ポリシー

TransFi Group Global Privacy Policy

Last Updated: 27 April 2026

Contact Us

If you have any questions about this Privacy Policy, you can contact us:
By email: compliance@transfi.com

1. What is the objective of TransFi’s Privacy Policy?

“TransFi” refers to Trans-Fi Inc. and its affiliates and subsidiaries worldwide as mentioned under Annexure A and as amended from time to time (collectively “TransFi Group”, “TransFi”, “we”, “us” or “our”).

TransFi may share your personal data with its other entities (subsidiaries and affiliates) and use it in accordance with this Privacy Policy.

The objective of TransFi’s (all subsidiaries and affiliates) privacy policy (the “Privacy Policy”) is to commit to protecting your privacy. Please read this carefully as this policy is legally binding when you choose to use our Services. For the purpose of the relevant data protection regulations, TransFi may act as either the “data controller”, “data processor” or both of your information.

This Privacy Policy describes how we collect, use, handle and, under certain conditions, disclose your personal data, when you access our Services, which include our content on the Website located at www.transfi.com or any other websites, pages, features, or content we own or operate, including the TransFi payments transaction platform (collectively, the “Website(s)”), or any TransFi widget, application programming interface (“API”) or third party applications relying on such an API, products (Payouts, Collections and Ramp) and related services (referred to collectively hereinafter as “Services”).

This Privacy Policy also explains the steps we have taken to secure your personal information. Finally, this Privacy Policy explains your options regarding the collection, use and disclosure of your personal information. By visiting the Website, you accept the practices described in this Privacy Policy for the Website. If you do not acknowledge and accept this Privacy Policy, you may not use the Services.

If you have any questions about this policy, please send them to compliance@transfi.com

2. What personal information do we collect from you?

Personal information means any data which relates to a living individual who can be identified from that data, or from that data and other information, which is in the possession of, or is likely to come into the possession of, TransFi (or its representatives or service providers). In addition to information, it includes any expression of opinion about an individual and any indication of the intentions of TransFi or any other person in respect of an individual. The definition of personal information depends on the relevant law applicable for your physical location. The data TransFi may collect and use about you is described below in sections 2.1–2.3 of this Privacy Policy.

TransFi obtains information about you from various sources. “You” may be an individual or legal entity entering into a business services agreement with TransFi and/or setting up a user account with TransFi and using the Services provided or through our Website or API (“User”), a legal entity/business identified under anti money laundering (“AML”) or counter terrorist financing (“CTF”) identification requirements as per local regulations, verified by TransFi, that uses our Services to collect payments, make payouts, or facilitate cross-border transfers (“Client”), a legal entity that has a contractual relationship with a TransFi Client and may be subject to AML/CTF identification requirements, verified either by TransFi or the Client (“Merchant”), a legal entity that is a client of a Merchant and may be subject to AML/CTF identification requirements, verified either by TransFi or the Merchant (“Sub-Merchant”), or individuals or legal entities that are the end users of Merchants who interact with the Services provided (“End User”). You may also be a recipient/beneficiary of one of our Services, or a visitor to our Website or other service that links to our API and Services. If You are a Merchant, a Sub-Merchant, or End User, your use of the Services will be governed by the applicable agreement between TransFi and the relevant Client.

2.1 Information you provide to us

This includes information you provide to us in order to establish an account and access our Services. This information is either required by law (e.g. to verify your identity), necessary to provide the requested Services (e.g. you will need to provide your bank account number if you would like to link that account to TransFi), or is relevant for our legitimate interests described in greater detail below.

The nature of the Services you are using or interacting with will determine the kind of personal information we might ask for, but may include:

  • Personal Identification Information: full name, date of birth, age, nationality/citizenship, country of residence, government-issued ID details (including ID number, ID type, issuance and expiry dates), social security number, tax ID number, account credentials, geolocation, unique device details, network information or internet protocol address, wallet address, gender, signature, utility bills, photographs, phone number, home address, email and/or any other information deemed necessary to comply with our legal obligations under applicable law and regulations;
  • Official Identity Documents: government-issued identity document such as a passport, visa or national identity card, state ID card, driver’s licence, and/or any other information deemed necessary to comply with our legal obligations under applicable law and regulations;
  • Financial Information: bank account information, payment card information, tax identification number (“TIN”), transaction history, trading data. For transaction details, we store order details, the User’s bank account number, bank account name, and card information, including the cardholder’s name, card number, CVV, and expiration date. As we are Payment Card Industry Data Security Standard (“PCI DSS”) certified, we are able to securely store this information to meet our compliance obligations and ensure data security. While we do not store your TransFi User account login credentials, we securely handle and store card details in compliance with PCI DSS standards. Payment card information may also be processed through our system during transactions via secure third-party service providers.
  • Transaction Information: information about the transactions you undertake in connection with our Services, such as the name of the recipient, your name, the amount and/or timestamp, purpose of transaction, jurisdiction of transaction;
  • Verification Information: to verify your identify, including information for fraud checks and other information you provide, including images of yourself and a liveliness check;
  • Employment Information: Office location, job title, and/or description of role; or
  • Correspondence: Survey responses, information provided to our support team or User research team.

If you are a company, we may request information such as your employer Identification number (or comparable number issued by a government), proof of legal formation (e.g. Articles of Incorporation) and personal identification information for all material beneficial owners for Know Your Business (“KYB”) purposes.

If you do not provide us with the information below, we may not be able to provide the Services to you, or your use of the Services may be restricted.

In addition to the information you provide to us in connection with your use of the Services, you may also choose to submit information to us via other channels, including in connection with an actual or potential business relationship with TransFi.

2.2 Information we collect automatically or generate about you

This includes information we collect automatically, such as whenever you interact with our Website or use our Services. With regard to your use of our Services we may automatically collect the following information:

  • Details of the transactions you carry out when using our Services, including geographic location from which the transaction originates;
  • Technical information, including the Internet protocol (“IP”) address used to connect your computer to the Internet, your login information, browser name, type and version, time zone setting, browser plug-in types and versions, operating system, geolocation/tracking details and platform, device details;
  • Information about your visit, including the authentication data, security questions, full Uniform Resource Locators (“URL”) clickstream to, through and from our Website or mobile application (including date and time); products you viewed or searched for; page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page and any email used to contact us.
  • Cookies and other Technology. Like many websites, our Website employs cookies, location-based Services and web beacons (also known as clear GIF technology or “action tags”) to speed your navigation of our Website, recognize you and your access privileges, and track your usage. Please read our Cookie Policy for more information.

2.3 Information collected from third parties

We may receive information about you if you visit or use our Website or use our Services. This includes information we may obtain about you from third-party sources. The main types of third parties we receive your personal information from are:

  • Public databases, ID verification partners in order to verify your identity in accordance with applicable law. ID verification partners use a combination of government records and publicly available information about you to verify your identity. Such information may include your name, address, job role, public employment profile, status on any sanction’s lists maintained by public authorities, and other relevant data;
  • Blockchain data to ensure parties using our Services are not engaged in illegal or prohibited activity, sanctioned jurisdiction, dark net, child abuse, etc. and to analyze transaction trends for research and development purposes by screening wallet address for the source of funds;
  • Marketing partners & resellers so that we can better understand which of our Services may be of interest to you;
  • The banks/financial service providers you use to transfer money to us will provide us with your basic personal information, such as your name and address, as well as your financial information such as your bank account details;
  • Business partners may provide us with your name and address, as well as financial information, such as card payment information; and
  • Advertising networks, analytics providers and search information providers may provide us with pseudonymised information about you, such as confirming how you found our Website.

3. How do we use your personal information?

We may use your information in the following ways and for the following purposes:

(a) Internal Use

We use your personal information to provide you with our Services. We may use your personal information to improve our Website’s content and layout, and improve our marketing efforts. Additionally, we use your information to ensure the safety, security, and integrity of our Services by protecting against fraudulent, unauthorised, or illegal activity; monitoring identity and service access; and addressing security risks.

(b) Communications with You

According to your preferences and in compliance with applicable law, we may send you marketing communications to inform you about events, to deliver targeted marketing and to share promotional offers. This may involve sending you communications via emails or mobile application notifications about our Services, features, promotions, surveys, news, updates, and events, managing your participation in promotions and events, delivering targeted marketing, and determining general information about visitors’ usage behaviour on the Website. Our marketing will be conducted in accordance with your advertising and marketing preferences and as permitted by applicable law. We require certain information, such as your identification, contact, and payment details, to provide and maintain our Services. If you are a new User or Client, we will contact you by electronic means for marketing purposes only if you have consented to such communication. If you do not want us to send you marketing communications, please go to your account settings to opt out or submit a request via compliance@transfi.com.

We may send you service updates regarding administrative or account-related information, security issues, or other transaction-related information. These communications are important to share developments relating to your account that may affect how you can use our Services. You cannot opt out of receiving critical service communications.

We also process your personal information when you contact us to resolve any questions, disputes, collect fees, or to troubleshoot problems. Without processing your personal information for such purposes, we cannot respond to your requests and ensure your uninterrupted use of the Services.

(c) Legal and Regulatory Compliance

TransFi is required to process your personal information in compliance with AML/CTF, and security laws, which may include the collection, use, and storage of your information in certain ways. For example, we must identify and verify customers using our Services, including collecting photo identification and using third-party service providers to compare your personal information against databases and public records. When you seek to link a bank account to your TransFi account, we may request additional information to verify your identity or address and manage risk, as required by applicable law. Additionally, we may disclose personal information in response to requests from law enforcement, subpoenas, court orders, or as otherwise required by law, and where necessary to protect our legal rights, enforce agreements, or prevent fraud and abuse of our Services. This includes efforts to mitigate account compromise or loss of funds, investigate complaints, claims and/or disputes, and comply with regulatory or legal requests/inquiries.

(d) External Use

We disclose information to our service providers to help enable them to perform Services on your behalf. For example, to facilitate the purchase and custody of digital assets, we share certain information with third parties, such as your name, email address, physical address, social security number, date of birth, government-issued identification and the amount of digital assets being purchased. Further, the types of data we collect and share with third parties are described above in the information you provide to us, which includes your date of birth, country of residence, first name, last name, ID number, ID type, ID issue date, and ID expiry date, your bank account number, bank account name, and card information, including the name on the card, card number, CVV, and expiration date.

We may share non-personal information (such as the number of daily visitors to our Website or the size of an order placed on a certain date) with third parties. This information does not directly personally identify you or any User. For the avoidance of doubt, any IP addresses or a device or other identifier we collect may be shared with one or more third parties.

(e) Our Legitimate Business Interests

Sometimes the processing of your personal information is necessary for our legitimate business interests, such as:

  • quality control and staff training;
  • to enhance security, monitor and verify identity or service access, and to combat spam or other malware or security risks;
  • research and development purposes;
  • to enhance your experience of our Services and Website;
  • to facilitate corporate acquisitions, mergers, or transactions;
  • to conduct internal operations needed to deliver our Services, including troubleshooting software bugs and operational issues.

4. What personal information do we disclose to third parties?

We allow your personal information to be accessed only by those who require access to perform their work and share it only with third parties who have a legitimate purpose for accessing it. TransFi will never sell or rent your personal information to third parties without your explicit consent. We will only share your personal information with selected third parties including:

  • Identity verification services to prevent fraud. This allows TransFi to confirm your identity by comparing the information you provide us to public records and other third-party databases;
  • Financial institutions which we partner with to process payments you have authorised;
  • Affiliates, business partners, suppliers and sub-contractors for the performance and execution of any contract we enter into with them or you;
  • Analytics and search engine providers that assist us in the improvement and optimisation of our Website;
  • Companies or other third parties in connection with business transfers or bankruptcy proceedings;
  • Companies or other entities that purchase TransFi assets;
  • Law enforcement, regulators, or any other third parties when we are compelled to do so by applicable law or if we have a good faith belief that such use is reasonably necessary, including to protect the rights, property, or safety of TransFi, TransFi customers, third party, or the public; comply with legal obligations or requests; enforce our terms and other agreements; or detect or otherwise address security, fraud, or technical issues; and
  • If you authorise one or more third-party applications to access our Services, then the information you have provided to TransFi may be shared with those third parties. A connection you authorise or enable between your TransFi account and a non-TransFi account, payment instrument, or platform is considered an “account connection.” Unless you provide further permissions, TransFi will not authorise these third parties to use this information for any purpose other than to facilitate your transactions using our Services. Please note that third parties you interact with, should have their own privacy policies and TransFi is not responsible for their operations or their use of data they collect.

Examples of account connections include:

Merchants

If you use your TransFi account to conduct a transaction with a third-party merchant, the merchant may provide data about you and your transaction to us.

Your financial services providers

For example, if you send us funds from your bank account, your bank will provide us with identifying information in addition to information about your account in order to complete the transaction.

You acknowledge and agree that TransFi may continue to use and disclose your personal data for a reasonable period following the termination of the relationship between you and TransFi for one or more of the following purposes:

  • to enable TransFi to fulfil its outstanding obligations to you under any agreement, if applicable;
  • to allow TransFi to enforce its rights under any agreement, if applicable;
  • for any purposes to which you have provided your written consent;
  • as required under applicable law; and
  • as mandated by an order from a court of competent jurisdiction.

5. Links to other sites

Our Website may contain links to other websites for your convenience or information. These websites are operated by entities unaffiliated with TransFi, and we do not control, endorse, or take responsibility for their content or privacy practices. Each linked website may have its own terms of use and privacy policies, which may differ from ours. We encourage you to review these policies whenever you visit third-party websites, as TransFi is not responsible for the practices or policies of these external sites.

6. How do we protect and store personal information?

TransFi implements and maintains reasonable measures to protect your personal information. Your files are protected with safeguards according to the sensitivity of the relevant information. Reasonable controls (such as restricted access) are placed on our computer systems.

TransFi is an international business with operations in multiple countries. This means we may transfer to locations outside of your country. When we transfer your personal information to another country, we will ensure that any transfer of your personal information is compliant with applicable data protection law.

We may store and process all or part of your personal and transactional information, including certain payment information, such as your encrypted bank account and/or routing numbers. We protect your personal information by maintaining physical, electronic, and procedural safeguards in compliance with the applicable laws and regulations.

As a condition of employment, TransFi’s employees are required to follow all applicable laws and regulations, including in relation to data protection law. Access to sensitive personal information is limited to those employees who need it to perform their roles. Unauthorized use or disclosure of confidential customer information by a TransFi employee is prohibited and may result in disciplinary measures.

Finally, we rely on third-party service providers for the physical security of some of our computer hardware. We require those third-party service providers to comply with commercially reasonable security practices and measures. For example, when you visit our Website, you access servers that are kept in a secure environment. While we take industry-standard precautions to safeguard your personal information and secure your account, no system can be completely secure. As such, you assume the risk of potential breaches and their consequences. To protect your account, please safeguard your credentials, choose a complex password when registering, enable advanced security features like two-factor authentication, and never share your account credentials with third parties.

If we anonymize your personal information so that it can no longer be associated with you, it will no longer be considered personal information, and we can use it without further notice to you.

We do not knowingly request to collect personal information from any person under the age of 18. If a User submitting personal information is suspected of being younger than 18 years of age, TransFi will require the User to close his or her account and will not allow the User to continue using our Services. We will also take steps to delete the information as soon as possible.

