AML Policy
Our anti-money-laundering and counter-terrorist-financing programme: governance, risk assessment, due diligence, screening, monitoring, reporting, records, training and review.
1. Purpose & scope
This document sets out FLOWA PAY INC.'s policy position and control objectives, published for transparency and to support institutional due diligence. It is reviewed periodically and does not constitute legal advice. FLOWA PAY INC. makes no representation that it holds any licence, authorisation or certification except the FINTRAC Money Services Business registration expressly stated in the Regulatory Disclosures.
This Anti-Money-Laundering and Counter-Terrorist-Financing Policy sets out the commitment, control objectives and programme of FLOWA PAY INC. ("Flowa Pay") for preventing money laundering, terrorist financing, proliferation financing, sanctions evasion and related financial crime.
It applies to all directors, officers, employees and contractors, to every product and service we provide, and to every merchant and counterparty we deal with. Compliance is a condition of employment and of engagement, not an aspiration.
This policy is supported by the detailed procedures published in our compliance library, including KYC, KYB, CDD, EDD, Sanctions, Transaction Monitoring, Suspicious Transaction Reporting, Training and Record Keeping.
2. Our regulatory position
FLOWA PAY INC. is registered with the Financial Transactions and Reports Analysis Centre of Canada ("FINTRAC") as a Money Services Business, registration number C100000902, verifiable on the public FINTRAC registry. As a registered MSB we are a reporting entity under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act ("PCMLTFA") and its regulations, and we maintain a compliance programme accordingly.
3. Governance and the compliance officer
A designated compliance officer is appointed with responsibility for the AML programme, with the authority and the access required to discharge it, and with a direct reporting line to senior management. The compliance officer owns this policy, approves the risk assessment, decides whether a report is filed, and reports on programme health to those charged with governance.
Senior management is accountable for the programme's adequacy and for providing the resources it requires. Responsibilities are separated across the business so that the people who own commercial outcomes do not also clear their own financial-crime alerts.
4. Risk-based approach
We maintain a documented enterprise risk assessment covering the money-laundering and terrorist-financing risk presented by our customers and their customers, our products and services, our delivery channels, and the geographies we operate in and touch.
The assessment drives the controls applied: it determines due-diligence depth, monitoring thresholds, screening frequency and review cycles. It is reviewed at least annually and whenever there is material change, including a new product, a new market, a new partner, a significant change in volume or mix, or a change in the external threat environment.
A risk-based approach means proportionate, not lenient. Lower risk attracts lighter measures; higher risk attracts heavier ones; and no risk rating permits a control to be skipped where the law requires it.
5. Customer due diligence
We do not establish a business relationship or process activity before the applicable due diligence is complete. For every customer we:
- identify the customer and verify identity using reliable, independent source material;
- for entities, verify existence, status and ownership, and identify and take reasonable measures to verify the beneficial owners who ultimately own or control the business, together with directors and authorised signatories;
- understand the intended purpose and nature of the relationship, including the business model, markets, expected volumes and payment methods;
- determine whether the customer is acting on behalf of a third party, and where so, obtain the prescribed information about that party;
- screen the customer and associated individuals for sanctions, politically exposed person status and adverse media.
Where we cannot complete due diligence to the required standard, we do not proceed with the relationship, and we consider whether the circumstances give rise to suspicion requiring escalation.
6. Enhanced due diligence and PEPs
Enhanced measures apply to higher-risk relationships, including those involving higher-risk jurisdictions, complex or opaque ownership structures, higher-risk business categories, unusual patterns, and politically exposed persons and heads of international organisations and their family members and close associates.
Enhanced measures include taking reasonable measures to establish source of funds and source of wealth, obtaining senior management approval to establish or continue the relationship, and applying more frequent and more intensive ongoing monitoring and review.
Politically exposed person status is a trigger for scrutiny, not an automatic refusal. The determination, the approval and the rationale are documented in every case.
7. Sanctions
We do not process transactions that would breach applicable sanctions. Customers and associated parties are screened before onboarding and on an ongoing basis thereafter, potential matches stop the activity pending review, and confirmed matches are escalated immediately and handled in accordance with the applicable regime, including freezing and reporting obligations where they apply. Applicable ministerial directives and country-level restrictions are given effect. See our Sanctions Policy.
8. Ongoing monitoring
We monitor business relationships and activity on a risk-sensitive basis to detect patterns that are unusual, inconsistent with what we know of the customer, or indicative of financial crime. Monitoring compares activity against the profile the customer was approved on, applies velocity and structuring controls, considers geography and counterparty concentration, and incorporates screening events arising after onboarding.
Alerts are worked by trained staff, outcomes are documented whether or not action follows, and customer information is kept current so that monitoring is measured against an accurate picture. See our Transaction Monitoring Policy.
9. Reporting to FINTRAC
Where we know, suspect, or have reasonable grounds to suspect that a transaction or attempted transaction is related to a money-laundering or terrorist-financing offence, we submit a Suspicious Transaction Report to FINTRAC as soon as practicable after the measures establishing those grounds are completed. An attempted transaction is reportable even though no funds moved.
We also make the other prescribed reports that our activities engage, including Terrorist Property Reports, Electronic Funds Transfer Reports for prescribed international transfers at or above the reporting threshold, and Large Cash and Large Virtual Currency Transaction Reports where applicable. Related transactions within a 24-hour period are aggregated where the rules require, and structuring to avoid a threshold is itself a red flag that is escalated.
10. Transfer-of-information requirements
Where a transfer is within scope, prescribed originator and beneficiary information accompanies it and is passed to the next institution in the chain. Incoming transfers with missing or incomplete required information are treated as a risk indicator and handled accordingly. See our Travel Rule Policy.
11. Record keeping
We keep records of identification and verification, due-diligence measures and their outcomes, beneficial ownership, risk assessments and ratings, transactions, monitoring alerts and their disposition, reports filed, training, and the decisions taken under this programme, for the period required by applicable law, which for the records to which the Canadian regime applies is generally a minimum of five years.
Records are kept so that any individual transaction or decision can be reconstructed and explained to a partner, an auditor or an examiner. See our Record Keeping Policy.
12. Training
We maintain an ongoing written training programme for all relevant personnel, delivered on joining and periodically thereafter, with role-appropriate depth, updated when obligations or risks change, and evidenced per individual. See our AML Training Policy.
13. Effectiveness review
The effectiveness of the compliance programme, including policies and procedures, the risk assessment and training, is reviewed by an independent party at least every two years. Findings are rated, assigned, tracked and verified to closure, and reported to senior management and governance. See our Compliance Effectiveness Review policy.
14. Risk appetite and prohibited activity
We decline business that we cannot adequately understand, verify or monitor, irrespective of its commercial value, and we exit relationships where risk can no longer be managed. Activities we do not support, and those supported only on conditions, are set out in our Prohibited & Restricted Activities policy. Merchants are assessed and risk-rated before processing under our Merchant Underwriting Policy.
15. Breaches and consequences
Failure to follow this policy, including circumventing a control, clearing an alert without a proper basis, or failing to escalate suspicion, is a serious disciplinary matter and may constitute a criminal offence attracting personal liability. Anyone may raise a concern confidentially and without detriment under our Whistleblowing Policy.
16. Contact
Questions about this policy, or requests for further information in connection with institutional due diligence, can be sent to hello@flowapay.co.