Login or Create an account
Or Login Via

ANTI-MONEY LAUNDERING (AML) POLICY

ZESTFLOW INDIA PRIVATE LIMITED (CIN-U62099DC2026PTC468956)

(Prepared in accordance with the Prevention of Money Laundering Act, 2002, the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, applicable)

Registered Address - Office No. 201, Plot No 4, 2nd Floor, LSC Gujranwala Colony North West Delhi Delhi India 110009

Anti-Money Laundering (AML) Policy

ZESTFLOW INDIA PRIVATE LIMITED is committed to maintaining the highest standards of integrity, transparency and regulatory compliance. We follow a risk-based AML framework, including appropriate KYC and due diligence measures, to prevent the misuse of our platform and services for money laundering, terrorist financing or other unlawful activities. We monitor relevant activities, identify and escalate suspicious transactions, maintain appropriate records and cooperate with regulated partners and competent authorities, wherever required under applicable law. Our AML framework is periodically reviewed and updated to ensure continued effectiveness and compliance.

1. Purpose and Policy Statement

ZESTFLOW INDIA PRIVATE LIMITED ("ZESTFLOW" or "the Company") is committed to conducting its business with integrity, transparency and in compliance with applicable laws. Considering the Company's activities in the field of technology-enabled financial services, digital payment facilitation, merchant onboarding and allied fintech solutions, the Company recognises the risks associated with money laundering, terrorist financing and other unlawful financial activities. This Anti-Money Laundering ("AML") Policy establishes a risk-based framework for identifying, assessing, preventing and mitigating such risks and for ensuring compliance with applicable legal, regulatory and contractual obligations. The Company shall not knowingly permit its platform, services, technology infrastructure or business relationships to be used for money laundering, terrorist financing or any other unlawful purpose.

2. Scope and Applicability

This Policy applies to:

  • the Board of Directors;
  • Designated Director or Principal Officer, where required under applicable law;
  • Compliance Officer and senior management;
  • all employees, consultants and authorised representatives;
  • merchants, channel partners and business correspondents, wherever applicable;
  • vendors and service providers involved in onboarding, payment processing or other material operations; and
  • any other person acting on behalf of the Company.

The extent of AML obligations applicable to the Company shall depend upon its business activities, regulatory status and arrangements with banks, financial institutions, payment service providers and other regulated entities. Where the Company acts on behalf of or in association with a regulated entity, it shall comply with the applicable AML/KYC requirements communicated by such regulated entity, in addition to its own obligations under applicable law.

3. Regulatory Framework

This Policy shall be interpreted in accordance with, to the extent applicable:

  • the Prevention of Money Laundering Act, 2002 ("PMLA");
  • the Prevention of Money Laundering (Maintenance of Records) Rules, 2005;
  • applicable notifications, directions and advisories issued by the Government of India and Financial Intelligence Unit-India ("FIU-IND");
  • applicable directions and guidelines issued by the Reserve Bank of India ("RBI"), wherever applicable to the Company or its business arrangements;
  • applicable sanctions and prohibited-person lists notified under Indian law; and
  • any amendment, modification or replacement of the above.

Where any provision of this Policy conflicts with applicable law, the applicable law shall prevail.

4. Key Definitions

  • Money Laundering: Any process or activity connected with proceeds of crime, including concealment, possession, acquisition, use or projection of such proceeds as untainted property.
  • Customer/Merchant: Any individual or entity seeking to establish or maintain a business relationship with the Company.
  • Beneficial Owner: The natural person who ultimately owns, controls or exercises effective control over a customer or entity, as determined under applicable law.
  • Customer Due Diligence ("CDD"): The process of identifying and verifying a customer or merchant and understanding the nature and purpose of the proposed business relationship.
  • Politically Exposed Person ("PEP"): A person entrusted with prominent public functions and such other persons connected with them as may be covered under applicable law or regulatory requirements.
  • Suspicious Activity/Transaction: Any actual or attempted activity or transaction that appears unusual, lacks an apparent lawful or economic purpose, is inconsistent with the known profile of the customer or merchant, or otherwise gives rise to reasonable suspicion of money laundering, terrorist financing or unlawful activity.

5. AML Governance and Responsibilities

The Board of Directors shall have overall oversight of the Company's AML framework and shall approve this Policy and material amendments thereto. The Company shall designate an appropriate officer or compliance function responsible for:

  • implementation of this Policy;
  • overseeing customer and merchant due diligence;
  • reviewing AML-related alerts and suspicious activities;
  • maintaining relevant records;
  • coordinating with regulated partner institutions and competent authorities, where required;
  • arranging appropriate employee training; and
  • periodically reviewing the effectiveness of AML controls.

Where the Company is legally required to appoint a Designated Director or Principal Officer or to make direct regulatory filings, such appointments and filings shall be made in accordance with applicable law. All employees and authorised representatives shall comply with this Policy and promptly report identified AML concerns to the designated compliance function.

6. Risk-based Approach

The Company shall adopt a Risk-Based Approach for assessing and managing money laundering and terrorist financing risks. Risk assessment may take into account:

  • nature and legal constitution of the customer or merchant;
  • nature of business or occupation;
  • ownership and beneficial ownership structure;
  • expected transaction volume and frequency;
  • geographical exposure;
  • products and services used;
  • mode of onboarding;
  • source of funds, where appropriate;
  • transaction behaviour;
  • regulatory or compliance history; and
  • any other relevant risk factor.

Customers and merchants may be classified as Low, Medium or High Risk based on the overall risk assessment. Risk classification shall be reviewed periodically and may be revised where there is a material change in the customer's profile, ownership, business activity or transaction behaviour.

7. Customer and Merchant Acceptance

The Company shall establish a business relationship only after completing appropriate due diligence. The Company shall not knowingly establish or continue a relationship with:

  • anonymous or fictitious persons;
  • persons unwilling to provide required KYC information;
  • persons providing false, forged or materially misleading information;
  • persons appearing on applicable sanctions or prohibited lists;
  • persons suspected of involvement in unlawful financial activities; or
  • persons whose identity or business activities cannot reasonably be verified.

The Company may reject, restrict, suspend or terminate a relationship where satisfactory due diligence cannot be completed, subject to applicable law and contractual obligations.

8. Customer Due Diligence and Beneficial Ownership

Before onboarding a customer or merchant, the Company shall obtain and verify appropriate information, which may include:

  • name and date of birth or incorporation;
  • PAN;
  • Aadhaar, where lawfully permitted and applicable, or other officially valid documents;
  • address and contact details;
  • business registration and GST details, where applicable;
  • bank account details;
  • nature of business or occupation;
  • ownership and beneficial ownership information;
  • regulatory registrations, where applicable;
  • expected transaction profile; and
  • such other information as may reasonably be required.

The Company may use legally permissible electronic or digital verification mechanisms. For non-individual customers, reasonable steps shall be taken to identify and verify the beneficial owner(s) in accordance with applicable law. CDD shall be an ongoing process. Updated information may be sought where there is a material change in the customer's profile, ownership, business activity or transaction pattern.

9. Enhanced Due Diligence and Screening

Customers or merchants presenting higher AML/CFT risk shall be subject to Enhanced Due Diligence ("EDD").

EDD measures may include:

  • obtaining additional documents or information;
  • enhanced verification of identity and beneficial ownership;
  • verification of source of funds or source of wealth, where appropriate;
  • senior management approval;
  • screening against applicable sanctions and watchlists;
  • enhanced transaction monitoring; and
  • more frequent review of the business relationship.

PEPs and other higher-risk relationships shall be subject to enhanced scrutiny in accordance with applicable law and the Company's risk assessment. A person shall not be classified as high-risk solely on the basis of wealth, nationality or legal constitution without considering the overall risk profile.

10. Merchant, Vendor and Partner Due Diligence

The Company shall undertake proportionate due diligence before onboarding material merchants, channel partners, vendors or service providers. Such due diligence may include verification of:

  • identity and business registration;
  • PAN and GST registration, where applicable;
  • bank account details;
  • business address and nature of business;
  • ownership and beneficial ownership;
  • applicable regulatory registrations; and
  • adverse information or compliance concerns.

