CYBERVED AI PRIVATE LIMITED
THIRD-PARTY / VENDOR RISK MANAGEMENT POLICY
POLICY NO. 15 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | CYBERVED AI PRIVATE LIMITED |
| CIN | U62090UP2024PTC201257 |
| Registered Office | Plot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028 |
| Website / Business Platform | e-suvidha.com |
| Business Context | Gift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners |
| Policy Owner | Vendor Management / Compliance / Risk / Information Security |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Third-Party Risk Controlled Policy |
1. PURPOSE
This Policy establishes a risk-based framework for selecting, onboarding, assessing, contracting, monitoring and exiting third-party vendors, service providers and business partners used by CYBERVED AI PRIVATE LIMITED.
2. OBJECTIVES
- Identify and manage third-party operational, financial, information-security, privacy, fraud and compliance risks.
- Apply appropriate due diligence before onboarding.
- Define contractual protections and service expectations.
- Monitor critical vendors throughout the relationship.
- Ensure incidents and material deficiencies are escalated promptly.
- Maintain evidence of vendor oversight.
3. SCOPE
This Policy applies to vendors, contractors, technology providers, cloud providers, payment/PPI partners, merchants, professional service providers and other third parties whose activities may affect Company operations, customers, data or compliance.
4. RISK CLASSIFICATION
- Critical – failure could materially affect regulated/payment operations, customers, security or business continuity.
- High – material operational, financial, security, privacy or compliance impact.
- Medium – moderate impact or limited access/dependency.
- Low – limited risk and non-critical services.
5. VENDOR ONBOARDING
- Define business requirement.
- Identify and assess potential vendor.
- Perform risk-based due diligence.
- Review commercial and service terms.
- Complete required security/privacy/compliance checks.
- Obtain approvals.
- Execute agreement before material access or service commencement.
6. DUE DILIGENCE
- Corporate identity and ownership information
- Relevant licences/authorisations where applicable
- Service capability and experience
- Information-security controls
- Privacy and data-processing practices
- Financial and operational stability
- Business continuity capability
- Fraud/compliance controls
- Relevant litigation or adverse information where appropriate
7. REGULATED PARTNERS
Where a vendor is an authorised PPI issuer, bank, payment processor or other regulated partner, applicable regulatory status and contractual responsibilities shall be documented and periodically reviewed.
8. INFORMATION SECURITY ASSESSMENT
Vendors with access to systems, APIs, customer information or sensitive data shall be assessed for appropriate security controls based on risk.
9. PRIVACY / DATA PROCESSING
Vendors processing personal information shall be subject to appropriate privacy, confidentiality, data-use, security, breach-notification and deletion/return requirements.
10. CONTRACTUAL REQUIREMENTS
- Defined scope and responsibilities
- Service levels / support expectations
- Confidentiality
- Security obligations
- Privacy and data protection
- Incident notification
- Audit / information rights where appropriate
- Subcontracting controls
- Business continuity
- Termination and data return/deletion
11. SERVICE LEVELS
Critical or material vendors should have documented service levels, escalation contacts and performance measures appropriate to the service.
12. ACCESS CONTROL
Third-party access shall be limited to the minimum required, authorised through appropriate processes and reviewed periodically.
13. SUBCONTRACTORS
Material subcontracting arrangements shall be disclosed or controlled according to contractual requirements. Vendors remain responsible for subcontractors to the extent agreed.
14. ONGOING MONITORING
- Service performance
- Security incidents
- Compliance issues
- Privacy events
- Material operational changes
- Financial/solvency indicators where relevant
- Contract and SLA compliance
- Audit findings
15. PERIODIC REASSESSMENT
Vendor risk shall be reassessed periodically based on risk tier and whenever there is a material change in service, ownership, access, incident history or regulatory status.
16. INCIDENT MANAGEMENT
Vendor incidents that may affect customers, systems, data, payments or business operations shall be escalated under the Cyber Incident Response & Cyber Fraud Policy and applicable contractual procedures.
17. FRAUD / FINANCIAL RISK
Vendors involved in payment, voucher, settlement or customer funds-related processes shall be subject to appropriate fraud, transaction and financial control assessment.
18. BUSINESS CONTINUITY
Critical vendors shall be assessed for continuity and recovery capabilities appropriate to the dependency and service criticality.
19. VENDOR PERFORMANCE
Performance may be reviewed against agreed SLAs, incident levels, customer impact, issue resolution, compliance obligations and service quality.
20. REMEDIATION
Material deficiencies shall be documented with corrective actions, owners and target dates. High-risk deficiencies may result in enhanced monitoring, suspension or termination.
21. VENDOR EXIT / TERMINATION
- Confirm termination approval.
- Disable third-party access.
- Recover or securely delete Company/customer information as required.
- Settle outstanding financial obligations.
- Transfer critical knowledge or services where necessary.
- Complete exit documentation.
22. RECORD KEEPING
Vendor due diligence, approvals, contracts, assessments, performance reviews, incidents, remediation and exit records shall be retained according to applicable requirements.
23. CONFLICTS OF INTEREST
Potential conflicts involving vendor selection or management shall be disclosed and managed through appropriate approval and segregation measures.
24. AUDIT / ASSURANCE
The Company may request appropriate assurance information, audit reports, certifications or other evidence based on vendor risk and contractual rights.
25. EXCEPTIONS
Exceptions to vendor risk requirements shall be documented, risk-assessed and approved by authorised management.
26. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Vendor Management | Onboarding, contracts, performance and records | Management |
| Compliance / Legal | Regulatory, contractual and compliance review | Compliance / Legal Head |
| Information Security | Security and technology risk assessment | Security Head |
| Risk | Risk classification and monitoring | Risk Head |
| Finance | Financial due diligence and settlement/vendor payments | Finance Head |
| Operations | Business owner and service performance | Operations Head |
| Management | Approval of critical/high-risk relationships | Director / Management |
27. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in the vendor ecosystem, products, partners, regulatory requirements or risk environment.
28. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Vendor Management / Compliance / Risk | |
| Reviewed By | Legal / Information Security / Management | |
| Approved By | Director / Authorised Signatory |