Stories

FLEXILOANS: THE LOAN APPROVAL THAT SEEMS TO EVAPORATE AFTER THE CLICK

“Your Loan Is Approved” — Then Come The Documents, The Verification, The Rejection And The Questions

There is something profoundly uncomfortable about a lender telling a customer that a sizeable business loan is already approved, only for the customer to discover that the supposed approval still needs documents, verification and another round of underwriting.

It becomes considerably more uncomfortable when the same customer later alleges that the application was rejected, that a credit enquiry appeared on the credit report, and that another financial product was subsequently offered.

And it becomes a matter deserving regulatory scrutiny when similar stories begin appearing in public complaints, online reviews and forums against an entity operating under the regulatory umbrella of the Reserve Bank of India.

This is the uncomfortable question surrounding FlexiLoans, the consumer-facing lending brand of Epimoney Private Limited: when the message says “approved”, what exactly has been approved?

The marketing message?

The lead?

The click?

The data capture?

The customer’s willingness to enter the lending funnel?

Or an actual credit decision?

That is not a semantic question. In digital lending, words can have financial consequences.

A customer who sees “you may be eligible” understands one thing.

A customer who sees “pre-approved” understands something stronger.

A customer who sees that a loan is “ready for disbursal” reasonably understands something stronger still.

And a customer who sees that a loan is “approved” may reasonably believe that the lender has already made the substantive credit decision.

That distinction is precisely why the allegations around FlexiLoans deserve much closer examination.


THE COMPANY IS NOT A SMALL, UNKNOWN DIGITAL OPERATOR

FlexiLoans is not operating from some regulatory grey zone.

Its own website identifies Epimoney Private Limited as the legal entity behind the FlexiLoans brand and describes Epimoney as an RBI-registered Non-Banking Financial Company. The company says it was founded in 2016, has more than 700 employees, has disbursed more than ₹13,000 crore and has served more than 100,000 businesses. It also says that its lending engine analyses more than 500 data points and that it offers business loans up to ₹50 lakh.

In other words, this is a sizeable digital-credit operation.

CRISIL’s February 2026 rating rationale places the company’s consolidated assets under management at approximately ₹2,467 crore as of December 31, 2025, up from ₹2,245 crore at March 31, 2025. CRISIL reported standalone profit after tax of ₹7.5 crore on total income of ₹337 crore for the nine months ended December 31, 2025.

For March 2025, CRISIL reported consolidated AUM of ₹2,245 crore, total income of ₹386 crore and profit after tax of ₹4.2 crore. The same rating rationale reported 90+ days past due, excluding write-offs, at 4.7% at March 31, 2025.

The scale matters because the larger the lending machine becomes, the less convincing the argument that troubling customer experiences are merely random accidents becomes.

A company processing credit at scale is expected to have systems.

It is expected to have audit trails.

It is expected to know what constitutes an application.

It is expected to know what constitutes a pre-approved offer.

It is expected to know exactly when a credit enquiry is triggered.

It is expected to know what consent was obtained.

And, above all, it is expected to know what its own SMS and WhatsApp messages actually tell customers.


THE MESSAGE THAT STARTS THE ENTIRE CONTROVERSY

One of the most troubling examples published by Inventiva concerns a WhatsApp communication attributed to “FlexiLoans Technologies P…” concerning a ₹22,90,737 CGTMSE business loan.

The message described the loan as “pre-approved at 1% Interest” and “ready for disbursal”, while directing the recipient to review and complete the application. Minutes later, according to the published account, another message stated that the ₹22,90,737 application was still being reviewed, identified a reference number, and requested pending information for verification.

There is nothing complicated about the contradiction.

One communication says, in substance:

the money is ready.

The next communication says, in substance:

the application is still under review.

That is precisely where an ordinary customer is entitled to ask:

Which one is true?

A pre-approved offer can, of course, be conditional. A lender may pre-screen a customer and subsequently undertake KYC, fraud checks, eligibility verification and other procedures.

But that makes the precision of the communication even more important.

The problem is not that a lender performs verification.

The problem is the possible mismatch between what the customer is told before clicking and what the customer discovers after clicking.

If “ready for disbursal” really means “subject to further verification and a fresh credit decision”, why use language that sounds substantially more final?

If the loan is genuinely approved, why does the recipient still need to complete material stages of the credit process?

