Loading blog...
Co-Lending Loan File Audit: Check Every File in 15 Days
Shweta K
|
October 8, 2026
|
5 minutes read
A co-lending loan file audit checks each loan a bank books from its NBFC partner against the partner’s sanction, the bank’s policy and RBI rules. Under the 2025 Directions, the bank books its share within 15 days and can no longer pick which loans it takes.
For a Head of Credit Operations running three NBFC partnerships, that changes the job. The file arrives sanctioned, the money has moved through escrow, and the commitment is irrevocable. An edited salary slip found in month seven is now the bank’s problem too.
Most of these files reach the bank as rows in a data feed, not as documents. A file nobody at the bank opened cannot be defended to its statutory auditor. KlearStack runs the checks on every co-lent file and keeps a trail that auditor can replay.
| Co-lending loan file audit (definition) A co-lending loan file audit is a lender’s own check of each co-lent loan file against the partner’s sanction, its own credit policy and the RBI (Co-Lending Arrangements) Directions, 2025. It confirms the documents are complete, consistent and unaltered, and logs every result as audit evidence. Under the Directions, co-lent loans sit inside each lender’s internal and statutory audit scope. |
TL;DR
- A co-lending loan file audit checks each co-lent file against the partner’s sanction, your policy and the RBI Directions.
- The RBI Co-Lending Directions 2025 took effect on 1 January 2026; partner commitments are now irrevocable.
- Each lender books its share within 15 calendar days, which makes that window the practical audit window.
- Co-lending platforms split funds and run escrow; they do not test the documents in the file.
- Partner due diligence is where a bank can still say no, so it needs eight checks before go-live.
- The 10-File, 15-Day Test shows in minutes whether your bank checked its co-lent files or trusted them.
- Borrower-level asset classification means a partner’s bad file becomes your NPA by the next working day.
See how KlearStack audits last month’s co-lent files in a 30-minute pilot
What the RBI Co-Lending Directions 2025 Make the Bank Answer For
The RBI (Co-Lending Arrangements) Directions, 2025 were issued on 6 August 2025 and apply from 1 January 2026. They cover commercial banks, All-India Financial Institutions and NBFCs, including HFCs. Each lender keeps at least 10% of every loan, books its share within 15 days, and routes borrower money through escrow.
A Chief Compliance Officer gets asked about the clauses below first. Each needs evidence, and that evidence lives in the audit trail behind each co-lent file, not in the partner’s MIS.
| Paragraph | What it requires | What the file audit must prove |
| Para 10 | Each lender retains at least 10% of every loan | Both shares match the agreement |
| Para 11 | Credit policy covers partner due diligence | Due diligence is on record |
| Para 21 | Partner’s commitment is irrevocable | Checks ran before the share was booked |
| Paras 22, 24 | Shares booked within 15 days, or the loan stays with the originator | Booking date per loan, checks inside the window |
| Para 26 | Borrower transactions route through escrow | Disbursement ties to sanction and escrow entry |
| Para 27 | Co-lent loans sit in internal and statutory audit scope | A file-level trail an auditor can replay |
| Para 29 | Partner may rely on the originator’s KYC identification | Which KYC documents were relied on and checked |
| Para 33 | Borrower-level classification; SMA and NPA shared by next working day | Status changes logged with dates |
The book these rules govern is large. CRISIL Ratings put NBFC co-lending AUM near Rs 1 lakh crore in April 2024. It expected 35 to 40% annual growth over the medium term.
📊 Nearly Rs 1 lakh crore of NBFC co-lending AUM, growing 35 to 40% a year
At that pace a co-lent book roughly doubles in two years. The audit team checking it rarely does.
Source: CRISIL Ratings
Document AI that Eliminates Manual Processing and Compliance Gaps
Why Your Co-Lending Platform Won’t Catch a Bad File
The assumption in many credit operations teams is that co-lending software covers compliance, because it was sold as RBI-aligned. The reality is that it governs the money and the data, not the documents. It splits ratios, routes escrow and produces the Key Facts Statement, but never opens the salary slip.
The 2025 Directions widened that gap. The old discretionary model let a bank review each loan and decline some; para 21 now makes the commitment irrevocable. Selective purchase has moved under the Transfer of Loan Exposures Directions.
