Design Prototype
CRP v3.2 · 2026
EXIM Bank of Pakistan

Credit Ratings Portal

A QR-driven credit intelligence system for Pakistani exporters at international trade expos. Three connected experiences — one mobile, two desktop — built around a strict separation of duties between EXIM and TDAP.

Demo flow
  1. 01 Exporter Mobile: start on the trade floor. Scan a booth, read the rating, see the recommended exposure cap.
  2. 02 EXIM Admin: the engine room. Maintain ratings, upload buyers in bulk, issue QR codes, audit everything.
  3. 03 TDAP Admin:  oversight without overreach. Verify exhibitors, run expos, see engagement, but never see ratings.
Three surfaces
Click any card to enter
Buyer · Hamburg
A+
Müller Textiles GmbH
Cap · USD 2.5M
Payment hist.94/100
Years in biz18
SanctionsClear
View advisory
Surface 01
Mobile · iOS / Android

Exporter Mobile

The point-of-trust experience. A Pakistani exhibitor scans a booth QR and receives EXIM's rating in under two seconds — readable one-handed under bright hall lighting.

9 screens QR scan Offline cache WCAG 2.1 AA
Open exporter view A1 → A9
BUYERS
1,204
SCANS TODAY
1,287
EXPORTERS
64
Surface 02
Desktop · 1440

EXIM Admin

The engine room. Maintain the buyer directory, bulk-upload via CSV, generate signed QR codes, second-line approve exporters, and audit every action.

Buyers Bulk upload QR Studio Audit log
Open EXIM admin 8 sections
TDAP CONSOLE
Exporter approvals
Rating band counts only
A+
A
B
C
D
E
Surface 03
Desktop · 1440

TDAP Admin

Oversight without overreach. First-line approve exhibitor applications, create & manage expo windows, see engagement analytics — ratings always withheld.

Approvals Expo mgmt Engagement SoD enforced
Open TDAP admin 5 sections
The model

One spine,
two mandates,
three surfaces.

EXIM owns
  • Buyer ratings & analyst notes
  • Recommended exposure caps
  • Sanctions & payment history
  • QR code issuance
TDAP owns
  • Exhibitor verification (KYC step 1)
  • Expo creation & rosters
  • Time-bound access windows
  • Engagement analytics
Shared
  • Tamper-evident audit log
  • Identity, session, RBAC
  • CSV ingest (API dormant)
  • SBP FE-25-2024 alignment