CYBERVED AI PRIVATE LIMITED
FRAUD PREVENTION & TRANSACTION
MONITORING POLICY
DOCUMENT CONTROL
| Company | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Regulatory Model | Fraud and transaction-monitoring controls shall be applied according to the Company's role, product structure, applicable requirements and the operating model with authorised / regulated partners. |
| Policy Owner | Risk / Fraud / Compliance / Operations |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Risk & Fraud Document |
1. PURPOSE
This Policy establishes the framework for preventing, detecting, investigating and responding to fraud and unusual transaction activity associated with CYBERVED AI PRIVATE LIMITED's gift-card, voucher and related digital business.
2. OBJECTIVES
- Reduce fraud losses and customer impact.
- Detect unusual or suspicious activity promptly.
- Protect voucher value, customer accounts and transaction systems.
- Support coordination with authorised PPI, bank and other partners.
- Maintain documented investigations, decisions and evidence.
- Continuously improve fraud controls based on incidents and trends.
3. SCOPE
This Policy applies to relevant customer, order, payment, voucher issuance, activation, redemption, refund, cancellation, support, partner and system activities.
4. FRAUD RISK GOVERNANCE
Fraud risk shall be assessed based on product, transaction, customer, channel, technology, partner and operational characteristics. Controls shall be proportionate to identified risk.
5. FRAUD TYPOLOGIES
- Stolen or compromised payment credentials
- Voucher/code theft or unauthorised use
- Duplicate or repeated redemption
- Account takeover or identity misuse
- Automated or scripted abuse
- Refund/cancellation abuse
- Transaction manipulation
- Social engineering or support-channel abuse
- Collusion or misuse involving internal/third-party access
6. PRE-TRANSACTION CONTROLS
- Input and customer validation where applicable
- Velocity and frequency controls
- Product/denomination restrictions
- Risk-based transaction screening
- Device/session signals where available
- Partner-side controls where operated by the authorised partner
7. TRANSACTION MONITORING
Relevant transaction and voucher activity shall be monitored through appropriate rules, alerts, partner controls, manual review or other risk mechanisms. Monitoring may include purchase, issuance, activation, redemption, refund and cancellation activity.
8. RISK INDICATORS
- Unusual transaction velocity
- Multiple transactions within a short period
- Repeated failed or reversed transactions
- Multiple accounts or identifiers showing suspicious linkage
- Rapid purchase and redemption patterns
- Unusual refund behaviour
- Repeated customer-support requests involving voucher credentials
- Activity inconsistent with normal product use
9. FRAUD RULES & ALERTS
Fraud rules and alerts shall be documented where appropriate. Thresholds may be adjusted based on observed fraud patterns, false-positive rates, product changes and partner requirements.
10. ALERT REVIEW
- Review the alert and relevant transaction information.
- Assess customer/order/voucher history where available and lawful.
- Determine whether additional verification is appropriate.
- Take an authorised action such as allow, hold, restrict, block or escalate.
- Document the decision and supporting evidence.
11. TRANSACTION HOLDS / BLOCKS
Where permitted by product terms, partner procedures and applicable law, suspicious activity may be held, blocked, cancelled or escalated for review.
12. CUSTOMER PROTECTION
Controls shall seek to minimise customer harm while managing fraud risk. Legitimate customers affected by controls shall be handled through appropriate verification, support and resolution procedures.
13. INVESTIGATION
Material fraud cases shall be investigated according to risk and available evidence. Investigations may include transaction history, voucher status, customer communications, system logs and partner information.
14. EVIDENCE PRESERVATION
- Transaction/order references
- Voucher identifiers and status information
- System and access logs where available
- Customer communications
- Partner communications
- Investigation notes and decisions
15. PARTNER COORDINATION
Where transaction processing, PPI services, payment processing or fraud controls are operated by a partner, relevant alerts and incidents shall be escalated through agreed channels.
16. AML / CFT COORDINATION
Potential financial-crime concerns shall also be assessed under the AML/CFT Policy and escalated to the responsible function or regulated partner where appropriate.
17. UNAUTHORISED TRANSACTIONS
Suspected unauthorised transactions shall be handled according to the Unauthorised Transaction Policy, including customer verification, investigation, partner coordination and resolution.
18. CUSTOMER SUPPORT CONTROLS
Support personnel shall not disclose sensitive voucher or account information without appropriate verification. High-risk requests shall be escalated.
19. EMPLOYEE & INSIDER FRAUD
Suspected employee or privileged-access misuse shall be escalated confidentially to authorised management, Compliance, Risk or Information Security as appropriate.
20. THIRD-PARTY FRAUD RISK
Material vendors and partners shall be assessed for fraud risks relevant to their services and shall have appropriate contractual, monitoring and incident-escalation requirements.
21. SYSTEM & API CONTROLS
Fraud monitoring systems and APIs shall be protected through access control, authentication, logging, secure configuration and appropriate change management.
22. FRAUD INCIDENT RESPONSE
Material fraud events shall be handled under the Cyber Incident Response & Cyber Fraud Policy where they involve cyber compromise, credential theft, system abuse or other security incidents.
23. REPORTING & METRICS
- Fraud alerts and confirmed cases
- Fraud loss/exposure where measurable
- False-positive trends
- Blocked/restricted transactions
- Refund/cancellation abuse
- Top fraud patterns
- Partner-related incidents
- Open investigations and ageing
24. MANAGEMENT REVIEW
Management shall receive appropriate information on material fraud trends, incidents, control gaps and remediation actions.
25. CONTROL TESTING
Fraud rules, monitoring processes and relevant controls may be tested periodically to assess effectiveness, detect gaps and reduce false positives.
26. TRAINING
Relevant personnel shall receive training on fraud indicators, customer protection, secure handling of information, escalation and incident procedures.
27. DATA PROTECTION
Fraud monitoring and investigation data shall be handled securely and retained according to applicable privacy, retention and legal requirements.
28. RECORD KEEPING
Fraud alerts, investigations, decisions, evidence, escalations and closure records shall be retained for the applicable period.
29. EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by authorised management. Fraud controls shall not be disabled without appropriate authority and risk assessment.
30. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Risk / Fraud | Fraud rules, monitoring, investigation and reporting | Risk/Fraud Head |
| Compliance | AML/regulatory coordination and oversight | Compliance Head |
| Operations | Transaction and customer process controls | Operations Head |
| Technology / IT | Monitoring systems, APIs and technical controls | Technology Head |
| Information Security | Cyber/fraud incident coordination | Security Head |
| Customer Support | Customer verification and suspicious-request escalation | Operations / Compliance |
| Partner Management | Partner fraud coordination | Management |
31. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in products, fraud trends, partner arrangements, technology, customer journey or applicable requirements.
32. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Risk / Fraud / Compliance / Operations | |
| Reviewed By | Legal / Management | |
| Approved By | Director / Authorised Signatory |