The pattern across audit cycles is consistent. The bank’s file review was built for a world where it could say no. It now has to move earlier, into partner due diligence, or become a post-booking audit that decides whether the partnership continues.
A reviewed file is not a checked file, and a check proves nothing unless the rule, result and sign-off were logged. That is the line between credit documentation automation that moves files and a check you can prove later.
Co-Lending Due Diligence Checklist: 8 Partner Checks Before You Sign
A co-lending due diligence checklist tests the partner before the first file arrives. Para 11 requires it in your credit policy. With commitments irrevocable, this is where a bank can still say no.
A Chief Compliance Officer signing off a new NBFC partner should see evidence for all eight.
1. Eligibility: the partner is a covered lender, with limits and target borrowers in your credit policy.
2. Underwriting fit: borrower criteria and thresholds in the agreement match your policy, as para 12 requires.
3. Sanction trail: who sanctioned each loan, in what order, against which threshold.
4. KYC reliance: para 29 lets you rely on the partner’s identification, so test it against your automated KYC verification standard.
5. Document quality: run your own identity, income and tamper checks on 25 recent files.
6. Information sharing: fixed timelines, including SMA and NPA status by the next working day.
7. Booking mechanics: a test batch booked within 15 days, end to end, through escrow.
8. Audit access: your auditors can reach the partner’s file-level evidence and its check logs.
The Co-Lending Loan File Audit: What to Check on Every File
A co-lending loan file audit runs seven checks on each file: completeness, identity, income, tampering, reuse, policy and approval order, and the money trail.
The LOD (List of Documents) for a Co-Lent File
An LOD, or list of documents, is the agreed checklist of papers each file must carry. For a retail loan it typically covers PAN, Aadhaar, address proof, salary slips or ITRs and bank statements. The sanction letter, KFS, loan agreement and disbursement proof complete it.
| Check | What it compares | What it catches |
| Completeness | File contents against the LOD | Missing, expired or unreadable papers |
| Identity | Name, date of birth and address across PAN, Aadhaar and address proof | Mismatched or borrowed identities |
| Income | Salary slip net pay against bank statement credits | Inflated income |
| Tampering | Forensic checks on statements, slips and bills | Edited figures, pasted lines, altered dates |
| Reuse | The same document across files and partners | One set of papers backing two loans |
| Policy and approvals | Credit policy thresholds and sign-off sequence | Out-of-policy sanctions, skipped approvers |
| Money trail | Sanction, disbursement, escrow entry and booking date | Over-disbursal, booking after day 15 |
For a Head of Internal Audit, the income and tampering rows carry most of the risk. A data feed cannot run them, because they need the document itself. Our guide on how to spot a fake bank statement walks through the signs.
Document AI that Eliminates Manual Processing and Compliance Gaps
The 10-File, 15-Day Test: Did Your Bank Check Its Co-Lent Files or Trust Them?
Ask your Head of Internal Audit to pull 10 co-lent files booked last month, from at least two partners. Answer four questions per file from records alone, not from memory or a call to the partner.
1. Which checks ran, and on which version of each document?
2. Did they run before the booking date, inside the 15-day window?
3. Who signed off, and in what order?
4. Could your statutory auditor replay each result without asking the partner?
Score a file only if all four answers come from a record. Eight or more means your bank checked. Fewer than five means it trusted the partner’s sanction, and the Directions made that trust irrevocable.
| ⚠️ Warning A partner MIS row that says “KYC done” is not evidence of a check. It records that the partner says it checked. Your auditor will ask for the document, the rule and the result |
The arithmetic explains low scores. An illustrative partner sending 2,000 files a month at 12 documents each puts about 12,000 documents into every 15-day window. A 10% sample leaves roughly 900 files per window unopened, which is why document fraud detection for banks has to run on every file.
Where Tampered Bank Statements and Salary Slips Get Through
Edited documents get through co-lending at the handoff. The partner’s credit team sees the upload under disbursal pressure, and the bank sees extracted figures. Neither side compares the document image with the numbers.
What we see in document-heavy lending teams is that tampering is rarely clever. A changed net-pay figure, a pasted credit line, a re-dated page. It survives because each team assumes the one before it looked at the pixels.
Auditors see it coming. In an IIA and AuditBoard survey released in February 2026, 65% of audit leaders named fictitious financial documentation a leading AI-enabled fraud threat. 57% cited a lack of suitable tools.
