Login or Create an account
Or Login Via

INTERNAL AML/CFT COMPLIANCE MANUAL

ZESTFLOW INDIA PRIVATE LIMITED (CIN-U62099DC2026PTC468956)

Registered Address - Office No. 201, Plot No 4, 2nd Floor, LSC Gujranwala Colony North West Delhi Delhi India 110009

Internal AML/CFT Compliance Framework

ZESTFLOW INDIA PRIVATE LIMITED maintains an integrated AML/CFT compliance framework covering KYC and due diligence, risk assessment, monitoring, employee awareness and suspicious activity escalation. Our internal controls are designed to promote consistent compliance, effective risk management and responsible business operations in accordance with applicable laws and requirements.

1. Purpose and Status of the Manual

ZESTFLOW INDIA PRIVATE LIMITED ("ZESTFLOW" or "the Company") is committed to maintaining an effective and proportionate compliance framework for managing risks relating to money laundering, terrorist financing, fraud, sanctions, identity misuse and other unlawful financial activities.

This Internal AML/CFT Compliance Manual ("Manual") establishes the operational framework through which the Company implements and coordinates its AML, CFT, KYC/CDD, risk management, record retention, employee training and suspicious activity escalation requirements.

This Manual is intended to:

  • establish a uniform internal compliance framework;
  • define key compliance responsibilities;
  • coordinate implementation of the Company's compliance policies;
  • provide a practical workflow for customer and merchant onboarding, monitoring and escalation;
  • promote timely identification and management of financial-crime risks;
  • maintain appropriate records and internal controls; and
  • protect the Company, its customers, partners and stakeholders from legal, financial, operational and reputational risks.

This Manual shall be read together with all applicable policies, procedures, contractual obligations and legal requirements of the Company.

Where a detailed Company policy or procedure deals specifically with a particular matter, that policy or procedure shall govern the relevant subject and this Manual shall operate as the overarching operational framework.

Nothing in this Manual shall be interpreted as creating a direct statutory or regulatory obligation upon the Company where such obligation does not otherwise apply under law.

2. Scope and Applicability

This Manual applies to:

  • the Board of Directors;
  • Senior Management;
  • the Compliance and Risk functions;
  • employees involved in customer or merchant onboarding;
  • Operations, Finance, Customer Support and Technology personnel performing compliance-sensitive functions;
  • consultants and authorised representatives; and
  • outsourced personnel performing material compliance-sensitive activities on behalf of the Company, where appropriate.

Merchants, vendors, channel partners, service providers and other third parties shall be required to comply with such contractual, due diligence, security and compliance requirements as may be applicable to their respective relationships with the Company.

The nature and extent of compliance controls shall be proportionate to:

  • the Company's business activities;
  • the products and services offered;
  • the Company's regulatory status;
  • the nature of the customer, merchant or partner relationship;
  • identified financial-crime and operational risks; and
  • arrangements with banks, financial institutions, payment service providers and other regulated entities.

3. Compliance Governance and Responsibilities

3.1 Board of Directors

The Board of Directors shall have overall oversight of the Company's compliance framework and shall:

  • approve material compliance policies;
  • oversee significant compliance risks;
  • consider material compliance incidents where appropriate;
  • support adequate compliance resources proportionate to the Company's size and operations; and
  • promote a culture of integrity and compliance.

3.2 Senior Management

Senior Management shall:

  • support implementation of the Company's compliance framework;
  • ensure that relevant departments implement applicable controls;
  • review material compliance issues and emerging risks;
  • support timely corrective and preventive action; and
  • escalate significant matters to the Board where appropriate.

3.3 Compliance Officer / Compliance Function

The Company shall designate an appropriate Compliance Officer or Compliance Function responsible for coordinating the implementation of the Company's AML/CFT and related compliance framework.

Responsibilities may include:

  • overseeing KYC and due diligence controls;
  • reviewing higher-risk customer or merchant relationships;
  • coordinating sanctions and watchlist screening;
  • reviewing suspicious activity referrals;
  • coordinating internal escalation and external reporting, where applicable;
  • maintaining appropriate compliance records;
  • providing employee guidance and training;
  • monitoring changes in relevant laws and compliance requirements; and
  • recommending improvements to policies and controls.

Where the Company is legally required to appoint a Designated Director, Principal Officer or any other specified officer, such appointment and related responsibilities shall be undertaken in accordance with applicable law.

3.4 Department Heads and Risk Owners

Department Heads shall ensure that relevant controls are implemented within their respective functions.

