Making Auto-debit simple for every borrower
Setu brought eNACH to its suite for NBFCs. I designed the flow borrowers use to set up auto-debit, built around the problems they actually face.
tl;dr
- What
- Setu's white-label eNACH flow. Borrowers of lenders like Ujjivan, IIFL and DMI Finance use it to set up auto-debit for EMIs, SIPs and insurance premiums.
- Why
- Existing eNACH flows were hard to use: bank jargon like “mandate”, unbranded pages, confusing account verification, and redirects with no warning.
- My role
- Designer on the project, end to end. Research, flows, UI, reviews and the developer handoff.
- Result
- A mobile and desktop flow that speaks plainly, shows the money first, and works for any lender without a redesign.
before we start, a quick question
Do you know what eNACH is?
Context
Setu, part of Pine Labs, wanted to bring eNACH into its suite for NBFCs, so lenders could collect repayments through auto-debit. My brief was to design the most efficient, scalable, and easy experience for the person at the other end: the borrower.
It's one of the most used flows in Indian finance. NACH, the system underneath eNACH, processed about 190 crore debits in a single year.
Set up auto-debit once, understand exactly what you agreed to, and never think about a payment date again. That's the convenience the flow exists for. Existing flows made it hard, so before designing anything, I looked at every problem people run into along the way.
Designing for Ramesh
I started with interviews, and wrote five personas from them: an EMI borrower, a first-time investor, an insurance buyer, a shop owner and a freelancer. One line from each set the tone for everything after.
Ramesh · EMI borrower
“Just show me clearly what I'm agreeing to, and make sure I can go back if anything goes wrong.”
Neha · first-time investor
“If I'm using a well-designed finance app, I expect this part to be just as good.”
Sundari · insurance buyer
“My son usually helps me. But if it's in Tamil and explains clearly, I can do it myself.”
Aman · shop owner
“Give me control. Let me verify my account, see the details clearly, and finish fast.”
Ritika · freelancer
“Don't make me read a wall of text. Just show me what I'm agreeing to in human language.”
I designed for Ramesh first. He's 34, a delivery partner in Nagpur, on a low-end Android phone. He pays with UPI and lives on WhatsApp, but he'd rather read Hindi, and bank words like “mandate” lose him. He worries about fraud, and about the wrong account getting debited.
He's also where lending is heading. Tier 3 cities already account for 40% of digital lending by value, the largest share of any tier.
If the flow works for Ramesh, it works for Neha in Mumbai too. It doesn't work the other way round.
The problems people run into
Then I walked Ramesh through the whole thing on a journey map, from the SMS to the final redirect: what he does, what he wants, and how he feels at every step. Alongside it, I went through the eNACH flows from Digio, Cashfree, BillDesk and NPCI.

Four problems kept coming up:
- 1
The link. A random SMS asking for bank access looks like fraud, even more so when the page doesn't look like his lender.
- 2
The words. eNACH, mandate, NACH registration. He's asked to agree to something nobody has explained.
- 3
Proving the account is his. He's told to verify, with no idea what that involves, or why ₹1 is about to leave his account.
- 4
The handover. Jumping to a UPI app or getting redirected to NPCI, with no warning that it's about to happen.
And getting it wrong costs the borrower. When an auto-debit bounces, the bank charges a fee (SBI's is ₹250 plus GST), and lenders report to credit bureaus every fortnight, so a missed EMI reaches a credit report within weeks.
The competitors didn't help much. Fixed layouts that barely showed the lender's brand, copy written for compliance, and browser redirects everywhere.
That gave me the problem statement: setting up auto-debit should be a quick, one-time task, but people are asked to give bank access through a link they don't trust, in words they don't understand.
Calling it what it does
The words came first, because every other screen leans on them.
We tested six names with a small sample group. Half of them had no idea what eNACH meant. That matches the wider picture: in a survey of 1,647 loan app users, only a third knew what a Key Fact Statement was. The friendlier options had problems of their own:
| Name | What people heard |
|---|---|
| eNACH | Nothing at all, for half the group. |
| Mandate | A legal notice. Formal and hard to follow. |
| Subscription | Netflix. It sounded like media. |
| Auto-pay | A credit card feature. |
| Recurring payment | The right idea, in too many words. |
| Auto-debit | Money leaving my account on its own. Exactly what happens. |
Auto-debit won because it describes what will actually happen to your money. It fits loans, SIPs and insurance alike, and it made sense to everyone we asked.
beforeRegister a NACH mandate for recurring debits.
afterSet up auto-debit to pay your monthly loan EMIs automatically.
So every screen, button and error message says auto-debit. The banking terms stay in the lender's integration docs, where the people reading them already know what they mean.
Money first
Before anyone verifies anything, they want three answers: how much, how often, and until when.
Early versions answered in the bank's order. A “mandate amount” label, then validity, purpose and frequency as separate rows to piece together. The final card says it the way a person would: ₹4,321 every month on 2nd, with the start and end dates right below.

