Seo Title

KYC & AML Policy

KYC & AML Policy
01
Preamble

This Know Your Customer (KYC) and Anti-Money Laundering (AML) Policy (“Policy”) has been adopted by Samraat Finlease Private Limited (“the Company”) in accordance with the regulatory framework prescribed by the Reserve Bank of India (RBI), including the Master Direction – Know Your Customer (KYC) Direction, 2016, as amended from time to time.

This Policy is aligned with the provisions of the Prevention of Money Laundering Act, 2002(PMLA), the rules framed thereunder, and other applicable laws, regulations, and guidelines relating to Anti-Money Laundering (AML) and Combating Financing of Terrorism (CFT).

The Policy establishes a risk-based and technology-enabled framework for customer acceptance, identification, verification, due diligence, customer risk classification, ongoing monitoring, and regulatory reporting, with the objective of preventing and detecting money laundering, terrorist financing, and other unlawful activities.

This Policy shall be read in conjunction with other applicable internal policies of the Company, including the Digital Lending Policy, Information Security Policy, and Risk Management Policy, to ensure a consistent compliance framework across the Company’s operations.

02
Regulatory Framework

This Policy is framed in accordance with and shall be governed by the applicable laws, regulations, and regulatory guidelines, including but not limited to:

  • The Reserve Bank of India (RBI) Master Direction – Know Your Customer (KYC) Direction, 2016, as amended from time to time;
  • The provisions of the Prevention of Money Laundering Act, 2002 (PMLA) and the rules framed thereunder, including applicable obligations relating to Anti-Money Laundering (AML) and Combating Financing of Terrorism (CFT);
  • Applicable circulars, notifications, directions, and guidelines issued by the RBI from time to time relating to KYC, AML, customer due diligence, and digital onboarding; and
  • Other applicable laws, regulations, and regulatory requirements issued by relevant authorities, as applicable from time to time.


This Policy shall be reviewed and updated periodically to ensure continued alignment with applicable regulatory requirements.

03
Objectives

The objectives of this Policy are to:

  • Establish a risk-based framework for customer acceptance, identification, verification, and due diligence in accordance with applicable regulatory requirements;
  • Prevent and detect money laundering, terrorist financing, and other illicit activities through effective Anti-Money Laundering (AML) and Combating Financing of Terrorism (CFT) measures;
  • Ensure identification and verification of beneficial ownership and control structures of customers;
  • Enable ongoing monitoring of customer relationships and transactions to identify unusual or suspicious activities;
  • Ensure timely reporting of prescribed transactions and suspicious activities to the appropriate regulatory authorities;
  • Adopt a risk-based approach for customer risk categorisation based on factors including customer profile, business activities, and geographical location;
  • Ensure compliance with the Prevention of Money Laundering Act, 2002 (PMLA), the RBI Master Direction – Know Your Customer (KYC) Direction, 2016, as amended from time to time, and other applicable regulatory requirements; and
  • Strengthen internal controls, employee awareness, and governance mechanisms for effective management of KYC and AML risks.

04
Scope

This Policy applies to all customer relationships, products, services, and transactions undertaken by the Company and covers the following:

  • All categories of customers, including individuals, proprietorships, partnerships, companies, trusts, and other legal entities;
  • All products and services offered by the Company through physical, digital, or third-party channels;
  • All stages of the customer lifecycle, including onboarding, identification, verification, due diligence, risk classification, ongoing monitoring, and account closure;
  • All employees, directors, officers, authorised representatives, agents, and third-party service providers involved in customer acquisition, KYC processes, transaction handling, monitoring, or compliance activities;
  • All branches, offices, and operational units of the Company.


This Policy shall apply across all business functions of the Company and shall be read in conjunction with other applicable internal policies to ensure a consistent compliance framework.

Where the Company engages third-party service providers or agents for customer onboarding or KYC-related activities, the ultimate responsibility for compliance with applicable KYC and AML requirements shall remain with the Company.

Where the Company relies on third-party service providers for customer due diligence or KYC processes, such reliance shall be in accordance with applicable regulatory guidelines, and the ultimate responsibility for customer identification, verification, and due diligence shall at all times remain with the Company.

