AssureCLA — independent control assurance for co-lending

Two regulated entities can share a loan while operating from different books. AssureCLA independently recomputes the controls that must agree — minimum retention, blended rate, 15-day booking, escrow movements, CIC reporting and borrower-level asset classification — and turns mismatches or missing evidence into traceable findings.

A Technology Service Provider control overlay with no allegiances — independent of transaction execution and designed for joint reliance. Not a lender, LOS/LMS or payment operator: AssureCLA supplies reproducible evidence and exceptions; the regulated entities retain every lending, compliance and remediation decision.

Engine & rule pack · BuiltDemonstrated on adversarial synthetic arrangementsLive RE connectivity · Design-partner stage

The problem

Two sets of books, one set of obligations

Both REs compute the split, the rate and the borrower’s classification. Most days the numbers agree. The days they don’t are the days that matter at audit — and a spreadsheet reconciliation three weeks later finds them after the window to fix them has closed. Transaction systems are not designed to provide independent cross-party assurance: each keeps one side’s book, or executes the deal itself.

The outcome AssureCLA buys: exceptions surface with an owner, an SLA and a lifecycle — while the transfer window is still open. New breaches notify both REs’ analysts; cured ones supersede on the record; an unchanged book stays quiet. Passing controls remain recorded but do not generate alerts.

AssureCLA operator workspace — a co-lending arrangement under evaluation: RED overall status driven by two non-maskable breaches, five health indicators including an honest UNKNOWN

The workspace on a demo arrangement (sub-retention scenario) — product view. A breach the engine cannot un-see: RED, with the reasons and the basis.

Headline controls · RBI Co-Lending Directions, 2025

Six controls that decide an inspection

Express requirements cite the paragraph they enforce; AssureCLA’s derived evidence models are labelled as such. Missing mandatory data resolves to UNKNOWN — never to a pass. A non-maskable exception can be remediated with a trail, never dismissed.

CL-RET-01non-maskablePara 10

On-book retention

Each RE retains at least 10% of every individual loan — checked on both sides, recomputed through every balance movement. Ratio-correct programmes routinely fail loan by loan.

CL-TRF-03non-maskableDerived control supporting Para 22

15-day booking evidence

The Directions set the 15-calendar-day window; AssureCLA's derived evidence test verifies all four events landed inside it — disbursement, partner acceptance, reimbursement and the partner's core-ledger posting. A middleware acknowledgement is not a booking.

CL-COMMIT-01non-maskablePara 8, 21

Ex-ante commitment

The partner's irrevocable back-to-back commitment must pre-date disbursement, with the agreed terms version pinned at commitment. Post-origination partner selection fails the Directions (transfer only to the identified partner RE, Para 23).

CL-CLASS-01non-maskablePara 33

Classification convergence

Borrower-level SMA/NPA classification must converge across both REs, with information shared near real time and no later than the end of the next working day. Divergence is a critical, non-maskable exception.

CL-CLASS-02Para 31

Both-RE CIC reporting

Each RE reports its own share to the credit information companies. Single filers, divergent DPD, contradictory statuses and unacknowledged files are caught per cycle.

CL-ESC-03Derived control supporting Para 26

Escrow evidence completeness

All flows route through escrow (Para 26). AssureCLA's derived continuity test checks statement sequences and balance chaining; a gap indicates the reconciliation evidence may be incomplete, and the status holds at UNKNOWN until continuity is restored or independently explained.

The full pack runs 24 controls in three groups: core CLA Directions controls (retention, commitment, booking, blended rate — every borrower-payable fee or charge folded into the disclosed APR — escrow routing, CIC, classification, and DLG capped at 5% of outstanding, providable only by the originating RE under Para 32); referenced-regime controls (PSL Directions, MD-DLD, MD-TLE); and internal data-quality and evidence controls. Full technical control specification →

How it sits

Evidence in from every participant. Assurance out, jointly relied on.

Deployed under a common mandate approved by both REs. Each party files its own evidence — loan tapes, booking timestamps, classifications, CIC files, and the escrow bank’s own statements — and the control plane produces shared, reproducible assurance evidence that can accompany the asset record, kept on a tamper-evident, hash-chained record.

AssureCLA control plane: evidence from both REs, the escrow bank and the bureaus flows into an independent control plane, producing verdicts, exceptions and assurance packs

Integration path

Synthetic → file-based shadow run → controlled parallel run

1 · Synthetic

The engagement starts on adversarial synthetic arrangements shaped like yours — sub-retention, late bookings, bureau divergence, escrow gaps — so you see the controls fire before any of your data moves.

2 · File-based shadow run

Batch files your systems already produce — loan tapes (CSV/XLSX), bank statements (MT940/942, camt), CIC files. No integration project to begin; unmatched entries are reported, never dropped.

3 · Controlled parallel run

The engine runs beside your existing reconciliation and earns reliance as a parallel assurance control — divergence is classified per cycle, and reliance follows three consecutive agreeing cycles.

Next capability: AssurePool — pool-readiness screens, a frozen loan tape and post-close surveillance over the same evidence base, for DA/PTC transactions. Details →

The boundary

We assure the arrangement. We are not in it.

AssureCLA never initiates, executes or holds funds — settlement messages are advice-only — and never makes a credit decision. An architecture test in our build pipeline fails the software if money-movement or credit-decision capability appears in the co-lending source.

AssureCLA does not provide a statutory audit, legal opinion, certification of compliance or regulatory approval. Each RE remains responsible for its decisions, regulatory obligations, remediation and reporting.

Where this is today

Engine and 24-control rule pack built and adversarially tested · demonstrated end-to-end on synthetic arrangements · live RE connectivity at design-partner stage. An engagement starts with a paid delta report on one live programme and one completed period.

Findings and evidence only · the REs decide · no custody

AssureLocker
Right Vectors India
3rd floor, Innov8, SKCL Tech Square,
SIDCO Industrial Estate, Guindy,
Chennai, TN 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. Right Vectors India, the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 Right Vectors India. All rights reserved. · Site version: al-20260721-155225-34ff216c8

Aligned with India Stack. Made in India.