e-suvidha

CYBERVED AI PRIVATE LIMITED

ANTI-MONEY LAUNDERING (AML) /
COUNTERING THE FINANCING OF TERRORISM (CFT) POLICY

POLICY NO. 04VERSION 1.0EFFECTIVE DATE: 29 SEPTEMBER 2026

DOCUMENT CONTROL

CompanyDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Regulatory ModelAML/CFT responsibilities shall be applied according to applicable law, the Company's role and the contractual operating model with authorised / regulated partners.
Policy OwnerCompliance / Risk / Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes the framework for identifying, assessing, preventing, detecting and escalating money-laundering, terrorist-financing and related financial-crime risks arising from CYBERVED AI PRIVATE LIMITED's gift-card, voucher and related activities.

2. OBJECTIVES

  • Maintain risk-based AML/CFT controls appropriate to the Company's role.
  • Support prevention of misuse of gift-card/voucher products for illicit purposes.
  • Coordinate with authorised PPI, banking and other regulated partners.
  • Identify and escalate suspicious or unusual activity.
  • Maintain appropriate records, confidentiality and audit trails.
  • Provide clear accountability and escalation mechanisms.

3. SCOPE

This Policy applies to applicable customer, order, transaction, voucher, refund, redemption, partner and operational activities conducted by or for CYBERVED AI PRIVATE LIMITED, subject to the Company's legal and contractual role.

4. REGULATORY & PARTNER MODEL

Where statutory AML/CFT obligations are assigned to an authorised PPI issuer, bank or other regulated partner, that entity remains responsible for functions allocated to it by law or agreement. CYBERVED AI PRIVATE LIMITED shall cooperate within its lawful and contractual scope and shall not represent itself as a regulated entity unless authorised.

5. AML/CFT RISK ASSESSMENT

The Company shall consider risks arising from products, customers, transactions, distribution channels, geography, partners, technology and other relevant factors. Controls shall be proportionate to the assessed risk.

6. CUSTOMER DUE DILIGENCE

Where KYC/CDD is required, customer identification and verification shall be performed by the responsible party in accordance with the KYC & Customer Due Diligence Policy and applicable partner procedures.

7. ENHANCED DUE DILIGENCE

Higher-risk circumstances may require additional information, review, transaction restrictions or partner escalation, as appropriate to the Company's role and applicable requirements.

8. TRANSACTION MONITORING

  • Unusual purchase or redemption patterns
  • Repeated transactions inconsistent with expected use
  • High-frequency or rapid activity
  • Multiple accounts or identifiers showing suspicious linkage
  • Repeated refund/cancellation activity
  • Potential voucher/code abuse
  • Activity identified through partner monitoring

9. FRAUD & AML COORDINATION

AML/CFT controls shall operate together with fraud-prevention and transaction-monitoring controls. Suspicious activity may be escalated for combined risk assessment.

10. SANCTIONS / PROHIBITED PERSON CONTROLS

Where applicable to the Company's role, relevant sanctions or prohibited-party screening shall be performed by the responsible regulated partner or through an approved process. Potential matches shall be escalated and handled according to applicable requirements.

11. SUSPICIOUS ACTIVITY ESCALATION

  1. Identify an unusual or potentially suspicious activity.
  2. Record relevant transaction/customer/partner references.
  3. Escalate to the designated Compliance/Risk function.
  4. Assess the matter and determine appropriate action.
  5. Coordinate with the regulated partner where required.
  6. Preserve relevant evidence and records.

12. TRANSACTION RESTRICTION

Where permitted and appropriate, the Company may temporarily restrict, hold, block or decline activity in accordance with product terms, partner procedures, risk controls and applicable law.

13. NO CUSTOMER ALERT / CONFIDENTIALITY

Information concerning internal investigations, suspicious activity reviews or partner/regulatory escalations shall be handled confidentially and disclosed only to authorised persons, subject to applicable legal requirements.

14. RECORD KEEPING

  • Customer due-diligence records where applicable
  • Transaction and voucher activity records
  • Risk assessments
  • Monitoring alerts
  • Investigation and escalation records
  • Partner communications
  • Decision and approval records
  • Relevant regulatory reporting evidence where applicable

15. DATA PROTECTION

AML/CFT records shall be protected through appropriate confidentiality, access control, retention and secure-disposal measures in accordance with the Data Protection, Privacy & Retention Policy.

16. PARTNER COORDINATION

Material AML/CFT alerts or cases involving PPI issuers, banks, payment processors or other regulated partners shall be escalated through agreed channels and documented.

17. CUSTOMER & TRANSACTION RISK INDICATORS

  • Unusual transaction velocity
  • Unexpected purchase/redemption behaviour
  • Patterns suggesting account or voucher sharing
  • Repeated failed verification
  • Multiple linked transactions or accounts
  • Abnormal refund/reversal behaviour
  • Information inconsistent with the stated use of the product

18. EMPLOYEE ESCALATION

Employees and relevant contractors shall promptly report suspected AML/CFT or financial-crime concerns through the designated internal escalation channel. Employees shall not independently investigate beyond their authority.

19. TRAINING & AWARENESS

Relevant personnel shall receive role-appropriate awareness on AML/CFT risks, suspicious activity indicators, escalation procedures, confidentiality and record keeping.

20. THIRD-PARTY CONTROLS

Material vendors or partners supporting customer, payment, voucher or transaction processes shall be subject to appropriate risk-based due diligence and contractual controls.

21. MANAGEMENT INFORMATION

Compliance/Risk may provide management with periodic information on material alerts, trends, investigations, fraud patterns, partner issues and control effectiveness, subject to confidentiality.

22. AUDIT & TESTING

The effectiveness of AML/CFT controls may be assessed through periodic reviews, sample testing, monitoring of alerts, reconciliation checks, partner reviews and internal or external assurance activities.

23. REGULATORY COOPERATION

The Company shall cooperate with authorised regulators, law-enforcement agencies and regulated partners where legally required and within the Company's role, subject to appropriate legal and confidentiality controls.

24. INCIDENT & CYBER COORDINATION

Where AML/CFT concerns involve cyber compromise, credential theft, voucher fraud or technology abuse, the matter shall also be handled under the Cyber Incident Response & Cyber Fraud Policy.

25. BUSINESS CONTINUITY

Critical AML/CFT monitoring, records and escalation processes shall be included in appropriate continuity and recovery arrangements.

26. NON-COMPLIANCE

Material control failures, missed escalations, unauthorised disclosures or other AML/CFT breaches shall be investigated and corrective action shall be taken.

27. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by authorised management. Applicable law, regulatory obligations and binding partner requirements shall not be bypassed.

28. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ComplianceAML/CFT framework, regulatory assessment and oversightCompliance Head
Risk/FraudMonitoring, alerts, investigations and escalationRisk/Fraud Head
OperationsTransaction/customer process controlsOperations Head
Partner ManagementCoordination with PPI/bank/regulated partnersManagement
Technology / ITMonitoring systems, data integrity and securityTechnology Head
Customer SupportEscalation of suspicious customer activityOperations / Compliance
ManagementMaterial risk decisions and approvalsDirector / Authorised Management

29. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in products, partner arrangements, customer journey, technology, regulatory requirements or risk profile.

30. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Risk / Operations
Reviewed ByLegal / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

This document is confidential and intended for authorised use only.