JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED
POLICY NO. 04 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Particular | Details |
|---|---|
| Company | JSR ALL-IN-ONE SOLUTIONS PRIVATE LIMITED |
| CIN | U72900UP2021PTC149592 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website / Brand | a2zgiftcard.in |
| Business Model | Gift Card / Gift Voucher business operated through applicable payment, PPI, banking, merchant and technology partners |
| Policy Owner | Risk / Fraud / Operations / Compliance |
| Review Frequency | At least annually and upon material product, risk or partner change |
| Classification | Confidential – Transaction Risk Control Policy |
This Policy establishes risk-based controls for transaction, purchase, issuance, activation, redemption, refund and related activity associated with the Company's gift-card and gift-voucher business. The objective is to reduce fraud, financial loss, operational errors, misuse and customer harm while supporting legitimate transactions.
This Policy applies to customer purchases, voucher issuance, activation, redemption, refunds, cancellations, account activity, partner transactions, payment transactions and other financial or value-related activity handled through Company systems or authorised partners.
Transaction controls shall be proportionate to customer profile, product, transaction value, frequency, velocity, channel, device or account risk, historical behaviour, fraud indicators, partner requirements and applicable legal or regulatory obligations.
Limits shall be approved by authorised management based on product design, customer requirements, fraud risk, operational capacity, partner rules and applicable requirements. System-enforced limits should be used wherever feasible.
Customer or account risk indicators may include account age, verification status, transaction history, failed attempts, unusual activity, device signals, location or channel anomalies, fraud history and other legitimate risk indicators.
High-risk transactions may be subject to additional verification, delayed processing, transaction hold, account restriction, manual review, partner confirmation or rejection, subject to applicable procedures.
Payment transactions shall be processed through authorised channels and may be subject to payment authentication, fraud screening, partner risk controls, transaction status verification and reconciliation.
Refunds and reversals shall be validated against the original transaction and applicable eligibility conditions. High-value, unusual or repeated refund activity may require enhanced review.
A transaction may be placed on hold where there is a reasonable security, fraud, operational, reconciliation or partner-related concern. Holds shall be documented and reviewed within appropriate operational timelines.
Manual review shall assess relevant customer, transaction, voucher, payment and historical information. Decisions shall be documented with the reason, reviewer and outcome for material cases.
Transactions or patterns indicating suspected fraud shall be escalated to the Fraud/Risk function and, where relevant, Cyber Security, Compliance, AML/KYC, Operations, Finance or external partners.
Where transaction activity creates potential financial-crime concerns, the matter shall be handled under applicable AML/CFT and KYC procedures. Transaction-risk controls shall not replace mandatory financial-crime controls.
Where transaction limits are determined by a PPI, bank, payment processor, merchant or other partner, the Company shall implement applicable partner controls within its operational scope and maintain appropriate escalation mechanisms.
Any temporary increase or override of an approved limit shall require authorised approval, documented business reason, defined duration and appropriate risk assessment. Emergency overrides shall be reviewed after the event.
Transaction, voucher, payment, refund and settlement records shall be reconciled as appropriate to identify discrepancies, duplicate processing, missing records or unauthorised changes.
Exceptions shall be documented, risk-assessed and approved by authorised management. Exceptions shall be time-bound where appropriate and shall not override mandatory legal, regulatory or partner requirements.
Material limit approvals, rule changes, alerts, reviews, overrides, investigations and reconciliation results shall be retained according to the Company's record-retention requirements.
Transaction-limit and risk controls shall be periodically tested to confirm correct configuration, effectiveness, alert generation, access control and resistance to inappropriate override.
Relevant employees shall be trained on transaction-risk indicators, limits, fraud escalation, customer handling, voucher controls and exception procedures appropriate to their roles.
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Risk appetite, material limits and policy approvals | Director / Management |
| Risk / Fraud | Risk rules, alerts, investigations and fraud escalation | Risk/Fraud Head |
| Operations | Transaction processing, holds and operational controls | Operations Head |
| Technology | System enforcement, monitoring and rule configuration | Technology Head |
| Finance | Refund, settlement and reconciliation controls | Finance Head |
| Compliance / Legal | Regulatory, AML/KYC and contractual oversight | Compliance/Legal Head |
| Customer Support | Customer communication and complaint escalation | Support Head |
| Partner Owner | Partner limit and payment/PPI coordination | Management |
This Policy shall be reviewed at least annually and whenever there is a material change in products, transaction volumes, fraud patterns, payment arrangements, technology, applicable requirements or risk appetite.
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Risk / Fraud / Operations | |
| Reviewed By | Compliance / Legal / Finance / Technology | |
| Approved By | Director / Authorised Signatory |