Skip to main content

Merchant Onboarding Policy

A. INTRODUCTION

A.1 Les Amis Private Limited ("EximPe") is committed to combating money laundering, financial fraud, and other financial crimes (collectively "Money Laundering") and complying fully with all applicable laws and regulations relating to combating money laundering. EximPe is also committed to complying with economic and trade sanctions administered and enforced by the government and supranational bodies, including, among others, the sanctions programs and designated sanctions lists administered by our supervisory.

A.2 In accordance with the Reserve Bank of India's ("RBI") "Regulation of Payment Aggregator – Cross Border" issued vide CO.DPSS.POLC.No.S-786/02-14-008/2023-24 dated October 31, 2023 ("PA-CB Guidelines") read with the "Guidelines on Regulation of Payment Aggregators and Payment Gateways, 2020" issued vide DPSS.CO.PD.No.1810/02.14.008/2019-20, dated March 17, 2020, (the "PA Guidelines"), the Know Your Customer ("KYC")/Anti-Money Laundering ("AML")/ Combating Financing of Terrorism ("CFT") guidelines issued by the Department of Regulation, RBI, in the "Master Direction - Know Your Customer Directions, 2016" ("KYC Master Directions") is applicable to all cross border payment aggregators ("PA-CB"). Provisions of Prevention of Money Laundering Act, 2002 and Prevention of Money Laundering (Maintenance of Records) Rules, 2005 framed thereunder, as amended from time to time, are also applicable. PA-CBs are also required to have a board of directors ("Board") approved policy for Customer onboarding.

A.3 EximPe intends to apply strict guidelines for onboarding its Customers and in relation to undertaking business with its partners or merchants, in compliance with applicable regulations mentioned above.

A.4 In accordance with the PAPG Guidelines read with PA-CB Guidelines, every PA entity is mandated to implement and adhere to Merchant Onboarding Policy ("the Policy") duly approved by the Board of Directors ("the Board"). The Policy is appropriately designed to ensure compliance with the applicable provisions for on boarding of the merchant.

A.5 This Policy will be read closely with Eximpe's Board approved KYC/ Customer Onboarding/ AML Policy (hereinafter the "KYC and AML Policy").

A.6 This guide is designed to help -

  1. Understand our responsibility as an RBI regulated entity;
  2. Comply with the RBI's policies and applicable AML regulations;
  3. Identify suspicious activity and transactions; and
  4. Document protocols and principles for Customer acceptance, Customer identification, transaction monitoring, and risk management.

This policy must be read in line with the relevant guidelines issued by the RBI, as amended from time to time and in case of any conflicts/clarification, applicable RBI guidelines shall be referred and followed.

B. OBJECTIVE

B.1 The aim of this Merchant Onboarding Policy is:

  1. To comply with the PAPG Guidelines read with PA-CB Guidelines, amendments to the Guidelines and other applicable regulations;
  2. To implement a detailed, robust and secure process to collect documents, conduct thorough assessment and evaluation of the prospective merchant of the Company ("Merchant");
  3. To ensure that Merchants are aware of the document and process of onboarding on the platform;
  4. To onboard a merchant in a seamless manner.

B.2 The policy is applicable to all the branches, shareholders, board of directors, employees, Customers, business correspondents/agents/ sales executives of entities doing business with EximPe and any other person involved with any process envisaged under this KYC/AML Policy ("Obligated Persons").

B.3 In the event, an employee fails to comply with this Merchant Policy, such an employee will be subject to disciplinary proceedings which may lead to dismissal of such an employee. Any act of disobeying this policy will be reported to the relevant regulatory authorities (as applicable) who may also take criminal action against such an employee.

