RanaPay

RANAPAY INDIA PRIVATE LIMITED

ANTI-MONEY LAUNDERING (AML) & COUNTER-TERRORIST FINANCING (CFT) POLICY

POLICY NO. 04 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyRANAPAY INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
Websiteranapay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerCompliance / Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes RanaPay's framework for identifying, assessing, preventing, escalating and managing money-laundering, terrorist-financing and related financial-crime risks relevant to its actual role, products, partners and applicable legal or contractual obligations.

2. IMPORTANT REGULATORY ROLE PRINCIPLE

RanaPay shall not assume or represent that it is an RBI-regulated PPI issuer or another regulated reporting entity unless it actually holds the relevant authorisation. Where AML/CFT obligations are legally assigned to an authorised PPI issuer, bank or other regulated partner, RanaPay shall follow the documented responsibility model and provide required cooperation.

3. OBJECTIVES

  • Identify AML/CFT risks relevant to RanaPay's business.
  • Prevent misuse of gift-card and payment-related services.
  • Support applicable KYC and customer due diligence.
  • Identify suspicious or unusual activity.
  • Maintain appropriate escalation and investigation processes.
  • Protect transaction and customer information.
  • Maintain required records.
  • Support authorised partners and competent authorities where legally required.

4. SCOPE

This Policy applies to relevant employees, management, operations, compliance, customer support, technology and partner-management functions involved in covered products and transactions.

5. RISK-BASED APPROACH

RanaPay shall apply a risk-based approach proportionate to its role and exposure. Controls shall consider customer, product, transaction, channel, geographic, partner and technology risks where relevant.

  • Customer risk
  • Product risk
  • Transaction risk
  • Channel risk
  • Geographic risk
  • Partner/vendor risk
  • Technology/API risk
  • Fraud and identity risk

6. AML/CFT RESPONSIBILITY MAPPING

For each product or partner arrangement, RanaPay shall document which AML/CFT controls are performed by RanaPay and which are performed by the authorised PPI issuer, bank or other regulated entity.

  • KYC/CDD
  • Screening
  • Transaction monitoring
  • Suspicious activity review
  • Regulatory reporting
  • Record keeping
  • Customer restrictions
  • Law-enforcement response

7. CUSTOMER DUE DILIGENCE

Where CDD/KYC is applicable to RanaPay's role, the controls described in the KYC & Customer Due Diligence Policy shall apply. Where a regulated partner performs CDD, RanaPay shall follow the approved partner process and escalation requirements.

8. PROHIBITED / HIGH-RISK ACTIVITY

RanaPay shall maintain controls to identify and escalate activities that are prohibited by law, partner rules or internal risk controls.

  • Suspected fraud
  • Identity misuse
  • Unusual transaction patterns
  • Attempts to circumvent controls
  • Suspicious use of multiple accounts/instruments
  • Activity inconsistent with known customer/product use
  • Other documented financial-crime indicators

9. TRANSACTION MONITORING

Transaction monitoring shall be proportionate to RanaPay's role and may include rules, alerts, partner-provided monitoring outputs, manual review or other risk-based controls.

  • Unusual transaction frequency
  • Unusual transaction values
  • Repeated failed attempts
  • Multiple accounts or instruments showing linked suspicious behaviour
  • Rapid purchase/redemption patterns
  • Unusual refund/reversal activity
  • Fraud-linked indicators

10. ALERT REVIEW & ESCALATION

  1. Generate or receive alert.
  2. Perform initial review.
  3. Collect relevant transaction/customer information available to RanaPay.
  4. Determine whether escalation is required.
  5. Coordinate with regulated partner where applicable.
  6. Document decision and action.
  7. Close or continue monitoring as appropriate.

11. SANCTIONS / WATCHLIST CONTROLS

Where applicable to RanaPay's role or required by a regulated partner, sanctions, prohibited-party or other screening shall be performed through approved processes. Potential matches shall be escalated for review and shall not be treated as confirmed matches without appropriate verification.

