NFR-DR-001 | Digital lending data residency | RBI Digital Lending Directions, para 13 requires all borrower data to be stored only on servers located in India, and if processed outside India it must be deleted offshore and brought back to India within 24 hours (RBI Digital Lending Directions, 2025). | Production databases, object storage, logs, analytics, search indexes, backups and support exports containing borrower data must reside in India regions. Any offshore processing must be approved, logged and auto-deleted within 24 hours. | Data-flow inventory proves no borrower data at rest outside India; DLP scan of logging/analytics vendors finds no PAN, Aadhaar, bank account, bureau, GST, ITR, AA or KYC payload outside India. |
NFR-DR-002 | LSP data minimisation | Digital Lending Directions allow LSPs to store only basic minimal borrower data needed for operations and place ongoing privacy/security responsibility on the RE. | Partner APIs and LSP portals expose only scoped fields: name, contact, coarse application status, next action, assigned cases and payment link where authorised. No raw bureau report, CAM, RCU note, AA transactions, ITR payload or KYC document is exposed unless a signed data-sharing scope explicitly permits it. | Contract test calls partner APIs with broad scopes and verifies denial; UI masking tests show bureau/AA/tax data unavailable to partner_api_client and dsa_user. |
NFR-DR-003 | CIC data localisation for specified users | RBI CIC Directions require specified users processing credit information to process/store it in India and retain credit information only for six months or until purpose is satisfied, whichever is earlier (RBI CIC Directions, 2025 public mirror). | Bureau/CIC data passed to any specified-user-style vendor or analytics service must remain in India and have purpose-bound TTL. | Bureau payload retention job deletes vendor-working copies by TTL; audit can prove the deletion timestamp. |
NFR-RT-001 | KYC record retention | RBI KYC Master Direction requires preservation of customer account information and identification/address records for at least five years after business relationship ends; transaction records must also be preserved for at least five years from transaction date (RBI KYC Master Direction, 2016). | kyc_profile, beneficial_owner, screening_hit, document_instance, consent evidence and transaction audit records cannot be hard-deleted before retention expiry. | Deletion API refuses active/retention-locked party records; retention report shows expiry date per party and loan. |
NFR-RT-002 | KFS and loan evidence retention | KFS circular makes KFS legally significant borrower disclosure; Digital Lending Directions require digitally signed documents to flow to borrower. | kfs_version, APR computation, amortisation schedule, borrower acknowledgement, sanction letter and executed loan documents are immutable and retained with sha256_hash. | Regenerate a closed loan evidence pack from stored versions without recomputing APR from current product rules. |
NFR-RT-003 | Consent lifecycle | Digital Lending Directions require borrowers to give/deny consent for specific data, restrict disclosure, revoke consent and request deletion/forgetting where applicable. | consent_artifact stores purpose, scope, text version, captured channel, evidence, expiry and revocation. Revocation blocks future fetch/sharing but preserves regulated records needed for audit, KYC, servicing, legal and reporting. | API call with revoked consent returns consent_required; audit event consent_revoked exists; existing booked-loan evidence remains available to compliance. |
NFR-AU-001 | Immutable auditability | Digital Lending, KYC, KFS, IRAC, co-lending and outsourcing controls all require reproducible evidence of decisions, consent, disclosures, fund flow and classification. | Every material state transition writes audit_event with actor, role, subject, before/after hash, evidence URI, timestamp, reason and approval reference. | Random sample of loan_booked, kfs_accepted, npa_classified, dlg_invoked, role_granted and settlement_approved events reconstructs full maker-checker chain. |
NFR-AU-002 | IRAC/date-true classification | RBI IRAC clarification requires day-end objective classification and NPA upgradation only after arrears are cleared. | loan_account.current_dpd and asset_classification are computed from due/receipt ledgers; manual override needs approval and audit. Collections cannot edit DPD. | Attempt by collections_agent to edit DPD fails; NPA upgrade test succeeds only after all principal and interest arrears across linked facilities are cleared. |
