PROPELOO

LENDING / CREDIT PLATFORM ENGINEERING

Build a lending platform that manages credit risk, not just loan records.

PROPELOO engineers lending platforms — from credit assessment pipelines and loan origination workflows through servicing infrastructure, collections management and the regulatory compliance layer that determines whether your platform can operate across markets. A lending platform is not a database of loans. It is a risk management system that happens to hold loan records.

The default rate you experience in production is determined by decisions made in the credit assessment system — not by the borrowers you approved.

A lending platform with poor credit assessment will approve borrowers who cannot repay. A lending platform with poor collections infrastructure will not recover from borrowers who will not repay. A lending platform without proper KYC/AML will be shut down by regulators before it discovers either problem. The engineering of a lending platform is inseparable from the risk management and compliance requirements that govern it. PROPELOO builds lending platforms where credit policy is implemented as code, compliance controls are enforced at the API layer, and every loan decision has an auditable chain of data that supports it.

The full lending platform stack.

A production lending platform has six distinct engineering domains, each with its own complexity.

System Layers

  • Origination Layer: Application intake, identity verification, document collection, credit assessment, decision engine
  • Credit Assessment Layer: Credit bureau integration, alternative data, ML scoring model, policy rules engine
  • Loan Management Layer: Disbursement, repayment scheduling, interest accrual, prepayment, restructuring
  • Servicing Layer: Payment processing, delinquency management, collections workflow, customer communications
  • Compliance Layer: KYC/AML, regulatory reporting, audit trail, data residency

Core Technical Capabilities

  • Loan Origination System

    End-to-end loan application workflow — applicant intake, KYC/identity verification, document upload and OCR, credit bureau query, decisioning, offer generation, digital contract execution and disbursement authorisation.

  • Credit Decision Engine

    Rules-based policy engine (minimum score, debt-to-income, employment type) combined with ML scoring models. A/B testing for policy variants. Champion/challenger framework for model comparison. Decision explainability for adverse action notices.

  • Loan Servicing Platform

    Repayment schedule generation, payment processing via ACH/UPI/SWIFT, interest accrual (simple, compound, reducing balance), prepayment calculation, statement generation and borrower portal.

  • Collections Management

    Delinquency segmentation and treatment strategy, automated communication workflows (SMS, email, IVR), promise-to-pay tracking, settlement offer management and legal escalation workflow.

  • KYC/AML Compliance

    Identity verification (Onfido, Sumsub, Jumio), document authenticity checks, PEP/sanctions screening (World-Check, Dow Jones), transaction monitoring and SAR filing workflow.

  • Portfolio Analytics

    Vintage analysis, cohort performance tracking, loss forecasting, concentration risk monitoring and regulatory capital calculation dashboards.

How we think about lending platform engineering.

Every lending platform decision eventually becomes a credit loss or a regulatory finding. Engineering and risk management are the same function.

  • The decisioning engine is the product

    The loan application form is a commodity. The credit decision engine — the combination of credit bureau data, alternative data, policy rules and ML scoring — is the defensible asset. A platform that makes better decisions than competitors at the same approval rate has a structural cost advantage. Engineering the decisioning system with full A/B testing and champion/challenger capability is the highest-value investment in a lending platform.

    Axiom:

  • Compliance is architecture, not features

    KYC at the point of application, transaction monitoring post-disbursement, adverse action notices for declined applications, data retention for regulatory examination — these are not optional compliance features that can be added later. They are architectural requirements that affect the data model, API design and workflow engine from day one. Adding them after launch requires reprocessing historical data and rebuilding workflows.

    Axiom:

  • Collections infrastructure determines recovery rate

    The difference between a 5% net charge-off rate and a 8% net charge-off rate is often not the quality of borrowers approved — it is the quality of the collections process for the 20% of borrowers who become delinquent. Collections treatment strategy (what communication do you send, when, to whom), payment plan flexibility and legal escalation timing are all engineering and operations decisions that directly affect P&L.

    Axiom:

  • Audit trail is a legal requirement, not a nice-to-have

    Regulatory examination of a lending platform requires being able to produce every data point that contributed to every credit decision, every communication sent to every borrower, and every payment processed. An immutable audit trail of all decisioning inputs, model outputs, policy rule evaluations and communications is a legal requirement in every regulated lending jurisdiction — not a data engineering enhancement.

    Axiom:

The lending platform decisions that define risk and compliance.

These choices determine your default rate, regulatory standing and operational efficiency.

  • Credit assessment approach?

    Impact: A rules engine that enforces credit policy combined with an ML scoring model is the industry standard for any lender with more than 1,000 loans/month. Rules prevent systematic errors; ML optimises within the rules.

    • Traditional credit bureau only — established data, limited coverage for thin-file borrowers
    • Bureau + alternative data (telco, utility, bank statements) — broader coverage, regulatory scrutiny
    • ML model + rules engine — flexible, explainable with SHAP values, requires data science capability
    • Third-party bureau score + internal policy rules — fastest to market, limited differentiation
  • BNPL vs term loan vs revolving credit?

    Impact: Product choice determines the regulatory framework, technology complexity and collection dynamics. BNPL is subject to increasing regulatory scrutiny globally. Revolving credit has the most complex servicing requirements.

    • BNPL (buy now pay later) — short duration, low APR, merchant-funded model
    • Term loan — fixed schedule, longer duration, higher ticket size
    • Revolving credit (line of credit) — flexible drawdown, ongoing relationship, complex servicing
    • Invoice financing — B2B, asset-backed, faster collections via invoice assignment
  • Own underwriting vs credit bureau scores?

    Impact: Your credit model is your primary competitive asset. Starting with bureau score + income verification and iterating toward a proprietary model as you accumulate performance data is the practical path for most new lenders.

    • Rely on bureau score only — fast to build, commoditised, no moat
    • Bureau score + income verification — 2-3 additional data points, meaningful differentiation
    • Full alternative data underwriting — proprietary model, regulatory complexity, potential moat
    • Third-party underwriting-as-a-service — fastest to market, pay per decision, no model ownership
  • Payment rails?

    Impact: Payment rail selection is jurisdiction-specific. ACH for US consumer lending. UPI for India. SEPA for EU. Evaluate cost, settlement speed and coverage for your target market. Debit pull is fastest but most expensive at scale.

    • ACH (US) — batch, 1-2 day settlement, low cost, high coverage
    • Real-time payments (FedNow/RTP) — instant settlement, growing coverage, higher cost
    • Debit card pull — real-time, high coverage, 2-3% cost
    • UPI (India) / PIX (Brazil) — real-time, near-zero cost, country-specific
  • Collections software?

    Impact: For early-stage lenders (<$50M portfolio): outsource collections or use a collections platform. For mature lenders (>$100M): custom collections workflow tailored to your borrower segments produces significantly better recovery rates.

    • Build custom — matches your workflow exactly, expensive to build and maintain
    • Collections platform (Debt Manager, FICO) — proven, expensive, integration required
    • CRM-based (Salesforce) — flexible, familiar to agents, less specialized
    • Outsource to collections agency — fastest, lower recovery rate, margin impact
  • Regulatory compliance approach?

    Impact: RegTech platforms for KYC/AML are justified at any meaningful scale — the cost of a compliance failure far exceeds the platform cost. The regulatory expertise is continuously updated by the provider rather than requiring internal regulatory tracking.

    • Build internally — maximum control, expensive to maintain as regulations change
    • RegTech platform (Alloy, Unit21) — specialised, up-to-date, per-decision cost
    • Banking-as-a-service partner (Stripe Treasury, Unit) — regulated entity partnership, constrains product
    • Legal counsel + manual process — lowest cost, highest operational risk

What PROPELOO builds.

  • Consumer Lending Platform

    Personal loan platform with credit bureau integration, ML decisioning, digital application, ACH disbursement and servicing portal — from application to payoff.

  • BNPL Infrastructure

    Buy-now-pay-later platform with merchant SDK, real-time decisioning, installment contract generation, ACH autopay and collections workflow.

  • P2P Lending Platform

    Peer-to-peer lending marketplace connecting investors with borrowers — credit assessment, auto-invest rules, loan servicing, investor dashboard and regulatory compliance.

  • DeFi Lending Protocol

    On-chain lending protocol with collateral management, interest rate curves, liquidation engine and oracle-based collateral pricing.

  • SME Working Capital Platform

    Invoice and receivables financing platform for SMEs — invoice verification, advance calculation, repayment from collections and concentration limit management.

  • Lending Core System

    Core lending system for a neobank or digital lender — multi-product support, configurable loan types, full audit trail, regulatory reporting and banking system integration.

The lending platform stack.

Each domain requires specific tooling with financial-grade reliability requirements.

  • Core Backend

    Stack: Node.js / Java Spring, PostgreSQL (financial ledger), Redis (decisioning cache), Kafka (event streaming), Temporal (workflow orchestration)

  • Credit & Decisioning

    Stack: Experian / Equifax / TransUnion APIs, Plaid (bank statements), Finicity (income verification), Custom ML scoring (Python/sklearn), Drools (rules engine)

  • KYC/AML

    Stack: Onfido / Sumsub (identity), Jumio (document verification), Alloy (orchestration), Chainalysis (crypto AML), ComplyAdvantage (sanctions)

  • Payments

    Stack: Dwolla (ACH), Stripe (card), Modern Treasury (payment ops), RazorPay (India), Stripe Treasury

  • Infrastructure

    Stack: AWS (primary), PostgreSQL with row-level audit, HashiCorp Vault (key management), Datadog, PagerDuty

  • Analytics

    Stack: Looker / Metabase, Snowflake (data warehouse), dbt (data transformation), Custom vintage analysis

Lending platform security protects borrower data and financial assets.