12. SUSPICIOUS ACTIVITY

Potentially suspicious activity shall be assessed using documented criteria and available information. RanaPay shall not make unsupported allegations and shall maintain confidentiality around internal reviews.

13. PARTNER COORDINATION

Where a PPI issuer, bank or payment partner has the primary regulatory responsibility for AML/CFT monitoring or reporting, RanaPay shall provide accurate and timely information required under the applicable agreement and law.

14. REPORTING & LAW-ENFORCEMENT COOPERATION

Where RanaPay has a direct legal reporting obligation, the designated function shall follow the applicable reporting process. Where reporting belongs to a regulated partner, RanaPay shall support the partner with relevant records and information as legally permitted.

15. CUSTOMER RESTRICTIONS / HOLD / BLOCKING

Where permitted and appropriate, RanaPay may restrict an account, transaction, product or service in response to fraud, AML/CFT, partner or legal requirements. Actions shall be documented and escalated.

16. RECORD KEEPING

  • CDD/KYC records
  • Transaction records
  • Monitoring alerts
  • Review/investigation records
  • Partner communications
  • Escalation records
  • Reporting records where applicable
  • Training records
  • Policy and risk assessments

Records shall be retained in accordance with applicable law, partner requirements and the Data Protection, Privacy & Retention Policy.

17. CONFIDENTIALITY

AML/CFT reviews, alerts, investigations and related information shall be handled on a need-to-know basis and protected against unauthorised disclosure, subject to applicable law.

18. EMPLOYEE RESPONSIBILITIES

  • Follow AML/CFT procedures.
  • Complete assigned training.
  • Escalate suspicious or unusual activity.
  • Protect confidential information.
  • Do not bypass monitoring or verification controls.
  • Maintain accurate records.

19. TRAINING & AWARENESS

Relevant personnel shall receive role-based training covering financial-crime risks, KYC/CDD, fraud indicators, escalation procedures, customer confidentiality and applicable partner requirements.

20. THIRD-PARTY / PARTNER RISK

Material partners involved in payment, PPI, KYC, transaction monitoring or other critical functions shall be subject to appropriate due diligence and ongoing oversight under the Third-Party / Vendor Risk Management Policy.

21. MONITORING, TESTING & AUDIT

RanaPay may periodically review AML/CFT controls, transaction-monitoring arrangements, partner responsibilities, alerts, escalations, training and records. Material deficiencies shall be documented and remediated.

22. INCIDENT & FRAUD LINKAGE

AML/CFT concerns involving cyber fraud, account takeover, unauthorised transactions or payment fraud shall also be handled under the applicable Fraud Prevention, Cyber Incident Response and Unauthorised Transaction Policies.

23. ESCALATION

  • Material suspicious activity
  • Potential sanctions/prohibited-party concern
  • Significant fraud
  • Repeated control bypass
  • Material partner failure
  • Regulatory or law-enforcement request
  • Potential legal/regulatory breach

Escalation shall be made to the designated Compliance/Management function and relevant authorised partner as applicable.

24. POLICY EXCEPTIONS

No exception may be used to bypass a mandatory legal or regulatory requirement. Any permitted internal exception shall be documented, risk-assessed and approved by an authorised function.

25. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ManagementOverall AML/CFT governance and risk oversightDirector / Authorised Management
ComplianceAML/CFT framework, monitoring and escalationManagement
OperationsOperational controls and transaction supportCompliance
Fraud/RiskAlert review and risk assessmentCompliance / Management
Partner ManagementRegulated-partner responsibility mapping and coordinationCompliance
Technology/SecurityMonitoring systems, access and data securityManagement / Security
Customer SupportCustomer-related escalation and information supportOperations / Compliance

26. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in applicable requirements, business model, product structure, regulated partner arrangements or financial-crime risk.

27. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Operations
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

RANAPAY INDIA PRIVATE LIMITED