Case study
One platform for every microfinance institution in the country
The Microcredit Regulatory Authority wanted a single multi-tenant system for the 731 institutions it licenses, with real-time oversight, on a fixed go-live date.
Context
The regulator oversees all 731 microfinance institutions in Bangladesh. It wanted one centrally managed platform that digitises loans, savings, accounting and field operations for every MFI, and gives the regulator real-time visibility. The initial rollout targeted 20 MFIs, 500 branches, 15,000 field officers, 600,000 borrowers and 1.2 million accounts.
Constraint
Every MFI had its own product structures and interest calculation methods, partly because the regulations were ambiguous. Years of handwritten records had to be migrated. Field officers had low digital literacy and thin rural connectivity. Load peaked hard at end of day and month end, then dropped, so the system had to be fast at peak and cheap in between.
What I owned
I led the team: architecture, sprint delivery, the two-MFI proof of concept, staff training and the field rollout. I travelled to Tangail repeatedly to watch paper-to-digital migration happen in real branches. The ledgers did not match the book, and the system had to accommodate that reality without weakening the audit trail.
Architecture
Decisions and trade-offs
- Configuration, not code, for product rules. Product types, repayment schedules and interest methods live in per-tenant configuration, so onboarding an MFI never meant a release.
- Reactive services and reactive batch. High throughput on ordinary hardware, with end-of-day and month-end routines running as parallel pipelines instead of overnight jobs.
- Two MFIs first. A proof of concept with hands-on training exposed the paper-world exceptions before scaling. Expansion waited until core processes were stable.
- Validate before migrating. Standardised collection and validation workflows turned handwritten ledgers into clean data, and every migrated record kept a full audit trail.
- Regulator-grade security. OAuth2 PKCE, MFA, VPN-only access, strict role permissions, and an audit entry on every transaction.
Outcome
- 600K+transactions per week at peak, no degradation
- 99.99%uptime
- 1.2Maccounts across 500 branches in the initial scope
- 731MFIs the platform is designed to scale to
Stack
Java, Spring Boot, Reactive Java, PostgreSQL, Redis, load balancing, Angular, Docker, GitLab CI/CD, OAuth2, Jira.