Overview
This Policy sets out milanj.money's Anti-Money Laundering ("AML") program and Know-Your-Customer ("KYC") and Know-Your-Business ("KYB") procedures. It is designed to prevent the use of the Platform for money laundering, terrorist financing and other financial crime, and to comply with:
The Prevention of Money Laundering Act 2002 ("PMLA") and the Prevention of Money-Laundering (Maintenance of Records) Rules 2005.
The RBI Master Direction on Know Your Customer, as amended from time to time.
The Digital Personal Data Protection Act 2023 ("DPDP Act") as it applies to the personal data we process for AML and KYC purposes.
Any other applicable Indian law or RBI guidance relating to financial crime prevention.
Milanj.money's AML and KYC program is overseen by the Designated Director and the Principal Officer appointed under the PMLA, supported by the Compliance function. All employees in scope undergo periodic AML training. This Policy is reviewed at least annually.
Milanj.money does not onboard anonymous or fictitious customers. We do not enter into a business relationship with persons or entities subject to applicable sanctions, included on terror-financing lists, or otherwise prohibited under applicable law.
KYC for individuals
Where individual customers use the Platform (for example, as the authorised signatory of a merchant entity, or as a direct individual user where the product supports it), we collect and verify identity and address documents recognised under the RBI Master Direction on KYC as Officially Valid Documents ("OVDs").
Identity OVDs. PAN card, Aadhaar card, passport, voter ID, driving licence, or NREGA job card.
Address OVDs. Any of the above where they carry an address, or utility bills, bank statements, or other documents acceptable under the RBI Master Direction.
Verification is carried out through electronic KYC (eKYC via Aadhaar), video KYC (V-CIP), or in-person KYC as permitted under the RBI Master Direction and applicable law.
Where eKYC or V-CIP is used, it is carried out in compliance with applicable UIDAI and RBI requirements.
KYB for businesses
All merchant and partner customers are business entities and are subject to Know-Your-Business ("KYB") verification before they are permitted to use the Platform for live transactions. KYB covers the entity, its beneficial owners and its authorised signatories.
The entity itself is verified against its registration documents and public records.
Beneficial owners holding 10% or more of the equity or voting rights (or such other threshold as applicable law requires) are identified and their identity is verified.
Authorised signatories are identified and their authority is confirmed through board resolutions, partnership deeds or equivalent authorisation documents.
Risk classification is assigned at onboarding: low, medium or high. The level of due diligence applied corresponds to the risk class.
Document requirements
The following documents are required at minimum for business customers. Additional documents may be requested depending on the risk profile and business type.
Certificate of incorporation or registration.
Permanent Account Number (PAN) of the entity.
Goods and Services Tax (GST) registration certificate, where applicable.
Memorandum and Articles of Association (or equivalent for LLPs, partnerships and trusts) and a list of directors, partners or trustees.
Beneficial owner declaration, with identity and address documents for each beneficial owner meeting the applicable threshold.
Authorised signatory identity, address and authorisation documents.
Bank account details, verified via penny-drop or equivalent mechanism.
Business model description, including the nature of payouts to be made, expected beneficiary types, transaction volumes and average transaction values.
Documents must be current, legible and in English or accompanied by a certified translation. milanj.money reserves the right to request certified copies, notarisations or additional corroborating documents where required by the risk assessment.
Customer due diligence
Milanj.money applies a risk-based approach to customer due diligence ("CDD"). The level of diligence is proportionate to the assessed risk of the customer and the nature of the Services they use.
Standard CDD is applied to all customers and covers the document collection and verification described above, plus sanctions and politically exposed persons ("PEP") screening at onboarding.
Enhanced Due Diligence ("EDD") is applied where the risk profile warrants it, including for:
Politically exposed persons and their close associates.
Customers from jurisdictions identified as higher risk by the Financial Action Task Force ("FATF") or by RBI guidance.
Customers in higher-risk business categories as defined in our internal risk policy.
Customers whose expected transaction profile materially exceeds standard thresholds.
Customers where the source of funds or the business model is not immediately clear from standard documentation.
