RANAPAY INDIA PRIVATE LIMITED
KYC & CUSTOMER DUE DILIGENCE POLICY
POLICY NO. 03 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | RANAPAY INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | ranapay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Compliance / Management |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes the framework for customer identification, verification and due diligence applicable to RanaPay's business activities, based on RanaPay's actual role, applicable law, product structure and contractual responsibilities with authorised PPI issuers, banks, payment providers and other regulated partners.
2. IMPORTANT ROLE PRINCIPLE
RanaPay shall not assume or represent that it performs a regulated KYC function where the applicable law or partner arrangement places that responsibility with an authorised PPI issuer, bank or other regulated entity. Responsibilities shall be documented for each product and customer journey.
3. OBJECTIVES
- Establish consistent customer due-diligence standards.
- Identify and manage customer-related risks.
- Support fraud prevention and transaction monitoring.
- Support applicable AML/CFT obligations.
- Prevent misuse of products and services.
- Maintain accurate and appropriate records.
- Protect customer information.
- Provide escalation for higher-risk cases.
4. SCOPE
This Policy applies to customer onboarding and verification activities performed by RanaPay or by authorised partners on RanaPay's behalf, where applicable, for gift cards, vouchers, virtual products and related payment-enabled services.
5. KYC RESPONSIBILITY MAPPING
Before launch of each relevant product, RanaPay shall document whether KYC/customer due diligence is performed by RanaPay, the PPI issuer, bank/payment partner or another authorised entity.
- Responsible entity
- Legal/regulatory basis
- Information collected
- Verification method
- Customer risk assessment
- Record custodian
- Escalation responsibility
6. CUSTOMER INFORMATION
Only information reasonably required for the applicable product, legal requirement, fraud/risk control or contractual obligation shall be collected.
- Customer identification information
- Contact details where required
- Transaction-related information
- Verification evidence where applicable
- Risk-related information where required
7. CUSTOMER IDENTIFICATION & VERIFICATION
Where RanaPay is responsible for verification, identity information shall be verified using appropriate and reliable methods permitted by applicable law and the relevant product/partner framework.
- Collect required information.
- Validate information for completeness.
- Perform applicable verification.
- Record verification outcome.
- Escalate discrepancies or risk indicators.
- Activate/continue service only when applicable requirements are satisfied.
8. PARTNER-PERFORMED KYC
Where KYC is performed by an authorised PPI issuer, bank or other regulated partner, RanaPay shall follow the agreed customer-data and operational process and shall not duplicate or contradict the partner's regulated KYC process unless required for RanaPay's own lawful responsibilities.
9. CUSTOMER RISK ASSESSMENT
Where risk assessment is applicable to RanaPay's role, customers or transactions may be categorised using relevant risk indicators.
- Unusual transaction behaviour
- Repeated failed or suspicious activity
- High-risk product/channel characteristics
- Fraud indicators
- Inconsistent customer information
- Sanctions or screening alerts where applicable
- Other documented risk factors
10. ENHANCED DUE DILIGENCE
Where applicable law, partner requirements or documented risk assessment identifies higher risk, enhanced due diligence or additional verification may be applied by the responsible entity.
- Additional information
- Additional verification
- Source or purpose information where legally applicable
- Senior approval where required
- Enhanced monitoring
- Restriction or rejection where appropriate
11. SANCTIONS / WATCHLIST SCREENING
Where screening obligations apply to RanaPay or are performed by a regulated partner, the applicable screening process shall be documented. Potential matches shall be handled through the designated escalation and review process.
12. MINORS / VULNERABLE CUSTOMERS
Product-specific age and eligibility requirements shall be followed. Where a product is not intended for minors or requires additional consent, the applicable customer journey shall contain appropriate controls.
13. BUSINESS / MERCHANT CUSTOMER DUE DILIGENCE
Where RanaPay onboards merchants, brands, corporate customers or business partners, appropriate entity due diligence shall be conducted based on the relationship and risk.
- Legal entity information
- Authorised representatives
- Business activity
- Relevant registrations/licences where applicable
- Beneficial ownership information where required
- Settlement information
- Risk assessment
14. FRAUD & IDENTITY ABUSE
KYC controls shall be integrated, where appropriate, with fraud-prevention controls to identify identity theft, account takeover, synthetic identities, duplicate accounts, suspicious onboarding or misuse of customer credentials.
15. CUSTOMER DATA PROTECTION
KYC information shall be collected, accessed, stored, shared and retained in accordance with applicable law, contractual requirements and RanaPay's Data Protection, Privacy & Retention Policy.
- Need-to-know access
- Secure storage
- Access logging where appropriate
- Controlled partner sharing
- Retention limits
- Secure disposal
16. KYC RECORDS
- Customer verification status
- Verification evidence where permitted/required
- Risk assessment
- Escalation records
- Partner verification confirmation where applicable
- Customer communications
- Review/update records
Records shall be maintained for the period required by applicable law, partner requirements and the company's retention schedule.
17. PERIODIC REVIEW / KYC UPDATES
Where ongoing KYC or customer review is applicable, information shall be refreshed when required by law, partner rules, risk triggers or material changes in customer information.
18. KYC FAILURE / INCOMPLETE INFORMATION
Where required information cannot be satisfactorily verified, the responsible function shall not proceed with the applicable activity unless permitted under the relevant legal and partner framework. The case shall be escalated where appropriate.
19. ESCALATION
- Potential identity fraud
- Material inconsistencies
- Screening alert
- Suspected prohibited activity
- Repeated suspicious onboarding
- Partner KYC failure
- Material customer-risk concern
Escalations shall be documented and handled under applicable AML/CFT, fraud, unauthorised transaction and incident procedures.
20. THIRD-PARTY / PARTNER KYC
Where a third party performs KYC, RanaPay shall maintain appropriate contractual controls, service requirements, data protection requirements and assurance/monitoring arrangements based on risk.
21. TRAINING
Personnel involved in onboarding, customer support, operations, fraud, compliance or partner management shall receive role-appropriate KYC and customer due-diligence training.
22. AUDIT & MONITORING
Compliance or an authorised reviewer may periodically assess KYC controls, sample records, partner performance, exceptions, escalations and data-protection controls.
23. POLICY EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by an authorised function. No exception shall override a mandatory legal or regulatory requirement.
24. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Overall KYC governance and risk oversight | Director / Authorised Management |
| Compliance | KYC framework, monitoring and escalation | Management |
| Operations | Customer onboarding/process execution | Compliance |
| Partner Management | Partner KYC responsibility mapping and oversight | Compliance / Management |
| Technology | KYC/API security and access controls | Security / Management |
| Customer Support | Customer information support and issue escalation | Operations / Compliance |
25. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in applicable requirements, product structure, partner responsibilities, customer journey or risk profile.
26. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Operations | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |
