What an Auditor-Ready Co-Lending Evidence Dossier Should Contain

A monthly MIS extract is not an audit proof package. Discover the seven critical components required in a stamped Evidence Dossier to satisfy risk committees, statutory auditors, and regulatory inspectors.

Co-Lending ComplianceAssureLocker Team·7 min read
Published: 26 July 2026

The Shift from MIS Spreadsheets to Auditor-Ready Proof

Historically, co-lending partners exchanged monthly Excel spreadsheets summarizing loan balances, interest collections, and DPD statuses. Under the RBI Co-Lending Directions 2025, spreadsheets no longer satisfy audit requirements. Regulatory inspectors expect verifiable, source-linked evidence proving that retention ratios, booking windows, blended interest rates, escrow flows, and CIC filings agreed on a loan-by-loan basis.

An Evidence Dossier is a stamped, single-click audit package compiled from underlying transaction logs and raw system events. Here are the 7 non-negotiable components an auditor-ready dossier must contain.

1. Executive Score & Status

The dossier must lead with a clear executive verdict and an Evidence Confidence Score (ECS) (ranging from 0 to 100). The overall status is color-coded based on deterministic severity:

  • GREEN: All mandatory controls pass, evidence coverage is complete, and no non-maskable exceptions exist.
  • AMBER: Minor operational gaps exist (e.g. pending document upload within SLA) but mandatory RBI requirements hold.
  • RED: One or more non-maskable breaches exist (e.g. sub-10% retention, 15-day booking window breach, or classification divergence).

2. Evidence Confidence Factors

The Evidence Confidence Score cannot be a black-box AI output. It must be computed transparently from five explainable factors:

  1. Loan & Tape Completeness: Percentage of mandatory field populations across both RE loan tapes.
  2. Connector Data Coverage: Presence of raw webhooks and statement files from escrow banks and CICs.
  3. Control Exception Burden: Deductions for open findings weighted by severity.
  4. Remediation SLA Health: Track record of resolving exceptions within agreed SLA windows.
  5. Audit Trail Integrity: Cryptographic verification of event sequence continuity.

3. Control Findings & Non-Maskable Exceptions

Every exception in the dossier must cite its exact regulatory or derived basis (e.g. CL-RET-01: Para 10 Minimum Retention or CL-TRF-03: Derived 15-Day Booking Evidence). Critical breaches must be flagged as non-maskable, meaning they cannot be hidden or overridden without an explicit audit trail.

4. Remediation SLA Rail State

Auditors examine how mismatches were handled. The dossier includes a Remediation SLA table detailing every open and resolved finding, assigned joint owners, SLA due dates, evidence submissions, and approval sign-offs.

5. Connector & Product-Evidence Coverage

The dossier lists the active intake shims and evidence pipelines (e.g. Yubi/M2P lifecycle webhooks, Finacle/T24 loan tapes, CIBIL/Experian CIC files, MT940 escrow bank feeds). A missing connector feed automatically flags affected controls as UNKNOWN rather than passing them.

6. Event Hash-Chain & Manifest Proof

To prevent post-facto tampering, every evidence ingestion, control evaluation, and commentary update is recorded on an append-only, hash-chained log. The dossier includes the audit proof sequence range, latest block hash, and manifest hash so external auditors can verify data integrity.

7. Explicit Scope Boundary & Caveats

An honest Evidence Dossier clearly states what it is not: it is not a statutory audit, legal opinion, credit decision, or fund-flow record. The regulated entities retain full responsibility for lending policies, regulatory reporting, and credit underwriting.

8. Review Gates for Public and Committee Claims

A modern dossier should also state what has been reviewed, and what has not. AssureCLA now keeps this separate through deterministic review gates: benchmark packets require an exact manifest-hash sign-off, product-control packs show approval and source-provenance status, and connector matrices distinguish built/tested shims from sandbox or credential-dependent integrations.

This matters because a risk committee can rely on the evidence packet without mistaking a demo-ready control pack for a production-certified regulatory interpretation, or a named adapter shim for an official third-party integration.

Export Branded Evidence Dossiers with AssureCLA

Generate single-click stamped PDF and JSON dossier packages for your risk committee and inspection workflows.

Learn More About AssureCLA

Continue reading

See AssureLocker in action

Book a 30-minute live walkthrough tailored to your lending use case.

Book a demo →
AssureLocker
AssureLocker Pvt Ltd. (inc. in progress)
3rd floor, Innov8, SKCL Tech Square, SIDCO Industrial Estate, Guindy,
Chennai, Tamil Nadu 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. AssureLocker Pvt Ltd. (inc. in progress), the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 AssureLocker Pvt Ltd.. All rights reserved. · Site version: al-20260905-192031-5156ce245