The public deserves an answer to that question—not a marketing explanation, but a compliance explanation.


THEN THERE IS THE ₹27-LAKH “APPROVAL”

Another published customer account is even more disturbing.

Inventiva reported that a recipient received an SMS and WhatsApp communication saying that approximately ₹27 lakh had been approved, despite the customer not having a recent live loan application. The published account states that the customer had an older rejected application dating back several years.

According to that report, the customer followed the communication, was asked for Aadhaar and PAN information, and was subsequently informed that the application could not proceed following an internal check.

That account is not a judicial finding.

It is not proof that FlexiLoans deliberately fabricated an approval.

But it raises a question sufficiently straightforward that a regulator should not need an elaborate theoretical framework to investigate it:

Where is the underlying application?

If there was a live application, what was its date?

Who initiated it?

When was consent captured?

What exact product was the customer applying for?

Was the ₹27-lakh communication generated before or after credit underwriting?

Was the amount actually sanctioned?

Was the message generated automatically by a rules engine?

Was it a marketing template?

Was it a conditional eligibility communication incorrectly labelled as an approval?

Did a third-party Lending Service Provider generate it?

Was any bureau enquiry subsequently initiated?

And most importantly:

What do the system logs show?

A digital lender should not have to guess the answer.

The company should have it.


THE CIBIL QUESTION: A CREDIT ENQUIRY IS NOT A TRIVIAL TECHNICALITY

This is where the issue moves beyond annoying marketing.

TransUnion CIBIL itself explains that enquiries form part of the information used in calculating the CIBIL Score and warns that multiple enquiries in a short period can negatively affect the score because lenders may interpret them as evidence of heightened credit-seeking behaviour.

That does not mean every hard enquiry automatically causes some fixed number of points to disappear.

Indeed, publicly circulating claims that one enquiry necessarily costs a particular number of points should not be treated as a universal rule. CIBIL says the impact depends upon the overall credit profile and that multiple enquiries can be a negative factor.

But the underlying issue is still serious.

A credit enquiry exists because a credit institution has accessed the consumer’s credit information.

CIBIL explains that its enquiry section records requests made by credit institutions in connection with credit applications, and that lenders may treat multiple enquiries within a short period with caution.

That creates a simple principle:

A consumer should know when a marketing communication has turned into a credit application.

There is a huge difference between:

“You may be eligible for ₹25 lakh.”

and:

“Your ₹25 lakh loan has been approved.”

There is another difference between clicking an advertisement and consciously applying for credit.

And there is yet another difference between submitting information for a quotation and authorising a lender to conduct the kind of credit assessment that produces an enquiry on a bureau file.

The question for FlexiLoans is therefore not merely whether a customer eventually got rejected.

The more important question is:

At exactly what point did the interaction become a credit application, and what evidence of customer consent exists at that precise point?


RBI HAS ALREADY WRITTEN THE RULEBOOK

This is not an industry without standards.

The RBI’s Guidelines on Digital Lending, issued on September 2, 2022, expressly state that outsourcing arrangements with Lending Service Providers do not diminish the obligations of the regulated entity. The regulated entity remains responsible for ensuring compliance by the LSPs and Digital Lending Apps working with it.

That is critical.

Because “our partner sent the message” is not a satisfactory regulatory escape hatch.

The RBI framework also requires digital lending arrangements to comply with prescribed requirements concerning borrower data, privacy, disclosures, grievance redressal and credit reporting. RBI material specifically states that data collected through digital lending applications should be need-based, have clear audit trails and be collected only with prior explicit consent of the borrower.

The RBI’s digital lending guidelines additionally require a Key Fact Statement, disclosure of the Annual Percentage Rate, disclosure of relevant charges, and provision of specified digitally signed documents to borrowers.

The RBI has also explicitly emphasised the continuing responsibility of regulated entities for the conduct of their digital lending partners and the existence of a specific grievance-redressal mechanism for digital-lending complaints.

So when a digital lending communication allegedly tells a customer that a substantial loan is approved, the real regulatory question is not:

“Was it only a marketing SMS?”

It is:

“Was the communication truthful, transparent, properly consented to, properly sourced, and consistent with the actual credit status recorded in the lender’s systems?”

That is a much more serious question.