05
Definitions

For the purpose of this Policy, the following terms shall have the meanings assigned to them below:

  1. Customer: A person or entity that establishes a business relationship with the Company or avails any financial product or service offered by the Company, including individuals and non-individual entities.
  2. Beneficial Owner (BO): The natural person(s) who ultimately owns or controls a customer or the person on whose behalf a transaction is being conducted, including the person(s) exercising ultimate effective control over a legal entity or arrangement.
  3. Politically Exposed Person (PEP): Individuals who are or have been entrusted with prominent public functions, including heads of state or government, senior politicians, senior government, judicial, or military officials, senior executives of state-owned corporations, and their immediate family members and close associates, as defined under applicable regulatory requirements.
  4. Customer Due Diligence (CDD): The process of identifying and verifying customers and beneficial owners, understanding the nature and purpose of the customer relationship, and assessing customer risk in accordance with applicable regulatory requirements.
  5. Enhanced Due Diligence (EDD): Additional due diligence measures undertaken for customers or relationships identified as posing higher risks, including high-risk customers, PEPs, or other categories requiring enhanced scrutiny.
  6. Customer Risk Categorisation: The process of classifying customers into appropriate risk categories based on factors such as customer profile, nature of business, geographic risk, transaction behaviour, and other relevant parameters.
  7. Ongoing Due Diligence: Continuous monitoring and review of customer relationships and transactions to ensure that the information maintained by the Company remains updated and that activities are consistent with the customer profile and risk classification.
  8. Suspicious Transaction: A transaction, whether completed or attempted, which appears to involve proceeds of crime, unusual activity, or circumstances indicating possible money laundering, terrorist financing, or other unlawful activities.
  9. Suspicious Transaction Report (STR): A report submitted to the Financial Intelligence Unit-India (FIU-IND) relating to transactions identified as suspicious in accordance with applicable regulatory requirements.
  10. Financial Intelligence Unit-India (FIU-IND): The central national agency responsible for receiving, processing, analysing, and disseminating information relating to suspicious financial transactions and other relevant financial intelligence.


These definitions shall be interpreted in accordance with the provisions of the Prevention of Money Laundering Act, 2002, the rules framed thereunder, the RBI Master Direction - Know Your Customer (KYC) Direction, 2016, and amendments issued from time to time.

5.1 Interpretation Words and expressions used in this Policy but not specifically defined herein shall have the meanings assigned to them under applicable laws, rules, and regulatory guidelines, including the Prevention of Money Laundering Act, 2002, the rules framed thereunder, and the RBI Master Direction - Know Your Customer (KYC) Direction, 2016, as amended from time to time.

In case of any ambiguity or interpretation-related issues, the matter shall be referred to the Principal Officer for appropriate guidance and resolution, subject to applicable laws, regulatory requirements, and directions issued by competent authorities.

06
Customer Acceptance Policy (CAP)

The Company shall adopt a risk-based Customer Acceptance Policy to ensure that customers are onboarded only after appropriate identification, verification, and risk assessment. The following principles shall be adhered to:

  • The Company shall accept customers only after establishing their identity, verifying required documents and information, and assessing their risk profile in accordance with applicable KYC requirements;
  • The Company shall not open or maintain accounts or establish customer relationships in anonymous or fictitious names or where the identity of the customer cannot be satisfactorily established;
  • The Company shall not establish or continue customer relationships where there are reasonable grounds to believe that the customer may be involved in money laundering, terrorist financing, or other unlawful activities;
  • Customers shall be categorized into appropriate risk categories, including low, medium, and high-risk categories, based on factors such as customer profile, nature of business, geographical location, expected transaction profile, and other relevant parameters;
  • Enhanced Due Diligence (EDD) measures shall be applied to high-risk customers, including Politically Exposed Persons (PEPs), non-resident customers, and customers having complex ownership or control structures, wherever applicable;
  • Customer acceptance decisions shall not be influenced by factors such as inability to obtain required information, lack of transparency in beneficial ownership, or other circumstances indicating increased risk;
  • The Company shall reject, suspend, or discontinue customer relationships where applicable KYC requirements are not fulfilled or where suspicious activity or regulatory concerns are identified;
  • The Company shall screen customers against applicable sanctions lists, including United Nations sanctions lists, RBI caution lists, and other applicable regulatory watchlists, prior to onboarding and during the customer relationship, as required.


