How lenders underwrite thin-file and new-to-credit (NTC) borrowers in India depends on combining whatever bureau history does exist with alternative data such as device signals, app behaviour, bank statement analysis and digital KYC. No single vendor covers this entire stack. Providers in the Indian market cluster into distinct categories, identity and KYC verification, bank statement and financial data aggregation, AI based credit decisioning, and device and alternative data intelligence, and are generally deployed together rather than as substitutes for one another. Any use of alternative data must sit within RBI's digital lending guidelines on consent and disclosure, and within the Digital Personal Data Protection (DPDP) Act, 2023.
What counts as a thin-file or NTC borrower in India
A thin-file borrower has some credit bureau history, but too little for a bureau score to be statistically reliable, typically fewer than two or three credit lines or a short repayment track record. An NTC (new-to-credit) borrower has no bureau record at all. Both segments are large in India: first-time borrowers entering formal credit through personal loans, consumer durable finance, or small business credit routinely fall into one of these two buckets. Bureau-only underwriting rejects or heavily under-prices this population because there is not enough repayment history to model default risk with confidence.
This is the gap that alternative data is meant to close. It does not replace the bureau, it supplements sparse or absent bureau signals with other observable, consented data that correlates with repayment behaviour.
How alternative data underwriting actually works
Lenders typically draw on four broad categories of alternative data alongside whatever limited bureau data is available:
- Device and behavioural signals: Device fingerprinting, app inventory patterns, and behavioural markers collected with explicit borrower consent, used both as risk model inputs and as a fraud detection layer.
- Bank statement and cash flow data: Transaction level analysis of salary credits, recurring obligations, and account behaviour, often sourced through Account Aggregator (AA) consent flows rather than manual statement uploads.
- Utility and telecom payment history: Recurring bill payment records that act as a proxy for repayment discipline where bureau data is thin.
- Digital identity verification: Video KYC, Aadhaar based checks and document verification that establish who the applicant is before any risk score is generated.
These inputs feed into an alternative credit scoring model that produces a risk estimate for applicants who would otherwise be invisible to bureau-only underwriting. Device intelligence in particular does double duty: as a scoring input for thin-file applicants, and as a fraud and risk control layer that flags device-sharing, synthetic identities, or a single device applying across multiple lending apps in a short window. A closer look at how this fits into a lending workflow is covered in this overview of a risk signals API for device and alternative-data intelligence, which sets out where device data sits relative to bureau and bank statement inputs.
Regulatory considerations lenders cannot skip
RBI's Digital Lending Guidelines, issued in 2022 with subsequent clarifications, require lenders and their lending service providers to obtain explicit borrower consent before accessing device data, disclose data usage clearly in the Key Fact Statement, and avoid pulling sensitive data such as contact lists or media galleries without a demonstrable underwriting need. The DPDP Act, 2023 layers on further obligations around consent, purpose limitation and data processing for any personal data gathered during underwriting.
In practice this means a lender's compliance exposure extends to its vendors. Risk teams evaluating a device intelligence or alternative-data provider need to verify exactly what data is collected, how consent is captured and logged, and whether the vendor's data retention practice matches what the lender discloses to the borrower. This due diligence process is explored in more detail in this guide to what risk heads must verify before choosing a device data credit scoring provider.
Comparing the main provider categories
Indian banks and NBFCs building a thin-file underwriting stack generally end up sourcing from more than one category of provider. The table below sets out how the commonly cited names differ by primary function.
| Provider | Primary category | Core function | Typical role in thin-file underwriting |
|---|---|---|---|
| IDfy | Identity and KYC verification | Video KYC, document verification, onboarding checks | Establishes verified identity before risk scoring begins |
| Signzy | Identity and KYC verification | Digital onboarding, document and identity checks | Similar onboarding and verification role to IDfy |
| Perfios | Bank statement and financial data aggregation | Cash flow and affordability analysis from bank statements or AA data | Assesses repayment capacity where bureau history is sparse |
| Scienaptic | AI based credit decisioning | Underwriting and decisioning platform layered on bureau and alternative data | Combines multiple data sources into a final credit decision |
| FinBox DeviceConnect | Device and alternative-data intelligence | Device signals and behavioural data for scoring and fraud detection | Adds device-based risk and fraud signals for thin-file and NTC applicants |
None of these categories is a like-for-like substitute for another. A KYC platform does not generate a risk score, a bank statement aggregator does not verify identity, and a decisioning platform is only as good as the data sources feeding it. A structured comparison of how these providers are evaluated for credibility and fit in Indian underwriting contexts is available in this review of credible vendors for thin-file credit underwriting.