EVEN FLEXILOANS’ OWN RULEBOOK MAKES THE QUESTIONS HARDER

The irony becomes sharper when FlexiLoans’ own published Fair Practices Code is read against the allegations.

The company’s Fair Practices Code says that digital lending platforms acting as sourcing agents should disclose the company’s name and identify the agent on whose behalf they are interacting with the customer.

It further says that immediately after sanction but before execution of the loan agreement, the sanction letter and/or KFS should be issued to the customer on the company’s letterhead.

It also expressly states that effective oversight and monitoring should be ensured over digital lending platforms engaged by the company.

The company’s published policy also says that its interest-rate model considers factors such as cost of funds, margin and risk premium, and that the rate and rationale for risk-based gradation are to be disclosed.

Those are sensible safeguards.

They also make the alleged “approved first, verified later” customer experience particularly worthy of investigation.

Because if the system knows the difference between:

lead → eligibility → application → underwriting → sanction → documentation → disbursal

then why should its marketing communication blur those stages?


THE “1% INTEREST” QUESTION

The ₹22.9-lakh communication presents another issue.

It advertised the offer as being at “1% Interest.”

But “1% interest” without stating clearly whether the rate is monthly, annual, flat, reducing-balance, or otherwise structured is hardly the kind of precision consumers deserve when evaluating a borrowing proposition.

FlexiLoans’ own public website elsewhere describes business-loan pricing and states that certain products can start at rates as low as 1% per month, depending on factors including amount, tenure and eligibility.

That makes disclosure even more important.

A sophisticated borrower understands the difference between:

1% per month

and

1% per annum.

A customer does not need marketing poetry.

A customer needs the actual cost of borrowing.

The RBI’s digital-lending framework requires the Annual Percentage Rate to be disclosed upfront and included in the KFS.

So the question is not merely whether “1%” appeared in an SMS.

The question is whether the consumer was being given enough information to understand what that 1% actually meant.


THEN COMES THE CONSENT ISSUE

The unsolicited-message allegations raise another regulatory fault line.

TRAI’s commercial-communication framework provides a formal preference-registration mechanism covering categories including banking, insurance, financial products and credit cards. Consumers can register preferences concerning modes of communication, categories, time bands and days.

TRAI’s framework also uses a Digital Consent Acquisition mechanism under which consent for commercial communication can be acquired and recorded through the telecom ecosystem, including verification through OTP.

That means the question of consent is not supposed to live in a mysterious fog of:

“The customer must have agreed somewhere.”

A serious compliance system should be able to answer:

When?

How?

For what product?

For what sender?

For what category?

Through which mechanism?

Was consent still valid?

Was it revoked?

Was the particular communication covered?

Where is the DLT record?

And if the customer says, “I never asked for this loan,” the answer should come from an audit trail—not from an improvisation by a call-centre employee.


“WE HAVE A PRIVACY POLICY” IS NOT THE END OF THE STORY

FlexiLoans publishes a privacy policy and says users consent to the collection, use, processing and disclosure of information by accepting its terms. It also says users who do not wish to receive mailers can opt out, while administrative and transactional communications may continue.

Its terms further state that customer information may be made available to authorised members, agents and lending partners, who may contact users for information and sales, and that users agree to receive promotional material through email or text message.

But a broad website consent clause does not automatically answer the narrower question at the heart of the controversy.

A person consenting to use a website is not the same thing as proving that the person consented to a particular commercial communication.

A person submitting data during a previous application is not necessarily the same thing as proving a present application for a ₹27-lakh loan.

And consent to receive marketing material is not an invitation to describe an unapproved loan as approved.

The investigation must therefore examine what consent existed—not merely whether a consent policy existed.


THE PUBLIC COMPLAINTS: SMOKE, FIRE — OR SOMETHING ELSE?

Public complaints and reviews deserve neither blind acceptance nor contempt.

Inventiva’s reporting records multiple customer accounts involving alleged unsolicited “loan approved” messages, document requests, rejection, bureau enquiries, later sales approaches and complaints concerning customer-service or recovery experiences.

The public record also includes Reddit discussions where users have reported receiving similar-looking loan-approval messages and questioned whether they were genuine.

But here journalism must remain disciplined.

A Google review is not an affidavit.

A Reddit post is not forensic evidence.

A customer’s recollection is not a regulatory finding.

