Home/Products/Loan Origination System
Loan origination system · Kenya & East Africa

Loan origination software for Kenya's banks, SACCOs and MFIs.

Every loan on one accountable path.

Originate, underwrite and disburse loans in one role-gated pipeline — thirteen stages from application intake to final disbursement, with credit committee approvals routed by loan amount, SLA tracking and a full audit trail. Deployed in the cloud or on-premise.

Cloud or on-premiseAzure AD + LDAPAudit trail on every actionKenya & East Africa
los.creodata · Pending decisionsWestlands · BCC
Pipeline today
Applications awaiting a credit decision
Office 04
In pipeline
142
across 6 offices
Avg turnaround
11d
−1.4d MoM
SLA breaches
3
escalated
Pending BCC decisionsOpen queue →
JS
João da Silva
Equipment finance · 6d at stage
KES 65.0MCRITICAL
FA
Fatima Al-Mansouri
Working capital · 4d at stage
KES 48.0MURGENT
ML
Mara Logistics Ltd
Trade finance · 2d at stage
KES 12.0MHIGH
AN
Amani Njoroge
Asset finance · 1d at stage
KES 2.4MNORMAL
13
Workflow stages
From CSO intake to final disbursement — each role-gated and recorded
5
Approval tiers
BCC, Head, MCC, Committee and Risk, routed by loan amount
SLA
Timer on every stage
Overdue and breached applications surface with priority and escalation — nothing waits unnoticed
2
Deployment modes
Azure cloud or on-prem Kubernetes — Azure AD or Windows/LDAP
The problem

Everyone blames the credit committee. The data usually says otherwise.

When a loan takes weeks to decide, the delay is rarely in the decision. It is in the handoffs between the people who have to make it.

When the auditor later asks how a facility was approved, the answer is reconstructed from email — because nothing recorded it at the time.

  • Files wait in queues nobody owns

    An application sits between a relationship manager and credit admin, and the wait is invisible until the customer calls.

  • Approval authority is applied from memory

    Who may sign what is written in a policy document, not enforced at the point of decision — so limits are checked by habit.

  • Every branch runs its own version of the process

    Spreadsheets and email threads differ from office to office, and head office has no single view of the pipeline.

What changes

What changes on one accountable path.

See where every application is, and how long it has been there

Every stage is timed against a target; overdue and breached applications surface with priority and escalation.

Approvals sized to the loan

The amount routes the file through BCC, Head, MCC, Committee and Risk gates, re-checked server-side at every decision point.

Nothing moves without a recorded handoff

Every decision, assignment and document action is logged with actor, timestamp and a correlation ID.

Each branch works its own pipeline

Applications, queues and approval limits are scoped per office, with the same workflow everywhere.

Built for lending in Kenya

Built for lending in Kenya: IPRS, CRB, KRA, core banking and check-off.

Creodata's lending suite runs on one platform. The Loan Origination System carries the credit workflow for any loan product; the Workplace Banking Application adds check-off origination with the Kenyan identity, bureau, tax and core-banking checks built in.

Verify the borrower's national ID against IPRS

The Workplace Banking Application checks identity against IPRS and shows the result on a split screen beside the application. Results are cached for 24 hours, so later stages do not call again.

Workplace BankingCompliance checks

Check credit history with a credit reference bureau (CRB)

Workplace Banking runs the CRB check inside the workflow and applies your CRB rules in its business-rules engine. In the Loan Origination System, a bureau report can be made a required document for any product and is checked at document verification.

Workplace BankingProduct catalogDocument verification

Validate the KRA PIN and screen for sanctions and PEPs

Workplace Banking validates the KRA PIN and screens every applicant through Comply Advantage for AML, sanctions and PEP risk. Ongoing monitoring once the loan is live is the job of Creodata AML compliance software.

