+91 98910 91088
+91 11 4246 1044
sales@moneyworkshop.in
IT Policy
MoneyWorkshop
201, NDM-2, Netaji Subhash Palace, Pitampura, Delhi – 110034
AMFI Registered Mutual Fund Distributor | ARN-10195 | Initial Registration: 05/09/2003 | Validity: 27/04/2028
Effective Date: 20/04/2010
Last Updated: 25/07/2020
Approved By: Management
Applicable To: All Employees, Consultants, Trainees and Authorized Users
The purpose of this IT & Information Security Policy is to establish guidelines for the secure and responsible use of information technology, computer systems, applications and digital information at MoneyWorkshop.
The policy is designed to protect client information, financial data, transaction records, company information and IT systems from unauthorized access, misuse, loss, alteration or disclosure.
This policy applies to all employees and authorized users who access MoneyWorkshop’s:
MoneyWorkshop shall maintain the following principles:
Access to IT systems shall be provided based on an employee’s job responsibilities.
Employees must:
Access rights should be reviewed periodically and removed promptly when an employee leaves the organization or changes roles.
All employees must maintain secure passwords.
Passwords should:
Where supported, multi-factor authentication (MFA) should be enabled for important systems such as email, cloud storage and financial platforms.
Client information is confidential and must be protected at all times.
This may include:
Employees must not download, copy, forward, photograph or share client information unless required for legitimate business purposes and through authorized channels.
Official company email accounts should be used for business communication wherever practical.
Employees must:
Sensitive documents should be shared using appropriate secure methods wherever available.
Employees may use approved messaging applications for client communication in accordance with company procedures.
Employees must exercise particular care when sharing:
Client information must not be shared in personal groups or with unauthorized persons.
Official client communication should be retained or documented where required under applicable record-keeping procedures.
Employees using platforms such as BSE StAR MF, CAMS, KFin Technologies, NSDL, RTA portals, CRM/portfolio systems or other authorized platforms must follow the applicable authorization and security procedures.
Employees shall:
Employees must ensure that company computers and laptops are adequately protected.
Employees should:
Company devices should not be used by unauthorized persons.
Internet access provided by MoneyWorkshop is primarily for legitimate business purposes.
Employees must not use company systems to:
Excessive personal use of company internet resources may be restricted.
Only authorized and properly licensed software should be installed on company devices.
Employees must not:
Requests for new software or applications should be approved by the designated person.
Important business and client-related records should be backed up through authorized backup systems.
Backups may include:
Backup procedures should be reviewed periodically to ensure that important information can be restored when required.
Company and client information should be stored only in authorized locations.
Employees must not permanently store confidential company or client information on personal devices unless specifically authorized.
Records shall be retained in accordance with:
Employees must remain alert to cybersecurity threats including:
Employees must never disclose passwords, OTPs, PINs or authentication credentials to unknown persons.
Any suspected IT or information-security incident must be reported immediately to the designated management/IT person.
Examples include:
Employees should not attempt to conceal or delete evidence of an incident.
Employees using mobile devices for business purposes must:
When working remotely, employees must maintain the same level of confidentiality and security as within the office.
Employees should:
Employees must not disclose confidential company or client information on social media.
Employees must not:
Only authorized personnel may publish official MoneyWorkshop content.
Where external vendors, software providers or service providers require access to company systems or information, such access should be:
Third parties should be expected to maintain appropriate confidentiality and security standards.
When an employee leaves MoneyWorkshop or changes responsibilities:
MoneyWorkshop should maintain reasonable procedures for continuing critical operations in the event of:
Critical information should be recoverable through appropriate backup and contingency arrangements.
Every employee is responsible for protecting the information and systems to which they have access.
Failure to follow this policy may result in:
This policy shall be reviewed periodically and updated whenever there are material changes in:
I confirm that I have read and understood the IT & Information Security Policy of MoneyWorkshop and agree to comply with the security, confidentiality and technology requirements applicable to my role.
Employee Name: __________________________
Designation: ______________________________
Signature: _________________________________
Date: _____________________________________
For MoneyWorkshop
Authorized Signatory: ______________________
Date: _____________________________________
Risk Factors: Mutual Fund investments are subject to market risks. Past performance may not be sustained and does not guarantee future returns. Investors should carefully read scheme documents and evaluate applicable exit loads and expenses before investing. We deal only in Regular Plans and receive trailing commissions, which are disclosed to clients at the time of investment. Direct Plans are also available with lower expense ratios; we do not deal in Direct Plans
WhatsApp us