Risk Management Policy - Global Access

Effective date - April 02, 2026

Objective

This policy establishes a comprehensive framework for identifying, assessing, monitoring, and mitigating risks arising from INDmoney Global (IFSC) Private Limited (“INDmoney Global”) activities as a Global Access Provider (GAP) under the International Financial Services Centres Authority (IFSCA) framework. It ensures alignment with the requirements under Clauses 26, 30, and related provisions of the circular-Regulatory Framework for Global Access in the IFSC and the IFSCA (Capital Market Intermediaries) Regulations, 2025.

Scope

This policy applies to:

  1. All global access operations of INDmoney Global.
  2. All employees, systems, and third-party partners (including but not limited to foreign brokers, introducing brokers, custodians, and technology service providers).
  3. All products offered through global access, limited to permitted financial products under IFSCA and FEMA guidelines.

Governance Structure

RoleResponsibility
Board of DirectorsOverall oversight of risk framework and annual review of this policy.
Principal Officer (PO)Reporting to the Board of Directors, implementation of risk mitigation controls.
Compliance OfficerEnsures regulatory adherence, reporting to IFSCA, and coordination with internal/external auditors. Day-to-day risk monitoring.
Operations & Product HeadsEmbed risk controls in trading, client onboarding, settlement, and technology systems.

Core Risk Categories and Management measures

Company's risk management policy comprehensively addresses all material risks inherent to the business, which are categorized as follows:

  1. Credit Risk (Counterparty Risk): To mitigate counterparty risks, INDmoney Global shall only enter into agreements with foreign brokers that are regulated or registered as brokers in their respective Foreign Jurisdictions and provide access in compliance with applicable local regulatory requirements. The Company mandates that such agreements must explicitly empower INDmoney Global to obtain all necessary data and information relating to Global Access activities from the foreign broker. Furthermore, the Company shall maintain a vigilant monitoring protocol to immediately inform the Authority in the event any action is taken by a financial sector regulator against the partner foreign broker.
  2. Market Risk: This is the risk of losses in the firm's balance sheet (specifically proprietary trading accounts) and client accounts due to adverse changes in market factors, including stock prices, interest rates, or foreign exchange rates. The firm mitigates this risk by establishing Board-approved proprietary limits, setting mandatory stop-loss triggers, and employing quantitative methods like Value-at-Risk (VaR). Crucially, the company maintains continuous oversight to ensure compliance with the minimum Liquid Net Worth requirement mandated by the IFSCA Master Circulars for Broker Dealers, ensuring the firm's resilience against significant market shocks.
  3. Operational Risk: This category encompasses the risk of loss resulting from inadequate or failed internal processes, human error, system failures, or external events (including fraud and regulatory breaches). Mitigation relies on documented Standard Operating Procedures (SOPs) for all critical functions, strict segregation of duties to prevent collusion, and robust internal audit procedures. Furthermore, operational risk includes Compliance Risk, managed through the daily monitoring and reporting of regulatory adherence by the Compliance Officer, as per IFSCA directives.
  4. Product and Regulatory Compliance Framework: The Company shall implement stringent system controls to ensure that access is provided solely to financial products listed on stock exchanges in Foreign Jurisdictions that fall within the definition of "financial products" applicable in the IFSC. The Company strictly prohibits providing access to crypto-assets, instruments with underlying crypto assets, or any other instruments not recognized as financial products in the IFSC. Additionally, the system shall block access to Global Markets for dealing in index derivatives, single stock derivatives, bond derivatives, or USD-INR/INR-USD derivatives that are available on Recognised Stock Exchanges within the IFSC. For clients resident in India, the Company shall maintain adequate systems to restrict access to products that are permitted under the Foreign Exchange Management Act, 1999, specifically ensuring compliance with the Liberalised Remittance Scheme notified by the Reserve Bank of India.
  5. Settlement Risk and Fund Management: To address settlement risks, INDmoney Global mandates that all client funds participating in global access must be routed through a designated bank account within the IFSC. The Company maintains strict segregation of funds by operating separate bank accounts for its Global Access activities distinct from its other activities in the IFSC. Furthermore, a clear separation is maintained between client funds and proprietary trading funds, with client funds being pooled in a separate account maintained with an International Banking Unit in the IFSC. This segregation ensures that client assets are protected from the Company's proprietary risks.
  6. Surveillance and Monitoring Systems: In accordance with regulatory requirements, INDmoney Global ensures that adequate systems and procedures are in place to monitor trading activities effectively. These systems are designed to detect and prevent irregularities, ensuring that all trading activities remain within the bounds of this circular. The surveillance framework includes maintaining all user, transaction, and trade data physically or digitally within the IFSC to ensure data sovereignty. The Company ensures that such data shall be made readily available to the Authority upon request, thereby facilitating regulatory supervision and inspection.
  7. Technology, Cyber Security, and BCP Risk: Given the IFSC's reliance on digital trading infrastructure, technology and cyber security risk management is critical.
    • Cyber Security Framework: The Company shall adhere to the IFSCA Guidelines on Cyber Security and Cyber Resilience for CMIs. This includes implementing multi-factor authentication, strong encryption protocols, and intrusion detection systems.
    • Data Integrity and Confidentiality: Procedures must be in place to ensure the integrity, confidentiality, and availability of all client and proprietary data, with regular data backups and offsite storage.
    • System Audit: The Company shall mandate a comprehensive System Audit by an independent auditor at least annually. The findings and compliance status must be reported promptly to the Board and the IFSCA, as required by the Master Circular for Broker Dealers.
    • Business Continuity Plan (BCP): The Company shall establish and maintain a documented BCP/Disaster Recovery (DR) plan to ensure essential operations can be restored within a defined timeframe following a serious disruption (e.g., natural disaster, prolonged system failure). Mandatory BCP/DR drills must be conducted periodically (e.g., bi-annually) to test the resilience of systems and the preparedness of personnel.

