Try the OS

Product scope · Capabilities and limits side by side

Covenant Desk Lending product map

Covenant Desk Lending is made of named modules. Each one is listed here with what it does, its implementation status, who uses it and — just as importantly — what it does not do. A capability list without limits is how “AI-assisted review” gets heard as “the machine decides”, so both columns are shown together.

Modules

22 named modules

Each module has a stable @id in structured data, so the same module is the same entity on every page and in both languages.

Management Portal

The permission-scoped workspace lending staff work in: one shared portal, one borrower database and one audit trail across every connected lending company.

What it does
  • Global borrower and loan search
  • Consolidated work queues
  • Inquiries inbox
  • Company-scoped dashboards
What it does not do
  • Does not make credit or approval decisions
  • Shows only data the lender has supplied or connected

Customer 360

One borrower record that joins applications, approved terms, documents, repayments, communications and related-company exposure in a single view.

What it does
  • Single borrower identity across companies
  • Duplicate borrower detection
  • Document and communication history
What it does not do
  • Does not import consumer credit reports from a CRA
  • Cross-company visibility is governed by the lender's own permissions

Loan Intake

Web, email, WhatsApp and staff-entered applications land in one assignable queue with channel, timestamp and required-document status preserved.

What it does
  • Multi-channel application capture
  • Assignable queues
  • Missing-document tracking
What it does not do
  • Captures and queues applications; it does not itself screen or approve them
  • Consent capture wording remains the lender's responsibility
Coming soon — not available today

Identity Verification (eKYC)

The live product records identity details and accepts supporting documents for staff review. Automated HKID extraction, liveness checks and iAM Smart confirmation are roadmap capabilities and are not available today.

What it does
  • Identity fields recorded during intake
  • Supporting-document upload and staff review
  • HKID format and check-digit validation where applicable
What it does not do
  • Automated document extraction, liveness and iAM Smart are not implemented
  • Document collection and format validation do not verify that a person is who they claim to be
  • The lender remains responsible for identity verification and customer due diligence
Live — UN sanctions screening only

UN Sanctions Screening

Applicants and existing borrowers can be screened against the UN Security Council Consolidated List, with possible matches held for a named staff member to clear or confirm.

What it does
  • UN sanctions-list screening at intake and approval
  • Book rescreening when the UN list changes
  • Possible-match review with clear or confirm decisions recorded against a named user
  • List version and screening history retained
What it does not do
  • Does not provide PEP, adverse-media, general watchlist or transaction monitoring
  • Returns possible matches for human adjudication; it does not clear or reject anyone automatically
  • It is one screening control, not a complete AML/CFT programme, and does not file suspicious transaction reports
Live — built-in policy, not a no-code rule builder

Decision Rules Engine

Built-in individual and SME scorecards apply documented affordability, evidence, delinquency and exposure rules consistently, then present the result to an authorised human reviewer.

What it does
  • Rules-based individual and SME scorecards
  • DSR, affordability, evidence-gap and cross-company exposure checks
  • Hard stops, manual-review triggers, reason codes and grade caps
  • Human approval and escalation records
What it does not do
  • Produces decision support, never a final approval or rejection
  • The current policy constants and scorecard weights are implemented in code rather than editable in a no-code rule builder
  • PD bands and pricing assumptions are policy templates, not calibrated predictions for a lender's portfolio

Human Review Workflow

Approval authority, exception reasons, escalation levels and the final human decision are recorded against every application.

What it does
  • Configurable approval authority
  • Mandatory exception reasons
  • Decision history per application
What it does not do
  • The lender makes the final credit decision
  • Covenant Desk does not automate approval

Repayment Operations

Schedules, instalments, consolidated repayment notices, arrears queues, reconciliation and settlement handled in one place after disbursement.

What it does
  • Repayment schedules and instalments
  • Consolidated repayment notices
  • Arrears and delinquency queues
  • FPS repayment reconciliation
What it does not do
  • Does not move money or hold client funds
  • Collection conduct rules remain the lender's responsibility
Live — channel-specific workflows

Outbound Communications

Borrowers and staff can exchange secure in-portal messages. Repayment reminders can be sent by SMS through the lender's configured provider; WhatsApp and email are separate intake channels rather than a unified outbound composer.

What it does
  • Secure borrower-to-staff messages inside the portal
  • Consented SMS repayment reminders through a configured provider
  • WhatsApp intake through a fixed application questionnaire
  • Inbound email intake with message and attachment capture
What it does not do
  • There is no single outbound composer for SMS, WhatsApp, email and push
  • WhatsApp is an intake workflow, not an AI assistant or general messaging channel
  • Message wording, consent, opt-out handling and contact frequency remain the lender's responsibility

Borrower App

A borrower-facing web app for loan details, repayment schedules, statements, FPS payment instructions and claims, secure messages, document requests and application status.

What it does
  • Loan details, balances, schedules and statements
  • FPS QR or payment instructions with borrower-submitted repayment claims
  • Secure messages, document requests and application status
What it does not do
  • eDDA autopay is marked coming soon and is not available today
  • Does not move money, hold client funds, show credit reports, or offer and price loans

AI Review Layer

Optional staff-facing AI adds portfolio Copilot answers, underwriting hints, risk commentary and collections drafts alongside the product's rules-based scorecards and human approval workflow.

