RanaPay

RANAPAY INDIA PRIVATE LIMITED

KYC & CUSTOMER DUE DILIGENCE POLICY

POLICY NO. 03 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyRANAPAY INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
Websiteranapay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerCompliance / Management
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes the framework for customer identification, verification and due diligence applicable to RanaPay's business activities, based on RanaPay's actual role, applicable law, product structure and contractual responsibilities with authorised PPI issuers, banks, payment providers and other regulated partners.

2. IMPORTANT ROLE PRINCIPLE

RanaPay shall not assume or represent that it performs a regulated KYC function where the applicable law or partner arrangement places that responsibility with an authorised PPI issuer, bank or other regulated entity. Responsibilities shall be documented for each product and customer journey.

3. OBJECTIVES

  • Establish consistent customer due-diligence standards.
  • Identify and manage customer-related risks.
  • Support fraud prevention and transaction monitoring.
  • Support applicable AML/CFT obligations.
  • Prevent misuse of products and services.
  • Maintain accurate and appropriate records.
  • Protect customer information.
  • Provide escalation for higher-risk cases.

4. SCOPE

This Policy applies to customer onboarding and verification activities performed by RanaPay or by authorised partners on RanaPay's behalf, where applicable, for gift cards, vouchers, virtual products and related payment-enabled services.

5. KYC RESPONSIBILITY MAPPING

Before launch of each relevant product, RanaPay shall document whether KYC/customer due diligence is performed by RanaPay, the PPI issuer, bank/payment partner or another authorised entity.

  • Responsible entity
  • Legal/regulatory basis
  • Information collected
  • Verification method
  • Customer risk assessment
  • Record custodian
  • Escalation responsibility

6. CUSTOMER INFORMATION

Only information reasonably required for the applicable product, legal requirement, fraud/risk control or contractual obligation shall be collected.

  • Customer identification information
  • Contact details where required
  • Transaction-related information
  • Verification evidence where applicable
  • Risk-related information where required

7. CUSTOMER IDENTIFICATION & VERIFICATION

Where RanaPay is responsible for verification, identity information shall be verified using appropriate and reliable methods permitted by applicable law and the relevant product/partner framework.

  1. Collect required information.
  2. Validate information for completeness.
  3. Perform applicable verification.
  4. Record verification outcome.
  5. Escalate discrepancies or risk indicators.
  6. Activate/continue service only when applicable requirements are satisfied.

8. PARTNER-PERFORMED KYC

Where KYC is performed by an authorised PPI issuer, bank or other regulated partner, RanaPay shall follow the agreed customer-data and operational process and shall not duplicate or contradict the partner's regulated KYC process unless required for RanaPay's own lawful responsibilities.

9. CUSTOMER RISK ASSESSMENT

Where risk assessment is applicable to RanaPay's role, customers or transactions may be categorised using relevant risk indicators.

  • Unusual transaction behaviour
  • Repeated failed or suspicious activity
  • High-risk product/channel characteristics
  • Fraud indicators
  • Inconsistent customer information
  • Sanctions or screening alerts where applicable
  • Other documented risk factors

10. ENHANCED DUE DILIGENCE

Where applicable law, partner requirements or documented risk assessment identifies higher risk, enhanced due diligence or additional verification may be applied by the responsible entity.

  • Additional information
  • Additional verification
  • Source or purpose information where legally applicable
  • Senior approval where required
  • Enhanced monitoring
  • Restriction or rejection where appropriate

11. SANCTIONS / WATCHLIST SCREENING

Where screening obligations apply to RanaPay or are performed by a regulated partner, the applicable screening process shall be documented. Potential matches shall be handled through the designated escalation and review process.

12. MINORS / VULNERABLE CUSTOMERS

Product-specific age and eligibility requirements shall be followed. Where a product is not intended for minors or requires additional consent, the applicable customer journey shall contain appropriate controls.

13. BUSINESS / MERCHANT CUSTOMER DUE DILIGENCE

Where RanaPay onboards merchants, brands, corporate customers or business partners, appropriate entity due diligence shall be conducted based on the relationship and risk.

  • Legal entity information
  • Authorised representatives
  • Business activity
  • Relevant registrations/licences where applicable
  • Beneficial ownership information where required
  • Settlement information
  • Risk assessment

14. FRAUD & IDENTITY ABUSE

KYC controls shall be integrated, where appropriate, with fraud-prevention controls to identify identity theft, account takeover, synthetic identities, duplicate accounts, suspicious onboarding or misuse of customer credentials.

15. CUSTOMER DATA PROTECTION

KYC information shall be collected, accessed, stored, shared and retained in accordance with applicable law, contractual requirements and RanaPay's Data Protection, Privacy & Retention Policy.

  • Need-to-know access
  • Secure storage
  • Access logging where appropriate
  • Controlled partner sharing
  • Retention limits
  • Secure disposal

16. KYC RECORDS

  • Customer verification status
  • Verification evidence where permitted/required
  • Risk assessment
  • Escalation records
  • Partner verification confirmation where applicable
  • Customer communications
  • Review/update records

Records shall be maintained for the period required by applicable law, partner requirements and the company's retention schedule.

17. PERIODIC REVIEW / KYC UPDATES

Where ongoing KYC or customer review is applicable, information shall be refreshed when required by law, partner rules, risk triggers or material changes in customer information.

18. KYC FAILURE / INCOMPLETE INFORMATION

Where required information cannot be satisfactorily verified, the responsible function shall not proceed with the applicable activity unless permitted under the relevant legal and partner framework. The case shall be escalated where appropriate.

19. ESCALATION

  • Potential identity fraud
  • Material inconsistencies
  • Screening alert
  • Suspected prohibited activity
  • Repeated suspicious onboarding
  • Partner KYC failure
  • Material customer-risk concern

Escalations shall be documented and handled under applicable AML/CFT, fraud, unauthorised transaction and incident procedures.

20. THIRD-PARTY / PARTNER KYC

Where a third party performs KYC, RanaPay shall maintain appropriate contractual controls, service requirements, data protection requirements and assurance/monitoring arrangements based on risk.

21. TRAINING

Personnel involved in onboarding, customer support, operations, fraud, compliance or partner management shall receive role-appropriate KYC and customer due-diligence training.

22. AUDIT & MONITORING

Compliance or an authorised reviewer may periodically assess KYC controls, sample records, partner performance, exceptions, escalations and data-protection controls.

23. POLICY EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by an authorised function. No exception shall override a mandatory legal or regulatory requirement.

24. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ManagementOverall KYC governance and risk oversightDirector / Authorised Management
ComplianceKYC framework, monitoring and escalationManagement
OperationsCustomer onboarding/process executionCompliance
Partner ManagementPartner KYC responsibility mapping and oversightCompliance / Management
TechnologyKYC/API security and access controlsSecurity / Management
Customer SupportCustomer information support and issue escalationOperations / Compliance

25. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in applicable requirements, product structure, partner responsibilities, customer journey or risk profile.

26. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Operations
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

RANAPAY INDIA PRIVATE LIMITED