RanaPay

RANAPAY INDIA PRIVATE LIMITED

FRAUD PREVENTION & TRANSACTION MONITORING POLICY

POLICY NO. 05 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyRANAPAY INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
Websiteranapay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerCompliance / Risk / Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes a risk-based framework to prevent, detect, investigate, escalate and respond to fraud and suspicious transaction activity connected with RanaPay's gift card, voucher, virtual product and related payment-enabled activities.

2. REGULATORY ROLE PRINCIPLE

RanaPay shall apply controls appropriate to its actual role. Where transaction monitoring or fraud controls are legally or contractually performed by an authorised PPI issuer, bank or payment partner, RanaPay shall coordinate with that entity and shall not represent that it performs a regulated function unless authorised to do so.

3. OBJECTIVES

  • Prevent misuse of products and systems.
  • Detect suspicious, fraudulent or abnormal activity.
  • Reduce customer and partner losses.
  • Support investigation and evidence preservation.
  • Coordinate with regulated partners.
  • Maintain appropriate monitoring and escalation.
  • Protect customer and transaction information.

4. SCOPE

This Policy applies to employees, operations, fraud/risk teams, customer support, technology teams, partner-management teams and other functions involved in covered products and transactions.

5. FRAUD RISK CATEGORIES

  • Payment fraud
  • Gift-card abuse
  • Voucher redemption abuse
  • Account takeover
  • Identity misuse
  • Credential compromise
  • Refund/reversal abuse
  • Duplicate or synthetic accounts
  • Social-engineering related fraud
  • Merchant/partner fraud
  • API or technology misuse
  • Collusive or coordinated activity

6. FRAUD RISK ASSESSMENT

RanaPay shall periodically assess fraud risks considering product design, transaction flows, customer journey, partner dependencies, channels, technology, historical incidents and emerging fraud patterns.

  1. Identify fraud scenarios.
  2. Assess likelihood and potential impact.
  3. Identify preventive/detective controls.
  4. Assign control owners.
  5. Monitor effectiveness.
  6. Update controls based on incidents and trends.

7. PREVENTIVE CONTROLS

  • Appropriate customer verification
  • Authentication controls
  • Transaction limits where applicable
  • Velocity controls
  • Secure API authentication
  • Role-based access
  • Device/session controls where appropriate
  • Partner validation
  • Customer communication controls

8. TRANSACTION MONITORING

Transaction monitoring shall be proportionate to RanaPay's role and may use automated rules, partner alerts, manual reviews or other approved methods.

  • Transaction velocity
  • Transaction amount patterns
  • Repeated attempts
  • Multiple accounts/instruments
  • Rapid purchase/redemption
  • Unusual refund activity
  • Geographic or channel anomalies where relevant
  • Known fraud indicators
  • Partner-provided risk signals

9. FRAUD RULES & ALERTS

Fraud rules shall be documented, risk-based and periodically reviewed. Alerts shall be prioritised according to severity and potential customer, financial, regulatory or operational impact.

10. ALERT REVIEW PROCESS

  1. Receive/generate alert.
  2. Classify severity.
  3. Review available customer and transaction information.
  4. Check related activity.
  5. Determine whether additional information is required.
  6. Escalate to partner/Compliance where applicable.
  7. Apply appropriate restriction or control.
  8. Document disposition.

11. HIGH-RISK INDICATORS

  • Repeated failed authentication
  • Rapid transactions inconsistent with normal use
  • Multiple accounts sharing suspicious characteristics
  • Unusual redemption patterns
  • Repeated refund requests
  • Known compromised credentials
  • Transaction activity linked to reported fraud
  • Attempts to bypass limits or controls

12. CUSTOMER ACCOUNT PROTECTION

Where technically and contractually applicable, RanaPay may use controls such as step-up verification, temporary restrictions, credential reset, transaction review or partner escalation to protect customers from suspected account compromise.