What it does
  • Company-scoped Copilot questions against authorised records
  • Optional underwriting hints and AI risk commentary
  • Collections message drafts for staff review
What it does not do
  • AI output is optional decision-support only; no automated approval, rejection or pricing
  • Document-to-field extraction and a borrower-facing AI assistant are not available today
  • Staff must verify outputs before acting on them
Coming soon — not available today

Document Extraction

Document-to-field extraction is planned but not live. Today the product supports document upload, review and applicant upload requests; Excel and CSV intake have a separate mapped import flow.

What it does
  • Borrower document folder and staff uploads
  • Applicant upload links with requested document categories
  • Excel and CSV preview, mapping and confirmation
What it does not do
  • PDF, image and text documents are not currently extracted into borrower fields
  • Document storage does not verify a document's authenticity
Coming soon — not available today

Document Templates & e-Signature

The live product generates printable loan agreements and statements from recorded loan data. Editable document templates and online signature capture are roadmap capabilities and are not available today.

What it does
  • Printable loan agreement generated from the loan record
  • Statement-of-account and receipt generation
  • Download events recorded in the audit trail
What it does not do
  • There is no editable lender template library or online signing flow today
  • Covenant Desk does not authenticate an online signer or store a signed electronic copy
  • The lender and its legal advisers remain responsible for document wording and execution

Management Copilot

Answers operating questions about the lender's own portfolio in plain language, with links back to the underlying records.

What it does
  • Plain-language portfolio questions
  • Links back to source records
  • Company-scoped answers
What it does not do
  • Answers cover the lender's own connected data only
  • Not a credit-decision or regulatory-advice tool

Multi-company Federation

Several lending companies operate from one login with separate books, separate permissions and a group-level view for owners.

What it does
  • Company-scoped books and permissions
  • Group-level oversight
  • Cross-company exposure checks where permitted
What it does not do
  • Cross-company visibility must be enabled and justified by the lender
  • Does not merge separate legal entities' obligations

Portfolio Oversight

Balances, arrears, ageing, exception volumes and operating throughput reported across one company or the whole group.

What it does
  • Arrears and ageing views
  • Exception and throughput reporting
  • Exportable operating reports
What it does not do
  • Reports describe the lender's own data, not market benchmarks
  • Not a statutory or regulatory return

Audit Trail

Who viewed, changed, approved or exported a borrower record, when, and under which company scope.

What it does
  • Access, change, approval and export events
  • Company scope on every event
  • Reviewable by compliance and audit roles
What it does not do
  • Retention periods are configured by the lender
  • An audit trail is evidence, not a compliance certification

Role-based Access Control

Roles decide who can see full identity data, who can approve, who can export and which companies each member of staff can reach.

What it does
  • Field-level identity data controls
  • Company scoping
  • Immediate revocation on role change
What it does not do
  • Role design and review remain the lender's responsibility
  • Access control does not by itself satisfy the PDPO

Source-system Sync

Mapped, agreed data flows between an existing loan ledger or spreadsheet set and the Covenant Desk borrower record.

What it does
  • Source field mapping before any sync
  • Spreadsheet and file import
  • Documented data flow per connection
What it does not do
  • Every connection starts with an agreed source mapping
  • Covenant Desk does not connect to a CRA or to Credit Data Smart

Phased Migration

Move a lender onto Covenant Desk in stages. Records held in an existing system such as Softmedia or TE Credit, or in spreadsheets, are imported into the Covenant Desk database, and the two can run side by side during rollout so nothing has to cut over in a single step.

What it does
  • Import borrower, loan and repayment records from an existing system or spreadsheets
  • Side-by-side running during rollout, at the lender's pace
  • Cut-over on the lender's own schedule, not ours
What it does not do
  • What can be imported depends on what the lender's existing system can export
  • Covenant Desk is not affiliated with Softmedia or TE Credit
  • Migration scope is agreed before any data moves

CDS Readiness Assessment

A free bilingual 15-point operating self-assessment that scores a lender's data, permission and workflow readiness and returns priority actions.

What it does
  • 15 scored questions in Traditional Chinese and English
  • Banded result with priority actions
  • Runs entirely in the browser with no data sent
What it does not do
  • An operating self-assessment, not a compliance assessment or certification
  • Does not determine whether a lender is in scope for CDS
Readiness preview — not the official CRP format

CDS Data-readiness Preview

Builds a human-readable XLSX preview of recent application, approved-term and repayment records, with warnings that help a lender assess data readiness. It is not an official submission file.

What it does
  • Human-readable XLSX preview covering recent application, approved-term and repayment data
  • Warnings for missing or inconsistent source data
  • Readiness review before an official submission workflow is designed
What it does not do
  • The official CRP wire format is not implemented and the preview must not be submitted
  • Covenant Desk does not submit credit data to Credit Data Smart
  • The lender must verify the official specification and remains responsible for submission, accuracy and timing

How modules are bought

How modules map to plans

Modules are not sold one by one; they are grouped into plans and add-ons. The product pages below set out the scope, users, inclusions and exclusions of each grouping.

See the product overview

Primary sources

Official sources and editorial note

Regulatory statements on this page link to the Hong Kong government or regulator material available on the review date. Requirements can change; each institution should check its own current licence conditions and take legal or compliance advice. This page is not legal advice. Read our editorial, sourcing and corrections policy.

Responsible publisher: Covenant Desk (the Covenant Desk product team) · 2026-08-26

Next step

Want to see a specific module running?

A demo can follow your own workflow: tell us which modules matter most and we will start there.

Try our lending OSSee the product overview
Covenant Desk is a software company. Covenant Desk Lending does not provide loans, issue credit reports or replace the lender’s final credit decision.