We retain personal information as long as reasonably necessary to fulfil its intended purposes and meet our contractual and legal obligations. Email addresses and phone numbers are stored until the User uses the TransFi Services, and data is retained for five years once the User unsubscribes or removes themselves. Information will be deleted or de-identified when no longer needed, unless longer retention is required by law. TransFi retains certain information under AML/CTF regulations and holds data for a period of five years. If we cannot fully delete or de-identify information, we will take reasonable measures to prevent further processing.

7. Do we do any profiling and automated decision making?

We may use some instances of your data in order to customise our Services and the information we provide to you, and to address your needs — such as your country of address and transaction history. For example, if you frequently send funds from one particular currency to another, we may use this information to inform you of new product updates or features that may be useful for you. When we do this, we take all necessary measures to ensure that your privacy and security are protected — and we only use pseudonymised data wherever possible. This activity has no legal effect on you.

8. What are your privacy and information access rights?

Depending on applicable law of where you reside, you may be able to assert certain rights related to your personal information. These rights include:

  • the right to obtain information regarding the processing of your personal information and access to the personal information which we hold about you;
  • the right to withdraw your consent to the processing of your personal information at any time. Please note, however, that we may still be entitled to process your personal information if we have another legitimate reason for doing so (for example, we may need to retain personal information to comply with a legal obligation);
  • in some circumstances, the right to receive some personal information in a structured, commonly-used and machine-readable format and/or request that we transmit that data to a third party where this is technically feasible. Please note that this right only applies to personal information which you have provided directly to TransFi;
  • the right to request that we rectify your personal information if it is inaccurate or incomplete;
  • the right to request that we erase your personal information in certain circumstances. Please note that there may be circumstances where you ask us to erase your personal information, but we are legally entitled to retain it;
  • the right to object to, or request that we restrict, our processing of your personal information in certain circumstances. Again, there may be circumstances where you object to, or ask us to restrict, our processing of your personal information but we are legally entitled to refuse that request;
  • the right to lodge a complaint with the relevant data protection regulator if you think that any of your rights have been infringed by us; and
  • the right to transfer your personal data between data controllers, for example, to move your account details from one online platform to another.

Our Services may, from time to time, contain links to and from the websites of our partners, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility for them. Please check these policies before you submit any personal data to these websites.

Further information about your rights may be obtained by contacting the supervisory data protection authority located in your jurisdiction.

Subject to applicable laws, you may have the right to access information we hold about you. Your right of access can be exercised in accordance with the relevant data protection legislation.

9. How often is the Privacy Policy updated?

We may update this Privacy Policy from time to time and without prior notice to you to reflect changes in our information practices, and any such amendments shall apply to information already collected and to be collected. Your continued use of our Website or any of our Services after any changes to this Privacy Policy indicates your agreement with the terms of the revised Privacy Policy.

Please review this Privacy Policy periodically and especially before you provide personal data to us. If we make material changes to this Privacy Policy, we will notify you here, by email or by means of a notice on the home page of our Website. The date of the last update of the Privacy Policy is indicated at the top of this document.

10. How can you contact us regarding any privacy questions?

If you have any questions about this Privacy Policy, please contact us at compliance@transfi.com

Annexure A

This list is indicative only and may be updated without notice

  • Trans-Fi Inc.
  • TransFi UAB
  • TransFi Canada INC.
  • TransFi PTE. LTD.
  • TransFi Technology LLC
  • TransFi Innovation Limited
  • Trans-Fi India Private Limited
  • TransFi Bahamas Limited
  • PT. TransFi Indonesia Merdeka
  • TransFi Digital Limited
  • TransFi Australia PTY LTD

TransFi AML KYC Policy

Last updated: August 2026

Table of Contents

Section 1: Version Control
Section 2: Document Overview
2.1 Objectives & Goals
2.2 Program Ownership
2.3 Stakeholders
Section 3: Introduction
3.1 Business Model Overview
3.2 Simple Flow of Funds
Section 4: Regulatory Overview
4.1 Definitions:
4.1.1 Money Laundering
4.1.2 Terrorist Financing
4.1.3 Money Service Business
4.1.4 FINTRAC
4.1.5 Financial Action Task Force (FATF)
4.1.6 Business Relationship
4.1.7 Tipping Off
4.1.8 24 Hour Rule
4.1.9 Ministerial Directives
4.1.10 Politically Exposed Persons & HIOs
4.2 Canadian Money Service Business Requirements
4.2.1 FINTRAC MSB Registration
4.2.2 Revenue Québec MSB Registration
4.2.3 FINTRAC Travel Rule
4.2.4 Sanctions Requirements
4.2.5 Ministerial Directives
4.3 Non-Compliance
Section 5: TransFi Canada's Compliance Program
5.1 Appointment of a Compliance Officer
5.2 Risk-Based Approach
5.3 Customer Due Diligence
5.4 Sanction and Applicant Screening
5.5 Client Risk Rating and Classification
Section 6: Enhanced Due Diligence (EDD)
6.1 Enhanced Measures
Section 7: Reporting Requirements
7.1 MSB Reporting Requirements Overview
Section 8: Identifying Suspicious Activity & Investigations
8.1 Investigation Framework
8.1.1 Investigation Outcomes
Section 9: Compliance Monitoring
9.1 Client Maintenance Reviews
9.2 Transaction Monitoring
Section 10: Record Keeping
Section 11: AML Staff Training Plan

Section 12: Two Year Effectiveness Review
Section 13: Voluntary Self-Declaration of Non-Compliance (VSDONC)
Section 14: Law Enforcement Requests
14.1 Notification
14.2 Review
14.3 Investigation
14.4 Response
14.5 Actions
Section 15: Country Acceptance Policy
15.1 Banned Countries
15.2 Restricted Countries
15.3 Onboarding Exceptions
Section 16: Prohibited Industries
16.1 Restricted Industries
16.2 Onboarding Exceptions
Section 17: Policy Review Schedule

Section 1: Version Control

Version Reviewer Date Description
1.0 Payaswani Shukla 04/1/2024 Creation of Policy
2.0 CAMLO 10/8/2024 Revamp & Update.
2.1 CAMLO 23/02/2025 Country and Industry updates.
2.2 CAMLO 10/10/2025 Country and Industry updates.
2.3 Payaswani Shukla 14/11/2025 UBO Ownership percentage updated
2.4 Payaswani Shukla 19/2/2026 Prohibited business list updated
2.5 Payaswani Shukla 07/4/2026 Updated sections as per review findings
2.6 Payaswani Shukla 01/5/2026 Updated Address
2.7 Payaswani Shukla 15/7/2026 Updated Prohibited Country
2.8 Payaswani Shukla 24/7/2026 Updated KYC description

Section 2: Document Overview

2.1 Objectives & Goals

TransFi Canada's AML policy and associated internal controls are designed to outline the regulations and requirements outlined in the Proceeds of Crime, Money Laundering and Terrorist Financing Act (PCMLTFA) and associated regulations and to ensure a culture of compliance, guide daily operational compliance functions, assesses and mitigate risk, and summarize TransFi Canada's overall compliance regime.

