
Fair Securities Private Limited (“the Company”) is a Non-Banking Financial Company (“NBFC”) registered with the Reserve Bank of India (“RBI”) and categorized as a Base Layer NBFC.
This Outsourcing Policy (“Policy”) is framed in accordance with applicable provisions of the Reserve Bank of India Act, 1934, RBI Master Directions applicable to NBFCs, Digital Lending guidelines (wherever applicable), Information Technology Governance requirements, and other regulatory instructions issued by RBI from time to time.
The purpose of this Policy is to establish a comprehensive framework governing outsourcing arrangements undertaken by the Company while ensuring protection of customer interests, confidentiality of data, operational resilience, and regulatory compliance.
The objectives of this Policy are to:
This Policy applies to all outsourcing arrangements entered into by the Company with third parties including but not limited to:
This Policy shall apply to both material and non-material outsourcing arrangements.
“Outsourcing” means an arrangement between the Company and a third party whereby the third party performs an activity, process, service, or function that is ordinarily undertaken by the Company itself.
Outsourcing may include activities related to customer acquisition, operational support, technology support, verification services, marketing support, collections assistance, analytics, customer servicing, or any other business support services.
The Company shall not outsource core management functions including:
The ultimate responsibility for outsourced activities shall always remain with the Company.
The Company shall ensure that:
Before entering into any outsourcing arrangement, the Company shall conduct appropriate due diligence on the proposed service provider, including assessment of:
The due diligence findings shall be documented and retained.
The Company shall maintain an Outsourcing Register containing details of all outsourcing arrangements.
The register shall include:
The Outsourcing Register shall be periodically reviewed by Management.
Prior to outsourcing any activity, the Company shall conduct a risk assessment considering:
Enhanced monitoring shall be undertaken for material outsourcing arrangements.
The Company shall classify outsourcing arrangements based on the nature, materiality and risk associated with the outsourced activity.
Critical / Material Outsourcing
Outsourcing arrangements shall be considered material where disruption may:
Examples include:
Non-Material Outsourcing
Outsourcing arrangements with limited operational or regulatory impact shall be classified as non-material.
Examples include:
Material outsourcing arrangements shall be subject to enhanced monitoring and oversight.
All outsourcing arrangements shall be governed by written agreements duly executed between the Company and the service provider.
Service providers shall maintain strict confidentiality of customer information and Company data.
The service provider shall:
The Company shall ensure that customer information is not disclosed to unauthorized persons except as permitted under law or with customer consent.
Service providers handling customer or Company data shall maintain adequate information security controls including:
The Company may require periodic security certifications, audits, or compliance confirmations from service providers.
Critical service providers shall maintain adequate:
The Company may periodically review or test such arrangements where necessary.
The Company shall continuously monitor outsourced activities to ensure compliance with contractual and regulatory requirements.
Monitoring activities may include:
Deficiencies identified during monitoring shall be addressed promptly.
The Company shall have the right to conduct audits, inspections, and reviews of the service provider relating to outsourced activities.
The service provider shall provide access to:
The Company may appoint internal or external auditors for such reviews.
The Company shall ensure that RBI or any regulatory authority authorized by RBI has unrestricted access to records, documents, data, systems, and information relating to outsourced activities.
The outsourcing arrangement shall not obstruct or interfere with RBI’s supervisory powers.
The Company shall remain responsible for customer grievance handling in respect of outsourced activities.
Customers shall continue to have access to the Company’s grievance redressal mechanism irrespective of outsourcing arrangements.
The Company shall ensure that outsourcing arrangements do not create conflicts of interest detrimental to customer interests or regulatory compliance.
Appropriate controls shall be implemented wherever potential conflicts are identified.
Service providers shall not further subcontract outsourced activities without prior written approval of the Company.
Where subcontracting is permitted, the primary service provider shall remain fully responsible for compliance with contractual and regulatory obligations.
The Company shall maintain appropriate records relating to outsourcing arrangements including:
Such records shall be maintained in accordance with applicable legal and regulatory requirements.
Where subcontracting is permitted, the primary service provider shall remain fully responsible for compliance with contractual and regulatory obligations.
The Company shall maintain documented exit strategies for outsourced activities to ensure continuity of operations.
Exit management procedures shall include:
This Policy shall be reviewed annually or earlier if required due to:
Any material amendments shall be placed before the Board for approval.
This Policy shall come into effect from the date of approval by the Board of Directors of the Company.
This Outsourcing Policy is approved by the Board of Directors of Fair Securities Private Limited on 01.04.2026.
For and on behalf of
Fair Securities Private Limited