| Legal Name | Crestmont Capital Pvt. Ltd. |
| CIN | U65100WB1990PTC049122 |
| RBI Certificate of Registration | B.05.03608 |
| NBFC Category | Non-Deposit Taking Company – Investment Credit Company |
| Registered Office | EP-Y-16, Sector V, Kolkata, West Bengal 700091 |
| Corporate Office | Bengaluru, Karnataka, India |
| Website | www.crestmontcapital.in |
| Customer Care | service@crestmontcapital.in | 08031290850 |
| Grievance Officer | Nodal Grievance Redressal Officer |
| Grievance Contact | service@crestmontcapital.in |
- aReserve Bank of India (Digital Lending) Directions, 2025 and all subsequent amendments.
- bReserve Bank of India (Non-Banking Financial Companies – Responsible Business Conduct) Directions, 2025, updated directions and fair practices requirements applicable to NBFCs.
- cRBI directions on Key Facts Statement, Annual Percentage Rate, penal charges, grievance redressal, outsourcing, recovery agents, credit information reporting, KYC/AML, cyber security and customer protection.
- dCompanies Act, 2013, Information Technology Act, Digital Personal Data Protection framework, Contract Act, consumer protection laws and any other applicable law.
In case of inconsistency between this Policy and any binding regulatory requirement, the stricter requirement shall apply automatically. Management shall place such inconsistency before the Board or authorised committee for formal amendment at the earliest feasible meeting.
The purpose of this Policy is to establish a comprehensive, transparent, borrower-protective and regulator-ready framework for terms and conditions for digital lending of Crestmont Capital Pvt. Ltd. The Policy is designed for digital lending through Askrupee, website publication, internal governance, LSP/DLA control, audit review and Board oversight.
This Policy is deliberately detailed so that business, compliance, technology, recovery, customer service, legal and audit teams can operate from a common control framework and avoid informal practices that may create regulatory, conduct, data, customer protection or reputational risk.
- aAll directors, KMPs, employees and officers of the Company.
- bAll digital lending journeys, including Askrupee and any web/app/API channel.
- cAll outsourced service providers, LSPs, DLAs, collection agencies, technology vendors, call centres, API partners and processors.
- dAll borrowers, applicants, co-applicants, references and customer data subjects to the extent applicable.
- eAll loan lifecycle stages: marketing, application, KYC, underwriting, sanction, KFS, disbursement, servicing, repayment, collection, closure and complaint handling.
This section establishes detailed operating expectations for scope and operating principles under the Crestmont Capital Pvt. Ltd. policy framework. It shall be implemented through SOPs, system controls, employee training, LSP contractual obligations and periodic compliance testing.
- aThis Policy applies to the Company, its directors, employees, officers, consultants, LSPs, DLAs, vendors and any person acting for or on behalf of the Company.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline. - bThe Policy is intended to ensure governance discipline, compliance ownership, transparent customer outcomes and auditable control environment.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline. - cAny exception shall require written justification, approval and retrospective reporting.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline. - dWhere this Policy refers to digital lending, it includes Askrupee and any related website, app, API, partner or customer interface.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
Operational Procedure
- 1Step 1: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 2Step 2: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 3Step 3: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 4Step 4: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 5Step 5: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 6Step 6: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
This section establishes detailed operating expectations for control requirements under the Crestmont Capital Pvt. Ltd. policy framework. It shall be implemented through SOPs, system controls, employee training, LSP contractual obligations and periodic compliance testing.
- aThe Company shall maintain maker-checker approval, access controls, periodic review, audit logs and documented evidence.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline. - bOutsourcing shall not dilute regulatory responsibility.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline. - cAll customer-impacting processes shall be tested for fairness, disclosure and consent.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline. - dMaterial issues shall be reported to senior management and the Board.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
Operational Procedure
- 1Step 1: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 2Step 2: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 3Step 3: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 4Step 4: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 5Step 5: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 6Step 6: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
This section establishes detailed operating expectations for prohibited actions under the Crestmont Capital Pvt. Ltd. policy framework. It shall be implemented through SOPs, system controls, employee training, LSP contractual obligations and periodic compliance testing.