6.1 Sanctions Screening and Watchlist Monitoring The Company shall establish and implement an appropriate sanctions screening framework to identify and mitigate risks associated with designated individuals and entities. The following measures shall be undertaken:

  • Customers shall be screened against applicable sanctions lists and watchlists, including but not limited to United Nations Security Council (UNSC) Sanctions Lists, RBI caution lists, and other lists prescribed by regulatory authorities, at the time of onboarding and on an ongoing basis during the course of the customer relationship, as required;
  • Periodic re-screening of existing customers shall be conducted to identify any changes in sanctions status and ensure continued compliance with applicable requirements;
  • Any potential or confirmed match with applicable sanctions lists shall be promptly escalated to the Principal Officer and Compliance Function for review, investigation, and appropriate action;
  • The Company shall ensure that transactions with individuals or entities appearing in applicable sanctions lists are not undertaken, except as permitted under applicable laws or regulatory requirements;
  • Records relating to screening activities, potential matches, false positives, and actions taken shall be maintained for audit and regulatory purposes.


6.2 Customer Exit Policy The Company shall maintain a defined process for terminating or discontinuing customer relationships in a risk-based and controlled manner. The Company may discontinue or terminate a customer relationship under circumstances including, but not limited to:

  • Failure of the customer to comply with applicable KYC requirements or periodic updation obligations;
  • Identification of suspicious transactions or reasonable grounds to believe that the customer may be involved in money laundering, terrorist financing, or other unlawful activities;
  • Inability to establish or verify the identity or beneficial ownership of the customer;
  • Adverse regulatory, reputational, or risk considerations.
  • Before termination or discontinuation, the Company shall ensure that:
  • Appropriate internal review and approvals are obtained in accordance with the Company’s internal processes;
  • The reasons for termination or discontinuation are properly documented and records are maintained;
  • The decision is taken in accordance with applicable laws, regulatory requirements, and internal policies.
The Company shall ensure that the exit process is conducted in a fair, transparent, and non-discriminatory manner while complying with applicable legal and regulatory requirements.

07
Customer Identification Procedures (CIP)

The Company shall establish and implement Customer Identification Procedures (CIP) to verify the identity of customers at the time of onboarding and ensure compliance with applicable KYC requirements. Customer identification shall be undertaken using reliable, independent, and officially valid documents, data, or information.

7.1 Individuals The Company shall obtain and verify the following documents and information for individual customers:

  • Permanent Account Number (PAN) or such other document as may be prescribed under applicable regulations;
  • Officially Valid Documents (OVDs) for identity and address verification, including Aadhaar, Passport, Voter ID, Driving Licence, or any other document notified by regulatory authorities;
  • Recent photograph and other information, wherever required, to establish identity and address.
Where Aadhaar is used for KYC purposes, the Company shall ensure compliance with applicable laws and regulatory guidelines.

7.2 Compliance with PMLA Rules The Company shall carry out customer identification and verification in accordance with Rule 9 of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, including verification of identity using reliable and independent sources, collection of prescribed documents, and maintenance of records as required under applicable law.

7.3 Non-Individual Customers For non-individual customers, the Company shall obtain and verify documents relating to legal existence, ownership, and control structure, including:

  • Certificate of Incorporation/Registration;
  • Memorandum and Articles of Association, Partnership Deed, Trust Deed, or other constitutional documents, as applicable;
  • Board Resolution or authorisation documents for authorised representatives, wherever applicable;
  • Identification documents of authorised signatories and key persons;
  • Details and identification of Beneficial Owner(s) in accordance with applicable regulatory requirements.
7.4 Modes of KYC The Company may undertake customer identification through permitted KYC modes, including:

  • Physical KYC through in-person verification;
  • Aadhaar-based e-KYC authentication, subject to customer consent and applicable legal requirements;
  • Video-based Customer Identification Process (V-CIP), wherever applicable, in accordance with prescribed standards and controls.
The Company shall ensure that all KYC processes, including digital modes, are conducted in a secure, auditable, and compliant manner.

7.5 Ongoing Due Diligence The Company shall periodically update customer identification records and undertake re-verification based on customer risk classification and applicable regulatory requirements.

7.6 Unique Customer Identification Code (UCIC) The Company shall assign a Unique Customer Identification Code (UCIC) to customers, wherever applicable, and use such identifier across relevant systems and records to facilitate customer tracking, monitoring, and prevention of duplication of customer information.

7.7 Central KYC Records Registry (CKYCR) The Company shall upload customer KYC records to the Central KYC Records Registry (CKYCR) in accordance with the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, and applicable regulatory requirements.

