One Wallet, One Premium: Rebuilding Credit Around the Client Instead of the Product
Banks should stop underwriting individual products and start underwriting the person, because small, frequent, payroll repaid advances carry roughly 0.3% charge offs while large stale facilities drive mass default. Non exclusive contracts make stacking the predicted equilibrium, so the fix is one wallet with one premium: a behavioural fingerprint plus portfolio limits on the client's total exposure, refreshed on evidence rather than a schedule.
There is an asymmetry sitting in plain sight in every retail lending book, and once you notice it you cannot unsee it. Some of the smallest, shortest and most frequently repaid advances we write exhibit extraordinarily low losses, particularly where repayment is tied closely to the customer’s income stream, and yet almost the entire architecture of a bank is built around the opposite proposition: lend a lot of money, through a slow and expensive process, very rarely. That matters because it suggests that information freshness and repayment mechanics may be at least as important as underwriting depth, which is not a comfortable thought for an industry that has spent thirty years investing almost exclusively in the latter. What follows is an argument that the fix is not another product but a different unit of account. Stop underwriting products, start underwriting people, use a behavioural representation of the kind that Revolut’s PRAGMA work has just made credible at scale, and treat lending as an ongoing control problem rather than a one time prediction.
1. The evidence that started the argument
The Consumer Financial Protection Bureau’s work on the paycheck advance market found employer partnered advances charging off at roughly 0.3% in both 2021 and 2022, on an average advance of about $106 taken around 27 times a year, while the direct to consumer version of what is functionally the same product, repaid by debiting a bank account rather than by sitting close to the front of the payroll queue, lost between 6.3% and 6.5%. The CFPB itself attributes the difference largely to payroll integration and repayment mechanics rather than to any underwriting brilliance, and that is precisely why the comparison is interesting. It is not evidence that microloans are inherently safe. It is evidence that ticket size, information proximity and repayment priority are thoroughly entangled, and that the industry has been attributing to borrower quality something that belongs at least partly to architecture.
The second piece of evidence points the same way from a different angle. The CFPB’s Buy Now, Pay Later research found that borrowers defaulted on roughly 2% of their BNPL loans while defaulting on around 10% of their credit cards over the same period, and that those borrowers ran card utilisation of 60 to 66% against 34% for non users, with the CFPB again pointing to automatic repayment arrangements as a likely contributor to the BNPL figure. The temptation is to say that the person is not defaulting, only the product is, and the line is satisfying enough that I used it in an earlier draft, but it goes further than the data supports. The defensible version is more useful anyway: the same person can exhibit radically different default behaviour across products held at the same time, which tells us that observed default is not merely a characteristic of the borrower but also a characteristic of the information, priority and repayment architecture surrounding each obligation.
Locally the stakes are not academic. Eighty20’s Credit Stress Report for the first quarter of 2026 counts 56 million open loans and R2.7 trillion of balances in South Africa, with 41% of credit active consumers in default on at least one loan and R237 billion of overdue balances. When four in ten borrowers are in default somewhere while servicing something else faithfully, the interesting question is not who these people are, but why our architecture keeps producing that result.
2. Banks are optimised for low frequency, low fidelity lending
The reason banks lend the way they do is structural rather than stupid. If an origination costs several thousand rand in acquisition, verification, affordability assessment, legal drafting and disbursement, the only way to recover it is to write a large enough ticket over a long enough tenor, which forces the bank into the least informative corner of the space. Everything downstream follows. Bureau data refreshes monthly at best and describes a world several weeks in the past, scorecards are rebuilt annually or less often, limits are set once at origination and revisited on a schedule rather than on evidence, and each product carries its own profit and loss statement, its own risk appetite, its own collections queue and its own partial view of the customer. Total exposure to a household ends up as a reporting artefact rather than a decision variable.
The consequence is that the products fall over each other, exactly as you would expect from a set of independent optimisers competing for one constrained resource, which is the customer’s monthly cash flow. The store card was granted assuming the vehicle instalment was the senior claim, the personal loan was granted assuming the store card would be repaid at the contractual rate, the BNPL line was granted with no visibility of either, and the home loan, by far the best secured of the group, quietly absorbs the residual risk of every decision the other four lenders made afterwards.
3. Stacking is not an anomaly, it is the predicted equilibrium
This is one of the older results in the theory of lending and it deserves more attention than it gets in product design meetings. David Bizer and Peter DeMarzo, writing in the Journal of Political Economy in 1992, modelled what happens when an agent can borrow sequentially from more than one lender under contracts that nobody can make exclusive. Each new loan imposes an externality on the loans that came before it because it reduces the probability that any individual claim is repaid, and the resulting equilibrium carries both higher interest rates than a world with commitment and higher indebtedness, with the probability of default rising as additional credit is extended. The pattern of a customer stacking a BNPL line on a store card on a personal loan on a vehicle instalment, with everyone repricing upward in response, is not a market failure that better collections will cure. It is what non exclusive contracting produces.