And ten anecdotes do not automatically become a statistical study.

That is precisely why these complaints should not simply be dismissed—or sensationally converted into proven criminal conduct.

They should be investigated.

The digital nature of the alleged conduct makes investigation unusually feasible.

There should be logs.

There should be template IDs.

There should be header registrations.

There should be consent records.

There should be CRM activity.

There should be IP/device information.

There should be application timestamps.

There should be underwriting timestamps.

There should be bureau-enquiry timestamps.

There should be KYC submission timestamps.

There should be rejection codes.

There should be call recordings.

There should be partner/LSP records.

There should be records showing what happened immediately before and immediately after each disputed message.

A regulator does not need to believe a Redditor.

It needs to examine the servers.


THE COMPANY ACTUALLY HAS A GRIEVANCE SYSTEM — SO USE IT

There is another important fact that should not be ignored.

FlexiLoans publicly provides a multi-level grievance mechanism. Its current grievance page says complaints are first handled by customer service, can move to the Customer Service Head, then to the Grievance Redressal Officer, and ultimately to the RBI Ombudsman if the complaint remains unresolved after the applicable period.

That is a positive compliance infrastructure on paper.

But regulatory compliance is not measured by the existence of an email address.

It is measured by what happens when a customer actually complains.

If a customer says:

“I never applied.”

The investigation should identify the application.

If the customer says:

“I never consented.”

The company should produce the consent record.

If the customer says:

“You damaged my CIBIL.”

The company should identify every bureau enquiry associated with the customer’s profile and explain its legal and contractual basis.

If the customer says:

“Your SMS said approved.”

The company should produce the exact underlying status that triggered that SMS.

And if the answer is:

“That was just a proposal.”

then the next question is unavoidable:

Why was it worded like an approval?


THERE IS ALSO AN IMPORTANT FACT THAT SHOULD NOT BE MISREPRESENTED

A responsible investigation must record facts that cut the other way.

Epimoney’s FY2025 annual-report material states that the Reserve Bank of India had not imposed any penalty on the company during that financial year.

That fact matters.

It would be irresponsible to imply that RBI has already found FlexiLoans guilty of the specific SMS allegations discussed here.

There is no such finding established by the material reviewed for this article.

At the same time, the FY2025 reporting records eight instances of financial-covenant breaches across five lenders, primarily related to asset quality, although it states that the breaches were promptly communicated and that no loans were recalled because of those breaches.

That information does not prove anything about SMS marketing.

It does, however, reinforce a broader point: this is a regulated financial institution operating a material credit portfolio, not an inconsequential advertising start-up whose communications can simply be waved away as harmless promotional noise.


THE RECOVERY COMPLAINTS SHOULD ALSO BE AUDITED — BUT NOT CONFUSED WITH THE SMS CASE

Public reporting around FlexiLoans also contains allegations concerning recovery conduct, including complaints about repeated calls, alleged contact with third parties, disputed accounts and other collection-related grievances. Those allegations require independent verification and should not be merged indiscriminately with the approval-SMS allegations.

The RBI has long stressed fair treatment in recovery and has warned regulated entities against intimidation, harassment and misleading representations by lenders or their agents.

The important issue is therefore one of governance.

If an NBFC uses a large network of employees, collection agents, technology platforms and lending partners, the compliance question is not merely:

“What did headquarters instruct?”

It is also:

“What did the ecosystem actually do?”

The RBI’s outsourcing framework makes regulated entities responsible for oversight rather than allowing them to treat outsourced conduct as somebody else’s problem.


THE MOST UNCOMFORTABLE POSSIBILITY IS ALSO THE SIMPLEST ONE

Perhaps there is no grand conspiracy.

Perhaps there is no secret operation designed to damage anybody’s CIBIL.

Perhaps the disputed communications are badly worded lead-generation messages generated by an over-aggressive marketing system.

Perhaps “approved” really means “pre-screened”.

Perhaps “pre-approved” really means “subject to verification”.

Perhaps some bureau enquiries were legitimately consented to.

Perhaps some complaints arise from misunderstandings.

All of those possibilities must remain open.

But there is an equally uncomfortable possibility:

That aggressive acquisition incentives have produced a system in which certainty is marketed before certainty exists.

That is the hypothesis the regulator should test.

Because “Your loan may be available” is a marketing proposition.

