AML & KYC Policy
Mahalaxmi Capital Group ("the Company") is committed to preventing money laundering, terrorist financing, proliferation financing, and other related financial crimes. This Anti-Money Laundering (AML) and Know Your Customer (KYC) Policy ("Policy") sets out the controls, procedures and obligations we follow in compliance with the Prevention of Money Laundering Act, 2002 (PMLA), the Rules notified thereunder, the RBI Master Direction on KYC, and other applicable laws and regulations issued by regulators in India from time to time.1. Objectives of the PolicyThe objectives of this Policy are to:• Prevent the misuse of our products, services and platform for money laundering, terrorist financing, proliferation financing, fraud, bribery, corruption, or other unlawful activity;• Comply with the KYC / AML / CFT obligations laid down by the RBI, SEBI, FIU-IND and other regulators;• Verify the identity and profile of every customer using reliable, independent sources;• Monitor, detect and report suspicious transactions to the appropriate authorities;• Maintain proper records for the periods prescribed by law;• Train our employees and outsourced agents on AML / KYC obligations and red-flag indicators.2. Definition of "Customer"For the purpose of this Policy, "Customer" means any person or entity that:• Applies for or avails any product or service offered by the Company or its Lending Partners;• Visits our website, submits an enquiry, registers on our platform, or interacts with us in any manner;• Acts as a guarantor, co-applicant, power of attorney holder, beneficial owner, or in any other capacity connected with a loan or service;• Undertakes any transaction on behalf of themselves or a third party.3. KYC — Know Your CustomerWe follow a risk-based approach to KYC. The level of KYC scrutiny applied depends on the customer''s risk profile, the product / service sought, the value and nature of the transaction, and the regulatory category (low / medium / high risk).3.1 Customer Identification Procedure (CIP)We collect, verify and record at least the following information before establishing any relationship or processing a transaction:• Identity Proof — PAN (mandatory), Aadhaar (with consent), Passport, Voter ID, Driving Licence, or any other officially valid document (OVD) as defined by the RBI;• Address Proof — Aadhaar, Passport, Utility Bill (not older than 3 months), Bank Statement, or any other OVD;• Date of Birth — from the OVD;• Permanent Account Number (PAN) — mandatory for all financial transactions, irrespective of amount;• Photograph — captured live or as part of the OVD;• Signature — for paper-based and certain digital journeys;• Mobile number and email address — verified through OTP / e-mail link;• Bank Account — verified through penny-drop or equivalent;• Income / Financial Information — for loan applications: salary slips, Form 16, ITR, bank statements, and other proof of income;• Nature of business / occupation — for non-individuals, we additionally collect incorporation documents, board resolutions, and beneficial ownership information.3.2 Customer Due Diligence (CDD)Simplified Due Diligence (SDD): May be applied to low-risk customers such as existing customers with clean history, government entities, and public sector undertakings.Normal CDD: Applied to all other customers, including standard identity and address verification, screening against sanctions lists, and risk categorisation.Enhanced Due Diligence (EDD): Applied to high-risk customers, including Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, customers with unusual transaction patterns, non-face-to-face relationships, and complex / large transactions. EDD includes additional verification, senior management approval, source-of-funds checks, and ongoing enhanced monitoring.3.3 Beneficial OwnershipFor non-individual customers (companies, partnerships, trusts, societies, LLPs), we identify and verify the natural persons who ultimately own or control the entity, and the persons on whose behalf the transaction is conducted. We require the Beneficial Owner (BO) to be identified using a threshold of 10% ownership / control, in line with PMLA Rules.3.4 KYC for Walk-in / One-time CustomersWe do not knowingly entertain anonymous walk-in customers. For any cash or large transaction with a non-account holder, full KYC (at least OVD + PAN) is mandatory regardless of the amount, in line with PMLA Rules.4. Customer Acceptance PolicyWe accept customers only after:• Completion of the required KYC process;• Successful verification of identity, address and other particulars;• Negative screening against sanctions, watchlists and adverse media lists;• Risk categorisation and assignment of the appropriate due-diligence level;• Receipt of all necessary consents (data sharing, communication, credit bureau check, etc.).We reserve the right to reject an application, suspend an account, or terminate a relationship if KYC is incomplete, fails verification, or the customer is found on a sanctions / negative list.5. Risk Management & CategorisationCustomers are categorised as Low, Medium or High risk based on:• Customer profile (identity, occupation, source of funds, geography);• Product / service used;• Transaction pattern, value and frequency;• Country of origin / destination (with reference to FATF and RBI high-risk lists);• Whether the customer is a PEP.The risk categorisation is reviewed periodically and updated when new information becomes available. Higher-risk customers are subject to enhanced monitoring and EDD.6. Ongoing Monitoring & Transaction Reporting6.1 Ongoing Monitoring: We monitor customer transactions on an ongoing basis to detect unusual activity, structuring, rapid in-and-out movement of funds, transactions inconsistent with the customer''s profile, and other red-flag indicators.6.2 Suspicious Transaction Reporting (STR): Any transaction (or attempted transaction) that is, or appears to be, connected with the proceeds of crime, terrorism, or any other unlawful activity, is reported to the Director, FIU-IND, in the prescribed format and within the prescribed timelines.6.3 Cash Transaction Reporting (CTR): All cash transactions of ₹10 lakh and above (and any series of cash transactions below ₹10 lakh that are integrally connected) are reported to FIU-IND through the prescribed CTR.6.4 Counterfeit Currency: Any suspected counterfeit currency received from a customer is retained and reported to the police / RBI as required.6.5 Negative List Screening: Customers, beneficial owners and counterparties are screened against UN, OFAC, EU, HMT, RBI and other applicable sanctions lists, both at onboarding and on a periodic basis.7. Record KeepingWe maintain the following records for a minimum of five (5) years from the date of the transaction or the closure of the relationship, whichever is later, in line with PMLA Rules:• Customer identification documents and KYC records;• Transaction records (including the originator, beneficiary, amount, currency, date, and account details);• Internal findings, risk assessments and EDD documentation;• Records relating to the internal investigation of suspicious activity;• Copies of STR / CTR filed with FIU-IND.Records are maintained in a manner that allows them to be retrieved without undue delay and produced to regulators upon request.8. Reporting to FIU-IND & Other AuthoritiesWe comply with all reporting obligations under the PMLA and the Rules, including:• Filing Cash Transaction Reports (CTR) for cash transactions of ₹10 lakh and above;• Filing Suspicious Transaction Reports (STR) for any transaction suspected to be related to proceeds of crime;• Reporting counterfeit currency;• Responding to enquiries and providing information to the FIU-IND, RBI, police, ED and other authorities as required.No employee, officer or agent of the Company shall disclose the fact that an STR or related report has been filed, except to the regulator or to authorised persons within the Company on a need-to-know basis.9. Designated Director & Principal OfficerIn line with Rule 8 of the PMLA Rules, the Board has appointed:• A Designated Director who is responsible for ensuring compliance with the obligations under the PMLA and the Rules;• A Principal Officer who is the point of contact for the FIU-IND and is responsible for the day-to-day implementation of this Policy.Their contact details are available on the Grievance Redressal page.10. Sanctions for Non-ComplianceNon-compliance with this Policy, the PMLA, the PMLA Rules or any other applicable law is a serious matter. Employees and outsourced agents who knowingly or wilfully violate this Policy are subject to disciplinary action, up to and including termination of employment, and may be subject to regulatory and criminal prosecution.11. TrainingAll employees, officers and outsourced agents undergo initial and ongoing AML / KYC training covering:• Their obligations under the PMLA, PMLA Rules and RBI KYC Direction;• Red-flag indicators of money laundering and terrorist financing;• Procedures for customer identification, monitoring, escalation and reporting;• Tipping-off and confidentiality requirements;• Recent typologies and case studies.Training records are maintained for inspection.12. Internal Controls, Audit & ReviewThe Company has put in place internal controls, including segregation of duties, maker-checker processes, system-based rule engines, and an independent compliance review, to ensure the effectiveness of this Policy. The Policy is reviewed at least annually and updated to reflect changes in law, regulation, risk profile or business activity.13. Whistle-blower & Tipping-off ProtectionEmployees and agents are encouraged to report any actual or suspected violation of this Policy to the Principal Officer or to the Designated Director, on a confidential basis. No retaliation will be tolerated against any person making a good-faith report. The fact that an STR has been filed is confidential and must not be disclosed to the customer or to any third party.14. OutsourcingWhen any KYC or AML-related activity is outsourced, we ensure that the third-party service provider is competent, has the necessary data-protection and confidentiality controls in place, and is subject to the same regulatory standards that we are. The ultimate responsibility for AML / KYC compliance rests with the Company and cannot be outsourced.15. Effectiveness & UpdatesThis Policy is approved by the Board and is reviewed at least once a year, or whenever there is a material change in the regulatory environment, our business or the risk profile. The latest version is available on the website.