Financial platforms are high-value targets with specific regulatory security requirements.

  • PII Protection

    Borrower SSN, income documents, bank account numbers and credit reports are among the most sensitive PII categories. Encryption at rest for all PII fields, field-level access controls, data masking in non-production environments and strict retention limits with automated deletion are required.

  • Payment Fraud

    ACH origination fraud (unauthorized debit), identity theft applications and account takeover are the primary fraud vectors. Multi-factor authentication for all account actions, velocity limits on disbursement, positive pay for ACH origination and machine learning fraud scoring are required mitigations.

  • Regulatory Audit Trail

    Every credit decision, every communication to a borrower, every payment processed and every policy exception must be immutably logged with timestamp, actor and all relevant data. This is not just good practice — it is a legal requirement in every regulated lending jurisdiction.

  • Third-party Data Security

    Credit bureau data, bank statement data and identity verification data received from third parties carries contractual data handling requirements. Data minimisation (retain only what is needed for the decision), strict retention limits and access logging for all third-party data are required.

  • API Security

    Lending APIs that expose customer data require: OAuth 2.0 authentication, per-client rate limiting, request signing for webhook delivery, TLS 1.3, and comprehensive API access logging for fraud detection.

  • Insider Threat

    Employees with access to loan officer functions, customer data and disbursement approvals represent an insider threat. Role-based access control with minimum necessary permissions, maker-checker for disbursement (two approvals required), and anomaly detection on employee activity patterns are required controls.

From concept to regulated lending platform.

  1. 01. Product & Compliance Scoping

    Define loan product, target market, regulatory requirements, compliance approach and data model before any engineering.

  2. 02. Core System Architecture

    Loan lifecycle design, data model for financial ledger, API architecture, workflow engine selection and audit trail design.

  3. 03. Origination & KYC

    Application intake, identity verification, credit bureau integration and document processing pipeline.

  4. 04. Decision Engine

    Rules engine, credit model integration, decision logging and adverse action notice generation.

  5. 05. Servicing & Payments

    Repayment scheduling, payment rail integration, interest accrual and borrower portal.

  6. 06. Collections & Reporting

    Collections workflow, delinquency management and regulatory reporting infrastructure.

  7. 07. Launch & Compliance Review

    Compliance audit, regulatory examination preparation, launch with portfolio monitoring and risk dashboards.

Frequently Asked Questions

What compliance requirements apply to lending platforms?

Requirements vary by jurisdiction. US: TILA (Truth in Lending Act) requiring APR disclosure, ECOA (Equal Credit Opportunity Act) requiring adverse action notices, FCRA (Fair Credit Reporting Act) for credit bureau data usage, BSA/AML for anti-money laundering. UK: FCA consumer credit authorisation, Consumer Credit Act. EU: Consumer Credit Directive, GDPR for data handling. India: RBI digital lending guidelines. The compliance framework must be defined before development begins.

How do we build a credit scoring model?

Cold start: use a third-party bureau score (Experian, Equifax) combined with income verification (Plaid, Finicity) as the initial model. After 6-12 months of performance data (which loans repaid, which defaulted), build an internal ML model trained on your actual book. Logistic regression for interpretability and regulatory explainability requirements, gradient boosting (XGBoost) for predictive performance. Validate with vintage analysis: do loans scored above X in quarter Y have better 90-day performance than loans scored below X?

What is an adverse action notice?

An adverse action notice (US requirement under ECOA and FCRA) must be sent to any applicant who is declined or offered less favourable terms, explaining the principal reasons for the adverse action (e.g. "insufficient credit history," "debt-to-income ratio too high"). The specific reason codes must come from the credit bureau if bureau data was used. Failure to provide accurate adverse action notices is a regulatory violation with significant penalty risk.

How do we handle loan defaults?

Collections strategy by delinquency bucket: 1-30 DPD (days past due) — automated SMS/email reminders, self-service payment plans. 30-60 DPD — outbound calling, hardship programme offers. 60-90 DPD — settlement offers, payment plan restructuring. 90+ DPD — legal escalation, write-off assessment, potential charge-off and third-party collections agency transfer. Early intervention at 1-30 DPD produces significantly better recovery rates than waiting.