e-suvidha

CYBERVED AI PRIVATE LIMITED

KYC & CUSTOMER DUE
DILIGENCE POLICY

POLICY NO. 03VERSION 1.0EFFECTIVE DATE: 29 SEPTEMBER 2026

DOCUMENT CONTROL

CompanyDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated partners
Regulatory ModelKYC responsibilities shall be allocated according to applicable law, product structure and the authorised PPI / regulated partner arrangement.
Policy OwnerCompliance / Operations / Partner Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes a risk-based framework for customer identification, verification, due diligence, record management and escalation applicable to CYBERVED AI PRIVATE LIMITED's gift-card, voucher and related services. It also defines coordination with the authorised PPI or regulated partner where KYC obligations are performed by that partner.

2. OBJECTIVES

  • Identify customers appropriately where KYC is required.
  • Prevent impersonation, misuse, fraud and prohibited activity.
  • Apply risk-based customer due diligence.
  • Maintain accurate and secure KYC records.
  • Define enhanced review and escalation controls.
  • Clearly allocate KYC responsibilities between CYBERVED AI PRIVATE LIMITED and applicable regulated partners.

3. SCOPE

This Policy applies to customer onboarding, account creation where applicable, gift-card/voucher purchases or services where customer identification is required, customer support interactions involving identity verification, and partner-operated KYC processes.

4. KYC RESPONSIBILITY MODEL

Where an authorised PPI issuer, bank or other regulated partner is legally responsible for KYC, CYBERVED AI PRIVATE LIMITED shall support the partner within the agreed contractual scope and shall not represent itself as independently performing regulated KYC functions unless legally authorised.

5. CUSTOMER IDENTIFICATION

Where applicable, the customer shall be identified using information and documents permitted by the relevant legal, regulatory and partner requirements. The information collected shall be limited to what is reasonably necessary for the applicable purpose.

6. CUSTOMER VERIFICATION

  • Validate submitted identity information through approved methods.
  • Check document or verification status where applicable.
  • Identify obvious inconsistencies or suspected manipulation.
  • Record verification outcome and relevant reference.
  • Escalate failed or suspicious verification.

7. CUSTOMER INFORMATION

  • Name and contact information where applicable
  • Identity/verification information where required
  • Transaction or order references
  • Relevant customer account information
  • Risk indicators and verification outcome

8. RISK-BASED APPROACH

Customer due diligence shall be proportionate to the nature and risk of the product, transaction, customer relationship and applicable legal/partner requirements. Higher-risk situations may require additional verification or review.

9. ENHANCED DUE DILIGENCE

Where a customer, transaction or activity presents elevated risk, additional checks may be performed or requested by the responsible regulated partner. The scope shall be documented and proportionate to the identified risk.

10. SANCTIONS / WATCHLIST CONTROLS

Where required by applicable law, partner procedures or the Company's role, appropriate screening or screening support shall be performed against relevant sanctions, prohibited-party or other legally applicable lists.

11. AML / CFT COORDINATION

KYC information and verification outcomes shall support applicable AML/CFT controls. Suspicious matters shall be escalated under the AML/CFT and Fraud Prevention policies and, where required, to the responsible regulated partner.

12. FRAUD PREVENTION

  • Detect inconsistent customer information.
  • Identify repeated or suspicious onboarding attempts.
  • Use appropriate transaction and account signals.
  • Escalate suspected identity misuse or document fraud.
  • Coordinate with PPI/bank partners where required.

13. CUSTOMER SUPPORT VERIFICATION

Before disclosing sensitive account, voucher or transaction information or performing a restricted support action, customer-support personnel shall use appropriate verification procedures.

14. KYC UPDATES

Where ongoing customer relationships exist and applicable requirements require updated information, the responsible function or regulated partner shall follow an appropriate refresh process.

15. FAILED / INCOMPLETE KYC

Where required KYC information is incomplete, inconsistent or cannot be satisfactorily verified, the relevant service or transaction may be restricted, delayed or declined in accordance with applicable requirements and partner procedures.

16. RECORD KEEPING

  • KYC/verification information where lawfully collected
  • Verification results and references
  • Due-diligence review records
  • Risk classification where applicable
  • Escalation records
  • Partner KYC confirmations
  • Customer communications relating to verification

17. DATA PROTECTION

KYC information is confidential and shall be collected, accessed, shared, retained and disposed of in accordance with the Data Protection, Privacy & Retention Policy and applicable requirements.

18. ACCESS CONTROL

Access to KYC information shall be restricted on a need-to-know and role-based basis. Privileged access shall be authorised, monitored and periodically reviewed.

19. THIRD-PARTY KYC SERVICES

Where a third party performs verification or related services, the relationship shall be governed by appropriate due diligence, security, privacy, contractual and performance controls.

20. PARTNER COORDINATION

Where KYC is operated by an authorised PPI issuer or bank partner, CYBERVED AI PRIVATE LIMITED shall follow the agreed operating model, provide required information within its lawful possession and promptly escalate material KYC issues.

21. PROHIBITED / HIGH-RISK ACTIVITY

Where activity appears inconsistent with applicable law, product terms, partner requirements or risk controls, the Company may restrict processing and escalate the matter for review.

22. CUSTOMER RIGHTS & COMMUNICATION

Customer-facing communications shall be clear about information required for verification and, where appropriate, the purpose of the request. The Company shall avoid collecting unnecessary information.

23. SECURITY & INCIDENT MANAGEMENT

Any suspected compromise, unauthorised access, leakage or misuse of KYC information shall be handled under the Information Security & Cyber Security Policy and Cyber Incident Response & Cyber Fraud Policy.

24. AUDIT & QUALITY CONTROL

Periodic quality checks may be performed to assess accuracy, completeness, access controls, exception handling and compliance with applicable procedures.

25. TRAINING

Personnel handling customer verification or KYC-related information shall receive appropriate training on verification procedures, privacy, fraud indicators, escalation and secure handling.

26. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by authorised management. Applicable legal, regulatory and partner requirements shall not be bypassed.

27. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ComplianceKYC framework, regulatory assessment and oversightCompliance Head
OperationsCustomer onboarding/support processes and recordsOperations Head
Partner ManagementCoordination with PPI/bank/regulatory partnersManagement
Customer SupportCustomer verification during support interactionsOperations / Compliance
Information Security / ITKYC data security, access and system controlsTechnology/Security Head
Risk / FraudIdentity-fraud indicators and escalationsRisk/Fraud Head

28. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in the business model, customer journey, partner arrangement, technology or applicable requirements.

29. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Operations
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

This document is confidential and intended for authorised use only.