Workplace BankingAML software

Enforce the approval authority in your board-approved credit policy

The loan amount routes each application through BCC, Head, MCC, Committee and Risk gates, and every decision endpoint re-checks the amount server-side before it routes. Limits are set per office.

Workflow engineAuthorization

Book and disburse into core banking under dual control

The loan module hands approved facilities to your core banking system over a message bus. Workplace Banking books in Finacle (CIF, loan booking, limit marking and disbursement) under maker-checker, so the officer who books cannot also disburse.

DisbursementCore banking integrationMaker-checker

Run check-off lending against employer schemes

Workplace Banking manages approved employer schemes, runs payslip affordability and generates the deduction data delivered to IPPD for government payrolls.

Workplace BankingEmployer schemes

Protect borrower data under the Data Protection Act, 2019

Role-based access follows your directory with least privilege by default, service keys stay server-side, and every action on an application is logged. The on-premises edition keeps borrower data in your own data centre.

AuthorizationAudit loggingOn-premise

Show an auditor or examiner how each facility was approved

Every decision, assignment and document action is recorded with the actor, a timestamp and a correlation ID, so the approval trail is read from the log rather than rebuilt from email.

Audit loggingSLA monitoring

IPRS, CRB, KRA, Comply Advantage, Finacle and IPPD integrations ship in the Workplace Banking Application. Tell us which systems you run and we will confirm the integration path during scoping. This is a product description, not legal advice.

The journey, at a glance

Loan origination from application to disbursement, on one accountable path.

Behind the scenes there are thirteen role-gated stages. For everyone else, the loan moves through six clear phases — each with a named owner and a clock running against it.

Stage 1
Apply
CSO

Capture the borrower, accounts and loan request; attach the required documents.

Stage 2
Assign
Branch Manager

Route the application to a relationship manager within the office.

Stages 3–4
Assess
RM · Credit Admin

Prepare the credit proposal; verify documents for completeness.

Stages 5–9
Decide
Credit committees

BCC, Head, MCC or Committee decide — escalated by amount.

Stages 11–12·R
Clear
Legal · Finance · Risk

Legal clearance, finance approval and a risk gate on large facilities.

Stages 10·13
Disburse
Disbursement

Release funds against the approval trail and close the application.

The workspace

Every officer works the same queue-to-decision surface.

No swivel-chairing between systems. Officers pick up what's assigned to them, see the full application in one aggregate view, and act — while the SLA clock and audit log run underneath. Click through the surfaces.

los.creodata/stage5/pending
Workflow/Pending decisions
Westlands
Pending BCC decisions
24 applications awaiting a credit decision · sorted by priority then age
My officeOverdueAll
ApplicantProductAmountAt stageSLAPriorityAction
JS
João da Silva
Business · Mara Holdings
Equipment financeKES 65.0M6dBreachedCRITICALMake decision
FA
Fatima Al-Mansouri
Business · Al-Mansouri Co
Working capitalKES 48.0M4dOverdueURGENTMake decision
ML
Mara Logistics Ltd
Business
Trade financeKES 12.0M2d1d leftHIGHMake decision
CX
Chen Xiaoming
Individual
Term loanKES 9.5M1d2d leftNORMALMake decision
AN
Amani Njoroge
Individual
Asset financeKES 2.4M1d2d leftNORMALMake decision
ZT
Zawadi Traders
Business
OverdraftKES 6.0M0d3d leftNORMALMake decision
The full pipeline

A 13-stage loan origination workflow, each stage gated to a role.

The workflow engine enforces who can act at every step and where the application goes next. Higher-value loans pick up extra committee and risk gates; smaller ones take the short path. No stage can be skipped, and nothing moves without a recorded handoff.

Origination
Stages 1–4
1
Application intake
Customer Service Officer
2
Assignment
Branch Manager
3
Proposal preparation
Relationship Manager
4
Document verification
Branch Credit Admin
Credit decision
Stages 5–9
5
BCC decision≤ 50K
Business Credit Committee
6
Head approval≤ 100K
Head of Corporate / Retail
7
Credit analysis
Credit Analyst
8
MCC review≤ 500K
Management Credit Committee
9
Committee review
Committee Members
Fulfilment
Stages 10–13 · R
11
Legal processing
Legal Officer
12
Finance approval
Finance Officer
R
Risk approval
Risk Officer · high-value
10
Loan disbursement
Disbursement Officer
13
Final disbursement
Final Disbursement Officer
Amount-based routing

Credit committee approvals, routed by loan amount.

Approval authority is tiered. Each decision point checks the amount against the next limit and routes the application up or onward — so a small asset-finance deal clears in a few hands, while a multi-million facility gathers every committee and risk sign-off it needs.

Every decision endpoint re-checks the amount against the next limit before it routes — authority is enforced server-side, not just in the UI.
Smaller loans skip the higher committees entirely and move straight to legal and disbursement.
Facilities above the risk threshold pick up a dedicated risk-officer gate before any funds are released.
Tier 1
BCC decision
First credit decision at the branch
≤ 50K
Tier 2
Head of Corporate / Retail
High-value review above the BCC limit
> 10M
Tier 3
MCC review
Major credit decisions
≤ 500K
Tier 4
Board / Committee
Largest facilities
> 400M
Tier 5
Risk approval
Final risk gate before disbursement
> 100M
Capabilities

Loan origination software built for accountable, auditable lending.

13-stage role-based workflow

The workflow engine orchestrates intake to disbursement, gating each stage to a role with explicit, recorded handoffs — so no stage is skipped and no handoff is unowned.

Amount-based routing

Loan value automatically routes applications through BCC, Head, MCC, Committee and Risk gates, checked at every decision point — so small loans clear quickly and large ones gather every sign-off they need.

SLA & turnaround monitoring

Every stage is timed against a target; overdue and breached applications surface with priority and escalation.

Full audit trail

Every decision, assignment and document action is logged with actor, timestamp and a correlation ID for distributed tracing — so the auditor's question is answered from the log, not from inboxes.

Multi-office & branch

Applications, queues and approval limits are scoped per office, so each branch sees and acts on only its own pipeline.

Configurable product catalog

Products, categories, fees, collateral, requirements and routing rules are configured per market — no code changes.

Notifications at every handoff

Templated, message-queue-backed email keeps officers and committees moving the moment work lands in their queue.

Azure AD + on-prem LDAP

Role-based access integrates with Entra ID in the cloud or Windows / LDAP on-premise, least privilege by default — so staff sign in with the identity they already have, and access follows your directory.

Architecture

A portal over six services — your cloud or ours.

A Next.js portal fronts a backend-for-frontend proxy that injects credentials server-side, so the browser never sees a service key. Behind it, six independent .NET services each own one concern. The same build runs on Azure or on your own Kubernetes.

Backend services
Workflow engine
Drives the 13-stage application lifecycle, transitions and routing.
Product catalog
Loan products, categories, attributes, fees, collateral and rules.
Authorization
RBAC roles, permissions and per-office user-role assignment.
Audit logging
Immutable audit logs and decision records across every stage.
Email notifications
Templated, message-queue-backed notifications and an outbox.
SLA monitoring
SLA configuration and turnaround tracking per stage and office.
Cloud and on-premise, at parity

Identity, storage and messaging sit behind abstractions, so every feature works the same on Azure or in your data centre — and authentication follows your estate.

Azure cloud
Azure Functions (.NET 9)
PostgreSQL
Entra ID / Azure AD
Application Insights
On-prem Kubernetes
Kubernetes (containers)
PostgreSQL + RabbitMQ
Windows / LDAP
OpenTelemetry (OTLP)
Identity & access

Role-based access, scoped per office. Authentication adapts to where you run.

