The 10-Step Borrower’s Safety Checklist: How to Vet Any Online Loan Offer

The 10-Step Borrower’s Safety Checklist: How to Vet Any Online Loan Offer

Before you click “Apply” on any online loan—especially a microfinance (MFO) offer or a quick-cash service—stop. Fraudsters and predatory lenders know that urgency and desperation are their best tools. This checklist is designed to be your practical, step-by-step safety net. It will not promise you approval, “instant” anything, or government backing. It will, however, give you a verifiable process to check every critical detail. Use it every time.


Step 1: Verify the Official Domain (Not Just the Logo)

Scammers create near-perfect copies of legitimate lender websites. The first red flag is often the URL.

What to do:

  • Check the exact spelling: Look for typos like “sberbankk.com” instead of “sberbank.ru,” or “alfabank-loan.xyz” instead of “alfabank.ru.”
  • Look for the padlock icon: A secure connection (HTTPS) is mandatory, but not proof of legitimacy—scammers also use it. Still, never enter data on a site without it.
  • Use a WHOIS lookup: Free tools like whois.ru or whois.icann.org will show you when the domain was registered. A very recently created domain can be a warning sign.
  • Avoid “mirror” domains: If the site claims to be a “regional office” or “partner” of a known bank but has a completely different domain (e.g., “sber-credit24.com”), do not proceed.
Pro tip: Bookmark the official website of any lender you are considering. Always navigate from your bookmark, not from an email link or ad.


Step 2: Read the Consent Text (Not Just Click “Agree”)

Every legitimate lender must obtain your explicit consent to process personal data. The text of that consent matters.

What to do:

  • Find the consent checkbox or separate document. It should be a clear, separate action—not buried in 50 pages of terms.
  • Look for specific language: The consent should state what data is collected (e.g., passport number, income, contact info), why it is collected (for loan processing, credit check), and who it is shared with (credit bureaus, collection agencies).
  • Watch for vague or unlimited consent: If the text says “we may share your data with any third parties” or “for any business purpose,” that is a red flag. Legitimate lenders list specific partners.
  • Check for a right to withdraw: Privacy regulations in many jurisdictions require that you can revoke consent at any time. If the document says “consent is irrevocable,” it is illegal.
If you cannot find a separate, clear consent document, close the tab.


Step 3: Identify the Lender’s Legal Identity

You need to know exactly who you are borrowing from. A flashy brand name is not enough.

What to do:

  • Find the full legal name: Look for “LLC,” “JSC,” “IP,” or “AO” followed by a registered name (e.g., “LLC ‘Microfinance Company X’”). This should be in the footer of every page or in the “About” section.
  • Check the OGRN (Primary State Registration Number): Every legal entity in Russia has a unique OGRN. Write it down.
  • Search the OGRN online: Go to the Federal Tax Service website (egrul.nalog.ru) and enter the OGRN. The result should match the lender’s name, registration date, and address. If the company doesn’t exist, or if the name is different, stop.
  • Beware of foreign entities: If the lender claims to be registered in Cyprus, the Bahamas, or another jurisdiction but targets Russian borrowers, it is almost certainly unregulated and likely a scam.
Do not proceed if you cannot find a verifiable legal entity with a valid OGRN.


Step 4: Check the MFO Registry (If Applicable)

If the lender is a microfinance organization (MFO), it must be in the official register of the Central Bank of Russia (CBR). This is non-negotiable.

What to do:

  • Go to the CBR website: Visit cbr.ru and navigate to the “Financial Markets” section, then “Registers.” Look for “Register of Microfinance Organizations.”
  • Search by name or OGRN: Enter the lender’s legal name or OGRN. The register will show the status (active, suspended, or excluded), the date of entry, and the license number.
  • Check the status: “Active” means the MFO is currently regulated. “Excluded” means it has lost its license—do not lend from or repay such an entity.
  • Verify the address: The registered address in the CBR register should match the address on the lender’s website. If they differ, contact the CBR to report it.
Note: Not all lenders are MFOs. Banks and credit cooperatives have their own registers. But if the offer says “microcredit” or “quick loan,” check the MFO register first.


Step 5: Calculate the Full Cost of the Loan (PSK)

The “interest rate” is a trap. The real cost is the Full Cost of the Loan (PSK) —a mandatory disclosure under Russian law (Federal Law 353-FZ).

What to do:

  • Find the PSK on the first page of the loan agreement. It must be displayed in a box in the upper right corner, in a font larger than the rest of the text. It looks like a percentage (e.g., “PSK: 365.0%”).
  • Compare the PSK to the advertised rate: If the ad says “0.1% per day,” the annual PSK will be around 36.5% (0.1% × 365). If the PSK is much higher (e.g., 500%), the lender is hiding extra fees.
  • Check for additional charges: The PSK includes interest, fees for account maintenance, insurance (if mandatory), and any other compulsory costs. If the PSK is missing or illegible, do not sign.
  • Check the CBR’s maximum PSK limits: The CBR sets a quarterly maximum PSK for different loan types. Verify the current limit on the CBR website before proceeding. If the PSK is above this, the loan may be illegal.
Example: A loan of 10,000 rubles for 30 days at a PSK of 365% means you will owe roughly 13,000 rubles back. If the lender says “only 1,000 rubles in interest,” but the PSK is much higher, they are lying.


Step 6: Assess Your Repayment Ability (Before You Apply)

This is not about what the lender approves—it’s about whether you can pay back without falling into a debt spiral.

