Financial services: controls first, speed second, and both are achievable
In lending, the system is the control environment. Maker–checker, immutable audit, segregation of duties and reportable data are not features — they are the reason a regulator lets you operate.
Financial services technology carries a constraint that most other industries do not: the system is simultaneously an operational tool and a control environment. Every design decision has an audit implication, every shortcut has a regulatory consequence, and the question "who approved this and when" must always be answerable.
We build for NBFCs, cooperative banks and credit societies, insurance intermediaries, brokers and fintech operators, with the control architecture treated as a first-class requirement rather than something added before an audit. Maker–checker on every consequential action. Immutable audit trails. Segregation of duties enforced by the system rather than by policy. Data residency in India. Encryption and access control that would survive scrutiny.
Within that constraint, speed is entirely achievable and is where the commercial value lies. A loan decision that takes four days loses customers to one that takes six hours, and the difference is almost never underwriting depth — it is document collection, verification, and the hand-offs between them.
We are explicit about our limits. We are technology builders, not compliance consultants, and we work alongside your compliance function rather than substituting for it. What we guarantee is that the system will do what your compliance team specifies, provably and with evidence.
Origination: where the days actually go
Analysing loan turnaround for our clients consistently shows the same pattern: underwriting takes hours, and the process takes days. The time goes into document collection, chasing missing items, verification, and waiting for a file to move between desks.
We compress that by moving collection and verification to the front and running them in parallel. Digital application with document upload from the customer's phone. e-KYC through Aadhaar or PAN with automated validation. Bank statement analysis producing income and obligation figures automatically. Bureau pull integrated. Penny-drop account verification. Each of these runs as soon as its input arrives rather than in sequence.
By the time the file reaches an underwriter, the data is complete and validated. Decision turnaround in our deployments has typically moved from around four days to under six hours, without reducing the depth of assessment.
The control architecture
Maker–checker is implemented at the transaction level rather than as a screen. Any action with financial or customer consequence — a disbursal, a limit change, a waiver, a write-off, a master data amendment — requires a separate authorised user to approve, and the system prevents the same person from doing both regardless of their role combination.
Audit logging is append-only and captures the actor, the timestamp, the before and after values, and the approval chain. It is retained beyond any plausible investigation window and it is queryable, because an audit trail that requires a database export to interrogate does not get used.
Segregation of duties is enforced through role design done with your compliance function, not by developers guessing. Access is reviewed periodically with a report showing who has what, which is the evidence an auditor asks for and which most institutions compile manually.
In practice
Every engagement starts with a conversation, not a proposal template.
Thirty minutes with a senior engineer. You leave with an architecture sketch and an honest cost range, whether or not you hire us.
Underwriting: rules, scorecards and the human decision
Most lenders operate a policy that is partly written and partly held in the heads of experienced credit officers. Encoding it produces two benefits: consistency, and a record of what the policy actually was when a decision was made.
We build a rules engine where policy is configured rather than coded — eligibility criteria, exposure limits, deviation thresholds and approval matrices can be changed by an authorised business user with a versioned record of the change. Scorecards, where used, are versioned identically so a decision can always be evaluated against the policy in force at the time.
What we do not do is remove the human from consequential decisions. The system produces a recommendation with the reasons for it, including any deviations from policy; a credit officer decides. That structure is both better lending and better defensible when a portfolio is reviewed.
| Stage | Typical duration before | After |
|---|---|---|
| Application and documents | 1–2 days | Same day, customer self-service |
| KYC and verification | 1 day | Minutes, automated |
| Bank statement analysis | Half a day, manual | Automatic on upload |
| Bureau and checks | Hours, sequential | Parallel, on trigger |
| Credit decision | Hours | Hours — unchanged, and that is correct |
| Total | ~4 days | Under 6 hours |
Collections: strategy rather than calling everyone
Collections is where portfolio quality is preserved or lost, and most operations run it as an undifferentiated calling exercise. The result is that low-risk accounts that would have paid anyway are contacted while genuinely deteriorating accounts get the same attention.
We build bucket-wise strategy: segmentation by risk and behaviour, differentiated treatment ladders — automated reminder for the reliable late payer, early field visit for the account showing deterioration signals — allocation to field agents with route optimisation, and outcome capture from a mobile app with geotagged evidence.
The measurable effect is concentrated in bucket-1 roll-forward, which is where intervention has the highest leverage. Clients typically see roll-forward reduce by around thirty per cent, which flows directly to provisioning and profitability.
Every engagement starts with a conversation, not a proposal template.
Thirty minutes with a senior engineer. You leave with an architecture sketch and an honest cost range, whether or not you hire us.
Regulatory reporting and audit readiness
Regulatory returns are usually compiled by a small team over several days each period, from data extracted and reworked. It is laborious and it introduces the risk of a filed figure not matching the operational record.
We generate returns from the operational ledger with the classification rules encoded — asset classification and provisioning under the applicable norms, ageing, exposure concentration, and the specific returns your registration requires. The reviewer checks and approves rather than compiles.
For audit, the useful deliverable is not a report but the ability to answer a question quickly. When an auditor selects fifty accounts and asks for the complete file including approvals, the response should be a query rather than a week of retrieval. That capability is designed in.
