Virtual Digital Asset Service Provider (VDASP)

KYC, AML/CFT & CPF Policy

Version 1.0•Effective: 26/05/2026•Last Updated: 26/05/2026•CIN: U58200MH2024PTC429181

1. Customer Acceptance

  • We do not open accounts for, or transact with, anonymous or fictitious persons or entities.
  • We do not onboard persons or entities on applicable sanctions or watchlists, or from jurisdictions on the FATF blacklist/grey list where adequate due diligence cannot be performed.
  • We do not accept shell entities or opaque ownership structures, and every customer may hold only one account.
  • Accounts are only opened for individuals aged 18 or above, in their personal capacity.

2. Know Your Customer (KYC)

What we collect

At onboarding, we verify a customer’s full legal name, date of birth, PAN (checked against income-tax records), one Officially Valid Document, current address, mobile and email (each OTP-verified), source of income, and bank account ownership via a penny-drop check. We also require a live selfie with liveness detection to confirm physical presence.

Ongoing refresh

KYC is refreshed periodically based on risk category: every 12 months for standard customers, every 6 months for medium risk, and every 3 months for high-risk customers (including politically exposed persons). Any material change to a customer’s profile triggers a fresh review, and expired identity documents must be replaced before continued access.

3. Risk-Based Approach

Risk classification

Every customer is assigned a risk category (low, medium, or high) based on factors including transaction volume and pattern, source of funds, geographic exposure, PEP status, and adverse media findings. Risk classifications are reviewed at least every six months.

Enhanced due diligence

Enhanced due diligence applies to high-risk customers, politically exposed persons, non-profit organisations, and transactions connected to restricted jurisdictions. This includes verified source-of-funds documentation, independent verification, and senior-management approval before the relationship is established.

4. Sanctions & Watchlist Screening

  • Every customer is screened against the UN Security Council Consolidated Sanctions List, Government of India lists notified under UAPA, and other applicable regulatory watchlists.
  • Screening happens at onboarding, on every KYC refresh, whenever a sanctions list is updated, and before executing any transaction.
  • A confirmed match results in the account being frozen pending review and escalation to our Principal Officer, and, where warranted, account closure and a report to the appropriate authority.

5. Transaction Monitoring & Reporting

Continuous monitoring

Our transaction monitoring programme profiles customer behaviour against declared transaction patterns and generates alerts on unusual or suspicious activity, including rapid fund movement, structuring, transactions connected to mixers/tumblers or anonymity-enhancing crypto assets, and activity inconsistent with a customer’s stated profile.

Suspicious Transaction Reports (STRs)

Where a transaction is suspected of involving money laundering, terrorist financing, or proceeds of crime, we file a Suspicious Transaction Report with FIU-IND without undue delay, irrespective of transaction value, and even where the transaction was only attempted, not completed.

No tipping-off

Disclosing to any customer or third party that an STR has been, or may be, filed is strictly prohibited under Section 8 of the PMLA and constitutes a criminal offence. We do not disclose STR filings or related investigations to the subject of the report.

6. Prohibited Activities

  • Anonymous or fictitious accounts.
  • Transactions on behalf of, or benefiting, sanctioned or watchlisted persons or entities.
  • Use of anonymity-enhancing crypto assets (AECs) and privacy coins.
  • Use of mixers, tumblers, or other transaction-obfuscation tools.
  • Structuring transactions to circumvent reporting thresholds.
  • Providing false or misleading information during KYC or account maintenance.

7. Record Retention

  • Customer KYC and identity records: retained for 5 years from account closure.
  • Transaction records: retained for 5 years from the date of the transaction.
  • STR filings and investigation records: retained for 5 years from filing.
  • Records are held in tamper-evident storage with role-based access control and encryption for sensitive personal data.

8. Governance & Contact

Oversight

This Policy is approved and overseen by our Designated Director, and administered day-to-day by our Principal Officer, who is responsible for transaction monitoring decisions, STR filings, and liaison with FIU-IND and law enforcement. An independent audit of our AML/CFT/CPF programme is conducted at least annually, with findings presented to the Board.

Policy review

This Policy is reviewed at least annually, or sooner in response to regulatory change, new products, or material audit findings. Amendments take effect on Board approval, and this public summary is updated accordingly. Questions regarding this Policy may be directed to our Principal Officer at [email protected].

Registered Office: 1st Floor, M Dange Caterers, In front of Neelam Mess, LIT Road, Ram Nagar, Nagpur, Maharashtra – 440010, India

© 2026 KRYPSM Private Limited. All rights reserved.

PMLA Compliant