Login or Signup
and Grab Exclusive deals
Registered Address - Office No. 201, Plot No 4, 2nd Floor, LSC Gujranwala Colony North West Delhi Delhi India 110009
ZESTFLOW INDIA PRIVATE LIMITED maintains an integrated AML/CFT compliance framework covering KYC and due diligence, risk assessment, monitoring, employee awareness and suspicious activity escalation. Our internal controls are designed to promote consistent compliance, effective risk management and responsible business operations in accordance with applicable laws and requirements.
ZESTFLOW INDIA PRIVATE LIMITED ("ZESTFLOW" or "the Company") is committed to maintaining an effective and proportionate compliance framework for managing risks relating to money laundering, terrorist financing, fraud, sanctions, identity misuse and other unlawful financial activities.
This Internal AML/CFT Compliance Manual ("Manual") establishes the operational framework through which the Company implements and coordinates its AML, CFT, KYC/CDD, risk management, record retention, employee training and suspicious activity escalation requirements.
This Manual is intended to:
This Manual shall be read together with all applicable policies, procedures, contractual obligations and legal requirements of the Company.
Where a detailed Company policy or procedure deals specifically with a particular matter, that policy or procedure shall govern the relevant subject and this Manual shall operate as the overarching operational framework.
Nothing in this Manual shall be interpreted as creating a direct statutory or regulatory obligation upon the Company where such obligation does not otherwise apply under law.
This Manual applies to:
Merchants, vendors, channel partners, service providers and other third parties shall be required to comply with such contractual, due diligence, security and compliance requirements as may be applicable to their respective relationships with the Company.
The nature and extent of compliance controls shall be proportionate to:
3.1 Board of Directors
The Board of Directors shall have overall oversight of the Company's compliance framework and shall:
3.2 Senior Management
Senior Management shall:
3.3 Compliance Officer / Compliance Function
The Company shall designate an appropriate Compliance Officer or Compliance Function responsible for coordinating the implementation of the Company's AML/CFT and related compliance framework.
Responsibilities may include:
Where the Company is legally required to appoint a Designated Director, Principal Officer or any other specified officer, such appointment and related responsibilities shall be undertaken in accordance with applicable law.
3.4 Department Heads and Risk Owners
Department Heads shall ensure that relevant controls are implemented within their respective functions.
They shall promptly escalate material compliance concerns, control deficiencies, suspicious activities and incidents to the appropriate authorised function.
3.5 Employees and Relevant Personnel
All employees and relevant personnel shall:
Employees shall not independently investigate suspected criminal activity beyond their authorised responsibilities.
The Company's AML/CFT and financial-crime compliance framework comprises the following principal documents:
1. Anti-Money Laundering (AML) Policy 2. Combating Financing of Terrorism (CFT) Policy 3. Know Your Customer (KYC) & Customer Due Diligence (CDD) Policy 4. Risk Management Policy 5. Record Retention & Data Preservation Policy 6. Employee AML/CFT Training Policy 7. Suspicious Activity Identification, Escalation & Reporting Procedure 8. This Internal AML/CFT Compliance Manual
These documents shall operate together as an integrated framework.
The AML Policy establishes the Company's overall financial-crime prevention framework.
The CFT Policy addresses risks relating to terrorist financing, designated persons and applicable sanctions concerns.
The KYC/CDD Policy establishes standards for identification, verification, beneficial ownership and risk-based due diligence.
The Risk Management Policy provides the broader framework for identifying, assessing and mitigating business and compliance risks.
The Record Retention & Data Preservation Policy governs the preservation, security and lawful disposal of records.
The Employee AML/CFT Training Policy establishes the Company's compliance training and awareness framework.
The Suspicious Activity Identification, Escalation & Reporting Procedure establishes the process to be followed when unusual or suspicious activity is identified.
This Manual connects these policies and procedures into a practical operational framework.
The Company shall adopt a risk-based onboarding process appropriate to the nature of the proposed relationship and applicable requirements.
The general onboarding process may include:
Identification → Verification → Due Diligence → Risk Assessment → Screening → Approval
5.1 Identification and Information Collection
The Company may collect relevant information, including:
The information required shall depend upon the nature and risk of the relationship.
5.2 Verification
The Company shall undertake appropriate verification using reliable documents, information or legally permissible verification methods.
Digital or non-face-to-face verification mechanisms may be used where legally permissible, operationally available and appropriate.
5.3 Customer and Merchant Due Diligence
Due diligence may include:
5.4 Risk Classification
Customers and merchants may be classified as:
Risk classification may consider:
Risk classification shall be based on the overall risk profile and may be revised where circumstances change.
