Licensing notice Kadyan Paygate India (OPC) Private Limited holds an NPCI Agent Institution licence for Bharat Connect (BBPS). This is the only licence we hold. We are not licensed or regulated by the Reserve Bank of India. Prepaid cards are issued by our RBI-licensed partner banks and issuers, and customer funds are held by those partners, not by us. How we work
Talk to us
ExpensesBill paymentsLoyalty EngagementCardsHow we work Grievance redressalPrivacy & cookies Talk to us
Policy

Anti-Money Laundering and Know Your Customer Policy

How we identify the businesses and people we work with, how we watch for financial crime, and how we work with our RBI-licensed partners and NPCI to meet the standards the law sets.

Version 1.0Effective 13 September 2026Issued by Kadyan Paygate India (OPC) Private Limited

Purpose, scope and legal basis

This policy sets out how Kadyan Paygate India prevents its platform from being used for money laundering, terrorist financing, proliferation financing, fraud or any other financial crime, and how we identify and verify the businesses and individuals we deal with. It applies to every client, every cardholder and beneficiary onboarded through a client's programme, every bill payer on Bharat Connect, every employee, and every third party that acts for us.

It is written to the standards of:

  • The Prevention of Money-Laundering Act, 2002 (PMLA) and the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (PML Rules), as amended, including the 2023 amendments on beneficial ownership.
  • The Reserve Bank of India's Master Direction – Know Your Customer (KYC) Direction, 2016, as amended from time to time.
  • The Reserve Bank of India's Master Directions on Prepaid Payment Instruments, 2021, as amended.
  • The Unlawful Activities (Prevention) Act, 1967 (UAPA), the Weapons of Mass Destruction and their Delivery Systems (Prohibition of Unlawful Activities) Act, 2005, and the procedures issued under them for freezing assets of designated persons.
  • The Financial Action Task Force (FATF) Recommendations and the procedural guidelines of NPCI Bharat BillPay applicable to Agent Institutions.
Our position. Kadyan Paygate India (OPC) Private Limited holds an NPCI Agent Institution licence for Bharat Connect and no other licence. The "reporting entities" under the PMLA for card programmes on our platform are our RBI-licensed partner banks and issuers; for bill payments they are the operating units on the Bharat Connect network. We adopt this policy because those partners and NPCI require it of us, because our contracts with them make us responsible for the first line of defence, and because we choose to operate to the same standard that applies to them. Where this policy says "we verify", it means we perform or obtain the verification to the standard the relevant partner requires and make the results available to that partner.

Governance and responsibilities

  • Principal Officer. The Director of the company acts as Principal Officer for anti-money-laundering matters, at management level as the PML Rules require. The Principal Officer is responsible for this policy, for liaison with partner institutions, NPCI and law-enforcement agencies, and for ensuring that suspicious matters are escalated to the appropriate reporting entity without delay. Contact: legal@kadyanindustries.com.
  • Maker and checker. No onboarding decision, limit change, or exception to this policy is made by a single person. Every such action is proposed by one authorised user and approved by a different one, and both are recorded.
  • Independent review. Compliance with this policy is tested at least annually by a person independent of the onboarding and operations functions, and the findings are reported to the Director.
  • Training. Every employee completes AML/KYC training on joining and at least annually thereafter. Staff in onboarding, operations and support receive role-specific training covering red flags for the products they handle.
  • Employee screening. Employees and contractors with access to customer data or money movement are screened before appointment, including identity, address, and sanctions checks.

Customer acceptance policy

We will not:

  • Open an account or issue an instrument in an anonymous or fictitious name, or where the identity of the client or its beneficial owners cannot be established.
  • Onboard any person or entity appearing on the United Nations Security Council sanctions lists (including the 1267/1989 and 1988 committees' lists), the lists notified by the Ministry of Home Affairs under the UAPA, the lists maintained under the WMD Act, or any list our partner institutions require us to screen against.
  • Onboard a business engaged in a prohibited category (see the Onboarding Policy) or one that refuses to provide the information required for due diligence.
  • Proceed where a client attempts to structure its relationship or transactions to avoid identification or reporting thresholds.
  • Allow a relationship to continue where periodic re-verification cannot be completed after reasonable notice.

Every prospective client is screened against sanctions lists, politically exposed person (PEP) databases and adverse media before onboarding and again on a continuing basis. A positive match is escalated to the Principal Officer before any further step is taken.

