Fair Securities Pvt Ltd
Banner background1

Outsourcing Policy

Home|Outsourcing Policy

1. Introduction

Fair Securities Private Limited (“the Company”) is a Non-Banking Financial Company (“NBFC”) registered with the Reserve Bank of India (“RBI”) and categorized as a Base Layer NBFC.

This Outsourcing Policy (“Policy”) is framed in accordance with applicable provisions of the Reserve Bank of India Act, 1934, RBI Master Directions applicable to NBFCs, Digital Lending guidelines (wherever applicable), Information Technology Governance requirements, and other regulatory instructions issued by RBI from time to time.

The purpose of this Policy is to establish a comprehensive framework governing outsourcing arrangements undertaken by the Company while ensuring protection of customer interests, confidentiality of data, operational resilience, and regulatory compliance.

2. OBJECTIVES

The objectives of this Policy are to:

  • a. Establish governance standards for outsourcing activities undertaken by the Company.
  • b. Ensure that outsourcing arrangements do not diminish the Company’s ability to fulfill its obligations to customers and regulators.
  • c. Ensure effective risk management and oversight over outsourced activities.
  • d. Protect customer information and confidential data.
  • e. Define roles and responsibilities relating to outsourced functions.
  • f. Ensure continuity of business operations and compliance with applicable laws and regulations.

3. SCOPE OF POLICY

This Policy applies to all outsourcing arrangements entered into by the Company with third parties including but not limited to:

  • • Service providers
  • • Vendors
  • • Agents
  • • Consultants
  • • Marketing agencies
  • • Lead generation agencies
  • • Backend support providers
  • • Document verification agencies
  • • Field investigation agencies
  • • Collection support agencies
  • • Data analytics providers
  • • Technology support providers
  • • Cloud service providers

This Policy shall apply to both material and non-material outsourcing arrangements.

4. DEFINITION OF OUTSOURCING

“Outsourcing” means an arrangement between the Company and a third party whereby the third party performs an activity, process, service, or function that is ordinarily undertaken by the Company itself.

Outsourcing may include activities related to customer acquisition, operational support, technology support, verification services, marketing support, collections assistance, analytics, customer servicing, or any other business support services.

5. ACTIVITIES THAT SHALL NOT BE OUTSOURCED

The Company shall not outsource core management functions including:

  • • Strategic decision making
  • • Board and senior management responsibilities
  • • Internal audit decision-making functions
  • • Compliance oversight functions
  • • Risk management ownership
  • • Approval of loans and credit policies unless specifically permitted under applicable law

The ultimate responsibility for outsourced activities shall always remain with the Company.

6. GOVERNING PRINCIPLES

The Company shall ensure that:

  • a. Outsourcing arrangements do not reduce the Company’s accountability to customers or regulators.
  • b. The Company maintains effective oversight and control over outsourced activities.
  • c. Customer interests are protected at all times.
  • d. Customer information and data confidentiality are preserved.
  • e. Service providers comply with applicable laws, RBI guidelines, data protection standards, and security requirements.
  • f. Outsourcing arrangements do not impede RBI’s supervisory functions.
  • g. The Company retains the ability to access records, documents, and data relating to outsourced activities.

7. BOARD AND MANAGEMENT RESPONSIBILITY

  • 7.1 Board Responsibility
  • The Board of Directors shall:
    • • Approve the Outsourcing Policy.
    • • Review outsourcing risks periodically.
    • • Ensure adequate governance mechanisms are established.
    • • Monitor material outsourcing arrangements.
  • 7.2 Senior Management Responsibility
  • Senior management shall:
    • Implement the Policy.
    • • Monitor outsourced activities.
    • • Conduct risk assessments.
    • • Ensure compliance with service agreements.
    • • Maintain records of outsourcing arrangements.

8. DUE DILIGENCE OF SERVICE PROVIDERS

Before entering into any outsourcing arrangement, the Company shall conduct appropriate due diligence on the proposed service provider, including assessment of:

  • a. Financial soundness and stability.
  • b. Reputation and market standing.
  • c. Experience and operational capability.
  • d. Regulatory track record and legal compliance.
  • e. Infrastructure and manpower capability.
  • f. Information security framework.
  • g. Data privacy and confidentiality controls.
  • h. Business continuity and disaster recovery preparedness.
  • i. Ability to comply with RBI requirements.

The due diligence findings shall be documented and retained.

9. OUTSOURCING REGISTER

The Company shall maintain an Outsourcing Register containing details of all outsourcing arrangements.

The register shall include:

  • • Name of Service Provider
  • • Nature of Outsourced Activity
  • • Date of Appointment
  • • Contract Validity Period
  • • Risk Classification
  • • Due Diligence Date
  • • Review Date
  • • Performance Rating
  • • Audit Status
  • • Renewal Date

The Outsourcing Register shall be periodically reviewed by Management.

10. RISK ASSESSMENT

Prior to outsourcing any activity, the Company shall conduct a risk assessment considering:

  • • Materiality of the activity
  • • Operational impact
  • • Customer impact
  • • Data sensitivity
  • • Reputational risks
  • • Compliance risks
  • • Cybersecurity risks
  • • Business continuity implications
  • • Concentration risks

Enhanced monitoring shall be undertaken for material outsourcing arrangements.

11. CLASSIFICATION OF OUTSOURCING ARRANGEMENTS

The Company shall classify outsourcing arrangements based on the nature, materiality and risk associated with the outsourced activity.

Critical / Material Outsourcing

Outsourcing arrangements shall be considered material where disruption may:

  • • Adversely affect customers;
  • • Impact regulatory compliance;
  • • Cause significant operational disruption;
  • • Result in financial loss;
  • • Cause reputational damage.

