Login or Signup
and Grab Exclusive deals
Registered Address - Office No. 201, Plot No 4, 2nd Floor, LSC Gujranwala Colony North West Delhi Delhi India 110009
ZESTFLOW INDIA PRIVATE LIMITED follows a structured risk management framework to identify, assess, mitigate and monitor risks across its business operations. We maintain appropriate controls to manage operational, financial, compliance, technology, cyber-security, fraud and other emerging risks, ensuring business resilience, regulatory compliance and protection of our customers and stakeholders.
ZESTFLOW INDIA PRIVATE LIMITED ("ZESTFLOW" or "the Company") is committed to maintaining an effective risk management framework for identifying, assessing, mitigating, monitoring and reporting risks arising from its business activities.
Considering the Company's activities in technology-enabled financial services, digital payment facilitation, merchant onboarding and allied fintech solutions, effective risk management is essential for protecting customers, ensuring business continuity, maintaining compliance and safeguarding the Company's operations, assets and reputation.
Risk management shall form an integral part of the Company's business decisions, operational processes and internal controls.
This Policy applies to:
Every department and employee shall be responsible for identifying and managing risks within their respective areas of responsibility.
This Policy shall be read together with the Company's other applicable policies, including its AML, CFT, KYC/CDD, information security, fraud prevention and business continuity policies, wherever applicable.
The Board of Directors shall have overall oversight of the Company's risk management framework and shall approve this Policy.
Senior Management shall:
The Compliance/Risk Function shall:
Department Heads and Risk Owners shall identify, assess and manage risks within their respective functions and promptly report material risks and incidents.
All employees shall comply with applicable controls and promptly report identified or emerging risks.
The Company may be exposed to various categories of risk, including:
a. Regulatory and Compliance Risk
Risk arising from non-compliance with applicable laws, regulatory requirements, contractual obligations or internal policies.
b. AML/CFT and Financial Crime Risk
Risk of the Company's platform, services or business relationships being misused for money laundering, terrorist financing, fraud or other unlawful activities. Such risks shall also be managed in accordance with the Company's AML, CFT and KYC/CDD Policies.
c. Operational Risk
Risk arising from process failures, human error, inadequate controls, system failures, business interruptions or other operational events.
d. Technology and Cyber Security Risk
Risk arising from cyber-attacks, unauthorised access, data breaches, system vulnerabilities, malware, technology failures or other information-security incidents.
e. Fraud Risk
Risk of financial or operational loss arising from internal or external fraud, identity theft, forged documents, account misuse, merchant fraud or other dishonest activities.
f. Merchant and Partner Risk
Risk arising from merchants, vendors, service providers, outsourcing partners or other third parties, including unlawful activities, service failures, excessive chargebacks or compliance concerns.
g. Financial Risk
Risk arising from liquidity constraints, settlement failures, accounting errors, cash-flow disruptions or other financial exposures.
h. Reputational Risk
Risk of adverse impact on the Company's reputation arising from operational failures, customer grievances, fraud, data breaches, regulatory action or unethical conduct.
The above categories are illustrative and not exhaustive. The Company may identify and manage any additional or emerging risk relevant to its business.
The Company shall adopt a structured process comprising:
Risk Identification → Risk Assessment → Risk Mitigation → Monitoring → Reporting and Review
Risks may be identified through:
Each identified risk shall be assessed based on relevant factors, including:
The Company may classify risks as:
The overall risk rating may be determined using the principle:
Risk Rating = Likelihood × Impact
Risk assessments shall consider the effectiveness of existing controls and the level of residual risk remaining after such controls are applied.
Appropriate mitigation measures shall be implemented based on the nature and severity of the identified risk.
The Compliance/Risk Function shall maintain an appropriate Risk Register, which may record:
The Risk Register shall be periodically reviewed and updated to reflect changes in the Company's operations, business environment and risk profile.
Material, High or Critical risks shall be escalated to Senior Management and, where appropriate, to the Board of Directors.
Material operational, technology, cyber-security, fraud, compliance, financial or other significant incidents shall be promptly reported through the Company's internal escalation mechanism.
Depending upon the nature and severity of the incident, the Company may undertake:
Material incidents and corrective actions shall be appropriately documented.
The Company shall maintain proportionate internal controls to manage identified risks.
Such controls may include:
The Company shall also maintain appropriate business continuity and recovery arrangements for critical operations, including reasonable measures relating to data backup, disaster recovery, incident response and continuity of essential services.
The nature and extent of controls shall be proportionate to the Company's business activities and identified risks.
The Company shall periodically review the effectiveness of its risk management framework and internal controls through management reviews, compliance assessments, audits or other appropriate mechanisms.
Deficiencies and control weaknesses shall be addressed through appropriate corrective and preventive measures.
Failure to comply with this Policy, deliberate concealment of material risks or incidents, circumvention of internal controls, or failure to implement assigned corrective actions may result in appropriate disciplinary, contractual or legal action.
Employees performing relevant functions shall receive appropriate risk management and compliance awareness based on their roles and responsibilities.
This Policy shall be reviewed periodically and, where appropriate, upon:
This Risk Management Policy has been approved by the Board of Directors of ZESTFLOW INDIA PRIVATE LIMITED and shall come into effect from the date of its approval.
The Board may amend or replace this Policy from time to time.
CERTIFICATION
All Directors, officers, employees and authorised representatives of ZESTFLOW INDIA PRIVATE LIMITED shall comply with this Policy to the extent applicable to their respective roles and responsibilities.
For ZESTFLOW INDIA PRIVATE LIMITED Approved by the Board of Directors on: __________________ Effective Date: __________________