mca | Verify companies/LLPs, directors, charges and company status. | kyc_pending, credit_in_review, secured lending | CIN, LLPIN, company/LLP name, director DIN/PAN where available, party_id. | Legal name, incorporation date, registered address, authorised/paid-up capital, status, directors/designated partners, charge index. | Updates business_entity.cin, business_entity.llpin, entity_status; adverse status creates deviation or rejection. | No retry for struck-off/dissolved status; provider technical failure retries; mismatch routes rework. |
| Sanctions, PEP, adverse media and negative lists | sanctions_vendor | Screen parties, beneficial owners, guarantors, partners, DSAs and vendors. | prescreen_pending, kyc_pending, partner onboarding, periodic monitoring | party_id, name, aliases, DOB/incorporation, PAN, nationality, address, role, list types. | Match score, list source, category, watchlist id, summary, hit confidence, update timestamp. | Creates screening_hit; true positive blocks kyc_verified and loan_booked. | Provider failure retries; possible hit opens manual review; true positive exits only through kyc_rejected, on_hold or compliance clearance. |
| Bank account verification/penny drop | bank_penny_drop | Verify borrower, supplier, dealer, escrow and repayment bank accounts. | documentation_pending, disbursement_pending, servicing bank change | Account number, IFSC, account holder name, party id, beneficiary type, consent/authorisation evidence. | Account status, name returned, match score, bank reference id, penny transaction id, failure code. | Supports documents_executed_and_cps_cleared and payment_initiated; mismatch blocks disbursement. | Name mismatch requires ops checker decision; invalid account no retry; bank rail timeout retries. |
| eSign | digilocker or eSign service provider extension | Obtain legally valid electronic signatures on loan agreement, guarantee, board resolution and mandate where permitted. | documentation_pending, mandate_setup | Document hash, signer party_id, signatory role, Aadhaar/eKYC or provider auth flow, callback URL, document version, consent/acceptance evidence. | Signature event id, certificate serial, signer name, timestamp, hash signed, failure reason. | Creates signature_event; all required signers enable documents_executed_and_cps_cleared. | Signer rejection no retry; failed OTP/auth may retry 3 times; document hash mismatch invalidates pack. CCA describes eSign as signing document hash with e-KYC authentication (CCA eSign). |
| eStamp | internal or stamp vendor extension | Procure or verify state stamp duty certificates for loan/security documents. | documentation_pending | State, article/instrument, consideration/loan amount, first party, second party, stamp amount, document id. | Certificate number, state, amount, issue date, GRN/reference, payer, verification status. | Creates stamp_certificate; stamp success supports documents_executed_and_cps_cleared. | Wrong state/article/amount requires cancellation or additional stamp per legal policy; provider failure retries; no silent downgrade to unstamped document. |
| eNACH/NACH mandate registration | Rail-specific mandate provider; writes mandate | Register recurring repayment debit mandate. | documentation_pending, disbursement_pending, servicing bank change | loan_account_id, party_id, bank_account_id, max amount, frequency, start/end date, mandate type enach, sponsor bank, utility code. | UMRN, mandate status, rejection reason, sponsor/destination bank timestamps, accepted amount and frequency. | mandate_activated supports documents_executed_and_cps_cleared or disbursement guard. | Rejected status requires borrower reattempt or alternate mandate; bank timeout retries status enquiry. NPCI says debit can start only after mandate acceptance and UMRN is 20 digits with fifth digit “6” for eSign mandates (NPCI eMandate FAQ). |
| CERSAI search/filing/satisfaction | cersai | Search existing security interests, register charge, modify and satisfy charge. | collateral-valuation-legal, documentation_pending, post-closure | Borrower party, PAN/CIN, collateral details, security_charge_id, charge type, charge amount, creation date, asset id, lender details. | Search result, filing id, registration number, status, fee, error list, satisfaction acknowledgement. | Creates/updates security_charge.cersai_filing_id; cersai_filed supports secured disbursement; satisfaction supports closure. | Search failure blocks secured disbursement; filing rejection returns to legal/ops; retry technical failures only. SARFAESI provides the central registry basis (India Code SARFAESI section 20). |
| NeSL Information Utility | External IU integration; normalized into document/evidence records | Submit debt records, get borrower authentication and store evidence of debt/default. | documentation_pending, loan_booked, default/legal recovery | Borrower identifiers, loan terms, sanction id, document hash, repayment obligations, authentication request, default details when applicable. | IU record id, authentication status, borrower response, evidence timestamp, default record status. | Authenticated debt evidence supports legal readiness; default evidence supports legal_route_requested. | Authentication pending remains waiting; borrower dispute routes legal review; technical failure retries. NeSL is registered as an Information Utility under IBBI (PIB NeSL registration). |
| Disbursement payment rails: NEFT/RTGS/IMPS/UPI | Payment service provider or bank host-to-host; writes payment_instruction and loan_transaction | Send loan proceeds to borrower, supplier, dealer, invoice seller, escrow or statutory authority. | disbursement_pending, loan_booked | Beneficiary account/IFSC or UPI id, beneficiary type, amount, payment mode, sanction/disbursement id, purpose, maker/checker approval, escrow id where CLA applies. | Bank UTR/reference, status initiated/posted/failed/reversed, failure code, value date. | Success supports loan_booked; failure emits disbursement_failed and may trigger booking_failed. | Pending status enquiry every 15 minutes for 2 hours, then hourly until end of day; failed payment requires checker-approved reinitiation; no LSP/pool account except permitted co-lending escrow under RBI Digital Lending Directions. |
| Repayment/payment collection rails: NACH debit, UPI collect, payment gateway, bank virtual account | Payment rail provider; writes loan_transaction | Collect dues directly into RE account or permitted CLA escrow. | Servicing, collections | loan_account_id, due id, amount, mandate/UPI/payment link id, payer party, expiry, payment purpose. | Receipt reference, amount, payer account masked, settlement status, bounce/failure code, value date. | receipt_posted, bounce, dpd_changed, arrears_cleared. | Bounce is business event; not retried unless mandate policy allows representation. Pending settlement reconciled daily; unapplied receipts open suspense item. |
| CIC reporting file exchange | CIC member integration; writes cic_submission | Report consumer/commercial/MFI credit information and corrections. | loan_booked, servicing, delinquency, closure | Borrower identifiers, co-borrower/guarantor links, account number, sanctioned amount, current balance, DPD, asset classification, suit-filed/wilful default, closure status, CERSAI property registration where applicable. | File ack, accepted/rejected counts, reject reasons, DQI score where provided, dispute/correction ack. | Supports compliance reporting; reject correction creates compliance task. | Rejected records fixed before next reporting date. As of July 2026, support configurable reporting calendar: at minimum fortnightly 15th/last-day cycles under RBI CIC Directions, and entity-specific amended CI schedules where applicable (RBI CIC Directions, 2025 public mirror). |