Part 10 — System Blueprint
Module Map
The system blueprint is written for an Indian small and medium enterprise (SME) lender that may run branch, direct selling agent (DSA), digital, lending service provider (LSP), and co-lending channels. The design principle is strict state ownership: one module owns a record, other modules consume events or read models. This prevents the common failure where the loan origination system (LOS) says “disbursed”, the loan management system (LMS) has not booked the account, collections does not know the first repayment date, and the credit bureau file is wrong.
Regulatory constraints are module boundaries, not footnotes. Digital loans must route disbursement and repayment directly between the regulated entity (RE) and borrower or permitted end-beneficiary, with no LSP pool account, under the RBI Digital Lending Directions, 2025. KYC data, beneficial owners, ongoing due diligence and record retention belong to a controlled KYC domain under the RBI KYC Master Direction, 2016. Co-lending must maintain each RE’s share, escrow routing, blended borrower disclosure and borrower-level SMA/NPA alignment under the RBI Co-Lending Arrangements Directions, 2025. Income recognition, SMA/NPA tagging and NPA upgradation must be date-true under the RBI IRACP clarification, November 12, 2021 and current IRAC directions.
System Modules
Section titled “System Modules”| Module | Owns | Does not own | Primary users | System of record tables | Key outbound events |
|---|---|---|---|---|---|
| Channel CRM | Raw leads, source attribution, campaign, DSA/connector handoff, telecalling disposition before login | Credit decision, KYC verification, sanction, live loan dues | Sales, call centre, DSA manager, partner manager | lead, source_attribution, channel_partner, campaign, lead_contact_event | lead_created, consent_captured, source_locked, lead_login_ready, lead_disqualified |
| DSA portal | DSA lead submission, document upload, coarse status, payout visibility | Bureau variables, credit memo, fraud signals, approval authority | DSA, connector, DSA ops | dsa_user, dsa_lead_view, dsa_document_upload, payout_claim | dsa_lead_submitted, dsa_document_uploaded, payout_hold_marked |
| Customer portal and DLA | Borrower self-service, consent capture, offer display, KFS acceptance, service requests | Internal underwriting, internal deviations, collections strategy | Borrower, promoter, guarantor | portal_session, customer_consent_action, offer_view, kfs_acceptance, service_request | borrower_consent_granted, offer_selected, kfs_accepted, service_request_created |
| Partner API gateway | API authentication, partner application intake, idempotency, partner callbacks, schema validation | Internal policy decision, partner commercial settlement | LSP, anchor, co-lender, marketplace | api_client, api_request_log, partner_application_ref, webhook_delivery | partner_application_received, partner_status_delivered, webhook_failed |
| Consent and privacy service | Consent artefacts, purpose, data scope, revocation, data-retention instruction | Parsed underwriting results | Borrower, compliance, integrations | consent_artifact, consent_scope, consent_revocation, data_retention_policy | consent_granted, consent_revoked, retention_expired |
| KYC and AML service | Party master, customer due diligence (CDD), beneficial owners, CKYC, V-CIP, sanctions/adverse media, periodic KYC | Credit approval, loan account accounting | KYC ops, AML officer, compliance | party, natural_person, business_entity, kyc_profile, beneficial_owner, screening_hit | kyc_verified, kyc_rejected, bo_added, sanctions_hit_cleared, rekyc_due |
| Document service and DMS | Document requirements, uploads, extraction, verification, executed document vault, versioning | Deciding whether a waiver is credit-approved | Operations, sales ops, legal, borrower | document_requirement, document_instance, document_extraction, executed_document, vault_packet | document_uploaded, document_verified, deficiency_raised, document_pack_locked, originals_vaulted |
| LOS workflow | Application lifecycle from login to loan booking handoff, queue assignment, SLA, conditions, audit trail | Live dues, interest accrual, final accounting ledger | Sales ops, credit, RCU, legal, valuation, ops | application, application_party, workflow_task, condition, queue_assignment | application_submitted, docs_complete, credit_submitted, sanction_accepted, loan_booking_requested |
