Risk and compliance, built into every stage of the lifecycle
RBI-compliant lending services, including debt collection, for NBFCs and banks start with controls, not promises. We build the rules you work under into every stage we run, from borrower acquisition to recovery, so the evidence exists before anyone asks for it.
Visible accountability.
The lender
Credit decision · Pricing · Loan contract
Regulatory responsibility stays with you.Rinncrest
Operations to your policy, with records you can inspect.
Does using an LSP transfer the lender's responsibility?
No. When a lender engages a Lending Service Provider, it stays fully responsible to RBI and to its borrowers for the work the LSP performs. RBI expects the lender to carry out enhanced due diligence on the LSP, to monitor what it does and to be able to audit it.
That holds at every stage an LSP touches, from the offer a borrower sees to the last recovery call. The exposure is highest in collections, where one call made at the wrong hour, or in the wrong words, becomes a complaint against the lender.
An LSP is only as useful as the evidence it can produce, so ours produces it by default. Every consent, disclosure, message, call and field visit leaves a record you can inspect.
Which controls run at each stage of the lifecycle?
Each stage has its own rules, so each has its own controls and its own evidence trail.
| Stage | Main frameworks | Controls we run | Evidence you get |
|---|---|---|---|
| Acquire | RBI (Digital Lending) Directions, 2025; your Fair Practices Code | Your name shown before the borrower accepts; Key Fact Statement before the contract; no fee before disbursal; marketing checked against your approved claims | KFS delivery logs and consent records |
| Originate | Digital Lending Directions; RBI KYC Directions and PMLA; DPDP Act, 2023 | Separate, logged consents; KYC to your policy through regulated providers; need-based data only, with no access to contacts, SMS or call logs | Consent ledger, verification results and decision records |
| Disburse and service | Digital Lending Directions; RBI outsourcing directions; your Fair Practices Code | Repayments only into your accounts; messages only on consented channels and approved templates; complaints logged at every touchpoint | Communication logs, payment events and grievance MIS |
| Monitor | RBI outsourcing directions; DPDP Act, 2023 | Role-based access; your data never pooled with another lender's; every figure tied to account-level records | MIS you can trace to accounts, and access logs |
| Collect and recover | RBI's recovery-agent norms; your Fair Practices Code; RBI outsourcing directions | Calling hours enforced in the dialler; borrower told before contact; approved scripts; recorded calls; ID and authorisation for field staff | Call recordings, visit logs and complaint records |
Collections conduct controls, enforced by the system
Collections is where conduct risk is highest, so these controls are enforced by the system, not left to judgement. They run on every account we work, across the AI voice bot, IVR, WhatsApp and SMS, the contact centre and field teams:
- Calling hours enforced in the dialler: calls only between 8:00 a.m. and 7:00 p.m., unless the borrower has asked for another time.
- The borrower is told before contact. The lender informs the borrower who will be in touch, and every caller and field visitor can identify themselves and show the lender's authorisation.
- Field staff carry ID and authorisation, and every visit is logged.
- Approved scripts and a prohibited-language list for the voice bot, IVR, messages and people, with QA review.
- No third-party pressure. We never contact a borrower's family, friends, employer or references to pressure or shame them.
- Calls recorded after notice, sampled for quality and conduct, and available to you for audit.
- Consent before every channel. Messages go only through channels the borrower has consented to, on templates you approve.
- Complaints logged and escalated to the lender's grievance officer, and counted in your grievance MIS.
The same platform runs the compliance-support workflows behind them:
- Consent ledger recording each consent, its wording, time and purpose, and its withdrawal.
- KFS delivery logs showing that the Key Fact Statement was delivered and acknowledged before the contract.
- Grievance tracking with ageing against the lender's timelines and RBI's 30-day outer limit.
- Audit trails for decisions, communications, payment events and data access.
- Retention schedules applied to each category of record, aligned to the lender's policy.
Data roles
For loan-related personal data, the lender is the Data Fiduciary and Rinncrest is a Data Processor acting on the lender's documented instructions. For Rinncrest's own website visitors, enquiry forms and partnership conversations, Rinncrest is the Data Fiduciary. The data-processing terms in each agreement set purpose, categories of data, retention, security measures, sub-processors, breach notification and return or deletion at exit.