The empirical counterpart is stark. The CFPB found that roughly 63% of BNPL borrowers held multiple simultaneous loans in 2022, a third of them across different providers, and noted plainly that even BNPL firms do not observe loans at other firms, so that stacking across firms is a structural blind spot.
Andrew Hertzberg, Jose Maria Liberti and Daniel Paravisini, in the Journal of Finance in 2011, show the other and more uncomfortable side of the problem. When a credit registry expansion made lenders’ negative private assessments visible to each other, the effect was not a tidy convergence on better decisions. Lenders anticipated how the others would react, coordination effects followed, lending fell and financial distress rose, particularly for borrowers exposed to several lenders at once. Fragmented lending therefore creates not only information asymmetry but coordination risk, and simply pouring more shared data into an architecture that still has five independent decision makers per household can make the run for the exit faster rather than slower. That is an argument for consolidating the decision, not merely for consolidating the data.
4. What PRAGMA actually changes
Which brings us to the piece that did not exist in usable form until recently. Revolut’s PRAGMA is a family of foundation models trained on banking event sequences, built on an encoder architecture with masked modelling in the manner of BERT rather than a generative decoder, and trained on roughly 26 million users and 24 billion events spanning transactions, application navigation and communications. The engineering choices matter for lending specifically. Amounts are encoded as percentile buckets rather than raw digits, and time is represented both as elapsed interval and as calendar cycle, so the model learns what is normal for this person at this point in their month rather than what is normal for the average person.
The reported gains are largest where they are hardest to get. Against models built for a single task, PRAGMA-L improves PR-AUC on credit scoring by 130.2% and recall on external fraud by 64.7%, which are relative improvements on particular metrics for rare events rather than a claim about overall accuracy. Perhaps more importantly for anyone deciding whether to invest in this approach, pretraining matters independently of architecture: on credit scoring, a pretrained PRAGMA-M subsequently adapted with LoRA achieved a 13.0% PR-AUC improvement over training the equivalent model from scratch. The value is in the shared representation, not in any one head bolted onto it.
The headline, though, is not the accuracy number. It is that one representation of a customer, learned from raw behaviour and refreshed continuously, transfers across credit, fraud and value prediction. That is a fingerprint in the useful sense: not a three digit score summarising the past, but a dense vector describing how this particular person’s money actually moves, against which any new obligation can be evaluated as a distance from their own established baseline. FinRegLab’s empirical work reached a compatible conclusion by a different route, finding that cash flow variables were generally at least as predictive as traditional bureau scores and, tellingly, added separation between borrowers whom the traditional systems had scored as identically risky.
5. What the fingerprint measures that a payslip cannot
I argued in the second part of this series that our assessment frameworks have quietly confused regularity with durability, because regularity is what a payslip happens to evidence and so it became the thing lending policy measures. A salaried employee receives twelve payments a year from exactly one payer, which is to say their income is perfectly concentrated in a single counterparty and their resilience has never been observed at all. A transactional timeline measures several things that bear directly on whether a household can carry an obligation: how concentrated their income is across payers, how their balance behaves in the days before a deposit lands and whether that margin is widening or narrowing, which obligations they protect and which they sacrifice when a month goes wrong, whether they can increase earning effort in response to a shortfall, and whether they are already leaning on expensive short term credit somewhere the bureau cannot yet see. A payslip measures precisely one of them.
That distinction is what turns a wallet from a packaging exercise into an underwriting one, because the affordability envelope stops being a fraction of a stated salary and becomes a function of an observed income distribution with its concentration, seasonality and demonstrated recovery speed attached. It is also where the honesty has to be applied. The PRAGMA results are impressive but they are not benchmarked against a bureau baseline, so the sensible working assumption is that behavioural signal stacks on top of bureau signal rather than replacing it. More importantly for this argument, a transactional view of one institution’s accounts cannot see what a household owes everywhere else, which is exactly the visibility that bureau and open banking data provide and exactly the gap that made stacking possible in the first place. The fingerprint tells you how this person handles money. It does not tell you how many other people are lending to them.
6. Lending as a control problem rather than an origination problem
Here is the idea that I think sits at the centre of all of this. A conventional loan estimates risk at the moment of origination and then flies on instruments that get progressively staler, discovering whether the estimate was right only when it is far too late to act on the answer. A relationship built out of small, short, frequently repeated advances does something structurally different, because every repayment, every cash flow movement and every short duration borrowing decision is a fresh probe that updates the estimated state of the system.