They shall promptly escalate material compliance concerns, control deficiencies, suspicious activities and incidents to the appropriate authorised function.

3.5 Employees and Relevant Personnel

All employees and relevant personnel shall:

  • understand and comply with policies applicable to their roles;
  • complete assigned compliance training;
  • follow approved onboarding and verification procedures;
  • remain alert to unusual or suspicious activities;
  • promptly escalate concerns through authorised channels;
  • preserve relevant records;
  • maintain confidentiality; and
  • cooperate with compliance reviews and investigations.

Employees shall not independently investigate suspected criminal activity beyond their authorised responsibilities.

4. Company Aml/cft Compliance Framework

The Company's AML/CFT and financial-crime compliance framework comprises the following principal documents:

1. Anti-Money Laundering (AML) Policy 2. Combating Financing of Terrorism (CFT) Policy 3. Know Your Customer (KYC) & Customer Due Diligence (CDD) Policy 4. Risk Management Policy 5. Record Retention & Data Preservation Policy 6. Employee AML/CFT Training Policy 7. Suspicious Activity Identification, Escalation & Reporting Procedure 8. This Internal AML/CFT Compliance Manual

These documents shall operate together as an integrated framework.

The AML Policy establishes the Company's overall financial-crime prevention framework.

The CFT Policy addresses risks relating to terrorist financing, designated persons and applicable sanctions concerns.

The KYC/CDD Policy establishes standards for identification, verification, beneficial ownership and risk-based due diligence.

The Risk Management Policy provides the broader framework for identifying, assessing and mitigating business and compliance risks.

The Record Retention & Data Preservation Policy governs the preservation, security and lawful disposal of records.

The Employee AML/CFT Training Policy establishes the Company's compliance training and awareness framework.

The Suspicious Activity Identification, Escalation & Reporting Procedure establishes the process to be followed when unusual or suspicious activity is identified.

This Manual connects these policies and procedures into a practical operational framework.

5. Customer and Merchant Onboarding Framework

The Company shall adopt a risk-based onboarding process appropriate to the nature of the proposed relationship and applicable requirements.

The general onboarding process may include:

Identification → Verification → Due Diligence → Risk Assessment → Screening → Approval

5.1 Identification and Information Collection

The Company may collect relevant information, including:

  • name and identity details;
  • contact and address information;
  • PAN and other identification details;
  • business registration information;
  • GST information, where applicable;
  • bank account information;
  • nature of business or occupation;
  • ownership and beneficial ownership information;
  • applicable licences or registrations;
  • expected business or transaction profile; and
  • such other information as may reasonably be required.

The information required shall depend upon the nature and risk of the relationship.

5.2 Verification

The Company shall undertake appropriate verification using reliable documents, information or legally permissible verification methods.

Digital or non-face-to-face verification mechanisms may be used where legally permissible, operationally available and appropriate.

5.3 Customer and Merchant Due Diligence

Due diligence may include:

  • identity verification;
  • business verification;
  • beneficial ownership checks;
  • understanding the nature and purpose of the relationship;
  • assessment of expected activities;
  • review of applicable licences or registrations;
  • bank account verification;
  • website or digital presence review, where relevant; and
  • additional checks based on identified risk.

5.4 Risk Classification

Customers and merchants may be classified as:

  • Low Risk;
  • Medium Risk; or
  • High Risk.

Risk classification may consider:

  • nature of business;
  • ownership structure;
  • geographical exposure;
  • expected transaction profile;
  • products or services used;
  • mode of onboarding;
  • regulatory or compliance history;
  • sanctions or adverse indicators; and
  • other relevant risk factors.

Risk classification shall be based on the overall risk profile and may be revised where circumstances change.

5.5 Enhanced Due Diligence

Higher-risk relationships may be subject to additional measures, including:

  • additional information or documents;
  • enhanced identity or ownership verification;
  • source of funds or source of wealth information, where appropriate;
  • additional management approval;
  • enhanced monitoring; and
  • more frequent review.

5.6 Screening

Appropriate screening may be conducted, where applicable, against:

  • sanctions and designated-person lists;
  • applicable Government of India notifications;
  • relevant UNSC sanctions measures; and
  • other legally applicable screening sources.

Potential matches shall be reviewed before adverse action is taken.

5.7 Approval, Rejection or Restriction

Following completion of applicable onboarding requirements, the Company may:

  • approve the relationship;
  • request additional information;
  • approve subject to additional controls;
  • reject the relationship; or
  • restrict or suspend onboarding pending further review.

