e-suvidha

CYBERVED AI PRIVATE LIMITED

REGULATORY REPORTING & RECORD-KEEPING POLICY

POLICY NO. 18 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Policy OwnerCompliance / Legal / Operations
Review FrequencyAt least annually / event driven
ClassificationConfidential – Regulatory & Record-Keeping Controlled Policy

1. PURPOSE

This Policy establishes controls for identifying reporting obligations, preparing and submitting required information, maintaining regulatory correspondence and preserving business records for CYBERVED AI PRIVATE LIMITED.

2. OBJECTIVES

  • Maintain complete, accurate and timely regulatory records.
  • Support applicable reporting and disclosure obligations.
  • Maintain an auditable trail of submissions and approvals.
  • Ensure records can be retrieved when required.
  • Coordinate reporting with authorised PPI, banking, payment and other regulated partners.
  • Prevent unauthorised alteration or destruction of records.

3. SCOPE

This Policy applies to regulatory, compliance, financial, transaction, customer, grievance, fraud, security, privacy, partner and corporate records maintained in connection with Company operations.

4. REGULATORY RESPONSIBILITY

The Company shall identify obligations applicable to its actual role, contractual arrangements and services. Where a regulated PPI issuer, bank or other authorised entity has the primary statutory reporting responsibility, the Company shall provide information and support as required under the applicable arrangement.

5. REPORTING IDENTIFICATION

  1. Identify applicable legal, regulatory and contractual reporting requirements.
  2. Assign an owner for each recurring or event-driven report.
  3. Define source data and approval requirements.
  4. Maintain reporting calendar or equivalent tracking.
  5. Monitor changes in applicable requirements.

6. REPORTING CATEGORIES

  • Regulatory / compliance reports
  • Partner and issuer reports
  • Transaction and settlement reports
  • Fraud / cyber incident reports
  • Customer grievance and dispute records
  • Financial and accounting records
  • Privacy / security incident records
  • Audit and assurance records

7. REPORTING ACCURACY

Reports shall be based on reliable source records and reviewed for material completeness, accuracy, consistency and appropriate approvals before submission.

8. APPROVAL & SIGN-OFF

Material regulatory or contractual submissions shall be reviewed and approved by designated personnel according to the nature of the report and internal authority matrix.

9. SUBMISSION EVIDENCE

Evidence of submission, acknowledgement, ticket/reference number, correspondence and supporting documents shall be retained where applicable.

10. CORRECTIONS / RE-SUBMISSIONS

If an error is identified in a material submission, the responsible function shall assess the impact and coordinate correction or re-submission with the relevant authority or partner as appropriate.

11. REGULATORY CORRESPONDENCE

Regulatory notices, queries, requests, inspection communications and responses shall be logged and assigned to an accountable owner.

12. RECORD CLASSIFICATION

  • Confidential / sensitive
  • Financial
  • Customer / personal information
  • Transaction / payment
  • Security / incident
  • Corporate / legal
  • Public or internal operational records

13. RECORD INTEGRITY

Records shall be protected against unauthorised alteration, deletion, loss or destruction. Where electronic records are used, appropriate access controls, audit trails and backups shall be maintained.

14. ELECTRONIC RECORDS

Electronic records shall be stored in approved systems with appropriate access, backup, security and retrieval controls.

15. PHYSICAL RECORDS

Where physical records are maintained, they shall be protected from unauthorised access, damage, loss and inappropriate disposal.

16. RECORD RETENTION

Records shall be retained for the period required by applicable law, regulation, contractual obligations, accounting requirements, dispute/investigation needs and legitimate business requirements.

17. RETENTION SCHEDULE

Record CategoryRetention BasisOwner
Regulatory submissionsApplicable legal/regulatory requirementCompliance
Transaction & payment recordsApplicable financial/legal/partner requirementsFinance / Operations
Customer & grievance recordsApplicable customer, dispute and legal requirementsSupport / Compliance
Fraud & security recordsSecurity, legal, audit and investigation requirementsRisk / Security
Contracts & partner recordsContractual, legal and audit requirementsLegal / Vendor Management
Accounting recordsApplicable accounting/tax/legal requirementsFinance
Corporate recordsApplicable corporate/legal requirementsManagement / Compliance

18. LEGAL HOLD

Records relevant to litigation, regulatory inquiry, audit, fraud investigation or other preservation requirements shall be placed on hold and protected from deletion until the hold is formally released.

19. RECORD DISPOSAL

At the end of the applicable retention period, records may be securely deleted or destroyed subject to legal holds and approved disposal procedures.

20. ACCESS & CONFIDENTIALITY

Access to regulatory and sensitive records shall be limited to authorised personnel on a need-to-know basis. Confidential information shall not be disclosed without authorisation or a lawful basis.

21. AUDIT TRAIL

Material reporting, approval, correction and record-disposal actions should have sufficient evidence to establish who performed the action, when and, where relevant, what was changed.

22. REGULATORY INSPECTIONS / AUDITS

The Company shall coordinate responses to authorised audits, inspections or information requests through designated personnel and maintain evidence of documents provided.

23. PARTNER COORDINATION

Information requested by an authorised PPI issuer, bank, payment processor or other relevant partner for regulatory, audit, fraud or operational purposes shall be coordinated through approved channels, subject to confidentiality and applicable requirements.

24. DATA PROTECTION

Records containing personal information shall be handled according to the Data Protection, Privacy & Retention Policy and applicable privacy requirements.

25. INCIDENT-RELATED RECORDS

Cyber incidents, fraud cases and material security events shall be recorded and preserved according to the Cyber Incident Response & Cyber Fraud Policy.

26. RECORD RETRIEVAL

Records shall be organised so that authorised personnel can retrieve relevant information within a reasonable period when required for business, audit, regulatory or legal purposes.

27. BUSINESS CONTINUITY

Critical regulatory, financial, transaction and compliance records shall be included in appropriate backup and business continuity arrangements.

28. TRAINING

Relevant personnel shall receive appropriate training on reporting responsibilities, record accuracy, confidentiality, retention and escalation.

29. EXCEPTIONS

Exceptions to this Policy shall be documented, risk-assessed and approved by authorised management, without overriding mandatory legal or regulatory requirements.

30. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Compliance / LegalRegulatory obligations, reporting calendar and correspondenceCompliance / Legal Head
FinanceFinancial, accounting and settlement recordsFinance Head
OperationsTransaction, customer and operational recordsOperations Head
Risk / FraudFraud and investigation recordsRisk/Fraud Head
Information SecuritySecurity and incident recordsSecurity Head
Technology / ITElectronic storage, access, backup and retrievalTechnology Head
ManagementMaterial regulatory decisions and approvalsDirector / Management

31. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in applicable requirements, business activities, regulatory status, products, partner arrangements or record systems.

32. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Legal / Operations
Reviewed ByRisk / Information Security / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – REGULATORY REPORTING & RECORD-KEEPING CONTROLLED POLICY