Sanctions Policy
Our sanctions compliance position, the regimes we apply, and how matches and breaches are handled.
1. Purpose & commitment
This document sets out FLOWA PAY INC.'s policy position and control objectives, published for transparency and to support institutional due diligence. It is reviewed periodically and does not constitute legal advice. FLOWA PAY INC. makes no representation that it holds any licence, authorisation or certification except the FINTRAC Money Services Business registration expressly stated in the Regulatory Disclosures.
FLOWA PAY INC. does not facilitate transactions that breach applicable sanctions. This policy sets out our commitment, the regimes we apply, and how we identify, escalate and handle potential matches and breaches. It sits alongside the operational detail in our Sanctions Screening procedure.
2. Regimes applied
We apply the sanctions regimes that bind us and those that bind our banking and payment partners, which in practice means screening against the lists applicable in the jurisdictions in which we and our partners operate, including Canadian sanctions measures and the lists our partners are required to apply. Where a partner applies a stricter standard, the stricter standard governs the activity routed through them.
We also give effect to applicable ministerial directives and to country-level restrictions, which may prohibit or condition activity involving a particular jurisdiction irrespective of whether a specific party is listed.
3. Controls
- Screening of applicants, their beneficial owners, directors and authorised signatories before onboarding, and no processing is enabled before screening is cleared.
- Ongoing re-screening of the customer base, so that a party listed after onboarding is identified rather than missed.
- Screening against updated list data, and re-screening following material list changes.
- Country and jurisdiction controls applied at the level of the business relationship and, where relevant, at transaction level.
- Escalation of potential matches to the compliance officer before any decision to proceed.
4. Handling a potential match
A potential match stops the activity pending review; it is not cleared by the person who encountered it in order to keep a transaction moving. Review establishes whether the match is a true match or a false positive, using identifiers beyond name alone. The conclusion, the identifiers relied upon and the reviewer are recorded in every case, including false positives, because the discipline of recording clearances is what makes the control auditable.
Confirmed true matches are escalated immediately. We do not proceed with the activity, we take the steps required by the applicable regime, including freezing and reporting obligations where they apply, and we do not disclose the reason to the customer beyond what may lawfully be said.
5. If a breach occurs
A suspected breach is escalated to the compliance officer immediately, the activity is stopped, the facts are established and preserved, and required disclosures are made to the relevant authority and to affected partners. A post-incident review identifies the control failure and the remediation, and the outcome is reported to governance.
6. Everyone's responsibility
Sanctions compliance is not delegated to a screening system. Any employee who becomes aware of information suggesting a party or transaction may be sanctioned must escalate it, whether or not a system has alerted. Circumventing or disabling a sanctions control is a serious disciplinary matter.