NFR-AU-003 | Co-lending audit and partner sync | Co-Lending Directions require partner shares in books within 15 calendar days, separate borrower accounts per RE share, escrow routing, audit scope and next-working-day asset classification sharing (RBI Co-Lending Directions, 2025). | partner_share, escrow_movement, partner_ledger and partner_status_event must reconcile daily. SMA/NPA event must be delivered to partner no later than next working day. | Simulated npa_classified event creates partner webhook and ack; missing ack breaches SLA; share-not-booked after 15 days creates reconciliation break. |
NFR-SEC-001 | IT governance | RBI IT Governance, Risk, Controls and Assurance Practices Directions, 2023 apply to commercial banks, NBFC Upper/Middle/Top Layer, CICs and AIFIs from April 1, 2024 and require Board/management oversight, IT risk, information security, assurance, IS audit and business continuity practices (RBI IT Governance Directions, 2023). | Maintain IT asset inventory, data classification, risk register, access reviews, IS audit evidence, BCP/DR plans, cyber incident process and control testing for LOS, LMS, BRE, DMS, partner gateway and payments. | Quarterly access review and annual IS audit produce evidence; critical systems have documented RTO/RPO and tested restoration logs. |
NFR-SEC-002 | IT outsourcing | RBI Outsourcing of IT Services Directions say outsourcing must not diminish RE obligations or impede RBI supervision and require governance, due diligence, risk management, audit/access rights, cross-border controls and exit strategy (RBI IT Outsourcing Directions, 2023). | SaaS LOS/LMS/BRE, cloud, document vault, analytics, SMS/email, payment gateway and security operations vendors require contract metadata: audit rights, data location, sub-outsourcing, incident SLA, exit plan and access controls. | Vendor cannot be marked active without due diligence checklist; exit test exports data and documents in usable format. |
NFR-SEC-003 | API security | Digital Lending Directions require technology/cyber standards compliance for RE and LSP DLAs; IT directions require access controls and information security. | Partner APIs require mTLS or OAuth2 client credentials/signed JWT, HMAC request signing, idempotency keys, IP allowlist, request replay protection and least-privilege scopes. | Replay with old timestamp fails; partner cannot access another partner’s application; all write APIs require idempotency. |
NFR-SEC-004 | Sensitive data protection | KYC/Digital Lending rules restrict biometric/full Aadhaar storage and require need-based collection. | Store aadhaar_last4 only; never store full Aadhaar or biometric data unless statutory basis is configured and approved. Encrypt PAN, bank account, bureau, GST, ITR, AA and document payloads at rest; mask in UI by role. | Static scan and database policy check show no full Aadhaar column; role tests show masked PAN/bank account for non-need-to-know users. |
NFR-AV-001 | Availability for borrower servicing | Digital lending and grievance rules require borrower access to documents, complaint channel, grievance officer and loan information. | Customer portal/DLA must expose KFS, sanction, repayment schedule, statements, payment status, complaint filing and grievance contacts even if partner channel is down. | Partner outage drill proves borrower can still access RE portal and repay directly to RE account. |
NFR-AV-002 | Business continuity for CLA | Co-Lending Directions require BCP to ensure uninterrupted service to borrowers if CLA terminates. | CLA termination cannot break repayment, statement, complaint, NOC, settlement, DPD and CIC reporting services. | Disable partner API in test; LMS continues demands/receipts and borrower portal still works. |
NFR-AV-003 | Payment and ledger recovery | Direct fund-flow rules and accounting controls require payment certainty and reconciliation. | Payments, receipts, mandates, escrow movements and GL postings must be recoverable from idempotent events. No payment callback may create duplicate loan_transaction. | Replay payment callback with same idempotency key returns original result; day-end reconciliation detects missing bank references. |
NFR-REP-001 | CIC reporting timeliness | RBI CIC framework requires regular credit information updates; as of July 2026 the scheduler must support fortnightly cycles and entity-specific granular schedules where applicable. | Reporting calendar is configuration by RE type, CIC and segment. Rejected CIC records create correction tasks. | Generate files for 15th/last-day cycle and 9th/16th/23rd/last-day cycle in test tenant; both pass schema validation. |
NFR-REP-002 | DLA reporting | Digital Lending Directions require REs to report DLAs deployed/joined on CIMS, update additions/cessations and certify compliance. | DLA inventory stores owner, app/website links, LSP, grievance officer, privacy policy, RE website link, certification status and CIMS ack. | New api_client/DLA cannot go live until DLA inventory and compliance certification fields are complete. |