The Company shall:

  • Ensure timely submission of customer KYC data to CKYCR within prescribed timelines;
  • Retrieve KYC records from CKYCR, wherever available, to avoid duplication of KYC processes;
  • Maintain the KYC Identifier (KYC ID) generated through CKYCR for customer identification and verification purposes;
  • Ensure accuracy, completeness, and security of KYC information submitted to CKYCR.
The Company shall comply with all applicable CKYCR-related obligations prescribed under applicable laws and regulatory guidelines from time to time.

08
Customer Due Diligence (CDD)

The Company shall undertake Customer Due Diligence (CDD) measures to identify and verify customers, understand the nature and purpose of the customer relationship, and assess associated risks. The extent and level of due diligence shall be determined based on the customer’s risk profile and in accordance with a risk-based approach.

8.1 Types of Due Diligence
• Simplified Due Diligence (SDD):
Applicable to customers assessed as low-risk, where the risk of money laundering or terrorist financing is considered low. Simplified measures may be applied in accordance with applicable regulatory requirements; however, basic customer identification and verification requirements shall continue to be complied with.

• Standard Due Diligence (CDD):
Applicable to customers assessed as normal-risk and includes obtaining and verifying customer identity, address details, and other relevant information, along with understanding the nature and purpose of the customer relationship.

• Enhanced Due Diligence (EDD):
Applicable to customers assessed as high-risk and involves additional verification, enhanced scrutiny, and monitoring measures to mitigate risks associated with such customers.

8.2 Enhanced Due Diligence (EDD)
Enhanced Due Diligence (EDD) shall be undertaken for customers identified as high-risk or where additional scrutiny is required based on the Company’s risk assessment. Such cases may include, but are not limited to:

  • Customers categorised as high-risk based on internal risk assessment parameters;
  • Politically Exposed Persons (PEPs), including their immediate family members and close associates, wherever applicable;
  • Non-resident customers and customers associated with high-risk jurisdictions;
  • Customers having complex ownership structures or where beneficial ownership cannot be readily established;
  • Customers exhibiting high-value, unusual, or suspicious transaction patterns;
  • Customers onboarded through non-face-to-face channels requiring enhanced controls under applicable regulatory requirements; and
  • Customers associated with jurisdictions identified by the Financial Action Task Force (FATF) as high-risk or non-cooperative jurisdictions;
  • Customers where there are reasonable grounds to suspect money laundering, terrorist financing, or other unlawful activities.
EDD measures may include, but are not limited to:

  • Obtaining additional customer identification, background, and business-related information, wherever applicable;
  • Verification of source of funds and source of wealth, wherever applicable;
  • Obtaining appropriate internal approval for onboarding or continuation of customer relationships;
  • Increased frequency of customer review and transaction monitoring based on the assessed risk.
8.3 Ongoing Due Diligence The Company shall conduct ongoing due diligence on customer relationships by:

  • Monitoring customer transactions to ensure consistency with the customer profile, nature of activities, and assigned risk category;
  • Identifying, reviewing, and reporting unusual or suspicious transactions in accordance with applicable regulatory requirements;
  • Updating customer information and KYC records periodically based on the customer’s risk classification and applicable regulatory requirements.
Based on its risk assessment, the Company may restrict, suspend, or terminate customer relationships where the customer fails to comply with KYC requirements, suspicious activities are identified, or continuation of the relationship poses regulatory, compliance, reputational, or operational risks to the Company.

09
Risk Categorization

The Company shall adopt a risk-based approach for categorising customers into appropriate risk levels to apply proportionate Customer Due Diligence (CDD), monitoring, and control measures.

9.1 Risk Categories Customers shall be classified into the following risk categories based on factors including customer profile, nature of activities, transaction behaviour, geographic risk, and other relevant parameters:

  • Low Risk: Customers assessed to have a lower risk profile based on factors such as transparent profile, satisfactory identification, and established source of income or funds;
  • Medium Risk: Customers presenting moderate risk factors requiring standard due diligence and periodic monitoring;
  • High Risk: Customers presenting higher exposure to money laundering, terrorist financing, or other regulatory risks, requiring Enhanced Due Diligence (EDD) and increased monitoring.
9.2 Risk Assessment Parameters Customer risk categorisation shall be based on various parameters, including but not limited to:

