e-suvidha
Compliance & Governance

CYBERVED AI

PRIVATE LIMITED

Master Policy & Compliance Framework

Gift Card / Gift Voucher & PPI Partner Business

Consolidated governance, compliance, risk, security, operational and customer-protection framework governing CYBERVED AI PRIVATE LIMITED's gift-card, gift-voucher and related digital-services business.

18

Policies

01

Framework

2026

Effective Year

01

Master Policy Principles

1

Customer protection and fair treatment

2

Lawful and risk-based operations

3

KYC / AML / CFT and fraud-risk controls where applicable

4

Information security and cyber resilience

5

Data protection and confidentiality

6

Transparent payment, settlement and reconciliation controls

7

Third-party and partner oversight

8

Regulatory cooperation and accurate record keeping

9

Business continuity and disaster recovery

10

Documented accountability, approvals and audit trails

CYBERVED AI Framework

18 Policy Framework

Explore the policies forming the CYBERVED AI compliance, governance, security, customer-protection and operational control framework.

01
Policy 01

PPI & Gift Card Regulatory Compliance Policy

Defines regulatory governance for the partner-led PPI / gift-card model, product responsibilities, compliance mapping and partner obligations.

Compliance & Governance
View Policy↗
02
Policy 02

PPI Issuer / Bank Partner Management Policy

Governs onboarding, due diligence, contractual responsibilities, operational coordination, escalation and monitoring of authorised PPI / bank partners.

Compliance & Governance
View Policy↗
03
Policy 03

KYC & Customer Due Diligence Policy

Provides customer identification, verification, risk-based due diligence, record and escalation controls where applicable to the Company's role and partner process.

Compliance & Governance
View Policy↗
04
Policy 04

AML / CFT Policy

Provides the framework for AML/CFT risk management, monitoring, escalation, sanctions-related controls and cooperation with relevant regulated partners where applicable.

Compliance & Governance
View Policy↗
05
Policy 05

Fraud Prevention & Transaction Monitoring Policy

Covers fraud-risk assessment, transaction monitoring, suspicious patterns, rule management, escalation, blocking/review and fraud reporting.

Compliance & Governance
View Policy↗
06
Policy 06

Gift Card Issuance & Product Governance Policy

Controls product approval, issuance, activation, lifecycle, limits, reconciliation, partner dependencies, customer protection and product changes.

Compliance & Governance
View Policy↗
07
Policy 07

Gift Card / Voucher Terms & Conditions

Sets the customer-facing contractual framework for purchase, use, validity, redemption, restrictions, liability, refunds and other applicable terms.

Compliance & Governance
View Policy↗
08
Policy 08

Refund, Cancellation & Chargeback Policy

Governs refund, cancellation, reversal, chargeback, dispute handling, evidence, approvals, settlement impact and customer communication.

Compliance & Governance
View Policy↗
09
Policy 09

Customer Grievance Redressal Policy

Defines complaint intake, acknowledgement, investigation, escalation, resolution, records, turnaround management and management reporting.

Compliance & Governance
View Policy↗
10
Policy 10

Unauthorised Transaction Policy

Provides controls for suspected unauthorised transactions, customer reporting, verification, investigation, partner coordination, refunds/reversals where applicable and closure.

Compliance & Governance
View Policy↗
11
Policy 11

Payment, Settlement & Reconciliation Policy

Controls payment processing, settlement, daily/periodic reconciliation, unmatched transactions, refunds, fees, holds, adjustments and financial controls.

Compliance & Governance
View Policy↗
12
Policy 12

Information Security & Cyber Security Policy

Establishes security governance covering systems, data, access, applications, APIs, endpoints, monitoring, vulnerabilities and security awareness.

Compliance & Governance
View Policy↗
13
Policy 13

Cyber Incident Response & Cyber Fraud Policy

Defines incident detection, classification, containment, investigation, evidence preservation, cyber-fraud response, partner/authority escalation and recovery.

Compliance & Governance
View Policy↗
14
Policy 14

Data Protection, Privacy & Retention Policy

Controls personal/confidential data collection, use, sharing, access, security, retention, disposal, privacy requests and breach handling.

Compliance & Governance
View Policy↗
15
Policy 15

Third-Party / Vendor Risk Management Policy

Governs vendor due diligence, risk classification, contracts, security/privacy requirements, monitoring, incidents, continuity and exit.

Compliance & Governance
View Policy↗
16
Policy 16

Access Control & API Security Policy

Controls user access, privileged access, authentication, service accounts, API authentication/authorisation, secrets, logging, rate limits and API testing.

Compliance & Governance
View Policy↗
17
Policy 17

Business Continuity & Disaster Recovery Policy

Provides continuity and recovery arrangements for critical processes, technology, partners, backups, cyber incidents, testing and emergency communication.

Compliance & Governance
View Policy↗
18
Policy 18

Regulatory Reporting & Record-Keeping Policy

Governs regulatory/partner reporting, source-data validation, approvals, submission evidence, retention, legal holds, audits and secure disposal.

Compliance & Governance
View Policy↗
02

Document Control & Approval

Company

CYBERVED AI PRIVATE LIMITED

CIN

U62090UP2024PTC201257

Version

Version 1.0

Effective Date

29 September 2026

Registered Office

Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028

Website / Business Platform

e-suvidha.com

Policy Owner

Board / Management / Compliance

Review Frequency

At least annually and upon material regulatory, business or technology change

Classification

Confidential – Master Compliance Policy

PPI Position

The Company does not itself operate as a PPI issuer under this framework; regulated PPI activities are undertaken through applicable authorised partners, subject to contracts and law.

Approval

Prepared By

Compliance / Operations

Reviewed By

Risk / Information Security / Legal

Approved By

Director / Authorised Signatory

CONFIDENTIAL – MASTER COMPLIANCE POLICY FRAMEWORK