The problem: useful evidence is difficult to reuse
A small business may have a record of repaying a lender, receiving customer payments or maintaining trading relationships. When its owner applies to another bank, that history may arrive as screenshots, statements or documents that require follow-up checks. Useful evidence exists, but the bank cannot readily establish who produced it, which period it covers or whether it remains current.
This can increase the work required from the applicant and the bank. For businesses with limited formal credit history, it may also make relevant evidence harder to consider.
OJK's explanation of POJK 29/2024 on Pemeringkat Kredit Alternatif (PKA) identifies alternative credit assessment as a way to address limited or absent credit history, including among UMKM.1 The proposed use case explores how verifiable credentials could improve the portability and checking of evidence used in that assessment.
The proposed approach
An accepted issuer provides a digitally signed statement about a business or its owner. The owner presents that statement to a bank through a supported wallet or assisted channel. The bank checks the credential and determines whether the evidence is suitable for its assessment.
The W3C credential model distinguishes issuers, holders and verifiers.2 In this example, a previous lender issues evidence, the applicant holds and presents it, and the receiving bank verifies it.
A credential is an evidence container. The bank still evaluates affordability, outstanding obligations and other relevant risks. A valid signature establishes a connection to the signing issuer and protects integrity; it does not establish that every claim is factually correct or guarantee future repayment.2
An illustrative business-owner journey
Maya runs a small tailoring business in Indonesia. She wants working capital to purchase materials for additional orders. She has repaid an earlier loan and has records of customer payments, but another bank has not previously served her business.
In the proposed arrangement:
- The bank explains its evidence requirements. Maya can see which credentials it accepts, what information it needs and the available assisted route.
- An accepted previous lender issues a repayment-history credential. The statement identifies the borrower, observation period and repayment performance recorded in that lender's own systems. It also states when the information was checked.
- Maya reviews and presents the requested evidence. The receiving bank identifies itself and explains the purpose. Maya selects the information to share through the supported channel.
- The bank checks the credential. Its verification service checks the issuer, integrity, validity and status, and confirms that the evidence concerns the applicant or relevant business.
- The bank assesses the application. Verified evidence joins the bank's other information. Where useful and permitted, a PKA provider can supply an assessment. The bank evaluates repayment capacity and makes its lending decision.
- Maya receives an outcome and a support route. If evidence is incorrect, she can seek correction from the responsible issuer. If the application is declined, the bank provides the applicable explanation and review channel.
The intended improvement is easier reuse of trustworthy evidence and fewer avoidable checking steps. Access to funding remains conditional on the bank's assessment and lending criteria.
Illustrative process map

What the credentials could contain
Each institution should issue only claims it is authorised and able to substantiate. Credentials about a company and those about its owner require an explicit link and authority to act for the business.
| Proposed credential | Possible issuer | Useful evidence | Important limitation |
|---|---|---|---|
| Repayment history | A participating previous lender | Performance for a defined loan and period, with the date checked. | A good past record does not establish current affordability. Active liabilities need separate, fresh checks. |
| Payment activity | A participating payment or account provider | A defined summary of recorded business receipts, with period and coverage. | Receipts are not necessarily profit; cash sales and other providers may be absent. |
| Business registration | An authorised source or issuer with a documented verification arrangement | Registration details and their verification date. | Registration does not prove revenue, ownership authority in every context or creditworthiness. |
These are proposed credential types. The page does not claim that Indonesian registration systems or payment providers currently issue them as verifiable credentials.
A bank should know the evidence's scope. For example, “no late payments recorded for this loan between these dates” conveys more than an undefined “good borrower” label. Where figures are summarised into ranges, the issuer and bank must agree on their meaning and suitability.
Keep verification separate from scoring
The receiving bank needs to answer different questions:
| Stage | Question |
|---|---|
| Credential verification | Is this credential intact, current and attributable to an accepted issuer? |
| Evidence validation | Does it concern this applicant, cover the relevant period and satisfy our evidence requirements? |
| Credit assessment | What does this and other information tell us about repayment capacity and risk? |
| Lending decision | Should the bank offer finance, on which terms, and with which obligations? |
If an external PKA provider participates, its regulatory position and responsibilities must be established. Issuing or verifying a credential does not by itself authorise an institution to operate an alternative credit-rating service.1
Trust, privacy and security
The pilot needs an agreement covering accepted issuers, claim definitions, signing keys, freshness, correction and liability. Acceptance should be specific to the type of evidence; an issuer trusted for repayment records is not automatically trusted for all business claims.
The proposed safeguards are:
- Limit disclosure. Request the information needed for the application. Selective disclosure depends on the chosen credential format and implementation; it is not automatic in every wallet.2
- Protect the presentation. Authenticate the verifier and bind evidence to the application session. OpenID for Verifiable Presentations describes mechanisms including a fresh transaction challenge to reduce replay risk.3
- Handle changing information. Define validity periods, status checks and reissue arrangements. A failed status service should trigger an exception process rather than an assumed pass.
- Support the correct applicant. Establish holder and subject binding and, where relevant, the person's authority to represent a business.
- Provide alternatives. Offer staff-assisted presentation and alternative evidence for people without a suitable device or digital history. Avoid treating missing digital data as evidence of poor repayment behaviour.
- Record responsibility. Retain the verification result and decision trail under defined access and retention rules. Make correction and complaint routes visible.
Indonesia's Personal Data Protection Law is relevant to the handling of personal and financial information.4 A sharing action in a wallet does not settle every legal obligation associated with subsequent processing.
A focused pilot and measures of success
Start with one previous lender, one receiving bank and one clearly defined credential type. Use synthetic data to test interoperability and failure handling before a limited, appropriately authorised pilot with real applicants.
Compare the proposed process with the bank's existing evidence-checking process. Suggested measures are:
| Measure | What it reveals |
|---|---|
| Verification time and staff effort | Whether credential checking reduces avoidable work. |
| Application-to-decision time | Whether the overall financing journey improves. |
| Follow-up document requests | Whether the applicant repeats fewer steps. |
| Completion across digital and assisted channels | Whether the approach remains accessible. |
| Incorrect evidence, disputed checks and correction time | Whether faster processing preserves reliability. |
| Approval patterns and later repayment performance | Whether accepted evidence is useful without introducing unfair exclusion or unsuitable lending. |
Measure security incidents and cost per completed application as well. Establish targets from the baseline; this concept makes no quantified time-saving or approval-rate claim.
Sources and further reading
This is an original MOSAIC proposal informed by the following sources. They establish the technical and policy context, not a confirmed Indonesian deployment. Sources were reviewed on 2 October 2026.
- OJK — Regulation on alternative credit assessment Explains the purpose and scope of POJK 29/2024, including its relevance to UMKM with limited credit history.
- W3C — Verifiable Credentials Data Model v2.0 Defines the credential ecosystem and distinguishes verification from evaluating the truth and suitability of claims.
- OpenID Foundation — OpenID for Verifiable Presentations 1.0 Describes presentation exchange and security mechanisms. A pilot must select a compatible format and protocol profile.
- JDIH Komdigi — Law 27/2022 on Personal Data Protection Provides the legal context for limited, purpose-specific and accountable personal-data processing.