  • Nature of the customer’s business, occupation, or activities;
  • Geographic location and associated risk factors, including exposure to high-risk jurisdictions, wherever applicable;
  • Expected and actual transaction patterns, transaction volume, and frequency;
  • Customer profile, including background, source of funds, and other relevant financial information, wherever applicable;
  • Type of product or service availed by the customer;
  • Mode of onboarding, including face-to-face and non-face-to-face channels, considering applicable risk factors and controls;
  • Complexity of ownership structure and identification of Beneficial Owner(s), wherever applicable.
9.3 Risk Scoring Methodology The Company shall adopt an internal risk scoring framework to classify customers into Low, Medium, or High-risk categories. The risk score shall be determined based on a combination of factors, including customer profile, nature of activities, geographic risk, transaction behaviour, mode of onboarding, and ownership structure.

Each parameter shall be assigned appropriate weightage, and the overall risk classification shall be derived based on an aggregated scoring approach. The Company may apply additional qualitative assessment or overrides, wherever required, based on specific risk indicators or regulatory considerations.

The risk scoring methodology shall be periodically reviewed and updated in line with applicable regulatory requirements and the Company’s internal risk assessment framework.

9.4 Review and Updation
  • Risk categorisation shall be carried out at the time of onboarding and shall be reviewed periodically or upon occurrence of any material change in the customer’s profile, risk indicators, or transaction behaviour;
  • The frequency of review shall be aligned with the customer’s risk category, with more frequent reviews and monitoring for high-risk customers, in accordance with applicable regulatory requirements;
  • The Company shall ensure that any changes in risk classification are appropriately documented, supported by rationale, and reflected in the customer’s KYC records and monitoring framework.
9.5 Linkage with Due Diligence The risk category assigned to a customer shall determine the level of Customer Due Diligence (CDD), ongoing monitoring, and periodic KYC updation requirements in accordance with the Company’s risk-based framework.

Customers categorised as low-risk shall be subject to simplified or standard due diligence measures, while customers categorised as medium-risk shall be subject to standard due diligence and monitoring. Customers identified as high-risk shall be subject to Enhanced Due Diligence (EDD), increased monitoring, and more frequent review and KYC updation, as applicable.

10
Ongoing Monitoring

The Company shall establish and maintain an effective framework for ongoing monitoring of customer relationships and transactions to ensure that activities are consistent with the customer’s profile, risk category, and source of funds.

10.1 Transaction Monitoring

  • The Company shall monitor customer transactions on a continuous basis using appropriate systems and controls to identify unusual, inconsistent, or suspicious patterns;
  • Transactions shall be analysed in the context of the customer profile, nature of activities, and expected transaction behaviour;
  • Special attention shall be given to complex, unusually large, or high-risk transactions, including those that have no apparent economic or lawful purpose;
  • Identified unusual or suspicious transactions shall be subject to appropriate review, escalation, and reporting in accordance with applicable regulatory requirements.

The Company shall ensure that all wire transfer transactions, where applicable, are accompanied by accurate and meaningful originator and beneficiary information in accordance with applicable regulatory requirements.

10.2 Identification and Escalation of Suspicious Transactions
  • The Company shall identify and investigate transactions that appear unusual or suspicious in a timely manner;
  • Such transactions shall be promptly escalated to the designated compliance function and the Principal Officer for further review and appropriate action;
  • Where a transaction is determined to be suspicious, the Company shall ensure reporting to the Financial Intelligence Unit-India (FIU-IND) in accordance with applicable laws, rules, and regulatory guidelines;
  • All actions relating to identification, investigation, escalation, and reporting of suspicious transactions shall be appropriately documented and recorded.
10.3 Periodic Updation of KYC The Company shall periodically update customer KYC records based on the customer’s risk classification, or earlier where required, in accordance with the timelines prescribed by the Reserve Bank of India (RBI).

As a general guideline:

  • High-Risk Customers: At least once every 2 years;
  • Medium-Risk Customers: At least once every 8 years;
  • Low-Risk Customers: At least once every 10 years;
or such other periodicity as may be prescribed by the RBI or other applicable regulatory authorities.

The Company may undertake more frequent KYC updation based on transaction behaviour, risk perception, or material changes in the customer’s profile.

10.4 Ongoing Due Diligence
  • The Company shall ensure that customer information, including identity, address, beneficial ownership, and risk profile, is maintained as accurate, complete, and up to date through periodic and event-based reviews;
  • Any material change in the customer’s profile, ownership structure, or transaction behaviour shall trigger a review and, where required, reclassification of the customer’s risk category;
  • The Company shall maintain adequate records of monitoring activities, review outcomes, and actions taken for audit and regulatory purposes.

11
Reporting Requirements

The Company shall ensure timely, accurate, and complete reporting of prescribed transactions to the appropriate regulatory authorities in accordance with applicable laws, rules, and regulatory guidelines.

11.1 Reporting to Financial Intelligence Unit - India (FIU-IND) The Company shall report the following transactions to the Financial Intelligence Unit-India (FIU-IND) in accordance with applicable regulatory requirements and prescribed timelines:

• Suspicious Transaction Reports (STRs):
All attempted or executed transactions, whether or not made in cash, which give rise to reasonable grounds of suspicion of money laundering, terrorist financing, or other unlawful activities;

• Cash Transaction Reports (CTRs):
All cash transactions exceeding the prescribed threshold, including integrally connected transactions, as defined under applicable regulations;

• Non-Profit Organisation Transaction Reports (NTRs):
Transactions involving Non-Profit Organisations (NPOs), where applicable, in accordance with regulatory requirements;

• Cross Border Wire Transfer Reports (CBWTRs):
Cross-border wire transfer transactions, where applicable, in accordance with prescribed thresholds and regulatory requirements.

• Suspicious Transaction Reports (STRs) shall be filed with FIU-IND promptly and in any case not later than seven (7) days from the date of determination of suspicion.

All such reports shall be submitted within the timelines prescribed under applicable laws and regulatory guidelines.

11.2 Reporting Process and Responsibility

  • The Principal Officer shall be responsible for furnishing reports to FIU-IND and ensuring compliance with all reporting obligations;
  • All unusual or suspicious transactions identified through monitoring systems or internal controls shall be promptly escalated to the Principal Officer for review and appropriate action;
  • The Company shall maintain adequate documentation and audit trails in respect of all identified and reported transactions;
  • The Principal Officer shall act as the nodal point for interaction with FIU-IND in relation to KYC/AML reporting and compliance matters.
11.3 Confidentiality and Non-Tipping Off
  • The Company shall maintain strict confidentiality in respect of STRs and related information;
  • No employee, officer, or representative shall disclose (“tip off”) the customer or any unauthorised person regarding the reporting of suspicious transactions or related actions.

12
Record Keeping

The Company shall maintain proper records of customer identification, account files, business correspondence, and transactions in accordance with applicable laws, rules, and regulatory requirements.

12.1 Maintenance of Records

  • The Company shall maintain records of all transactions, including attempted transactions, whether domestic or international, for a minimum period of five (5) years from the date of transaction;
  • The Company shall ensure that transaction records are sufficient to permit reconstruction of individual transactions so as to provide, if necessary, evidence for investigation or prosecution of criminal activity.
12.2 Preservation of KYC Documents
  • The Company shall preserve all customer identification records and KYC documents for at least five (5) years after the end of the business relationship with the customer;
  • Records relating to beneficial ownership, customer due diligence, and account files shall also be maintained in accordance with applicable regulatory requirements.
12.3 Security and Accessibility
  • All records shall be maintained in a secure manner with appropriate safeguards to ensure confidentiality, integrity, and protection against unauthorised access, alteration, or misuse;
  • The Company shall ensure that records are readily retrievable and made available without delay to regulatory authorities, auditors, and law enforcement agencies, as required under applicable laws and regulatory guidelines.

13
Appointment of Officials

The Company shall designate key officials to ensure effective implementation of the KYC/AML compliance framework in accordance with applicable laws, rules, and regulatory requirements.

