Haripay INDIA PRIVATE LIMITED
ANTI-MONEY LAUNDERING (AML) & COUNTER-TERRORIST FINANCING (CFT) POLICY
POLICY NO. 04 | VERSION 1.0
EFFECTIVE DATE: 29 SEPTEMBER 2026
| Document Control | Details |
|---|---|
| Company | Haripay INDIA PRIVATE LIMITED |
| CIN | U72900UP2021PTC140275 |
| Registered Office | D30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010 |
| Website | Haripay.in |
| Business Context | Gift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners |
| Policy Owner | Compliance / Management |
| Review Frequency | At least annually / event driven |
| Classification | Confidential – Controlled Compliance Document |
1. PURPOSE
This Policy establishes Haripay's framework for identifying, assessing, preventing, escalating and managing money-laundering, terrorist-financing and related financial-crime risks relevant to its actual role, products, partners and applicable legal or contractual obligations.
2. IMPORTANT REGULATORY ROLE PRINCIPLE
Haripay shall not assume or represent that it is an RBI-regulated PPI issuer or another regulated reporting entity unless it actually holds the relevant authorisation. Where AML/CFT obligations are legally assigned to an authorised PPI issuer, bank or other regulated partner, Haripay shall follow the documented responsibility model and provide required cooperation.
3. OBJECTIVES
- Identify AML/CFT risks relevant to Haripay's business.
- Prevent misuse of gift-card and payment-related services.
- Support applicable KYC and customer due diligence.
- Identify suspicious or unusual activity.
- Maintain appropriate escalation and investigation processes.
- Protect transaction and customer information.
- Maintain required records.
- Support authorised partners and competent authorities where legally required.
4. SCOPE
This Policy applies to relevant employees, management, operations, compliance, customer support, technology and partner-management functions involved in covered products and transactions.
5. RISK-BASED APPROACH
Haripay shall apply a risk-based approach proportionate to its role and exposure. Controls shall consider customer, product, transaction, channel, geographic, partner and technology risks where relevant.
- Customer risk
- Product risk
- Transaction risk
- Channel risk
- Geographic risk
- Partner/vendor risk
- Technology/API risk
- Fraud and identity risk
6. AML/CFT RESPONSIBILITY MAPPING
For each product or partner arrangement, Haripay shall document which AML/CFT controls are performed by Haripay and which are performed by the authorised PPI issuer, bank or other regulated entity.
- KYC/CDD
- Screening
- Transaction monitoring
- Suspicious activity review
- Regulatory reporting
- Record keeping
- Customer restrictions
- Law-enforcement response
7. CUSTOMER DUE DILIGENCE
Where CDD/KYC is applicable to Haripay's role, the controls described in the KYC & Customer Due Diligence Policy shall apply. Where a regulated partner performs CDD, Haripay shall follow the approved partner process and escalation requirements.
8. PROHIBITED / HIGH-RISK ACTIVITY
Haripay shall maintain controls to identify and escalate activities that are prohibited by law, partner rules or internal risk controls.
- Suspected fraud
- Identity misuse
- Unusual transaction patterns
- Attempts to circumvent controls
- Suspicious use of multiple accounts/instruments
- Activity inconsistent with known customer/product use
- Other documented financial-crime indicators
9. TRANSACTION MONITORING
Transaction monitoring shall be proportionate to Haripay's role and may include rules, alerts, partner-provided monitoring outputs, manual review or other risk-based controls.
- Unusual transaction frequency
- Unusual transaction values
- Repeated failed attempts
- Multiple accounts or instruments showing linked suspicious behaviour
- Rapid purchase/redemption patterns
- Unusual refund/reversal activity
- Fraud-linked indicators
10. ALERT REVIEW & ESCALATION
- Generate or receive alert.
- Perform initial review.
- Collect relevant transaction/customer information available to Haripay.
- Determine whether escalation is required.
- Coordinate with regulated partner where applicable.
- Document decision and action.
- Close or continue monitoring as appropriate.
11. SANCTIONS / WATCHLIST CONTROLS
Where applicable to Haripay's role or required by a regulated partner, sanctions, prohibited-party or other screening shall be performed through approved processes. Potential matches shall be escalated for review and shall not be treated as confirmed matches without appropriate verification.
