vcurd is engineered from the ground up for India's financial regulatory landscape — meeting RBI Digital Payment Security Controls, CERT-In cybersecurity guidelines, NPCI UPI reporting requirements, and NBFC-specific compliance mandates.
Regulatory frameworks covered
vcurd maps every product feature to the specific clauses of Indian financial regulation — so you can demonstrate compliance without guesswork.
vcurd's real-time scoring, audit trail, and FMR reporting module directly address the RBI Master Direction on Digital Payment Security Controls (January 2021), which mandates transaction monitoring, anomaly detection, and systematic fraud reporting for all regulated payment entities.
CERT-In's empanelment requirements for information security auditors and the CERT-In Directions 2022 mandate incident reporting, access controls, log retention, and encrypted storage. vcurd's architecture satisfies every technical requirement in this framework.
NPCI's UPI Procedural Guidelines require member banks to report fraud cases, maintain risk thresholds, and implement velocity controls. vcurd's rule engine and reporting module are purpose-built to fulfil NPCI's operational requirements for UPI fraud management.
NBFCs face specific obligations under RBI Master Directions — including gold loan LTV compliance under Circular No. RBI/2021-22/119, escrow account monitoring for payment aggregators, and bureau pull velocity controls to prevent loan-stacking fraud.
vcurd generates RBI-compliant Financial Monitoring Reports with one click — structured, linked to source alerts, and exportable in the exact JSON format expected by RBI.
Automated Financial Monitoring Report generation with deadline tracking and alert linkage
A persistent dashboard widget displays the days, hours, and minutes remaining until the next RBI FMR submission deadline. Compliance teams always know where they stand without checking external calendars.
The FMR export generates a structured JSON payload conforming to RBI's prescribed format — covering transaction counts, flagged amounts, rule triggers, and ML verdicts — ready for direct submission or review.
Every line item in the FMR is hyperlinked to the originating alert record, including the rule that triggered it, the ML probability score, SHAP feature attribution, and the analyst who reviewed it.
Every decision, rule change, and model score is permanently recorded with full context. No retroactive editing. No gaps. Exactly what CERT-In and RBI examiners require.
Audit log entries are write-once. No user — including administrators — can modify or delete a decision record after it is written.
Every manual override, alert disposition, rule change, and LLM configuration update is attributed to the authenticated user who made it.
All transactions, rule evaluations, ML scores, and alert actions carry microsecond-precision UTC timestamps — traceable to the originating API call.
Export any date range of audit logs in CSV or JSON format. Directly shareable with RBI examiners, CERT-In auditors, and internal compliance teams.
Specialist compliance modules for NBFCs, payment aggregators, and lending platforms — monitoring the exact thresholds RBI has prescribed.
vcurd monitors loan-to-value ratios for gold-backed lending in real time. When the LTV of any loan account breaches the RBI-mandated 75% ceiling — due to gold price fluctuations or additional drawdowns — the system raises an immediate alert with full breach context.
Payment aggregators under RBI's PA-PG guidelines must maintain escrow accounts within prescribed balance tolerances. vcurd performs daily reconciliation between actual escrow balances and expected amounts, flagging variances above 15% for immediate compliance review.
CERT-In Directions 2022 set a high bar for cybersecurity infrastructure. vcurd satisfies every requirement relevant to financial transaction monitoring systems.
Every fraud event, rule trigger, and model decision is logged as a structured incident record with full context, preservable for 5 years as required by CERT-In Directions 2022.
Three-tier role-based access control — viewer, analyst, admin — limits data exposure and action permissions. No over-permissioned service accounts.
Immutable, timestamped, user-attributed logs of all decisions and administrative actions. Exportable in CSV and JSON for examiner review at any time.
All transaction data, alert records, and user credentials are stored encrypted at rest. Data in transit is protected via TLS 1.2+. JWT tokens for API authentication are signed with a configurable secret key.
Fraudulent transactions trigger instant alerts broadcast via WebSocket to all connected dashboard clients — with no polling delay. Alert severity escalation is automated.
Consecutive breach detection triggers an automated escalation workflow — notifying compliance leads and generating a structured breach report ready for CERT-In submission within the 6-hour reporting window.
Talk to us about deploying vcurd's compliance modules for your institution.