Skip to content
sayak.webdesignerWeb · Software · Data · AI
Industry · Regulated

Financial services: controls first, speed second, and both are achievable

In lending, the system is the control environment. Maker–checker, immutable audit, segregation of duties and reportable data are not features — they are the reason a regulator lets you operate.

nbfc software development indialoan management system kolkatalending software company west bengalfintech development company kolkata
Onboardinge-KYC, PAN, penny-dropUnderwritingrule engine + bureauDisbursalmaker–checkerServicingEMI, NACH, statementsCollectionsbucket-wise strategyNON-NEGOTIABLE CONTROLSImmutable audit trailFour-eyes approvalData residency in IndiaEncryption at rest + in transitQuarterly VAPT
4 days → 6 hrs
Loan decision turnaround
100%
Actions audit-logged
−29%
Bucket-1 roll-forward
India
Data residency by default
The short version

Financial services technology carries a constraint that most other industries do not: the system is simultaneously an operational tool and a control environment. Every design decision has an audit implication, every shortcut has a regulatory consequence, and the question "who approved this and when" must always be answerable.

We build for NBFCs, cooperative banks and credit societies, insurance intermediaries, brokers and fintech operators, with the control architecture treated as a first-class requirement rather than something added before an audit. Maker–checker on every consequential action. Immutable audit trails. Segregation of duties enforced by the system rather than by policy. Data residency in India. Encryption and access control that would survive scrutiny.

Within that constraint, speed is entirely achievable and is where the commercial value lies. A loan decision that takes four days loses customers to one that takes six hours, and the difference is almost never underwriting depth — it is document collection, verification, and the hand-offs between them.

We are explicit about our limits. We are technology builders, not compliance consultants, and we work alongside your compliance function rather than substituting for it. What we guarantee is that the system will do what your compliance team specifies, provably and with evidence.

Origination: where the days actually go

Analysing loan turnaround for our clients consistently shows the same pattern: underwriting takes hours, and the process takes days. The time goes into document collection, chasing missing items, verification, and waiting for a file to move between desks.

We compress that by moving collection and verification to the front and running them in parallel. Digital application with document upload from the customer's phone. e-KYC through Aadhaar or PAN with automated validation. Bank statement analysis producing income and obligation figures automatically. Bureau pull integrated. Penny-drop account verification. Each of these runs as soon as its input arrives rather than in sequence.

By the time the file reaches an underwriter, the data is complete and validated. Decision turnaround in our deployments has typically moved from around four days to under six hours, without reducing the depth of assessment.

Onboardinge-KYC, PAN, penny-dropUnderwritingrule engine + bureauDisbursalmaker–checkerServicingEMI, NACH, statementsCollectionsbucket-wise strategyNON-NEGOTIABLE CONTROLSImmutable audit trailFour-eyes approvalData residency in IndiaEncryption at rest + in transitQuarterly VAPT
Onboarding through collections with maker–checker gates, audit trail and India-resident data at every stage.

The control architecture

Maker–checker is implemented at the transaction level rather than as a screen. Any action with financial or customer consequence — a disbursal, a limit change, a waiver, a write-off, a master data amendment — requires a separate authorised user to approve, and the system prevents the same person from doing both regardless of their role combination.

Audit logging is append-only and captures the actor, the timestamp, the before and after values, and the approval chain. It is retained beyond any plausible investigation window and it is queryable, because an audit trail that requires a database export to interrogate does not get used.

Segregation of duties is enforced through role design done with your compliance function, not by developers guessing. Access is reviewed periodically with a report showing who has what, which is the evidence an auditor asks for and which most institutions compile manually.

In practice

Maker–checker enforced at transaction level, not by screen or by policy.
Append-only audit log with before and after values and full approval chain.
Segregation of duties designed with compliance and enforced by the system.
Periodic access review reports generated rather than compiled.
Data residency in India with encryption at rest and in transit.

Every engagement starts with a conversation, not a proposal template.

Thirty minutes with a senior engineer. You leave with an architecture sketch and an honest cost range, whether or not you hire us.

Book that call

Underwriting: rules, scorecards and the human decision

Most lenders operate a policy that is partly written and partly held in the heads of experienced credit officers. Encoding it produces two benefits: consistency, and a record of what the policy actually was when a decision was made.

