A $12.5 million Series A for automating the most sensitive call a lender makes
FinTech Global reported on 21 August 2026 that Rezolv raised a USD 12.5 million Series A from Norwest, Vertex Ventures Southeast Asia and India, and 3one4 Capital, to build AI-native lending technology with a debt-collection platform at its centre. The same week's funding round-up carried Centricity raising USD 33 million, split as USD 27 million equity and USD 6 million venture debt, from the SMBC Asia Rising Fund, Lightspeed India Partners and the Burman Family Office, at a valuation of roughly USD 216 million.
Both rounds point at the same build-out of software sitting between an Indian regulated entity and its customer. Collections is the sharper case. Every other part of a lending stack automates a decision the lender makes internally. Collections automates a conversation with a borrower already in distress, at scale, about money the borrower cannot currently pay.
That is the most conduct-sensitive interaction in Indian retail lending, and it is the one the RBI has policed hardest through its recovery-agent expectations. Automating it does not move the regulatory consequence onto the software vendor. The lender is the regulated entity. When an automated call goes out at the wrong hour, in the wrong tone, or to the wrong number, the borrower complains about the NBFC, the ombudsman writes to the NBFC, and the supervisory action lands on the NBFC.
For brokers, this creates a two-sided placement problem that is worth setting up correctly now, while these platforms are still signing their first large regulated customers. The vendor needs technology errors and omissions and cyber cover sized to an obligation it has contractually accepted. The lender needs conduct, privacy and investigation-cost cover, plus a vendor contract whose indemnity and insurance clauses are worth something when a claim actually arrives.
Why the regulated lender absorbs the conduct consequence
The structural point that decides most of what follows is simple. Outsourcing an activity does not outsource accountability for it. An NBFC or bank that appoints a collection agent, human or software, remains answerable for how that agent behaves toward the borrower. The RBI's recovery-agent expectations run to the regulated entity, and a lender cannot answer a supervisory query by pointing at a vendor's model.
The failure modes an automated collections platform introduces are not exotic. They are the same conduct failures a badly run human agency produces, delivered faster and logged more completely:
- Contact at prohibited hours, or at a frequency that reads as harassment when aggregated across channels.
- Contact with a person who is not the borrower, including references, employers or family members, from stale or wrongly matched contact data.
- Misstatement of the amount due, the consequence of non-payment, or the borrower's legal position, generated by a model that was optimised for recovery rate rather than accuracy.
- Contact continuing after the borrower disputed the debt, requested a grievance escalation, or withdrew consent for a channel.
The practical consequence for the lender is that its own controls have to sit above the vendor's. Calling-window enforcement, frequency caps across channels, suppression lists for disputed and escalated accounts, and script approval have to be configured, tested and monitored by the lender's compliance function, not accepted as vendor defaults. The same governance discipline that [agentic underwriting deployments](/ai-insurtech/agentic-underwriting-governance-human-in-the-loop-commercial-india-2026) demand applies here with more force, because the counterparty is a retail borrower rather than a corporate risk.
The DPDP exposure follows the fiduciary, not the processor
Collections runs on personal data of an unusually sensitive kind: contact details, employment information, financial distress, and the fact of default itself. Under the DPDP Act 2023, the lender is the data fiduciary and the collections platform is a processor acting on the lender's instructions. The penalty schedule follows that split without much sympathy for the fiduciary.
The schedule provides for penalties of up to Rs 250 crore for failure to maintain reasonable security safeguards and up to Rs 200 crore for failure to notify a breach. That exposure attaches to the data fiduciary. If the vendor's environment is breached and borrower data leaks, the Data Protection Board's proceeding runs against the lender that appointed the processor, and the lender's recovery against the vendor is a contractual matter it has to litigate separately.
Three specific DPDP pressure points recur in collections deployments:
- Purpose limitation on contact data. Numbers and addresses collected at origination for servicing are being used for recovery contact, sometimes enriched from third-party sources. The lawful basis and the notice given at collection have to cover that use.
- Consent withdrawal and erasure. A borrower who withdraws consent for a channel, or exercises erasure rights on data no longer needed, creates an obligation the vendor's system must be able to execute, not merely record.
- Cross-border processing and sub-processors. A platform running inference on infrastructure outside India, or routing voice synthesis through a third-party model provider, extends the fiduciary's chain. The lender is accountable for the whole chain.
The insurance consequence is that DPDP penalties are, in most Indian cyber insurance wordings, either excluded outright as regulatory fines or available only where insurable by law and then heavily sublimited. What the cyber policy does reliably fund is the response: forensic investigation, legal representation before the Board, borrower notification, and the third-party claims that follow. That is not a small thing, and it is the part brokers should be sizing. The fiduciary-versus-processor split is worked through in more detail in our note on DPDP data-fiduciary liability and cyber cover.
Who regulates the model: MeitY's sectoral routing puts the RBI in charge
There is a common assumption among founders that AI governance in India is a single horizontal regime they can comply with once. It is not. The MeitY India AI Governance Guidelines, released on 5 November 2025, set out a techno-legal approach that places sector-specific AI rulemaking with sectoral regulators rather than creating a standalone AI statute.
For lending, that means the RBI. An AI collections platform deployed by an NBFC is governed through the RBI's expectations on the lender: outsourcing governance, recovery-agent conduct, grievance redressal, and the lender's own model and technology risk management. The vendor's compliance posture is relevant to the lender's diligence, and it is not a substitute for it.