Examples include:

  • • Technology Support Services
  • • Customer Servicing Operations
  • • Collection Support Activities
  • • Document Verification Services
  • • Backend Processing Activities
  • • Cloud Service Providers

Non-Material Outsourcing

Outsourcing arrangements with limited operational or regulatory impact shall be classified as non-material.

Examples include:

  • • Housekeeping Services
  • • Administrative Support
  • • Office Maintenance Services

Material outsourcing arrangements shall be subject to enhanced monitoring and oversight.

12. OUTSOURCING AGREEMENT

All outsourcing arrangements shall be governed by written agreements duly executed between the Company and the service provider.

  • The agreement shall, at a minimum, contain:
  • a. Scope and nature of services.
  • b. Roles and responsibilities of parties.
  • c. Service levels and performance standards.
  • d. Confidentiality obligations.
  • e. Data privacy and protection provisions.
  • f. Information security obligations.
  • g. Audit and inspection rights of the Company.
  • h. RBI’s right to inspect records, systems, and documents.
  • i. Compliance with applicable laws and RBI guidelines.
  • j. Business continuity and disaster recovery obligations.
  • k. Incident reporting obligations.
  • l. Restrictions on sub-contracting.
  • m. Termination rights.
  • n. Exit management and transition obligations.
  • o. Indemnity and liability provisions.

13. CONFIDENTIALITY AND DATA PRIVACY

Service providers shall maintain strict confidentiality of customer information and Company data.

The service provider shall:

  • a. Use customer information only for authorized purposes.
  • b. Prevent unauthorized disclosure, sharing, or misuse of data.
  • c. Implement adequate technical and organizational security measures.
  • d. Restrict access to authorized personnel only.
  • e. Comply with applicable data protection and privacy laws.
  • f. Promptly notify the Company regarding any data breach or security incident.

The Company shall ensure that customer information is not disclosed to unauthorized persons except as permitted under law or with customer consent.

14. INFORMATION SECURITY REQUIREMENTS

Service providers handling customer or Company data shall maintain adequate information security controls including:

  • • Access controls
  • • Password management
  • • Data encryption
  • • Network security
  • • System monitoring
  • • Log management
  • • Secure storage mechanisms
  • • Incident response procedures

The Company may require periodic security certifications, audits, or compliance confirmations from service providers.

15. BUSINESS CONTINUITY MANAGEMENT

Critical service providers shall maintain adequate:

  • • Business Continuity Plans (“BCP”)
  • • Disaster Recovery (“DR”) arrangements
  • • Data backup procedures
  • • System recovery mechanisms
  • • Emergency response procedures

The Company may periodically review or test such arrangements where necessary.

16. MONITORING AND OVERSIGHT

The Company shall continuously monitor outsourced activities to ensure compliance with contractual and regulatory requirements.

Monitoring activities may include:

  • • Periodic performance reviews
  • • Service level monitoring
  • • Audit reviews
  • • Compliance checks
  • • Security assessments
  • • Incident reviews
  • • Customer complaint monitoring

Deficiencies identified during monitoring shall be addressed promptly.

17. AUDIT RIGHTS

The Company shall have the right to conduct audits, inspections, and reviews of the service provider relating to outsourced activities.

The service provider shall provide access to:

  • • Records
  • • Documents
  • • Systems
  • • Processes
  • • Relevant personnel

The Company may appoint internal or external auditors for such reviews.

18. RBI ACCESS AND REGULATORY COMPLIANCE

The Company shall ensure that RBI or any regulatory authority authorized by RBI has unrestricted access to records, documents, data, systems, and information relating to outsourced activities.

The outsourcing arrangement shall not obstruct or interfere with RBI’s supervisory powers.

19. CUSTOMER GRIEVANCE REDRESSAL

The Company shall remain responsible for customer grievance handling in respect of outsourced activities.

Customers shall continue to have access to the Company’s grievance redressal mechanism irrespective of outsourcing arrangements.

20. CONFLICT OF INTEREST

The Company shall ensure that outsourcing arrangements do not create conflicts of interest detrimental to customer interests or regulatory compliance.

Appropriate controls shall be implemented wherever potential conflicts are identified.

21. SUB-OUTSOURCING

Service providers shall not further subcontract outsourced activities without prior written approval of the Company.

Where subcontracting is permitted, the primary service provider shall remain fully responsible for compliance with contractual and regulatory obligations.

22. RECORD RETENTION

The Company shall maintain appropriate records relating to outsourcing arrangements including:

  • • Service agreements
  • • Due diligence reports
  • • Risk assessments
  • • Performance reviews
  • • Audit reports
  • • Incident reports
  • • Termination records

Such records shall be maintained in accordance with applicable legal and regulatory requirements.

Where subcontracting is permitted, the primary service provider shall remain fully responsible for compliance with contractual and regulatory obligations.

23. EXIT MANAGEMENT

The Company shall maintain documented exit strategies for outsourced activities to ensure continuity of operations.

Exit management procedures shall include:

  • • Orderly transfer of activities
  • • Return or destruction of Company/customer data
  • • Transition support obligations
  • • Continuity of critical services
  • • Protection of customer interests

24. POLICY REVIEW

This Policy shall be reviewed annually or earlier if required due to:

  • • Regulatory changes
  • • Business requirements
  • • Operational developments
  • • Risk considerations

Any material amendments shall be placed before the Board for approval.

25. EFFECTIVE DATE

This Policy shall come into effect from the date of approval by the Board of Directors of the Company.

26. APPROVAL

This Outsourcing Policy is approved by the Board of Directors of Fair Securities Private Limited on 01.04.2026.

For and on behalf of

Fair Securities Private Limited