Login or Create an account
Or Login Via

RISK MANAGEMENT POLICY

ZESTFLOW INDIA PRIVATE LIMITED (CIN-U62099DC2026PTC468956)

Registered Address - Office No. 201, Plot No 4, 2nd Floor, LSC Gujranwala Colony North West Delhi Delhi India 110009

Risk Management Policy

ZESTFLOW INDIA PRIVATE LIMITED follows a structured risk management framework to identify, assess, mitigate and monitor risks across its business operations. We maintain appropriate controls to manage operational, financial, compliance, technology, cyber-security, fraud and other emerging risks, ensuring business resilience, regulatory compliance and protection of our customers and stakeholders.

1. Purpose and Policy Statement

ZESTFLOW INDIA PRIVATE LIMITED ("ZESTFLOW" or "the Company") is committed to maintaining an effective risk management framework for identifying, assessing, mitigating, monitoring and reporting risks arising from its business activities.

Considering the Company's activities in technology-enabled financial services, digital payment facilitation, merchant onboarding and allied fintech solutions, effective risk management is essential for protecting customers, ensuring business continuity, maintaining compliance and safeguarding the Company's operations, assets and reputation.

Risk management shall form an integral part of the Company's business decisions, operational processes and internal controls.

2. Scope and Applicability

This Policy applies to:

  • the Board of Directors and Senior Management;
  • the Compliance and Risk functions;
  • all departments and business functions;
  • employees, consultants and authorised representatives; and
  • material vendors, service providers and outsourcing partners, where relevant.

Every department and employee shall be responsible for identifying and managing risks within their respective areas of responsibility.

This Policy shall be read together with the Company's other applicable policies, including its AML, CFT, KYC/CDD, information security, fraud prevention and business continuity policies, wherever applicable.

3. Risk Governance and Responsibilities

The Board of Directors shall have overall oversight of the Company's risk management framework and shall approve this Policy.

Senior Management shall:

  • oversee the Company's overall risk profile;
  • ensure implementation of appropriate risk controls;
  • review material and emerging risks; and
  • ensure timely corrective action where necessary.

The Compliance/Risk Function shall:

  • coordinate periodic risk assessments;
  • maintain the Risk Register;
  • monitor significant risks and mitigation measures;
  • report material risks to Senior Management; and
  • recommend improvements to the risk management framework.

Department Heads and Risk Owners shall identify, assess and manage risks within their respective functions and promptly report material risks and incidents.

All employees shall comply with applicable controls and promptly report identified or emerging risks.

4. Risk Categories

The Company may be exposed to various categories of risk, including:

a. Regulatory and Compliance Risk

Risk arising from non-compliance with applicable laws, regulatory requirements, contractual obligations or internal policies.

b. AML/CFT and Financial Crime Risk

Risk of the Company's platform, services or business relationships being misused for money laundering, terrorist financing, fraud or other unlawful activities. Such risks shall also be managed in accordance with the Company's AML, CFT and KYC/CDD Policies.

c. Operational Risk

Risk arising from process failures, human error, inadequate controls, system failures, business interruptions or other operational events.

d. Technology and Cyber Security Risk

Risk arising from cyber-attacks, unauthorised access, data breaches, system vulnerabilities, malware, technology failures or other information-security incidents.

e. Fraud Risk

Risk of financial or operational loss arising from internal or external fraud, identity theft, forged documents, account misuse, merchant fraud or other dishonest activities.

f. Merchant and Partner Risk

Risk arising from merchants, vendors, service providers, outsourcing partners or other third parties, including unlawful activities, service failures, excessive chargebacks or compliance concerns.

g. Financial Risk

Risk arising from liquidity constraints, settlement failures, accounting errors, cash-flow disruptions or other financial exposures.

h. Reputational Risk

Risk of adverse impact on the Company's reputation arising from operational failures, customer grievances, fraud, data breaches, regulatory action or unethical conduct.

The above categories are illustrative and not exhaustive. The Company may identify and manage any additional or emerging risk relevant to its business.