- aNo employee or partner shall bypass approved SOPs.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline. - bNo communication shall misrepresent RBI approval.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline. - cNo undisclosed fee shall be charged.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline. - dNo borrower data shall be used beyond approved purposes.
Implementation standard: the responsible owner shall map this requirement to system screens, SOP steps, evidence records, maker-checker approval, exception logs and periodic MIS. Any deviation shall be documented with root cause, customer impact, corrective action and closure timeline.
Operational Procedure
- 1Step 1: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 2Step 2: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 3Step 3: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 4Step 4: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 5Step 5: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
- 6Step 6: The process owner shall ensure that the relevant transaction, customer communication, approval or control event is recorded with adequate evidence, date/time stamp, responsible user and supervisory review. Where the step is performed by an LSP/DLA/vendor, the Company shall retain contractual audit rights and operational logs.
Board Ownership
The Board shall own this Policy, approve material changes, monitor management implementation and ensure that the Company does not operate any product, channel or partner arrangement in a manner inconsistent with RBI directions. The Board may delegate day-to-day monitoring to a committee or senior management; however, regulatory accountability remains with the Company.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Management Responsibility
Senior management shall convert this Policy into SOPs, process notes, system controls, maker-checker workflows, vendor obligations, employee training, audit programmes and exception reporting. Each business owner shall ensure that operational teams and LSPs follow the approved policy without informal deviations.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Three Lines of Defence
The first line shall operate the process, the second line comprising compliance/risk/legal shall independently review design and exceptions, and the third line comprising internal audit shall test adequacy and effectiveness. Material gaps shall be escalated with corrective action timelines.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Policy Review
This Policy shall be reviewed at least yearly and earlier upon any RBI circular, product change, technology change, LSP onboarding, adverse audit observation, material complaint trend, data incident or Board direction.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Customer-first Standards
All borrower communication shall be transparent, fair, non-misleading and in a language understood by the borrower. The customer shall not be pressurised through dark patterns, hidden charges, pre-selected options, forced consent or difficult exit flows.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Disclosure Standards
The Company shall disclose lender identity, NBFC status, non-deposit taking nature, product terms, interest, APR, fees, taxes, penal charges, cooling-off rights, grievance contacts, LSP/DLA involvement and repayment schedule before loan acceptance.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Consent Standards
Consent must be specific, informed, purpose-linked, revocable where permissible, separately recorded and preserved in a retrievable audit trail. Bundled consent or silence shall not be treated as valid consent for sensitive actions.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Vulnerable Borrowers
Teams shall exercise additional care for borrowers who appear distressed, financially vulnerable, digitally inexperienced, elderly or otherwise unable to understand consequences. Such borrowers shall not be pushed into repeat loans or refinancing merely for collection targets.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Digital Lending App Governance
Askrupee and any other DLA shall be governed as a regulated digital lending interface of the Company. The app journey shall not misrepresent approval status, conceal charges, access prohibited device data or allow LSPs to control loan decisions outside Company-approved rules.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Fund-flow Control
Loan disbursement and repayment must flow directly between the Company and borrower/end-beneficiary except as expressly permitted. LSP pool accounts, pass-through accounts or informal collections are not permitted.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
LSP Accountability
The Company remains responsible for outsourced activities. Every LSP shall be subject to due diligence, contract controls, customer conduct obligations, data processing restrictions, audit rights, complaint reporting, termination rights and periodic performance review.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Prohibited Data Access
The app shall not access contact list, call logs, file/media, telephony functions or other intrusive device resources. Any camera, microphone or location access shall be one-time or need-based, disclosed clearly and supported by consent.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Record Keeping
The Company shall maintain records of applications, KYC, bureau pulls, underwriting outputs, KFS, consent logs, sanction terms, disbursement, repayment, complaints, recovery actions, notices, settlement, closure and audit trails for the prescribed retention period.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception for this clause through system records, policy attestations, MIS and audit trail.
