One Portal for Every Investor Complaint, from Filing to Final Decision
We designed and built the Mutual Funds Association of Pakistan's official Digital Complaint Management System. Investors get an online channel to file and follow a complaint; MUFAP's officers get a deadline-driven workflow that escalates a complaint automatically when it is left unattended.
Mutual Funds Association of Pakistan (MUFAP)
Financial services · Regulatory
Product Design, Web Application Development, Database Design, CI/CD & Deployment
The Mutual Funds Association of Pakistan (MUFAP) is the industry body for the asset management companies that run Pakistan's mutual funds. Under the MUFAP (SRO Functioning) Regulations, 2025, MUFAP must give investors a formal route to raise a complaint against a member company and see it through to a decision.
The Digital Complaint Management System (DCMS) is that route. An investor registers, files a complaint against an asset management company and receives a ticket number in the format CMS-2026-00001. From there the complaint moves through scrutiny by an Authorized Officer, a response from the regulated company, a decision by the Complaint Resolution Officer and, where needed, an appeal, with every step recorded on the complaint's timeline.
The public homepage, mobile filing, the CRO dashboard, automatic escalation and the reports area.
Role-based workspaces: Complainant, Authorized Officer, AO Supervisor, CRO, Regulated Person (AMC), RAC, Board and Administrator
Automatic escalation levels, triggered at day 7, 15, 22 and 28
Authorized Officer response window (working days) for a new complaint
Estimated Resolution Time in working days, configurable, with an approval flow for extensions
Languages across the public portal: English and Urdu
Export formats for reports, compliance data and complaint lists
Complaint counts visible in the screenshots come from the test environment, and personal details have been replaced with sample names. They are not production volumes.
Complaints reach MUFAP online, by email and on paper, and each one carries regulatory timelines: it has to be acknowledged, scrutinised, sent to the right asset management company, answered and decided within set periods. Tracked by hand across inboxes and spreadsheets, it is hard to tell which complaints are waiting on whom, which are overdue, and what was said at each stage.
Investors, meanwhile, had no way to see where their complaint stood, and the audience spans English and Urdu readers. The priority was a single system of record in which every complaint has an owner, a deadline and a complete history, and in which missed deadlines surface on their own rather than being discovered late.
Every complaint gets a ticket, an owner, a deadline and a timeline that investors, officers and member companies all share.
The public site explains the process in four steps and keeps English and Urdu side by side on every screen. Registration runs through four stages (Identity, Contact, Verify and Security) and validates a CNIC or passport before an account is created.
The complaint form captures the company, fund, folio number, the nature of the complaint, the relief sought and supporting documents. The investor receives a ticket number and can follow each stage of the complaint from their own dashboard.
Each role sees only the work that belongs to it. Authorized Officers scrutinise new complaints, accept or reject them, or ask the complainant for clarification, and can enter complaints received by email or on paper through a staff intake form.
Accepted complaints are forwarded to the regulated company, which answers through its own member portal. Responses and rejoinders build up on a shared timeline, the CRO records the decision, and an appeal can go to the Regulatory Appellate Committee (RAC).
Background services check every open complaint against its deadlines. A reminder goes to the Authorized Officer at day 7; the complaint escalates to the AO Supervisor at day 15, to the CRO at day 22 and to the RAC at day 28. Overdue complaints are flagged on the dashboards and on the complaint itself.
Any extension of the Estimated Resolution Time needs a new date and a written reason before it is approved. The escalation thresholds, email templates and lookups are all editable by administrators without a code change.
Dashboards show complaint volumes by status and stage at a glance. The Reports area covers status dashboards, statistical trends, ERT compliance, a report builder, a compliance report and the audit trail, along with an Authorized Officer performance breakdown. Reports export to PDF and CSV, and every significant action is written to an audit log.
Accounts are managed with ASP.NET Core Identity and role-based authorisation. Login throttling, idle-session timeouts, HTML sanitisation of user input and checks on uploaded files protect the portal and its data. Structured logging records application activity, and GitHub Actions pipelines build and deploy separate QA and Production environments to IIS.
Names and personal details in these screens are sample data. Select any screen to enlarge it.
Every complaint has a ticket number, a current owner and a deadline, so nothing waits without someone being accountable for it.
Escalation is automatic: the system raises an unattended complaint to the next level rather than relying on someone to notice.
Investors, MUFAP officers and regulated companies work from the same complaint record and timeline, each through their own workspace.
Built-in reports and the audit trail let MUFAP show how complaints were handled and whether timelines were met.
The project went through user acceptance testing with MUFAP, with 45 observations logged and tracked portal by portal.