Know Your Customer (KYC) & Anti-Money Laundering (AML) Policy
DhanLY · Orin Financial Advisory Private Limited
1.0
1st June 2026
Board of Directors
Annual
1. Purpose
Orin Financial Advisory Private Limited ("OFAPL" or the "Company"), operating under the brand name DhanLY, is committed to preventing the misuse of its platform for money laundering, terrorist financing, identity fraud, and other financial crimes.
As a Lending Service Provider (LSP), the Company facilitates customer onboarding, identity verification, and related due diligence processes on behalf of regulated Banks and Non-Banking Financial Companies ("Lending Partners"), in accordance with applicable laws and regulatory requirements.
This Policy establishes the Company's framework for Know Your Customer ("KYC") and Anti-Money Laundering ("AML") practices to support secure and compliant lending operations.
2. Scope
This Policy applies to:
- Directors
- Employees
- Customer Operations Teams
- Compliance Personnel
- Technology Teams
- Third-party KYC Service Providers
- Vendors acting on behalf of the Company
All personnel are expected to comply with this Policy while performing customer onboarding and related activities.
3. Regulatory Framework
The Company shall conduct its KYC and AML activities in accordance with applicable laws and regulatory guidelines, including, where relevant:
- Reserve Bank of India (RBI) Master Direction – Know Your Customer (KYC)
- Prevention of Money Laundering Act, 2002 (PMLA)
- Prevention of Money Laundering Rules
- Digital Lending Guidelines issued by RBI
- Information Technology Act, 2000
- Digital Personal Data Protection Act, 2023
- Directions issued by Lending Partners
Where the Lending Partner prescribes additional KYC requirements, the Company shall support such requirements as contractually agreed.
4. Objectives
The objectives of this Policy are to:
- Verify customer identity.
- Prevent identity fraud.
- Reduce the risk of financial crime.
- Support Lending Partners in complying with regulatory obligations.
- Protect the integrity of the Company's platform.
- Ensure responsible customer onboarding.
- Promote customer confidence.
5. Customer Identification
The Company shall facilitate customer identification using reliable and legally permissible methods. Depending upon the product, applicable regulations, and Lending Partner requirements, verification may include:
- PAN verification
- Aadhaar-based authentication (where legally permissible and with customer consent)
- DigiLocker document verification
- Officially Valid Documents (OVDs)
- Bank account verification
- Mobile number verification through OTP
- Email verification
- Selfie or liveness verification (where applicable)
The Company shall collect only such information as is reasonably necessary for onboarding and servicing customers.
6. Customer Due Diligence (CDD)
The Company shall perform appropriate Customer Due Diligence to assist Lending Partners in assessing customer identity and authenticity. CDD may include:
- Verification of identity documents
- Verification of mobile number
- Verification of bank account ownership
- Address verification, where required
- Employment or income verification, where applicable
- Cross-verification through trusted third-party service providers
Applications containing incomplete, inconsistent, or suspicious information may be referred for additional verification or declined, subject to the Lending Partner's policies.
7. Risk-Based Approach
The Company adopts a risk-based approach towards customer onboarding. Customers may be assessed based on factors such as:
- Identity verification results
- Nature of employment
- Geographic location
- Transaction behaviour
- Document authenticity
- Fraud indicators
- Information provided during onboarding
Where enhanced due diligence is considered necessary, the Company may seek additional information or documentation in coordination with the Lending Partner.
8. Anti-Money Laundering Measures
The Company shall implement reasonable measures to reduce the risk of money laundering and financial crime. Such measures may include:
- Identity verification
- Transaction monitoring support
- Duplicate customer detection
- Device intelligence
- Fraud analytics
- Verification of banking details
- Screening against internal fraud indicators
- Escalation of suspicious activities to the Lending Partner where appropriate
The Company shall not knowingly facilitate transactions involving unlawful activities.
9. Politically Exposed Persons (PEPs) and Sanctions
Where required by the Lending Partner or applicable law, additional due diligence may be undertaken for customers identified as:
- Politically Exposed Persons (PEPs)
- Individuals appearing on applicable sanctions or watch lists
- High-risk customers
Appropriate escalation procedures shall be followed before onboarding such customers.
10. Record Maintenance
The Company shall maintain customer records for the period prescribed under applicable law, regulatory requirements, or contractual arrangements with Lending Partners. Records may include:
- Identity verification records
- Customer declarations
- Consent records
- KYC documents
- Audit logs
- Communication records
Such records shall be securely stored and protected against unauthorized access.
11. Data Privacy and Confidentiality
The Company recognizes that customer information is confidential. Accordingly, the Company shall:
- Collect only necessary information.
- Use customer information only for legitimate business purposes.
- Protect customer information using appropriate technical and organizational safeguards.
- Restrict access based on business need.
- Avoid unauthorized disclosure of customer information.
The Company shall comply with applicable data protection laws while processing customer information.
12. Employee Responsibilities
Employees involved in customer onboarding shall:
- Follow approved KYC procedures.
- Verify documents diligently.
- Escalate suspicious applications.
- Maintain confidentiality.
- Avoid accepting forged or incomplete documentation.
- Cooperate with internal compliance reviews.
Employees shall receive periodic awareness regarding KYC and AML obligations.
13. Reporting of Suspicious Activities
Employees who identify potentially suspicious activity shall immediately report the matter to the designated Compliance function or authorized management personnel. Examples include:
- Suspected forged documents
- Multiple applications using similar credentials
- Identity inconsistencies
- Suspicious transaction patterns
- Attempts to misrepresent customer identity
The Company shall coordinate with the relevant Lending Partner for appropriate action wherever required.
14. Third-Party Service Providers
The Company may engage specialized service providers for:
- Identity verification
- PAN verification
- DigiLocker services
- Bank account validation
- Document verification
- Fraud detection
The Company shall exercise reasonable due diligence while selecting such providers and shall require them to maintain appropriate security and confidentiality standards.
15. Monitoring and Review
The Company shall periodically review:
- KYC processes
- AML controls
- Fraud trends
- Regulatory developments
- Vendor performance
- Customer onboarding quality
Corrective measures shall be implemented wherever improvements are identified.
16. Policy Review
This Policy shall be reviewed annually or earlier if required due to:
- Changes in applicable laws or regulations.
- RBI directions.
- Changes in Lending Partner requirements.
- Introduction of new products or services.
- Significant operational or compliance developments.
Any amendments shall be approved by the Board of Directors or an authorized committee.
17. Disclaimer
This Policy establishes the Company's KYC and AML framework in its capacity as a Lending Service Provider.
The Company facilitates customer due diligence and identity verification on behalf of regulated Lending Partners. Final customer acceptance, regulatory reporting obligations, and lending decisions remain the responsibility of the respective Lending Partner, unless otherwise agreed under applicable law or contractual arrangements.
Nothing contained in this Policy shall override any applicable law, regulatory direction, or contractual obligation. In the event of any inconsistency, the applicable law or regulatory requirement shall prevail.