Live Instant personal loans up to ₹20,000 — No collateral needed. Apply via askrupee.com →
Navigate
🏠 Home ℹ️ About Us 📖 Our Story 🛡️ Grievance 📞 Contact
Core Policies
🔒 Privacy Policy 📋 Terms & Conditions ⚖️ Fair Practice Code 🛡️ Grievance Redressal Policy 📊 Interest Rate & Charges ↩️ Refund & Cancellation
Lending & Operations
🤝 Collection & Recovery 📱 Digital Lending (DLA/LSP) 🔗 Outsourcing & LSP 📈 Credit Assessment 📄 KFS & Customer Disclosure 🏦 DLG / FLDG Policy
Compliance & Governance
💻 IT & Cyber Security 🆔 KYC, AML & CFT 🔐 Fraud Risk Management 📑 CIC & Credit Reporting 🏛️ Corporate Governance 🔍 Statutory Auditors 📢 Whistleblower Policy 🌟 Ethics & Code of Conduct 💚 CSR Policy 🌐 Website Disclosure
More
📱 askrupee.com — Apply for Loan ✍️ Blog 🤝 Lending Partners
🔒 Data Protection · RBI Digital Lending Directions, 2025 · DPDP Framework

Privacy & Data Protection Policy

Crestmont Capital Pvt. Ltd.'s comprehensive framework governing borrower data collection, sharing, security and rights — aligned with RBI Digital Lending Directions 2025 and the Digital Personal Data Protection framework.

Policy CodeATFPL/PDP/2026-27/05
Version1.0
Board Approval Date31-07-2026
Effective Date31-07-2026
Review FrequencyYearly and event-based
Approving AuthorityBoard of Directors
Applicable ChannelAskrupee
NBFC StatusNon-Deposit Taking Company – Investment Credit Company
📄 View Policy Document
01 Document Control and Company Particulars
Legal NameCrestmont Capital Pvt. Ltd.
CINU65100WB1990PTC049122
RBI Certificate of RegistrationB.05.03608
NBFC CategoryNon-Deposit Taking Company – Investment Credit Company
Registered OfficeEP-Y-16, Sector V, Kolkata, West Bengal 700091
Corporate OfficeBengaluru, Karnataka, India
Websitewww.crestmontcapital.in
Customer Careservice@crestmontcapital.in | 08031290850
Grievance OfficerNodal Grievance Redressal Officer
Grievance Contactservice@crestmontcapital.in
ℹ️
Crestmont Capital Pvt. Ltd. is a non-deposit taking NBFC. The Company does not accept public deposits.
02 Regulatory References
  • aReserve Bank of India (Digital Lending) Directions, 2025 and all subsequent amendments.
  • bReserve Bank of India (Non-Banking Financial Companies – Responsible Business Conduct) Directions, 2025, updated directions and fair practices requirements applicable to NBFCs.
  • cRBI directions on Key Facts Statement, Annual Percentage Rate, penal charges, grievance redressal, outsourcing, recovery agents, credit information reporting, KYC/AML, cyber security and customer protection.
  • dCompanies Act, 2013, Information Technology Act, Digital Personal Data Protection framework, Contract Act, consumer protection laws and any other applicable law.

In case of inconsistency between this Policy and any binding regulatory requirement, the stricter requirement shall apply automatically. Management shall place such inconsistency before the Board or authorised committee for formal amendment at the earliest feasible meeting.

03 Purpose and Philosophy

The purpose of this Policy is to establish a comprehensive, transparent, borrower-protective and regulator-ready framework for privacy and data protection of Crestmont Capital Pvt. Ltd. The Policy is designed for digital lending through Askrupee, website publication, internal governance, LSP/DLA control, audit review and Board oversight.

This Policy is deliberately detailed so that business, compliance, technology, recovery, customer service, legal and audit teams can operate from a common control framework and avoid informal practices that may create regulatory, conduct, data, customer protection or reputational risk.

04 Applicability and Scope
  • aAll directors, KMPs, employees and officers of the Company.
  • bAll digital lending journeys, including Askrupee and any web/app/API channel.
  • cAll outsourced service providers, LSPs, DLAs, collection agencies, technology vendors, call centres, API partners and processors.
  • dAll borrowers, applicants, co-applicants, references and customer data subjects to the extent applicable.
  • eAll loan lifecycle stages: marketing, application, KYC, underwriting, sanction, KFS, disbursement, servicing, repayment, collection, closure and complaint handling.
05 Data Collection

This section establishes detailed operating expectations for data collection under the Crestmont Capital Pvt. Ltd. policy framework. It shall be implemented through SOPs, system controls, employee training, LSP contractual obligations and periodic compliance testing.

  • aData collected: Detailed borrower data fields as per live app flow — need-based, purpose-specific and documented.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
  • bCollection shall be need-based, purpose-specific and consent-backed.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
  • cNo prohibited device permissions shall be taken.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
  • dBorrower must be able to view key data practices.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.

Operational Procedure

  1. 1The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  2. 2The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  3. 3The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  4. 4The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  5. 5The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  6. 6The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
📋
Minimum Evidence Pack: Policy approval and version history · Customer-facing screenshot or template · Consent/audit log · MIS extract · Exception register · Training record · Internal audit/compliance review note · Corrective action tracker
06 Data Sharing and Processors

This section establishes detailed operating expectations for data sharing and processors under the Crestmont Capital Pvt. Ltd. policy framework. It shall be implemented through SOPs, system controls, employee training, LSP contractual obligations and periodic compliance testing.

  • aProcessors/API partners: Third-party processors and API partners as applicable to the Askrupee lending journey.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
  • bData sharing shall be contractual, limited and auditable.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
  • cData shall be stored in India.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
  • dDeletion/forget workflow: Borrower data deletion/forget request workflow to be enabled, subject to statutory/regulatory retention requirements.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.

Operational Procedure

  1. 1The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  2. 2The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  3. 3The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  4. 4The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  5. 5The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  6. 6The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
📋
Minimum Evidence Pack: Policy approval and version history · Customer-facing screenshot or template · Consent/audit log · MIS extract · Exception register · Training record · Internal audit/compliance review note · Corrective action tracker
07 Security and Breach

This section establishes detailed operating expectations for security and breach under the Crestmont Capital Pvt. Ltd. policy framework. It shall be implemented through SOPs, system controls, employee training, LSP contractual obligations and periodic compliance testing.

  • aIncident owner: Incident response owner / CISO / CTO / Compliance Officer as designated by management.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
  • bIncidents shall be classified, contained, investigated and reported as required.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
  • cAccess shall be role-based and logged.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
  • dPrivacy impact shall be reviewed for app changes.
    Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.

Operational Procedure

  1. 1The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  2. 2The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  3. 3The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  4. 4The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  5. 5The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
  6. 6The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
📋
Minimum Evidence Pack: Policy approval and version history · Customer-facing screenshot or template · Consent/audit log · MIS extract · Exception register · Training record · Internal audit/compliance review note · Corrective action tracker
08 Governance

Board Ownership

The Board shall own this Policy, approve material changes, monitor management implementation and ensure that the Company does not operate any product, channel or partner arrangement in a manner inconsistent with RBI directions. The Board may delegate day-to-day monitoring to a committee or senior management; however, regulatory accountability remains with the Company.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Management Responsibility

Senior management shall convert this Policy into SOPs, process notes, system controls, maker-checker workflows, vendor obligations, employee training, audit programmes and exception reporting. Each business owner shall ensure that operational teams and LSPs follow the approved policy without informal deviations.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Three Lines of Defence

The first line shall operate the process, the second line comprising compliance/risk/legal shall independently review design and exceptions, and the third line comprising internal audit shall test adequacy and effectiveness. Material gaps shall be escalated with corrective action timelines.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Policy Review

This Policy shall be reviewed at least yearly and earlier upon any RBI circular, product change, technology change, LSP onboarding, adverse audit observation, material complaint trend, data incident or Board direction.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
09 Customer

Customer-first Standards

All borrower communication shall be transparent, fair, non-misleading and in a language understood by the borrower. The customer shall not be pressurised through dark patterns, hidden charges, pre-selected options, forced consent or difficult exit flows.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Disclosure Standards

The Company shall disclose lender identity, NBFC status, non-deposit taking nature, product terms, interest, APR, fees, taxes, penal charges, cooling-off rights, grievance contacts, LSP/DLA involvement and repayment schedule before loan acceptance.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Consent Standards

Consent must be specific, informed, purpose-linked, revocable where permissible, separately recorded and preserved in a retrievable audit trail. Bundled consent or silence shall not be treated as valid consent for sensitive actions.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Vulnerable Borrowers

Teams shall exercise additional care for borrowers who appear distressed, financially vulnerable, digitally inexperienced, elderly or otherwise unable to understand consequences. Such borrowers shall not be pushed into repeat loans or refinancing merely for collection targets.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
10 Digital

Digital Lending App Governance

Askrupee and any other DLA shall be governed as a regulated digital lending interface of the Company. The app journey shall not misrepresent approval status, conceal charges, access prohibited device data or allow LSPs to control loan decisions outside Company-approved rules.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Fund-flow Control