C. APPLICABLE REGULATIONS

C.1 EximPe has considered the following legislations, regulations, guidelines to prepare this policy:

  1. Payments & Settlement Systems Act, 2007;
  2. Prevention of Money Laundering Act, 2002 and Prevention of Money Laundering (Maintenance of Records), Rules, 2005;
  3. Aadhaar (Target Delivery of Financial and other Subsidies, Benefits and Services) Act, 2016 and related regulations;
  4. RBI Master Directions on Know Your Customer (KYC) Direction, 2016;
  5. RBI Guidelines on Regulation of Payment Aggregators and Payment Gateways, 2020 dated March 17, 2020 read with clarifications to these Guidelines dated March 31, 2021; and
  6. RBI Regulation of Payment Aggregator – Cross Border (PA - Cross Border) dated October 2023.

D. RELEVANT TEAMS INVOLVED AND ROLES

Respective business teams and the risk team of Eximpe are primarily responsible for ensuring adherence to the Policy & respective product procedures. The responsibilities under this Policy will not be outsourced, except as permitted under extant RBI guidelines.

The Merchant On-Boarding Process is a robust process to ensure thorough assessment and evaluation of prospective Merchants for availing our variant services. Business segments wise there are different teams that are involved to onboard the Merchants including:

  • KYC and Operations Team
  • Business Team
  • Risk and Compliance team

Each team works to assess and evaluate the data sets received from the Merchant. Each team will have Standard Operating Procedure (SOPs) drafted primarily on the guidelines and rules framed by the RBI and prevailing industry best practices, which will be followed diligently by each team.

After the individual assessments are complete, Merchant will be onboarded on the platform. The teams do not onboard any merchants in restricted lines of business, that are either carrying out business operations that do not comply with defined standards or carry a high degree of risk to the business or are otherwise fraudulent. These processes shall be updated from time to time as per the regulatory guidelines enforced and change in business practice.

The roles of the various teams include:

  • The Board of Directors will review and approve the Policy.
  • The Business team will source merchants and KYC and Operations team will carry out the onboarding in a manner ensuring implementation of the Policy on the ground. Collection and verification of merchant documents as per the KYC and AML Policy will be carried out by these teams.
  • The Risk and Compliance team along with the Designated Director and Principal Officer will carry out risk evaluation, risk categorisation, due diligence and diligent AML monitoring as defined under the KYC and AML Policy.
  • The Risk and Compliance team will assist with drafting and updating this Policy to ensure compliance with applicable guidelines and with formalising agreements with the Merchants.

E. MERCHANT ONBOARDING PROCESS

Eximpe will be sourcing and onboarding the Merchant on the platform in line with the PAPG Guidelines read with PA-CB Guidelines. The Policy and related SOPs create a comprehensive approach to help assess a prospective Merchant's activities, line of business, financial standing and soundness, to help determine if the Merchant meets Eximpe's criteria for onboarding. This includes defining Merchant types, obtaining relevant details about the Merchant and assessing these either through automated means or by scrutiny from designated teams, to ensure the desired objectives are met and guidelines are followed in letter and spirit.

E.1 Import Related Onboarding

For facilitating import transactions, Eximpe will:

  • Directly on-board merchants located abroad, or
  • Enter into agreement with e-commerce marketplaces, or
  • Enter into agreement with entities providing PA services abroad.

A standard process to collect and verify the officially valid documents ("OVDs") or constitutional documents of Indian Customers as per KYC checklist mentioned in Annexure 1 and Foreign Merchants as as per KYC checklist mentioned in Annexure 2 of the KYC and AML Policy.

While onboarding merchants, Eximpe will ensure that it does not facilitate payment transactions for import of any restricted / prohibited goods and services (not permissible under prevailing Foreign Trade Policy).

E.1.1 Buyer Due Diligence

In case per unit goods / services imported is more than ₹2,50,000, then Eximpe will undertake due diligence of buyer also. The due diligence will be conducted as per defined process outlined in the Annexure 1a of the KYC and AML Policy.

E.2 Export Related Onboarding

For export transactions, in arrangements where Eximpe facilitates transactions between merchants / e-commerce marketplaces in India and customers / e-commerce marketplaces abroad, Eximpe will ensure that the transactions for export of any restricted / prohibited goods and services (not permissible under prevailing Foreign Trade Policy) will not be facilitated.