5.5 Enhanced Due Diligence
Higher-risk relationships may be subject to additional measures, including:
5.6 Screening
Appropriate screening may be conducted, where applicable, against:
Potential matches shall be reviewed before adverse action is taken.
5.7 Approval, Rejection or Restriction
Following completion of applicable onboarding requirements, the Company may:
The Company may decline to establish a relationship where satisfactory due diligence cannot be completed or where identified risks cannot reasonably be mitigated, subject to applicable law and contractual obligations.
Compliance does not end upon onboarding.
The Company may undertake ongoing or periodic review based on the nature and risk of the relationship.
Monitoring may consider:
Monitoring may be automated, manual or a combination of both.
The Company may update KYC, due diligence or risk classification where:
The extent of monitoring shall be proportionate to the Company's business activities, technological capabilities and identified risks.
All employees and relevant personnel shall promptly escalate activities that give rise to a reasonable suspicion or financial-crime concern.
An employee is not required to prove that unlawful activity has occurred before making an internal report.
The general escalation process shall be:
Employee / System Alert → Internal Referral → Compliance Review → Decision and Action → External Escalation or Reporting, Where Applicable
7.1 Internal Referral
Suspicious or unusual activity shall be reported through the authorised internal channel.
The referral should include available information concerning:
7.2 Compliance Review
The authorised Compliance Officer or function may review:
7.3 Decision and Action
Following review, the Company may determine that:
Material decisions shall be appropriately documented.
7.4 External Reporting
Where the Company is directly required under applicable law to make a report to FIU-IND or another competent authority, such reporting shall be undertaken by the duly authorised person in accordance with applicable requirements.
Where the relevant statutory reporting obligation rests with a regulated partner institution, the Company shall promptly escalate relevant information to such institution in accordance with applicable law and contractual arrangements.
Nothing in this Manual shall be interpreted as requiring direct regulatory reporting by the Company where no such legal obligation applies.
All compliance reviews, suspicious activity referrals, investigations, screening results and related information shall be treated as confidential.
No employee or unauthorised person shall improperly inform a customer, merchant or other concerned person that:
Compliance information shall be disclosed internally only on a need-to-know basis and externally only where authorised, contractually required or permitted by law.
The Company shall maintain appropriate records necessary to demonstrate implementation of its compliance framework.
Such records may include:
Records shall be:
Records subject to a Legal Hold, investigation, audit, regulatory inquiry or reasonably anticipated proceeding shall not be destroyed until authorised for release.
Relevant employees and personnel shall receive appropriate AML/CFT and compliance training based on their roles and responsibilities.
Training may cover:
The Company shall endeavour to provide induction and periodic refresher training to relevant personnel.
Higher-risk or specialised functions may receive additional role-based training.
Appropriate training records shall be maintained.
Material compliance-related incidents may include:
Material incidents shall be promptly escalated through the Company's authorised internal reporting mechanism.
Depending upon the nature and severity of the incident, the Company may undertake:
The Company may maintain an Incident Register or other appropriate record of material incidents.
The Company may periodically assess the effectiveness of its compliance framework through:
Reviews may consider:
The frequency and scope of reviews shall be proportionate to the Company's size, business activities, risk profile and applicable requirements.
Material deficiencies shall be appropriately documented and corrective measures shall be implemented within reasonable timelines.
Violations of the Company's compliance framework may include:
Depending upon the nature and seriousness of the matter, the Company may take appropriate action, including:
Corrective action shall be proportionate to the circumstances and applicable law.
The Company shall periodically review and improve its AML/CFT compliance framework having regard to:
Policies, procedures and controls may be amended where reasonably necessary to maintain an effective and proportionate compliance framework.
This Manual shall be reviewed periodically and may be amended or replaced by the Company as required.
This Internal AML/CFT Compliance Manual has been approved by the Board of Directors of ZESTFLOW INDIA PRIVATE LIMITED and shall come into effect from the date of its approval.
All Directors, officers, employees, consultants and relevant authorised personnel shall comply with this Manual to the extent applicable to their respective roles and responsibilities.
Merchants, vendors, channel partners and service providers shall comply with the compliance requirements applicable to them under their respective agreements, onboarding requirements and applicable law.
CERTIFICATION
All Directors, officers, employees, consultants and relevant authorised personnel of ZESTFLOW INDIA PRIVATE LIMITED shall comply with this Manual to the extent applicable to their respective roles and responsibilities.
For ZESTFLOW INDIA PRIVATE LIMITED Approved by the Board of Directors on: __________________ Effective Date: __________________