13. GIFT CARD / VOUCHER FRAUD

  • Unusual bulk purchases
  • Rapid purchase-to-redemption patterns
  • Repeated redemption attempts
  • Multiple instruments used in linked activity
  • Abnormal merchant/brand patterns
  • Resale/abuse indicators
  • Refund manipulation
  • Code or credential compromise

14. INVESTIGATION

Fraud investigations shall be proportionate to the incident and based on available evidence. Investigations may include transaction review, customer communications, partner information, system logs and relevant operational records.

15. EVIDENCE PRESERVATION

  • Transaction records
  • Reference IDs
  • System/API logs
  • Relevant communications
  • Alert history
  • Customer reports
  • Partner communications
  • Screenshots or other evidence where appropriate

Evidence shall be preserved securely and access shall be restricted to authorised personnel.

16. ESCALATION

  • Confirmed or suspected material fraud
  • Significant customer impact
  • Potential financial loss
  • Systemic fraud pattern
  • Partner-related fraud
  • Cybersecurity-linked fraud
  • Potential regulatory/legal breach
  • Law-enforcement request

Material cases shall be escalated to the designated Compliance/Management function and the relevant regulated partner where applicable.

17. CUSTOMER REPORTING & SUPPORT

Customers shall have appropriate channels to report suspected fraud or unauthorised activity. Customer reports shall be recorded, acknowledged and routed for investigation according to applicable procedures.

18. PARTNER COORDINATION

Where a transaction is processed or issued through a PPI issuer, bank or payment partner, RanaPay shall coordinate investigation, transaction status, restrictions, refunds, reversals and evidence sharing as permitted by contract and law.

19. FRAUD CASE MANAGEMENT

Material fraud cases shall have a case reference, owner, status, actions, evidence and closure rationale. Repeated or systemic cases shall be reviewed for control improvements.

20. LOSS & RECOVERY MANAGEMENT

Where fraud results in financial loss, RanaPay shall coordinate with the responsible partner regarding transaction reversal, refund, chargeback, recovery or other available remedy according to applicable rules and contracts.

21. INFORMATION SECURITY LINKAGE

Fraud involving account compromise, malicious activity, credential theft, API abuse or cybersecurity incidents shall also be handled under the Information Security & Cyber Security Policy and Cyber Incident Response & Cyber Fraud Policy.

22. MONITORING EFFECTIVENESS

Fraud controls shall be periodically reviewed using appropriate indicators such as alert volumes, false positives, confirmed fraud, response times, losses, recovery and repeat incidents.

23. REPORTING & MANAGEMENT INFORMATION

  • Fraud incidents
  • Transaction alerts
  • Confirmed cases
  • Customer reports
  • Financial impact
  • Recovery status
  • Partner incidents
  • Control gaps
  • Remediation status

24. TRAINING & AWARENESS

Relevant personnel shall receive periodic fraud-awareness training covering common fraud patterns, customer red flags, escalation procedures, data confidentiality and secure operational practices.

25. THIRD-PARTY / VENDOR CONTROLS

Material vendors and partners supporting payment, transaction processing, APIs, fraud monitoring or customer operations shall be subject to risk-based due diligence and monitoring.

26. AUDIT & TESTING

RanaPay may periodically test fraud controls, review alert handling, sample cases, assess partner arrangements and verify that corrective actions are completed.

27. POLICY EXCEPTIONS

Any internal exception shall be documented, risk-assessed and approved by an authorised function. No exception may bypass mandatory legal, regulatory or partner requirements.

28. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ManagementFraud-risk governance and major decisionsDirector / Authorised Management
Compliance/RiskFramework, monitoring oversight and escalationManagement
Fraud/OperationsAlert review, investigation and case managementCompliance / Management
Technology/SecurityTechnical fraud controls, logs and API securityManagement / Security
Customer SupportCustomer fraud reports and escalationOperations / Fraud
Partner ManagementPartner coordination and contractual controlsCompliance / Management
FinanceLoss, recovery, settlement and reconciliation supportManagement

29. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in fraud risk, products, technology, partner arrangements, applicable requirements or incident trends.

30. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Risk / Operations
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

RANAPAY INDIA PRIVATE LIMITED