Financial Services · Web Platform

MUFAP Complaint Management System

One Portal for Every Investor Complaint, from Filing to Final Decision

We designed and built the Mutual Funds Association of Pakistan's official Digital Complaint Management System. Investors get an online channel to file and follow a complaint; MUFAP's officers get a deadline-driven workflow that escalates a complaint automatically when it is left unattended.

MUFAP complaint portal: All Complaints screen
Client

Mutual Funds Association of Pakistan (MUFAP)

Industry

Financial services · Regulatory

Services

Product Design, Web Application Development, Database Design, CI/CD & Deployment

Live portal

cms.mufap.com.pk

Project Overview

A Formal Route From Complaint to Decision

The Mutual Funds Association of Pakistan (MUFAP) is the industry body for the asset management companies that run Pakistan's mutual funds. Under the MUFAP (SRO Functioning) Regulations, 2025, MUFAP must give investors a formal route to raise a complaint against a member company and see it through to a decision.

The Digital Complaint Management System (DCMS) is that route. An investor registers, files a complaint against an asset management company and receives a ticket number in the format CMS-2026-00001. From there the complaint moves through scrutiny by an Authorized Officer, a response from the regulated company, a decision by the Complaint Resolution Officer and, where needed, an appeal, with every step recorded on the complaint's timeline.

The public homepage, mobile filing, the CRO dashboard, automatic escalation and the reports area.

Platform at a Glance

8

Role-based workspaces: Complainant, Authorized Officer, AO Supervisor, CRO, Regulated Person (AMC), RAC, Board and Administrator

4

Automatic escalation levels, triggered at day 7, 15, 22 and 28

7 days

Authorized Officer response window (working days) for a new complaint

30 days

Estimated Resolution Time in working days, configurable, with an approval flow for extensions

2

Languages across the public portal: English and Urdu

PDF / CSV

Export formats for reports, compliance data and complaint lists

Complaint counts visible in the screenshots come from the test environment, and personal details have been replaced with sample names. They are not production volumes.

The Challenge

Complaints reach MUFAP online, by email and on paper, and each one carries regulatory timelines: it has to be acknowledged, scrutinised, sent to the right asset management company, answered and decided within set periods. Tracked by hand across inboxes and spreadsheets, it is hard to tell which complaints are waiting on whom, which are overdue, and what was said at each stage.

Investors, meanwhile, had no way to see where their complaint stood, and the audience spans English and Urdu readers. The priority was a single system of record in which every complaint has an owner, a deadline and a complete history, and in which missed deadlines surface on their own rather than being discovered late.

Solution Approach

How We Built It

Every complaint gets a ticket, an owner, a deadline and a timeline that investors, officers and member companies all share.

01

A Public Portal Investors Can Use

The public site explains the process in four steps and keeps English and Urdu side by side on every screen. Registration runs through four stages (Identity, Contact, Verify and Security) and validates a CNIC or passport before an account is created.

The complaint form captures the company, fund, folio number, the nature of the complaint, the relief sought and supporting documents. The investor receives a ticket number and can follow each stage of the complaint from their own dashboard.

Mobile views: the homepage, the bilingual registration flow and the CRO dashboard.
02

A Workspace for Every Role

Each role sees only the work that belongs to it. Authorized Officers scrutinise new complaints, accept or reject them, or ask the complainant for clarification, and can enter complaints received by email or on paper through a staff intake form.

Accepted complaints are forwarded to the regulated company, which answers through its own member portal. Responses and rejoinders build up on a shared timeline, the CRO records the decision, and an appeal can go to the Regulatory Appellate Committee (RAC).

All Complaints: filters by status, stage, regulated company and ticket number, with an Action Required queue.
03

Deadlines Enforced by the System

Background services check every open complaint against its deadlines. A reminder goes to the Authorized Officer at day 7; the complaint escalates to the AO Supervisor at day 15, to the CRO at day 22 and to the RAC at day 28. Overdue complaints are flagged on the dashboards and on the complaint itself.

Any extension of the Estimated Resolution Time needs a new date and a written reason before it is approved. The escalation thresholds, email templates and lookups are all editable by administrators without a code change.

Manage Complaint on desktop and mobile: an overdue complaint at escalation Level 4, with its deadline flagged.
04

Reporting and Accountability

Dashboards show complaint volumes by status and stage at a glance. The Reports area covers status dashboards, statistical trends, ERT compliance, a report builder, a compliance report and the audit trail, along with an Authorized Officer performance breakdown. Reports export to PDF and CSV, and every significant action is written to an audit log.

Reports and Analytics: status dashboards, six-month volume trend and Authorized Officer performance.
05

Security and Operations

Accounts are managed with ASP.NET Core Identity and role-based authorisation. Login throttling, idle-session timeouts, HTML sanitisation of user input and checks on uploaded files protect the portal and its data. Structured logging records application activity, and GitHub Actions pipelines build and deploy separate QA and Production environments to IIS.

Under the Hood

Technology Stack

Backend
ASP.NET Core 9 (Razor Pages), C#, Entity Framework Core 9
Database
Microsoft SQL Server, with EF Core migrations applied on deployment
Identity & security
ASP.NET Core Identity, role-based authorisation, Data Protection keys stored in SQL Server, HtmlSanitizer
Automation
Hosted background services for reminders, escalation and login-throttle cleanup; templated SMTP email notifications
Frontend
Tailwind CSS 3.4, Chart.js, Lucide icons, Choices.js, Quill editor, jQuery Validation
Languages & typography
English and Urdu, with Inter and Noto Nastaliq Urdu
Logging
Serilog
Delivery
GitHub Actions CI/CD to IIS on Windows Server, with QA and Production pipelines

Key Takeaways

01

Every complaint has a ticket number, a current owner and a deadline, so nothing waits without someone being accountable for it.

02

Escalation is automatic: the system raises an unattended complaint to the next level rather than relying on someone to notice.

03

Investors, MUFAP officers and regulated companies work from the same complaint record and timeline, each through their own workspace.

04

Built-in reports and the audit trail let MUFAP show how complaints were handled and whether timelines were met.

05

The project went through user acceptance testing with MUFAP, with 45 observations logged and tracked portal by portal.

Need a Compliance-Ready Portal for Your Organisation?

If your organisation handles complaints, cases or requests under regulatory timelines, 360TechSys can design and build a portal that assigns every item an owner, enforces its deadlines and keeps a complete record.