2.2 Program Ownership

Designation Name Email
Primary Head of Compliance Payaswani Shukla payaswani@transfi.com
Reviewed By CAMLO Justin Leegsma Compliance@transfi.com

2.3 Stakeholders

Stakeholders in this process include:

  • Executives
  • Legal Counsel
  • Operational Staff
  • Brokers & Counterparties
  • Merchants
  • Consumers
  • Agents and Mandataries

Section 3: Introduction

3.1 Business Model Overview

TransFi Canada, doing business as TransFi Canada, is an Ontario corporation with physical operations at 325 Front Street West 2nd floor, Toronto, ON M5V2Y1 offering money services within North American markets. TransFi Canada is a Money Service Business (MSB) with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) with the registration number M24519990 for the following Money Service designations:

  • Payment Service Provider
  • Virtual Currency Dealing
  • Money Transmission
  • Foreign Exchange Dealing

TransFi Canada offers the following services related to these designations:

  • Cross-border remittance transactions to business entities only.
  • Cross-border remittance transactions to individual and entity clients.
  • Cross-border remittance transactions for high net wealth individuals to business entities only.
  • Cross-border remittance transactions for high net wealth individuals to individual and entity clients.
  • Invoice payment services.
  • Payment process services enabling e-commerce Merchants to accept Canadian domestic banking rails such as Interac E-Transfer services.
  • Foreign Exchange services enabling clients to exchange various currencies at favorable rates.

TransFi Canada does not deal with cash, cheques, money orders, or other payment instruments not listed in the flow of funds below.

3.2 Simple Flow of Funds

Payout — CAD to fiat and Fiat to CAD

Typical Product Journey

  1. A Client seeking to use TransFi Canada's services signs up on TransFi Canada and after completion of KYC/KYB procedures and other compliance checks as well as after agreeing to the Business Services Agreement of TransFi Canada, gets onboarded.
  2. Client signs up a Merchant that they want to offer TransFi Canada's product. The Merchant gets onboarded post KYB and other compliance checks and after agreeing to TransFi Canada's Payments T&Cs.
  3. The Client/Merchant can then select the option to "Add Contact" (a new payee/counterparty). The Client/Merchant can select the contact type (business v individual), country/region, name, email ID and other details.
       
    a) For fiat payouts: The Client/Merchant can add the payee/counterparty's bank account details.

    b) For CAD payouts: The Client/Merchant can add the payee/counterparty's CAD bank account details.

  4. The Client/Merchant can then select the option to make a payment to the payee/counterparty. The Client/Merchant is asked to provide the payment purpose and to confirm the fiat currency/stablecoin in which they will send TransFi the money (Payin currency), against which the payout would be initiated.
  5. Once the Client/Merchant selects the payin currency and the payout currency and required payout amount, the next step depends on whether the payin is done in CAD or fiat:
       
    a) For CAD Payin — The Client/Merchant can choose which payment method they want to send CAD in like interac, domestic wire or billpay (any such CAD payments would be made to TransFi Canada account/sub-account with TransFi Canada LLPs that processes the fiat currency) and they will be displayed how much CAD they would need to send, in order to initiate payout of the required amount. TransFi Canada will display the price of the transaction on the TransFi Canada Pay dashboard. This price will be displayed for a maximum of 5 minutes during which the Client/Merchant is able to accept it. If accepted during the aforementioned period, the Client/Merchant is required to send the required amount of CAD using the method selected, after which, the order to send payout will be considered final and TransFi Canada will execute the order.

    b) For Fiat payin — The Client/Merchant can choose which fiat currency they would want to prefund their balance with (any such fiat payments would be made to TransFi Canada account/sub-account with TransFi Canada LLPs that processes the fiat currency) and they will be displayed how much fiat they would need to send, in order to initiate payout of the required amount. TransFi Canada will display the price of the transaction on the TransFi Canada Pay dashboard. This price will be displayed for a maximum of 5 minutes during which the Client/Merchant is able to accept it. If accepted during the aforementioned period, the Client/Merchant is required to send the required amount of fiat using the method selected, after which, the order to send payout will be considered final. TransFi Canada shows the updated account balance real-time in the Client/Merchant's account on the TransFi Canada Pay product.
  1. Upon receipt of such transfer by TransFi Canada, the corresponding payout to the designated counterparty shall be initiated automatically.
  2. TransFi Canada processes the transaction the same day either real time or within a few hours depending on terms signed up with the Client/Merchant.
  3. The transaction details are then shown to the Client/Merchant and processing done
       
    a) For fiat payouts: The transaction details shown are the status of transaction, amount of fiat the payee/counterparty will receive, and any fees the Client/Merchant will pay in connection with the transaction.

    b) For CAD payouts: The transaction details shown are the status of transaction, the amount of CAD the payee/counterparty will receive and any fees the Client/Merchant will pay in connection with the transaction.
  1. The transaction is subjected to transaction monitoring, fraud and other compliance checks.
  2. The Client/Merchant can monitor the status of all settled and unsettled payouts on the TransFi Canada Pay dashboard.
  3. Funds in local currency with local partners/bank are then, later on, converted to stablecoins offline, net of any payouts, by TransFi Canada's treasury and vice versa.

Section 4: Regulatory Overview

Money service businesses are subject to the regulations under Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated regulations. As a money service business, TransFi Canada is required to:

  • Identify clients according to MSB Guidelines;
  • Report eligible transactions;
  • Facilitate an independent review of the company's compliance program every two years at minimum;
  • Conduct AML/CTF staff training;
  • Implement a written compliance program; and
  • Implement a risk-based approach for service delivery.

TransFi Canada has implemented a compliance program to meet the requirements designated by FINTRAC.

At any time, TransFi Canada is subject to audits of this program by FINTRAC and other regulatory bodies.

4.1 Definitions

4.1.1 Money Laundering

Money laundering is the process of taking money obtained through illicit means and disguising the source to make it appear legitimate. Money laundering typically takes places in three stages:

  • Placement – initial deposit of proceeds of crime into the financial system, placement may or may not include the predicate offence from which illicit funds were derived.
  • Layering – conducting multiple transactions and/or transfers to convert illicit funds to another form and obfuscate the true source/original placement.
  • Integration – withdrawal or conversion of the funds to a "clean" form. Money laundering may, or may not be, accompanied by a predicate criminal offence.
4.1.2 Terrorist Financing

Terrorist financing is the process of moving funds in relation to terrorist activities. The source of funds may come from legitimate sources and does not always involve additional illicit activity or money laundering. Terrorist financing is defined as the collection, provision or receipt of money or other property for the purpose of it being used, or in the knowledge that it is intended to be used to:

  • To commit particularly serious crimes as referred to in section 74 of the PCMLTFA (every person or entity that knowingly contravenes any of the sections, subsections or the regulations listed, is guilty of an offence.)
  • By a person or persons forming an association that commit such crime as referred to in section 3 of the PCMLTFA or is guilty of attempt, preparation, conspiracy or complicity in such crime, or
  • For such travel as referred to in Criminal Responsibility for Public Provocation, Recruitment and Training concerning Terrorist Offences and other Particularly Serious Crimes.
4.1.3 Money Service Business

A person or entity with a presence in Canada engaged in providing at least one of the following services:

  • Dealing in virtual currencies,
  • Foreign exchange dealing;
  • Remitting funds or transmitting funds by any means or through any person, entity or electronic funds transfer network,
  • Issuing or redeeming money orders, traveler's cheques or other similar negotiable instruments except for cheques payable to a named person or entity, or
  • Crowd-funding platform services.

Money services businesses (MSBs) must fulfill specific obligations as required by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated Regulations, to help combat money laundering and terrorist activity financing in Canada and abroad.

4.1.4 FINTRAC

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) is Canada's Financial Intelligence Unit (FIU) agency that regulates Money Service Businesses and money service activities. FINTRAC issues requirements and guidance for the obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated acts.

4.1.5 Financial Action Task Force (FATF)

The Financial Action Task Force (FATF) is an international and intergovernmental organization that aims to develop and promote policies focused on combating money laundering, terrorist financing, and other related threats to the integrity of the international financial system. FATF sets standards and provides recommendations that member countries are expected to implement. The organization's work includes monitoring the progress of member countries implementing these standards, reviewing measures taken, and promoting effective legislative, regulatory, and operational measures. FATF's recommendations are widely recognized as the global standard for compliance best practices in relation to anti-money laundering and counter-terrorist financing.

