JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 13 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Risk / Fraud / Operations / Compliance |
| Review Frequency | At least annually and upon material fraud, product, transaction or partner-risk changes |
| Classification | Confidential – Fraud Prevention & Transaction Monitoring Policy |
This Policy establishes a risk-based framework for preventing, detecting, investigating and managing fraudulent or suspicious transaction activity associated with the Company's gift-card and gift-voucher business, customer accounts, payment channels, redemption activity and relevant partner relationships.
This Policy applies to customer onboarding, purchases, payments, gift-card/voucher issuance, activation, redemption, refunds, account activity, APIs, merchant activity and other transaction processes within the Company's operational scope.
Management shall establish appropriate fraud-risk oversight, risk appetite, resources and accountability. Risk/Fraud, Operations, Technology, Compliance, Finance and Customer Support shall cooperate in fraud prevention and investigation.
The Company shall maintain transaction monitoring controls appropriate to its risk profile and business model. Monitoring may consider transaction value, frequency, velocity, customer behaviour, voucher activity, payment status, account/device indicators and other relevant signals.
Where technology supports risk scoring, transactions or accounts may be assigned risk indicators based on approved rules, models or signals. Risk scores shall support investigation and control decisions and shall be subject to appropriate review.
Alerts shall be prioritised according to potential customer impact, financial exposure, fraud indicators, transaction status, recurrence and other relevant risk factors.
Higher-risk alerts may require manual review. Reviewers shall examine available transaction, customer, account, payment, voucher, device and communication information and document the rationale for the outcome.
Where risk is sufficiently identified, the Company may delay, decline, hold, restrict or otherwise control a transaction or account within its authority and applicable partner arrangements.
Refund and reversal requests may be subject to verification and risk review. Repeated, unusual or inconsistent refund activity shall be escalated for investigation.
Indicators of account takeover may include unusual login behaviour, credential-reset activity, device changes, transaction behaviour or customer reports. Appropriate account protection and escalation measures shall be applied.
Material fraud alerts and investigations shall be assigned an owner and tracked through appropriate case records, including alert reason, evidence, actions, decision and closure.
Investigations shall be evidence-based and may include transaction history, customer communications, authentication information, device indicators, voucher records, payment data, system logs and partner information, as lawfully available.
Where fraud involves a bank, payment processor, PPI, merchant or other partner, the Company shall coordinate with the relevant party for transaction tracing, blocking, reversal, investigation and other appropriate actions.
The Company shall take reasonable steps within its authority to limit further customer loss, secure affected accounts, investigate reported fraud and coordinate appropriate refunds, reversals or partner actions where applicable.
Disputed or unauthorised-transaction claims shall be assessed objectively. The Company shall not automatically conclude that a claim is fraudulent or genuine without reasonable review of available evidence.
Relevant fraud patterns, indicators, confirmed cases and lessons learned may be used to improve fraud rules, monitoring, training and partner controls, subject to confidentiality and applicable data-protection requirements.
Fraud alerts, investigations, evidence references, decisions, communications, restrictions, refunds, reversals and corrective actions shall be retained in accordance with applicable requirements and the Company's record-retention policy.
Fraud monitoring and investigation data shall be collected, accessed, used and retained in accordance with the Company's Data Protection, Privacy, Retention & Record-Keeping Policy.
Fraud rules and monitoring controls should be periodically tested and calibrated using appropriate historical cases, false-positive analysis, emerging fraud patterns and control performance information.
Management may receive reports on fraud attempts, confirmed fraud, prevented losses, alert volumes, false positives, chargebacks, refunds, account restrictions, fraud typologies and remediation.
Relevant employees shall receive periodic training on fraud indicators, escalation, customer handling, transaction controls, social engineering and applicable procedures.
Exceptions shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory and contractual requirements shall continue to apply.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Fraud governance, risk appetite and material decisions | Director / Management |
| Risk / Fraud | Monitoring, alert triage, investigation and fraud controls | Risk/Fraud Head |
| Operations | Transaction review, case handling and operational restrictions | Operations Head |
| Technology | Monitoring systems, rules, logs and technical controls | Technology Head |
| Compliance / AML | Financial-crime coordination and regulatory escalation | Compliance/AML Head |
| Finance | Refunds, reversals and financial reconciliation | Finance Head |
| Customer Support | Customer fraud reports and communication | Support Head |
| Partner Owner | Payment/PPI/bank/merchant coordination | Management |
This Policy shall be reviewed at least annually and whenever there is a material change in fraud trends, products, transaction channels, technology, partner arrangements or applicable requirements.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Risk / Fraud / Operations | |
| Reviewed By | Compliance / Legal / Technology / Finance | |
| Approved By | Director / Authorised Signatory |