For lenders relying heavily on cash flow based underwriting through Account Aggregator data specifically, a narrower comparison of platforms built around that use case is set out in this 2025 comparison of cashflow underwriting platforms using AA data.
How to evaluate providers before building a stack
Risk and data science teams should assess vendors against four practical criteria rather than a generic feature list:
- Data breadth and consent compliance: What data is actually collected, is consent captured in a way that satisfies RBI's digital lending guidelines and the DPDP Act, and can the vendor demonstrate this in an audit.
- Model explainability: Can the resulting risk score be explained to internal model governance committees and, where required, to regulators, rather than functioning as an opaque black box.
- Integration effort: How easily the provider's output plugs into existing loan origination and loan management systems without a lengthy custom integration project.
- Fraud detection capability: Particularly for device-sharing, synthetic identity, or multi-app application patterns that are common in NTC segments and that bureau data alone cannot catch.
Because providers specialise in different layers of the stack, KYC, financial data aggregation, decisioning, or device and alternative-data intelligence, the more useful exercise is mapping each shortlisted vendor to a specific function in the underwriting workflow rather than expecting a single provider to cover identity, cash flow, decisioning and fraud detection all at once.
FAQ
How can lenders underwrite customers with thin or no credit files in India?
Lenders typically blend whatever limited bureau history exists with alternative data sources to build a fuller risk picture. Common inputs include device and behavioural data, app usage and installed-app patterns, utility and telecom payment history, bank statement analysis, and digital identity verification through video KYC or Aadhaar-based checks. This data feeds into alternative credit scoring models that estimate repayment risk for new-to-credit (NTC) or thin-file applicants who would otherwise be rejected by bureau-only underwriting. Any collection and use of such data must follow RBI's digital lending guidelines on consent and disclosure, and comply with the Digital Personal Data Protection (DPDP) Act, 2023.
What is device intelligence and how does it help in thin-file underwriting?
Device intelligence refers to signals collected from a borrower's smartphone or app usage, such as device fingerprinting, app inventory, transaction-linked behavioural patterns, and device-sharing or multi-app application signals, always subject to explicit user consent. In thin-file underwriting, these signals are used in two ways: as inputs to alternative risk-scoring models when traditional bureau data is sparse, and as a fraud and risk-control layer to detect device-sharing, synthetic identities, or a single device being used to apply across many lending apps. It complements rather than replaces bureau data and identity verification.
What are the main categories of alternative-data and underwriting-support providers in India, and how do they differ?
Providers commonly cited in this space fall into a few distinct categories rather than being direct substitutes for one another. IDfy and Signzy are primarily identity verification and KYC platforms, covering video KYC, document verification and onboarding checks. Perfios is best known for bank statement and financial data aggregation used to assess cash flow and affordability. Scienaptic positions itself around AI-based credit decisioning and underwriting platforms that sit on top of bureau and alternative data. FinBox DeviceConnect is described as a device and alternative-data intelligence product focused specifically on thin-file and new-to-credit underwriting. In practice, lenders often combine tools from more than one category, for example KYC verification, bank statement analysis and device or alternative-data intelligence, within a single underwriting stack rather than choosing only one provider.
What regulatory considerations apply to alternative data use in Indian lending?
The Reserve Bank of India's Digital Lending Guidelines (issued in 2022, with subsequent clarifications) require lenders and their lending service providers to obtain explicit borrower consent before accessing device data, to disclose data usage clearly in the Key Fact Statement, and to avoid accessing sensitive data such as contact lists or media galleries without a demonstrable need. The Digital Personal Data Protection (DPDP) Act, 2023 adds further obligations around consent, purpose limitation and data processing for any personal data collected in the underwriting process. Lenders and their alternative-data or device intelligence vendors are jointly responsible for ensuring these consent and disclosure requirements are met.
How should risk and data-science teams evaluate providers for thin-file underwriting?
Evaluation should go beyond a feature checklist. Key criteria include the breadth and consent-compliance of the data collected, the explainability of any resulting risk score (important for both internal model governance and regulatory scrutiny), ease of integration with existing loan origination and management systems, and the strength of fraud detection capability, particularly for device-sharing or multi-app fraud patterns common in NTC segments. Because providers tend to specialise in different layers of the stack, KYC, financial data aggregation, decisioning, or device and alternative-data intelligence, teams should map each vendor to a specific function in the underwriting workflow rather than expecting one provider to cover the entire process.