“Your loan has been approved” is a representation about the status of a financial transaction.

Those are not interchangeable sentences.


WHAT RBI, TRAI AND CREDIT BUREAUS SHOULD NOW DEMAND

The appropriate response is not another generic assurance.

It is a forensic audit.

RBI should require Epimoney/FlexiLoans to produce the complete universe of disputed “approved”, “pre-approved” and “ready for disbursal” communications for a defined audit period, together with the underlying application and underwriting status for each communication.

For every disputed customer, regulators should establish:

Was there a live application?

When was it created?

Who created it?

What consent was captured?

What product was applied for?

What amount was actually sanctioned, if any?

What internal status triggered the message?

Was KYC completed before or after the claimed approval?

Was a credit enquiry generated?

Which bureau received it?

Was it a hard or soft enquiry?

What consent and disclosure supported it?

Was the enquiry later disputed?

What happened to the enquiry after the dispute?

Was another FlexiLoans or partner product marketed to the customer afterwards?

Was the second product more expensive or secured?

Which employee, LSP, API, campaign, CRM rule or automated workflow initiated each stage?

That is how allegations become evidence.


TRAI SHOULD FOLLOW THE MESSAGE, NOT JUST THE CUSTOMER

TRAI should independently examine the disputed communications through telecom records.

For each message, the audit trail should identify:

the principal entity,

the sender/header,

the registered template,

the content template,

the delivery channel,

the consent record,

the relevant customer preference,

the date of communication,

and the telecom trail associated with the message.

The system already exists precisely so that commercial communications are not supposed to operate as anonymous digital graffiti. TRAI’s framework provides mechanisms for preference registration, consent recording, complaint management and sender/template controls.

There is no reason for the public to accept “marketing mistake” as the end of the inquiry when a properly configured telecom ecosystem can potentially reveal who sent what, under which template and pursuant to what registered consent.


CREDIT BUREAUS SHOULD LOOK AT THE OTHER END OF THE PIPE

The same scrutiny should be applied to CIBIL and other credit information companies.

The question is not simply whether an enquiry appeared.

It is whether the enquiry corresponded to a genuine credit application.

That distinction is vital.

A lender should not obtain the commercial and economic benefit of turning a marketing lead into a bureau event while leaving the consumer to discover the consequences afterward.

Where customers dispute enquiries, a structured audit should compare:

marketing contact → click → application → consent → bureau request → underwriting decision → rejection → subsequent offer.

The timestamps may tell the story more clearly than any press release.


“LOAN NAHI, SAMJHO TARKKI HAI” CAN BECOME A VERY DIFFERENT SLOGAN

FlexiLoans publicly presents itself with the slogan “Loan Nahi, Samjho Tarakki Hai” and markets speed, flexibility and digital convenience.

The irony writes itself.

For a small business desperate for working capital, the arrival of a message announcing approval of ₹20 lakh or ₹27 lakh does not feel like an ordinary advertisement.

It feels like relief.

It feels like liquidity.

It feels like rescue.

That emotional effect is precisely why approval language must be handled with extraordinary care.

Because once a borrower believes the loan is already approved, the psychological barrier to handing over Aadhaar, PAN, financial statements and other documents drops dramatically.

The message does not merely communicate.

It persuades.

And when the persuasion concerns regulated credit, persuasion comes with regulatory consequences.


THE WORD “APPROVED” SHOULD NOT BE A MARKETING PROP

There is nothing wrong with digital lending.

There is nothing wrong with automated underwriting.

There is nothing wrong with targeted offers.

There is nothing wrong with a lender proactively identifying customers who may qualify for credit.

What is problematic is the potential conversion of uncertainty into certainty through language.

“Eligible.”

“Indicative.”

“Pre-qualified.”

“Subject to verification.”

“Conditional offer.”

Those terms tell the customer that the process is not complete.

“Approved.”

“Sanctioned.”

“Ready for disbursal.”

Those words carry a materially stronger message.

A regulated financial institution should know the difference.

Indeed, it should be obsessive about the difference.

Because if the customer discovers after clicking that the supposedly approved loan is still under review, the customer has been told one story by the marketing funnel and another by the underwriting system.

That is not technological innovation.

That is a governance problem.


THE BIGGER QUESTION: WHO BENEFITS FROM THE CONFUSION?

