Login or Create an account
Or Login Via

SUSPICIOUS ACTIVITY IDENTIFICATION, ESCALATION & REPORTING PROCEDURE POLICY

ZESTFLOW INDIA PRIVATE LIMITED (CIN-U62099DC2026PTC468956)

Registered Address - Office No. 201, Plot No 4, 2nd Floor, LSC Gujranwala Colony North West Delhi Delhi India 110009

Suspicious Activity Identification, Escalation & Reporting

ZESTFLOW INDIA PRIVATE LIMITED maintains a structured process to identify, review and escalate suspicious or unusual activities. We promote timely internal reporting, strict confidentiality and appropriate action or external reporting, wherever required under applicable laws and regulatory arrangements.

1. Purpose and Scope

ZESTFLOW INDIA PRIVATE LIMITED ("ZESTFLOW" or "the Company") is committed to maintaining an effective framework for identifying, reviewing, escalating and appropriately reporting suspicious or unusual activities that may indicate money laundering, terrorist financing, fraud or other unlawful financial activity.

This Procedure establishes a uniform internal process to ensure that suspicious activities are:

  • promptly identified and internally escalated;
  • appropriately reviewed by authorised personnel;
  • handled confidentially;
  • documented and preserved; and
  • reported or escalated externally where required under applicable law or contractual arrangements.

This Procedure applies to all Directors, officers, employees, consultants and other relevant persons acting on behalf of the Company.

This Procedure shall be read together with the Company's AML, CFT, KYC/CDD, Risk Management, Record Retention and Employee AML/CFT Training Policies.

2. Key Principles and Responsibilities

All employees and relevant personnel shall remain reasonably vigilant for activities that appear unusual, inconsistent with a known customer or merchant profile, or otherwise give rise to a reasonable concern of financial crime.

An employee is not required to establish or prove that criminal activity has occurred before making an internal report. A genuine and reasonable concern shall be sufficient for internal escalation.

Employees shall:

  • report suspicious or unusual activities promptly;
  • provide available facts and supporting information;
  • avoid conducting unauthorised independent investigations;
  • preserve relevant records and information;
  • maintain strict confidentiality; and
  • cooperate with authorised internal reviews.

The Company shall designate an appropriate Compliance Officer or Compliance Function responsible for receiving and reviewing internal suspicious activity referrals.

Where a Principal Officer or other designated officer is appointed or legally required, such person may perform the relevant responsibilities under this Procedure.

No employee shall be penalised merely for making a genuine internal report in good faith, even where the activity is subsequently determined not to be suspicious.

3. Identification of Suspicious Activity

Suspicious activity may include an actual, attempted or proposed transaction, conduct or pattern that:

  • is inconsistent with the known customer or merchant profile;
  • lacks an apparent lawful or reasonable economic purpose;
  • involves unexplained or unusual transaction volumes or frequency;
  • involves rapid or unusual movement of funds;
  • involves unrelated third-party payments or settlement instructions;
  • involves multiple apparently linked accounts without reasonable explanation;
  • involves excessive or unusual refunds, reversals or chargebacks;
  • involves forged, altered or inconsistent documents;
  • involves false, fictitious or misleading identity information;
  • appears structured to avoid applicable controls or scrutiny;
  • involves sanctions, prohibited persons or higher-risk geographical exposure;
  • involves unexplained changes in bank accounts, ownership or business activities;
  • involves attempts to bypass KYC, compliance or monitoring controls; or
  • otherwise gives rise to a reasonable concern of money laundering, terrorist financing, fraud or unlawful activity.

The presence of one or more red flags does not automatically establish unlawful activity. Each case shall be assessed based on the available facts and circumstances.

The above indicators are illustrative and not exhaustive.

4. Internal Escalation and Review Procedure

Where suspicious or unusual activity is identified, the following process shall ordinarily apply:

Step 1 - Identification and Internal Referral

The employee or relevant person identifying the concern shall promptly report it through the authorised internal channel, which may include the Reporting Manager, Compliance Officer or Compliance Function.

The referral should contain available information relating to:

  • the customer, merchant or relevant person;
  • the transaction or activity;
  • the reason for concern;
  • relevant dates, amounts or transaction details; and
  • available supporting records.