EDD may include senior management approval before onboarding, additional documentation, source-of-funds enquiries, and an elevated monitoring frequency for the duration of the business relationship.
Transaction monitoring
All transactions processed through the Platform are subject to automated monitoring. Our monitoring system uses both rule-based controls and behavioural analytics to detect unusual or potentially suspicious activity.
Rules cover velocity (volume and frequency over defined periods), value thresholds, beneficiary concentration, round-tripping patterns, dormant account activity and mismatch against the declared transaction profile.
Behavioural analytics flag deviations from a customer's own historical pattern, including sudden changes in transaction type, volume or beneficiary geography.
Alerts generated by the monitoring system are reviewed by the Compliance function within defined timelines. All alerts are documented, together with the outcome of the review.
Customers with elevated risk indicators may be temporarily restricted pending compliance review, without prior notice where immediate restriction is necessary to protect the Platform or comply with applicable law.
Velocity and risk controls
In addition to transaction-level monitoring, milanj.money applies platform-wide velocity and risk controls designed to prevent misuse of the payout infrastructure.
Per-transaction and per-day payout limits apply by default, with higher limits available for customers with an established track record and an approved risk profile.
New merchants are subject to reduced limits during the initial period of their relationship with milanj.money, with limits reviewed after the first 30 days of live activity.
Sudden or unexplained increases in transaction volume or value may trigger a temporary hold pending compliance review, even where individual transactions are within normal parameters.
Beneficiary accounts that appear on internal watchlists or that are flagged by banking partner risk systems may be blocked from receiving payouts.
Sandbox and test environments are isolated from production and are not capable of initiating real money movements.
Suspicious activity reporting
Where the Compliance function, following review of a monitoring alert or other information, determines that a transaction or pattern of transactions is suspicious, the following process applies.
A Suspicious Transaction Report ("STR") is prepared and filed with the Financial Intelligence Unit India ("FIU-IND") within the timelines prescribed under PMLA 2002 and the rules thereunder.
Cash Transaction Reports ("CTR"), counterfeit currency reports and any other reports required under applicable law are prepared and filed within the prescribed timelines.
Tipping-off is prohibited. Where applicable law restricts disclosure, milanj.money will not inform the customer that a report has been or may be filed, or that their account is under review in connection with a suspected offence.
Milanj.money cooperates fully with regulatory and law-enforcement authorities, including providing records on lawful request, and will not obstruct any lawful investigation.
Record retention
Milanj.money maintains records of customer identification, transactions, STR and CTR filings and all other records required under the PMLA and the Prevention of Money-Laundering (Maintenance of Records) Rules 2005.
Records are retained for a minimum of five (5) years after the date of the transaction or the end of the business relationship, whichever is later, or for such longer period as applicable law requires.
Records are stored securely and access is controlled on a need-to-know basis. Audit logs are maintained for all access to AML and KYC records.
Records are available for production to regulatory or law-enforcement authorities on lawful demand within the timeframes they specify.
On expiry of the retention period, records are deleted or irreversibly anonymised in accordance with our data retention schedule.
PMLA 2002 alignment
Milanj.money's AML and KYC program is designed to be compliant with the Prevention of Money Laundering Act 2002 ("PMLA") and the rules, directions and guidelines issued thereunder, including:
Appointment of a Principal Officer and a Designated Director as required under the PMLA.
Maintenance of records of identity, transactions, STR and CTR filings for the prescribed period.
Filing of STRs, CTRs and other reports with FIU-IND within prescribed timelines.
Cooperation with the Enforcement Directorate, FIU-IND and other competent authorities.
Annual review of this Policy for alignment with the latest PMLA amendments, RBI Master Directions and FATF guidance.
Milanj.money does not facilitate, knowingly or recklessly, any transaction that constitutes money laundering or terrorist financing as defined under the PMLA or the Unlawful Activities (Prevention) Act 1967, and will take all steps required by applicable law where such activity is detected or suspected.
Questions about this Policy?
Email compliance@milanj.money. For grievances, see the Grievance Redressal page.
Email compliance →