5. Risk Management Process

The Company shall adopt a structured process comprising:

Risk Identification → Risk Assessment → Risk Mitigation → Monitoring → Reporting and Review

Risks may be identified through:

  • business and product reviews;
  • compliance assessments and audits;
  • customer complaints and feedback;
  • fraud and transaction monitoring;
  • incident reporting;
  • technology and cyber-security assessments;
  • regulatory developments; and
  • management reviews.

Each identified risk shall be assessed based on relevant factors, including:

  • likelihood of occurrence;
  • potential financial impact;
  • operational impact;
  • customer impact;
  • regulatory or legal consequences; and
  • reputational impact.

The Company may classify risks as:

  • Low
  • Moderate
  • High
  • Critical

The overall risk rating may be determined using the principle:

Risk Rating = Likelihood × Impact

Risk assessments shall consider the effectiveness of existing controls and the level of residual risk remaining after such controls are applied.

Appropriate mitigation measures shall be implemented based on the nature and severity of the identified risk.

6. Risk Register and Monitoring

The Compliance/Risk Function shall maintain an appropriate Risk Register, which may record:

  • description and category of the risk;
  • responsible Risk Owner;
  • risk rating;
  • existing controls;
  • required mitigation measures;
  • target timelines; and
  • review or closure status.

The Risk Register shall be periodically reviewed and updated to reflect changes in the Company's operations, business environment and risk profile.

Material, High or Critical risks shall be escalated to Senior Management and, where appropriate, to the Board of Directors.

7. Incident Management and Escalation

Material operational, technology, cyber-security, fraud, compliance, financial or other significant incidents shall be promptly reported through the Company's internal escalation mechanism.

Depending upon the nature and severity of the incident, the Company may undertake:

  • immediate containment;
  • investigation and assessment;
  • corrective and preventive action;
  • root-cause analysis;
  • escalation to Senior Management;
  • notification to regulated partners or competent authorities, where required; and
  • measures to prevent recurrence.

Material incidents and corrective actions shall be appropriately documented.

8. Internal Controls and Business Continuity

The Company shall maintain proportionate internal controls to manage identified risks.

Such controls may include:

  • authorisation and approval controls;
  • segregation of duties;
  • maker-checker mechanisms;
  • access and system controls;
  • transaction and activity monitoring;
  • periodic reconciliations;
  • customer and merchant due diligence;
  • vendor and partner oversight;
  • information-security safeguards; and
  • compliance reviews.

The Company shall also maintain appropriate business continuity and recovery arrangements for critical operations, including reasonable measures relating to data backup, disaster recovery, incident response and continuity of essential services.

The nature and extent of controls shall be proportionate to the Company's business activities and identified risks.

9. Compliance, Review and Corrective Action

The Company shall periodically review the effectiveness of its risk management framework and internal controls through management reviews, compliance assessments, audits or other appropriate mechanisms.

Deficiencies and control weaknesses shall be addressed through appropriate corrective and preventive measures.

Failure to comply with this Policy, deliberate concealment of material risks or incidents, circumvention of internal controls, or failure to implement assigned corrective actions may result in appropriate disciplinary, contractual or legal action.

Employees performing relevant functions shall receive appropriate risk management and compliance awareness based on their roles and responsibilities.

10. Policy Review, Approval and Effective Date

This Policy shall be reviewed periodically and, where appropriate, upon:

  • changes in applicable laws or regulatory requirements;
  • material changes in the Company's business model;
  • introduction of new products or services;
  • significant operational or technology changes;
  • material incidents or emerging risks; or
  • findings arising from compliance reviews or audits.

This Risk Management Policy has been approved by the Board of Directors of ZESTFLOW INDIA PRIVATE LIMITED and shall come into effect from the date of its approval.

The Board may amend or replace this Policy from time to time.

CERTIFICATION

All Directors, officers, employees and authorised representatives of ZESTFLOW INDIA PRIVATE LIMITED shall comply with this Policy to the extent applicable to their respective roles and responsibilities.

For ZESTFLOW INDIA PRIVATE LIMITED Approved by the Board of Directors on: __________________ Effective Date: __________________