For all such arrangements, Eximpe will

  • Directly on-board Indian merchants or
  • Enter into agreement with e-commerce marketplaces, or
  • Enter into agreement with entities providing PA services.

A standard process to collect and verify the officially valid documents ("OVDs") or constitutional documents of Indian Customers as per KYC checklist mentioned in Annexure 1 and Foreign Merchants as as per KYC checklist mentioned in Annexure 2 of the KYC and AML Policy.

E.3 Jurisdictions from which Merchants may be Onboarded

Eximpe will serve jurisdictions identified taking into account the current Foreign Trade Policy, FATF Recommendations, and any other guidance received from the FIU and/ or the RBI. Foreign merchants will only be onboarded from identified jurisdictions.

E.4 Merchant Onboarding Process

Merchant will only be accepted if:

  • Merchant is selling goods and services on the platform
  • Merchant's entity name is clearly visible on the website/ application etc. so that the end customer can verify the merchant details at the time of purchase.
  • Merchant meets mandatory requirements as prescribed by banking partners and/or by card networks.

The process of onboarding a Merchant on the platform will include the following steps:

Merchant Onboarding Form Collection:

  1. The Merchant approaches Eximpe via various channels such as the website or via the Business team.
  2. Domestic and foreign Merchants will sign up on EximPe platform and complete the Account Opening Form which will include information on:
    • Company Details - Details of incorporation, Tax Identification, incorporation and other company incorporation and constitution related details
    • Business Details - Details pertaining to the product/service of the company
    • Bank Account Details
    • Authorised User Details
    • Proprietor Details
    • Beneficial Ownership Details
    • Details required for Video KYC
    • Declaration by Authorised Signatory
  3. Merchant fills this form and submits it and the onboarding applications would be accessible to the KYC and Operations team via EximPe Operations Dashboard

KYC Collection:

  1. A standard process to verify the officially valid documents ("OVDs") or constitutional documents of Indian Customers as per KYC checklist mentioned in Annexure 1 KYC AML Policy is done by EximPe. Eximpe's KYC Operations team will ensure that the Merchant must successfully meet the Customer Acceptance Policy and complete the Customer Identification Procedure defined therein.
  2. Video KYC will be done as per the RBI's KYC Master Direction for an individual/ sole proprietor/ authorised signatory/ beneficial owner.

Background Checks:

  1. Eximpe's KYC and Operations team will undertake background and antecedent check of the merchants, to ensure that such merchants do not have any malafide intention of duping customers, do not sell fake / counterfeit/ prohibited products, etc.
  2. Eximpe shall check that the merchant's website shall clearly indicate the terms and conditions of the service and timeline for processing returns and refunds.
  3. Eximpe's KYC Operations team will carry out multiple system-level checks which includes:
    • Verification of documents through government sources like, PAN from NSDL, Documents/Information for Corporates from MCA website, documents/information from regulatory or government website/database like GST, etc
    • Various checks on the directors, litigation history to see if there are legal cases against the corporate/beneficial owners.
    • The OVD's provided by beneficial owners and authorized users are checked using API's from independent providers to verify the authenticity of the OVD.
    • Politically Exposed Persons ("PEP") check, Adverse Media and AML Screening is done on the entity and the beneficial owners of the company.
    • Daily name screening checks are done against all watch lists.

Bank Account Verification

  1. Eximpe will also perform a penny drop test to verify the bank account details to which the proceeds of sales will be settled. Details of the verification is mentioned in Annexure 4 of the KYC AML policy

Security Checks

  1. Eximpe will be responsible to check Payment Card Industry-Data Security Standard (PCI-DSS) and Payment Application-Data Security Standard (PA-DSS) compliance, as applicable, of the infrastructure of the merchants on-boarded.
  2. Eximpe will ensure that the merchant site will not save customer card and such related data. A security audit of the merchant may be carried out to check compliance, as and when required.
  3. Merchant is required to sign an agreement with Eximpe and hence would be considered as a Merchant on record for Eximpe. The Agreement with the Merchant will have provision for:
    • Security / privacy of customer data,
    • Compliance to PCI-DSS/ PA-DSS (as applicable) and incident reporting obligations, and
    • Clear delineation of the roles and responsibilities of the involved parties in sorting / handling complaints, refund / failed transactions, return policy, customer grievance redressal (including turnaround time for resolving queries), dispute resolution mechanism, reconciliation, etc.
  4. Eximpe will obtain periodic security assessment reports either based on the risk assessment (large or small merchants) and / or at the time of renewal of contracts.