4.1.6 Business Relationship

The relationship established between a Money Service Business and its Clients for financial transaction services. Money Service Business enter a business relationship under the following two conditions:

  • A Client's identity is verified a second time within a 5-year period. This equates to a Client transacting equal to or greater than CAD 1,000 on two separate occasions.
  • Engaging in a written service agreement with a Client for services related to financial transactions.

Business relationships carry verification and record keeping obligations to meet regulatory requirements and combat money laundering activity within Canada.

4.1.7 Tipping Off

In Canada, tipping off offenses under anti-money laundering regulations refer to the illegal act of informing a person or entity that they are the subject of a suspicious transaction report or an ongoing investigation by authorities. This is prohibited because it can compromise the investigation and allow the suspect to alter their behavior, destroy evidence, or flee. Violations of this rule can result in significant penalties, including fines and imprisonment.

4.1.8 24 Hour Rule

The 24-hour rule in Canadian regulations mandates that MSBs aggregate multiple transactions conducted by or on behalf of the same individual or entity within a 24-hour period when determining whether they meet the reporting thresholds for large cash transactions or electronic funds transfers. This means if the total amount of transactions reaches or exceeds $10,000 in a single day from the same individual or entity.

4.1.9 Ministerial Directives

Ministerial Directives are issued by the Minister of Finance of Canada to safeguard Canada's financial system. Measures are enacted to counter threats from foreign jurisdictions or entities that are identified to pose a significant risk for enabling money laundering and terrorist financing activities. The directives mandate reporting entities to implement countermeasures on transactions originating from or directed to designated foreign jurisdictions or entities.

4.1.10 Politically Exposed Persons & HIOs

FINTRAC divides PEPs into two categories: Foreign and Domestic.

Foreign Politically Exposed Person (Foreign PEP)

A foreign PEP is an individual who holds or has held one of the following offices or positions in or on behalf of a foreign state:

  • Head of state or head of government
  • Member of the executive council of government or member of a legislature
  • Deputy minister or equivalent rank
  • Ambassador, or attaché or counsellor of an ambassador
  • Military officer with a rank of general or above
  • President of a state-owned company or a state-owned bank
  • Head of a government agency
  • Judge of a supreme court, constitutional court, or other court of last resort
  • Leader or president of a political party represented in a legislature

Important Note: According to FINTRAC, once an individual is determined to be a foreign PEP, they remain a foreign PEP forever (even after death). All Foreign PEPs are automatically classified as High Risk

Domestic Politically Exposed Person (Domestic PEP)

A domestic PEP is a person who currently holds, or has held within the last 5 years, a specific office or position in or on behalf of the Canadian federal government, a provincial (or territorial) government, or a municipal government:

  • Governor General, lieutenant governor, or head of government
  • Member of the Senate or House of Commons, or member of the legislature of a province
  • Deputy minister or equivalent rank
  • Ambassador, or attaché or counsellor of an ambassador
  • Military officer with a rank of general or above
  • President of a corporation that is wholly owned directly by the Crown in right of Canada or a province
  • Head of a government agency
  • Judge of an appellate court in a province, the Federal Court of Appeal, or the Supreme Court of Canada
  • Leader or president of a political party represented in a legislature
  • Mayor, reeve, or other similar chief officer of a municipal or local government

Important Note: An individual ceases to be a domestic PEP 5 years after they have left office (or upon death).

Head of an International Organization (HIO)

A HIO is an individual who currently holds, or has held within the last 5 years, the office or position of head of an international organization. To qualify, the organization must be:

  • An international organization established by the governments of states (e.g., the United Nations, NATO, the World Bank).
  • An institution established by an international organization (e.g., the World Health Organization).

Important Note: Similar to domestic PEPs, a person ceases to be an HIO 5 years after they leave the position (or upon death).

Family Members and Close Associates

Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), reporting entities must also apply measures to the family members and close associates of PEPs and HIOs, as their proximity makes them vulnerable to being used for illicit financial activities.

Family Members are strictly defined as:

  • Spouse or common-law partner
  • Biological or adoptive children
  • Mother or father
  • Mother or father of the spouse or common-law partner (mother-in-law or father-in-law)
  • Children of the mother or father (siblings or half-siblings)

Close Associates are individuals who are reasonably known to be closely connected to the PEP or HIO. This can include:

  • Business partners or individuals who beneficially own/control a business with the PEP/HIO
  • Individuals in a romantic relationship with the PEP/HIO
  • Prominent members of the same political party, union, or board
  • Individuals closely carrying out charitable works with the PEP/HIO
  • Individuals jointly listed on policies or involved in financial transactions with the PEP/HIO
4.1.11 Proliferation Financing

Proliferation financing refers to the act of providing funds or financial services that contribute, in whole or in part, to the development, production, acquisition, possession, transfer, or deployment of chemical, biological, radiological, or nuclear (CBRN) weapons and their means of delivery, in contravention of international law.

Proliferation financing is distinct from terrorist financing in that the funds may originate from entirely legitimate sources and may not involve conventional money laundering activity. The complexity of proliferation financing schemes means that transactions may appear commercially legitimate on the surface, with common typologies including:

  • Front companies and intermediaries used to obscure the true end-use or end-user of goods or funds
  • Trade-based concealment through misrepresentation of the nature, quantity, or value of goods in international trade documentation
  • Correspondent and nested relationships exploited to move funds across jurisdictions without triggering scrutiny
  • Shell companies and complex ownership structures used to distance the ultimate beneficiary from the transaction

Regulatory Basis

As a Money Service Business registered with FINTRAC, TransFi Canada is subject to the United Nations Act and the Special Economic Measures Act, both of which give effect to United Nations Security Council Resolutions (UNSCRs) targeting proliferation financing, including Resolutions 1540, 1718, 1737, 1747, 1803, 1929, and 2231. Compliance with these resolutions and associated Canadian sanctions regulations is mandatory.

FINTRAC's guidance on money laundering and terrorist financing risk assessment requires reporting entities to assess their exposure to proliferation financing as part of their enterprise-wide risk assessment (EWRA). TransFi Canada incorporates proliferation financing risk into its EWRA and reviews this assessment at least annually.

TransFi Canada's Obligations

TransFi Canada must:

  • Screen all clients, beneficial owners, directors, and counterparties against UN Security Council consolidated sanctions lists and Canadian autonomous sanctions lists for proliferation-related designations, in addition to standard sanctions screening conducted through SumSub and Accend
  • Apply enhanced scrutiny to transactions involving dual-use goods, technology sectors, or jurisdictions associated with CBRN proliferation risk, including those subject to Ministerial Directives (currently DPRK, Iran, and Russia)
  • Treat any transaction where there are reasonable grounds to suspect a link to proliferation financing as a Suspicious Transaction Report (STR) obligation under the PCMLTFA, regardless of the transaction value
  • Maintain records of all proliferation financing-related screening, reviews, and escalations for a minimum of five years

Risk Indicators

The following indicators may suggest exposure to proliferation financing risk and must be escalated to the Compliance Officer:

  • Clients or counterparties operating in, or transacting with, jurisdictions subject to UN or Canadian proliferation-related sanctions
  • Transactions involving technology companies, logistics providers, or trading entities in high-risk jurisdictions without a clear commercial rationale
  • Complex or opaque ownership structures where the ultimate beneficial owner cannot be confirmed and the client operates in a sector with dual-use potential
  • Payments to or from entities that appear on, or are associated with entities on, the UN 1267/1989/2253 ISIL and Al-Qaida Sanctions List or any UNSCR-related consolidated list
  • Requests to structure transactions in a manner that obscures the origin, destination, or purpose of funds in the context of international trade

Where proliferation financing is suspected, the CAMLO must be notified immediately. An STR must be filed with FINTRAC and, where the activity may involve UN-listed entities or sanctioned property, a Listed Person or Entity Property Report must also be submitted to FINTRAC, CSIS, and the RCMP.