For the platform, the practical effect is that its enterprise sales cycle is a governance audit. Regulated buyers ask for the model's decision boundaries, the human-review points, the audit log design and the data-residency map. That evidence pack also answers most of what a technology E&O underwriter wants to know.
The vendor side: technology E&O and cyber sized to the contract
A collections platform's insurance need is driven less by its own balance sheet than by what it has promised its customers. The relevant covers are professional indemnity in its technology errors and omissions form, and cyber.
Technology E&O responds to a claim that the software failed to perform as contracted and caused the customer financial loss. In collections, the realistic claim shapes are a calling-window control that did not enforce, a suppression list that did not apply, a model that generated a materially inaccurate statement of dues, or an integration defect that mis-mapped borrower records. The customer's loss is its own regulatory exposure, remediation cost, and any compensation it paid borrowers.
Cyber responds to compromise of the environment holding borrower data: incident response, forensics, notification, business interruption, and third-party liability arising from the breach. For a platform holding contact and default data on lakhs of borrowers, this is the larger tail.
Four underwriting questions decide the terms, and a founder should have the answers written down before broking the risk:
- What limit has been contractually promised? Enterprise lending customers routinely require a named insurance limit in the MSA. That number, not a risk assessment, usually sets the tower.
- Is the indemnity capped, and at what multiple? An uncapped indemnity for data-protection breach is common in Indian financial-services contracts and is effectively uninsurable at the limits a Series A company can afford.
- Does the E&O wording contemplate AI output? A wording silent on model-generated content leaves the vendor arguing about whether a hallucinated statement of dues is a covered error. Affirmative treatment is worth paying for.
- Where does the data sit, and who are the sub-processors? Residency and the sub-processor chain drive both the cyber rating and the customer's DPDP diligence.
Read the customer contract before the proposal form. For a B2B platform selling into regulated financial services, the insurance programme is largely a derivative of the MSA's liability, indemnity and insurance clauses. Placing cover without reading them produces a tower that is the wrong size in at least one direction.
The lender side: conduct, privacy and investigation costs
The NBFC or bank deploying the platform has a different exposure map, and it is broader than most lenders assume when they sign the vendor.
Regulatory investigation and defence costs are the first line item. A supervisory inspection, an ombudsman escalation cluster, or a Data Protection Board proceeding all generate external legal and forensic spend well before any penalty is determined. Investigation-cost cover, whether within a cyber policy, a directors and officers liability tower, or a specific financial-institutions professional indemnity wording, is what funds that phase. Check the trigger carefully: many wordings respond only to a formal proceeding, not to a preliminary regulatory query, which is when the spend actually starts.
Third-party claims from borrowers follow conduct failures. Harassment, defamation to third parties contacted in error, and mental-distress claims are pleaded in Indian consumer forums with increasing frequency. Personal-injury style extensions in a liability wording, and the privacy liability grant in cyber, are the places these land.
Directors' exposure arises where a governance failure in the outsourcing decision is alleged. A board that approved an automated collections rollout without documented conduct controls is exposed in a way a board that documented the control framework is not.
Vendor default risk is the residual. If the vendor's cover is inadequate or its indemnity is capped below the lender's loss, the lender's own policy carries the gap. This is the reason vendor insurance verification belongs in the procurement process rather than in the contract file. Our note on DPDP AI vendor governance sets out the diligence sequence in more detail.
The contract clauses to fix before the first automated call goes out
Most of the allocation between lender and vendor is decided in the MSA, and decided badly when insurance is raised after signature. Six clauses do the work.
- Scope of instruction and control. Define precisely what the platform decides autonomously and what the lender configures or approves: calling windows, frequency caps, script content, escalation triggers, suppression rules. A vendor operating inside lender-set parameters is in a materially different liability position from one exercising discretion.
- Data-processing terms. A DPDP-aligned processing agreement naming the purposes, the retention period, the sub-processors, the residency, the security measures, the breach-notification timeline to the fiduciary, and the vendor's obligation to execute consent-withdrawal and erasure instructions.
- Indemnity, with a cap that means something. An indemnity for the vendor's breach of the processing terms and for defective performance, capped at a multiple of fees that is realistically collectible and matched to insurance the vendor actually carries. An uncapped indemnity against a company with a USD 12.5 million balance sheet is a comfort clause, not a recovery.
- Insurance clause with named covers and limits. Technology E&O and cyber, at stated limits, with the lender as additional insured or loss payee where the wording permits, evidence produced annually, and notice of cancellation or material change.
- Audit and log-access rights. The lender needs contractual access to the platform's contact logs, model version history, and control-test evidence, in a form it can hand to a regulator without the vendor's cooperation being a precondition.
- Exit and data-return. Deletion certificates, transition assistance, and continuity of log access after termination, because a complaint about a call made in year two will surface in year four.
Where a wording is silent on AI-generated output, the default reading is that the insurer never priced it. Silence is not cover, and it is not an exclusion either, which is the worst of both positions for a claim.
Brokers advising either side of this deal are, in practice, comparing an E&O grant, a cyber privacy grant, and a financial-institutions professional indemnity wording clause by clause across several insurers to find where the automated-collections exposure actually sits. Sarvada gives commercial-insurance brokers structured, searchable access to insurer policy wordings, so the AI and outsourcing carve-outs across a client's tower can be read side by side rather than reconstructed from PDFs. Brokers building programmes for lending platforms and their NBFC customers can Request Access to evaluate the platform.