This is the question that an actual investigative investigation should answer.

Suppose a customer receives an approval message.

The customer clicks.

The customer submits identity documents.

The customer enters the lending funnel.

The customer undergoes further verification.

The customer is rejected.

A bureau enquiry appears.

A different product is subsequently offered.

Who benefits?

The customer?

Clearly not, if the allegations are correct.

The marketing team?

Potentially, if the objective is lead conversion.

The technology platform?

Potentially, if the funnel generates measurable engagement.

The lending ecosystem?

Potentially, if rejected customers can be converted into alternative products.

None of this proves misconduct.

But it establishes a powerful investigative hypothesis:

Was “approval” being used as a conversion mechanism rather than as a faithful description of a completed credit decision?

That is the question that should be answered with system data—not corporate assurances.


AND THIS IS WHERE THE REGULATOR MUST BE FASTER THAN THE MARKETING ENGINE

Digital lending operates at machine speed.

A campaign can reach thousands of phones while a complaint is still sitting in an inbox.

An automated decision can generate an enquiry in seconds.

A customer-service investigation can take days.

A regulatory investigation can take months.

That asymmetry is dangerous.

By the time an authority begins asking for logs, the campaign may have changed.

Templates may have disappeared.

Vendors may have changed.

Employees may have moved.

CRM configurations may have been overwritten.

The regulator therefore needs to move quickly whenever there is credible evidence of systematic conduct.

Preserve the logs.

Preserve the messages.

Preserve the consent records.

Preserve the bureau requests.

Preserve the call recordings.

Preserve the vendor records.

Then investigate.

Not the other way around.


WHAT FLEXILOANS SHOULD ANSWER — IN PUBLIC AND WITH DOCUMENTS

The appropriate response from FlexiLoans is not simply that it is an RBI-registered NBFC.

Everyone already knows that.

The relevant questions are far narrower and far harder.

How many customers received “approved” or “pre-approved” communications during the relevant period?

How many of those customers had live applications?

How many had previously rejected applications?

How many messages used the words “approved”, “pre-approved” or “ready for disbursal”?

What internal status triggered those messages?

How many recipients subsequently submitted KYC documents?

How many generated hard bureau enquiries?

How many enquiries were later disputed?

How many complaints concerning alleged unauthorised enquiries were received?

How many communications were generated by FlexiLoans itself and how many by LSPs, marketing partners or technology vendors?

What proportion of such recipients subsequently received offers for other financial products?

What controls prevent a marketing message from describing a loan as approved before sanction?

Those answers would do more to settle the controversy than any public-relations paragraph ever could.


THE DEMAND IS NOT FOR A VERDICT. IT IS FOR AN INVESTIGATION.

The temptation in cases like this is to declare everything proven.

That would be bad journalism.

The opposite temptation is equally dangerous: to dismiss everything because no court has convicted anyone.

That would also be bad journalism.

Journalism exists precisely in the space between allegation and adjudication.

The public record currently supports a serious set of questions concerning allegedly misleading approval language, consent, KYC collection, credit enquiries and subsequent customer treatment. The published customer accounts are not themselves proof of a coordinated scheme. But the allegations are sufficiently specific, technically testable and potentially consequential that regulators should not leave the matter at the level of online arguments.

The evidence exists somewhere.

It is inside databases.

It is inside consent systems.

It is inside SMS gateways.

It is inside CRM records.

It is inside credit-bureau enquiries.

It is inside application logs.

And it is inside the audit trail.

The job now is to retrieve it.


A FINAL QUESTION FOR FLEXILOANS

A company can survive a bad review.

A company can survive an angry Reddit post.

A company can survive a newspaper investigation.

What a regulated lender cannot afford to survive is the loss of credibility in the word “approved.”

Because if “approved” means approved, then show the approval.

If it means pre-qualified, call it pre-qualified.

If it means indicative, call it indicative.

If it means subject to verification, say that.

If it means the customer still has to submit documents and pass underwriting, do not make the message sound as though the underwriting is over.

The difference may appear to be one word.

For the customer, that one word can determine whether he clicks, uploads documents, applies for credit, creates a bureau enquiry and enters another sales funnel.

That is why the FlexiLoans controversy should not be trivialised as a dispute over wording.