Frequency is fidelity. A lender who writes many small exposures to a client is buying information at a very low price, and that information is what makes it defensible to carry the large exposure. The objective changes accordingly. It is no longer to predict default accurately at origination and then hold on, but to keep total credit inside a safe operating envelope as the client’s circumstances move, in the way that any control system holds a process near its setpoint.
The control has to be asymmetric, though, and this is a design constraint rather than a nicety. When the signal improves, and the improvement is visible in more buffer days before payday, lower reliance on expensive short term credit and a widening rather than narrowing month end margin, the wallet can act on price and reprice the client downward within the term, which is something the current architecture essentially never does. When the signal deteriorates, repricing upward on an existing line is conduct risk under the National Credit Act and should be treated as off limits, so deterioration acts on the envelope instead, tightening the availability of new drawdowns and slowing limit growth while leaving agreed obligations exactly where the client agreed them. Prices ratchet one way, availability moves both ways, and the small advance stops being a marginal product with an awkward fee line and becomes the sensor array that keeps the whole relationship observable.
7. The portfolio principle
Harry Markowitz’s contribution in 1952 was not that risk and return trade off, which everyone knew, but that the risk of a holding is meaningless in isolation and only acquires meaning in the context of the portfolio around it. Banks eventually applied this to their own asset side, where modelling correlated default and diversification across a loan book is now standard practice. Nobody has seriously applied it to the other side of the same transaction, which is the portfolio of obligations that a single household carries.
The analogy is not mathematically exact, and it is worth saying so plainly rather than being caught claiming it. A household’s debts are not securities with stable return distributions and well behaved covariances, and nobody should be running literal mean variance optimisation over a client’s store card. The more honest object is a cash flow and liquidity portfolio under stress, with income modelled as a distribution rather than a number on a payslip, and with scheduled, contingent and revolving obligations arrayed against it. The principle survives the loss of the mathematics: no single obligation can be judged sensibly without understanding the portfolio around it, and most real households are sitting well inside any reasonable frontier, carrying a mix of expensive unsecured revolving credit and cheap secured term credit that no optimiser would have chosen, having assembled it one approval at a time from lenders who each saw a fragment.
8. One risk signal underneath, product economics on top
The pricing consequence follows directly. The starting risk premium should belong to the client rather than being independently rediscovered, from partial data, by every product the client touches. Product economics then adjust that common signal for the things that genuinely differ: tenor, collateral, utilisation, repayment priority, expected exposure at the point of default and expected recovery.
It would be overreaching to say that probability of default is purely a property of the person and everything else is loss given default. Observed default rates are shaped by facility structure, limits, utilisation and how the borrower behaves around that specific exposure, and the Basel framework reflects that nuance rather than contradicting it, with retail probability of default and loss given default estimated for identified pools of exposures and with exposure and recovery parameters explicitly tied to facility characteristics. The retail loss given default floors under the advanced approach make the collateral point cleanly enough on their own: 5% for residential mortgages irrespective of how much property stands behind them, 30% for other unsecured retail exposures and 50% for unsecured qualifying revolving retail. The spread between a home line and a shopping line is therefore mostly arithmetic once you hold the client signal constant, which is not how it is arrived at today.
9. What the single lending wallet looks like
Concretely, the client holds one credit relationship with one total limit, governed by an affordability envelope derived from their observed income process rather than a stated monthly salary. Inside that envelope sit several lines with different characteristics, all drawing on the same client risk signal. A home line is long tenor and property backed, so it prices lowest. A vehicle line is backed by an asset that depreciates on a known curve. A liquidity line is short and unsecured and prices accordingly. A purchase line handles the four instalment behaviour that BNPL invented, inside the limit rather than outside it. Repayments waterfall according to a rule the client sets and the wallet optimises, rather than according to whichever lender’s debit order hits the account first, which is the mechanism quietly setting priority in most South African households today.
10. Who gains, and the market this opens
The gain is available to both sides at once rather than being a transfer from one to the other. For the client, consolidating fragmented obligations under one risk signal with collateral properly recognised should reduce the blended cost of carrying the same debt, and it removes the internal version of the stacking externality entirely, because within the bank there is no longer a sequence of products independently diluting one another.
External stacking does not disappear, and claiming otherwise would be the easiest way to lose a credit risk audience. The customer can still hold your wallet alongside two BNPL accounts, another bank’s card and a retail account. What changes is that the remaining external exposure becomes an explicit, monitored input drawn from bureau and open banking data rather than an accidental blind spot, and the envelope can be set against total household obligations rather than against the fraction the bank happens to own. For the lender, the same book can be held at lower unexpected loss, the loss curve on large tickets flattens because the client signal is refreshed by advance behaviour rather than decaying from origination day, and the marginal cost of extending credit inside an existing envelope becomes a decision rather than a process.