13.1 Designated Director

  • The Company shall appoint a Designated Director, in accordance with the provisions of the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, to ensure overall compliance with KYC/AML obligations;
  • The Designated Director shall be responsible for overseeing the Company’s compliance with the provisions of the Prevention of Money Laundering Act, 2002, the rules framed thereunder, and the RBI Master Direction - Know Your Customer (KYC) Direction, 2016, as amended from time to time;
  • The Designated Director shall ensure that appropriate policies, procedures, and internal controls are in place and effectively implemented.
13.2 Principal Officer
  • The Company shall appoint a Principal Officer responsible for monitoring compliance with KYC/AML requirements and for reporting prescribed transactions to the Financial Intelligence Unit–India (FIU-IND);
  • The Principal Officer shall act as the central point of contact for all KYC/AML-related matters, including coordination with regulatory authorities and law enforcement agencies;
  • The Principal Officer shall ensure timely identification, escalation, and reporting of suspicious transactions and other prescribed reports;
  • The Principal Officer shall maintain records of all reported transactions and ensure proper documentation and audit trails;
  • The Principal Officer shall report to senior management and/or the Board, as appropriate, on KYC/AML compliance matters.
13.3 Reporting Line and Independence
  • The Principal Officer shall have adequate authority, independence, and unrestricted access to senior management and relevant information to effectively discharge responsibilities;
  • The Company shall ensure that there is no conflict of interest in the discharge of duties of the Designated Director and the Principal Officer.
The appointment and functioning of these officials shall be in compliance with applicable laws, rules, and regulatory guidelines.

14
Employee Training

The Company shall establish and implement an ongoing employee training program to ensure effective compliance with KYC/AML requirements and to enhance awareness of risks associated with money laundering and terrorist financing.

14.1 Training Framework

  • The Company shall conduct regular and periodic KYC/AML training programs for relevant employees, including new hires and existing staff;
  • Training programs shall be tailored based on roles and responsibilities, particularly for employees involved in customer onboarding, transaction monitoring, and compliance functions.
14.2 Awareness and Capacity Building
  • Employees shall be trained to understand applicable regulatory requirements, internal policies, and procedures relating to KYC/AML;
  • Training shall include identification of suspicious transactions, red flag indicators, and reporting obligations;
  • The Company shall ensure that employees are aware of their responsibilities in preventing money laundering and terrorist financing activities.
14.3 Updates and Continuous Learning
  • The Company shall provide periodic updates to employees on changes in applicable laws, regulatory guidelines, and internal policies;
  • Refresher training sessions shall be conducted at defined intervals to reinforce knowledge and ensure continued compliance.
14.4 Record of Training
  • The Company shall maintain adequate records of training programs conducted, including details of content, attendance, frequency, and mode of delivery, for audit and regulatory purposes;
  • Training records shall be retained in accordance with the Company’s record retention requirements.

15
Internal Control and Audit

The Company shall establish an internal control and audit framework to ensure effective implementation and ongoing compliance with KYC/AML requirements.

15.1 Internal Control Framework

  • The Company shall implement adequate internal controls, policies, and procedures to ensure compliance with KYC/AML regulations and to mitigate risks associated with money laundering and terrorist financing;
  • Such controls shall include segregation of duties, maker-checker mechanisms, and system-based controls for customer onboarding, due diligence, and transaction monitoring.
15.2 Internal Audit
  • The Company shall conduct periodic internal audits, on a risk-based frequency, to assess the adequacy and effectiveness of its KYC/AML framework;
  • The audit function shall be independent and shall evaluate compliance with applicable laws, internal policies, and regulatory guidelines;
  • The scope of audit shall include customer onboarding, due diligence processes, risk categorisation, transaction monitoring, reporting mechanisms, and record-keeping practices.
15.3 Reporting and Escalation
  • Audit findings, observations, and deficiencies shall be documented and reported to senior management and/or the Board of Directors, as appropriate;
  • The Company shall establish a mechanism to track audit observations and ensure timely rectification and closure of identified deficiencies.
15.4 Ongoing Review
  • The Company shall periodically review its KYC/AML systems, controls, and procedures to ensure their effectiveness and alignment with applicable regulatory requirements;
  • Necessary updates and improvements shall be made based on audit findings, regulatory changes, and internal risk assessments.

16
Technology and Data Security

The Company shall implement appropriate technology and information security measures to safeguard customer data and ensure secure execution of KYC processes, including digital onboarding.