Cloud — Azure AD / Entra ID
MSAL single sign-on for staff identities managed in your tenant.
On-prem — Windows / LDAP
Directory-backed authentication for air-gapped deployments.
BFF proxy keeps keys server-side
Service credentials are injected by the proxy — never exposed to the browser.
Who it's for

Loan origination software for Kenya's regulated lenders.

Built for lenders whose credit decisions pass through more than one pair of hands, and who have to show afterwards who approved what.

Commercial banks and microfinance banks

Corporate, SME, asset-finance and retail lending under Central Bank of Kenya supervision, with BCC, MCC and Board approvals routed by amount.

SACCOs

Member loans with multi-level approval by credit committee and board, per-branch queues and an audit trail ready for the SASRA inspection of deposit-taking SACCOs.

Microfinance institutions and credit-only lenders

Configurable products, fees, collateral and document requirements, with SLA timers that show where turnaround is lost.

Payroll and check-off lenders

Employer schemes, payslip affordability and IPPD deduction data through the Workplace Banking Application, on the same platform.

Loan origination software across East Africa.

The same workflow serves lenders in Uganda and Tanzania. The regulator and the bureaus change; the approval trail does not.

FAQ

Loan origination software: frequently asked questions.

What is a loan origination system?

A loan origination system (LOS) manages a loan from application to disbursement: intake, document collection and verification, credit assessment, approval and handover for booking. It sits beside your core banking or SACCO system, which keeps the loan account and repayments after disbursement. Creodata's LOS runs that path as a 13-stage, role-gated workflow with approvals routed by loan amount.

Is this loan origination software built for Kenyan banks, SACCOs and MFIs?

Yes. Creodata is a Nairobi software company, and the system is configured for how Kenyan lenders approve credit: branch and management credit committees, board approval for the largest facilities, a risk gate before disbursement and per-branch queues. Products, fees, collateral, document requirements and approval limits are configured per institution without code changes.

Does it integrate with IPRS, CRB and KRA?

Those checks are built into the Creodata Workplace Banking Application, our check-off loan origination product: IPRS identity verification, CRB credit history, KRA PIN validation and Comply Advantage screening, shown beside the application and cached for 24 hours. In the Loan Origination System, bureau reports and other evidence can be made required documents per product and are checked at document verification. Tell us which checks you run today and we will confirm the integration path during scoping.

Which core banking systems does it connect to?

The loan module is designed to integrate with a core banking system over a message bus (Azure Service Bus in the cloud, RabbitMQ on-premises), so approved facilities pass to the core for booking and disbursement. The Workplace Banking Application books loans in Finacle, including CIF, limit marking and disbursement. For any other core, we confirm the interface during scoping.

What is the difference between a loan origination system, a loan management system and core banking?

The origination system decides whether and on what terms to lend, and records who approved it. A loan management system or the core banking system then services the loan: the schedule, repayments, arrears and collections. Core banking also holds the customer, accounts and general ledger. Banks and larger SACCOs usually keep their core and add an LOS in front of it for the approval workflow.

Can it run on-premise, and where is our data hosted?

Both. The same build runs on Microsoft Azure or on your own Kubernetes cluster with feature parity, using Entra ID in the cloud or Windows/LDAP on-premises. If borrower data must stay in Kenya, the on-premises edition keeps it in your own data centre.

How much does loan origination software cost in Kenya?

We quote per institution. The price depends on the modules you need, the number of offices and users, cloud or on-premises deployment, and the integrations involved. Ask every vendor for a three-year total cost on the same basis (licences, implementation, integrations, hosting and support) so the quotes can be compared.

How long does implementation take?

It depends on the number of loan products, the approval matrix and the integrations. We agree the timeline at scoping and follow a phased path: configure products, roles and approval limits; connect the core banking system and any checks; run in parallel on live applications; then go live office by office.

See a loan move from application to disbursement.

A live walkthrough on a realistic pipeline — your products, your offices, your approval limits.