4.2 Canadian Money Service Business Requirements

4.2.1 FINTRAC MSB Registration

Money Service Business (MSB)s must register with Financial Transactions and Reports Analysis Centre of Canada (FINTRAC), Canada's Financial Intelligence Unit (FIU) and maintain an active registration while offering money services including:

  • Remain active while offering money services;
  • List the appropriate money service designations;
  • Be current with director, officer, ownership and associated financial institutions;
  • Respond to clarification requests in the prescribed form and manner;
  • Renew the registration before the expiry date; and
  • Notify FINTRAC within 30 days if money service activities cease to offer.
4.2.2 Revenue Québec MSB Registration

Revenue Québec is the regulatory body maintaining the province's MSBs in licensing and compliance. The Quebec MSB Act defines MSBs more broadly than the Canadian federal definition and includes provincial licensing and registration requirements. TransFi Canada does not operate in Québec or service Québec customers and is not required to register as an MSB with Revenue Quebec.

4.2.3 FINTRAC Travel Rule

FINTRAC has implemented the travel rule requirements for virtual currency transfers that require documentation and retention of specific information associated with these transfer activities.

4.2.3.1 VC Travel Rule

Travel rule information records must be kept by TransFi Canada when sending VC transfers and take reasonable measures to ensure Travel Rule information is included when receiving virtual currency. Travel rule information must be retained and included in applicable FINTRAC reports:

  • Name, address and account/reference number of the person or entity that requested the transfer (originator information); and
  • Name, address and account/reference (if any) of the beneficiary.

Travel rule information is obtained through onboarding, due diligence and compliance monitoring practices.

Note:If TransFi Canada is unable to obtain required Travel Rule information despite "reasonable measures," the transaction must be reviewed by the Compliance Officer to determine if it should be rejected, held, or reported as suspicious.

4.2.4 Sanctions Requirements

Sanctions are measures or actions taken against a target to influence behavior, policy, or actions. These measures typically have three components:

  1. an economic action;
  2. the identification of a target (such as a country, an individual, an entity or a specific function); and
  3. the intended influence on the target's actions.

Sanctions can restrict trade, financial transactions, diplomatic relations, and movement. They may be implemented and enforced either specifically or generally. The Government of Canada imposes economic sanctions under three federal statutes and acts related to trade measures and restrictions:

  • The Criminal Code
  • United Nations Act
  • Justice for Victims of Corrupt Foreign Officials Act
  • Special Economic Measures Act
  • OFAC
  • HM treasury list
  • The State Department Foreign Terrorist Organizations List and Non-Proliferation List
  • US DOJ (FBI, DEA, US Marshals, and others)
  • Freezing Assets of Corrupt Foreign Officials Act

Canadian sanction laws prohibit Money Service Businesses engaging with designated persons, jurisdictions, and specific sectors. Compliance with sanctions law is mandatory and requires screening, monitoring, and reporting to meet obligations. Obligations for Canadian individuals and businesses remain under subsection 83.1(1) Criminal Code (R.S.C., 1985, c. C-46). Canadian sanctions laws impose strict liability for direct and indirect dealings with sanctioned persons or organizations. These laws also require TransFi Canada to comply with asset-freezing obligations to prevent sanctioned parties from accessing financial or material resources. TransFi Canada is dedicated to adhering to all applicable Canadian laws and regulations concerning sanctions evasion. Sanctions evasion occurs when individuals or entities attempt to circumvent restrictions imposed under Canadian laws. Common methods include structuring transactions through intermediaries or high-risk jurisdictions or obscuring the identity of sanctioned parties. Any suspected evasion activities must be promptly reported to the Compliance Officer for investigation and reporting to FINTRAC through suspicious transaction reports (STRs) and relevant authorities, such as the RCMP and CSIS.

4.2.5 Ministerial Directives

Ministerial Directives and transaction restrictions are issued by the Minister of Finance that mandate reporting entities to implement countermeasures for transactions originating from, or destined for, specific foreign jurisdictions or entities that are considered to present high risks for facilitating money laundering and terrorist financing. These measures allow the Minister of Finance to take steps to protect Canada's financial system and support MSBs in combating money laundering and terrorist financing through money service activities. Each directive outlines countermeasures to either enhance or expand upon current obligations that exist under existing obligations for Money Service Businesses. The directives specify the effective date and will remain active until they are officially revoked, suspended, or amended. Current Ministerial Directives issued by Canada as of July 31, 2024 include:

  • February 24, 2024: Russia
  • July 25, 2020: Islamic Republic of Iran (updated February 24, 2024)
  • December 9, 2017: Democratic People's Republic of Korea (DPRK)

Compliance with Ministerial Directives and transaction restrictions is mandatory. FINTRAC monitors and assesses compliance with AML directives under the PCMLTFA and may examine records or inquire into the business activities of entities covered under the Act. Compliance activities, such as on-site or desk-based examinations, may now include reviewing adherence to Ministerial Directives. TransFi Canada does not allow individuals, entities or transactions linked to countries subject to Ministerial Directives under any circumstances.

4.3 Non-Compliance

Compliance with FINTRAC regulations is mandatory. Failure to adhere to regulations and legislation may lead to severe criminal or administrative penalties. Monetary penalties for non-compliance are related to the following activities:

  • Failure to report a suspicious transaction;
  • Reporting information that demonstrated non-compliant activity, entities, individuals, relationships, jurisdictions, or flow-of-funds; and
  • Reporting information that is non-compliant or inaccurate which enhances the efficiency of FINTRAC's analysis.

Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), criminal penalties criterion are defined as:

  • General offences, including the failure to register as a money services business, to verify client's identity, and to keep prescribed records;
  • Reporting offences for suspicious transactions;
  • Reporting offences for electronic funds transfers, large cash transactions, large virtual currency transactions, and casino disbursements; and
  • Money services business registration information offences for providing false or misleading statements or information to FINTRAC.

FINTRAC Registration Maintenance

TransFi Canada shall ensure its registration with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) remains accurate and current. The Compliance Officer is mandated to update FINTRAC registration information within 30 days of any change to the entity's status, ownership, or operations.

Section 5: TransFi Canada's Compliance Program

TransFi Canada is committed to mitigating money laundering and illicit activity associated with provided services, follows the measures required by the PCMLTFA, governed by an established written compliance program implementing a risk-based approach to prevent money laundering, and will provide reasonable assistance to law enforcement and regulatory bodies in the event of an audit or law enforcement request.

The following measures have been implemented into this compliance program to meet regulatory requirements in Canada:

  • Appointment of a dedicated, knowledgeable Compliance Officer responsible for overseeing AML/ATF program to ensure compliance with all applicable laws and regulations.
  • Maintaining a risk-based approach management program that assesses inherent risk, mitigation efforts, and the resulting residual risk factors as they relate to service delivery.
  • Conducting annual AML/ATF staff training pertaining to Canadian regulations that is documented with written testing components to assess company-wide understanding of regulatory obligations.
  • Implementation of a written compliance program outlining company policies to meet reporting, record keeping, and customer identification obligations that is approved by senior management.
  • Scheduled independent reviews of the compliance program to assess the efficacy and relevance of the compliance regime that are conducted every two years.
  • The first independent effectiveness review commencement date is 26/01/2026 scheduled to take place two years after obtaining registration approval from FINTRAC on 26/01/2024.
  • The Board of Directors holds ultimate accountability for the AML/CTF program. Their responsibilities include:
    • Approval of the AML/CTF Policy and Risk Assessment.
    • Appointment of a qualified Compliance Officer.
    • Ensuring adequate resources are allocated to financial crime prevention.
    • Reviewing the results of biennial effectiveness reviews and ensuring timely remediation of gaps.