Line of Business related checks

  1. There are certain categories where no banking facility should be ideally leveraged and as part of the financial industry, the Company will also comply with the Policy and procedures laid down as per Industry standards. Hence, all the Merchants to be onboarded shall be filtered with the restricted list of merchants as added to the KYC and AML Policy, and any such Merchants will not be provided with any services from Eximpe. This list will be updated from time to time and used for screening.
  2. Details on the nature of business of the Merchant will be collected at the time of onboarding. Line of Business verifications will be conducted for the Merchants as per the KYC and AML Policy and related SOPs.

E.5 Accounts Opened Of Merchants In Partnership With Marketplaces/ Payment Aggregators

EximPe may onboard merchants via foreign or domestic marketplaces, subject to the following terms and conditions:

  1. Customer Acceptance, Identification, and Due Diligence: EximPe shall conduct Customer Acceptance, Customer Identification Procedures ("CIP"), and Customer Due Diligence ("CDD") of the marketplace prior to onboarding any merchant as part of a partnership with the marketplace.
  2. Partnership Agreement: A valid partnership agreement must be duly executed between EximPe and the partner marketplace, outlining the terms and conditions of the partnership.
  3. Master Service Agreement: Each merchant onboarded through the marketplace shall execute a Master Service Agreement with EximPe, governing the merchant's relationship with EximPe.
  4. Merchant Onboarding Process: Each merchant account referred by the marketplace shall undergo EximPe's onboarding process, which includes Customer Acceptance, Customer Identification Procedures ("CIP"), Customer Due Diligence, risk management, and transaction monitoring at the merchant level.
    • Marketplace Documentation: The marketplace may furnish required documentation on behalf of the merchant, including the documents listed in Annexure 1 for Indian merchants and Annexure 2 for foreign merchants. All such documents must be duly attested by the marketplace.
    • Account Operation: Merchants referred by the marketplace may either be directly onboarded onto EximPe's platform or may operate their account through the marketplace via API integration, as agreed by both parties and as permitted under applicable guidelines.

F. ADHERENCE TO FOREIGN TRADE POLICY

While onboarding merchants, Eximpe will ensure that it does not facilitate payment transactions for export or import of any restricted / prohibited goods and services (not permissible under prevailing Foreign Trade Policy).

For this, the Foreign Trade Policy defined by the Directorate General of Foreign Trade, as updated from time to time, will be referred to.

The list of Unqualified/ Unacceptable Businesses listed under Annexure 3 of the KYC and AML Policy will also be updated from time to time as per the requirements of partner banks and networks.

G. WIRE TRANSFER OBLIGATIONS

For cross-border wire transfers, Eximpe will comply with the prescribed requirements for cross- border wire transfers as applicable as per the RBI KYC Master Direction. This will include the following requirements:

