CIN: U51109WB1995PTC070852| NBFC CoR No.: B-05.05188| Reg. Office: Kolkata, West Bengal
Disclosures  /  KYC & AML Policy

KYC & AML Policy

Our customer identification, due diligence and anti-money laundering framework.

Know Your Customer (KYC) & Anti-Money Laundering (AML) Policy

Collocate Merchants Private Limited  |  CIN: U51109WB1995PTC070852  |  Version 1.0  |  Approved by the Board of Directors

1. Introduction

The Reserve Bank of India (“RBI”) has issued guidelines on Know Your Customer (KYC) norms and Anti-Money Laundering (AML) standards that mandate every Non-Banking Financial Company (NBFC) to formulate and adopt a suitable policy with the approval of its Board of Directors. Collocate Merchants Private Limited (the “Company” or “Collocate”), as a Regulated Entity, is obligated to comply with these directives. This KYC-AML Policy (the “Policy”) is framed in accordance with the RBI Master Direction – Know Your Customer (KYC) Direction, 2016, as amended; the Prevention of Money Laundering Act, 2002 (“PMLA”) and the Prevention of Money-laundering (Maintenance of Records) Rules, 2005; and other applicable laws and guidelines, including FATCA/CRS and CKYCR requirements.

The Board of Directors has approved this Policy. Its primary objectives are to:

  1. identify and understand customers and their financial dealings effectively;
  2. manage risks prudently to preserve the integrity of the Company’s operations; and
  3. prevent the Company from being used, intentionally or unintentionally, for money laundering, terrorist financing or other unlawful activities.

2. Applicability

This Policy applies to all offices, departments, employees and authorised representatives of the Company involved in dealing with customers and their financial transactions. It covers customer onboarding through all channels — physical (face-to-face) interactions and digital/online platforms, including the mobile and web platform of the Company’s digital lending partner, LoanDidi — as well as any outsourced or third-party arrangement relating to customer identification and verification.

3. Key Definitions

For the purposes of this Policy, terms such as “Aadhaar number”, “Authentication”, “Customer”, “Customer Due Diligence (CDD)”, “Central KYC Records Registry (CKYCR)”, “Digital KYC”, “Officially Valid Document (OVD)”, “Principal Officer”, “Transaction” and “Video-based Customer Identification Process (V-CIP)” carry the meanings assigned to them under the PMLA, the Rules, the RBI KYC Direction, 2016 and the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, as applicable. V-CIP is treated as a face-to-face process for the purpose of this Policy.

4. Elements of the Policy

The Company’s KYC-AML framework rests on four key elements:

  1. Customer Acceptance Policy (CAP);
  2. Customer Identification Procedure (CIP);
  3. Monitoring of Transactions; and
  4. Risk Management.

5. Customer Acceptance Policy (CAP)

  • No account will be opened or loan disbursed in an anonymous, fictitious or benami name, or where the customer’s identity cannot be verified.
  • Customers will be accepted only after their identity is verified through the CDD process; where adequate CDD cannot be carried out, the relationship will not be established.
  • No account-based relationship or transaction will commence without following the prescribed CDD procedures.
  • Mandatory KYC information will be collected at onboarding and updated periodically as required by regulation; optional information will be collected only with the customer’s explicit consent.
  • The Company will screen customers against sanctions lists circulated by the RBI and other competent authorities, and will not onboard any sanctioned individual or entity.
  • While ensuring compliance, the Company will not inconvenience genuine customers or discriminate against financially or socially disadvantaged sections.

6. Customer Identification Procedure (CIP) and Customer Due Diligence (CDD)

Customer identification involves verifying the customer’s identity on the basis of reliable, independent documents, data or information, so as to be satisfied that the customer is who they claim to be. For an account-based relationship, the Company will obtain:

(A) Proof of Identity (POI)

  • A scan/image of the PAN card (or its equivalent e-document) uploaded on the digital platform at onboarding.

(B) Proof of Address (POA)

  • A scan/image of any one of: passport, voter identity card, or masked UIDAI (Aadhaar) document (or their equivalent e-documents).
  • Address-mismatch protocol: where, on subsequent physical KYC (triggered when cumulative disbursement to a borrower in a financial year exceeds a Company-determined threshold), the OVD address does not match the current residence, the customer must provide a current address proof such as a rent agreement, utility bill or municipal tax receipt.

(C) Real-Time Selfie

  • The customer must capture a real-time selfie during the application to confirm authenticity and prevent impersonation.