It is a dispute about whether a regulated digital lender’s words accurately describe what its systems have actually decided.

And that is a question regulators have every reason to answer.


THE REQUIRED DISCLAIMER

DISCLAIMER / LEGAL NOTICE:
This article is an investigative and analytical report based on publicly available regulatory material, corporate disclosures, credit-rating information, published customer accounts, online reviews and publicly accessible reports. References to alleged misleading SMS/WhatsApp communications, alleged unauthorised or unwanted credit enquiries, alleged KYC/data practices, alleged subsequent marketing of other products and alleged customer-service or recovery misconduct are allegations and reported customer experiences unless expressly identified as an independently verified fact or finding of an authority. Public reviews, Reddit posts and individual customer statements are not treated as conclusive proof of systemic misconduct.

The publication does not state that FlexiLoans, Epimoney Private Limited, its directors, employees, agents or service providers have committed fraud or any other criminal offence as an established fact. No conclusion of criminal guilt should be inferred merely from the allegations discussed in this article. Based on the public material reviewed for this report, no court of law has convicted FlexiLoans/Epimoney Private Limited in respect of the specific “approved-loan SMS”, alleged CIBIL-enquiry and related allegations examined here. The absence of a conviction is not a finding that the allegations are true or false; only a competent investigating and adjudicating authority can determine that.

FlexiLoans/Epimoney Private Limited should be given a full and meaningful opportunity to respond to every specific allegation, produce relevant records and correct any factual errors. Any later response, clarification, regulatory finding, investigation report, charge-sheet, adjudicatory order or judicial decision should be reported with equal prominence.

PUBLIC-INTEREST DEMAND: Given the potentially significant implications of digital marketing, customer consent, KYC/data collection and credit-bureau enquiries, the Reserve Bank of India, TRAI and the relevant Credit Information Companies should conduct a prompt, independent and technically forensic investigation wherever credible complaints and documentary evidence warrant it. Relevant logs, communications, consent records, application records, bureau-enquiry records and partner/LSP records should be preserved immediately. Where an investigation establishes statutory or criminal violations, prosecution should follow without avoidable delay and trials should be conducted on a time-bound basis in accordance with law, while fully protecting the due-process and defence rights of every person concerned.

The public does not need a predetermined guilty verdict.

It needs the truth.

SOURCES AND DOCUMENTARY RECORD

  1. FlexiLoans, About Us / Company Information — legal identity, RBI-registered NBFC status, stated disbursals, customers, product range and business model.
  2. FlexiLoans, Fair Practices Code — digital-lending sourcing, sanction/KFS, disclosure and oversight requirements published by the company.
  3. FlexiLoans, Grievance Redressal Mechanism — complaint escalation structure and RBI Ombudsman route.
  4. RBI, Guidelines on Digital Lending, September 2, 2022 — regulated-entity responsibility, LSP/DLA oversight and digital-lending requirements.
  5. RBI, Digital Lending requirements on KFS, APR, disclosures and grievance redressal.
  6. TRAI, Telecom Commercial Communications framework — customer preferences, consent acquisition, DLT, templates and commercial communications.
  7. TransUnion CIBIL, CIBIL Score and Credit Enquiries — treatment of multiple enquiries and their potential effect on credit evaluation.
  8. CRISIL Ratings, Epimoney Private Limited rating rationale, February 2026 — AUM, income, profitability and company profile.
  9. CRISIL Ratings, Epimoney Private Limited rating rationale, October 2025 — FY2025 financial and asset-quality indicators.
  10. Inventiva, “Deliberate Digital Harassment? How FlexiLoans Repeatedly Uses Fake Approval Language…” — published account of the ₹22,90,737 WhatsApp communication and alleged contradiction between “pre-approved/ready for disbursal” and “being reviewed.”
  11. Inventiva, “Loan Nahi, Samjho ‘Vipatti’ Hai…” — published customer account concerning the approximately ₹27-lakh approval message, KYC request, rejection and reported credit-enquiry concerns.
  12. Inventiva, “FlexiLoans’ Google Reviews Expose…” — compilation of public complaints and reviews, treated in this article as allegations rather than adjudicated evidence.
  13. Epimoney FY2025 annual-report material — company statement that no RBI penalty was imposed during FY2025 and disclosure of eight financial-covenant breaches across five lenders, primarily concerning asset quality.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button