Customer identification and due diligence

Business clients (know your business)

For every company, LLP, partnership, proprietorship, trust or society we onboard, we obtain and verify:

  • Proof of legal existence and registration: certificate of incorporation and CIN, LLP or partnership registration, trust deed or society registration, as applicable; and constitutional documents (memorandum and articles, partnership deed, LLP agreement, trust deed).
  • Permanent Account Number of the entity, verified against the income-tax database, and GST registration verified on the GST portal, or a declaration explaining why GST registration is not required.
  • The resolution or authority under which the entity is entering the relationship, and the names, designations and identity documents of the persons authorised to operate the account.
  • Identification of every beneficial owner — any natural person who, directly or indirectly, holds 10% or more of the shares, capital or profits of a company, 10% or more of the capital or profits of a partnership, 15% or more of the property or capital of an unincorporated body, or, for a trust, the author, trustees, beneficiaries with 10% or more interest, and any protector. Where no natural person is identified on this basis, the senior managing official is recorded. Companies listed on a recognised stock exchange in India (or a notified foreign exchange) and their subsidiaries are exempt from beneficial-owner identification as the law permits.
  • Identity and address verification of each beneficial owner and authorised signatory to the individual standard below.
  • The nature of the business, the purpose of the relationship, the expected products, volumes and geographies, and the source of funds that will be loaded onto the platform.

Individuals (cardholders, beneficiaries, bill payers)

Individuals are identified using an officially valid document as defined in the PML Rules: passport, driving licence, Voter's Identity Card, NREGA job card signed by a State Government officer, a letter from the National Population Register, or proof of possession of an Aadhaar number, in each case together with the Permanent Account Number or Form 60. Verification is carried out by one of the methods permitted to our partner institutions under the KYC Direction:

  • Aadhaar offline verification or Aadhaar OTP-based e-KYC, only where the individual voluntarily chooses it and only through the licensed partner entitled to perform it.
  • Video-based customer identification process (V-CIP) conducted by trained officials of the partner institution in accordance with the KYC Direction.
  • Digital KYC using a live photograph and geo-tagged capture of the document.
  • Retrieval of a KYC record from the Central KYC Records Registry (CKYCR) using the KYC identifier, where the individual consents.
  • Equivalent e-documents issued through DigiLocker.

KYC levels for prepaid instruments

The level of verification and the limits that apply to any prepaid instrument on our platform are those prescribed by the RBI's Master Directions on Prepaid Payment Instruments and applied by the issuing partner. In summary:

InstrumentIdentification requiredIndicative limits under the RBI directions
Small PPI (minimum-detail)Minimum details as prescribed; PAN or Form 60; OTP-verified mobileLoading not exceeding ₹10,000 per month and ₹1,20,000 per financial year; outstanding balance not exceeding ₹10,000; cash withdrawal and fund transfer not permitted; must be converted to a full-KYC instrument within the period prescribed
Full-KYC PPIFull customer due diligence as aboveOutstanding balance not exceeding ₹2,00,000 at any time; fund transfer and cash withdrawal as permitted by the directions
Gift PPIIssuer verifies the purchaser; recipient details as prescribedMaximum value ₹10,000; non-reloadable; no cash-out; no fund transfer
Corporate or employee programmeFull KYC of the corporate client; KYC of each employee or beneficiary by the issuing partner before activationAs applicable to the underlying instrument type

These figures are reproduced for transparency and are subject to the RBI directions in force at the time; the issuing partner's limits prevail. No instrument is activated on our platform until the issuing partner confirms that the required KYC has been completed.

Risk categorisation and periodic review

Every client and, where applicable, every individual is assigned a risk category of low, medium or high at onboarding, based on the nature of the business, the products used, the delivery channel, the geography of the client and its counterparties, the expected volumes, the ownership structure, the presence of any PEP among the owners or signatories, and the results of screening. The category is recorded with the reasons and is reviewed whenever a material change comes to our attention.

