Preamble and objective
In line with RBI’s Know Your Customer (KYC) guidelines and the FATF recommendations on Anti-Money-Laundering (AML) and Combating Financing of Terrorism (CFT), Recapita Finance Private Limited has adopted a board-approved KYC and AML framework. Its objective is to prevent the Company from being used, intentionally or unintentionally, for money laundering or terrorist financing, and to help the Company know and understand its customers and their financial dealings so as to manage its risks prudently.
Scope
This policy applies to all employees and agents involved in customer onboarding, transaction monitoring and compliance functions, and to all categories of customers — including individuals, corporations and politically exposed persons (PEPs). All customer data collected for KYC purposes is handled securely and protected under applicable data-protection laws.
Key elements
- Customer Acceptance Policy (CAP) — no anonymous, fictitious or benami accounts; risk perception parameters clearly defined.
- Customer Identification Procedure (CIP) — identity and address verified on the basis of an Officially Valid Document (OVD) or e-KYC via UIDAI.
- Monitoring of transactions — ongoing due diligence proportionate to the risk category of the account.
- Risk management — management oversight, systems, controls, segregation of duties and staff training.
Customer due diligence
For individuals, the Company obtains a certified copy of an OVD containing proof of identity and address, a recent photograph, and such other documents as required. e-KYC through UIDAI is accepted as a valid process. Simplified measures and ‘small accounts’ are available for low-risk customers who do not possess a standard OVD, subject to the conditions and monitoring prescribed by the PML Rules.
Risk categorisation
| Risk category | Illustrative customers |
|---|---|
| Low risk | Salaried employees; self-employed individuals / proprietary firms; government departments; limited companies; registered partnership firms. |
| Medium risk | NGOs; registered societies. |
| High risk | Politically exposed persons; NRIs; transactions linked to high-risk countries; cash-intensive or high down-payment transactions; trusts. |
Periodic updation
KYC is re-verified at least once every two years for high-risk customers, every eight years for medium-risk customers and every ten years for low-risk customers. High-risk accounts are subject to more intensive monitoring, with risk categorisation reviewed at least once every six months. Customers may be notified for KYC updates by email or SMS and may provide updated information online, by post or in person at a branch.
Governance and confidentiality
The Company nominates a Designated Director and appoints a Principal Officer responsible for compliance, monitoring and reporting to FIU-IND. Information collected from customers is treated as confidential and is not used for cross-selling without the customer’s express consent. Customer data is stored in encrypted systems and monitored by analytics to detect suspicious activity.
