DIGITAL FINANCE PLATFORM
आरबीआई कहती है जानकर बनिए सतर्क रहिए•आरबीआई कहती है जानकर बनिए सतर्क रहिए
•SECURE CUSTOMER JOURNEY
LinkedIn WhatsApp Facebook Instagram YouTube X

POLICY / GOVERNANCE

POLICIES › RISK / FRAUD

Policy on Fraud Risk Management & Prevention

Read the approved policy online in a clear, searchable text format.

APPROVED POLICY

Policy on Fraud Risk Management & Prevention

Text-format policy • Read online

POLICY ON FRAUD RISK MANAGEMENT & PREVENTION For NBFC / Banking Institution Version 1.0 | Industry Ready Template

1. Purpose This policy establishes the framework for identifying, preventing, detecting, investigating and reporting fraud across all business operations, digital channels, Loan Origination System (LOS), Loan Management System (LMS), treasury, collections and support functions.

2. Scope Applicable to all employees, directors, agents, vendors, BCs, DSAs, fintech partners and outsourced service providers handling customer data, lending or payment processes.

3. Objectives Protect customer assets and institutional reputation.

Prevent financial losses arising from fraud.

Ensure compliance with RBI and applicable regulations.

Establish accountability and escalation procedures.

Strengthen digital fraud monitoring using technology.

4. Fraud Governance

5. Fraud Risk Categories Identity & KYC Fraud

Application Fraud

Document Forgery

Employee/Internal Fraud

Digital & Cyber Fraud

Collection Fraud

Vendor & Procurement Fraud

Account Takeover / Payment Fraud

6. Preventive Controls

Customer Onboarding CKYC/Aadhaar/PAN verification

Liveness & face match

Duplicate customer detection

Device fingerprinting

Credit Underwriting BRE validation

Income & bureau verification

Geo-tagging

Fraud score integration

Disbursement

Maker-checker approval

Bank account validation

Name match

Cooling period for changes

Collections Receipt controls

Cashless collection preferred

GPS tagged visits

Receipt reconciliation

Information Security MFA

Role-based access

Encryption

Audit trails

7. Fraud Detection Framework Real-time monitoring shall generate alerts using predefined scenarios and AI/ML models where applicable.

Multiple applications from same device

High-risk PIN code & velocity checks

PAN/mobile duplication

Frequent bank account changes

Unusual repayment behaviour

Employee override monitoring

8. Investigation & Escalation

1. Alert generated

2. Preliminary assessment within 24 hours

3. Case registration

4. Evidence preservation

5. Customer/vendor interview

6. Root cause analysis

7. Closure with corrective actions

9. Fraud Classification

10. Reporting & Regulatory Compliance Immediate reporting of suspected fraud.

Regulatory reporting as per RBI guidelines.

Quarterly MIS to Board.

Maintain investigation records for minimum 8 years.

11. Key Risk Indicators (KRIs)

12. Whistleblower Mechanism Employees and stakeholders may confidentially report suspected fraud without retaliation. Reports shall be investigated independently.

13. Training & Awareness Mandatory annual fraud training

Quarterly phishing simulations

Vendor compliance declarations

New joiner fraud awareness program

14. Policy Review This policy shall be reviewed annually or earlier upon regulatory or business changes.

Appendix A – Fraud Incident Report Template • Incident ID: ______________________________

Role Responsibility

Board of Directors Approve policy and review fraud reports.

Risk Management Committee Monitor fraud risk and KRIs.

Chief Risk Officer Own enterprise fraud framework.

Fraud Risk Unit Detection, investigation and reporting.

Internal Audit Independent testing of controls.

Business Heads First line ownership of fraud controls.

Level Indicative Loss Escalation

Minor Up to ₹50,000 Business Head

Moderate ₹50,001–₹5 Lakh CRO & Audit

Major Above ₹5 Lakh Board & RBI as applicable

KRI Threshold Frequency

Duplicate PAN Rate >1% Daily

Application Fraud Rate >0.5% Daily

Employee Overrides >25/month Monthly

Chargeback/Failed Disbursement Defined by Risk Weekly

Transparency notice: This web page presents the policy in text format for convenient online reading and reference.