JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 05 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Management / Vendor Management / Compliance / Risk |
| Review Frequency | At least annually and upon material vendor, product, risk or regulatory change |
| Classification | Confidential – Third-Party / Vendor Risk Policy |
This Policy establishes a risk-based framework for identifying, assessing, approving, onboarding, monitoring and exiting third-party vendors and partners that support JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED, including payment, PPI, banking, merchant, technology, cloud, security, customer-support and other service providers.
This Policy applies to material vendors, service providers, consultants, contractors, technology providers, payment processors, PPI/bank partners, merchants, cloud providers, outsourced service providers and other third parties that may affect Company operations, customers, data, systems or transactions.
Each material vendor shall have an accountable business owner. Risk, Compliance, Information Security, Legal, Finance and Operations shall participate where relevant to the nature and risk of the engagement.
Critical or high-risk vendors may require enhanced assessment, including security assurance, independent certifications or reports where available, financial review, continuity testing, data-flow assessment, management references, penetration-testing information or other evidence proportionate to risk.
No material vendor shall be onboarded without approval through the Company's designated procurement, risk, compliance, legal and management process appropriate to the vendor's risk classification.
Vendor access to Company or customer information shall be limited to the minimum required. Appropriate authentication, access control, encryption, logging and security requirements shall be established according to risk.
Partners involved in payment processing, PPI, banking, gift-card issuance, merchant redemption or settlement shall be subject to appropriate due diligence and contractual arrangements within the Company's operational role.
Critical vendors should have documented service-level expectations and escalation procedures. Material service-level failures shall be recorded, investigated and remediated.
Vendors shall promptly notify the Company of material security incidents affecting Company systems, customer information, transactions or services, subject to applicable contractual and legal requirements.
Critical vendors should maintain appropriate continuity and recovery arrangements. The Company shall assess material dependency and concentration risks and identify alternatives or contingency measures where reasonably practicable.
Material subcontracting that could affect Company data, systems, customers or critical services shall be subject to appropriate disclosure, approval or contractual controls based on risk.
Vendor access to systems and data shall be periodically reviewed. Unnecessary, expired or unauthorised access shall be revoked promptly.
Material vendors may be reviewed for compliance with agreed contractual requirements, security controls, privacy obligations, service levels and applicable legal requirements.
Material security incidents, repeated service failures, significant financial deterioration, compliance concerns, data breaches or other serious vendor risks shall be escalated to Management and relevant control functions.
The Company may request appropriate assurance documentation, assessments, audit reports, certifications or other evidence from material vendors, subject to contractual arrangements and proportionality.
Material vendors should be recorded in a vendor risk register containing ownership, service description, risk classification, criticality, contract status, review date, key controls and open issues.
Vendor risk shall be reviewed periodically based on criticality and risk. High-risk vendors should receive more frequent review than low-risk vendors.
Management shall consider reliance on a single vendor, payment partner, cloud provider, merchant or other critical service provider. Material concentration risks should have mitigation or contingency measures where practicable.
Any exception to this Policy shall be documented, risk-assessed and approved by authorised management. Mandatory legal, regulatory and contractual requirements shall not be waived through an internal exception.
Due-diligence records, contracts, approvals, risk assessments, reviews, incidents, performance records, audit evidence and exit documentation shall be retained according to the Company's record-retention requirements.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Material vendor approval, risk acceptance and strategic decisions | Director / Management |
| Vendor Owner | Business need, performance and relationship management | Functional Head |
| Risk / Fraud | Vendor risk assessment and risk monitoring | Risk Head |
| Information Security | Security due diligence and cyber requirements | Security Head |
| Compliance / Legal | Regulatory, contractual, privacy and compliance review | Compliance/Legal Head |
| Finance | Commercial, settlement and financial assessment | Finance Head |
| Technology | Technical integration, access and service dependencies | Technology Head |
| Operations | Service delivery, reconciliation and operational monitoring | Operations Head |
This Policy shall be reviewed at least annually and whenever there is a material change in vendor relationships, products, technology, regulatory requirements, security risks or business operations.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Vendor Management / Risk / Compliance | |
| Reviewed By | Legal / Information Security / Finance / Technology | |
| Approved By | Director / Authorised Signatory |