Credit deviation matrix: designing approval authority that does not slow the file down
A credit deviation matrix is the table in a lender's credit policy that maps each type of policy breach - a FOIR above the norm, an LTV above cap, thinner income documentation, an age or vintage exception - to the authority level that may approve it and the compensating conditions required. It exists so that sensible exceptions get approved quickly by the right person, and every exception leaves an audit trail with a named approver and a reason code.
No credit policy survives contact with a real book. A self-employed borrower with excellent banking and a thin ITR, a strong salaried profile whose FOIR lands at 57% against a 50% norm, a used vehicle that appraises 8% over the LTV cap - these files are not frauds, they are the reason a deviation framework exists.
The problem is rarely the policy. It is that deviation handling is informal: a WhatsApp message to the regional credit head, an approval recorded in an email thread, and an auditor six months later asking who signed off and on what basis. This guide covers how to structure the matrix, how to keep it fast, and what to record.
What belongs in the matrix
A usable deviation matrix has four columns and nothing decorative. Anything longer than two pages stops being read and starts being guessed at.
- Deviation parameter - the specific policy line being breached, stated as a measurable band, not a category.
- Severity band - how far outside the norm, because a 2% FOIR breach and a 15% breach are different decisions.
- Approving authority - a named role, with a defined delegate for absence. Never a committee for routine bands.
- Compensating conditions - what must be true for the approval to hold: higher margin, co-applicant, additional security, shorter tenor, or a pricing loading.
A worked example
The bands below are illustrative of an unsecured and secured retail book at a mid-sized NBFC. Your own numbers come from your delinquency cuts, not from a template - but the shape, with three severity levels and a hard stop, is close to universal.
| Parameter | Level 1 - branch credit | Level 2 - regional credit head | Level 3 - national credit head | No deviation |
|---|---|---|---|---|
| FOIR above policy norm | Up to +5 pp | +5 to +10 pp | +10 to +15 pp | Above +15 pp |
| Bureau score below cut-off | Up to 20 points | 21-40 points | 41-60 points | Below 60 points or -1 with adverse history |
| LTV above cap | Up to +3 pp | +3 to +7 pp | +7 to +10 pp | Above +10 pp |
| Income document substitution | Banking in lieu of one payslip | Banking in lieu of ITR, GST corroborated | Assessed income method | No verifiable income trail |
| Applicant age at maturity | Up to +2 years | +2 to +4 years | Case by case with insurance | Beyond insurable age |
| Negative profile or area | Not permitted | Not permitted | Documented exception only | Blacklisted profile or fraud match |
Keep a genuine 'no deviation' column. A matrix where everything is approvable by someone senior enough is not a policy, it is a queue - and it is the single most common finding in an internal audit of a growing book.
Two deviations on one file are a different decision
Most matrices handle single breaches well and stacked breaches badly. A file with a FOIR at +4 pp and a bureau score 15 points below cut-off has two Level 1 deviations, and a branch credit manager will approve both without either crossing a threshold. The combined risk is not Level 1.
The simple fix that works: any file carrying two or more deviations automatically moves one authority level up, and any file carrying three moves to the highest level regardless of individual band. Encode this as a rule in the system rather than as a paragraph in the policy document, because paragraphs are not enforced at 7pm on the last day of the month.
Keeping deviations from eating your TAT
In most books, deviation files carry two to four days of extra turnaround, and almost all of it is discovery and chase rather than assessment. The file is logged, works its way to credit, and only then is anyone aware an exception is needed. Then it waits for an approver who has not been told it is waiting.
- Flag at sourcing. If FOIR, LTV and score are computed on the phone before login, the rep knows the file needs an exception before the customer stands up.
- Auto-route, do not escalate. The system should place the file in the correct authority's queue the moment the breach is detected, with the compensating conditions pre-filled.
- Time-bound the approval. A deviation request with no action in 24 hours escalates on its own; silence should never be the default outcome.
- Pre-approve common patterns. If 40% of your deviations are the same +5 pp FOIR on a specific salaried segment, that is not a deviation, that is a policy your book has already voted for. Recalibrate the norm.
Reviewing the matrix with portfolio data
A deviation matrix is a hypothesis about risk. Once you have twelve to eighteen months of seasoning, test it. Cut early delinquency by deviation type and by approving authority, and you learn two useful things: which exceptions are actually costing you, and whether any single approver is systematically generous.
- Deviation rate by product and by sourcing channel - a DSA running 40% deviation files is telling you something about their filtering.
- 30+ and 90+ delinquency of deviated files against clean files at the same vintage.
- Approval rate by authority level - a Level 3 approving 98% of what reaches it is a rubber stamp, not a control.
- Frequency by reason code, so the policy can be recalibrated rather than perpetually excepted.
Where Toolyt fits
Toolyt computes eligibility, obligations and policy breaches at the point of sourcing, flags the deviation before the file is logged, and routes it to the correct authority with compensating conditions attached. Every approval carries an approver, a timestamp and a reason code, so the audit trail is a report rather than an email search.
Frequently asked questions
- What is a credit deviation matrix?
- It is the section of a lender's credit policy that lists each permitted policy exception, the severity bands for that exception, the role authorised to approve each band, and the compensating conditions required. It converts informal exception handling into a delegated, auditable authority structure.
- What are common deviations in retail lending?
- The frequent ones are FOIR above the policy norm, bureau score below cut-off, LTV above cap, substituted or assessed income documentation, applicant age at loan maturity, property or vehicle age, and borrower vintage in business loans.
- Who approves a credit deviation?
- Approval authority is delegated by severity. Minor breaches sit with branch or hub credit, mid-range breaches with a regional credit head, and material breaches with the national credit head or a credit committee. Files with multiple simultaneous deviations should move up at least one level automatically.
- How many deviations are acceptable in a loan book?
- There is no universal figure, but most retail lenders get uncomfortable above 15-20% of sanctioned files carrying any deviation, and above 5% carrying a Level 2 or higher. Consistently high rates usually mean the policy norm is set away from the market you actually serve.
- Do deviations increase loan turnaround time?
- They do when the exception is discovered at the credit stage rather than at sourcing. Detecting the breach on the field app before login, routing it automatically to the right authority, and time-bounding the response typically removes most of the extra days.
Related to this
Want to see this running on your own data? Book the lending operations demo