5.1 Appointment of a Compliance Officer

A Compliance Officer is responsible for implementing and managing day-to-day compliance and anti-money laundering activities of money service business operations. The Compliance Officer reports directly to the Board of Directors and is independent from all other departments/divisions.

Duties and responsibilities of the Compliance Officer include:

  • Develop and maintain written compliance policies and procedures.
  • Develop and maintain an enterprise-wide risk assessment (EWRA) to outline inherent risk and identify mitigation measures to support residual risk management and guide day to day operations.
  • Review and evaluate external partnerships with vendors, acquirers, and other parties to ensure that they align with overall risk appetite.
  • Monitoring regulatory changes and adjusting or modifying risk management policies to ensure the compliance program remains compliant.
  • Facilitate AML staff training to be conducted once per year at minimum.
  • Coordinating independent effectiveness reviews of the compliance program every two years at minimum.
  • Act as the point of contact for law enforcement, regulatory bodies, and other external parties.
  • Reporting semi-annually to the CEO and Board of Directors on compliance activities and the status of the compliance regime.

5.2 Risk-Based Approach

Implementing a risk-based approach can contribute to preventing money laundering before it occurs. An RBA (Risk-Based Approach) is a tool utilized to assess risk associated with service delivery and to applying control measure to mitigate these risks where possible:

  • Inherent risk exists before the implementation of controls or mitigation measures.
  • Residual risk remains after controls or mitigation measures have been implemented to reduce the likelihood of Money Laundering, Terrorist Financing or an illicit activity event occurring.

An Enterprise-Wide Risk Assessment (EWRA) must be maintained at all times to guide a risk-based approach and evaluate money laundering and terrorist financing risks related to services, clients, geographic regions, operations, and regulatory risks. The assessment will be reviewed and updated at least annually to reflect new and emerging risks, legislative changes, and updates made to the business model and services. Implementation of new technologies, products, and services must first undergo assessment for money laundering and terrorist financing risks before it is implemented in operations and be maintained in the documented risk assessment to ensure proper risk assessment and mitigation.

Risk management measures are assessed to strike a balance between TransFi Canada's ability to operate efficiently and meet FINTRAC's risk assessment guidelines. Results of overall risk assessments are used to ensure the quality of adapted risk-based measures, including:

  • Customer due diligence procedures and processes;
  • Ongoing follow-up;
  • Transaction monitoring;
  • Internal checks;
  • Resource allocation and to guide staff AML training.

TransFi Canada presents a low overall residual risk and does not tolerate residual high-risk ratings in any category. Mitigation measures have been implemented to reduce inherent high risks intrinsically associated with services by outlining proactive compliance protocols tailored to business specific risk factors.

Client Risk-Rating Methodology

Clients are assigned a risk rating (Low, Medium, or High) based on a weighted scoring matrix. This methodology evaluates:

  • Geography: Residency in high-risk jurisdictions.
  • Products: High-velocity or anonymous-leaning services.
  • Delivery Channel: Non-face-to-face vs. in-person.
  • Entity Type: Complexity of ownership structure.
  • Behavioral Patterns: Deviations from expected activity.

Beneficial Ownership and Discrepancy Reporting

  • Effective October 1, 2025, entities regulated by FINTRAC must report any material discrepancies found between beneficial ownership information obtained and the individuals with significant control (ISC) listed in Corporations Canada's database. This reporting obligation applies when a reporting entity determines that an active corporation governed by the Canada Business Corporations Act (CBCA) presents a high risk of involvement in money laundering or terrorist activity financing.
  • All reporting entities, excluding title insurers, are required to take reasonable steps to verify the accuracy of beneficial ownership information both at initial acquisition and during ongoing monitoring of business relationships. Should a reporting entity assess a CBCA corporation as high risk for money laundering or terrorist activity financing, it must consult Corporations Canada's database and compare its collected beneficial ownership data with ISC records to identify any material discrepancies.
  • For CBCA corporations not deemed high risk, reporting entities may voluntarily submit a Beneficial Ownership Discrepancy Report to Corporations Canada if a material discrepancy is identified.
  • TransFi must report any material discrepancy to Corporations Canada within 30 days of identification. Reporting is not required if the discrepancy is resolved within 30 days of being identified.

Termination of Business Relationships

The "Business Relationship" and all associated ongoing/enhanced monitoring conclude only when:

  • The account/service agreement is formally closed.
  • TransFi ceases to provide any MSB-specific services to the client.
  • The final transactional "cool-down" period (as defined in the Risk Assessment) has elapsed.

An independent Enterprise-Wide Risk Assessment (EWRA) document is maintained and is utilized to guide this AML Policy. The most current and detailed EWRA can be found in TransFi Canada Business Wide Risk Assessment.

5.3 Customer Due Diligence

Verifying client identity is required through FINTRAC's acceptable methods of verifying used to identity a person or entity. Client information and documentation is used to confirm existence and associated risk. Customer Due Diligence applies to all clients regardless of application method, if a client cannot be identified, they will not be approved for services.

The Company is a B2B2C business and shall provide Services to Business. The end users can be both natural persons and legal entities. The Company provides services primarily to the business who are Customers-Clients, Merchants, and end users. Both the Merchants and the End Users receive Services and both these subjects are considered as Customers of the Company, who shall be identified accordingly. TransFi's current product suite is described below. All of these products are available as both a solution and as a single Application Programming Interface ("API") and provide a dashboard or other solution for monitoring transactions and orders:

  • Payins: Enabling our Clients/their Merchants to collect payments in fiat currency (e.g. the US Dollar or Euro) or stablecoins from their counterparties (both businesses or individuals) by sending a payment link and settling in stablecoins or fiat, as desired, with ease from anywhere across the world.
  • Payouts: Enabling our Clients/their Merchants to pay their employees, vendors, freelancers, and trade partners globally in fiat or stablecoins across the world by exchanging crypto-assets for fiat (stablecoin-to-fiat) or exchanging fiat for crypto-assets (fiat-to-stablecoin) or crypto-assets for crypto-assets (crypto-to-stablecoin).

Ramp:Enabling our Clients to offer the exchange of fiat to crypto-assets (fiat-to-crypto "onramp") and the exchange of crypto-assets to fiat (crypto-to-fiat "offramp") to their Merchants and/or End Users.

KYC — Individuals

We have tiered based KYC structure, namely,

  • Basic KYC
  • Standard KYC
  • Enhanced KYC
Basic KYC Standard KYC Enhanced KYC
First name, last name, DOB/email ID, country of citizenship, address, crypto wallet address (crypto), phone (optional) First name, last name, email ID, country of citizenship, address, ID number, phone (optional) Proof of source of funds, Proof of address
ID document ID document Proof of source of funds, Proof of address

Product-Specific Controls: The KYC requirements outlined above represent the minimum standard. Depending on the product or service being used and the associated risk, the Company may request additional information, documentation as deemed necessary.