| BRE and decision service | Rule versions, eligibility, scorecards, pricing bands, deviations, automated decisions | Human committee minute, post-booking repayment accounting | Credit policy, risk analytics, credit manager | rule_set, rule_version, rule_execution, scorecard_result, deviation | bre_executed, rule_failed, deviation_raised, eligibility_approved, pricing_computed |
| Credit workbench | Credit appraisal memo (CAM), financial spreading, analyst recommendations, committee decisions, DoA resolution | Disbursement maker-checker, cash posting | Credit analyst, credit manager, committee | credit_assessment, financial_spread, cam, approval_request, committee_decision | cam_submitted, authority_resolved, credit_approved, credit_rejected, condition_added |
| Collateral and security service | Collateral assets, owners, title chain, legal opinion, valuation, insurance, CERSAI/ROC filings | Repayment collections, borrower service requests except release | Legal, technical, ops, credit | collateral_asset, collateral_owner, legal_opinion, valuation_report, security_charge, cersai_filing, roc_charge_filing | collateral_approved, charge_created, cersai_filed, roc_srn_received, charge_satisfied |
| Documentation and execution service | Document checklist, generation, stamp duty, e-sign/wet-sign evidence, guarantee execution | Credit term approval and pricing | Operations, legal, borrower | document_checklist, stamp_certificate, signature_event, guarantee, documentation_exception | document_generated, stamp_paid, esign_completed, wet_signature_verified, documents_executed |
| Disbursement service | CP verification, bank account verification, mandate status, tranche instruction, payment instruction | Sanction approval, post-booking schedule recalculation | Operations maker/checker, treasury | disbursement_request, condition_clearance, bank_account_verification, mandate, tranche, payment_instruction | cp_cleared, mandate_activated, payment_initiated, disbursement_posted, disbursement_failed |
| LMS core | Loan account, facility, repayment schedule, demands, receipts, appropriation, interest, charges, DPD/SMA/NPA, closure | New application underwriting | Operations, finance, servicing, collections | loan_account, facility, schedule_version, repayment_due, loan_transaction, asset_classification | loan_booked, demand_generated, receipt_posted, dpd_changed, loan_closed |
| Collections platform | Delinquency cases, allocation, PTP, tele/field/legal workflows, agency activity, settlement proposal | Regulatory asset classification calculation source; it consumes LMS classification | Collections, recovery, agency manager, legal | delinquency_snapshot, collection_case, case_allocation, contact_attempt, ptp, settlement_proposal | case_opened, ptp_recorded, field_visit_completed, settlement_approved, case_closed |
| Finance and GL adapter | Accounting event mapping, GL posting, suspense, reconciliation, DSA payout, tax splits | Customer-facing statements unless sourced from LMS | Finance, treasury, audit | accounting_event, gl_posting, bank_reconciliation, suspense_item, payout_ledger | gl_posted, reconciliation_break_created, payout_accrued, payout_reversed |
| Co-lending and partner ledger | Partner shares, escrow split, blended rate, partner status exchange, DLG set and invocation | Base loan schedule; LMS remains source for borrower dues | Partner ops, finance, risk, co-lender | co_lending_arrangement, partner_share, escrow_movement, partner_ledger, dlg_set, partner_status_event | partner_share_booked, escrow_reconciled, partner_dpd_sent, dlg_invoked |
| Compliance, audit and reporting | Audit trail, regulatory evidence, CIC reporting extract, KFS archive, grievance control, access review | Operational approval except compliance holds | Compliance, internal audit, statutory audit | audit_event, regulatory_report_run, cic_submission, kfs_version, complaint, access_review | audit_event_recorded, cic_file_generated, complaint_escalated, access_review_due |
The BRE module is detailed in BRE functional specification for decision contracts and BRE runtime architecture for deterministic evaluation, scaling, replay and observability.
