Orin Financial Advisory Private Limited
Legal

Corporate Governance Policy

DhanLY · Orin Financial Advisory Private Limited

Version
1.0
Effective Date
1st June 2026
Approved By
Board of Directors
Review Frequency
Annual, or earlier if required by regulatory changes

1. Purpose

Orin Financial Advisory Private Limited ("OFAPL" or the "Company"), operating under the brand name DhanLY, is committed to maintaining the highest standards of corporate governance, ethical conduct, regulatory compliance, transparency, accountability, and customer protection.

As a Lending Service Provider ("LSP"), OFAPL supports regulated Banks and Non-Banking Financial Companies ("Lending Partners") through technology-enabled customer acquisition, onboarding, underwriting assistance, servicing support, customer engagement, and other allied services.

This Corporate Governance Policy establishes the principles and governance framework through which the Company conducts its business in a responsible, transparent, and compliant manner while safeguarding the interests of customers, lending partners, regulators, employees, and other stakeholders.

2. Scope

This Policy applies to:

  • Directors of the Company
  • Senior Management
  • Employees
  • Consultants
  • Contractual Staff
  • Technology Service Providers
  • Outsourced Vendors
  • Any individual or entity acting on behalf of OFAPL

All personnel are expected to understand and comply with this Policy while discharging their responsibilities.

3. Governance Philosophy

The Company's governance framework is built upon the following principles:

  • Integrity in business conduct
  • Compliance with applicable laws and regulations
  • Fair treatment of customers
  • Responsible use of technology and customer data
  • Transparency in business operations
  • Accountability for decision-making
  • Effective risk oversight
  • Ethical business practices
  • Continuous improvement

The Company believes that sound governance enhances customer confidence and supports sustainable business growth.

4. Role of the Board of Directors

The Board of Directors is responsible for providing strategic direction and oversight to the Company. The Board shall:

  • Approve significant business strategies and policies.
  • Ensure compliance with applicable laws and regulatory requirements.
  • Promote ethical conduct throughout the organization.
  • Oversee risk management practices.
  • Monitor financial and operational performance.
  • Ensure customer interests remain protected.
  • Review key compliance matters periodically.
  • Oversee information security and data protection initiatives.

The Board may delegate operational responsibilities to management while retaining overall oversight.

5. Responsibilities of Management

Senior Management shall be responsible for implementing the governance principles approved by the Board. Management responsibilities include:

  • Conducting business ethically.
  • Ensuring regulatory compliance.
  • Maintaining operational controls.
  • Supervising outsourced service providers.
  • Monitoring customer grievances.
  • Reporting significant operational or compliance issues to the Board.
  • Ensuring adequate employee awareness regarding applicable policies.

Management shall foster a culture where compliance and ethical behaviour form an integral part of daily operations.

6. Regulatory Compliance

The Company shall comply with all applicable laws, regulations and directions issued by competent authorities, including but not limited to:

  • Reserve Bank of India (RBI)
  • Information Technology Act, 2000
  • Digital Personal Data Protection Act, 2023
  • Prevention of Money Laundering Act, 2002
  • Payment and Settlement Systems Act, 2007
  • Applicable consumer protection laws

As an LSP, the Company acknowledges that loan sanctioning and lending decisions remain the sole responsibility of its regulated Lending Partners.

The Company shall operate strictly within the scope permitted under applicable RBI guidelines governing Digital Lending and Lending Service Providers.

7. Ethical Business Conduct

The Company expects all employees and representatives to conduct business honestly, fairly and professionally. Employees shall:

  • Avoid conflicts of interest.
  • Maintain confidentiality of customer information.
  • Refrain from accepting inappropriate gifts or inducements.
  • Deal fairly with customers and business partners.
  • Protect Company assets.
  • Report suspected misconduct promptly.

Any violation of ethical standards may attract disciplinary action.

8. Customer Protection

Customer trust remains central to the Company's operations. Accordingly, the Company shall:

  • Ensure transparent customer communication.
  • Obtain appropriate customer consent before collecting personal information.
  • Avoid misleading advertisements or representations.
  • Respect customer privacy.
  • Provide accessible grievance redressal mechanisms.
  • Ensure that customer information is processed only for legitimate business purposes.

The Company shall endeavour to maintain fair and courteous interactions with all customers throughout the customer lifecycle.

9. Information Security and Data Privacy

The Company recognises that protection of customer information is fundamental to responsible digital financial services. Accordingly, the Company shall:

  • Implement appropriate technical and organisational security measures.
  • Restrict access to customer information based on business need.
  • Maintain secure storage of sensitive information.
  • Protect systems against unauthorised access.
  • Periodically review information security controls.
  • Ensure third-party service providers adhere to appropriate security standards.

Customer information shall not be disclosed except where permitted by applicable law, customer consent, or contractual obligations with Lending Partners.

10. Vendor Governance

The Company works with various technology providers and business partners to deliver its services. Before engaging vendors, the Company shall evaluate:

  • Business capability
  • Information security standards
  • Regulatory compliance
  • Operational reliability
  • Reputation
  • Service quality

The Company shall periodically monitor vendor performance and ensure that outsourced activities do not compromise customer interests or regulatory obligations.

11. Internal Controls

The Company shall establish internal controls designed to:

  • Safeguard Company assets.
  • Protect customer information.
  • Ensure reliable operational processes.
  • Prevent fraud.
  • Detect operational deficiencies.
  • Promote regulatory compliance.

Management shall periodically review the adequacy of these controls and implement corrective actions wherever necessary.

12. Conflict of Interest

Employees and Directors shall avoid situations where personal interests conflict with the interests of the Company or its customers.

Any actual or potential conflict of interest shall be disclosed promptly to the appropriate reporting authority.

The Company shall take appropriate measures to manage such conflicts fairly and transparently.

13. Customer Grievance Oversight

The Company shall maintain an effective grievance redressal framework to ensure timely resolution of customer complaints. Management shall periodically review:

  • Complaint volumes
  • Resolution timelines
  • Root causes
  • Corrective actions

Insights from customer complaints shall be used to continuously improve products, processes and customer experience.

14. Policy Review

This Policy shall be reviewed at least annually or earlier in the event of:

  • Regulatory changes;
  • Material changes in business operations;
  • Changes in RBI guidelines;
  • Significant operational developments.

Any amendments shall be approved by the Board of Directors or an authorised committee.

15. Disclaimer

This Policy is intended to establish the governance framework of Orin Financial Advisory Private Limited.

Nothing contained herein shall override any applicable law, regulation, or contractual obligation. In case of any inconsistency, the applicable law or regulatory direction shall prevail.