JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 10 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Compliance / AML / Risk |
| Review Frequency | At least annually and upon material legal, regulatory, product or risk change |
| Classification | Confidential – AML / CFT Policy |
This Policy establishes a risk-based framework for preventing and identifying potential money laundering, terrorist financing and other financial-crime risks relevant to the Company's business, products, customers, transactions and authorised partners. The Policy shall be applied to the extent relevant to the Company's legal status, business model, regulatory obligations and contractual role.
This Policy applies to applicable customer onboarding, transaction processing, gift-card/voucher activity, payment relationships, merchant or corporate relationships, partner interactions, employees and third parties within the Company's operational and legal scope.
AML/CFT controls shall be proportionate to identified risk. Risk factors may include customer type, product, transaction behaviour, geography, delivery or redemption patterns, payment method, partner relationship, unusual activity and other legally relevant indicators.
Where applicable, customer due diligence shall be conducted in accordance with the Company's KYC / Customer Verification Policy and applicable requirements. Information shall be collected and verified proportionately to risk.
Enhanced due diligence may be applied to higher-risk customers, transactions, products or relationships, including additional information, verification, management review, enhanced monitoring or other appropriate controls.
Where applicable, relevant customers, counterparties or transactions may be screened against legally relevant sanctions, watchlists, internal risk indicators and other appropriate sources. Screening shall be performed through authorised processes.
The Company shall consider risks arising from rapid voucher issuance, resale or redemption, unusual concentration, suspicious payment activity, abnormal refund patterns, account misuse and other patterns that may indicate fraud or financial crime.
Alerts generated through transaction monitoring, partner notifications, customer complaints or other sources shall be reviewed by appropriately authorised personnel. Material cases shall be documented and escalated.
Where activity creates a reasonable concern of money laundering, terrorist financing or another financial crime, the matter shall be escalated to the designated Compliance/AML function for assessment and appropriate action.
Where the Company is legally required or otherwise authorised to make a report or disclosure to a competent authority, such reporting shall be handled by authorised personnel in accordance with applicable requirements. The Company shall not make unauthorised disclosures about confidential investigations.
Information concerning suspicious activity reviews, investigations or regulatory reports shall be handled confidentially. Personnel shall not disclose restricted information to customers or other persons where such disclosure is prohibited or could compromise an investigation.
Relevant KYC, transaction, monitoring, investigation, escalation and reporting records shall be retained for periods required by applicable law, regulation, contractual requirements or legitimate business needs, subject to legal holds.
Customer or relationship risk shall be reassessed where material changes, unusual activity, significant transaction patterns, adverse information or other relevant risk indicators arise.
Where AML/CFT-relevant activities are performed by a bank, PPI, payment processor, merchant, KYC provider or other partner, the Company shall apply appropriate due diligence and contractual oversight consistent with its role.
AML/CFT controls shall operate alongside fraud prevention, transaction monitoring, KYC and cyber-fraud controls. Suspected cyber-enabled financial crime shall be escalated under applicable fraud and incident-response procedures.
Relevant employees shall receive periodic training appropriate to their roles, including financial-crime risks, red flags, KYC requirements, transaction monitoring, escalation, confidentiality and record keeping.
The Company may conduct periodic control reviews, sample testing, risk assessments, monitoring-rule reviews and other assurance activities to evaluate the effectiveness of its AML/CFT framework.
Management may receive appropriate AML/CFT information, including risk assessments, alert volumes, material cases, control issues, training status and remediation actions, while protecting confidential information.
Exceptions shall be documented, risk-assessed and approved by authorised management. No internal exception shall override mandatory legal or regulatory obligations.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | AML/CFT governance, risk appetite and material decisions | Director / Management |
| Compliance / AML | AML framework, risk assessment, escalation and regulatory coordination | AML/Compliance Head |
| Risk / Fraud | Transaction monitoring, fraud indicators and investigations | Risk/Fraud Head |
| KYC / Operations | Customer verification and record maintenance | Operations Head |
| Technology | Monitoring systems, rules, access and audit trails | Technology Head |
| Finance | Transaction, refund and settlement information | Finance Head |
| Customer Support | Customer complaints and suspicious-activity escalation | Support Head |
| Vendor Management | Third-party AML/KYC control oversight | Vendor Owner |
| Legal | Legal interpretation and confidentiality matters | Legal Head |
This Policy shall be reviewed at least annually and whenever there is a material change in applicable AML/CFT requirements, business model, products, transaction patterns, partners, technology or risk environment.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / AML / Risk | |
| Reviewed By | Legal / Operations / Technology / Finance | |
| Approved By | Director / Authorised Signatory |