CategoryTypical indicatorsKYC updation (in line with the KYC Direction)
LowEstablished Indian company with transparent ownership, listed or subsidiary of listed entity, government body, regulated financial institution, low-value programmesAt least once every 10 years
MediumPrivate companies with straightforward ownership, moderate volumes, standard categoriesAt least once every 8 years
HighComplex or layered ownership, PEP involvement, high-risk jurisdictions (as per FATF), cash-intensive or restricted categories, non-face-to-face onboarding, adverse media, non-profit organisations, unusual volumes relative to the stated businessAt least once every 2 years, with enhanced due diligence

Enhanced due diligence

For high-risk relationships we additionally obtain approval from the Principal Officer before onboarding, establish and document the source of funds and, for PEPs, the source of wealth, obtain senior-management approval to continue a relationship where a client or beneficial owner subsequently becomes a PEP, and apply tighter transaction limits and closer monitoring. Non-face-to-face onboarding is treated as higher risk unless verification is completed through V-CIP or an equivalent method recognised by the KYC Direction.

Transaction monitoring

We monitor activity on the platform continuously using rules that are reviewed at least annually and tuned to each product. The purpose is to detect activity inconsistent with what we know about the client. Indicators we watch for include:

  • Loads, spends or redemptions structured just below reporting or KYC thresholds, or split across multiple instruments held by connected persons.
  • Rapid loading followed by rapid withdrawal or redemption with little genuine use; balances moved between instruments without an evident business reason.
  • Volumes, values or categories of spend inconsistent with the client's stated business or with its history on the platform.
  • Multiple instruments linked to the same device, address, mobile number or bank account without a legitimate explanation.
  • Bill payments on Bharat Connect where many unrelated payers settle the same consumer number, where a single payer settles an unusually large number of unrelated consumer numbers, or where bill amounts are repeatedly overpaid and refunded.
  • Transactions involving high-risk jurisdictions, sanctioned parties, or merchants in prohibited categories.
  • Reactivation of dormant instruments followed by high-value activity.
  • Reward or incentive programmes where points are earned on transactions that appear circular, self-dealing or fabricated.

Alerts are reviewed by trained staff within one working day. Where an alert cannot be explained, the matter is escalated to the Principal Officer, activity on the affected instruments may be restricted, and the relevant partner institution is informed.

Suspicious activity, reporting and tipping-off

  • Any employee who suspects that a transaction or relationship may involve the proceeds of crime, terrorist financing or fraud must report it to the Principal Officer immediately and must not discuss it with the client.
  • The Principal Officer assesses every internal report and, where suspicion is confirmed, escalates it to the relevant reporting entity — the issuing partner for card activity, the operating unit for Bharat Connect activity — promptly and in any event within the timelines our partner agreements require, so that the reporting entity can file a Suspicious Transaction Report with the Financial Intelligence Unit – India (FIU-IND) within the period the PML Rules prescribe.
  • We provide reporting entities with the information they need for cash transaction reports, counterfeit currency reports and non-profit organisation transaction reports, where our platform is the source of the underlying data.
  • Tipping-off is prohibited. No one will inform a client, cardholder or third party that a report has been made or is being considered. Requests from clients for the reasons behind a restriction are answered only to the extent the law allows.
  • Where a client or beneficial owner is found to match a designated person under the UAPA or the WMD Act, we freeze the affected instruments and balances without delay, inform the partner institution and the nodal officer designated by the Central Government, and act on their instructions. We do not notify the client before freezing.
  • Requests from law-enforcement and regulatory agencies are handled by the Principal Officer, verified for authenticity, logged, and answered within the period required.

Record keeping

We maintain, and make available to our partner institutions, NPCI and competent authorities on request:

  • All identification and verification records for clients, beneficial owners, authorised signatories and individuals, including copies of documents, verification results, screening outputs and risk categorisations, for at least five years after the relationship ends.
  • Records of every transaction on the platform sufficient to reconstruct it — parties, amounts, currency, dates, instrument identifiers and references — for at least five years from the date of the transaction.
  • Records of alerts raised, reviews conducted, decisions taken and escalations made, together with the reasons.
  • Records of training delivered and of independent reviews of this policy.

Records are stored on infrastructure located in India, in an encrypted and access-controlled form, and are retained beyond five years where a competent authority or a partner institution requires it, or where the record is relevant to a pending matter.

Review of this policy

This policy is approved by the Director and reviewed at least annually, and immediately following any material change in the PMLA, the PML Rules, the RBI's KYC or PPI directions, NPCI's guidelines for Agent Institutions, or the requirements of a partner institution. The version and effective date appear at the top of this page. Questions about this policy may be sent to legal@kadyanindustries.com.

Questions about this policy: merchant.support@kadyanindustries.com · Legal notices: legal@kadyanindustries.com · Grievance Officer: Harsh Kadyan