CYBERVED AI PRIVATE LIMITED
REGULATORY REPORTING & RECORD-KEEPING POLICY
POLICY NO. 18 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Policy Owner | Compliance / Legal / Operations |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Regulatory & Record-Keeping Controlled Policy |
1. PURPOSE
This Policy establishes controls for identifying reporting obligations, preparing and submitting required information, maintaining regulatory correspondence and preserving business records for CYBERVED AI PRIVATE LIMITED.
2. OBJECTIVES
- Maintain complete, accurate and timely regulatory records.
- Support applicable reporting and disclosure obligations.
- Maintain an auditable trail of submissions and approvals.
- Ensure records can be retrieved when required.
- Coordinate reporting with authorised PPI, banking, payment and other regulated partners.
- Prevent unauthorised alteration or destruction of records.
3. SCOPE
This Policy applies to regulatory, compliance, financial, transaction, customer, grievance, fraud, security, privacy, partner and corporate records maintained in connection with Company operations.
4. REGULATORY RESPONSIBILITY
The Company shall identify obligations applicable to its actual role, contractual arrangements and services. Where a regulated PPI issuer, bank or other authorised entity has the primary statutory reporting responsibility, the Company shall provide information and support as required under the applicable arrangement.
5. REPORTING IDENTIFICATION
- Identify applicable legal, regulatory and contractual reporting requirements.
- Assign an owner for each recurring or event-driven report.
- Define source data and approval requirements.
- Maintain reporting calendar or equivalent tracking.
- Monitor changes in applicable requirements.
6. REPORTING CATEGORIES
- Regulatory / compliance reports
- Partner and issuer reports
- Transaction and settlement reports
- Fraud / cyber incident reports
- Customer grievance and dispute records
- Financial and accounting records
- Privacy / security incident records
- Audit and assurance records
7. REPORTING ACCURACY
Reports shall be based on reliable source records and reviewed for material completeness, accuracy, consistency and appropriate approvals before submission.
8. APPROVAL & SIGN-OFF
Material regulatory or contractual submissions shall be reviewed and approved by designated personnel according to the nature of the report and internal authority matrix.
9. SUBMISSION EVIDENCE
Evidence of submission, acknowledgement, ticket/reference number, correspondence and supporting documents shall be retained where applicable.
10. CORRECTIONS / RE-SUBMISSIONS
If an error is identified in a material submission, the responsible function shall assess the impact and coordinate correction or re-submission with the relevant authority or partner as appropriate.
11. REGULATORY CORRESPONDENCE
Regulatory notices, queries, requests, inspection communications and responses shall be logged and assigned to an accountable owner.
12. RECORD CLASSIFICATION
- Confidential / sensitive
- Financial
- Customer / personal information
- Transaction / payment
- Security / incident
- Corporate / legal
- Public or internal operational records
13. RECORD INTEGRITY
Records shall be protected against unauthorised alteration, deletion, loss or destruction. Where electronic records are used, appropriate access controls, audit trails and backups shall be maintained.
14. ELECTRONIC RECORDS
Electronic records shall be stored in approved systems with appropriate access, backup, security and retrieval controls.
15. PHYSICAL RECORDS
Where physical records are maintained, they shall be protected from unauthorised access, damage, loss and inappropriate disposal.
16. RECORD RETENTION
Records shall be retained for the period required by applicable law, regulation, contractual obligations, accounting requirements, dispute/investigation needs and legitimate business requirements.
17. RETENTION SCHEDULE
| Record Category | Retention Basis | Owner |
|---|---|---|
| Regulatory submissions | Applicable legal/regulatory requirement | Compliance |
| Transaction & payment records | Applicable financial/legal/partner requirements | Finance / Operations |
| Customer & grievance records | Applicable customer, dispute and legal requirements | Support / Compliance |
| Fraud & security records | Security, legal, audit and investigation requirements | Risk / Security |
| Contracts & partner records | Contractual, legal and audit requirements | Legal / Vendor Management |
| Accounting records | Applicable accounting/tax/legal requirements | Finance |
| Corporate records | Applicable corporate/legal requirements | Management / Compliance |
18. LEGAL HOLD
Records relevant to litigation, regulatory inquiry, audit, fraud investigation or other preservation requirements shall be placed on hold and protected from deletion until the hold is formally released.
19. RECORD DISPOSAL
At the end of the applicable retention period, records may be securely deleted or destroyed subject to legal holds and approved disposal procedures.
20. ACCESS & CONFIDENTIALITY
Access to regulatory and sensitive records shall be limited to authorised personnel on a need-to-know basis. Confidential information shall not be disclosed without authorisation or a lawful basis.
21. AUDIT TRAIL
Material reporting, approval, correction and record-disposal actions should have sufficient evidence to establish who performed the action, when and, where relevant, what was changed.
22. REGULATORY INSPECTIONS / AUDITS
The Company shall coordinate responses to authorised audits, inspections or information requests through designated personnel and maintain evidence of documents provided.
23. PARTNER COORDINATION
Information requested by an authorised PPI issuer, bank, payment processor or other relevant partner for regulatory, audit, fraud or operational purposes shall be coordinated through approved channels, subject to confidentiality and applicable requirements.
24. DATA PROTECTION
Records containing personal information shall be handled according to the Data Protection, Privacy & Retention Policy and applicable privacy requirements.
25. INCIDENT-RELATED RECORDS
Cyber incidents, fraud cases and material security events shall be recorded and preserved according to the Cyber Incident Response & Cyber Fraud Policy.
26. RECORD RETRIEVAL
Records shall be organised so that authorised personnel can retrieve relevant information within a reasonable period when required for business, audit, regulatory or legal purposes.
27. BUSINESS CONTINUITY
Critical regulatory, financial, transaction and compliance records shall be included in appropriate backup and business continuity arrangements.
28. TRAINING
Relevant personnel shall receive appropriate training on reporting responsibilities, record accuracy, confidentiality, retention and escalation.
29. EXCEPTIONS
Exceptions to this Policy shall be documented, risk-assessed and approved by authorised management, without overriding mandatory legal or regulatory requirements.
30. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Compliance / Legal | Regulatory obligations, reporting calendar and correspondence | Compliance / Legal Head |
| Finance | Financial, accounting and settlement records | Finance Head |
| Operations | Transaction, customer and operational records | Operations Head |
| Risk / Fraud | Fraud and investigation records | Risk/Fraud Head |
| Information Security | Security and incident records | Security Head |
| Technology / IT | Electronic storage, access, backup and retrieval | Technology Head |
| Management | Material regulatory decisions and approvals | Director / Management |
31. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in applicable requirements, business activities, regulatory status, products, partner arrangements or record systems.
32. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Legal / Operations | |
| Reviewed By | Risk / Information Security / Management | |
| Approved By | Director / Authorised Signatory |