📊 65% of internal audit leaders rank fabricated financial documents a top AI-enabled fraud threat
Salary slips and bank statements, the papers behind a co-lent retail loan, fall in that category.
A Head of Credit Operations should expect income cross-checks and page-level forensic checks before the share is booked. It is the same discipline as salary slip verification on any retail desk.
What Co-Lending Loan File Audit Software Should Do
A Head of Credit Operations can use this table when a vendor demo starts. Each question can be tested in a 30-minute pilot.
| Requirement | Why it matters | Question to ask the vendor |
| Checks every file | Para 27 puts every co-lent loan in audit scope | What share of last month’s files would you have checked? |
| Runs your policy rules | Paras 11 and 12 tie files to your policy | Who approves a new rule before it goes live? |
| Tamper checks on every document | Income documents carry the fraud risk | Show the result on an edited statement from my files |
| Logs rule, result and sign-off order | Your auditor must replay each check | Export the trail for one file, now |
| Fits inside 15 days | Para 22 booking deadline | How long from file arrival to result? |
| Leaves the decision with people | RBI maker-checker expectations | Can your system approve a loan on its own? |
The Loan KYC Agent in KlearStack’s Loan Document Compliance lane runs these checks as each file arrives. It matches identity across PAN, Aadhaar and address proof, ties slip income to statement credits and runs forensic tamper checks. It also flags reused documents, applies your policy rules and blocks out-of-order sign-offs.
Exceptions go to the credit officer you name, with the rule behind each result. The Loan KYC Agent never approves or rejects a loan: KlearStack takes the drudgery, and your team keeps the judgment and the final decision. The engine has processed 150M+ documents in total, the base for continuous auditing with AI agents.
Run the 10-File, 15-Day Test on your own co-lent files with KlearStack
What Changes in a 30-Day Pilot, and When It Isn’t a Fit
The first pilot runs on last month’s co-lent files in 30 minutes, with nothing to install. Files are read from the inbox, S3 bucket or SFTP folder they already land in. On-premise deployment is available when borrower files cannot leave your network.
Before and after, for a co-lending operations team:
- Coverage: a sample after booking becomes every file, as it arrives.
- Evidence: a partner MIS status becomes the rule, result and sign-off order per file.
- Edited income documents: found at first default becomes flagged before your share is booked.
- Statutory audit: weeks of file requests becomes an exported trail per file.
- Clean files: 95%+ STP within 90 days of go-live, so the credit team works on exceptions.
When it isn’t a fit:
- You need escrow routing, blended rates and KFS generation. Buy a co-lending platform; this sits beside it.
- You need video KYC or a government-database identity check. Keep that step; this checks the file’s documents.
- You want a system that underwrites. Compare automated underwriting systems instead.
Conclusion
A bank cannot reject a co-lent loan it has committed to. The file audit inside the 15-day window, and the partner review it feeds, is the control that remains.
The cost of skipping it is concrete. Advances made up Rs 40,774 crore of the Rs 48,021 crore in frauds reported in FY26, per RBI data reported by Outlook Business. That total includes Rs 30,199 crore of older cases reported afresh, but loan fraud is still where the money goes.
Under borrower-level classification, a partner’s bad file becomes your NPA by the next working day.
Book a pilot on last month’s co-lent files and see what your sample missed
FAQs
What is co-lending?
Co-lending is an arrangement in which two eligible lenders, usually a bank and an NBFC, jointly fund individual loans. One lender originates each loan and the partner takes its agreed share onto its books. In India it is governed by the RBI (Co-Lending Arrangements) Directions, 2025.
What is a loan audit?
A loan audit is an independent review of loan files to confirm each loan was sanctioned, documented, disbursed and monitored as policy and regulation require. In co-lending, each lender’s internal and statutory audit must cover its co-lent loans.
What is the difference between co-lending and a consortium?
In co-lending, one lender originates many retail or MSME loans and a partner funds a share of each. In consortium lending, several banks jointly finance one large borrower under a lead bank, with shared appraisal and security.
What is an audit checklist?
An audit checklist lists the items an auditor must verify and the evidence expected for each. For a co-lent loan file it covers document completeness, identity and income consistency, tamper checks, policy compliance, approval order and the booking trail.