We build a rules engine where policy is configured rather than coded — eligibility criteria, exposure limits, deviation thresholds and approval matrices can be changed by an authorised business user with a versioned record of the change. Scorecards, where used, are versioned identically so a decision can always be evaluated against the policy in force at the time.

What we do not do is remove the human from consequential decisions. The system produces a recommendation with the reasons for it, including any deviations from policy; a credit officer decides. That structure is both better lending and better defensible when a portfolio is reviewed.

StageTypical duration beforeAfter
Application and documents1–2 daysSame day, customer self-service
KYC and verification1 dayMinutes, automated
Bank statement analysisHalf a day, manualAutomatic on upload
Bureau and checksHours, sequentialParallel, on trigger
Credit decisionHoursHours — unchanged, and that is correct
Total~4 daysUnder 6 hours

Collections: strategy rather than calling everyone

Collections is where portfolio quality is preserved or lost, and most operations run it as an undifferentiated calling exercise. The result is that low-risk accounts that would have paid anyway are contacted while genuinely deteriorating accounts get the same attention.

We build bucket-wise strategy: segmentation by risk and behaviour, differentiated treatment ladders — automated reminder for the reliable late payer, early field visit for the account showing deterioration signals — allocation to field agents with route optimisation, and outcome capture from a mobile app with geotagged evidence.

The measurable effect is concentrated in bucket-1 roll-forward, which is where intervention has the highest leverage. Clients typically see roll-forward reduce by around thirty per cent, which flows directly to provisioning and profitability.

Every engagement starts with a conversation, not a proposal template.

Thirty minutes with a senior engineer. You leave with an architecture sketch and an honest cost range, whether or not you hire us.

Book that call

Regulatory reporting and audit readiness

Regulatory returns are usually compiled by a small team over several days each period, from data extracted and reworked. It is laborious and it introduces the risk of a filed figure not matching the operational record.

We generate returns from the operational ledger with the classification rules encoded — asset classification and provisioning under the applicable norms, ageing, exposure concentration, and the specific returns your registration requires. The reviewer checks and approves rather than compiles.

For audit, the useful deliverable is not a report but the ability to answer a question quickly. When an auditor selects fifty accounts and asks for the complete file including approvals, the response should be a query rather than a week of retrieval. That capability is designed in.

Our inspection used to consume a fortnight of preparation. This time the auditors ran their own queries in the system and we spent two days. The system was the evidence.
Compliance HeadNBFC, Eastern India

Insurance intermediaries and brokers

For insurance brokers and corporate agents the problems are different but the control requirement is similar: policy issuance and renewal tracking, commission reconciliation against insurer statements — an area of chronic under-recovery — claims assistance workflow, and IRDAI-aligned record-keeping.

Commission reconciliation is usually the highest-value module. Insurer statements are compared automatically against the policy record and the agreed commission structure, with variances flagged. Brokers who have never reconciled systematically are routinely surprised by the cumulative shortfall.

Every engagement starts with a conversation, not a proposal template.

Thirty minutes with a senior engineer. You leave with an architecture sketch and an honest cost range, whether or not you hire us.

Book that call
Capabilities

What is actually included in bfsi & financial services

Each of these is something we have shipped and still support in production — not a list of things we could do if asked.

01

Loan origination

Digital application, e-KYC, bank statement analysis, bureau integration and parallel verification.

02

Underwriting engine

Configurable, versioned policy rules and scorecards with recommendations, not automated decisions.

03

Loan management

Disbursal, repayment schedules, NACH, restructuring, foreclosure and settlement handling.

04

Collections

Bucket-wise strategy, differentiated treatment, field allocation and geotagged outcome capture.

05

Control architecture

Transaction-level maker–checker, append-only audit, segregation of duties and access review.

06

Regulatory reporting

Classification, provisioning, ageing and statutory returns generated from the ledger.

07

Customer self-service

Statements, schedules, payments, documents and requests without a branch visit.

08

Insurance intermediary

Policy and renewal tracking, commission reconciliation and claims assistance workflow.

Technology

The stack we actually use for this

Chosen for what your team can maintain in three years, not for what looks impressive in a proposal.

