The workflow is ready. The certificates are not.
A complaint platform for a bank has to do three things: hold the 30-day clock, refuse to reject a complaint before the Internal Ombudsman has seen it, and produce reporting your board committee can table. WTN does all three today. Your security review will also ask what assurance certifications we hold — and this page answers that plainly rather than burying it.
What the product does
The complaint loop a bank is required to run
What a bank actually needs from a complaint platform is narrow and specific: a clock, a mandatory escalation before any rejection, categories that match its reporting, root-cause analysis, and a pack the board committee can read. WTN runs all five today.
The 30-day clock, per complaint.
Turnaround deadlines are set per category, overdue cases raise an alert, and escalation fires on its own rather than waiting for somebody to notice the date.
No rejection without the Internal Ombudsman step.
A complaint the bank intends to reject cannot be closed until it has passed the escalation step. It ships as a preset, so it is not a rule somebody has to remember to configure.
Categories that map to the taxonomy you already report in.
Complaint categories are configuration, not code, so they can be set to match the classification your complaint-management reporting already uses.
Root-cause analysis and reporting packs.
Repeat complaints grouped by category and department, monthly trend analysis, and a twelve-month register export your Customer Service Committee can table.
Data stays in India, and every sub-processor is on a register.
Hosting and the database are India-resident, personal data is encrypted by the application before it is stored, and every sub-processor is recorded on a register we maintain and supply on request.
What is not in place
The certifications your security review will ask for
The capability above is real. The assurance paperwork around it is a separate question, and a bank asks that question early — so here is the honest answer rather than a page that leaves you to discover it in the third meeting.
ISO 27001 and a CERT-In-empanelled penetration test are not yet held.
These two are the practical gate in bank procurement, and WTN holds neither today. They are obtained when a deal requires them: a penetration-test engagement runs roughly two to six weeks, and ISO 27001 certification roughly four to eight months end to end. Until a certificate is actually issued, this page will not imply one.
Outsourcing rules reach us as contract terms, not as a licence.
A complaint tool holding customer data is likely to be treated as material outsourcing. That flows down to us as audit rights for the bank and for the regulator, exit terms that return your data intact, business-continuity expectations, and India residency. We plan for the full clause set rather than negotiating it away.
Banks are not our current priority, and saying so is cheaper for you.
Hospitals, HR teams and research agencies come first. If a bank or an NBFC finds the fit compelling anyway, the conversation starts with the security review above and the sequencing it implies — not with a proposal.
Kept current regardless, because they cost little and matter more than a badge: the data-processing agreement template, the 72-hour breach-notification runbook, the security whitepaper, and access reviews on a calendar.
Who is regulated
The regulator supervises you, not your software
There is no licence, registration or certificate a complaint platform can hold that makes a bank compliant. The obligations are yours; what a vendor can do is make them provable — a numbered complaint, an acknowledgment that went out on time, an escalation that fired, a resolution communicated, and a record of all four that survives an inspection.
Supports your RB-IOS and Internal Ombudsman obligations and produces the records your Customer Service Committee reports from. Complaint workflows aligned with ISO 10002. DPDP-aligned: consent receipts, erasure, and storage in India. WTN is not a regulated entity and claims no regulatory approval of any kind.
This is a conversation about fit and sequencing. Nothing is offered here ahead of the security work described above.