The level of due diligence shall be proportionate to the nature and risk of the relationship.

11. Transaction Monitoring and Red Flags

The Company shall maintain appropriate systems and procedures to identify unusual or potentially suspicious activities. Monitoring may consider:

  • transaction value and frequency;
  • unusual payment or settlement patterns;
  • unexplained refunds or chargebacks;
  • transactions inconsistent with the declared business profile;
  • unrelated third-party payments;
  • rapid movement of funds;
  • unusual changes in transaction volume;
  • linked accounts, devices or other indicators;
  • geographical inconsistencies; and
  • any other relevant red flag.

The Company may use automated systems, rule-based alerts, manual reviews or a combination thereof, depending upon its business and operational requirements. Illustrative red flags are provided in Annexure I.

12. Suspicious Activity Escalation and Reporting

Any employee or authorised person who identifies suspicious activity shall promptly report the matter to the designated compliance officer or function along with available information and supporting records. The designated officer shall review the matter and may seek additional information without unnecessarily alerting the concerned customer or merchant. Where the Company is directly required by law to report a suspicious transaction or activity to FIU-IND or another competent authority, the prescribed report shall be filed within the applicable timeline. Where reporting obligations are undertaken by a regulated partner institution, the Company shall promptly escalate relevant information to such institution in accordance with applicable law and contractual arrangements. No person shall disclose to a customer or unauthorised third party that:

  • a suspicious activity is under review;
  • an internal investigation is being conducted;
  • a regulatory report has been or may be filed; or
  • information has been provided to a competent authority,

except where disclosure is required by law.

13. Record Retention, Confidentiality and Data Protection

The Company shall maintain appropriate records relating to:

  • KYC and due diligence;
  • beneficial ownership;
  • merchant and partner onboarding;
  • transactions, where applicable;
  • risk assessments;
  • suspicious activity reviews;
  • regulatory or partner communications; and
  • AML training and compliance reviews.

Records shall be retained for the period required under applicable law, regulatory requirements and contractual obligations. AML and customer information shall be protected through appropriate administrative, technical and organisational safeguards and shall be accessible only to authorised persons on a need-to-know basis.

14. Employee Training and Compliance Review

Employees performing relevant functions shall receive appropriate AML/CFT awareness and training based on their roles and responsibilities. Training may cover:

  • applicable AML/CFT requirements;
  • KYC and due diligence procedures;
  • identification of red flags;
  • internal escalation procedures;
  • confidentiality and prohibition of tipping-off; and
  • consequences of non-compliance.

The Company shall periodically review the effectiveness of its AML controls and take appropriate corrective measures where deficiencies are identified.

15. Violations and Corrective Action

Failure to comply with this Policy may result in appropriate disciplinary or corrective action, including:

  • warning or retraining;
  • restriction or withdrawal of system access;
  • suspension or termination of employment or engagement;
  • suspension or termination of a merchant, vendor or partner relationship; and
  • reporting to competent authorities, where required by law.

The nature of the action shall depend upon the seriousness of the violation and applicable law.

16. Regulatory Cooperation

The Company shall cooperate with FIU-IND, law enforcement agencies, regulated partner institutions and other competent authorities to the extent required under applicable law and contractual obligations. Information and records shall be provided only through authorised channels and in accordance with applicable legal requirements.

17. Policy Review, Approval and Effective Date

This Policy shall be reviewed periodically and, where appropriate, upon:

  • changes in applicable laws or regulatory requirements;
  • introduction of new products or services;
  • material changes in the Company's business model;
  • significant AML-related incidents; or
  • findings arising from compliance reviews or audits.

This Policy has been approved by the Board of Directors of ZESTFLOW INDIA PRIVATE LIMITED and shall come into effect from the date of its approval. The Board may amend or replace this Policy from time to time. CERTIFICATION

All Directors, officers, employees and authorised representatives of ZESTFLOW INDIA PRIVATE LIMITED shall comply with this Policy to the extent applicable to their respective roles and responsibilities.

For ZESTFLOW INDIA PRIVATE LIMITED Approved by the Board of Directors on: __________________ Effective Date:___________________