
OUTSOURCING POLICY

AGRIM FINCAP PRIVATE LIMITED
OUTSOURCING POLICY
A Non-Banking Financial Company – Investment and Credit Company (NBFC-ICC), Non-Deposit Taking, Non-Systemically Important (ND–NSI)
Corporate Address: F40, Ground Floor, Sector 6, Gautam Buddha Nagar, Noida, Uttar Pradesh– 201301
Registered Office Address: 276, First Floor, Gagan Vihar, Shahdara, Delhi- 110051
INTRODUCTION
Agrim Fincap Private Limited (“the Company”), having Corporate Office at F40, Ground Floor, Sector 6, Gautam Buddha Nagar, Noida, Uttar Pradesh– 201301 and Registered Office at 276, First Floor, Gagan Vihar, Shahdara, Delhi- 110051 adopts this Outsourcing Policy (“the policy”) in alignment with the Reserve Bank of India (Non-Banking Financial Companies – Managing Risks in Outsourcing) Directions, 2025, RBI/DOR/2025-26/363DOR.ORG.REC.No.282/21-04-158/2025-26 dated November 28, 2025 or any successions thereof.
PURPOSE
This Outsourcing Policy sets out the guiding principles and governance framework for the Company’s outsourcing arrangements, ensuring that such engagements enhance operational efficiency while safeguarding the interests of customers and stakeholders. The policy seeks to ensure that outsourcing activities are conducted in a prudent, transparent, and risk-managed manner in line with applicable regulatory requirements and industry best practices. It also establishes clear roles, responsibilities, and oversight mechanisms so that the Company retains ultimate accountability and effective control over all outsourced functions and service providers.
KEY RESPONSIBILITIES OF THE COMPANY
The outsourcing of any activity by the Company does not diminish its obligations, and those of its Board and Senior Management, who have the ultimate responsibility for the outsourced activity.
In respect of outsourcing of financial services the Board shall be responsible, inter alia, for:
The Audit Committee of the Board shall:
In respect of outsourcing of IT services, the Board shall be responsible, inter alia, for:
The Company if chooses to outsource financial services shall however not outsource core management functions including Internal Audit, strategic and compliance functions, and decision-making functions such as determining compliance with KYC norms for opening deposit accounts, giving sanction for loans (including retail loans) and management of investment portfolio.
AUTHORISATION, ACCOUNTABILITY, AND OVERSIGHT
The Company shall ensure that:
The Company shall be responsible for making Currency Transactions Reports (CTRs) and Suspicious Transactions Reports (STRs) to FIU or any other competent authority in respect of its customer related activities carried out by the service providers.
OUTSOURCING POLICY FRAMEWORK:
Criteria for Selection of Activities and Service Providers:
The Company shall outsource only those activities that are appropriate and do not affect its control, governance, or regulatory obligations. Prior to outsourcing, the Company shall conduct due diligence to assess the service provider’s competence, financial soundness, reputation, experience, operational capability, and compliance with applicable laws and data security standards.
Delegation of Authority Depending on Risks and Materiality:
Outsourcing arrangements shall be approved based on a defined delegation of authority framework considering the risk and materiality of the activity. Material outsourcing arrangements shall require approval of the Board, while other arrangements may be approved by the senior management.
Systems to Monitor and Review Outsourced Activities:
The Company shall ensure it uses appropriate mechanisms to monitor and periodically review the performance of service providers. This shall include conducting audit at such intervals as the Company thinks fit.
ROLE OF SENIOR MANAGEMENT
The Senior Management of the Company shall, inter alia, be responsible for:
CONFIDENTIALITY AND SECURITY OF INFORMATION
The Company shall seek to ensure the confidentiality, security, preservation, and protection of the customer information in the custody or possession of the service provider. Access to customer information by a service provider or its staff shall be on a ‘need to know’ basis, i.e., limited to those areas where the information is required in order to perform the outsourced function.
The Company shall review and monitor the security practices and control processes of its service providers on a regular basis and require the service provider to disclose security breaches. In instances, where a service provider acts as an outsourcing agent for multiple entities, The Company shall take care to build strong safeguards so that there is no comingling or combining of information, documents, records, and assets.
The Company shall ensure that a service provider is able to isolate and clearly identify the Company’s customer information, documents, records and assets to protect the confidentiality of the information. The Company shall immediately notify RBI in the event of breach of security and leakage of confidential customer related information.
OUTSOURCING AGREEMENT
The Company shall ensure that the terms and conditions governing the outsourcing arrangement are carefully defined in written agreements and vetted by the Company’s legal counsel on their legal effect and enforceability. The agreement shall appropriately reckon the associated risks and the strategies for mitigating or managing them. The Company shall ensure that such an agreement is sufficiently flexible to allow it to retain an appropriate level of control over the outsourcing and the right to intervene with appropriate measures to meet legal and regulatory obligations. The agreement shall also bring out the nature of legal relationship between the parties, i.e., whether agent-principal or otherwise.
MONITORING AND CONTROL OF OUTSOURCED ACTIVITIES
The Company shall maintain a central record of all material outsourcing of financial services for review by its Board and Senior Management. The records shall be updated promptly, and half yearly reviews shall be placed before the Board or Risk Management Committee.
Regular audits, by either the internal auditors or external auditors of the Company shall assess the adequacy of the risk management practices adopted in overseeing and managing the outsourcing arrangement, the company’s compliance with its risk management framework, and the requirements of these Directions.
The Company shall, on an annual basis, review the financial and operational condition of the service provider to assess its ability to continue to meet its outsourcing obligations. Such due diligence reviews, which shall be based on all available information about the service provider, shall highlight any deterioration or breach in performance standards, confidentiality, and security, and in operational resilience or business continuity preparedness.
Certain services, viz., outsourcing of cash management, might involve reconciliation of transaction between the Company, and the service provider (or its subcontractors). In such cases, the Company shall ensure that reconciliation of transactions between itself and the service provider (or its subcontractors) is carried out in a timely manner.
In the event of termination of an outsourcing agreement for any reason, this shall be publicised by the Company by displaying at a prominent place in the branch, posting it on the website, and informing the customers so as to ensure that the customers do not continue to deal with the service provider.
REDRESSAL OF GRIEVANCES RELATED TO OUTSOURCED SERVICES
Company’s Grievance Redressal Machinery will also deal with the issue relating to services provided by the outsourced agency. The Company will give a time limit of 30 days to the customers for preferring their complaints or grievances, as per the procedure given in grievance redressal policy of the Company placed at https://agrimfincap.com/ If a complaint is rejected wholly or partly by the Company and the complainant is not satisfied with the reply or does not get any reply within 30 days, after the Company received the complaint, the complainant can proceed towards Consumer Education and Protection Cell (CEPC) of Regional Office of RBI.

