Helpline:

+91 98910 91088

Office:

+91 11 4246 1044

Email Us:

sales@moneyworkshop.in

Helpline No.: +91 98910 91088

Email us: mf@moneyworkshop.co.in

IT Policy

MoneyWorkshop
201, NDM-2, Netaji Subhash Palace, Pitampura, Delhi – 110034

AMFI Registered Mutual Fund Distributor | ARN-10195 | Initial Registration: 05/09/2003 | Validity: 27/04/2028

Effective Date: 20/04/2010

Last Updated: 25/07/2020

Approved By: Management

Applicable To: All Employees, Consultants, Trainees and Authorized Users

1. Purpose

The purpose of this IT & Information Security Policy is to establish guidelines for the secure and responsible use of information technology, computer systems, applications and digital information at MoneyWorkshop.

The policy is designed to protect client information, financial data, transaction records, company information and IT systems from unauthorized access, misuse, loss, alteration or disclosure.

2. Scope

This policy applies to all employees and authorized users who access MoneyWorkshop’s:

  • Computers and laptops
  • Email accounts
  • Internet and Wi-Fi
  • Mutual fund transaction platforms
  • CRM and portfolio management systems
  • Cloud applications and storage
  • Mobile phones and other company devices
  • Client databases and records
  • Digital documents and files
  • Social media and communication platforms
3. Information Security Principles

MoneyWorkshop shall maintain the following principles:

  • Confidentiality: Information must only be accessed by authorized persons.
  • Integrity: Information and records must remain accurate and protected from unauthorized alteration.
  • Availability: Critical systems and information should remain accessible to authorized users when required.
4. User Access & Authorization

Access to IT systems shall be provided based on an employee’s job responsibilities.

Employees must:

  • Use only their own user ID and password.
  • Never share passwords or login credentials.
  • Access only information necessary for their assigned duties.
  • Log out of systems when leaving their workstation.
  • Immediately report suspected unauthorized access.
  • Not attempt to bypass security controls.

Access rights should be reviewed periodically and removed promptly when an employee leaves the organization or changes roles.

5. Password Policy

All employees must maintain secure passwords.

Passwords should:

  • Be unique for each important system.
  • Not be shared with colleagues or external persons.
  • Not be written where unauthorized persons can access them.
  • Not contain easily identifiable personal information.
  • Be changed immediately if compromise is suspected.

Where supported, multi-factor authentication (MFA) should be enabled for important systems such as email, cloud storage and financial platforms.

6. Client Data Confidentiality

Client information is confidential and must be protected at all times.

This may include:

  • PAN and KYC information
  • Bank account details
  • Folio numbers
  • Investment and transaction details
  • Portfolio statements
  • Contact information
  • Financial information
  • Identity documents
  • Nominee information
  • Other personal or financial records

Employees must not download, copy, forward, photograph or share client information unless required for legitimate business purposes and through authorized channels.

7. Email & Digital Communication

Official company email accounts should be used for business communication wherever practical.

Employees must:

  • Verify recipients before sending confidential information.
  • Exercise caution before opening unknown attachments or links.
  • Not respond to suspicious requests for passwords, OTPs or financial information.
  • Not forward confidential client information to unauthorized personal email accounts.
  • Report suspected phishing or fraudulent emails immediately.

Sensitive documents should be shared using appropriate secure methods wherever available.

8. WhatsApp & Messaging Applications

Employees may use approved messaging applications for client communication in accordance with company procedures.

Employees must exercise particular care when sharing:

  • KYC documents
  • PAN/Aadhaar-related information
  • Bank details
  • Portfolio statements
  • Transaction information
  • Other sensitive client documents

Client information must not be shared in personal groups or with unauthorized persons.

Official client communication should be retained or documented where required under applicable record-keeping procedures.

9. Mutual Fund Platforms & Financial Systems

Employees using platforms such as BSE StAR MF, CAMS, KFin Technologies, NSDL, RTA portals, CRM/portfolio systems or other authorized platforms must follow the applicable authorization and security procedures.

Employees shall:

  • Use individual credentials wherever provided.
  • Verify client and transaction details before submission.
  • Obtain required client authorization/consent.
  • Not share platform credentials.
  • Not initiate unauthorized transactions.
  • Not alter or manipulate transaction records.
  • Maintain appropriate supporting documentation.
  • Report errors or suspicious transactions promptly.
10. Computer & Laptop Security

Employees must ensure that company computers and laptops are adequately protected.

Employees should:

  • Lock their computer when away from their desk.
  • Keep operating systems and security software updated.
  • Avoid installing unauthorized software.
  • Not connect unknown USB devices without authorization.
  • Use approved antivirus/security solutions.
  • Report lost or stolen devices immediately.

Company devices should not be used by unauthorized persons.

11. Internet Usage

Internet access provided by MoneyWorkshop is primarily for legitimate business purposes.