“Our inspection used to consume a fortnight of preparation. This time the auditors ran their own queries in the system and we spent two days. The system was the evidence.”
Insurance intermediaries and brokers
For insurance brokers and corporate agents the problems are different but the control requirement is similar: policy issuance and renewal tracking, commission reconciliation against insurer statements — an area of chronic under-recovery — claims assistance workflow, and IRDAI-aligned record-keeping.
Commission reconciliation is usually the highest-value module. Insurer statements are compared automatically against the policy record and the agreed commission structure, with variances flagged. Brokers who have never reconciled systematically are routinely surprised by the cumulative shortfall.
Every engagement starts with a conversation, not a proposal template.
Thirty minutes with a senior engineer. You leave with an architecture sketch and an honest cost range, whether or not you hire us.
What is actually included in bfsi & financial services
Each of these is something we have shipped and still support in production — not a list of things we could do if asked.
Loan origination
Digital application, e-KYC, bank statement analysis, bureau integration and parallel verification.
Underwriting engine
Configurable, versioned policy rules and scorecards with recommendations, not automated decisions.
Loan management
Disbursal, repayment schedules, NACH, restructuring, foreclosure and settlement handling.
Collections
Bucket-wise strategy, differentiated treatment, field allocation and geotagged outcome capture.
Control architecture
Transaction-level maker–checker, append-only audit, segregation of duties and access review.
Regulatory reporting
Classification, provisioning, ageing and statutory returns generated from the ledger.
Customer self-service
Statements, schedules, payments, documents and requests without a branch visit.
Insurance intermediary
Policy and renewal tracking, commission reconciliation and claims assistance workflow.
The stack we actually use for this
Chosen for what your team can maintain in three years, not for what looks impressive in a proposal.
Platform
- Node.js
- Java
- PostgreSQL
- React
- React Native
Verification
- Aadhaar e-KYC
- PAN validation
- Bureau APIs
- Penny drop
- Account aggregator
Payments
- NACH
- UPI Autopay
- Payment gateways
- Bank statement parsers
Controls
- Append-only audit store
- HSM/KMS
- RBAC
- Encryption at rest
From first conversation to something in production
Two-week slices, a demo you can share every alternate Friday, and no phase where you are waiting without seeing progress.
Control design with compliance
Roles, approval matrices and audit requirements defined by your compliance function first.
Policy encoding
Credit policy written down explicitly — often for the first time — and configured with versioning.
Origination build
Digital application, verification integrations and parallel processing.
Parallel operation
New process run alongside existing for a defined period with reconciliation.
Collections and reporting
Strategy configuration, field app rollout and statutory return generation.
Audit rehearsal
A simulated inspection before the real one, to verify evidence is retrievable.
The questions clients actually ask
Including the ones where the honest answer is that you may not need us. If your question is not here, call +91 70033 91355 — you will speak to an engineer, not a call handler.
No, and we say so clearly. We are technology builders. Your compliance function defines what the controls must be; we implement them provably and produce the evidence. We know the control patterns regulators expect and we will raise a concern if a requirement seems inconsistent with them, but the regulatory judgement stays with your compliance and legal advisers.
In India, by default and without exception for BFSI clients — either in an Indian cloud region or on-premise depending on your policy and regulator expectations. Encryption at rest and in transit, key management through a managed service or HSM, complete access logging, and retention configured to your regulatory obligation.
Yes, and it is done with the same discipline as any financial migration: parallel running with account-level reconciliation until balances, schedules and classifications match exactly, for a defined number of periods. Migration of active loan books requires particular care around accrued interest, restructured accounts and part-payments, and we allow proper time for it rather than compressing.
It produces a recommendation with the reasons, including any policy deviations, and a human decides on anything consequential. Fully automated approval is technically straightforward and we implement it only where the client has explicitly decided to, for defined low-value segments, with monitoring. Our default is that the system removes the delay, not the judgement.
Policy, classification and provisioning rules are configuration with versioning rather than code, so most changes are made by an authorised user with a record of what changed and when. Structural changes — a new return format, a changed classification framework — are handled under the support agreement. Versioning matters as much as changeability: you must be able to show what rule applied on a past date.
Origination live in fourteen to twenty weeks. Full loan management with collections and regulatory reporting is nine to fifteen months depending on product complexity and whether an existing book is being migrated. Control design with your compliance team happens first and is not compressed — it determines everything downstream.
Why being local to you matters here
Eastern India has a large cooperative banking and NBFC sector, much of it running on ageing systems with control environments that depend heavily on manual discipline. Modernisation is increasingly driven by regulatory expectation rather than commercial ambition, and the institutions that treat it as a control upgrade rather than a software purchase get better outcomes.
For BFSI and lending software in Kolkata, call +91 70033 91355 or WhatsApp us. The first conversation should include your compliance head.
Related industries we serve
View everythingTell us what is slowing your business down.
A 30-minute call with a senior engineer — not a salesperson. You leave with an architecture sketch and an honest cost range, whether or not you hire us.
Direct line
+91 70033 91355Mon–Sat · 9:30 AM – 7:30 PM IST · Sealdah, Kolkata