Step 2 - Compliance Review

The Compliance Officer or authorised function shall review the matter and may consider:

  • KYC and due diligence information;
  • customer or merchant profile;
  • transaction history and behaviour;
  • expected business activities;
  • ownership and beneficial ownership information;
  • previous alerts or internal reviews;
  • sanctions or screening results;
  • geographical exposure;
  • available adverse information; and
  • any other relevant facts.

Additional information may be obtained internally or through legally permissible means, provided that the concerned customer or person is not unnecessarily alerted to the review.

Step 3 - Risk Assessment and Decision

Following review, the authorised Compliance Officer or function may determine that:

  • no further action is presently required;
  • additional information or monitoring is required;
  • enhanced due diligence or additional controls are appropriate;
  • the matter should be escalated to Senior Management;
  • services or activities should be restricted, suspended or terminated, subject to applicable law and contractual rights;
  • information should be escalated to a regulated partner institution; or
  • external reporting or other action is required under applicable law.

The reasons for material decisions should be appropriately documented.

5. External Escalation and Regulatory Reporting

Where ZESTFLOW is directly required under applicable law to submit a Suspicious Transaction Report ("STR") or other report to FIU-IND or another competent authority, the report shall be made by the duly authorised officer in the prescribed manner and within the applicable timeline.

Where the relevant statutory reporting obligation rests with a bank, financial institution, payment service provider or other regulated partner institution, the Company shall promptly provide or escalate relevant information to such institution in accordance with applicable law and contractual arrangements.

Nothing in this Procedure shall be interpreted as requiring the Company to make a direct regulatory filing where no such legal obligation applies to the Company.

The Company may cooperate with competent authorities and regulated partner institutions and provide information where required or permitted under applicable law.

Any restriction, blocking, freezing or other action affecting funds or transactions shall be undertaken only where legally authorised or required, or in coordination with the relevant regulated partner institution or competent authority.

6. Confidentiality and Prohibition of Tipping-off

All suspicious activity referrals, reviews, investigations, decisions and external reports shall be treated as strictly confidential.

No employee or unauthorised person shall inform a customer, merchant or other concerned person that:

  • a suspicious activity report or internal referral has been made;
  • an internal review or investigation is underway;
  • enhanced monitoring is being undertaken;
  • information has been escalated to a regulated partner institution;
  • a regulatory report has been or may be filed; or
  • a competent authority has been or may be informed,

except where disclosure is authorised or required under applicable law.

Employees shall avoid any communication or action that may improperly alert the concerned person or prejudice an internal review, investigation or lawful reporting process.

A material breach of confidentiality or deliberate tipping-off may result in disciplinary, contractual or legal action.

7. Record Keeping, Oversight and Corrective Action

The Company shall maintain appropriate records relating to:

  • internal suspicious activity referrals;
  • review and investigation notes;
  • supporting information and documents;
  • decisions and reasons for material decisions;
  • internal and external escalations;
  • regulatory reports, where applicable; and
  • relevant correspondence.

Such records shall be maintained securely and access shall be restricted to authorised persons on a need-to-know basis.

Records shall be retained in accordance with applicable law and the Company's Record Retention & Data Preservation Policy.

The Company may periodically review the effectiveness of this Procedure, including:

  • quality and timeliness of internal referrals;
  • adequacy of review and documentation;
  • compliance with confidentiality requirements;
  • effectiveness of escalation arrangements; and
  • implementation of corrective measures.

Failure to report a material suspicious activity, deliberate suppression or concealment of relevant information, destruction of relevant records, tipping-off or failure to

cooperate with an authorised review may result in appropriate disciplinary, contractual or legal action.

8. Procedure Review, Approval and Effective Date

This Procedure shall be reviewed periodically and, where appropriate, upon:

  • changes in applicable laws or regulatory requirements;
  • material changes in the Company's business model;
  • introduction of new products or services;
  • significant financial-crime incidents;
  • changes in regulated partner arrangements; or
  • findings arising from audits or compliance reviews.

This Suspicious Activity Identification, Escalation & Reporting Procedure has been approved by the Board of Directors of ZESTFLOW INDIA PRIVATE LIMITED and shall come into effect from the date of its approval.

The Company may amend or replace this Procedure from time to time.

CERTIFICATION

All Directors, officers, employees, consultants and other relevant personnel of ZESTFLOW INDIA PRIVATE LIMITED shall comply with this Procedure to the extent applicable to their respective roles and responsibilities.

For ZESTFLOW INDIA PRIVATE LIMITED Approved by the Board of Directors on: __________________ Effective Date: __________________