e-suvidha

CYBERVED AI PRIVATE LIMITED

FRAUD PREVENTION & TRANSACTION
MONITORING POLICY

POLICY NO. 05VERSION 1.0EFFECTIVE DATE: 29 SEPTEMBER 2026

DOCUMENT CONTROL

CompanyDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Regulatory ModelFraud and transaction-monitoring controls shall be applied according to the Company's role, product structure, applicable requirements and the operating model with authorised / regulated partners.
Policy OwnerRisk / Fraud / Compliance / Operations
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Risk & Fraud Document

1. PURPOSE

This Policy establishes the framework for preventing, detecting, investigating and responding to fraud and unusual transaction activity associated with CYBERVED AI PRIVATE LIMITED's gift-card, voucher and related digital business.

2. OBJECTIVES

  • Reduce fraud losses and customer impact.
  • Detect unusual or suspicious activity promptly.
  • Protect voucher value, customer accounts and transaction systems.
  • Support coordination with authorised PPI, bank and other partners.
  • Maintain documented investigations, decisions and evidence.
  • Continuously improve fraud controls based on incidents and trends.

3. SCOPE

This Policy applies to relevant customer, order, payment, voucher issuance, activation, redemption, refund, cancellation, support, partner and system activities.

4. FRAUD RISK GOVERNANCE

Fraud risk shall be assessed based on product, transaction, customer, channel, technology, partner and operational characteristics. Controls shall be proportionate to identified risk.

5. FRAUD TYPOLOGIES

  • Stolen or compromised payment credentials
  • Voucher/code theft or unauthorised use
  • Duplicate or repeated redemption
  • Account takeover or identity misuse
  • Automated or scripted abuse
  • Refund/cancellation abuse
  • Transaction manipulation
  • Social engineering or support-channel abuse
  • Collusion or misuse involving internal/third-party access

6. PRE-TRANSACTION CONTROLS

  • Input and customer validation where applicable
  • Velocity and frequency controls
  • Product/denomination restrictions
  • Risk-based transaction screening
  • Device/session signals where available
  • Partner-side controls where operated by the authorised partner

7. TRANSACTION MONITORING

Relevant transaction and voucher activity shall be monitored through appropriate rules, alerts, partner controls, manual review or other risk mechanisms. Monitoring may include purchase, issuance, activation, redemption, refund and cancellation activity.

8. RISK INDICATORS

  • Unusual transaction velocity
  • Multiple transactions within a short period
  • Repeated failed or reversed transactions
  • Multiple accounts or identifiers showing suspicious linkage
  • Rapid purchase and redemption patterns
  • Unusual refund behaviour
  • Repeated customer-support requests involving voucher credentials
  • Activity inconsistent with normal product use

9. FRAUD RULES & ALERTS

Fraud rules and alerts shall be documented where appropriate. Thresholds may be adjusted based on observed fraud patterns, false-positive rates, product changes and partner requirements.

10. ALERT REVIEW

  1. Review the alert and relevant transaction information.
  2. Assess customer/order/voucher history where available and lawful.
  3. Determine whether additional verification is appropriate.
  4. Take an authorised action such as allow, hold, restrict, block or escalate.
  5. Document the decision and supporting evidence.

11. TRANSACTION HOLDS / BLOCKS

Where permitted by product terms, partner procedures and applicable law, suspicious activity may be held, blocked, cancelled or escalated for review.

12. CUSTOMER PROTECTION

Controls shall seek to minimise customer harm while managing fraud risk. Legitimate customers affected by controls shall be handled through appropriate verification, support and resolution procedures.

13. INVESTIGATION

Material fraud cases shall be investigated according to risk and available evidence. Investigations may include transaction history, voucher status, customer communications, system logs and partner information.

14. EVIDENCE PRESERVATION

  • Transaction/order references
  • Voucher identifiers and status information
  • System and access logs where available
  • Customer communications
  • Partner communications
  • Investigation notes and decisions

15. PARTNER COORDINATION

Where transaction processing, PPI services, payment processing or fraud controls are operated by a partner, relevant alerts and incidents shall be escalated through agreed channels.

16. AML / CFT COORDINATION

Potential financial-crime concerns shall also be assessed under the AML/CFT Policy and escalated to the responsible function or regulated partner where appropriate.

17. UNAUTHORISED TRANSACTIONS

Suspected unauthorised transactions shall be handled according to the Unauthorised Transaction Policy, including customer verification, investigation, partner coordination and resolution.

18. CUSTOMER SUPPORT CONTROLS

Support personnel shall not disclose sensitive voucher or account information without appropriate verification. High-risk requests shall be escalated.

19. EMPLOYEE & INSIDER FRAUD

Suspected employee or privileged-access misuse shall be escalated confidentially to authorised management, Compliance, Risk or Information Security as appropriate.

20. THIRD-PARTY FRAUD RISK

Material vendors and partners shall be assessed for fraud risks relevant to their services and shall have appropriate contractual, monitoring and incident-escalation requirements.

21. SYSTEM & API CONTROLS

Fraud monitoring systems and APIs shall be protected through access control, authentication, logging, secure configuration and appropriate change management.

22. FRAUD INCIDENT RESPONSE

Material fraud events shall be handled under the Cyber Incident Response & Cyber Fraud Policy where they involve cyber compromise, credential theft, system abuse or other security incidents.

23. REPORTING & METRICS

  • Fraud alerts and confirmed cases
  • Fraud loss/exposure where measurable
  • False-positive trends
  • Blocked/restricted transactions
  • Refund/cancellation abuse
  • Top fraud patterns
  • Partner-related incidents
  • Open investigations and ageing

24. MANAGEMENT REVIEW

Management shall receive appropriate information on material fraud trends, incidents, control gaps and remediation actions.

25. CONTROL TESTING

Fraud rules, monitoring processes and relevant controls may be tested periodically to assess effectiveness, detect gaps and reduce false positives.

26. TRAINING

Relevant personnel shall receive training on fraud indicators, customer protection, secure handling of information, escalation and incident procedures.

27. DATA PROTECTION

Fraud monitoring and investigation data shall be handled securely and retained according to applicable privacy, retention and legal requirements.

28. RECORD KEEPING

Fraud alerts, investigations, decisions, evidence, escalations and closure records shall be retained for the applicable period.

29. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by authorised management. Fraud controls shall not be disabled without appropriate authority and risk assessment.

30. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Risk / FraudFraud rules, monitoring, investigation and reportingRisk/Fraud Head
ComplianceAML/regulatory coordination and oversightCompliance Head
OperationsTransaction and customer process controlsOperations Head
Technology / ITMonitoring systems, APIs and technical controlsTechnology Head
Information SecurityCyber/fraud incident coordinationSecurity Head
Customer SupportCustomer verification and suspicious-request escalationOperations / Compliance
Partner ManagementPartner fraud coordinationManagement

31. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in products, fraud trends, partner arrangements, technology, customer journey or applicable requirements.

32. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByRisk / Fraud / Compliance / Operations
Reviewed ByLegal / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED RISK & FRAUD DOCUMENT

This document is confidential and intended for authorised use only.