RANAPAY INDIA PRIVATE LIMITED
THIRD-PARTY / VENDOR RISK MANAGEMENT POLICY
POLICY NO. 15 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | RANAPAY INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | ranapay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Compliance / Vendor Management / Information Security |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes the framework for identification, due diligence, onboarding, contracting, monitoring, review and exit of third parties and vendors whose services may affect RanaPay's customers, transactions, information, technology, compliance or business continuity.
2. OBJECTIVES
- Identify third-party risks before engagement.
- Apply risk-based due diligence.
- Define contractual controls and responsibilities.
- Protect customer and company information.
- Monitor vendor performance and security.
- Manage incidents and material changes.
- Ensure orderly termination and data return/deletion.
3. SCOPE
This Policy applies to PPI issuers, banks, payment processors, gift-card/voucher issuers, merchants, technology providers, cloud providers, API providers, consultants, service providers, outsourcing partners and other material third parties.
4. THIRD-PARTY RISK CATEGORIES
- Regulatory/compliance risk
- Financial risk
- Information-security risk
- Data/privacy risk
- Fraud risk
- Operational risk
- Business continuity risk
- Reputational risk
- Concentration/dependency risk
- Legal/contractual risk
5. RISK CLASSIFICATION
- Critical / High – material customer, financial, regulatory, data or operational dependency
- Medium – meaningful operational or information access
- Low – limited access and limited business impact
Risk classification shall consider service criticality, data access, transaction impact, regulatory role, substitutability and dependency.
6. DUE DILIGENCE
- Legal entity and ownership information
- Applicable licences/authorisations where relevant
- Business and service profile
- Financial/operational capability
- Security controls
- Data protection practices
- Business continuity arrangements
- Relevant compliance history where legally and reasonably assessable
- References or experience where appropriate
7. PPI / BANK / REGULATED PARTNER DUE DILIGENCE
Where a third party performs a regulated activity or provides regulated infrastructure, RanaPay shall verify the relevant authorisation/licence or other basis for providing the service, to the extent applicable and reasonably verifiable.
8. INFORMATION SECURITY DUE DILIGENCE
- Security policy
- Access control
- Encryption
- Vulnerability management
- Incident response
- Backup/recovery
- Logging/monitoring
- Security testing where appropriate
9. DATA PRIVACY DUE DILIGENCE
Where a vendor processes personal or confidential information, RanaPay shall assess purpose, data access, security controls, retention, sub-processing and incident notification arrangements as appropriate.
10. FRAUD & FINANCIAL RISK
Vendors involved in transactions, settlement, gift-card issuance/redemption or customer funds-related processes shall be assessed for fraud, reconciliation, financial-control and settlement risks appropriate to the service.
11. APPROVAL BEFORE ONBOARDING
- Business owner submits requirement.
- Risk classification is assigned.
- Due diligence is completed.
- Material gaps are documented.
- Compliance/security/legal review is completed where applicable.
- Commercial and contractual approval is obtained.
- Vendor is onboarded through approved process.
12. CONTRACTUAL REQUIREMENTS
- Scope of services
- Roles and responsibilities
- Service levels
- Security obligations
- Data protection/confidentiality
- Incident notification
- Audit/assessment rights where appropriate
- Subcontracting controls
- Business continuity
- Termination and data return/deletion
- Regulatory cooperation where applicable
13. SERVICE LEVELS
Critical or material vendors shall have documented service expectations, escalation contacts and appropriate service-level arrangements.
14. ACCESS MANAGEMENT
Vendor access shall be limited to the minimum necessary, approved, monitored and revoked when no longer required.
15. API / SYSTEM INTEGRATION
Vendor APIs and integrations shall follow approved security, authentication, credential management, logging and change-management requirements.
16. SUBCONTRACTORS
Material subcontracting shall be disclosed or controlled as required by contract. Vendors shall remain responsible for subcontractors to the extent provided in contractual arrangements.
17. ONGOING MONITORING
- Service performance
- Security incidents
- Compliance changes
- Material ownership changes
- Financial/operational concerns
- Customer complaints
- Audit findings
- Repeated SLA failures
18. PERIODIC REVIEW
High-risk or critical vendors shall be reviewed more frequently and in greater depth than low-risk vendors, based on documented risk assessment.
19. MATERIAL CHANGE MANAGEMENT
Changes in ownership, service scope, technology, processing location, subcontractors, security posture or regulatory status shall be assessed for impact and may trigger re-due diligence.
20. VENDOR INCIDENT MANAGEMENT
Vendor security, fraud, privacy or operational incidents affecting RanaPay or its customers shall be escalated promptly through the relevant incident-management process.
21. BUSINESS CONTINUITY
Critical vendors shall have appropriate continuity and recovery arrangements, or RanaPay shall maintain compensating controls appropriate to the dependency risk.
22. CONCENTRATION & DEPENDENCY RISK
RanaPay shall identify material dependency on a single vendor, partner or technology provider and consider alternatives, contingency arrangements or exit plans where proportionate.
23. CUSTOMER IMPACT
Material vendor issues that may affect customers, transactions, gift-card availability, settlement, privacy or service continuity shall be escalated and managed promptly.
24. AUDIT & ASSURANCE
Where appropriate, RanaPay may request assurance reports, certifications, questionnaires, audit evidence, testing results or other reasonable evidence of control effectiveness.
25. PERFORMANCE MANAGEMENT
- SLA performance
- Availability
- Transaction accuracy
- Support responsiveness
- Security events
- Complaint trends
- Reconciliation exceptions
- Corrective-action status
26. VENDOR REMEDIATION
Material control gaps shall have documented corrective actions, owners and target dates. Unresolved high-risk issues may require management escalation or risk acceptance.
27. SUSPENSION / RESTRICTION
RanaPay may restrict or suspend vendor access or activity where there is a material security, fraud, compliance, operational or contractual risk, subject to applicable agreements and business procedures.
28. TERMINATION / EXIT
- Confirm termination decision.
- Restrict/revoke access.
- Complete pending transactions and settlements.
- Return or securely delete information as required.
- Recover company assets.
- Document outstanding liabilities/issues.
- Complete final risk review.
29. RECORD KEEPING
- Due diligence records
- Approval records
- Contracts
- Security assessments
- SLA reports
- Incident records
- Review results
- Corrective actions
- Termination/exit records
30. CONFIDENTIALITY
Vendor information and due-diligence materials shall be handled according to applicable confidentiality and information-security requirements.
31. EXCEPTIONS
Exceptions shall be documented, risk-assessed and approved by an authorised function. Mandatory legal, regulatory or contractual requirements shall not be overridden.
32. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Business Owner | Business need, vendor performance and relationship management | Management |
| Compliance | Regulatory/compliance due diligence and oversight | Compliance Head |
| Information Security | Security and technology risk assessment | Security/Technology Head |
| Legal | Contractual terms and legal risk | Legal / Management |
| Finance | Financial and settlement-related vendor review | Finance Head |
| Vendor Management | Onboarding, monitoring and records | Management |
| Management | High-risk approval, risk acceptance and termination decisions | Director / Authorised Management |
33. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in vendor risk, business model, partner arrangements, technology or applicable requirements.
34. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Vendor Management / Information Security | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |
