CYBERVED AI PRIVATE LIMITED
KYC & CUSTOMER DUE
DILIGENCE POLICY
DOCUMENT CONTROL
| Company | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated partners |
| Regulatory Model | KYC responsibilities shall be allocated according to applicable law, product structure and the authorised PPI / regulated partner arrangement. |
| Policy Owner | Compliance / Operations / Partner Management |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes a risk-based framework for customer identification, verification, due diligence, record management and escalation applicable to CYBERVED AI PRIVATE LIMITED's gift-card, voucher and related services. It also defines coordination with the authorised PPI or regulated partner where KYC obligations are performed by that partner.
2. OBJECTIVES
- Identify customers appropriately where KYC is required.
- Prevent impersonation, misuse, fraud and prohibited activity.
- Apply risk-based customer due diligence.
- Maintain accurate and secure KYC records.
- Define enhanced review and escalation controls.
- Clearly allocate KYC responsibilities between CYBERVED AI PRIVATE LIMITED and applicable regulated partners.
3. SCOPE
This Policy applies to customer onboarding, account creation where applicable, gift-card/voucher purchases or services where customer identification is required, customer support interactions involving identity verification, and partner-operated KYC processes.
4. KYC RESPONSIBILITY MODEL
Where an authorised PPI issuer, bank or other regulated partner is legally responsible for KYC, CYBERVED AI PRIVATE LIMITED shall support the partner within the agreed contractual scope and shall not represent itself as independently performing regulated KYC functions unless legally authorised.
5. CUSTOMER IDENTIFICATION
Where applicable, the customer shall be identified using information and documents permitted by the relevant legal, regulatory and partner requirements. The information collected shall be limited to what is reasonably necessary for the applicable purpose.
6. CUSTOMER VERIFICATION
- Validate submitted identity information through approved methods.
- Check document or verification status where applicable.
- Identify obvious inconsistencies or suspected manipulation.
- Record verification outcome and relevant reference.
- Escalate failed or suspicious verification.
7. CUSTOMER INFORMATION
- Name and contact information where applicable
- Identity/verification information where required
- Transaction or order references
- Relevant customer account information
- Risk indicators and verification outcome
8. RISK-BASED APPROACH
Customer due diligence shall be proportionate to the nature and risk of the product, transaction, customer relationship and applicable legal/partner requirements. Higher-risk situations may require additional verification or review.
9. ENHANCED DUE DILIGENCE
Where a customer, transaction or activity presents elevated risk, additional checks may be performed or requested by the responsible regulated partner. The scope shall be documented and proportionate to the identified risk.
10. SANCTIONS / WATCHLIST CONTROLS
Where required by applicable law, partner procedures or the Company's role, appropriate screening or screening support shall be performed against relevant sanctions, prohibited-party or other legally applicable lists.
11. AML / CFT COORDINATION
KYC information and verification outcomes shall support applicable AML/CFT controls. Suspicious matters shall be escalated under the AML/CFT and Fraud Prevention policies and, where required, to the responsible regulated partner.
12. FRAUD PREVENTION
- Detect inconsistent customer information.
- Identify repeated or suspicious onboarding attempts.
- Use appropriate transaction and account signals.
- Escalate suspected identity misuse or document fraud.
- Coordinate with PPI/bank partners where required.
13. CUSTOMER SUPPORT VERIFICATION
Before disclosing sensitive account, voucher or transaction information or performing a restricted support action, customer-support personnel shall use appropriate verification procedures.
14. KYC UPDATES
Where ongoing customer relationships exist and applicable requirements require updated information, the responsible function or regulated partner shall follow an appropriate refresh process.
15. FAILED / INCOMPLETE KYC
Where required KYC information is incomplete, inconsistent or cannot be satisfactorily verified, the relevant service or transaction may be restricted, delayed or declined in accordance with applicable requirements and partner procedures.
16. RECORD KEEPING
- KYC/verification information where lawfully collected
- Verification results and references
- Due-diligence review records
- Risk classification where applicable
- Escalation records
- Partner KYC confirmations
- Customer communications relating to verification
17. DATA PROTECTION
KYC information is confidential and shall be collected, accessed, shared, retained and disposed of in accordance with the Data Protection, Privacy & Retention Policy and applicable requirements.
18. ACCESS CONTROL
Access to KYC information shall be restricted on a need-to-know and role-based basis. Privileged access shall be authorised, monitored and periodically reviewed.
19. THIRD-PARTY KYC SERVICES
Where a third party performs verification or related services, the relationship shall be governed by appropriate due diligence, security, privacy, contractual and performance controls.
20. PARTNER COORDINATION
Where KYC is operated by an authorised PPI issuer or bank partner, CYBERVED AI PRIVATE LIMITED shall follow the agreed operating model, provide required information within its lawful possession and promptly escalate material KYC issues.
21. PROHIBITED / HIGH-RISK ACTIVITY
Where activity appears inconsistent with applicable law, product terms, partner requirements or risk controls, the Company may restrict processing and escalate the matter for review.
22. CUSTOMER RIGHTS & COMMUNICATION
Customer-facing communications shall be clear about information required for verification and, where appropriate, the purpose of the request. The Company shall avoid collecting unnecessary information.
23. SECURITY & INCIDENT MANAGEMENT
Any suspected compromise, unauthorised access, leakage or misuse of KYC information shall be handled under the Information Security & Cyber Security Policy and Cyber Incident Response & Cyber Fraud Policy.
24. AUDIT & QUALITY CONTROL
Periodic quality checks may be performed to assess accuracy, completeness, access controls, exception handling and compliance with applicable procedures.
25. TRAINING
Personnel handling customer verification or KYC-related information shall receive appropriate training on verification procedures, privacy, fraud indicators, escalation and secure handling.
26. EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by authorised management. Applicable legal, regulatory and partner requirements shall not be bypassed.
27. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Compliance | KYC framework, regulatory assessment and oversight | Compliance Head |
| Operations | Customer onboarding/support processes and records | Operations Head |
| Partner Management | Coordination with PPI/bank/regulatory partners | Management |
| Customer Support | Customer verification during support interactions | Operations / Compliance |
| Information Security / IT | KYC data security, access and system controls | Technology/Security Head |
| Risk / Fraud | Identity-fraud indicators and escalations | Risk/Fraud Head |
28. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in the business model, customer journey, partner arrangement, technology or applicable requirements.
29. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Operations | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |