Technical control specification
The full engineering detail behind AssureCLA, for technical evaluators. Express regulatory requirements cite their paragraph; AssureCLA-derived evidence models are labelled as derived. Nothing here changes the boundary: findings and evidence only — the REs decide.
The 24-control catalogue
Three groups, per the taxonomy on the product page. Every control is versioned data in a maker-checker-approved rule pack; each check run pins the pack version in force.
Core CLA Directions controls
| CL-RET-01 | Para 10 | Per-loan ≥10% retention on both REs, recomputed through every balance movement | non-maskable |
| CL-COMMIT-01 | Para 8, 21 (23) | Irrevocable back-to-back commitment pre-dates disbursement; terms version pinned; transfer only to the identified partner RE | non-maskable |
| CL-TRF-01 | Para 22, 24 | 15-calendar-day window; on expiry the loan stays wholly with the originating RE (MD-TLE only) | non-maskable |
| CL-TRF-02 | Para 24, 23 | Post-expiry the partner share is never booked under CLA treatment; transfer only to the named partner | non-maskable |
| CL-TRF-03 | Derived · supports Para 22 | Four-point booking evidence: disbursement, partner acceptance, reimbursement, core-ledger GL posting — each inside the window; mis-sequenced evidence fails | non-maskable |
| CL-RATE-01 | Para 17–19 | Single blended rate recomputed as the weighted average of each RE's rate by funding share | |
| CL-RATE-02 | Para 19, 14 | Every borrower-payable fee or charge folded into the disclosed APR on the KFS | non-maskable |
| CL-ESC-01 | Para 26 | All disbursements and repayments route through the escrow account | |
| CL-ESC-02 | Para 26, 25 | Escrow reconciliation: end-to-end ID → loan reference → amount/date; duplicates flagged | |
| CL-ESC-03 | Derived · supports Para 26 | Statement-series continuity (sequence + balance chaining); a gap holds the status at UNKNOWN until restored or independently explained | |
| CL-CLASS-01 | Para 33 | Borrower-level SMA/NPA convergence across both REs by end of next working day | non-maskable |
| CL-CLASS-02 | Para 31 | Each RE reports its own share to the CICs; single-filer, DPD/status divergence, unacknowledged files | non-maskable |
| CL-ID-01 | Para 25 | Paired individual borrower accounts present in BOTH REs' books; a single-book loan is a provable exception | non-maskable |
| CL-DLG-01 | Para 32 | DLG up to 5% of loans outstanding under the CLA, providable only by the originating RE | non-maskable |
| CL-DLG-02 | Para 20 + fn. 3 | No disguised credit enhancement through fee structures; implicit-guarantee detection | non-maskable |
| CL-DISC-01 | Para 35, 36 | Website partner listing + Notes-to-Accounts disclosure presence, per RE | |
| CL-DISC-02 | Para 11–14 | Agreement provisions: role segregation, single customer interface, grievance, info-exchange timeframe |
Referenced-regime controls (PSL Directions, MD-DLD, MD-TLE)
| CL-PSL-01 | CLA Para 15 | PSL claimable per-RE for its OWN share only — never the whole loan |
| CL-PSL-02 | PSL MD Para 5 | Exactly one of the eight eligible PSL categories per loan |
| CL-PSL-03 | PSL MD Para 7 | Aggregate book targets (40/18/7.5/12; UCB 60) evaluated on RE-supplied portfolio evidence |
| CL-PSL-04 | PSL MD Paras 9–16 | Per-category ceilings: education, housing by centre population, renewables, MSME start-ups, social infra |
| CL-PSL-05 | PSL MD Para 17.1 | Weaker-sections women-beneficiary ₹2 lakh cap (UCB-exempt) |
| CL-PSL-06 | PSL MD Para 1.2/4.3/26 | PSL status persists to repayment/maturity; premature de-tagging flagged |
Internal data-quality and evidence controls
| CL-DQ-01 | internal | Mandatory-input gate: missing data resolves to UNKNOWN, never to a pass |
Engineering model
Money that reconciles exactly
One money primitive in integer minor units to four decimal places, banker’s rounding as the single policy, largest-remainder apportionment — the parts always sum to the whole. No floats anywhere in computation.
Evidence formats
Bank statements: MT940/942 statements, MT900/910 advices, ISO 20022 camt.052/053/054 — one tag/XML grammar each, normalised to a canonical shape. Loan tapes: CSV/XLSX with all-or-nothing validation. APIs with HMAC-signed, retried, delivery-logged webhooks. Unmatched entries are counted and returned, never dropped.
Data zones
Originator-private, partner-private, shared and simulation zones. A control reads an authorised private zone but publishes only a shared conclusion with declared excerpts; sharing is decided per field. Each RE files its own evidence — enforced server-side on every intake path.
Tamper-evident record
Canonical events are hash-chained and append-only; corrections append, never overwrite. Batch roots are anchored on a tamper-evident, hash-chained record — cryptographic digests only, never deal data. Every result reproduces from the same events and pack version under a manifest hash.
Identity resolution
Deterministic exact keys first; a conservative fuzzy fallback that records its reason and confidence (composite fuzzy capped below certainty); ambiguity routed to an attributed human queue; human decisions survive engine re-runs; one partner record is never double-claimed.
Assurance in CI
An architecture test fails the build if fund-release, payment-execution, custody or credit-decision capability appears in the co-lending source. The adversarial suite attacks boundaries — malformed files, forged evidence, cross-arrangement access, frozen-record mutation — and every attack must fail loudly for the build to pass.
Operator workspace
Ten modules — Overview, Loans, Exceptions, Bureau (CIC), Governance, Disputes, Connector health, Evidence & Packs, Dual-run, API & Webhooks — each with a summary and exception-level drill-down; review journeys usable from a phone. The governance module tracks obligations and attestations: incomplete attestation prevents the AssureCLA readiness status being marked complete — the REs decide whether to activate the arrangement.
Inspection access
RE-authorised, read-only, time-boxed, scope-restricted access to that RE’s own shared record — watermarked, immutably logged, auto-expiring. Useful for internal audit, statutory audit and, at the RE’s instance, supervisory review.
AssurePool — pool assurance over the same evidence base
Pre-selection
Eligibility and holding-period screens (MHP tiering by tenor, standard-asset status, evidence presence). Verdict taxonomy separates hard exclusions from missing evidence from policy variance — unknown is never eligible.
Freeze & overrides
A frozen loan tape under a manifest hash — substitution after freeze requires a new, visibly distinct version. Overrides are attributed with reasons; regulatory exclusions cannot be overridden at all.
Post-close surveillance
Waterfall conservation checked in exact minor units; delinquency and credit-enhancement trigger states with honest unknowns; a missing reporting month is named as a gap. The transferee’s diligence remains non-outsourcable and its own.
AssureCLA does not provide a statutory audit, legal opinion, certification of compliance or regulatory approval. Each RE remains responsible for its decisions, regulatory obligations, remediation and reporting.