The larger prize is eligibility rather than efficiency. Roughly 16 million South African adults have no active bureau profile, informal work accounts for close to a fifth of employment here and something near 85% across sub Saharan Africa on ILO estimates, and the share of consumers borrowing from informal lenders rose from about 15% in 2014 to roughly 37% by 2021, mostly because formal assessment was never available to them rather than because it found them wanting. A bureau silence is an absence of information, but a policy built on bureau data is forced to treat it as though it were a signal, so the customer is declined or priced for uncertainty rather than for risk. A wallet governed by an observed income process and a behavioural signal can price many of those households for the first time, using data the bank already owns, which makes this an addressable market argument rather than a margin argument.
11. The objections that deserve a straight answer
Portfolio thinking is weakest exactly where lending is most dangerous, because correlations that look stable in ordinary conditions converge violently in a downturn, and a household’s income shock, house price shock and employment shock are frequently the same shock wearing three hats. Any envelope constructed for a client has to be stressed against a single common factor rather than against the historical covariance, or it will simply be a more elegant way of being wrong at the bottom of the cycle.
The regulatory position is real but narrower than I first thought. In South Africa the affordability assessment regulations and section 119 of the National Credit Act attach the obligation to the point of initial credit approval and to increases in an existing credit limit, rather than to every individual draw inside a facility that has already been authorised, which means the governance burden falls on envelope creation and envelope increases, exactly where a wallet should want to concentrate its evidence anyway. What still has to be solved is explainability, since a decision emerging from a learned representation has to produce reasons that a regulator and a declined customer can both interrogate, and that comes from monotonic constraints, reason code generation and challenger scorecards rather than from hoping the model is charming.
Behavioural underwriting brings its own governance load, and inclusion objectives do not exempt anyone from it. Merchant level patterns can encode protected characteristics without anyone intending it, so proxy testing has to be a precondition of deployment rather than a remediation exercise, and categories such as gambling need explicit treatment rather than being left to a model to interpret as ordinary discretionary spending. There is also a signal decay problem that nobody has solved: customers who understand that their behaviour sets their limit will manage their behaviour, and a measurement that changes the thing it measures degrades over time.
The sharpest structural objection is concentration. A single wallet means one institution holds the complete behavioural picture of a household, which is the classic condition under which relationship lenders extract rents from borrowers who cannot credibly shop elsewhere. The remedy has to be portability, but portability of the right object. An embedding produced by one bank’s model is meaningless outside the model, tokenisation and event taxonomy that created it, so what must be portable is the consented underlying behavioural data, from which a competitor can build its own representation. That makes data rights and open banking the load bearing policy question rather than a technical footnote.
Finally there is the behavioural risk that a wallet which makes borrowing frictionless simply produces more borrowing. Frictionless credit against a live view of affordability is not automatically safer than clumsy credit against a stale one, and building a product whose commercial incentive is to lend more while its stated purpose is to lend better is a tension you design against explicitly, with a binding envelope and hard limits on how fast it can expand, or you do not really design against it at all.
12. Where a bank would actually start
None of this requires the full apparatus on day one. It requires, in order, a single customer exposure view that treats total obligations as the decision variable rather than a report; a common client risk signal estimated from behaviour and applied consistently to every line the institution grants that client; a wallet ledger that can hold multiple lines with different tenors and different collateral against one governed limit; a deliberate expansion of small advance volume as an information acquisition strategy rather than as a fee line; and only then a pretrained event sequence model of the PRAGMA variety to replace the hand engineered feature tables underneath all of it.
The prize is worth the effort. We currently operate a system in which the same person can be a 0.3% loss and a 10% loss at the same moment depending on which of our products they happen to be standing in front of, and we have chosen to interpret that as a fact about people. It is substantially a fact about information, priority and architecture, and all three of those are things we now know how to fix.
Sources
- PRAGMA: Revolut Foundation Model, arXiv 2604.08649
- Finally, an AI That Understands Money, Part Two: The Lending Market Hiding in Your Embeddings
- CFPB Data Spotlight: Developments in the Paycheck Advance Market
- CFPB, Consumer Use of Buy Now, Pay Later and Other Unsecured Debt, January 2025
- Eighty20 Credit Stress Report, Q1 2026
- Bizer and DeMarzo, Sequential Banking, Journal of Political Economy 100(1), 1992
- Hertzberg, Liberti and Paravisini, Public Information and Coordination: Evidence from a Credit Registry Expansion, Journal of Finance 66(2), 2011
- FinRegLab, The Use of Cash Flow Data in Underwriting Credit: Empirical Research Findings
- Basel Framework CRE 32: IRB approach, risk components for each asset class
- National Credit Act affordability assessment regulations, 2015