12. SUSPICIOUS ACTIVITY
Potentially suspicious activity shall be assessed using documented criteria and available information. Haripay shall not make unsupported allegations and shall maintain confidentiality around internal reviews.
13. PARTNER COORDINATION
Where a PPI issuer, bank or payment partner has the primary regulatory responsibility for AML/CFT monitoring or reporting, Haripay shall provide accurate and timely information required under the applicable agreement and law.
14. REPORTING & LAW-ENFORCEMENT COOPERATION
Where Haripay has a direct legal reporting obligation, the designated function shall follow the applicable reporting process. Where reporting belongs to a regulated partner, Haripay shall support the partner with relevant records and information as legally permitted.
15. CUSTOMER RESTRICTIONS / HOLD / BLOCKING
Where permitted and appropriate, Haripay may restrict an account, transaction, product or service in response to fraud, AML/CFT, partner or legal requirements. Actions shall be documented and escalated.
16. RECORD KEEPING
- CDD/KYC records
- Transaction records
- Monitoring alerts
- Review/investigation records
- Partner communications
- Escalation records
- Reporting records where applicable
- Training records
- Policy and risk assessments
Records shall be retained in accordance with applicable law, partner requirements and the Data Protection, Privacy & Retention Policy.
17. CONFIDENTIALITY
AML/CFT reviews, alerts, investigations and related information shall be handled on a need-to-know basis and protected against unauthorised disclosure, subject to applicable law.
18. EMPLOYEE RESPONSIBILITIES
- Follow AML/CFT procedures.
- Complete assigned training.
- Escalate suspicious or unusual activity.
- Protect confidential information.
- Do not bypass monitoring or verification controls.
- Maintain accurate records.
19. TRAINING & AWARENESS
Relevant personnel shall receive role-based training covering financial-crime risks, KYC/CDD, fraud indicators, escalation procedures, customer confidentiality and applicable partner requirements.
20. THIRD-PARTY / PARTNER RISK
Material partners involved in payment, PPI, KYC, transaction monitoring or other critical functions shall be subject to appropriate due diligence and ongoing oversight under the Third-Party / Vendor Risk Management Policy.
21. MONITORING, TESTING & AUDIT
Haripay may periodically review AML/CFT controls, transaction-monitoring arrangements, partner responsibilities, alerts, escalations, training and records. Material deficiencies shall be documented and remediated.
22. INCIDENT & FRAUD LINKAGE
AML/CFT concerns involving cyber fraud, account takeover, unauthorised transactions or payment fraud shall also be handled under the applicable Fraud Prevention, Cyber Incident Response and Unauthorised Transaction Policies.
23. ESCALATION
- Material suspicious activity
- Potential sanctions/prohibited-party concern
- Significant fraud
- Repeated control bypass
- Material partner failure
- Regulatory or law-enforcement request
- Potential legal/regulatory breach
Escalation shall be made to the designated Compliance/Management function and relevant authorised partner as applicable.
24. POLICY EXCEPTIONS
No exception may be used to bypass a mandatory legal or regulatory requirement. Any permitted internal exception shall be documented, risk-assessed and approved by an authorised function.
25. RESPONSIBILITY MATRIX
| Function | Responsibility | Escalation |
|---|---|---|
| Management | Overall AML/CFT governance and risk oversight | Director / Authorised Management |
| Compliance | AML/CFT framework, monitoring and escalation | Management |
| Operations | Operational controls and transaction support | Compliance |
| Fraud/Risk | Alert review and risk assessment | Compliance / Management |
| Partner Management | Regulated-partner responsibility mapping and coordination | Compliance |
| Technology/Security | Monitoring systems, access and data security | Management / Security |
| Customer Support | Customer-related escalation and information support | Operations / Compliance |
26. REVIEW & AMENDMENT
This Policy shall be reviewed at least annually and whenever there is a material change in applicable requirements, business model, product structure, regulated partner arrangements or financial-crime risk.
27. APPROVAL
| Role | Name / Designation | Signature / Date |
|---|---|---|
| Prepared By | Compliance / Operations | |
| Reviewed By | Legal / Risk / Management | |
| Approved By | Director / Authorised Signatory |
