RCU services for banks and NBFCs
GVS runs the Risk Containment Unit function for lenders. Before a loan is sanctioned we screen the file, verify the documents against the record held by the authority that issued them, and put a field agent at the borrower's home, office and place of business. Every finding comes back with the evidence under it.

An RCU asks a different question
Credit appraisal asks whether the borrower can repay. The Risk Containment Unit asks whether any of it is true. The two run beside each other, and the second one is the last gate before money moves.
Can this borrower repay?
Your appraisal, on the numbers as submitted.
- Income and obligations assessed against the product.
- Bureau score and repayment history read.
- Eligibility and ticket size worked out.
- The file moves toward sanction.
Is this application genuine?
Our work, independent of whoever sourced the file.
- Documents checked against the issuer's own record.
- Declared income tested against the income proofs and the tax record.
- The address, the office and the business seen in person.
- The file screened against your fraud and rejection database.
How a file moves through the RCU
Four stages before sanction, and three ways a case can close. Each stage links to the section that explains it.
All of them read for suspect documents and suspect profiles. An agreed share goes on to full verification.
Verify at the issuerKYC, income, property and entity records checked against the record the issuing authority holds.
See it in personResidence, office and business unit visited. Contact point verification runs alongside.
Screen against your listsFraud and rejection database, bureau alerts, negative areas and negative profiles.
Everything checked stood up, and the file carries the source responses that say so.
The discrepancy is named and what the source said is attached alongside it.
Not enough to call it honestly. We say what is missing rather than round it up or down.
The sanction decision stays with you. We report the finding and what it was checked against. We do not recommend a sanction.
Screening and sampling
Every file logged in gets screened. Anything that does not sit right gets pulled, and an agreed share goes to full verification. The share is yours to set, not ours.
100% of files logged in are read for suspect documents and suspect profiles. Nothing is sampled out at this stage, because the point of the screen is to find the files worth spending money on.
A document that does not match its issuer's format, a profile that contradicts itself, an applicant you have already rejected once. These come out of the run whether or not the sample would have caught them.
The agreed share of logged-in files goes to full verification alongside everything the screen flagged. Most lenders set the share by product and ticket size, with more on secured and high-value files.
One report per batch, in your format, inside the turnaround the mandate sets. Each finding names the document, the discrepancy and the source it was checked against.
The sampling percentage is a policy decision. It belongs in your mandate, not in our discretion, and we report against it so an internal audit can see that the screen was total and the sample was met. If a batch runs over the flagged share, you hear that with the batch rather than at the end of the quarter.
Document verification, at the issuing authority
A forged salary slip passes a rules engine. It does not pass the employer's HR department. Every document is checked against the record held by the body that issued it, and the reply is kept.
Aadhaar, PAN, passport, voter ID, driving licence and utility bills, matched against the issuing record rather than read off the scan.
Salary slips, Form 16, appointment and increment letters, confirmed with the employer and against the deductor's TDS record.
Income tax returns, audited financials, GST returns and business registration, checked against the filings themselves rather than the printout supplied.
The income proofs read against each other and against the tax record. A payslip figure the employer will not confirm, or a proof that appears only once the file was logged, is the finding.
For home loans and loans against property: title, sale deed, sanctioned plans and approvals, and encumbrance, checked where they are actually registered.
ROC and MCA records for companies and LLPs, and the licences, registrations and approvals a new unit says it holds.
What gives a file away. Fonts and layout that do not match the issuer's own format. A TAN that does not exist against the deductor named on the Form 16. A return filed days before the application. Credits that do not add up to the declared income. Each is reported as what it is, with the source response attached, and the credit call stays yours.
Field investigation
Digital lending took away the branch manager who knew the neighbourhood. A field visit is how that knowledge is rebuilt: somebody stands at the address and reports what is actually there.
An office that turns out to be a residential flat. A manufacturing unit with no equipment in it. A trading company with no goods on the floor. None of that is visible in a file, and all of it is visible in twenty minutes on site.
Visits are planned or unannounced, as your mandate requires, and the report carries photographs and the location the visit was made from.
Contact point verification is not the same thing
Lenders buy both and they answer different questions. Running one and calling it the other is how a file gets through.
Contact point verification
Is this applicant where they say they are, and can you reach them?
- The stated mobile number is called on a recorded line.
- The residence, and the office where the mandate asks for it, is visited.
- Relationship to the address and time at the address are recorded.
- The outcome is positive or negative, and a negative one escalates the same day.
Risk containment
Is what this applicant told you true?
- Documents checked against the record the issuer holds.
- Declared income tested against the income proofs on file and the tax record.
- The file screened against your fraud and rejection database.
- The business itself inspected where the file warrants it.
Why the distinction matters in recovery. If a borrower defaults and the contact point was never real, collections has nowhere to go. CPV is what makes an account recoverable. Document verification is what stops the account being written in the first place. They are not substitutes for one another.
Screening beyond the file
Not everything an RCU catches is in the application. Four activities that sit outside the sanction queue.
Applicants screened against your own fraud and rejection database, against bureau fraud alerts, and against negative lists. A hit stops the file where it is.
A posed application run through your own channel, to see whether a branch, a DSA or an associate actually follows the customer identification process they are meant to.
After the money moves: is the borrower still at the address, and was the facility used for the purpose it was sanctioned for.
Desk and field work on one suspect file. Lifestyle against declared income, business associates, and a previous employer's view of the applicant's integrity.
What lands back with you
A finding you can act on, the evidence under it, and somewhere to watch the batch while it runs.
Three outcomes, no fourth. We do not soften a negative to keep a file moving and we do not resolve a refer by guessing. What we could not establish is stated as exactly that.
The issuer's own reply, the registry's own record, the photographs from the visit. Your risk team and your auditor read what we read, months or years later.
Reports built to your template and submitted through the client portal, with every case in the batch trackable while it is open.
Independence is the point of the function. An RCU finding is worth nothing if the channel that sourced the loan can influence it. GVS is engaged by your risk or credit function and reports to it, and nobody in the sourcing chain sees a finding before you do. Anything that looks wrong is escalated when we see it, not held back for the batch report.
Borrower files are the most sensitive data a lender holds. RCU work is carried out on your instruction, under the KYC and loan documentation the applicant has already signed, and handled under India's DPDP Act. GVS is ISO 27001 certified for information security and ISO 9001:2015 for quality management. Retention, access control and the grievance route are set out in the Trust Centre.
Why lenders empanel GVS
We are the empanelled RCU for Canara Bank and Punjab & Sind Bank, running customer due diligence on their lending. We have been verifying for Indian organisations since 2010.
Genuine Verification Services Private Limited has run verification work for Indian organisations from New Delhi since then.
Banks, NBFCs, staffing firms, IT companies, retail chains and gig platforms.
Canara Bank and Punjab & Sind Bank, on customer due diligence for their lending.
Independently audited, alongside ISO 9001:2015 for quality management.
Where your book actually is
Metro coverage is not what separates agencies. A field network across Tier 2, Tier 3 and rural pin codes is what makes a residence or unit visit possible where the address is not on any map service.
Independent of the channel
We are engaged by your risk function and report to it. Nobody who sourced the file sees a finding first, which is the only condition under which an RCU finding means anything.
Committed turnaround per activity
Each activity carries its own turnaround, set in the mandate against your product and volume rather than quoted as one number for everything.
The number that makes the case. Banks and financial institutions reported 10,114 fraud cases involving Rs 48,021 crore in FY26. Across the last three years the number of cases has fallen for public and private sector banks while the amount involved has risen, which is a sentence about bigger frauds getting through rather than fewer. Source: RBI Annual Report 2025-26.
Questions lenders ask
What does RCU stand for?
Is RCU the same as CPV?
What percentage of files do you sample?
Do you verify guarantors as well as borrowers?
What happens when you find a forged document?
Do you cover Tier 2 and Tier 3 locations?
Related
Submit a batch, watch every case while it is open, and pull the evidence when you need it.
See the portal Trust CentreISO 27001 and ISO 9001 certification, DPDP handling, retention and the grievance route.
Trust Centre DSA and vendor due diligenceThe same standard extended to the sourcing agents and partners who represent you to a customer.
Vendor due diligencePut a live batch through
Send us files from a real product and judge us on the findings.
Talk to sales