Finance & insuranceFlagship industry

Financial services. Trust is the product.

Every screen is a disclosure, and every message is on the record.

Banks, lenders, insurers, wealth and payments businesses, where the customer meets the regulator on every screen. We design journeys with the disclosures built in, CRMs that know what happened last, and secure platforms that leave an audit trail.

The number we move
Onboarding completion
Where we work in financial services
  • Retail & digital banking
  • Digital lending & NBFCs
  • Payments & fintech
  • Cards & credit
  • Microfinance & small-business credit
Rules mapped
9 rules · 6 areas
Disciplines that lead
TechnologyProductMarketing
Frameworks we build to
PCI DSS v4.0.1 — Payment Card Industry Data Security StandardDPDP Act 2023 — Digital Personal Data Protection Act, 2023GDPR — General Data Protection Regulation (EU) 2016/679WCAG 2.2 AA — Web Content Accessibility Guidelines
Looking up the glass and steel façade of a tall office tower
Financial servicesStability is still the first thing a customer looks for.

Where the rules biteMap of all forty-one industries

  • Claims Advertising & claims: Often shapes the work
  • Regulator Sector regulator: Shapes most of the work
  • Payments Payments: Shapes most of the work
  • Data Personal data: Shapes most of the work
  • Security Security & incidents: Shapes most of the work
  • Access Accessibility: Often shapes the work
  • AI AI governance: Often shapes the work

What is shifting

The branch moved into the app, and the regulator came with it.

Onboarding, lending and service now happen on a phone screen, under directions that say what the screen must show. Each shift names what it demands, and a fact that shows it.

A woman at a desk holds a smartphone in one hand and a payment card in the other
Most journeys now start and end on the phone.
  1. Onboarding, lending and investing moved to the phone, with KYC done by video.

    It demandsA digital identity that still reads as secure and regulated.

    SignalRBI treats video KYC (V-CIP) as equal to in-person KYC when its controls are followed.

  2. Regulators now specify what a loan screen must show and when.

    It demandsJourneys where required disclosures are designed in, not bolted on.

    SignalA Key Fact Statement with the all-in APR must reach the borrower before the contract is signed.

  3. Customers compare the app, not the branch — and churn after one confusing journey.

    It demandsA CRM that knows what happened last, so every message is relevant and consented.

    SignalCustomers can share their financial data with any regulated lender through a revocable Account Aggregator consent.

  4. AI now drafts, answers and decides inside regulated journeys.

    It demandsAI with an owner, an evaluation set and a path for incidents.

    SignalRBI’s FREE-AI committee (August 2025) recommends a board-approved AI policy for every regulated entity.

The rulebook

Every screen is a disclosure. These are the rules that say so.

RBI, SEBI and IRDAI directions, the payment and security standards and the data law, read for a typical programme. Your compliance team keeps sign-off; every disclosure screen we design is logged for their review.

Frameworks we build to

  • PCI DSS v4.0.1 — Payment Card Industry Data Security Standard
  • DPDP Act 2023 — Digital Personal Data Protection Act, 2023
  • GDPR — General Data Protection Regulation (EU) 2016/679
  • WCAG 2.2 AA — Web Content Accessibility Guidelines

Frameworks we design and build to — not a claim of certification.

Advertising & claims

Often shapes the work

  1. Securities and Exchange Board of India

    SEBI rules on finfluencers and advertising

    Regulated entities may not associate with unregistered advisers or with anyone claiming returns without permission; advertising may not promise assured returns.

    We designCreator and content programmes are screened for registration and for return claims before they run.

    SEBI · Intermediaries and other amendment regulations, 29 August 2024

  2. Insurance Regulatory and Development Authority of India

    IRDAI policyholder-protection regulations, 2024

    Insurance advertising must be fair and not misleading; the 2021 advertisement regulations were folded into the 2024 framework and its master circulars.

    We designInsurance messaging is checked against the policy wording it describes.

    IRDAI (Protection of Policyholders’ Interests …) Regulations, 2024

Sector regulator

Shapes most of the work

  1. Reserve Bank of India

    RBI Digital Lending Directions

    Key Fact Statement with the all-in APR before the contract, a cooling-off period to exit without penalty, and disclosure of every lending service provider and app.

    We designThe KFS is a designed, logged screen shown before consent — never a PDF behind a link.

    RBI · Digital Lending Directions, 8 May 2025, as consolidated in the November 2025 Master Directions Official text: RBI Digital Lending Directions

  2. Reserve Bank of India

    RBI Know Your Customer Directions — video KYC

    Video-based customer identification (V-CIP) counts as in-person KYC when its controls hold: a live official, liveness checks, geo-tagging, recordings stored in India and an audit trail.

    We designV-CIP journeys are designed with slot booking, retry paths and an assisted fallback.

    RBI · KYC Directions, 2025 (successor to the 2016 Master Direction)

Payments

Shapes most of the work

  1. Reserve Bank of India

    RBI authentication directions, 2025

    From 1 April 2026, domestic digital payments need at least two factors of authentication, one of them dynamic, with risk-based checks encouraged.