Evidence Quality
Every important customer action shall be evidenced through timestamp, user identifier, IP/device metadata where lawful, document hash/version, OTP/e-sign trail, communication log and maker-checker approval as applicable.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception for this clause through system records, policy attestations, MIS and audit trail.
MIS and Exception Reporting
Monthly MIS shall include loan volumes, pricing, complaints, TAT, recovery exceptions, LSP breaches, data incidents, cooling-off cancellations, NPA movement, write-offs, fraud alerts and regulatory exceptions.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
Audit Readiness
Policies, SOPs, logs, Board approvals, contracts, training records, system screenshots and exception closures shall be maintained in a form suitable for statutory audit, internal audit, RBI inspection and management review.
- aControl expectation 1: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- bControl expectation 2: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- cControl expectation 3: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
- dControl expectation 4: the responsible owner shall evidence design, operation, maker-checker review and exception closure for this clause through system records, policy attestations, MIS and audit trail.
| Control Point | Minimum Standard | Owner | Frequency | Evidence |
|---|---|---|---|---|
| Governance owner identified | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| Customer disclosure completed before consent | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| Maker-checker approval applied | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| Digital audit trail maintained | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| LSP activity monitored | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| Complaint impact assessed | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| Data privacy and security control mapped | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| Exception and breach escalation defined | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| Board/committee reporting enabled | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| Website/app publication requirement confirmed | Required control | Business / Compliance / Technology as applicable | Monthly or event-based | Policy, SOP, system log, screenshot, MIS and approval note |
| Risk | Rating | Mitigation |
|---|---|---|
| Mis-selling / inadequate disclosure | Medium/High | KFS, APR, terms, cooling-off and website disclosure before acceptance |
| LSP misconduct | High | Due diligence, contract, training, monitoring and termination rights |
| Data over-collection | High | Need-based data collection, no prohibited permissions, consent logs |
| Coercive recovery | High | Approved scripts, agent training, complaint monitoring and disciplinary action |
| Wrong fund flow | Critical | Direct RE-borrower fund flow and reconciliation |
| Unapproved pricing/charges | High | Board-approved pricing grid and KFS validation |
| Unresolved grievances | High | 30-day escalation and RBI Ombudsman disclosure |
- 1Checklist item 1: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 2Checklist item 2: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 3Checklist item 3: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 4Checklist item 4: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 5Checklist item 5: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 6Checklist item 6: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 7Checklist item 7: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 8Checklist item 8: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 9Checklist item 9: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 10Checklist item 10: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 11Checklist item 11: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 12Checklist item 12: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 13Checklist item 13: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 14Checklist item 14: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
- 15Checklist item 15: Confirm that the policy requirement is reflected in customer journey, back-office system, lender/LSP contract, website disclosure, employee training, MIS, exception reporting and audit working papers. The compliance team shall mark the item as Complied / Not Applicable / Gap Identified with remarks.
| Particular | Policy Position / Control Requirement |
|---|---|
| Policy owner | Compliance / Business Head as relevant |
| Recommending authority | Managing Director / CEO / Compliance Head |
| Approving authority | Board of Directors |
| Review cycle | Yearly and event-based |
| Exception approval | Board / authorised committee, with reasons recorded |
The above annexure forms an integral part of this Policy and shall be used by management, audit, compliance and operations teams for implementation testing and evidence collection.
| Particular | Policy Position / Control Requirement |
|---|---|
| No public deposit acceptance | Website and app must not imply deposit acceptance. |
| No RBI endorsement statement | RBI registration cannot be shown as product approval. |
| No LSP fee from borrower | LSP fee shall be paid by the Company. |
| No prohibited mobile data | No contacts, call logs, file/media or telephony access. |
| No coercive recovery | No threats, harassment, public shaming or misleading criminal consequences. |
| No automatic limit increase | No limit enhancement without borrower request and assessment. |
The above annexure forms an integral part of this Policy and shall be used by management, audit, compliance and operations teams for implementation testing and evidence collection.