Co-Lending, Audit-Ready: A Quarter in the Life of a Bank–NBFC Pair

A hypothetical case study of one co-lending programme — how continuous, independent recomputation keeps operations informed on the day an exception opens, keeps the arrangement compliant while the window to fix it is still open, and hands internal teams, auditors and supervisors the same reproducible evidence trail.

Case StudyAssureLocker Team·10 min read
Published: 20 July 2026

The institutions, people and figures below are illustrative composites — a hypothetical programme built from the recurring operational patterns of Indian co-lending, not a real customer or a real supervisory action.

The Programme

A mid-size bank and an originating NBFC run a co-lending programme for MSME term loans under a Co-Lending Arrangement (CLA). The NBFC originates and services; the bank takes its agreed share of each loan. Under the RBI Co-Lending Directions 2025, the pair carries a precise set of standing obligations: each RE retains at least 10% of every individual loan on its own books, the partner's share must be reflected in both books within 15 calendar days of disbursement, all flows route through an escrow account, and borrower-level SMA/NPA classification must move in step across both lenders.

Before the assurance overlay, those obligations were managed the way most pairs manage them: a monthly spreadsheet reconciliation, email threads with attachments named FINAL_v3_revised.xlsx, and a quarter-end scramble whenever internal audit asked how the pair knew the retention floor held on every loan — not just on the sampled twenty.

What Changed: An Independent Overlay on a Monitored Cadence

The pair connected the programme to an independent assurance overlay. Each RE's records become hash-chained, append-only events; the overlay independently recomputes the split, on-book retention, blended rate, transfer clock, escrow reconciliation and classification consistency from those events — it does not take either lender's answer as the answer. Every control conclusion is sourced to the specific paragraph of the 2025 Directions it tests.

Crucially, the recomputation does not happen only when someone remembers to run it. The monitored cadence re-evaluates the live arrangement automatically: a new breach opens a finding and notifies both lenders' analysts; an unchanged book stays silent; a cured breach is superseded on the record — with the machine's own action written to the same immutable trail as everything else.

A Quarter, Three Catches

Week 3 — the transfer clock, caught while it could still be fixed

A batch of eleven loans disburses. Nine book cleanly at the bank within days. Two sit in a queue at the bank's end — invisible in the NBFC's systems, unremarkable in the bank's. On day twelve the overlay's transfer-window control flags both loans as approaching the 15-day limit. The finding lands with an owner and a remediation SLA, and both operations teams see the same excerpt: loan IDs, disbursement dates, days elapsed. The booking is completed on day fourteen. On the next cadence run the finding stops firing and is superseded automatically.

The alternative timeline is the one every co-lending ops team knows: the breach is discovered at month-end, after the window has expired — at which point the Directions are unambiguous about the consequence (the loan stays wholly with the originating RE), and the conversation is no longer operational but contractual.

Week 7 — classification divergence, surfaced the day it opened

A borrower slips. The NBFC's servicing system moves the account to SMA-1. The bank's book, fed by a monthly file, still shows standard. Borrower-level classification consistency is exactly the kind of obligation that fails quietly — each system is internally consistent; only the pairis wrong. The overlay's classification-sync control compares both sides on cadence and opens a CRITICAL, non-maskable finding the day the divergence appears. Both risk teams get the same view; the bank re-classifies; the finding is worked through its lifecycle — acknowledged, remediated, closed — with every transition recorded, by whom, from what state to what state.

Non-maskable matters here: a regulatory breach in this overlay cannot be dismissed as a false positive or averaged away inside a friendly composite score. There is no waiver state. A single 0–100 "compliance score" is deliberately rejected — a breach forces the status red until it is actually resolved.

Week 10 — an escrow line that appears twice

A repayment file is re-submitted after a bank holiday and one credit lands twice in the escrow reconstruction. The reconciliation control matches flows end-to-end — reference, loan, amount, date — and flags the duplicate rather than double-counting it. The break is worked and cleared in two days. Small on its own; the point is the pattern: the overlay catches the error class, not just the error instance, because every flow reconciles exactly, in integer minor units, under one rounding policy.

Then the Auditors Arrive

Quarter-end. Three different audiences ask three versions of the same question — and get answers from the same evidence spine.

AudienceThe questionWhat the trail answers
Internal audit"Show me every retention exception this quarter and who closed it."The findings register, loan-level, with each finding's owner, SLA, lifecycle transitions and the excerpt behind the conclusion — exportable, not reconstructed from inboxes.
Statutory auditor"How do I know this record wasn't edited after the fact?"Events are hash-chained and append-only; batch roots are anchored (hashes only — never deal data), and the anchor state is truthful: a pending anchor says PENDING, never a fake sequence.
Supervisory review"Reproduce the Q2 control results."Every control result reproduces from the same source events, pinned rule-pack version and inputs — the re-exported evidence pack carries a manifest hash, signed and verifiable offline.

The evidence-pack preparation that used to be a two-week collation exercise becomes an export. Not because anyone worked harder — because the evidence was produced by the controls as they ran, rather than assembled after the fact.

The Dual-Run: Trust, Then Verify, Then Agree

Neither lender is asked to take the overlay's figures on faith. In the dual-run, each RE submits its own computed splits; the overlay recomputes independently from the projected events and classifies any divergence per loan. Agreement, sustained over real data, is what earns the overlay its place — and where the books disagree, the divergence itself is the finding, with both sides looking at the same evidence rather than each other's spreadsheets.

Who Stays Informed, and Of What

RoleWhat they see, without asking anyone
Operations (both REs)New exceptions on the monitored cadence, with owners, SLAs and the evidence excerpt.
ComplianceControl status against each named obligation of the 2025 Directions; nothing maskable that shouldn't be.
Credit & riskClassification consistency across the pair, borrower-level, with divergence flagged the day it opens.
Internal & external auditThe findings register, the transition history and a reproducible evidence pack.
The counterpartyThe same shared conclusions — zone-isolated, so neither RE ever opens its private book to the other.

The Honest Boundary

The overlay is an independent technology layer, and only that. It does not originate, underwrite, price, or move funds; it does not decide what either lender should do about a finding; and it gives neither party access to the other's customer records or private book — controls read authorised zones but publish only shared conclusions with declared excerpts. Signals, reconciliation and evidence; the lenders own every decision.

That boundary is also why the trail is credible to the three audiences above: the layer that produces the evidence has no stake in what the evidence shows.

The Takeaway

Co-lending compliance fails quietly and gets discovered loudly — at month-end, at audit, or in a supervisory letter. The fix is not more reconciliation effort at quarter-end; it is continuous, independent recomputation with an evidence trail as a by-product. Informed on the day an exception opens. Compliant while the window to fix it is still open. Audit-ready because the audit answer already exists.

Continue reading

See AssureLocker in action

Book a 30-minute live walkthrough tailored to your lending use case.

Book a demo →
AssureLocker
Right Vectors India
3rd floor, Innov8, SKCL Tech Square,
SIDCO Industrial Estate, Guindy,
Chennai, TN 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. Right Vectors India, the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 Right Vectors India. All rights reserved. · Site version: al-20260721-155225-34ff216c8

Aligned with India Stack. Made in India.