JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 07 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Compliance / Risk / Operations |
| Review Frequency | At least annually and upon material legal, product, partner or risk change |
| Classification | Confidential – KYC / Customer Verification Policy |
This Policy establishes a risk-based customer identification and verification framework for JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED. It is designed to support appropriate customer onboarding, fraud prevention, financial-crime risk management, customer protection and applicable legal, regulatory and contractual requirements.
This Policy applies to customer onboarding and verification activities undertaken directly by the Company or through authorised partners, platforms or service providers, to the extent applicable to the Company's role and products.
Depending on the product, channel and applicable requirements, relevant information may include name, contact details, date of birth or incorporation information, address, identification information, account details, transaction information and other information reasonably required for verification.
Where identity documents are required, the Company shall accept only documents and verification methods permitted by applicable requirements and the relevant product or partner arrangement. Copies and records shall be protected against unauthorised access.
Where applicable, customers shall receive appropriate notice regarding collection and use of verification information, and consent shall be obtained where required.
Verification intensity may vary based on customer type, product, transaction risk, account behaviour, fraud indicators, channel, partner requirements and other legitimate risk factors.
Where corporate customers or merchants are onboarded, the Company may obtain appropriate business identity, ownership/control, authorised representative and other information required by applicable requirements and the nature of the relationship.
Where applicable, customers or relevant parties may be screened against legally relevant sanctions, fraud, internal risk or other screening sources. Screening shall be performed in accordance with applicable requirements and the Company's AML/CFT and fraud-control framework.
Where verification cannot be completed or material information is inconsistent, the account, transaction or service may be restricted, delayed, rejected or escalated for manual review, subject to applicable procedures.
Customer risk information may be reviewed periodically or when triggered by material changes, suspicious behaviour, significant transaction activity, fraud indicators, information inconsistencies or relevant partner requirements.
Where ongoing verification or periodic refresh is applicable, customer information shall be reviewed and updated according to risk, product requirements and applicable obligations.
Suspected identity theft, impersonation, account takeover or credential compromise shall be escalated to the appropriate fraud and information-security functions and handled under applicable incident-response procedures.
Where KYC information indicates potential money-laundering, terrorist-financing or other financial-crime risk, the matter shall be escalated under the Company's applicable AML/CFT procedures. KYC controls shall operate together with transaction monitoring and fraud controls.
Where verification is performed by an authorised partner or service provider, the Company shall assess the partner's reliability, contractual responsibilities, data-security controls and evidence availability proportionate to risk.
KYC and identity information shall be handled according to the Company's Data Protection, Privacy, Retention & Record-Keeping Policy and applicable data-protection requirements.
KYC and verification records shall be retained for the period required by applicable law, regulation, contractual obligations, legitimate business needs or audit requirements, subject to legal holds and approved retention procedures.
Access to identity and KYC information shall be restricted to authorised personnel with a legitimate business need. Access should be logged and periodically reviewed where appropriate.
Any exception to standard verification requirements shall be documented, risk-assessed and approved by authorised personnel. Exceptions shall not override mandatory legal, regulatory or partner requirements.
Employees involved in onboarding, customer support, fraud, compliance, operations or transaction processing shall receive appropriate training on KYC procedures, identity fraud indicators, data protection and escalation requirements.
The Company may conduct sample reviews, quality checks, access reviews, partner assessments and control testing to confirm that customer verification is being performed consistently and appropriately.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | KYC governance, risk appetite and material decisions | Director / Management |
| Compliance | KYC framework, regulatory interpretation and escalation | Compliance Head |
| Risk / Fraud | Risk indicators, fraud review and suspicious activity escalation | Risk/Fraud Head |
| Operations | Customer onboarding, verification and record maintenance | Operations Head |
| Technology | Verification systems, access and audit trails | Technology Head |
| Customer Support | Customer KYC requests and issue escalation | Support Head |
| Vendor Management | Third-party KYC provider due diligence | Vendor Owner |
| Legal | Privacy, contractual and legal requirements | Legal Head |
This Policy shall be reviewed at least annually and whenever there is a material change in applicable KYC/AML requirements, products, customer journeys, technology, partners or risk environment.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Risk / Operations | |
| Reviewed By | Legal / Information Security / Technology | |
| Approved By | Director / Authorised Signatory |