RanaPay

RANAPAY INDIA PRIVATE LIMITED

REGULATORY REPORTING & RECORD-KEEPING POLICY

POLICY NO. 18 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyRANAPAY INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
Websiteranapay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerCompliance / Legal / Operations / Finance
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes the framework for identifying, preparing, reviewing, approving, submitting, storing and retrieving regulatory, statutory, contractual and management records maintained by RanaPay India Private Limited.

2. OBJECTIVES

  • Maintain complete and reliable records.
  • Support applicable legal and regulatory reporting obligations.
  • Ensure reports are accurate, timely and properly approved.
  • Preserve evidence for audits, disputes and investigations.
  • Maintain controlled access and confidentiality.
  • Enable prompt retrieval of records.

3. SCOPE

This Policy applies to regulatory submissions, statutory records, customer and transaction records, KYC/verification records, AML/CFT records, fraud records, settlement and reconciliation records, security records, grievances, contracts, partner records, audit records and other business records required to support RanaPay's activities.

4. REPORTING PRINCIPLES

  • Accuracy
  • Completeness
  • Timeliness
  • Consistency
  • Traceability
  • Confidentiality
  • Authorised approval
  • Evidence-based reporting

5. REGULATORY OBLIGATION IDENTIFICATION

Compliance shall maintain an appropriate register of applicable reporting obligations based on RanaPay's business model, contractual arrangements, applicable law, regulatory status and activities performed through authorised partners.

6. REPORTING CALENDAR

Where applicable, a reporting calendar shall identify the report, recipient, frequency, due date, responsible owner, reviewer and evidence of submission.

7. REPORT PREPARATION

  1. Identify applicable reporting requirement.
  2. Collect source data.
  3. Validate completeness and accuracy.
  4. Prepare report in required format.
  5. Obtain required review/approval.
  6. Submit through the approved channel.
  7. Retain submission evidence.

8. REVIEW & APPROVAL

Material regulatory or statutory reports shall be reviewed by the designated responsible function before submission. Where required, management or an authorised signatory shall approve the report.

9. SUBMISSION CHANNELS

Reports shall be submitted through authorised portals, email channels, partner processes or other officially designated mechanisms, as applicable.

10. SUBMISSION EVIDENCE

  • Acknowledgement/reference number
  • Submission date/time
  • Submitted report
  • Portal confirmation
  • Official communication
  • Approval evidence

11. CORRECTIONS / RE-SUBMISSION

If an error is identified in a submitted report, the responsible function shall assess the impact, escalate as appropriate and make correction or re-submission where required.

12. CUSTOMER & TRANSACTION RECORDS

Customer, transaction, order, redemption, refund, payment-reference and related records shall be retained according to applicable legal, contractual, operational and fraud-prevention requirements.

13. KYC / AML / FRAUD RECORDS

KYC/verification, customer due diligence, AML/CFT review, transaction monitoring, suspicious activity review and fraud investigation records shall be maintained according to applicable requirements and internal policies.

14. SETTLEMENT & RECONCILIATION RECORDS

  • Settlement statements
  • Bank/payment references
  • Partner statements
  • Reconciliation reports
  • Exception records
  • Refund/reversal records
  • Approval and closure evidence

15. GRIEVANCE & DISPUTE RECORDS

Customer complaints, grievance correspondence, dispute records, chargeback records, unauthorised transaction investigations and resolution evidence shall be maintained for the applicable retention period.

16. INFORMATION SECURITY RECORDS

  • Security logs where required
  • Incident reports
  • Access review evidence
  • Vulnerability/security assessment records
  • Backup/recovery test records
  • Cyber incident evidence

17. CONTRACT & PARTNER RECORDS

Executed agreements, amendments, due diligence records, partner communications, SLA records, vendor reviews and termination/exit documentation shall be securely maintained.

18. RECORD CLASSIFICATION

  • Public – approved for public disclosure
  • Internal – business use
  • Confidential – restricted business/customer information
  • Restricted – highly sensitive security, fraud, legal or personal information

19. RECORD OWNERSHIP

Each material record category shall have a responsible business owner who ensures completeness, retention, accessibility and appropriate disposal.

20. RECORD INTEGRITY

Records shall be maintained in a manner that protects them from unauthorised alteration, deletion or destruction. Where appropriate, version control, access logs or other integrity mechanisms shall be used.

21. ELECTRONIC RECORDS

Electronic records shall be stored in approved systems with appropriate access control, backup, security and retention controls.

22. PHYSICAL RECORDS

Where physical records are maintained, they shall be stored securely and protected from unauthorised access, damage, loss or destruction.

23. RETENTION PERIODS

Records shall be retained for the period required by applicable law, regulatory requirements, contractual obligations, legitimate business needs and approved internal schedules. Where requirements differ, the longer applicable period may be followed unless otherwise determined by authorised legal/compliance advice.

24. LEGAL / REGULATORY HOLD

Records subject to litigation, investigation, audit, regulatory review, dispute or other authorised hold shall not be destroyed until the hold is formally released.

25. ACCESS & CONFIDENTIALITY

Access to records shall follow least-privilege and need-to-know principles. Confidential or restricted records shall only be shared with authorised persons or entities for legitimate purposes.

26. DATA PROTECTION

Personal and sensitive information contained in records shall be handled in accordance with the Data Protection, Privacy & Retention Policy and applicable requirements.

27. RECORD RETRIEVAL

Records shall be organised and indexed sufficiently to allow reasonable retrieval for audits, customer matters, partner reconciliation, investigations, legal requirements and management review.

28. AUDIT TRAIL

Material regulatory submissions and controlled records should maintain sufficient evidence to identify who prepared, reviewed, approved, submitted or amended the record, where practicable.

29. AUDIT & INSPECTION

RanaPay shall provide appropriate records and evidence to authorised auditors, regulators, legal advisers or other authorised parties, subject to confidentiality and applicable law.

30. RECORD DISPOSAL

Records shall be securely deleted, destroyed or anonymised when the applicable retention period has expired and no legal, regulatory, contractual or business hold applies.

31. THIRD-PARTY RECORDS

Where records are maintained by a PPI issuer, bank, payment processor, cloud provider or other vendor, contractual arrangements shall address access, availability, confidentiality and retrieval requirements appropriate to the service.

32. BUSINESS CONTINUITY

Critical records shall have appropriate backup and recovery arrangements consistent with the Business Continuity & Disaster Recovery Policy.

33. NON-COMPLIANCE

Missing, inaccurate, unauthorised, altered or improperly disclosed records shall be investigated and corrective action shall be taken as appropriate.

34. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by an authorised function. Mandatory legal or regulatory record-keeping requirements shall not be overridden.

35. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
ComplianceRegulatory obligation register, reporting oversight and evidenceCompliance Head
LegalLegal interpretation, holds and legal record requirementsLegal / Management
FinanceFinancial, settlement and accounting recordsFinance Head
OperationsCustomer, transaction and operational recordsOperations Head
Information Security / ITSecurity, access, system and technical recordsTechnology/Security Head
Vendor ManagementThird-party record requirementsManagement
ManagementMaterial approvals and risk decisionsDirector / Authorised Management

36. TRAINING & AWARENESS

Relevant personnel shall receive appropriate awareness regarding reporting obligations, record accuracy, confidentiality, retention and secure handling.

37. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in RanaPay's business model, partner arrangements, regulatory obligations, systems or applicable requirements.

38. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Legal / Operations / Finance
Reviewed ByRisk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

RANAPAY INDIA PRIVATE LIMITED