The Company may decline to establish a relationship where satisfactory due diligence cannot be completed or where identified risks cannot reasonably be mitigated, subject to applicable law and contractual obligations.

6. Ongoing Monitoring and Periodic Review

Compliance does not end upon onboarding.

The Company may undertake ongoing or periodic review based on the nature and risk of the relationship.

Monitoring may consider:

  • changes in customer or merchant information;
  • changes in ownership or control;
  • changes in business activities;
  • unusual transaction values or frequency;
  • excessive refunds, reversals or chargebacks;
  • unusual settlement instructions;
  • rapid movement of funds;
  • third-party payments;
  • multiple linked accounts or devices;
  • geographical inconsistencies;
  • sanctions or adverse compliance indicators; and
  • activities inconsistent with the known profile.

Monitoring may be automated, manual or a combination of both.

The Company may update KYC, due diligence or risk classification where:

  • material information changes;
  • unusual activity is identified;
  • existing information appears inaccurate or outdated;
  • new risk factors emerge; or
  • applicable law or partner requirements require an update.

The extent of monitoring shall be proportionate to the Company's business activities, technological capabilities and identified risks.

7. Suspicious Activity Identification and Escalation

All employees and relevant personnel shall promptly escalate activities that give rise to a reasonable suspicion or financial-crime concern.

An employee is not required to prove that unlawful activity has occurred before making an internal report.

The general escalation process shall be:

Employee / System Alert → Internal Referral → Compliance Review → Decision and Action → External Escalation or Reporting, Where Applicable

7.1 Internal Referral

Suspicious or unusual activity shall be reported through the authorised internal channel.

The referral should include available information concerning:

  • the relevant customer, merchant or person;
  • the transaction or activity;
  • the reason for concern;
  • relevant dates and amounts; and
  • supporting information.

7.2 Compliance Review

The authorised Compliance Officer or function may review:

  • KYC and due diligence information;
  • transaction or activity history;
  • expected customer or merchant profile;
  • ownership information;
  • previous alerts;
  • screening results;
  • geographical exposure; and
  • other relevant information.

7.3 Decision and Action

Following review, the Company may determine that:

  • no further action is presently required;
  • additional information is required;
  • enhanced monitoring or due diligence is appropriate;
  • the matter should be escalated internally;
  • services should be restricted, suspended or terminated, subject to applicable law and contractual rights;
  • information should be escalated to a regulated partner institution; or
  • external reporting or other action is required under applicable law.

Material decisions shall be appropriately documented.

7.4 External Reporting

Where the Company is directly required under applicable law to make a report to FIU-IND or another competent authority, such reporting shall be undertaken by the duly authorised person in accordance with applicable requirements.

Where the relevant statutory reporting obligation rests with a regulated partner institution, the Company shall promptly escalate relevant information to such institution in accordance with applicable law and contractual arrangements.

Nothing in this Manual shall be interpreted as requiring direct regulatory reporting by the Company where no such legal obligation applies.

8. Confidentiality and No Tipping-off

All compliance reviews, suspicious activity referrals, investigations, screening results and related information shall be treated as confidential.

No employee or unauthorised person shall improperly inform a customer, merchant or other concerned person that:

  • an internal suspicious activity referral has been made;
  • a compliance review or investigation is underway;
  • enhanced monitoring is being undertaken;
  • information has been escalated to a regulated partner;
  • a regulatory report has been or may be made; or
  • a competent authority has been or may be informed.

Compliance information shall be disclosed internally only on a need-to-know basis and externally only where authorised, contractually required or permitted by law.

9. Record Management and Documentation

The Company shall maintain appropriate records necessary to demonstrate implementation of its compliance framework.

Such records may include:

  • customer and merchant onboarding records;
  • KYC and due diligence information;
  • beneficial ownership records;
  • risk assessments and classifications;
  • screening results;
  • transaction or activity monitoring records;
  • suspicious activity referrals and review records;
  • material compliance decisions;
  • regulatory or partner communications;
  • incident records;
  • audit or compliance review records; and
  • employee training records.

Records shall be:

  • reasonably accurate and complete;
  • protected against unauthorised access or alteration;
  • accessible to authorised persons where legitimately required; and
  • retained in accordance with applicable law and the Company's Record Retention & Data Preservation Policy.

Records subject to a Legal Hold, investigation, audit, regulatory inquiry or reasonably anticipated proceeding shall not be destroyed until authorised for release.

10. Employee Training and Awareness

Relevant employees and personnel shall receive appropriate AML/CFT and compliance training based on their roles and responsibilities.

