Haripay

Haripay INDIA PRIVATE LIMITED

THIRD-PARTY / VENDOR RISK MANAGEMENT POLICY

POLICY NO. 15 | VERSION 1.0

EFFECTIVE DATE: 29 SEPTEMBER 2026

Document ControlDetails
CompanyHaripay INDIA PRIVATE LIMITED
CINU72900UP2021PTC140275
Registered OfficeD30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010
WebsiteHaripay.in
Business ContextGift Cards, Gift Vouchers & Virtual Gift Products through applicable authorised/regulated partners
Policy OwnerCompliance / Vendor Management / Information Security
Review FrequencyAt least annually / event driven
ClassificationConfidential – Controlled Compliance Document

1. PURPOSE

This Policy establishes the framework for identification, due diligence, onboarding, contracting, monitoring, review and exit of third parties and vendors whose services may affect Haripay's customers, transactions, information, technology, compliance or business continuity.

2. OBJECTIVES

  • Identify third-party risks before engagement.
  • Apply risk-based due diligence.
  • Define contractual controls and responsibilities.
  • Protect customer and company information.
  • Monitor vendor performance and security.
  • Manage incidents and material changes.
  • Ensure orderly termination and data return/deletion.

3. SCOPE

This Policy applies to PPI issuers, banks, payment processors, gift-card/voucher issuers, merchants, technology providers, cloud providers, API providers, consultants, service providers, outsourcing partners and other material third parties.

4. THIRD-PARTY RISK CATEGORIES

  • Regulatory/compliance risk
  • Financial risk
  • Information-security risk
  • Data/privacy risk
  • Fraud risk
  • Operational risk
  • Business continuity risk
  • Reputational risk
  • Concentration/dependency risk
  • Legal/contractual risk

5. RISK CLASSIFICATION

  • Critical / High – material customer, financial, regulatory, data or operational dependency
  • Medium – meaningful operational or information access
  • Low – limited access and limited business impact

Risk classification shall consider service criticality, data access, transaction impact, regulatory role, substitutability and dependency.

6. DUE DILIGENCE

  • Legal entity and ownership information
  • Applicable licences/authorisations where relevant
  • Business and service profile
  • Financial/operational capability
  • Security controls
  • Data protection practices
  • Business continuity arrangements
  • Relevant compliance history where legally and reasonably assessable
  • References or experience where appropriate

7. PPI / BANK / REGULATED PARTNER DUE DILIGENCE

Where a third party performs a regulated activity or provides regulated infrastructure, Haripay shall verify the relevant authorisation/licence or other basis for providing the service, to the extent applicable and reasonably verifiable.

8. INFORMATION SECURITY DUE DILIGENCE

  • Security policy
  • Access control
  • Encryption
  • Vulnerability management
  • Incident response
  • Backup/recovery
  • Logging/monitoring
  • Security testing where appropriate

9. DATA PRIVACY DUE DILIGENCE

Where a vendor processes personal or confidential information, Haripay shall assess purpose, data access, security controls, retention, sub-processing and incident notification arrangements as appropriate.

10. FRAUD & FINANCIAL RISK

Vendors involved in transactions, settlement, gift-card issuance/redemption or customer funds-related processes shall be assessed for fraud, reconciliation, financial-control and settlement risks appropriate to the service.

11. APPROVAL BEFORE ONBOARDING

  1. Business owner submits requirement.
  2. Risk classification is assigned.
  3. Due diligence is completed.
  4. Material gaps are documented.
  5. Compliance/security/legal review is completed where applicable.
  6. Commercial and contractual approval is obtained.
  7. Vendor is onboarded through approved process.

12. CONTRACTUAL REQUIREMENTS

  • Scope of services
  • Roles and responsibilities
  • Service levels
  • Security obligations
  • Data protection/confidentiality
  • Incident notification
  • Audit/assessment rights where appropriate
  • Subcontracting controls
  • Business continuity
  • Termination and data return/deletion
  • Regulatory cooperation where applicable

13. SERVICE LEVELS

Critical or material vendors shall have documented service expectations, escalation contacts and appropriate service-level arrangements.

14. ACCESS MANAGEMENT

Vendor access shall be limited to the minimum necessary, approved, monitored and revoked when no longer required.