Loan disbursement and repayment must flow directly between the Company and borrower/end-beneficiary except as expressly permitted. LSP pool accounts, pass-through accounts or informal collections are not permitted.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

LSP Accountability

The Company remains responsible for outsourced activities. Every LSP shall be subject to due diligence, contract controls, customer conduct obligations, data processing restrictions, audit rights, complaint reporting, termination rights and periodic performance review.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Prohibited Data Access

The app shall not access contact list, call logs, file/media, telephony functions or other intrusive device resources. Any camera, microphone or location access shall be one-time or need-based, disclosed clearly and supported by consent.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
11 Records

Record Keeping

The Company shall maintain records of applications, KYC, bureau pulls, underwriting outputs, KFS, consent logs, sanction terms, disbursement, repayment, complaints, recovery actions, notices, settlement, closure and audit trails for the prescribed retention period.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Evidence Quality

Every important customer action shall be evidenced through timestamp, user identifier, IP/device metadata where lawful, document hash/version, OTP/e-sign trail, communication log and maker-checker approval as applicable.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

MIS and Exception Reporting

Monthly MIS shall include loan volumes, pricing, complaints, TAT, recovery exceptions, LSP breaches, data incidents, cooling-off cancellations, NPA movement, write-offs, fraud alerts and regulatory exceptions.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.

Audit Readiness

Policies, SOPs, logs, Board approvals, contracts, training records, system screenshots and exception closures shall be maintained in a form suitable for statutory audit, internal audit, RBI inspection and management review.

  • 1The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 2The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 3The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
  • 4The responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
12 Detailed Control Matrix
Control PointMinimum StandardOwnerFrequencyEvidence
Governance owner identifiedRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
Customer disclosure completed before consentRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
Maker-checker approval appliedRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
Digital audit trail maintainedRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
LSP activity monitoredRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
Complaint impact assessedRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
Data privacy and security control mappedRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
Exception and breach escalation definedRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
Board/committee reporting enabledRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
Website/app publication requirement confirmedRequired controlBusiness / Compliance / Technology as applicableMonthly or event-basedPolicy, SOP, system log, screenshot, MIS and approval note
13 Regulatory Risk and Mitigation Register
RiskRatingMitigation
Mis-selling / inadequate disclosureMedium/HighKFS, APR, terms, cooling-off and website disclosure before acceptance
LSP misconductHighDue diligence, contract, training, monitoring and termination rights
Data over-collectionHighNeed-based data collection, no prohibited permissions, consent logs
Coercive recoveryHighApproved scripts, agent training, complaint monitoring and disciplinary action
Wrong fund flowCriticalDirect NBFC-borrower fund flow and reconciliation
Unapproved pricing/chargesHighBoard-approved pricing grid and KFS validation
Unresolved grievancesHigh30-day escalation and RBI Ombudsman disclosure
14 SOP Checklist for Implementation

Each checklist item below requires the compliance team to confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. Each item shall be marked as Complied / Not Applicable / Gap Identified with remarks.

  • 1Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 2Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 3Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 4Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 5Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 6Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 7Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 8Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 9Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 10Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 11Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 12Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 13Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 14Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
  • 15Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers.
15 Approval Matrix
ParticularPolicy Position / Control Requirement
Policy ownerCompliance / Business Head as relevant
Recommending authorityManaging Director / CEO / Compliance Head
Approving authorityBoard of Directors
Review cycleYearly and event-based
Exception approvalBoard / authorised committee, with reasons recorded

The above annexure forms an integral part of this Policy and shall be used by management, audit, compliance and operations teams for implementation testing and evidence collection.

16 RBI-Safe Exclusion List
ParticularPolicy Position / Control Requirement
No public deposit acceptanceWebsite and app must not imply deposit acceptance.
No RBI endorsement statementRBI registration cannot be shown as product approval.
No LSP fee from borrowerLSP fee shall be paid by the Company.
No prohibited mobile dataNo contacts, call logs, file/media or telephony access.
No coercive recoveryNo threats, harassment, public shaming or misleading criminal consequences.
No automatic limit increaseNo limit enhancement without borrower request and assessment.

The above annexure forms an integral part of this Policy and shall be used by management, audit, compliance and operations teams for implementation testing and evidence collection.

Regulatory Notice: Crestmont Capital Pvt. Ltd. is registered with the Reserve Bank of India as a Non-Deposit Taking NBFC-ICC (CoR: B.05.03608). RBI registration is not an endorsement of the Company's products or services.