Training may cover:

  • AML and CFT principles;
  • KYC and customer or merchant due diligence;
  • beneficial ownership;
  • risk classification;
  • sanctions and screening;
  • financial-crime red flags;
  • suspicious activity identification and escalation;
  • confidentiality and no tipping-off;
  • record retention;
  • fraud prevention;
  • relevant information-security risks; and
  • consequences of non-compliance.

The Company shall endeavour to provide induction and periodic refresher training to relevant personnel.

Higher-risk or specialised functions may receive additional role-based training.

Appropriate training records shall be maintained.

11. Incident Management and Escalation

Material compliance-related incidents may include:

  • significant fraud;
  • suspected money laundering or terrorist financing;
  • sanctions concerns;
  • material KYC or onboarding failures;
  • unauthorised disclosure of confidential information;
  • material data or cyber-security incidents affecting compliance;
  • deliberate circumvention of internal controls;
  • significant record loss or destruction; and
  • other events creating material legal, financial or reputational risk.

Material incidents shall be promptly escalated through the Company's authorised internal reporting mechanism.

Depending upon the nature and severity of the incident, the Company may undertake:

  • immediate containment;
  • investigation and assessment;
  • preservation of relevant records;
  • corrective and preventive action;
  • escalation to Senior Management or the Board;
  • notification to regulated partners; and
  • reporting to competent authorities where required under applicable law.

The Company may maintain an Incident Register or other appropriate record of material incidents.

12. Compliance Reviews and Internal Assurance

The Company may periodically assess the effectiveness of its compliance framework through:

  • management reviews;
  • compliance testing;
  • internal assessments;
  • risk-based audits;
  • external reviews, where considered appropriate; or
  • other suitable assurance mechanisms.

Reviews may consider:

  • compliance with approved policies and procedures;
  • effectiveness of customer and merchant onboarding controls;
  • quality of due diligence and risk classification;
  • effectiveness of monitoring and escalation;
  • record maintenance;
  • employee awareness;
  • incident management; and
  • implementation of corrective actions.

The frequency and scope of reviews shall be proportionate to the Company's size, business activities, risk profile and applicable requirements.

Material deficiencies shall be appropriately documented and corrective measures shall be implemented within reasonable timelines.

13. Policy Violations and Corrective Action

Violations of the Company's compliance framework may include:

  • deliberate bypassing of KYC or due diligence controls;
  • falsification or suppression of information;
  • failure to report material suspicious activity;
  • unauthorised tipping-off;
  • breach of confidentiality;
  • destruction or unauthorised alteration of relevant records;
  • deliberate circumvention of internal controls;
  • failure to cooperate with authorised compliance reviews; or
  • repeated or serious disregard of applicable policies.

Depending upon the nature and seriousness of the matter, the Company may take appropriate action, including:

  • guidance or retraining;
  • enhanced supervision;
  • restriction of access or responsibilities;
  • disciplinary action;
  • suspension or termination of employment or engagement;
  • termination or restriction of a business relationship; and
  • legal or regulatory action where required or appropriate.

Corrective action shall be proportionate to the circumstances and applicable law.

14. Continuous Improvement and Review

The Company shall periodically review and improve its AML/CFT compliance framework having regard to:

  • changes in applicable laws and regulatory requirements;
  • material changes in the Company's business model;
  • new products, services or technologies;
  • changes in regulated partner arrangements;
  • compliance incidents and control failures;
  • fraud and financial-crime trends;
  • audit and review findings;
  • emerging risks; and
  • operational experience.

Policies, procedures and controls may be amended where reasonably necessary to maintain an effective and proportionate compliance framework.

This Manual shall be reviewed periodically and may be amended or replaced by the Company as required.

15. Approval and Effective Date

This Internal AML/CFT Compliance Manual has been approved by the Board of Directors of ZESTFLOW INDIA PRIVATE LIMITED and shall come into effect from the date of its approval.

All Directors, officers, employees, consultants and relevant authorised personnel shall comply with this Manual to the extent applicable to their respective roles and responsibilities.

Merchants, vendors, channel partners and service providers shall comply with the compliance requirements applicable to them under their respective agreements, onboarding requirements and applicable law.

CERTIFICATION

All Directors, officers, employees, consultants and relevant authorised personnel of ZESTFLOW INDIA PRIVATE LIMITED shall comply with this Manual to the extent applicable to their respective roles and responsibilities.

For ZESTFLOW INDIA PRIVATE LIMITED Approved by the Board of Directors on: __________________ Effective Date: __________________