HBL Microfinance Bank · Program Office

Root & Rise

A loyalty program run as a financial instrument — six layers, one wallet, and a governed control room.

PurposeBoard briefing · note & approve
BasisProgram Console v1.0 · on-premise
DateAugust 2026
What the board is asked to do

Three decisions, nothing else

Note

Points are a recognised liability

Every reward value is an IFRS 15 contract liability, revalued nightly and tied to the general ledger daily.

Approve

The dual-control regime

No reward change is self-service. Draft, submit, second signature, applied on the next nightly run.

Hold the line

Trust Score stays gated

No preferential credit pricing off the score until risk-model cohort validation clears. A launch gate, not a formality.

The program in one slide

Six layers on one wallet

Layer What it is Funded by Fails when
OnrampOne-time bonus for clearing Level 0 to Level 1Growth budgetBonus paid, customer never returns
FoundationInstant cashback — cash, not pointsBank's own marginRate creeps above the point value
Daily HabitsCheck-ins, streaks, fraud quizzesMarketplace partnersEngagement rises, Trust Score does not
MomentsCapped chance reward on a qualifying transactionMarketing budgetVelocity farming on small tickets
Trust ScoreBehavioural score that unlocks credit termsReduced cost of riskUsed for pricing before validation
MarketplaceWhere points are spent; literacy and grantsPartners, bank, donorsA redemption fails and nobody notices
The rule that governs all six layers

Points are earned by doing. The Trust Score is earned by banking well.

Habits, quizzes and campaign awards never touch the score. That separation is what makes the score usable for credit — and why the console refuses to add a points input to it, for anyone, at any level.

Financial treatment

Three numbers, three owners

liability = outstanding points × point value × (1 − breakage)

Outstanding points

Ledger · not an opinion

Produced by the earn engine and tied to the GL account by account, every day.

Point value

Finance + Internal Audit

The highest-impact number in the console — it reprices the entire liability at once.

Breakage

Finance signs · Audit traces

Re-signed quarterly. A change appears in the audit log as a re-signature, never a silent edit.

The counter-intuitive part

Lower breakage means a larger liability — and a better program. A program with 40% breakage is cheap because it is not working. Read the liability with redemption rate beside it.

Governance

Nothing is live when you save it

01

Draft

Edited values highlight; the banner counts unpublished changes.

02

Price it

Backtest against real history; simulate the forward liability curve.

03

Submit

A line-by-line diff enters Approvals and the audit log, under a name.

04

Second signature

A different person, with the right role. Rejection carries a reason.

05

Nightly run

It applies tomorrow, not now. The batch is the bank's own batch.

Point value / rupees per pointFinance + Internal Audit
Campaign launchFinance + Compliance
Earn rule or habit valueFinance + Program admin
Customer-facing copy or quizCompliance
Tier threshold or score weightCredit Risk
Partner settlement runFinance + Procurement
The credit asset

Trust Score — and its guardrail

Why it is worth building

A customer with two years of punctual bill payments through the wallet and no bureau history is invisible to a traditional score and legible to this one. The return is a lower cost of risk on customers the bank currently cannot price.

Five behavioural inputs — repayment punctuality, transaction regularity, savings behaviour, tenure, dispute history — each with a weight and a lookback. Weights must total 100%. Recalculated weekly.

Explicitly excluded from the score
Campaign awards Habit activity Quiz results Redemptions Manual adjustments App opens

Preferential pricing off the score stays gated on risk-model cohort validation. Pressure to move early is refused and routed to Credit Risk — the console will not carry the decision.

Spend discipline

We only claim what a holdout can prove

Minimum 10% holdout, every campaign

Eligible customers deliberately not given the bonus. The gap between them and the treated group is the effect.

Cost per incremental active

Divided by the customers the campaign caused — never by everyone it reached.

Persistence, not the spike

Habit retained after the campaign ended. A spike that vanishes bought transactions, not customers.

Reported as prominently as the wins

Spend that cannot be read — campaigns with no adequate control — is excluded from the blended cost figure rather than assumed to work.

Two tools, one honest sequence

Backtest prices a change on activity that really happened. It answers cost, never behaviour.

Simulation projects the liability curve 6–24 months. Quote the peak and the band, never the closing figure alone.

Only a holdout can tell you whether behaviour moved.

Integrity of the ledger

Abuse detection and reconciliation, nightly

Six detection patterns

Circular P2P2 round trips in 24h
Agent collusion4 customers, one agent, 30 min
QR velocity farming12 payments just over the floor
Self-referral ring3 bonuses per device
Quiz automationUnder 4s, 5 days running
Dormant spike30 transactions in 48h

Nothing reverses points on its own. A claw-back is the mirror of a goodwill credit and carries the same dual authorisation; agent and ring cases are referred to the Financial Crime Unit in parallel.

The ledger ties to the GL daily

Opening, issued, redeemed, expired, closing, GL, variance — account by account. A variance becomes a break with an owner and a target date. The ledger is never adjusted to force a tie.

Why batch reliability is on this slide

A streak payout job once timed out with no retry. Three days later it was a customer complaint; three days after that, a goodwill adjustment with two signatures. Batch reliability is a customer-trust metric, not an IT metric.

Assurance

What the console will not let anyone do

Approve their own submission — raiser and approver are always different accounts
Apply an engine change immediately — everything waits for the nightly run
Unmask a book of customer names — one at a time, each reveal logged
Delete or edit an audit entry — append-only, including for administrators
Re-run a closed settlement period — corrections go to the next run
Adjust the ledger to make the GL tie — a break stays a break until explained
Price credit off the Trust Score before cohort validation
Add a points or habit input to the Trust Score — ever

The console runs on the bank's own infrastructure. Points, scores, traces and audit entries are computed and stored in-house — there is no external analytics dependency to explain to Compliance.

What the board receives monthly

Assembled from live figures. Closing with what did not work.

Leads with DAU/MAU

The north star: it moves two to three months before churn shows up in revenue.

The mercenary test

Engagement and Trust Score read on the same cohort. Engagement rising with the score flat means we are buying attention, not habit.

Then the bad news

Spend with no detectable lift, spend that cannot be judged, SLA breaches, open reconciliation breaks.

A board pack containing only good news is a pack nobody can act on — and the first time bad news arrives from outside the program office, the argument for the program is already lost.