Every schedule a lender can set gets its own sentence: every week, every 15 days, every month after the 5th. When the amount can change from month to month, the card leads with the maximum instead, so nobody is surprised by a bigger debit.
Asking for consent the slow way
To verify the account, we need the person's permission to use their bank details. There are four ways to ask for it:

| A | Unticked box, the person ticks it | Legal, and a real yes |
| B | Pre-ticked box | Legal, but assumes the yes |
| C | “By continuing, you agree…” | Legal, and easy to miss |
| D | No consent message | Not compliant |
B and C would have been faster, and both would pass. But both let someone agree without noticing. In a flow about their bank account, that's the worst moment to go quiet.
After talking it through with Akshay and the legal team, we chose A, the unticked box. It costs one extra tap. In exchange, every person who continues has actually said yes. The terms are a visible link, and the final step names the lender in plain words: “I authorise Ujjivan Small Finance Bank Ltd to debit my bank account.”
It's also the option closest to what RBI's digital lending guidelines ask of lenders: prior and explicit consent, with an audit trail.
Leaving the other door open
There are two ways to prove an account is yours. With UPI, you pay ₹1 from your UPI app and get it back. Or you type your account number and IFSC, and ₹1 lands in your account.
UPI takes a few seconds. The manual route means finding your IFSC, typing a long account number, and waiting for the ₹1 to arrive, which is exactly where people get stuck and give up. So one early idea was to show only UPI, with the manual route behind a small “Try another method” link.

Where I stand on this: I hate dark patterns. Tricking people into something for the company's benefit has no place in a flow about their money, and I'm on the user's side every time.
Guiding someone toward the easier path is a different thing, when the easier path is genuinely better for them. And UPI is. It already carries 83% of India's digital payments, so most borrowers know it by heart. When Kissht moved its borrowers to UPI verification on Setu, drop-offs at the bank account step fell from 18–20% to under 4%. At scale, that nudge means thousands of people finish in seconds, with less typing and far less panic about getting a digit wrong.
So the line I drew was simple. Recommend the easier path, and keep the other one in plain sight. Someone without UPI, or on a shared phone, should never have to hunt for their way through. India's own dark pattern guidelines have a name for hiding a relevant option like that: interface interference.
Both options sit side by side. UPI is marked Recommended and selected by default, because for most people it really is quicker and calmer. The manual route is one tap away.

Meeting people on the device in their hand
Paying ₹1 by UPI means leaving the page, which is exactly where people get lost. So this step changes with the device.
On a phone, you pick your UPI app from a row of familiar icons, and it opens straight to the payment. If no UPI app is found, the sheet says so and points to the manual route.

On a laptop, there's no app to open, so a QR code appears instead. Scan it with the phone already in your pocket, and the page picks up from there.

The whole flow, the way Ramesh walks it
Here's the prototype, start to finish.
And the screens behind it, step by step:
Open the link and enter the OTP. If it's wrong, the error says so plainly, and a new OTP is one tap away.

See the money first, then verify with UPI. The details collapse once you've read them, so the next step gets the screen.

Or verify by hand. Two fields, IFSC and account number, then a clear wait while the ₹1 lands.

Confirm the account, choose Aadhaar, debit card or net banking, and authorise. Success says what happens next. Registrations often fail for reasons the borrower can't see, like a debit card that isn't linked to the account, so failure offers a retry and a person to talk to.

One flow for every lender
Setu's clients don't all start in the same place. Studying them, I noticed every eNACH journey shares the same spine: review the details, verify the account, authenticate. What changes is how much the lender already knows about the borrower.
account unknown
The borrower verifies their account by UPI or by hand, and can change it after.
already verified
The lender has verified it already, say an investing app with KYC done. It shows read-only, and the borrower goes straight to authentication.
verified, changeable
The lender passes an account, but it may not be the one the borrower wants debited. They see it, and can switch.
One design covers all three with a few switches, so a new client never means a new flow.
On top of it goes the lender's brand: name, logo and three colours, set once. The borrower who got an SMS from Ujjivan lands on a page that looks like Ujjivan. That recognition is the first answer to “is this a scam?”



One flow, three lenders. Scroll sideways.
Built for real bank names
Before handoff, I ran an hour-long review with the whole design team, then separate sessions with Akshay and the developers. Everyone clicked through the prototype alone first, so the feedback was their own.
The PM review caught something the mockups hid: real data breaks layouts. Account numbers run long. Some bank names do too, like Baroda Rajasthan Kshetriya Grameen Bank. Someone banking with a regional rural bank should see its full name, same as anyone at ICICI.
So the handoff covers every case: long names wrapping cleanly, a fallback icon when a bank's logo won't load, savings and current accounts, and each debit schedule written out as its own sentence.


Two pages of the handoff: bank account edge cases, and every debit schedule.
How we'd know it works
My part ended at developer handoff, so there are no launch numbers in this story. Before handing over, we agreed on what should judge the design, and the bar for each:
| Measure | Why it matters | The bar |
|---|---|---|
| Link opened to auto-debit registered | Does the flow earn a yes? | 85%+ |
| Drop-off at OTP, verification, authentication | Where people lose confidence | <8%, <10%, <8% |
| Time from link to done | Is it quick on a small phone? | <3 min |
| Success after a failed attempt | Do retries and the manual route rescue people? | 50%+ |
What I learned
- 1
The biggest design decision was a word. I spent longer on “auto-debit” than on any single screen. Before someone can trust a flow, they have to understand what it's asking of them. Jargon quietly tells people the page wasn't made for them.
- 2
Name the cost of the honest choice, then take it. The unticked box costs a tap. The visible manual option costs some UPI conversions. Writing those costs down made the conversation with product and legal easy, because we were weighing real trade-offs instead of opinions.
- 3
Design for the edges first. The rural bank with the long name, the person without UPI, the borrower on a laptop. They're the most likely to give up, and designing for them made the flow calmer for everyone else.
Sources
- RBI, Payment Systems Report ↗
- FACE and Equifax, Digital Lending Report ↗
- FACE and MicroSave, Customer survey on digital lending apps ↗
- Setu, Reverse penny drop at Kissht ↗
- SBI, Schedule of service charges ↗
- RBI, via Business Standard, Fortnightly credit reporting ↗
- RBI, Guidelines on Digital Lending ↗
- CCPA, Guidelines on Dark Patterns ↗
Credits
Designed by me, and never a solo effort.
- AJ
Akshay Joshi
Product Owner
Owned the product and the PRD, and pressure-tested every flow in review.
- M
Madhuri
Senior Product Designer
Critique in the design review that sharpened the flow.
- KJ
Kavya Jha
Head of Design
Guidance throughout, from the first flows to the handoff.



