This Know Your Customer (KYC) and Anti-Money Laundering (AML) Policy (“Policy”) has been adopted by Samraat Finlease Private Limited (“the Company”) in accordance with the regulatory framework prescribed by the Reserve Bank of India (RBI), including the Master Direction – Know Your Customer (KYC) Direction, 2016, as amended from time to time.
This Policy is aligned with the provisions of the Prevention of Money Laundering Act, 2002(PMLA), the rules framed thereunder, and other applicable laws, regulations, and guidelines relating to Anti-Money Laundering (AML) and Combating Financing of Terrorism (CFT).
The Policy establishes a risk-based and technology-enabled framework for customer acceptance, identification, verification, due diligence, customer risk classification, ongoing monitoring, and regulatory reporting, with the objective of preventing and detecting money laundering, terrorist financing, and other unlawful activities.
This Policy shall be read in conjunction with other applicable internal policies of the Company, including the Digital Lending Policy, Information Security Policy, and Risk Management Policy, to ensure a consistent compliance framework across the Company’s operations.
This Policy is framed in accordance with and shall be governed by the applicable laws, regulations, and regulatory guidelines, including but not limited to:
The objectives of this Policy are to:
This Policy applies to all customer relationships, products, services, and transactions undertaken by the Company and covers the following:
For the purpose of this Policy, the following terms shall have the meanings assigned to them below:
The Company shall adopt a risk-based Customer Acceptance Policy to ensure that customers are onboarded only after appropriate identification, verification, and risk assessment. The following principles shall be adhered to:
The Company shall establish and implement Customer Identification Procedures (CIP) to verify the identity of customers at the time of onboarding and ensure compliance with applicable KYC requirements. Customer identification shall be undertaken using reliable, independent, and officially valid documents, data, or information.
7.1 Individuals
The Company shall obtain and verify the following documents and information for individual customers:
The Company shall undertake Customer Due Diligence (CDD) measures to identify and verify customers, understand the nature and purpose of the customer relationship, and assess associated risks. The extent and level of due diligence shall be determined based on the customer’s risk profile and in accordance with a risk-based approach.
8.1 Types of Due Diligence
• Simplified Due Diligence (SDD):
Applicable to customers assessed as low-risk, where the risk of money laundering or terrorist financing is considered low. Simplified measures may be applied in accordance with applicable regulatory requirements; however, basic customer identification and verification requirements shall continue to be complied with.
• Standard Due Diligence (CDD):
Applicable to customers assessed as normal-risk and includes obtaining and verifying customer identity, address details, and other relevant information, along with understanding the nature and purpose of the customer relationship.
• Enhanced Due Diligence (EDD):
Applicable to customers assessed as high-risk and involves additional verification, enhanced scrutiny, and monitoring measures to mitigate risks associated with such customers.
8.2 Enhanced Due Diligence (EDD)
Enhanced Due Diligence (EDD) shall be undertaken for customers identified as high-risk or where additional scrutiny is required based on the Company’s risk assessment. Such cases may include, but are not limited to:
The Company shall adopt a risk-based approach for categorising customers into appropriate risk levels to apply proportionate Customer Due Diligence (CDD), monitoring, and control measures.
9.1 Risk Categories
Customers shall be classified into the following risk categories based on factors including customer profile, nature of activities, transaction behaviour, geographic risk, and other relevant parameters:
The Company shall establish and maintain an effective framework for ongoing monitoring of customer relationships and transactions to ensure that activities are consistent with the customer’s profile, risk category, and source of funds.
10.1 Transaction Monitoring
The Company shall ensure timely, accurate, and complete reporting of prescribed transactions to the appropriate regulatory authorities in accordance with applicable laws, rules, and regulatory guidelines.
11.1 Reporting to Financial Intelligence Unit - India (FIU-IND)
The Company shall report the following transactions to the Financial Intelligence Unit-India (FIU-IND) in accordance with applicable regulatory requirements and prescribed timelines:
• Suspicious Transaction Reports (STRs):
All attempted or executed transactions, whether or not made in cash, which give rise to reasonable grounds of suspicion of money laundering, terrorist financing, or other unlawful activities;
• Cash Transaction Reports (CTRs):
All cash transactions exceeding the prescribed threshold, including integrally connected transactions, as defined under applicable regulations;
• Non-Profit Organisation Transaction Reports (NTRs):
Transactions involving Non-Profit Organisations (NPOs), where applicable, in accordance with regulatory requirements;
• Cross Border Wire Transfer Reports (CBWTRs):
Cross-border wire transfer transactions, where applicable, in accordance with prescribed thresholds and regulatory requirements.
• Suspicious Transaction Reports (STRs) shall be filed with FIU-IND promptly and in any case not later than seven (7) days from the date of determination of suspicion.
All such reports shall be submitted within the timelines prescribed under applicable laws and regulatory guidelines.
11.2 Reporting Process and Responsibility
The Company shall maintain proper records of customer identification, account files, business correspondence, and transactions in accordance with applicable laws, rules, and regulatory requirements.
12.1 Maintenance of Records
The Company shall designate key officials to ensure effective implementation of the KYC/AML compliance framework in accordance with applicable laws, rules, and regulatory requirements.
13.1 Designated Director
The Company shall establish and implement an ongoing employee training program to ensure effective compliance with KYC/AML requirements and to enhance awareness of risks associated with money laundering and terrorist financing.
14.1 Training Framework
The Company shall establish an internal control and audit framework to ensure effective implementation and ongoing compliance with KYC/AML requirements.
15.1 Internal Control Framework
The Company shall implement appropriate technology and information security measures to safeguard customer data and ensure secure execution of KYC processes, including digital onboarding.
16.1 Data Security and Confidentiality
This Policy shall be subject to periodic review to ensure its continued relevance, effectiveness, and alignment with applicable laws, regulatory requirements, and the Company’s risk framework.
17.1 Approval
The Company shall ensure clear, transparent, and timely communication with customers regarding KYC requirements, documentation, and obligations, in accordance with applicable regulatory requirements.
18.1 Disclosure of KYC Requirements