  1. P2M transactions for credit card, debit card and PPI are exempted from these requirements. These will be complied with in relation to P2M UPI and net banking transactions and P2P card and PPI transactions.
  2. All cross-border wire transfers listed above will have the following accurate and complete information:
    • Name of the originator;
    • The originator account number where such an account is used to process the transaction;
    • The originator's address, or national identity number, or customer identification number, or date and place of birth;
    • Name of the beneficiary; and
    • The beneficiary account number where such an account is used to process the transaction (In the absence of an account, a unique transaction reference number will be included.)
  3. For PA-CB import, PA-CBs will comply with following requirements for an originator RE, which include:
    • Ensure originator and beneficiary information listed above is captured.
    • Make customer identification if he is intentionally structuring transaction below Rs.50,000/- to avoid monitoring, and file STR if found to be suspicious.
    • Not execute any transaction that does not comply with the above.
  4. For PA-CB export, PA-CB will comply with following requirements for an intermediary RE, which include:
    • Ensure originator and beneficiary information listed above is retained.
    • Keep a record, for at least 7 years of all information received from the originator.
    • Take reasonable measures consistent with straight through processing identify wire transfers without the required information.
    • Have risk based policies to determine (i) when to execute, reject or suspend a wire transfer lacking required information, and (ii) appropriate follow-up action to seek further information on a suspicious transaction, report to FIU, etc.
  5. All information on the wire transfer will promptly be made available to appropriate law enforcement authorities including FIU. Information will be made available within 3 working days on receiving request from another originator or intermediary RE.
  6. If any unregulated entities are involved in the wire transfer process, Eximpe will be fully responsible for information, reporting and other requirements. Eximpe will ensure:
    • Unhindered flow of required information
    • Agreement with unregulated entities clearly stipulates obligations under wire transfer instructions
    • Termination clause is included in agreement in case the unregulated entity is unable to support with these requirements.
  7. Eximpe will conduct name screening to ensure they do not conduct transactions with designated persons and entities.
  8. Eximpe will ensure that complete beneficiary and originator information will be retained as per the record keeping requirements outlined in this policy.

H. MERCHANT RISK CATEGORISATION

Merchants will be categorised as low, medium and high-risk category, based on the assessment and risk perception of the Eximpe. It will be based on the merchant category, declared turnover, location, transactions limit and other parameters as outlined in related SOPs. As per KYC and AML Policy prohibited Merchant categories are restricted for onboarding as a Merchant with Eximpe. This list will be updated from time to time and will be shared with the onboarding team / Sales leaders.

Based on risk categorisation of the Merchant, their on-going KYC will be performed by Eximpe. The re-KYC will be conducted of the already onboarded Merchants – for high-risk Merchants every two years, for medium risk Merchants every eight years and for low risk Merchants every ten years. Eximpe ensures to keep the information or data collected up-to-date and relevant, particularly in case of high risk merchants.

I. SUBMISSION OF MERCHANT LIST TO ESCROW BANK

Eximpe will submit the list of Merchants acquired by them to the bank where they are maintaining the escrow account and update the same from time to time. The bank will ensure that payments are made only to eligible merchants / purposes. There will be an exclusive clause in the agreement signed between the Eximpe and the bank maintaining escrow account towards usage of balance in escrow account only for the purposes as permitted under the PA Guidelines. For undertaking reconciliation/settlement of funds, Eximpe follows, on a case to case basis, agreements/arrangements exists with Merchant establishments.

J. TERMINATION OF A MERCHANT ACCOUNT

There are two possible scenarios when a Merchant account is required to be terminated:

  • Merchant will decide to terminate the account
  • The Company decides to terminate the account on grounds of fraud related issues/ commercial/ business related issues, etc.

This is detailed in the section F.7 of the KYC AML policy

K. SHARING OF INFORMATION WITH THIRD PARTIES

EximPe ensures that sharing information with third parties, if any, are in accordance with the privacy policies of EximPe & Applicable Laws. EximPe ensures that disclosures of KYC records are only to the extent required and permitted under Applicable Laws.

L. OTHER OBLIGATIONS

EximPe only collects, processes, stores or discloses such personally identifiable information of a Customer to the extent required by EximPe & under Applicable Laws and as laid out in EximPe's Privacy Policy.

M. POLICY REVIEW AND APPROVAL

(a) This Policy shall be reviewed at least annually and duly approved by the Board, to effect any changes in Applicable Laws and need for revision in internal processes.

(b) Till such review of this Policy, the contents of this Policy shall always be read in tandem with modifications which may be advised by the RBI or by any regulators as applicable and / or by EximPe from time to time.