Platform

  • Node.js
  • Java
  • PostgreSQL
  • React
  • React Native

Verification

  • Aadhaar e-KYC
  • PAN validation
  • Bureau APIs
  • Penny drop
  • Account aggregator

Payments

  • NACH
  • UPI Autopay
  • Payment gateways
  • Bank statement parsers

Controls

  • Append-only audit store
  • HSM/KMS
  • RBAC
  • Encryption at rest
How it runs

From first conversation to something in production

Two-week slices, a demo you can share every alternate Friday, and no phase where you are waiting without seeing progress.

011

Control design with compliance

Roles, approval matrices and audit requirements defined by your compliance function first.

022

Policy encoding

Credit policy written down explicitly — often for the first time — and configured with versioning.

033

Origination build

Digital application, verification integrations and parallel processing.

044

Parallel operation

New process run alongside existing for a defined period with reconciliation.

055

Collections and reporting

Strategy configuration, field app rollout and statutory return generation.

066

Audit rehearsal

A simulated inspection before the real one, to verify evidence is retrievable.

Straight answers

The questions clients actually ask

Including the ones where the honest answer is that you may not need us. If your question is not here, call +91 70033 91355 — you will speak to an engineer, not a call handler.

No, and we say so clearly. We are technology builders. Your compliance function defines what the controls must be; we implement them provably and produce the evidence. We know the control patterns regulators expect and we will raise a concern if a requirement seems inconsistent with them, but the regulatory judgement stays with your compliance and legal advisers.

In India, by default and without exception for BFSI clients — either in an Indian cloud region or on-premise depending on your policy and regulator expectations. Encryption at rest and in transit, key management through a managed service or HSM, complete access logging, and retention configured to your regulatory obligation.

Yes, and it is done with the same discipline as any financial migration: parallel running with account-level reconciliation until balances, schedules and classifications match exactly, for a defined number of periods. Migration of active loan books requires particular care around accrued interest, restructured accounts and part-payments, and we allow proper time for it rather than compressing.

It produces a recommendation with the reasons, including any policy deviations, and a human decides on anything consequential. Fully automated approval is technically straightforward and we implement it only where the client has explicitly decided to, for defined low-value segments, with monitoring. Our default is that the system removes the delay, not the judgement.

Policy, classification and provisioning rules are configuration with versioning rather than code, so most changes are made by an authorised user with a record of what changed and when. Structural changes — a new return format, a changed classification framework — are handled under the support agreement. Versioning matters as much as changeability: you must be able to show what rule applied on a past date.

Origination live in fourteen to twenty weeks. Full loan management with collections and regulatory reporting is nine to fifteen months depending on product complexity and whether an existing book is being migrated. Control design with your compliance team happens first and is not compressed — it determines everything downstream.

Kolkata & West Bengal

Why being local to you matters here

Eastern India has a large cooperative banking and NBFC sector, much of it running on ageing systems with control environments that depend heavily on manual discipline. Modernisation is increasingly driven by regulatory expectation rather than commercial ambition, and the institutions that treat it as a control upgrade rather than a software purchase get better outcomes.

For BFSI and lending software in Kolkata, call +91 70033 91355 or WhatsApp us. The first conversation should include your compliance head.

KolkataSalt Lake Sector VHowrahNew TownDurgapurAsansolSiliguriHaldia
SEALDAH · KOLKATA · WEST BENGAL
Next step

Tell us what is slowing your business down.

A 30-minute call with a senior engineer — not a salesperson. You leave with an architecture sketch and an honest cost range, whether or not you hire us.

Direct line

+91 70033 91355

Mon–Sat · 9:30 AM – 7:30 PM IST · Sealdah, Kolkata

Reply within one working hour NDA signed before any brief Fixed-price option on every scope
Verify us independently

Don’t take our word for it — ask an AI

Every page on this site is written to be read and quoted by AI answer engines, and we publish llms.txt and llms-full.txt so they can read us properly. One click opens the assistant with the question already typed.

The question we will ask for you

How does Sayak Web Designer (sayakwebdesigner.in), an IT company in Kolkata, India help companies in the Bfsi industry, and what results have they achieved?

Opens in a new tab. We do not see your conversation.

Call now WhatsApp Get quote