Corporate governance policy
Effective: 01 January 2026 · Last reviewed: 01 January 2026
PaisaSure Technologies Pvt. Ltd. (Loan Service Provider (LSP)) operates under a governance framework that mirrors the standards expected of its lending partner, NorthStar Capital NBFC Pvt. Ltd. (RBI CoR #B-14.03491, a NBFC-ND (Non-deposit-taking)). This page summarises the key elements; the full policy is available on request to companysecretary@paisasure.money.
1. Board of directors
- The Board has independent and executive directors in a ratio compliant with the Companies Act, 2013 and the RBI Scale-Based Regulation (SBR) framework.
- The Board meets at least four times a year, with no gap of more than 120 days between meetings.
- At least one director has experience in financial services, one in technology, and one in audit / risk.
2. Committees of the Board
| Committee | Mandate |
|---|---|
| Audit Committee | Reviews quarterly financials, internal audit reports, related-party transactions. |
| Risk Management Committee | Owns credit, operational, cyber, market, and conduct risk frameworks; meets quarterly. |
| Nomination & Remuneration Committee | Director and senior-management appointments, fit-and-proper assessments, compensation policy. |
| IT Strategy Committee | Oversees IT investments, outsourcing, business continuity, and information security. |
| Customer Service Committee | Reviews grievance metrics, mystery-shopping reports, customer satisfaction surveys. |
3. Fit-and-proper criteria
Every director and key managerial person is screened annually for the fit-and-proper criteria laid down by the RBI — including no regulatory ban, no criminal conviction, no insolvency, and no ongoing disciplinary action by a professional body.
4. Risk and compliance
- A Chief Risk Officer (CRO) reports administratively to the CEO and functionally to the Risk Management Committee.
- A Chief Compliance Officer (CCO) reports to the Audit Committee and has unrestricted access to the Board.
- Internal audit is performed by an independent firm of chartered accountants; reports are placed before the Audit Committee every quarter.
- An information-security audit is conducted at least once every 18 months by a CERT-In empanelled auditor.
5. Outsourcing and third parties
Critical outsourcing arrangements — KYC providers, Account Aggregator TSPs, eSign providers, payout banks, SMS/WhatsApp gateways — are governed by written agreements with confidentiality, data-localisation, audit and exit clauses aligned to the RBI outsourcing guidelines for NBFCs.
6. Whistleblower policy
Employees, contractors and external stakeholders can report concerns about fraud, misconduct or policy violations confidentially to whistleblower@paisasure.money. The Audit Committee Chair reviews every report; the identity of the whistleblower is protected.
7. Code of conduct
Every employee certifies adherence to the company Code of Conduct annually. The Code covers conflicts of interest, gifts and hospitality, insider information, anti-bribery, and customer respect.
8. Disclosures
Annual financial statements, related-party transactions, key personnel remuneration and material penalties from any regulator are disclosed in the annual report, published by 30 September each year.