    We designStep-up authentication is designed for the risky moment, not for every tap.

    RBI · Authentication Mechanisms for Digital Payment Transactions Directions, 25 September 2025

  2. PCI Security Standards Council

    PCI DSS v4.0.1

    Card-data security standard; since 31 March 2025 every script on a payment page must be inventoried and authorised (6.4.3) and changes to the page detected (11.6.1).

    We designPayment pages ship with a script inventory and change detection from day one.

    PCI SSC · PCI DSS v4.0.1, June 2024 Official text: PCI DSS v4.0.1

Personal data

Shapes most of the work

  1. MeitY · Reserve Bank of India

    DPDP Act, 2023 and Account Aggregator consent

    Consent for each purpose with easy withdrawal; financial data moves between institutions only under a granular, revocable consent artefact.

    We designConsent and data-sharing screens are designed to the consent artefact, and every grant is logged.

    DPDP Rules, 2025 (core obligations from 13 May 2027) · RBI NBFC – Account Aggregator Directions

Security & incidents

Shapes most of the work

  1. Indian Computer Emergency Response Team

    CERT-In Directions, 2022

    Report cyber incidents within six hours of noticing them, and keep logs of every ICT system for a rolling 180 days, within India.

    We designLogging and incident runbooks are built into the platform, not added after launch.

    CERT-In · Directions under section 70B(6), 28 April 2022 Official text: CERT-In Directions, 2022

AI governance

Often shapes the work

  1. Reserve Bank of India

    RBI FREE-AI framework

    A committee report, not yet binding: seven principles and 26 recommendations, including a board-approved AI policy, consumer protection and AI incident reporting.

    We designEvery AI feature ships with an owner, an evaluation set and an incident path.

    RBI · FREE-AI Committee Report, 13 August 2025

Compiled 2 October 2026. Our reading of typical programmes, not legal advice. Rules change; your counsel confirms how each one applies to you.

Challenges

Clarity at the moment of commitment, and a record of every step.

What borrowers and policyholders need before they sign, and what your teams must be able to prove afterwards.

Your customers

  1. Clarity at the moment of commitment

    Borrowers need the cost, the term and the way out before they sign.

  2. Proof that it is safe

    Customers judge security by the first screen and by every message after it.

  3. One journey across channels

    The app, the branch and the call centre should all know what happened last.

A woman signs a document at a table while a colleague reaches for the papers
The moment of commitment is where disclosure has to be clearest.

Your operation

  1. Disclosures that change

    Regulators update what a screen must show; journeys have to follow without a rebuild.

  2. Partners in the journey

    Lending service providers, apps and processors must all be disclosed and governed.

  3. An audit trail for everything

    Every consent, disclosure and decision needs a record a supervisor can read.

What we build

Disclosures designed in, not bolted on.

Journeys, the customer record and the secure platform beneath them carry most of a financial-services programme. Every line links to the capability that does the work.

Leads Core Supports Share of a typical programme, by role · illustrative
  1. Secure web and app builds, payment integration and audit-ready infrastructure.

  2. Onboarding, KYC and lending journeys designed around required disclosures.

  3. CRM rebuilt around the customer journey, with consent and suppression built in.

  4. 04

    Brand Design

    Core

    A brand that signals safety and clarity at the size of an app icon.

  5. Compliance-reviewed campaigns, and creator programmes that never promise returns.

  6. 06

    AI Design

    Supports

    Service assistants that cite the policy they answer from and hand off to people.

Programmes

Audit the journey first, then rebuild what costs you customers.

The way in walks every onboarding and lending journey against the directions that apply and ranks the fixes by drop-off and by risk. Lengths are typical, never promised.

The way in

Disclosure and journey audit

We walk every onboarding and lending journey against the RBI directions that apply, then rank the fixes by drop-off and by risk.

Package
Sprint · Fixed fee
Typical length
2–3 weeks
It sets
Drop-off at each disclosure step, as a baseline
  • Product experience audit
  • Compliance readiness

What it hands over

  • A disclosure-gap register against the RBI directions
  • Screen-by-screen evidence for your compliance review
  • A fix list ranked by risk and by lost applicants
Start here
  1. 02Milestone · 4–8 months

    Digital onboarding and video-KYC journey

    Application, PAN, video KYC and funding redesigned as one journey, tested with customers and integrated with your approved providers.

    MovesOnboarding completion rate

    Services: End-to-end UX & UI design · Web or mobile app · User research & usability testing

    Enquire about Digital onboarding and video-KYC journey
  2. 03Project · 8–12 weeks

    Lending journey with KFS and APR designed in

    The Key Fact Statement, the all-in APR and the cooling-off period designed as screens customers read, with every view logged.

    MovesDrop-off at each disclosure step

    Services: End-to-end UX & UI design · UX writing & content design

    Enquire about Lending journey with KFS and APR designed in
  3. 04Milestone · 4–9 months

    Journey-led CRM and lifecycle messaging

    One customer record behind every message, with consent, suppression and the last event known before anything is sent.