Cross-Module Contracts
Section titled “Cross-Module Contracts”| Contract | Producer | Consumers | Required payload | Idempotency key | Failure handling |
|---|---|---|---|---|---|
| Lead to application | Channel CRM | LOS, consent service | lead_id, source, product, requested amount, identifiers, consent ref | lead_id | Duplicate creates a dedupe_match, not a second application. |
| KYC result | KYC service | LOS, LMS, compliance | party_id, KYC status, risk category, BO status, expiry/re-KYC date | party_id plus kyc_profile_version | Failed screening places application on compliance hold. |
| BRE decision | BRE | LOS, credit workbench | Rule version, pass/fail tree, score, limit, tenor, price band, deviations | application_id plus rule_version_id | External dependency failure retries; policy hard fail cannot be suppressed without deviation approval. |
| Document pack lock | Document service | LOS, documentation service, credit | Requirement status, verified documents, waivers, deficiencies | application_id plus checklist_version | New upload after lock creates a new version and reopens verification. |
| Sanction accepted | Credit workbench | LOS, documentation, KFS archive, co-lending | Sanction id, terms, conditions, KFS version, acceptance timestamp | sanction_id | Expired sanction blocks documentation and routes to revalidation. |
| Loan booking request | Disbursement service | LMS, finance, co-lending | Accepted sanction, cleared CPs, tranche, mandate, disbursement instruction | disbursement_request_id | LMS booking failure rolls LOS to booking_failed; no collections record is opened. |
| Repayment event | LMS | Collections, finance, co-lending, CIC reporting | Loan id, receipt, reversal, appropriation, DPD before/after | loan_transaction_id | Reversal creates compensating event; DPD recomputes from due ledger. |
| Asset classification event | LMS | Collections, finance, risk, co-lending | Borrower id, facility ids, SMA/NPA status, effective date, reason | borrower_id plus classification_date | Manual override requires maker-checker because it affects IRAC and CIC reporting. |
| Recovery agent assignment | Collections | Customer portal, notification service, compliance | Case id, agency, agent, valid dates, contact channel | case_allocation_id | Borrower notification must precede first recovery contact under RBI digital-lending and recovery-agent conduct requirements. |
Source Of Truth Rules
Section titled “Source Of Truth Rules”| Data object | Source of truth | Read-only mirrors allowed in | Rationale |
|---|---|---|---|
| Party identity and KYC status | KYC and AML service | LOS, LMS, collections, partner module | KYC/beneficial-owner duties are regulated under the RBI KYC Master Direction. |
| Application state | LOS workflow until loan_booked | Channel CRM, portals, partner APIs | Origination queues and pre-booking conditions need one owner. |
| Credit decision and DoA evidence | Credit workbench | LOS, compliance, audit | Approval authority must remain immutable after sanction. |
| KFS and borrower acceptance | KFS archive with LOS reference | Customer portal, document service, LMS | KFS must preserve APR, charges and schedule disclosure for covered MSME loans under RBI’s KFS circular. |
| Live dues, DPD and asset class | LMS | Collections, customer portal, co-lending, finance | IRAC classification must be computed from dues, receipts, reversals and waivers, not edited in collections. |
| Collection strategy and PTP | Collections platform | LMS, risk dashboard | Collections strategy changes daily and should not pollute accounting ledgers. |
| GL posting and reconciliation | Finance and GL adapter | LMS, co-lending, reporting | Accounting events must reconcile to bank and GL independently of UI status. |
| Partner share and DLG | Co-lending module | LMS, finance, compliance | Co-lending needs partner-wise books, escrow movements and DLG cap tracking. |
Minimum Deployment Slices
Section titled “Minimum Deployment Slices”| Slice | Include | Exclude until later | Exit criteria |
|---|---|---|---|
| Origination MVP | CRM lead, LOS, consent, KYC, document checklist, BRE policy gates, credit approval, sanction | Co-lending, advanced scorecards, automated valuation | A policy-compliant unsecured loan can reach accepted sanction with audit trail. |
| Booking MVP | Documentation checklist, e-sign evidence, mandate, disbursement maker-checker, LMS booking, repayment schedule, GL event | Tranches, supplier financing, CERSAI filing automation | A booked loan has account number, schedule, first due date, accounting event and borrower communication. |
| Servicing and delinquency MVP | Demand generation, receipts, appropriation, DPD/SMA/NPA, collections case opening, PTP, payment link | Legal recovery, repossession, OTS | Missed EMI creates correct bucket and collections task from LMS event. |
| Secured SME extension | Collateral, valuation, legal opinion, security charge, insurance, CERSAI/ROC tracking, vault | Complex consortium security trustee workflows | A loan against property cannot disburse without approved charge or approved exception. |
| Partner/co-lending extension | Partner APIs, CLA config, partner share, escrow reconciliation, partner DPD exchange, DLG set | Portfolio sale/securitisation | Both RE shares reconcile within the 15-calendar-day rule in RBI CLA directions. |