What to do:

  • Calculate your debt-to-income ratio (DTI): Add up all your monthly loan payments (existing loans, credit cards, this new loan) and divide by your monthly net income. A safe DTI is below 30%. If it’s above 50%, do not take the loan.
  • Check the lender’s debt load assessment: Many lenders are required to check your “debt load ratio.” If they approve you despite a high DTI, they are being predatory.
  • Plan for the worst: What if you lose your job or have a medical emergency? If you cannot afford the payment without taking another loan, do not borrow.
  • Check the loan term: Shorter terms (e.g., 7 days) mean higher monthly payments. Make sure the payment fits your budget, not just your hope.
Remember: If you cannot repay, the lender may sell your debt to collectors, and your credit score could be damaged for years.


Step 7: Verify Card Requirements (No CVV/CVC)

Legitimate lenders will never ask for your card’s security code (CVV/CVC) or the full card number for a “verification” deposit.

What to do:

  • Check the payment method: The lender should only ask for your card number and expiry date to deposit the loan. They should not ask for the CVV code.
  • Beware of “verification” fees: A common scam is to ask for a small deposit (e.g., 100 rubles) to “verify” your account. Legitimate lenders do not do this.
  • Look for 3D Secure: If the lender asks you to enter a one-time SMS code from your bank, that is normal for 3D Secure. But if they ask for the code “to confirm the loan,” that is a scam—they are trying to steal your money.
  • Use a separate card: If possible, use a virtual or disposable card with a low limit for any online loan application. This limits your exposure.
If any request makes you uncomfortable, stop the process and contact your bank immediately.


Step 8: Gather the Required Documents (Know What’s Normal)

Legitimate lenders ask for a reasonable set of documents. If they ask for too much or too little, be suspicious.

What to do:

  • Check the standard list: For most online loans in Russia, the minimum is:
  • Passport (Russian Federation)
  • Second document (e.g., driver’s license, SNILS, INN)
  • Proof of income (e.g., 2-NDFL, bank statement, or pension certificate)
  • Watch for excessive demands: If the lender asks for your passport scan, a selfie with your passport, a video of your face, your social media passwords, or your bank login credentials—stop. That is data theft.
  • Beware of “no documents” offers: A loan that requires “only a passport” is usually a high-risk MFO with a very high PSK. It is not a good deal.
  • Check for notarization: Some loans require notarized documents. If the lender insists on a notary that they recommend, it might be a kickback scheme. Use your own notary.
Do not upload documents to a site that looks unprofessional or has broken English.


Step 9: Review the Privacy Policy (Not Just the Consent)

The privacy policy tells you what happens to your data after the loan is approved or denied.

What to do:

  • Find the privacy policy link: It should be in the footer of every page.
  • Look for data retention periods: The policy should state how long your data is kept (e.g., “for the duration of the loan plus 5 years after repayment”). If it says “indefinitely,” that is a risk.
  • Check for third-party sharing: The policy should list all third parties (credit bureaus, collection agencies, marketing partners). If it says “we may share your data with any partners without notice,” it is a red flag.
  • Look for cross-border transfer: If the lender says they may transfer your data to countries with weaker privacy laws, that is a risk.
  • Check for a data protection officer: Legitimate lenders often list a contact for data protection inquiries. If there is none, the company is not serious about compliance.
If the privacy policy is missing, copy-pasted from another site, or contradicts the consent text, do not proceed.


Step 10: Identify Scam Signals (The Final Gut Check)

By now, you have a lot of technical data. But sometimes the biggest red flags are behavioral.

What to do:

  • Check for pressure tactics: If the lender says “limited time offer,” “only 2 loans left,” or “apply now or lose the chance,” it’s a scam. Legitimate lenders don’t use artificial scarcity.
  • Look for typos and poor design: Professional lenders invest in their websites. If the site has broken links, grammar errors, or blurry images, it’s likely a scam.
  • Search for reviews (with skepticism): Look at banki.ru, otzovik.com, or the CBR’s complaint database. But beware of fake reviews—scammers often post 5-star reviews. Look for patterns: multiple complaints about hidden fees or aggressive collection.
  • Check the support contacts:
  • A legitimate lender will have a phone number, email, and physical address.
  • Call the number. If no one answers, or if it’s a mobile number, be suspicious.
  • Send a test email. If you get an auto-reply with poor grammar, it’s a scam.
  • Check the CBR’s resources: The CBR may publish information about companies with signs of illegal activity. Search for the lender’s name on the CBR website.
Final test: If something feels off, it probably is. Trust your gut. There will always be another loan offer tomorrow.


Summary: Your Quick Reference

StepWhat to CheckRed Flag
1Domain spelling, age, HTTPSTypos, very new domain, no padlock
2Consent text clarityVague, unlimited, irrevocable
3Legal entity + OGRNMissing or mismatched OGRN
4MFO registry (if MFO)Not in register, status “excluded”
5PSK (Full Cost)Missing, above legal limit, hidden fees
6Your repayment abilityDTI > 50%, no emergency plan
7Card requirementsAsking for CVV, “verification” fee
8Document listToo many/too few, asks for passwords
9Privacy policyMissing, indefinite retention, vague sharing
10Scam signalsPressure tactics, bad reviews, no support

Remember: No legitimate lender will promise “guaranteed approval,” “instant money,” or “government support.” If they do, run. Use this checklist every time, and you will avoid most traps. Stay safe.

Полина Козлова

Полина Козлова

Legal-Source Monitor

Irina tracks changes in Russian legislation related to microloans and digital identification. She curates official sources.

Комментарии (0)

Оставить комментарий