AssureCLA — independent control assurance for co-lending
Two regulated entities can share a loan while operating from different books. AssureCLA independently recomputes the controls that must agree — minimum retention, blended rate, 15-day booking, escrow movements, CIC reporting and borrower-level asset classification — and turns mismatches or missing evidence into traceable findings.
A Technology Service Provider control overlay with no allegiances — independent of transaction execution and designed for joint reliance. Not a lender, LOS/LMS or payment operator: AssureCLA supplies reproducible evidence and exceptions; the regulated entities retain every lending, compliance and remediation decision.
The problem
Two sets of books, one set of obligations
Both REs compute the split, the rate and the borrower’s classification. Most days the numbers agree. The days they don’t are the days that matter at audit — and a spreadsheet reconciliation three weeks later finds them after the window to fix them has closed. Transaction systems are not designed to provide independent cross-party assurance: each keeps one side’s book, or executes the deal itself.
The outcome AssureCLA buys: exceptions surface with an owner, an SLA and a lifecycle — while the transfer window is still open. New breaches notify both REs’ analysts; cured ones supersede on the record; an unchanged book stays quiet. Passing controls remain recorded but do not generate alerts.

The workspace on a demo arrangement (sub-retention scenario) — product view. A breach the engine cannot un-see: RED, with the reasons and the basis.
Headline controls · RBI Co-Lending Directions, 2025
Six controls that decide an inspection
Express requirements cite the paragraph they enforce; AssureCLA’s derived evidence models are labelled as such. Missing mandatory data resolves to UNKNOWN — never to a pass. A non-maskable exception can be remediated with a trail, never dismissed.
On-book retention
Each RE retains at least 10% of every individual loan — checked on both sides, recomputed through every balance movement. Ratio-correct programmes routinely fail loan by loan.
15-day booking evidence
The Directions set the 15-calendar-day window; AssureCLA's derived evidence test verifies all four events landed inside it — disbursement, partner acceptance, reimbursement and the partner's core-ledger posting. A middleware acknowledgement is not a booking.
Ex-ante commitment
The partner's irrevocable back-to-back commitment must pre-date disbursement, with the agreed terms version pinned at commitment. Post-origination partner selection fails the Directions (transfer only to the identified partner RE, Para 23).
Classification convergence
Borrower-level SMA/NPA classification must converge across both REs, with information shared near real time and no later than the end of the next working day. Divergence is a critical, non-maskable exception.
Both-RE CIC reporting
Each RE reports its own share to the credit information companies. Single filers, divergent DPD, contradictory statuses and unacknowledged files are caught per cycle.
Escrow evidence completeness
All flows route through escrow (Para 26). AssureCLA's derived continuity test checks statement sequences and balance chaining; a gap indicates the reconciliation evidence may be incomplete, and the status holds at UNKNOWN until continuity is restored or independently explained.
The full pack runs 24 controls in three groups: core CLA Directions controls (retention, commitment, booking, blended rate — every borrower-payable fee or charge folded into the disclosed APR — escrow routing, CIC, classification, and DLG capped at 5% of outstanding, providable only by the originating RE under Para 32); referenced-regime controls (PSL Directions, MD-DLD, MD-TLE); and internal data-quality and evidence controls. Full technical control specification →
How it sits
Evidence in from every participant. Assurance out, jointly relied on.
Deployed under a common mandate approved by both REs. Each party files its own evidence — loan tapes, booking timestamps, classifications, CIC files, and the escrow bank’s own statements — and the control plane produces shared, reproducible assurance evidence that can accompany the asset record, kept on a tamper-evident, hash-chained record.

Integration path
Synthetic → file-based shadow run → controlled parallel run
1 · Synthetic
The engagement starts on adversarial synthetic arrangements shaped like yours — sub-retention, late bookings, bureau divergence, escrow gaps — so you see the controls fire before any of your data moves.
2 · File-based shadow run
Batch files your systems already produce — loan tapes (CSV/XLSX), bank statements (MT940/942, camt), CIC files. No integration project to begin; unmatched entries are reported, never dropped.
3 · Controlled parallel run
The engine runs beside your existing reconciliation and earns reliance as a parallel assurance control — divergence is classified per cycle, and reliance follows three consecutive agreeing cycles.
Next capability: AssurePool — pool-readiness screens, a frozen loan tape and post-close surveillance over the same evidence base, for DA/PTC transactions. Details →
The boundary
We assure the arrangement. We are not in it.
AssureCLA never initiates, executes or holds funds — settlement messages are advice-only — and never makes a credit decision. An architecture test in our build pipeline fails the software if money-movement or credit-decision capability appears in the co-lending source.
AssureCLA does not provide a statutory audit, legal opinion, certification of compliance or regulatory approval. Each RE remains responsible for its decisions, regulatory obligations, remediation and reporting.
Where this is today
Engine and 24-control rule pack built and adversarially tested · demonstrated end-to-end on synthetic arrangements · live RE connectivity at design-partner stage. An engagement starts with a paid delta report on one live programme and one completed period.
Findings and evidence only · the REs decide · no custody