Employees must not use company systems to:

  • Access illegal or inappropriate content.
  • Download unauthorized software.
  • Conduct activities that compromise system security.
  • Visit suspicious websites.
  • Engage in activities that may damage the company’s reputation.

Excessive personal use of company internet resources may be restricted.

12. Software & Applications

Only authorized and properly licensed software should be installed on company devices.

Employees must not:

  • Install pirated software.
  • Download unauthorized applications.
  • Use unapproved cloud-storage services for company information.
  • Install browser extensions or applications that create security risks.

Requests for new software or applications should be approved by the designated person.

13. Data Backup

Important business and client-related records should be backed up through authorized backup systems.

Backups may include:

  • Client records
  • Transaction records
  • Accounting records
  • Compliance documents
  • Business correspondence
  • Important operational files

Backup procedures should be reviewed periodically to ensure that important information can be restored when required.

14. Data Storage & Record Retention

Company and client information should be stored only in authorized locations.

Employees must not permanently store confidential company or client information on personal devices unless specifically authorized.

Records shall be retained in accordance with:

  • Applicable regulatory requirements
  • Company record-retention procedures
  • Legal requirements
  • Applicable mutual fund documentation requirements
15. Cybersecurity & Phishing

Employees must remain alert to cybersecurity threats including:

  • Phishing emails
  • Fake login pages
  • Malware
  • Ransomware
  • Identity theft
  • Social engineering
  • Unauthorized remote-access requests
  • Fraudulent client communications

Employees must never disclose passwords, OTPs, PINs or authentication credentials to unknown persons.

16. Information Security Incident Reporting

Any suspected IT or information-security incident must be reported immediately to the designated management/IT person.

Examples include:

  • Lost or stolen laptop/mobile
  • Suspected hacking
  • Unauthorized login
  • Phishing attack
  • Malware infection
  • Accidental disclosure of client information
  • Wrong email recipient
  • Loss of important data
  • Unauthorized transaction
  • Compromised password

Employees should not attempt to conceal or delete evidence of an incident.

17. Mobile Devices

Employees using mobile devices for business purposes must:

  • Use a secure screen lock.
  • Keep the device updated.
  • Enable device security features where available.
  • Avoid storing unnecessary sensitive client information.
  • Report lost or stolen devices immediately.
  • Avoid using unsecured public Wi-Fi for sensitive business activities wherever possible.
18. Remote Work / Work From Home

When working remotely, employees must maintain the same level of confidentiality and security as within the office.

Employees should:

  • Use secure internet connections.
  • Avoid accessing sensitive information through public computers.
  • Prevent family members or other persons from accessing company devices.
  • Keep confidential documents secure.
  • Use only authorized applications and systems.
19. Social Media

Employees must not disclose confidential company or client information on social media.

Employees must not:

  • Publish client portfolios or personal information.
  • Share internal company documents.
  • Disclose confidential business information.
  • Make unauthorized statements representing the company.
  • Share screenshots of internal systems or client records.

Only authorized personnel may publish official MoneyWorkshop content.

20. Third-Party & Vendor Access

Where external vendors, software providers or service providers require access to company systems or information, such access should be:

  • Authorized by management.
  • Limited to the information required for the service.
  • Provided for the minimum period necessary.
  • Revoked when no longer required.

Third parties should be expected to maintain appropriate confidentiality and security standards.

21. Employee Exit & Access Revocation

When an employee leaves MoneyWorkshop or changes responsibilities:

  • System access shall be reviewed.
  • Login credentials shall be disabled or modified as appropriate.
  • Company devices must be returned.
  • Company documents and data must be handed over.
  • Access to email, cloud storage and financial platforms must be revoked where applicable.
  • Confidentiality obligations shall continue after employment.
22. Business Continuity

MoneyWorkshop should maintain reasonable procedures for continuing critical operations in the event of:

  • System failure
  • Internet outage
  • Cybersecurity incident
  • Hardware failure
  • Data loss
  • Power failure
  • Other operational disruptions

Critical information should be recoverable through appropriate backup and contingency arrangements.

23. Employee Responsibility

Every employee is responsible for protecting the information and systems to which they have access.

Failure to follow this policy may result in:

  • Withdrawal of system access
  • Warning or disciplinary action
  • Termination of employment, where appropriate
  • Reporting to relevant authorities, where required
24. Policy Review

This policy shall be reviewed periodically and updated whenever there are material changes in:

  • Regulatory requirements
  • Technology
  • Cybersecurity risks
  • Business operations
  • Internal systems and processes
25. Employee Acknowledgement

I confirm that I have read and understood the IT & Information Security Policy of MoneyWorkshop and agree to comply with the security, confidentiality and technology requirements applicable to my role.

Employee Name: __________________________

Designation: ______________________________

Signature: _________________________________

Date: _____________________________________

For MoneyWorkshop

Authorized Signatory: ______________________

Date: _____________________________________

Need help with Investing?