CDD Measures, OTP-based e-KYC and V-CIP

  • Where the total amount borrowed by a single borrower in a financial year exceeds the threshold prescribed by the RBI, the Company will conduct enhanced CDD, which may include physical verification or V-CIP.
  • OTP-based e-KYC may be used in non-face-to-face mode subject to RBI conditions, including the customer’s explicit consent, the aggregate cap on term loans sanctioned in a financial year using OTP-based KYC (not exceeding the RBI-prescribed limit), a customer declaration on other accounts, and marking such accounts in CKYCR pending full CDD.
  • V-CIP may be undertaken with the customer’s informed consent, with offline verification of PAN and Aadhaar, geo-tagging to confirm presence in India, live recording, dynamic questioning to rule out pre-recorded sessions, a concurrent audit and robust data security. The Aadhaar number will be redacted/blacked-out in all records.
  • A Unique Customer Identification Code (UCIC) will be assigned to each customer to track relationships consistently across products and services.

7. Monitoring of Transactions

  • Officials will understand the customer’s typical transactional behaviour to identify deviations that may indicate suspicious activity.
  • Special attention will be given to large, complex or unusual transactions without an apparent lawful purpose.
  • Internal threshold limits may be set, and transactions exceeding them scrutinised; large cash transactions inconsistent with a customer’s profile are red flags.
  • High-risk accounts will be subject to enhanced and more frequent monitoring, and customer risk profiles will be reviewed and re-categorised periodically.

8. Risk Management

The Company adopts a Risk-Based Approach (RBA) to assess and manage money-laundering (ML) and terrorist-financing (TF) risk, classifying customers broadly into Low, Medium and High risk based on factors such as credit evaluation and repayment history, nature and location of activities, source of funds, client characteristics and the volume, value and pattern of transactions. An annual ML/TF risk assessment will be documented and placed before the Board or a delegated authority, and made available to regulators on request.

9. Principal Officer and Designated Director

  • The Company will appoint a Principal Officer at senior-management level to oversee monitoring and reporting of transactions, furnish information to the Director, FIU-IND, and maintain liaison with enforcement agencies.
  • The Board will appoint a Designated Director to ensure compliance with AML/CFT obligations. The Principal Officer cannot be the Designated Director. The name, designation and address of both will be communicated to FIU-IND.

10. Reporting to FIU-IND

  • Pursuant to Section 12 of the PMLA and Rule 3 of the Rules, the Company will report prescribed cash and suspicious transactions to the Director, FIU-IND, within the prescribed timelines — cash and related transactions by the 15th of the succeeding month, and suspicious transactions within seven working days of determining suspicion.
  • The Company and its employees will maintain strict confidentiality regarding the fact and contents of such reports. No “NIL” report is required where no reportable transaction occurred.

11. Record Maintenance and Preservation

  • Transaction records will be maintained for at least five years from the date of the transaction, and customer identity and address records for at least five years after the relationship ends, in line with the PMLA and Rules.
  • A destruction register will be maintained under the custody of a senior officer, and records will be stored securely with efficient retrieval for regulators.

12. CKYCR and FATCA/CRS Compliance

The Company will upload KYC data to the Central KYC Records Registry (CKYCR) for new individual accounts and maintain KYC data for existing customers in digital form. The Company will comply with FATCA/CRS reporting obligations as issued by the RBI and the Government of India from time to time.

13. Reliance on Third-Party Due Diligence

The Company may rely on third-party CDD where the third party provides the necessary information promptly, the Company can obtain copies of the underlying documents on request, the third party is regulated and adheres to equivalent standards, and is not based in a high-risk jurisdiction. Notwithstanding such reliance, ultimate responsibility for CDD and AML/CFT compliance rests with the Company.

14. Technology, Security, Training and Review

  • The Company will use secure, encrypted platforms for digital KYC, conduct adequate security audits, and mask or redact sensitive information such as Aadhaar numbers.
  • The Company will conduct ongoing training for employees and authorised personnel on KYC/AML obligations and the detection of suspicious activity.
  • This Policy will be reviewed at least annually, or upon significant regulatory change, with any amendment approved by the Board of Directors. It is effective from the date of Board approval until revised or superseded.
Disclaimer: Registration with the Reserve Bank of India, where applicable, does not imply that the RBI guarantees the correctness of any statement or representation made or opinion expressed by the company, nor for the repayment of any deposits/dues. This website is for general information about Collocate Merchants Private Limited.