This KYC & AML Policy (“Policy”) is established by Zed LeafinPrivate Limited (“Company” or “NBFC”) to ensure that appropriate measures are adopted for identification and verification of customers, prevention of money laundering and terrorist financing, and compliance with applicable KYC and AML requirements.
The Company shall ensure that all customer onboarding and lending activities are carried out in accordance with applicable RBI guidelines and laws.
The objectives of this Policy are to:
Establish appropriate procedures for customer identification and verification.
Prevent the Company from being used for money laundering, terrorist financing and other financial crimes.
Adopt a risk-based approach to Customer Due Diligence (“CDD”).
Ensure appropriate customer risk categorisation and ongoing monitoring.
Comply with applicable KYC, CKYCR, PMLA and AML/CFT requirements.
Ensure that LSPs engaged by the Company follow applicable KYC and AML requirements.
The Company shall undertake KYC and Customer Due Diligence before establishing a lending relationship with a customer.
The Company shall:
Verify the identity and address of the customer using KYC methods permitted under applicable RBI guidelines.
Obtain and verify applicable Officially Valid Documents (“OVDs”) or permitted electronic/digital KYC documents.
Ensure that the customer information obtained is accurate and adequate for identification purposes.
Ensure that anonymous, fictitious or fraudulent customer accounts are not created.
Obtain such additional information as may be required based on the customer's risk profile.
Maintain appropriate records and audit trails of the KYC process.
KYC shall be completed before loan disbursement unless otherwise specifically permitted under applicable regulatory requirements.
The Company shall comply with applicable requirements relating to the Central KYC Records Registry (“CKYCR”).
Where applicable, the Company shall:
Obtain/retrieve the customer's KYC Identifier and KYC records from CKYCR;
Use CKYCR records in accordance with applicable regulatory requirements;
Update customer KYC records with CKYCR within the prescribed timelines; and
Obtain additional information or documents where the CKYCR records are incomplete, outdated or insufficient for the Company's regulatory or risk assessment requirements.
The Company shall undertake appropriate CDD for all customers.
CDD shall include:
Identification and verification of the customer;
Verification of identity and address;
Understanding the purpose and nature of the customer relationship;
Assessment of the customer's profile and risk;
Screening against applicable sanctions and restricted lists; and
Ongoing monitoring, where applicable.
The extent of CDD may be enhanced based on the customer's risk category and other relevant risk factors.
The Company shall adopt a risk-based approach and categorise customers into appropriate risk categories, such as Low, Medium and High Risk.
Risk categorisation may consider:
Customer profile and occupation;
Identity and KYC verification status;
Geographic factors;
Product and digital channel risks;
Customer behaviour and transaction patterns;
Adverse information;
Sanctions/PEP status; and
Fraud or suspicious activity indicators.
High-risk customers shall be subject to Enhanced Due Diligence (“EDD”) and enhanced monitoring, as appropriate.
Where a customer presents higher AML/CFT or financial crime risk, the Company may undertake additional measures, including:
Obtaining additional customer information;
Additional verification of identity/address;
Verification of source of income/funds, where appropriate;
Enhanced monitoring of customer activity; and
Obtaining appropriate management approval, wherever required.
The Company shall maintain appropriate mechanisms for identifying Politically Exposed Persons (“PEPs”), their family members and close associates, as applicable under the RBI KYC framework.
Where required, the Company shall undertake enhanced due diligence and obtain appropriate approval before establishing or continuing the customer relationship.
The Company shall conduct appropriate screening of customers against applicable sanctions lists, terrorist lists and other restricted/prohibited lists.
Any potential match shall be reviewed and escalated to the Compliance/AML function for appropriate action
.
The Company shall maintain appropriate mechanisms for ongoing monitoring of customer accounts and activities to identify unusual or suspicious patterns.
Monitoring may include:
Multiple loan applications involving inconsistent customer information;
Unusual repayment behaviour;
Activity inconsistent with the customer's profile;
Suspected identity theft or account takeover;
Unusual digital or transaction behaviour;
Fraud indicators; and
Other AML/CFT risk indicators identified by the Company.
The monitoring framework shall be reviewed periodically and updated based on emerging risks.
The Company shall maintain appropriate systems and controls to prevent its products, services and digital lending platform from being misused for:
Money laundering;
Terrorist financing;
Fraud;
Identity theft; or
Other financial crimes.
The Company shall adopt a risk-based approach to identify, assess, monitor and mitigate AML/CFT risks arising from its customers, products, delivery channels and business relationships.
Any transaction or activity suspected to involve money laundering, terrorist financing or other reportable financial crime shall be escalated to the Company's Principal Officer/AML Compliance Officer.
Where required under applicable law, the Company shall report suspicious transactions to the Financial Intelligence Unit – India (“FIU-IND”) within the prescribed timelines and in the prescribed manner.
The Company shall maintain confidentiality in relation to suspicious transaction reporting and shall not disclose such information to the concerned customer except where permitted or required by law.
The Company shall periodically update customer KYC information in accordance with applicable RBI requirements and the customer's risk category.
The Company shall ensure that material changes in customer information are appropriately identified and updated in its records.
Where required, customers may be requested to provide updated KYC information or documents.
Where an LSP is engaged for customer sourcing, onboarding or other digital lending activities, the Company shall ensure that the LSP follows the Company's prescribed KYC and AML procedures.
The Company shall:
Conduct appropriate due diligence on the LSP;
Define KYC/AML responsibilities contractually;
Monitor the LSP's compliance;
Ensure appropriate records and audit trails are maintained;
Periodically review the LSP's KYC/AML processes; and
Take corrective action where deficiencies are identified.
Engagement of an LSP shall not relieve the Company of its responsibility for compliance with applicable KYC and AML requirements.
The Company shall maintain KYC and AML-related records, including customer identification, transaction and monitoring records, for the period prescribed under applicable law and RBI requirements.
Records shall be maintained in a manner that enables the Company to establish the identity of customers and reconstruct relevant transactions when required by competent authorities.
This Policy shall be reviewed at least annually or earlier where there are changes in applicable laws, RBI directions, the Company's products, digital lending model or AML/CFT risk environment.
In case of any conflict between this Policy and applicable law or regulatory directions, the applicable law or regulatory directions shall prevail.
Any additional payment made by You shall be refunded back within 30 days pursuant to the reconciliation of the accounts by Zed Finance. There will be no cancellation of the service once You have received the loan amount in Your bank account.