Transaction Monitoring
How activity is monitored for unusual or suspicious patterns, how alerts are worked and how outcomes are recorded.
1. Purpose & scope
This document sets out FLOWA PAY INC.'s policy position and control objectives, published for transparency and to support institutional due diligence. It is reviewed periodically and does not constitute legal advice. FLOWA PAY INC. makes no representation that it holds any licence, authorisation or certification except the FINTRAC Money Services Business registration expressly stated in the Regulatory Disclosures.
This policy sets out how FLOWA PAY INC. monitors activity on the platform for patterns that may indicate money laundering, terrorist financing, fraud, sanctions evasion or breach of the merchant agreement. It covers both merchant-level behaviour and transaction-level activity, and supports the obligations described in our AML Policy.
2. Risk-based approach
Monitoring intensity follows the risk rating assigned at underwriting and maintained thereafter. A higher-risk merchant, market or product attracts tighter thresholds and more frequent review. Monitoring is not a single screen run once: it is continuous, and it is re-tuned as patterns change.
3. What is monitored
- Activity against expectation. Volume, value, frequency and geography compared with the profile the merchant was approved on. Divergence is the single most useful signal we have.
- Velocity. Transaction counts and values per card, customer, device, address or merchant over defined windows.
- Structuring indicators. Patterns that appear designed to stay below thresholds, including aggregation across related transactions.
- Geography. Activity involving higher-risk jurisdictions, or inconsistency between issuing country, customer market and the approved model.
- Counterparty concentration. Repeated activity with the same instrument, beneficiary or counterparty where that is inconsistent with the business.
- Dispute and refund behaviour. Ratios and trends, which frequently surface both fraud and business-model problems.
- Payout behaviour. Changes to beneficiary details, unusual destinations, and payout patterns inconsistent with the collection pattern.
- Screening events. Sanctions, politically exposed person and adverse-media matches arising after onboarding.
4. How alerts are worked
Alerts are queued, prioritised by risk, and assigned for review. Each review records who performed it, what was examined, what the merchant said where contact was appropriate, the conclusion reached and the basis for it. Possible outcomes are: close with no action; close with a documented explanation; apply controls such as limits or additional verification; escalate for enhanced due diligence; escalate to the compliance officer for reporting consideration; or suspend activity.
Where a review raises grounds for suspicion, the matter is escalated under our Suspicious Transaction Reporting Policy. Reviewers do not disclose to the customer that a report may be or has been made.
5. Tuning and quality
Rules and thresholds are reviewed periodically and after material change to the business, the product set or the risk environment. Tuning considers both missed activity and alert quality, because a system generating alerts nobody can work is a control in name only. Changes to rules are versioned, attributable and recorded.
6. Records
Alerts, reviews, decisions and the evidence relied upon are retained for the period required by applicable law, as set out in our Record Keeping Policy, so that any decision can be reconstructed and explained to a partner, auditor or regulator.