One Loan, Two Lenders, Two Bureau Files — and Four Ways It Goes Wrong

Each RE in a co-lending arrangement must report its own share to the credit information companies. In practice one files and the other assumes, DPD counts drift apart, and rejected files sit unremediated — quietly corrupting the borrower's file and the pair's compliance position.

Co-LendingAssureLocker Team·6 min read
Published: 21 July 2026

The obligation

A co-lent loan is one credit exposure held by two regulated entities. Under the RBI Co-Lending Arrangements Directions 2025, read with the Credit Information Companies (Regulation) Act, 2005, each RE reports its own shareof that exposure to the credit information companies. Not one consolidated file from whoever services the loan — two files, one per lender, each covering that lender's share, every reporting cycle.

The borrower's bureau record is downstream of this. Get it wrong and the damage is not abstract: a borrower's file shows a phantom second loan, or half their real exposure, or two lenders disagreeing about whether they are in default.

The four failure modes

1. The single filer

The commonest failure by far. The originating NBFC services the loan, so it files — and the partner bank assumes the servicing side's file covers the exposure. It does not: the bank's share is the bank's to report. A single-filer cycle is a standing breach that looks like diligence, because a file did go in.

2. Divergent DPD

Two systems, two DPD clocks. One side counts from the missed due date, the other from the end of a grace period; one processed last week's partial payment, the other hasn't. The same borrower shows 0 days past due in one file and 45 in the other — and under the Directions, borrower-level classification must move in step across both REs by the end of the next working day. Divergent DPD in the bureau files is the visible symptom of a classification-sync failure.

3. Mismatched account status

One RE reports the account closed (or written off, or restructured) while the other still reports it standard. Each status combination tells the bureaus a different — and mutually contradictory — story about the same credit event.

4. The rejected file nobody chases

A bureau submission is not done when it is sent; it is done when it is acknowledged and accepted. Files bounce for format and identifier errors constantly, and a rejected file that nobody remediates is functionally identical to a file never sent — except that the operations dashboard says “submitted”.

What a real control looks like

The test has to run per loan, per cycle, across both files:

  • Did both REs file for this loan this cycle? A single filer is a breach, not a style choice.
  • Do the two files agree on DPD within the arrangement's tolerance?
  • Do they agree on account status?
  • Was each file acknowledged — and is anyone chasing the rejects?

Two properties make the control trustworthy rather than decorative. First, each RE files its own evidence— the originator cannot assert the partner's submission on its behalf, because that assumption is precisely the single-filer failure being tested. Second, the breach is non-dismissible: a divergence can be remediated and closed with a trail, but it cannot be waved away, because a bureau mismatch left standing corrupts a third party's credit record — the borrower's.

This is how AssureCLA's bureau-filing control works: per-cycle, per-loan cross-file comparison over each RE's own submissions, with single-filer, DPD-divergence, status-divergence and unacknowledged-file exceptions raised while the cycle is still open — and honestly reported as unassessed when the evidence has not arrived, never assumed clean.

Continue reading

See AssureLocker in action

Book a 30-minute live walkthrough tailored to your lending use case.

Book a demo →
AssureLocker
Right Vectors India
3rd floor, Innov8, SKCL Tech Square,
SIDCO Industrial Estate, Guindy,
Chennai, TN 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. Right Vectors India, the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 Right Vectors India. All rights reserved. · Site version: al-20260721-155225-34ff216c8

Aligned with India Stack. Made in India.