Risk Identification and Assessment

The Company identifies risks under three broad categories.

Category I: Customer and onboarding risks, which include incorrect KYC, failure to detect red-flagged customers, customers funding wallets from unauthorized accounts, and fraudulent activities involving identity theft.

Category II: Transaction and operational risks, which include customer funds stuck in SWIFT settlement, erroneous transfers, incorrect beneficiary crediting, and issues arising from 180-day flush-out requirements and suspense accounts.

Category III: Technology, cybersecurity, and third-party risks, including cyberattacks, vulnerabilities in third-party providers, and geographic or operational dependencies.

A risk register is maintained to classify risks as high, medium, or low, based on likelihood and impact ratings.

Risk Mitigation Measures

Risk mitigation measures include strengthening customer onboarding with automated AML and CFT screening, penny-drop verification, CKYC integration, and geo-tagging controls. Transaction controls are ensured by requiring dual authorisation for outward payments, automated transaction monitoring with red flag alerts, and validation of purpose codes for wallet credits.

Customer funds are safeguarded through segregation of applicable funds in nodal accounts, daily reconciliation of wallet balances, and adherence to regulatory guidelines.

Operational risks are mitigated by maintaining a Business Continuity Plan (BCP) and Disaster Recovery (DR) framework and by conducting periodic stress tests on liquidity and net worth. Cybersecurity resilience is maintained in accordance with IFSCA standards, while FATCA and CRS compliance (if applicable) is ensured through collection of tax residency declarations and timely regulatory reporting.

Risk Management of Third-Party Service Relationships

The Company evaluates the criticality of third-party services based on financial, operational, and strategic importance, substitutability, and sensitivity of shared data. Due diligence is carried out on the financial soundness, cybersecurity capabilities, internal controls, conflicts of interest, and geographic dependencies of third-party providers.

Contractual arrangements are put in place with binding clauses on information sharing and regulatory access. Ongoing monitoring ensures that third parties perform in line with contractual obligations, while exit strategies are documented to manage provider failure, breaches, or extended service disruptions.

Monitoring and Review

Compliance Officer shall submit Annual risk management reports to the Board. The Company ensures timely submission of all required returns and submissions to regulators. This Framework shall be reviewed annually, or earlier if necessitated by regulatory changes or material risk events, to ensure its continued effectiveness and alignment with regulatory expectations.