e-suvidha

CYBERVED AI PRIVATE LIMITED

THIRD-PARTY / VENDOR RISK MANAGEMENT POLICY

POLICY NO. 15 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyCYBERVED AI PRIVATE LIMITED
CINU62090UP2024PTC201257
Registered OfficePlot No. 33 B, Kanchanpur, Matiyari, Lucknow, Uttar Pradesh – 226028
Website / Business Platforme-suvidha.com
Business ContextGift Cards, Gift Vouchers & related digital products through applicable authorised / regulated PPI and other partners
Policy OwnerVendor Management / Compliance / Risk / Information Security
Review FrequencyAt least annually / event driven
ClassificationConfidential – Third-Party Risk Controlled Policy

1. PURPOSE

This Policy establishes a risk-based framework for selecting, onboarding, assessing, contracting, monitoring and exiting third-party vendors, service providers and business partners used by CYBERVED AI PRIVATE LIMITED.

2. OBJECTIVES

  • Identify and manage third-party operational, financial, information-security, privacy, fraud and compliance risks.
  • Apply appropriate due diligence before onboarding.
  • Define contractual protections and service expectations.
  • Monitor critical vendors throughout the relationship.
  • Ensure incidents and material deficiencies are escalated promptly.
  • Maintain evidence of vendor oversight.

3. SCOPE

This Policy applies to vendors, contractors, technology providers, cloud providers, payment/PPI partners, merchants, professional service providers and other third parties whose activities may affect Company operations, customers, data or compliance.

4. RISK CLASSIFICATION

  • Critical – failure could materially affect regulated/payment operations, customers, security or business continuity.
  • High – material operational, financial, security, privacy or compliance impact.
  • Medium – moderate impact or limited access/dependency.
  • Low – limited risk and non-critical services.

5. VENDOR ONBOARDING

  1. Define business requirement.
  2. Identify and assess potential vendor.
  3. Perform risk-based due diligence.
  4. Review commercial and service terms.
  5. Complete required security/privacy/compliance checks.
  6. Obtain approvals.
  7. Execute agreement before material access or service commencement.

6. DUE DILIGENCE

  • Corporate identity and ownership information
  • Relevant licences/authorisations where applicable
  • Service capability and experience
  • Information-security controls
  • Privacy and data-processing practices
  • Financial and operational stability
  • Business continuity capability
  • Fraud/compliance controls
  • Relevant litigation or adverse information where appropriate

7. REGULATED PARTNERS

Where a vendor is an authorised PPI issuer, bank, payment processor or other regulated partner, applicable regulatory status and contractual responsibilities shall be documented and periodically reviewed.

8. INFORMATION SECURITY ASSESSMENT

Vendors with access to systems, APIs, customer information or sensitive data shall be assessed for appropriate security controls based on risk.

9. PRIVACY / DATA PROCESSING

Vendors processing personal information shall be subject to appropriate privacy, confidentiality, data-use, security, breach-notification and deletion/return requirements.

10. CONTRACTUAL REQUIREMENTS

  • Defined scope and responsibilities
  • Service levels / support expectations
  • Confidentiality
  • Security obligations
  • Privacy and data protection
  • Incident notification
  • Audit / information rights where appropriate
  • Subcontracting controls
  • Business continuity
  • Termination and data return/deletion

11. SERVICE LEVELS

Critical or material vendors should have documented service levels, escalation contacts and performance measures appropriate to the service.

12. ACCESS CONTROL

Third-party access shall be limited to the minimum required, authorised through appropriate processes and reviewed periodically.

13. SUBCONTRACTORS

Material subcontracting arrangements shall be disclosed or controlled according to contractual requirements. Vendors remain responsible for subcontractors to the extent agreed.

14. ONGOING MONITORING

  • Service performance
  • Security incidents
  • Compliance issues
  • Privacy events
  • Material operational changes
  • Financial/solvency indicators where relevant
  • Contract and SLA compliance
  • Audit findings

15. PERIODIC REASSESSMENT

Vendor risk shall be reassessed periodically based on risk tier and whenever there is a material change in service, ownership, access, incident history or regulatory status.

16. INCIDENT MANAGEMENT

Vendor incidents that may affect customers, systems, data, payments or business operations shall be escalated under the Cyber Incident Response & Cyber Fraud Policy and applicable contractual procedures.

17. FRAUD / FINANCIAL RISK

Vendors involved in payment, voucher, settlement or customer funds-related processes shall be subject to appropriate fraud, transaction and financial control assessment.

18. BUSINESS CONTINUITY

Critical vendors shall be assessed for continuity and recovery capabilities appropriate to the dependency and service criticality.

19. VENDOR PERFORMANCE

Performance may be reviewed against agreed SLAs, incident levels, customer impact, issue resolution, compliance obligations and service quality.

20. REMEDIATION

Material deficiencies shall be documented with corrective actions, owners and target dates. High-risk deficiencies may result in enhanced monitoring, suspension or termination.

21. VENDOR EXIT / TERMINATION

  1. Confirm termination approval.
  2. Disable third-party access.
  3. Recover or securely delete Company/customer information as required.
  4. Settle outstanding financial obligations.
  5. Transfer critical knowledge or services where necessary.
  6. Complete exit documentation.

22. RECORD KEEPING

Vendor due diligence, approvals, contracts, assessments, performance reviews, incidents, remediation and exit records shall be retained according to applicable requirements.

23. CONFLICTS OF INTEREST

Potential conflicts involving vendor selection or management shall be disclosed and managed through appropriate approval and segregation measures.

24. AUDIT / ASSURANCE

The Company may request appropriate assurance information, audit reports, certifications or other evidence based on vendor risk and contractual rights.

25. EXCEPTIONS

Exceptions to vendor risk requirements shall be documented, risk-assessed and approved by authorised management.

26. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Vendor ManagementOnboarding, contracts, performance and recordsManagement
Compliance / LegalRegulatory, contractual and compliance reviewCompliance / Legal Head
Information SecuritySecurity and technology risk assessmentSecurity Head
RiskRisk classification and monitoringRisk Head
FinanceFinancial due diligence and settlement/vendor paymentsFinance Head
OperationsBusiness owner and service performanceOperations Head
ManagementApproval of critical/high-risk relationshipsDirector / Management

27. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in the vendor ecosystem, products, partners, regulatory requirements or risk environment.

28. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByVendor Management / Compliance / Risk
Reviewed ByLegal / Information Security / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – THIRD-PARTY RISK CONTROLLED POLICY