AML Policy

1. Introduction

Name: Rishab Kalyani

SEBI Research Analyst Registration: INH000027502

Registered/Correspondence Address: Newtown Square, Atghora, Chinar Park, 3rd Floor Unit No. 3D, Room No. 5, Kolkata, West Bengal 700136

Official Email: rarishabkalyani@gmail.com

Validity: May 21, 2026 – Perpetual

2. Purpose & Scope

Rishab Kalyani ("the Company") is committed to full compliance with the Prevention of Money-Laundering Act, 2002 (PMLA), PML Rules, 2005, and applicable SEBI AML/CFT directions and master circulars for intermediaries, as relevant to Research Analysts (RAs).

This Policy establishes a risk-based framework to prevent the use of Rishab Kalyani's research services and payment channels for money laundering, terrorism financing, sanctions evasion, fraud, or other unlawful activity.

Note: While Research Analysts do not handle client trading accounts, Rishab Kalyani voluntarily applies robust AML/CFT standards to client onboarding, payments, refunds, vendor relationships, and business counterparties.

3. Governance & Roles

  1. This Policy is reviewed at least annually or whenever new SEBI/PMLA amendments are made.
  2. Principal Officer (PML Rules) & Compliance Officer (SEBI): Rishab Kalyani
  3. Responsible for AML/CFT implementation, risk assessment, monitoring, internal reporting, and timely submission of Suspicious Transaction Reports (STRs) to FIU-IND via FINGate 2.0, where applicable. The Company is in the process of obtaining FIU registration.
  1. Lines of Defence:
  2. i.)Business teams perform Customer Due Diligence (CDD) and first-level monitoring.
  3. ii).Compliance independently oversees, tests, and reports.
  4. iii).Internal/independent review provides periodic assurance.

4. Risk-Based Approach (RBA)

  1. Enterprise-Wide Risk Assessment (EWRA): Conducted at least annually, covering client types, geographies, delivery channels (online subscriptions), products (research reports and advisories), payment methods, third parties, and technology risks.
  2. Risk Categorization: Clients, partners, and counterparties are classified as Low, Medium, or High risk using defined criteria (for example, Politically Exposed Persons (PEPs), high-risk jurisdictions, complex ownership structures, and unusual payment patterns).
  3. Enhanced Due Diligence (EDD): Applied to high-risk cases, PEPs, adverse media hits, or sanctions proximity. Approval by the Principal Officer is required.

5. Customer Acceptance & CDD/KYC

When CDD is performed: Customer Due Diligence (CDD) is conducted prior to onboarding subscribers to paid plans, execution of the Terms & Conditions (T&C) and MITC, granting institutional or corporate access, or entering into material vendor or outsourcing arrangements involving client funds or data.

Minimum KYC (Natural Persons)

  1. Full name, date of birth (DOB), nationality, and residence status.
  2. Government ID: PAN is mandatory for Indian residents; passport or OCI is required for NRIs and foreign nationals.
  3. Address proof and a recent photograph (digital copies are acceptable).
  4. Contact details: Email address, mobile number, and occupation/source of funds declaration.
  5. Payment instrument ownership: Confirmation is required. Only bank accounts, UPI, or authorized payment gateways in the client's own name are permitted.

Non-Individuals

  1. Certificate of incorporation/registration, PAN, constitutional documents, and address proof.
  2. Beneficial ownership identification (10% or greater ownership or control, as applicable).
  3. Board resolution or authorized signatory list, along with KYC of authorized persons.
  4. GSTIN (if applicable).

Additional Rules

  1. No cash payments are accepted.
  2. Third-party payments are not allowed. Refunds will be made only to the original payment source.
  3. For non-face-to-face or online onboarding, apply Enhanced Due Diligence (EDD), including e-KYC, penny-drop or micro-debit verification, and liveness/OTP controls.
  4. Sanctions Screening: Names are screened against UN, Indian, and other applicable sanctions lists, as well as adverse media, during onboarding and periodically thereafter.
  5. Politically Exposed Persons (PEPs): Senior management approval, Enhanced Due Diligence (EDD), and ongoing enhanced monitoring are required.

6. Ongoing Monitoring

  1. i.)Automated and manual reviews of:
    1. Mismatches between the client profile and subscription/payment behavior.
    2. Multiple or rapid plan upgrades or cancellations with refund requests.
    3. Payments originating from, or high activity while masking location (VPN/TOR), or activity from high-risk jurisdictions.
    4. Use of company cards by unrelated individuals, or corporate subscriptions inconsistent with the business profile.
    5. Affiliates or referrers requesting unusual fee splits or routing through layered entities.
  2. ii).Trigger-based refresh of KYC for material changes or risk re-ratings.
  3. iii).Periodic name screening rechecks for active clients and relevant third parties.

7. Red Flags (Illustrative)

  1. Identity inconsistencies, reluctance to provide KYC information, or forged/altered documents.
  2. Payment instruments not in the subscriber's name or frequent refunds to different accounts.
  3. Subscriptions purchased from or for sanctioned or embargoed locations.
  4. Attempts to route payments through cryptocurrency, cash proxies, or unregulated wallets.
  5. Pressure to expedite onboarding through unusual urgency or incentives.
  6. Adverse media relating to financial crime, bribery, terrorism, or market abuse.

8. Record Keeping & Data Protection

  1. Retention: CDD, transaction, and screening records are retained for 5 years from the end of the customer relationship or transaction, or longer where required by law or requested by regulators or law enforcement agencies.
  2. Confidentiality: STR and AML records are confidential and accessible only on a strict need-to-know basis.
  3. Data Security: Personal data is handled in accordance with applicable data protection laws and stored securely using appropriate access controls and audit trails.

9. Regulatory Reporting

  1. The Principal Officer evaluates alerts and determines whether further investigation or regulatory reporting is required.
  2. CSSPL cooperates with SEBI, FIU-IND, and law enforcement agencies (LEAs) while maintaining confidentiality and complying with the prohibition on "tipping off."
  3. Cash Transaction Reports (CTR): Cash transactions are not expected because cash payments are prohibited. Any inadvertent cash transaction is escalated immediately and reported where legally required.

10. Employee & Partner Controls

  1. Training: Mandatory AML/CFT induction and at least annual refresher training tailored to Research Analyst (RA) operations, including KYC, screening, red flags, and reporting.
  2. Outsourcing/Partners/Affiliates: Contractual clauses require AML compliance, audit rights, and immediate reporting of suspicious matters.
  3. Employee Due Diligence: Pre-employment screening proportionate to the role, along with acknowledgment of AML responsibilities and confidentiality obligations.

11. Internal Controls, Testing & Audit

  1. Documented Standard Operating Procedures (SOPs) for onboarding, screening, monitoring, escalation, Suspicious Transaction Report (STR) filing, refunds, vendor/affiliate onboarding, and record keeping.
  2. Independent Testing: Internal audit or a qualified external reviewer conducts testing at least annually to assess the design and operating effectiveness of AML controls. Findings are tracked through to closure.

12. Disciplinary Measures & Non-Retaliation

  1. Breaches of this Policy may result in disciplinary action, including termination and reporting to the appropriate authorities.
  2. Good-faith reporting: Reporting concerns in good faith is protected. Retaliation against any person making such a report is strictly prohibited.

13. Policy Ownership, Review & Versioning

  1. Owner: Principal Officer & Compliance Officer – Rishab Kalyani.
  2. Review Cycle: This Policy is reviewed at least annually or whenever there are regulatory or business changes.