15. API / SYSTEM INTEGRATION

Vendor APIs and integrations shall follow approved security, authentication, credential management, logging and change-management requirements.

16. SUBCONTRACTORS

Material subcontracting shall be disclosed or controlled as required by contract. Vendors shall remain responsible for subcontractors to the extent provided in contractual arrangements.

17. ONGOING MONITORING

  • Service performance
  • Security incidents
  • Compliance changes
  • Material ownership changes
  • Financial/operational concerns
  • Customer complaints
  • Audit findings
  • Repeated SLA failures

18. PERIODIC REVIEW

High-risk or critical vendors shall be reviewed more frequently and in greater depth than low-risk vendors, based on documented risk assessment.

19. MATERIAL CHANGE MANAGEMENT

Changes in ownership, service scope, technology, processing location, subcontractors, security posture or regulatory status shall be assessed for impact and may trigger re-due diligence.

20. VENDOR INCIDENT MANAGEMENT

Vendor security, fraud, privacy or operational incidents affecting Haripay or its customers shall be escalated promptly through the relevant incident-management process.

21. BUSINESS CONTINUITY

Critical vendors shall have appropriate continuity and recovery arrangements, or Haripay shall maintain compensating controls appropriate to the dependency risk.

22. CONCENTRATION & DEPENDENCY RISK

Haripay shall identify material dependency on a single vendor, partner or technology provider and consider alternatives, contingency arrangements or exit plans where proportionate.

23. CUSTOMER IMPACT

Material vendor issues that may affect customers, transactions, gift-card availability, settlement, privacy or service continuity shall be escalated and managed promptly.

24. AUDIT & ASSURANCE

Where appropriate, Haripay may request assurance reports, certifications, questionnaires, audit evidence, testing results or other reasonable evidence of control effectiveness.

25. PERFORMANCE MANAGEMENT

  • SLA performance
  • Availability
  • Transaction accuracy
  • Support responsiveness
  • Security events
  • Complaint trends
  • Reconciliation exceptions
  • Corrective-action status

26. VENDOR REMEDIATION

Material control gaps shall have documented corrective actions, owners and target dates. Unresolved high-risk issues may require management escalation or risk acceptance.

27. SUSPENSION / RESTRICTION

Haripay may restrict or suspend vendor access or activity where there is a material security, fraud, compliance, operational or contractual risk, subject to applicable agreements and business procedures.

28. TERMINATION / EXIT

  1. Confirm termination decision.
  2. Restrict/revoke access.
  3. Complete pending transactions and settlements.
  4. Return or securely delete information as required.
  5. Recover company assets.
  6. Document outstanding liabilities/issues.
  7. Complete final risk review.

29. RECORD KEEPING

  • Due diligence records
  • Approval records
  • Contracts
  • Security assessments
  • SLA reports
  • Incident records
  • Review results
  • Corrective actions
  • Termination/exit records

30. CONFIDENTIALITY

Vendor information and due-diligence materials shall be handled according to applicable confidentiality and information-security requirements.

31. EXCEPTIONS

Exceptions shall be documented, risk-assessed and approved by an authorised function. Mandatory legal, regulatory or contractual requirements shall not be overridden.

32. RESPONSIBILITY MATRIX

FunctionResponsibilityEscalation
Business OwnerBusiness need, vendor performance and relationship managementManagement
ComplianceRegulatory/compliance due diligence and oversightCompliance Head
Information SecuritySecurity and technology risk assessmentSecurity/Technology Head
LegalContractual terms and legal riskLegal / Management
FinanceFinancial and settlement-related vendor reviewFinance Head
Vendor ManagementOnboarding, monitoring and recordsManagement
ManagementHigh-risk approval, risk acceptance and termination decisionsDirector / Authorised Management

33. REVIEW & AMENDMENT

This Policy shall be reviewed at least annually and whenever there is a material change in vendor risk, business model, partner arrangements, technology or applicable requirements.

34. APPROVAL

RoleName / DesignationSignature / Date
Prepared ByCompliance / Vendor Management / Information Security
Reviewed ByLegal / Risk / Management
Approved ByDirector / Authorised Signatory

CONFIDENTIAL – CONTROLLED COMPLIANCE DOCUMENT

Haripay INDIA PRIVATE LIMITED