AML Policy
1. Introduction
Name: Rishab Kalyani
SEBI Research Analyst Registration: INH000027502
Registered/Correspondence Address: Newtown Square, Atghora, Chinar Park, 3rd Floor Unit No. 3D, Room No. 5, Kolkata, West Bengal 700136
Official Email: rarishabkalyani@gmail.com
Validity: May 21, 2026 – Perpetual
2. Purpose & Scope
Rishab Kalyani ("the Company") is committed to full compliance with the Prevention of Money-Laundering Act, 2002 (PMLA), PML Rules, 2005, and applicable SEBI AML/CFT directions and master circulars for intermediaries, as relevant to Research Analysts (RAs).
This Policy establishes a risk-based framework to prevent the use of Rishab Kalyani's research services and payment channels for money laundering, terrorism financing, sanctions evasion, fraud, or other unlawful activity.
Note: While Research Analysts do not handle client trading accounts, Rishab Kalyani voluntarily applies robust AML/CFT standards to client onboarding, payments, refunds, vendor relationships, and business counterparties.
3. Governance & Roles
- This Policy is reviewed at least annually or whenever new SEBI/PMLA amendments are made.
- Principal Officer (PML Rules) & Compliance Officer (SEBI): Rishab Kalyani
- Responsible for AML/CFT implementation, risk assessment, monitoring, internal reporting, and timely submission of Suspicious Transaction Reports (STRs) to FIU-IND via FINGate 2.0, where applicable. The Company is in the process of obtaining FIU registration.
- Lines of Defence:
- i.)Business teams perform Customer Due Diligence (CDD) and first-level monitoring.
- ii).Compliance independently oversees, tests, and reports.
- iii).Internal/independent review provides periodic assurance.
4. Risk-Based Approach (RBA)
- Enterprise-Wide Risk Assessment (EWRA): Conducted at least annually, covering client types, geographies, delivery channels (online subscriptions), products (research reports and advisories), payment methods, third parties, and technology risks.
- Risk Categorization: Clients, partners, and counterparties are classified as Low, Medium, or High risk using defined criteria (for example, Politically Exposed Persons (PEPs), high-risk jurisdictions, complex ownership structures, and unusual payment patterns).
- Enhanced Due Diligence (EDD): Applied to high-risk cases, PEPs, adverse media hits, or sanctions proximity. Approval by the Principal Officer is required.
5. Customer Acceptance & CDD/KYC
When CDD is performed: Customer Due Diligence (CDD) is conducted prior to onboarding subscribers to paid plans, execution of the Terms & Conditions (T&C) and MITC, granting institutional or corporate access, or entering into material vendor or outsourcing arrangements involving client funds or data.
Minimum KYC (Natural Persons)
- Full name, date of birth (DOB), nationality, and residence status.
- Government ID: PAN is mandatory for Indian residents; passport or OCI is required for NRIs and foreign nationals.
- Address proof and a recent photograph (digital copies are acceptable).
- Contact details: Email address, mobile number, and occupation/source of funds declaration.
- Payment instrument ownership: Confirmation is required. Only bank accounts, UPI, or authorized payment gateways in the client's own name are permitted.
Non-Individuals
- Certificate of incorporation/registration, PAN, constitutional documents, and address proof.
- Beneficial ownership identification (10% or greater ownership or control, as applicable).
- Board resolution or authorized signatory list, along with KYC of authorized persons.
- GSTIN (if applicable).
Additional Rules
- No cash payments are accepted.
- Third-party payments are not allowed. Refunds will be made only to the original payment source.
- For non-face-to-face or online onboarding, apply Enhanced Due Diligence (EDD), including e-KYC, penny-drop or micro-debit verification, and liveness/OTP controls.
- Sanctions Screening: Names are screened against UN, Indian, and other applicable sanctions lists, as well as adverse media, during onboarding and periodically thereafter.
- Politically Exposed Persons (PEPs): Senior management approval, Enhanced Due Diligence (EDD), and ongoing enhanced monitoring are required.
6. Ongoing Monitoring
-
i.)Automated and manual reviews of:
- Mismatches between the client profile and subscription/payment behavior.
- Multiple or rapid plan upgrades or cancellations with refund requests.
- Payments originating from, or high activity while masking location (VPN/TOR), or activity from high-risk jurisdictions.
- Use of company cards by unrelated individuals, or corporate subscriptions inconsistent with the business profile.
- Affiliates or referrers requesting unusual fee splits or routing through layered entities.
- ii).Trigger-based refresh of KYC for material changes or risk re-ratings.
- iii).Periodic name screening rechecks for active clients and relevant third parties.
7. Red Flags (Illustrative)
- Identity inconsistencies, reluctance to provide KYC information, or forged/altered documents.
- Payment instruments not in the subscriber's name or frequent refunds to different accounts.
- Subscriptions purchased from or for sanctioned or embargoed locations.
- Attempts to route payments through cryptocurrency, cash proxies, or unregulated wallets.
- Pressure to expedite onboarding through unusual urgency or incentives.
- Adverse media relating to financial crime, bribery, terrorism, or market abuse.
8. Record Keeping & Data Protection
- Retention: CDD, transaction, and screening records are retained for 5 years from the end of the customer relationship or transaction, or longer where required by law or requested by regulators or law enforcement agencies.
- Confidentiality: STR and AML records are confidential and accessible only on a strict need-to-know basis.
- Data Security: Personal data is handled in accordance with applicable data protection laws and stored securely using appropriate access controls and audit trails.
9. Regulatory Reporting
- The Principal Officer evaluates alerts and determines whether further investigation or regulatory reporting is required.
- CSSPL cooperates with SEBI, FIU-IND, and law enforcement agencies (LEAs) while maintaining confidentiality and complying with the prohibition on "tipping off."
- Cash Transaction Reports (CTR): Cash transactions are not expected because cash payments are prohibited. Any inadvertent cash transaction is escalated immediately and reported where legally required.
10. Employee & Partner Controls
- Training: Mandatory AML/CFT induction and at least annual refresher training tailored to Research Analyst (RA) operations, including KYC, screening, red flags, and reporting.
- Outsourcing/Partners/Affiliates: Contractual clauses require AML compliance, audit rights, and immediate reporting of suspicious matters.
- Employee Due Diligence: Pre-employment screening proportionate to the role, along with acknowledgment of AML responsibilities and confidentiality obligations.
11. Internal Controls, Testing & Audit
- Documented Standard Operating Procedures (SOPs) for onboarding, screening, monitoring, escalation, Suspicious Transaction Report (STR) filing, refunds, vendor/affiliate onboarding, and record keeping.
- Independent Testing: Internal audit or a qualified external reviewer conducts testing at least annually to assess the design and operating effectiveness of AML controls. Findings are tracked through to closure.
12. Disciplinary Measures & Non-Retaliation
- Breaches of this Policy may result in disciplinary action, including termination and reporting to the appropriate authorities.
- Good-faith reporting: Reporting concerns in good faith is protected. Retaliation against any person making such a report is strictly prohibited.
13. Policy Ownership, Review & Versioning
- Owner: Principal Officer & Compliance Officer – Rishab Kalyani.
- Review Cycle: This Policy is reviewed at least annually or whenever there are regulatory or business changes.