Risk
Field verification quality is now a credit-risk control, not a back-office chore
As retail books grow through partners and remote origination, the integrity of contact-point work has become a first-order risk question for banks and NBFCs across India.

NETZONE Research
March 12, 2026·16 min read

Retail credit in India has scaled faster than many institutions’ field-control architecture. Origination now runs through branches, digital funnels, DSAs, and fintech partners. The customer may be verified in a city the credit officer has never visited. That distance is not inherently unsafe, but it is unsafe when verification is treated as a volume task rather than a control.
Reserve Bank of India guidance on outsourcing, KYC, and fair practices has long assumed that the regulated entity remains accountable for work done in its name. In practice, that accountability is only as strong as the evidence trail from the doorstep: who visited, what was observed, what was contradicted, and how exceptions were closed. NETZONE’s view, formed across more than two decades of supporting retail risk operations, is that field verification quality should sit in the same conversation as scorecards and policy, not after disbursement, when the file is already in collections.
Why volume programmes drift
Most weak programmes do not fail because staff are careless. They fail because incentives and design pull in opposite directions. When turnaround time is the only visible KPI, a verifier will complete the visit. Completing the visit is not the same as testing the case.
Typical drift patterns we see in Indian retail books include: neighbour checks that are recorded but not independently sourced; photographs that confirm a façade, not occupancy; tele-verification that repeats the application form rather than testing it; and de-dupe that runs against an incomplete negative database. None of these look dramatic in a dashboard. Together they create a book that appears underwritten and is, in truth, sampled.
- Visit completion rates without exception ageing
- Same-day “clean” files with no contradiction notes
- Agency concentration in a few pin codes with weak rotation
- Photo evidence without geo or time integrity
A control design that holds up in audit
A defensible programme starts with a written sampling and verification standard: which products require physical CPV, which allow tele-plus-document, and which combinations of risk flags force a second visit. That standard should be product-specific. A used-vehicle loan, a small-ticket personal loan, and a housing loan do not share the same fraud geometry.
Second, the file should capture contradictions as first-class data. If the neighbour does not recognise the applicant, that is not a footnote. It is a credit input. Institutions that only store “positive / negative” lose the ability to see patterns across agencies, geographies, and sourcing channels.
Third, independence matters. The person who sourced the file should not control the verifier. Rotation, mystery shopping, and seeding, placing known test cases into the stream, remain among the few ways to know whether a network is actually looking.
What leadership should ask this quarter
Credit and risk heads do not need another generic SOP. They need a short set of questions that expose whether the control is real: What share of files had a material contradiction in the last 90 days? How quickly were those files stopped? Which agencies have never raised a negative? Which pin codes produce perfect files at a speed that is physically implausible?
Those questions travel well across India. State labels differ; the operating risk does not. A partner that can run visits, write usable MIS, and sit comfortably in an internal-audit sample is not a vendor of “field force.” It is part of the credit decision.
Rs 41+ lakh cr
Scheduled commercial bank retail loans (RBI trend scale)
12,000+
NBFCs on the RBI register, highly uneven field control
T+0 / T+1
Visit TAT many lenders now demand in metro pin codes
What Indian data actually tells credit risk
RBI's Financial Stability Reports have repeatedly flagged unsecured retail and personal-loan growth as a supervisory watch item. That does not mean every personal loan is weak. It means a larger share of the book now depends on information that never sat inside a branch file: partner-sourced applications, digital KYC, and field work done by a third party.
When a bank in Tamil Nadu books a two-wheeler loan sourced by a DSA in a Tier-3 town, the credit officer in Tamil Nadu or Chennai is underwriting a photograph, a neighbour note, and a bureau score. If those three items are not independently produced, the scorecard is decorating a gap.
NBFC-ICC and HFC books show the same pattern at different ticket sizes. Housing finance still has legal and technical diligence. Small-ticket consumer durable and personal loans often do not. Field verification is then the only physical test of occupancy and identity collusion.

A practical sampling grid for Indian products
A defensible grid is product by risk, not one SOP pasted across the book. Used cars and commercial vehicles need dealer and valuation triangulation. Housing needs occupancy plus address stability. Gold loans are a different control set. Personal loans need identity, occupancy, and employment that can survive a second call.
- Metro salaried personal loan: tele plus document, physical if bureau or geo flags fire
- Self-employed MSME or CV: physical CPV plus workplace or yard check as default
- DSA or fintech sourced: higher physical sample in the first 90 days of the partner
- Repeat or top-up: lighter check only if the prior file still reconciles
A file that is never negative is not a high-quality agency. It is an agency that has stopped looking.
How NETZONE would run the next 90 days
Start with a contradiction register, not a new vendor RFP. Pull 90 days of CPV outcomes by agency, pin code, and sourcing channel. Rank agencies that have never raised a refer or decline. Those names go into mystery shopping and seeding first.
Second, rewrite the report so credit sees four fields on page one: found or not found, activity consistent with income, policy action, and residual uncertainty. Everything else is appendix.
Third, put exception ageing next to TAT. A visit completed in six hours with an open contradiction is not a success. A visit completed in 30 hours that stopped a bad file is.
This note reflects NETZONE operating experience in risk, audit, and statutory work across India. It is not legal, tax, or regulatory advice. Institutions should take counsel on their specific facts and licences.