Control and accountability
- Written agreement. Every engagement is governed by a written LSP and outsourcing agreement that defines roles, rights and obligations, service levels, conduct standards, reporting, escalation and termination.
- Audit and inspection rights for the lender, its internal and external auditors and the regulator, over the records, systems and premises used for the services.
- No core functions. Credit decisions, pricing, the loan contract and policy approval stay with the lender. We do not perform functions that RBI does not permit a lender to outsource.
- Money goes only to the lender. Repayments are collected into accounts in the lender's name, never through Rinncrest's accounts, and Rinncrest does not charge borrowers.
- Sub-contracting only with the lender's prior consent, and on terms no weaker than our own.
- Business continuity arrangements described in the agreement and tested Pending confirmation: business continuity and disaster recovery plan and test cadence..
What do Rinncrest's ISO certificates cover?
- ISO 9001:2015 (Cert. No. IN/84728131/5962). Quality management for loan origination, lifecycle management, debt collection and credit analytics.
- ISO/IEC 27001:2022 (Cert. No. IN/96828132/6481). Information security for the same platform and services. Both are issued by ICV Assessments and certify our management systems, not a lending licence. See Trust and security.
- Self-regulatory organisation membership Pending confirmation: SRO membership and code-of-conduct link, if any..
- Default loss guarantee. Where any DLG arrangement exists, it will be within RBI's limits and disclosed at portfolio level as RBI requires Pending confirmation (F-39)..
What we give you for due diligence
We expect to be diligenced, stage by stage, and we diligence our partners in return. Under NDA, a prospective partner receives a due-diligence pack covering Not yet published: due-diligence pack — confirm contents before publishing.:
- incorporation documents, CIN and director details;
- ISO certificates and their full scope;
- information-security and data-protection policies;
- grievance policy, and the conduct standards for each stage in scope, including collections;
- a sample agreement and data-processing terms;
- insurance and a business-continuity summary.
What we ask of you in return:
- your RBI Certificate of Registration and the Board-approved policies relevant to the services in scope;
- your due-diligence and vendor-risk questionnaire;
- named owners for compliance, grievance and information security;
- agreement on audit scope and frequency.
Frequently asked questions
Can the lender's auditors and RBI inspect Rinncrest's records?
Yes. Our agreements give the lender, its internal and external auditors and the regulator access to the records, systems and premises used for the services. Every consent, message, call and payment event leaves a record you can inspect.
What is Rinncrest's regulatory status?
Rinncrest is a Lending Service Provider, not a lender, NBFC or bank, and it holds no lending licence. It works under written agreements with RBI-regulated lenders, who stay responsible for the activities we perform.
Is Rinncrest a debt collection agency?
Rinncrest is not a debt collection agency, but we provide debt collection services for our lending partners. Collections run on your Fair Practices Code, with approved scripts, a prohibited-language list, recorded calls and a log of every field visit.
Which decisions stay with the lender?
Credit decisions, pricing, the loan contract and policy approval stay with the lender. We do not perform functions that RBI does not permit a lender to outsource.
Where do borrowers' repayments go?
Repayments go only into accounts in the lender's name, never through Rinncrest's accounts. Rinncrest does not charge borrowers.
Who is the data fiduciary for borrower data, the lender or Rinncrest?
For loan-related personal data, the lender is the Data Fiduciary and Rinncrest is a Data Processor acting on the lender's documented instructions. The data-processing terms in each agreement cover purpose, retention, security, sub-processors, breach notification and return or deletion at exit.
Can Rinncrest sub-contract any of the work?
Only with the lender's prior consent, and on terms no weaker than our own. The written agreement also sets service levels, reporting, escalation and termination.
What do you need from us to start due diligence?
We ask for your RBI Certificate of Registration, the Board-approved policies relevant to the services in scope, your due-diligence and vendor-risk questionnaire, named owners for compliance, grievance and information security, and agreement on audit scope and frequency. In return you can review our ISO certificates, policies and agreement terms under NDA.
