CYBERVED AI PRIVATE LIMITED
ANTI-MONEY LAUNDERING (AML) /
COUNTERING THE FINANCING OF TERRORISM (CFT) POLICY
DOCUMENT CONTROL
| Company | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Regulatory Model | AML/CFT responsibilities shall be applied according to applicable law, the Company's role and the contractual operating model with authorised / regulated partners. |
| Policy Owner | Compliance / Risk / Management |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes the framework for identifying, assessing, preventing, detecting and escalating money-laundering, terrorist-financing and related financial-crime risks arising from CYBERVED AI PRIVATE LIMITED's gift-card, voucher and related activities.
2. OBJECTIVES
- Maintain risk-based AML/CFT controls appropriate to the Company's role.
- Support prevention of misuse of gift-card/voucher products for illicit purposes.
- Coordinate with authorised PPI, banking and other regulated partners.
- Identify and escalate suspicious or unusual activity.
- Maintain appropriate records, confidentiality and audit trails.
- Provide clear accountability and escalation mechanisms.
3. SCOPE
This Policy applies to applicable customer, order, transaction, voucher, refund, redemption, partner and operational activities conducted by or for CYBERVED AI PRIVATE LIMITED, subject to the Company's legal and contractual role.
4. REGULATORY & PARTNER MODEL
Where statutory AML/CFT obligations are assigned to an authorised PPI issuer, bank or other regulated partner, that entity remains responsible for functions allocated to it by law or agreement. CYBERVED AI PRIVATE LIMITED shall cooperate within its lawful and contractual scope and shall not represent itself as a regulated entity unless authorised.
5. AML/CFT RISK ASSESSMENT
The Company shall consider risks arising from products, customers, transactions, distribution channels, geography, partners, technology and other relevant factors. Controls shall be proportionate to the assessed risk.
6. CUSTOMER DUE DILIGENCE
Where KYC/CDD is required, customer identification and verification shall be performed by the responsible party in accordance with the KYC & Customer Due Diligence Policy and applicable partner procedures.
7. ENHANCED DUE DILIGENCE
Higher-risk circumstances may require additional information, review, transaction restrictions or partner escalation, as appropriate to the Company's role and applicable requirements.
8. TRANSACTION MONITORING
- Unusual purchase or redemption patterns
- Repeated transactions inconsistent with expected use
- High-frequency or rapid activity
- Multiple accounts or identifiers showing suspicious linkage
- Repeated refund/cancellation activity
- Potential voucher/code abuse
- Activity identified through partner monitoring
9. FRAUD & AML COORDINATION
AML/CFT controls shall operate together with fraud-prevention and transaction-monitoring controls. Suspicious activity may be escalated for combined risk assessment.
10. SANCTIONS / PROHIBITED PERSON CONTROLS
Where applicable to the Company's role, relevant sanctions or prohibited-party screening shall be performed by the responsible regulated partner or through an approved process. Potential matches shall be escalated and handled according to applicable requirements.
11. SUSPICIOUS ACTIVITY ESCALATION
- Identify an unusual or potentially suspicious activity.
- Record relevant transaction/customer/partner references.
- Escalate to the designated Compliance/Risk function.
- Assess the matter and determine appropriate action.
- Coordinate with the regulated partner where required.
- Preserve relevant evidence and records.
12. TRANSACTION RESTRICTION
Where permitted and appropriate, the Company may temporarily restrict, hold, block or decline activity in accordance with product terms, partner procedures, risk controls and applicable law.
13. NO CUSTOMER ALERT / CONFIDENTIALITY
Information concerning internal investigations, suspicious activity reviews or partner/regulatory escalations shall be handled confidentially and disclosed only to authorised persons, subject to applicable legal requirements.
14. RECORD KEEPING
- Customer due-diligence records where applicable
- Transaction and voucher activity records
- Risk assessments
- Monitoring alerts
- Investigation and escalation records
- Partner communications
- Decision and approval records
- Relevant regulatory reporting evidence where applicable
15. DATA PROTECTION
AML/CFT records shall be protected through appropriate confidentiality, access control, retention and secure-disposal measures in accordance with the Data Protection, Privacy & Retention Policy.
16. PARTNER COORDINATION
Material AML/CFT alerts or cases involving PPI issuers, banks, payment processors or other regulated partners shall be escalated through agreed channels and documented.
17. CUSTOMER & TRANSACTION RISK INDICATORS
- Unusual transaction velocity
- Unexpected purchase/redemption behaviour
- Patterns suggesting account or voucher sharing
- Repeated failed verification
- Multiple linked transactions or accounts
- Abnormal refund/reversal behaviour
- Information inconsistent with the stated use of the product
18. EMPLOYEE ESCALATION
Employees and relevant contractors shall promptly report suspected AML/CFT or financial-crime concerns through the designated internal escalation channel. Employees shall not independently investigate beyond their authority.
19. TRAINING & AWARENESS
Relevant personnel shall receive role-appropriate awareness on AML/CFT risks, suspicious activity indicators, escalation procedures, confidentiality and record keeping.
20. THIRD-PARTY CONTROLS
Material vendors or partners supporting customer, payment, voucher or transaction processes shall be subject to appropriate risk-based due diligence and contractual controls.
21. MANAGEMENT INFORMATION
Compliance/Risk may provide management with periodic information on material alerts, trends, investigations, fraud patterns, partner issues and control effectiveness, subject to confidentiality.
22. AUDIT & TESTING
The effectiveness of AML/CFT controls may be assessed through periodic reviews, sample testing, monitoring of alerts, reconciliation checks, partner reviews and internal or external assurance activities.
23. REGULATORY COOPERATION
The Company shall cooperate with authorised regulators, law-enforcement agencies and regulated partners where legally required and within the Company's role, subject to appropriate legal and confidentiality controls.
24. INCIDENT & CYBER COORDINATION
Where AML/CFT concerns involve cyber compromise, credential theft, voucher fraud or technology abuse, the matter shall also be handled under the Cyber Incident Response & Cyber Fraud Policy.
25. BUSINESS CONTINUITY
Critical AML/CFT monitoring, records and escalation processes shall be included in appropriate continuity and recovery arrangements.
26. NON-COMPLIANCE
Material control failures, missed escalations, unauthorised disclosures or other AML/CFT breaches shall be investigated and corrective action shall be taken.
27. EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by authorised management. Applicable law, regulatory obligations and binding partner requirements shall not be bypassed.
28. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Compliance | AML/CFT framework, regulatory assessment and oversight | Compliance Head |
| Risk/Fraud | Monitoring, alerts, investigations and escalation | Risk/Fraud Head |
| Operations | Transaction/customer process controls | Operations Head |
| Partner Management | Coordination with PPI/bank/regulated partners | Management |
| Technology / IT | Monitoring systems, data integrity and security | Technology Head |
| Customer Support | Escalation of suspicious customer activity | Operations / Compliance |
| Management | Material risk decisions and approvals | Director / Authorised Management |
29. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in products, partner arrangements, customer journey, technology, regulatory requirements or risk profile.
30. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Risk / Operations | |
| Reviewed By | Legal / Management | |
| Approved By | Director / Authorised Signatory |