Join our Newsletter — 33% off our NHI Course

How should banks and NBFCs structure co-lending so customer onboarding stays compliant and operationally simple?

Banks and NBFCs should define a single borrower interface, clear roles for origination, underwriting, disbursement, and collection, and a shared control framework for eligibility and record keeping. The practical goal is to reduce friction for the borrower while preserving accountability across both lenders. A clean operating model also helps avoid duplicated checks and inconsistent decisions across the lending chain.

How to structure co-lending without creating avoidable onboarding friction

Co-lending works best when the customer sees one front door, not two lenders competing for control. The operating model should define which party owns origination, what is shared, what must be separately approved, and how records are retained. That keeps the customer journey simple while preserving a clean audit trail across the lending chain.

The first design choice is to standardise the borrower interface. One application path, one document set, and one decision workflow reduce duplicated checks and inconsistent handoffs. The customer should not be asked to repeat the same disclosures because the back-end allocation between bank and NBFC is still being resolved.

It also helps to make responsibility explicit at process boundaries. For example, one party may collect and validate onboarding information, another may perform underwriting or funding checks, and both may need access to the final approved record. The more clearly those boundaries are written into the policy and operating procedures, the less likely it is that control gaps appear during exceptions, corrections, or escalations.

Which controls matter most for compliance and operating discipline?

The core control question is whether the arrangement can prove who did what, when, and on what basis. That means eligibility rules, KYC or CDD checks, approvals, and record keeping must be consistent across both lenders even if some tasks are operationally delegated. A shared control framework is more important than a shared system, because accountability has to survive audits and dispute handling.

To make that workable, banks and NBFCs should align the onboarding data fields, define a single source of truth for customer identity and eligibility status, and preserve immutable records of key decisions. Where the parties use different technology stacks, the operating model should still enforce common decision points and common evidence standards so that one lender is not relying on incomplete or stale information from the other.

Documentation should also separate customer-facing simplicity from internal accountability. The borrower may experience one unified journey, but the underlying process needs clear ownership for verification, exception approval, disbursement release, and post-onboarding updates. That distinction reduces friction without blurring responsibility.

Where co-lending models most often break down

Most failures come from ambiguity rather than from the lending concept itself. If the interface is fragmented, customers may be re-screened, asked for duplicate documents, or routed through inconsistent eligibility checks. If roles are vague, one side may assume the other validated a condition, only to discover later that neither party retained enough evidence to support the decision.

Operational complexity also rises when record keeping is treated as a back-office afterthought. If onboarding evidence, approval timestamps, and exception rationales are not captured in a consistent way, the arrangement becomes difficult to defend in an audit or a customer grievance. A simple borrower journey is useful only if it is matched by a defensible internal control trail.

Risk and Threat Considerations

Co-lending structures create compliance and conduct risk when the customer-facing process and the internal control model drift apart. The main exposure is inconsistent onboarding evidence, duplicated or incomplete checks, and unclear accountability if a customer later challenges the decision or if regulators review the file.

Failure mechanism: fragmented ownership, inconsistent eligibility criteria, or weak record retention can let one lender assume the other has validated a requirement, leaving gaps in KYC, approvals, or exception handling.

Impact: the arrangement can produce remediation work, delayed disbursement, audit findings, customer complaints, and avoidable operational rework across both institutions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-3 — Access Enforcement Covers controlled access to shared onboarding records and decision data.
AU-2 — Audit Events Onboarding must preserve who approved, validated, and recorded each step.
Recommendation — Enforce access boundaries for shared onboarding records and decision evidence. Define audit events for approvals, exceptions, and record changes.
ISO/IEC 27001:2022 A.5.15 — Access control Supports clear access and responsibility rules for shared lending operations.
Recommendation — Define access rules for onboarding data and shared records.
CIS Controls v8 CIS-5 — Account Management Aligns with disciplined ownership and lifecycle control for onboarding actors and records.
Recommendation — Assign and review ownership for each onboarding role and account.
SOC 2 (AICPA) CC6.1 — Logical and Physical Access Controls Relevant where co-lending onboarding requires controlled access and accountability over shared records.
Recommendation — Restrict and review access to shared onboarding evidence and decisions.

Practitioner Guidance

What to prioritise: lock down the single borrower journey first, then map each onboarding step to a named owner, evidence requirement, and handoff rule. If a step cannot be assigned cleanly, it is usually the source of future friction or dispute.

What to verify: confirm that the bank and NBFC use the same eligibility criteria, the same retained records for the same decision, and the same exception logic. If the parties cannot produce the same file story from their own systems, the operating model is not yet stable.

Common mistake: treating co-lending as a documentation exercise while leaving workflow ownership implicit. That approach may look efficient at launch, but it usually creates inconsistent onboarding decisions, duplicate work, and messy accountability when something goes wrong.

Practitioner takeaway: the best co-lending model is not the one with the fewest internal steps, but the one that gives the borrower a simple journey and gives both lenders an unambiguous control trail.