    MovesOpt-out and complaint rates

    Services: Customer data & identity foundation · Lifecycle journey build · Customer journey mapping

    Enquire about Journey-led CRM and lifecycle messaging
  4. 05Retainer · Ongoing

    Compliance-reviewed content and campaign system

    Templates and approved modules that move compliance review from every asset to the system that makes them.

    MovesCompliance review cycle time

    Services: Campaign design system · Content production retainer

    Enquire about Compliance-reviewed content and campaign system

How success is measured

The number we moveOnboarding completion

  • Onboarding completion rate
  • Drop-off at each disclosure step
  • Compliance review cycle time
  • Opt-out and complaint rates

AI, under the rules

AI that cites the policy, and hands hardship to people.

Each use case has an owner, an evaluation set and an incident path, in line with RBI’s FREE-AI recommendations; a person approves what matters, and every answer is kept for the audit trail.

Use case 01

Service assistant that cites policy

Measured byContained conversations, with the complaint rate held flat

Tested forOWASP LLM01 · Prompt injection

agent / service-assistant-that-cites-policy Guarded
  1. TaskAnswers account and loan questions from the product terms and the customer’s own record.
  2. GuardrailCites the clause it answers from, never quotes a rate it cannot see, and gives no investment advice.
  3. HumanComplaints, disputes and hardship go to a person with the full conversation.
  4. LogConversation, sources and hand-offs kept for the audit trail.

Ships only with its evaluation set, its guardrail and an owner

Use case 02

Disclosure checker

Measured byCompliance review cycle time

Tested forOWASP LLM06 · Excessive agency (it can block, never publish)

agent / disclosure-checker Guarded
  1. TaskChecks every journey release against the required KFS, APR and consent screens.
  2. GuardrailBlocks a release that removes or reorders a mandatory disclosure.
  3. HumanCompliance approves the release.
  4. LogEach check stored with the screen version it saw.

Ships only with its evaluation set, its guardrail and an owner

Use case 03

Plain-language hardship messages

Measured byComplaints per thousand contacts

Tested forOWASP LLM09 · Misinformation

agent / plain-language-hardship-messages Guarded
  1. TaskDrafts collection and hardship messages from approved templates in plain language.
  2. GuardrailContent rules forbid threats, false urgency and contact outside permitted hours.
  3. HumanThe collections lead approves every template change.
  4. LogEvery message tied to the template and the approval it came from.

Ships only with its evaluation set, its guardrail and an owner

A deliverable, in working code

Change one step of the funnel and the rest recalculates.

One hundred applicants through onboarding. Move how many clear each step and see where the largest drop goes and how many fund the account. Illustrative figures.

Onboarding funnel · KYCIllustrative

Of every hundred applicants who start

  1. Application started 100 of 100start lost at this step
  2. PAN verified 84 of 100−16 lost at this stepPre-fill from PAN
  3. Video KYC (V-CIP) Largest drop63 of 100−21 lost at this stepSlot booking added after the drop
  4. Key Fact Statement accepted 58 of 100−5 lost at this stepAPR shown before contract
  5. Account funded 52 of 100−6 lost at this step

KFS v3 shown · consent logged · cooling-off date sent

What it shows

An illustrative onboarding funnel of one hundred applicants: 84 verify PAN, 63 finish video KYC, 58 accept the Key Fact Statement and 52 fund the account, with each disclosure logged. Change how many clear a step and the rest of the funnel recalculates.

Figures

Every number here is an illustration of how the deliverable reads, never a client result.

Work and insights

Onboarding, lending and CRM, anonymised.

Financial-services projects, anonymised until each client approves the write-up, and what we have written on disclosures and consent.

All work in financial services

A typical programme · composite

A lender rebuilt its CRM around the customer journey, so every message knows what happened last and every disclosure is logged.

Anonymised and illustrative: the shape a programme takes, never a named client.

Questions

What product, risk and compliance leads ask us first.

Something else on your mind? Ask us directly

Q.01Do you build the lending or banking system itself?

We design and build the customer-facing journeys, the CRM and the integration layer. Core banking and loan management stay on your licensed platforms.

Q.02How do you handle KYC and video KYC?

We design the journey and its screens and integrate the KYC and V-CIP providers you have approved. Recordings and data stay where the RBI directions require.

Q.03Can AI be used inside regulated journeys?

Yes, inside guardrails: it cites its sources, it hands complaints and hardship to people, and every use has an owner, an evaluation set and an incident path — in line with RBI’s FREE-AI recommendations.

Q.04Who is responsible for compliance?

Your compliance team keeps sign-off. We design to the directions, keep a record of every disclosure screen and make their review faster.

Let’s build what happens next.

Tell us what you’re building. We’ll answer straight.

Book a discovery call

Three ways to start

  1. 01About 2 minutes

    A quick question

    You get A reply from a lead, not a sales queue

  2. 02About 8 minutesMost useful

    A project brief

    You get Options and a first scope after one call

  3. 03About 15 minutes

    A formal RFQ or RFP

    You get Receipt confirmed and a named bid lead

Every engagement starts with a written scope and a quote agreed before work begins. How each package is priced