16.1 Data Security and Confidentiality

  • All KYC records and customer data shall be securely stored with access restricted on a need-to-know and role-based basis;
  • The Company shall ensure confidentiality, integrity, and availability of customer information through appropriate technical and organisational safeguards;
  • Access to customer data shall be subject to proper authorization, authentication, and monitoring controls.
16.2 System Controls and Audit Trails
  • The Company shall implement system-based controls to ensure accuracy, completeness, and reliability of KYC data;
  • All KYC-related activities, including data capture, modification, and verification, shall be logged and maintained through audit trails;
  • Systems shall be capable of detecting and preventing unauthorized access, data alteration, or misuse.
16.3 Cybersecurity Measures
  • The Company shall implement cybersecurity controls, including encryption, secure data transmission, firewalls, and intrusion detection/prevention systems;
  • Regular vulnerability assessments, penetration testing, and system audits shall be conducted to identify and mitigate risks.
16.4 Digital KYC and V-CIP Controls
  • Digital KYC processes, including Aadhaar-based e-KYC and Video-based Customer Identification Process (V-CIP), shall be conducted in compliance with applicable regulatory requirements;
  • The Company shall ensure secure capture, transmission, and storage of customer data, consent, and video recordings obtained through digital channels;
  • Adequate safeguards shall be implemented to prevent identity fraud, impersonation, and misuse of digital onboarding systems.
16.5 Digital KYC Risk Management The Company shall implement enhanced controls for digital onboarding and non-face-to-face customer identification, including:

  • Use of secure and tamper-resistant systems for capturing customer data, documents, and live images or videos;
  • Implementation of geo-tagging, time-stamping, and device/IP tracking mechanisms, wherever feasible;
  • Deployment of liveness detection and face-matching technologies to mitigate impersonation risks;
  • Monitoring for multiple accounts linked to common identifiers such as device, mobile number, or IP address;
  • Real-time alerts and escalation mechanisms for suspicious onboarding activities;
  • Periodic review and audit of digital KYC systems to ensure compliance and effectiveness.
16.6 Data Retention and Protection
  • Customer data shall be retained and protected in accordance with applicable regulatory requirements and internal data protection policies;
  • The Company shall ensure protection of data against unauthorized access, disclosure, alteration, or loss.

17
Policy Review

This Policy shall be subject to periodic review to ensure its continued relevance, effectiveness, and alignment with applicable laws, regulatory requirements, and the Company’s risk framework.

17.1 Approval

  • This Policy shall be approved by the Board of Directors of the Company;
  • Any amendments or modifications to this Policy shall be subject to approval by the Board.
17.2 Periodic Review
  • The Policy shall be reviewed at least annually, or more frequently as required;
  • The review shall be undertaken by the Compliance Function in coordination with relevant departments and shall be placed before senior management and the Board.
17.3 Trigger-Based Review The Policy shall be reviewed and updated as required upon occurrence of events including:

  • Changes in applicable laws, regulations, or regulatory guidelines, including updates to the RBI Master Direction – Know Your Customer (KYC) Direction, 2016;
  • Amendments to the Prevention of Money Laundering Act, 2002 or the rules framed thereunder;
  • Observations arising from internal or external audits, regulatory inspections, or compliance reviews;
  • Changes in the Company’s business model, products, operations, or risk profile.
17.4 Documentation and Version Control
  • All revisions to this Policy shall be appropriately documented, version-controlled, and communicated to relevant stakeholders;
  • The Company shall maintain records of Policy approvals, amendments, and review history for audit and regulatory purposes.
This Policy shall remain in force until amended or superseded by a revised version approved by the Board of Directors.

18
Customer Communication

The Company shall ensure clear, transparent, and timely communication with customers regarding KYC requirements, documentation, and obligations, in accordance with applicable regulatory requirements.

18.1 Disclosure of KYC Requirements

  • Customers shall be informed, at the time of onboarding, of applicable KYC requirements, including documentation and information required for establishing identity and address;
  • The Company shall clearly communicate the purpose of collecting such information and the regulatory requirements governing the same, in a clear and understandable manner.
18.2 Documentation and Consent
  • Customers shall be informed of the documents and information required for KYC and ongoing due diligence;
  • In case of digital KYC processes, including Aadhaar-based e-KYC and Video-based Customer Identification Process (V-CIP), explicit customer consent shall be obtained and recorded in accordance with applicable laws and regulatory guidelines.
18.3 Periodic Updation and Ongoing Communication
  • Customers shall be informed of their obligation to periodically update KYC information and provide necessary documents as required;
  • The Company shall communicate KYC updation requirements through appropriate channels, including digital and electronic modes.
18.4 Communication Channels
    <i>The Company may communicate KYC-related information through its website, mobile applications, email, SMS, or other appropriate channels;
  • All communications shall be clear, accurate, and accessible to customers.
18.5 Confidentiality and Data Protection The Company shall ensure that all customer information collected for KYC purposes is handled with strict confidentiality and in accordance with applicable data protection and regulatory requirements.

The Company shall make the KYC/AML Policy or key aspects thereof available on its website.