Individual Verification

The Customer (natural person) identification and ID document validity verification shall be performed following these steps:

5.4 Registration

The Customer shall enter First name, Last name, Date of Birth, Email, the country of citizenship on the web page dedicated to onboarding;

5.5 Identification

The Company applies remote identification – via real-time selfie and ID document photo (video) transmission. Namely: In case of a photo transmission:

A. The Customer shall take a photo of his / her ID document. 

Only the following ID documents can be accepted for Customer due diligence purposes. The Company shall accept only those ID documents that are valid and only if there are no circumstances showing possible forgery of the ID document:

  • Passports,
  • National ID cards,
  • Any other acceptable ID allowed by regulation

The collected ID document shall contain the following information about the Customer:

  • Name(s);
  • Surname(s);
  • ID number
  • Photo;
  • Citizenship

Individuals are required to provide the following information to aid in identity verification, client due diligence, reporting and record keeping requirements:

  • Full name;
  • Date of birth;
  • Email;
  • Phone number;
  • Address; and
  • Occupation.

TransFi Canada utilizes FINTRAC's Government Issued Photo Identification Method to verify individual applicants, ultimate beneficial owners (UBO), and authorized signatories of entity applicants. Under this method, the provided government issued ID documents must meet the following criteria:

  • Be genuine and have the characteristics of an original and credible document that is unaltered;
  • Not be invalid due to a name change or similar occurrence;
  • Must be up to date and not past expiry at the time of verification;
  • Be issued by a federal or national government;
  • List the individuals full name;
  • Have a unique identification number;
  • Include a photo of the individual; and
  • Match the name and likeness of the individual applicant.

Applicants are onboarded through non-face to face interactions and are not physically present during authentication; therefore, additional measures must be taken during verification. The following measures are acceptable for non-face-to-face ID verification:

  • Liveness selfie verification.

Individuals under the age of 18 years are not onboarded for individual services under any circumstances. Additionally, individuals over 70 years are not onboarded for any services under any circumstances.

5.5.1 Entity Verification

The Confirmation of Existence method is utilized to verify all entities under current operational practices. Entities include Corporations, Partnerships. In all cases the existence of an entity must be confirmed to be authentic, valid, and current. Certain entity structures carry increased risk for money laundering and terrorist activity and require additional measures to verify such as Charities and Trusts. Document requirements to support confirmation of existence include:

  • Being genuine and have the characteristics of an original and credible document that is unaltered;
  • Not be invalid due to a name change or similar occurrence;
  • Be issued by or registered with a federal, national, or state registry;
  • List the entity registered name;
  • Contain the entity's address; and
  • List the names of the Directors for the entity (if applicable).

The following documents for business entity verification are considered acceptable:

  • Certificate of Incorporation (COI);
  • Articles of Association/ Company Bylaws;
  • Self certified Shareholder Register;
  • Proof of address
  • Self certified Director's Register

Charities, Non-Government Organizations and Trusts present a heightened risk for Money Laundering, Terrorist Financing, and illicit activity due to the intrinsic structure. Entities under this category will automatically be categorized as high risk and undergo Enhanced Due Diligence with approval from TransFi Canada's Compliance Officer required before being approved to transact. When publicly available, the existence of an entity is confirmed and referenced against the provided documentation via the issuing corporate registry. Publicly available information is used to record and document additional information regarding the entity.

TransFi Canada does not onboard:

  • Known beneficiaries of Corruption or Illegal Activities;
  • Shell companies/shell banks;
  • Unregulated casinos or gambling companies;
  • Incomplete or failed KYB (Know your business);
  • Unlicensed money transmitters / payments / financial services companies; and
  • Customers with bearer shares in the ownership structure.
  • Marijuana/cannabis;
  • Guns, Arms and ammunition;
  • Precious metals;
  • Cash Intensive Businesses;
  • Adult content or Pornography;
5.5.1.1 Beneficial Ownership Requirements

Beneficial Ownership information must collect for all business entities. Beneficial ownership varies based on a business entity structure and can include:

  • All individuals who own or control, directly or indirectly, 20% or more of the business entity.

The following information must be collected regarding beneficial owners and directors of a business entity:

  • Full legal name (no initials, short forms or abbreviations);
  • Full home address (post office boxes, business offices and general delivery addresses are not acceptable for this purpose);
  • The role and/or ownership stake in the organization; and
  • UBO's KYC
5.5.2 Indirect Beneficial Ownership

Indirect beneficial ownership is when the ultimate beneficial ownership stake is through an intermediary entity or through a chain of ownership entities, rather than holding it directly through individual shareholders. All shareholder business entities will be verified under the entity verification requirements outlined in this policy until Ultimate Beneficial Individual Owners of 20% or more are identified and verified pursuant to this policy.

5.5.3 Third Party Determination

A third party refers to an individual or entity that directs another person or entity to perform a transaction or activity on their behalf. In this context, the third party is the instructing party and is understood to be acting "on behalf of" someone else. TransFi Canada must take reasonable measures to determine whether a third party is involved in a transaction. Indicators that may suggest third-party involvement include:

  • An unusual or inconsistent source of funds relative to the client's profile
  • The client demonstrates limited knowledge of the transaction details
  • Instructions for the transaction are being provided by someone other than the client

If a third party is identified, the following information must be documented in the client's profile:

  • If the third party is an individual: their full name, address, date of birth, and occupation
  • If the third party is a corporation or entity: their name, address, nature of business, registration number, and jurisdiction of issue
  • The nature of the relationship between the third party and the client

Third parties are not permitted to conduct transactions through TransFi Canada's services under any circumstances. Where third-party involvement is identified or suspected, the matter must be escalated to the Compliance Officer for review and a determination made as to whether a Suspicious Transaction Report is required.

5.5.4 Risk-Based Due Diligence for Licensed and High-Profile Customers

In the onboarding of a customer that meets the following criteria, the organization shall apply a risk-based approach to due diligence:

  • Licensed Status: The customer, if applicable, must hold a valid and active license from a recognized regulatory authority.
  • Established Market Presence: The customer must be a well-known entity in the market, with a proven track record of compliance and stability.
  • Risk-Based Due Diligence Steps:
       
          Open-Source Research: Conduct comprehensive searches of public internet sources to verify the customer reputation and operational history.
  • Public and Government Databases: Cross-check the customer credentials, including license validity, through official public records and government databases.
  • Verification of Licensing: Ensure that all licenses are current and in good standing.

5.6 Sanction and Applicant Screening

Applicants are screened against numerous sanctions and screening watch lists through third party compliance tools SumSub and Accend which utilizes over 1700 global databases to screen for exposures related to sanctions, PEPs, HIOs and watch lists. Individuals, Business Entities, Ultimate Beneficial Owners, Directors and other authorized signatories are screened prior to transacting and set to continuous monitoring where new listings publications are referenced against internal client lists where new alerts and associations trigger an email notification to the Chief Compliance Officer for manual review. Sanctioned individuals and entities will not be permitted to transaction through offered services under any circumstances. Sanctions associations identified during onboarding or through client monitoring procedures must result in submission of a Suspicious Transaction report to FINTRAC, at minimum.

If sanctioned funds are believed to be in TransFi Canada's possession at any time, the Chief Compliance Officer, Senior Management and General Counsel must be contacted immediately as funds seizures obligations may apply. TransFi Canada does not onboard sanctioned individuals or business entities, under any circumstances. PEPs and HIOs are only onboarded on a case by case basis, after Enhanced due Diligence and with the approval of the Compliance Officer. TransFi Canada does not have any PEP or HIO clients currently.

5.7 Client Risk Rating and Classification

Applicant and Client Risk Assessments are utilized to support compliance monitoring, suspicious transaction monitoring and investigations, and the overall understanding of the active Business Relationships to aid in day-to-day operations and risk mitigation processes.

Risk factors that must be considered while assessing Individuals must include the following considerations and minimum:

  • Services Provided;
  • Service delivery channel;
  • Payment methods;
  • Demographic;
  • Occupation; and
  • Jurisdiction.

Risk factors that must be considered while assessing Business Entities must include the following considerations and minimum:

  • Services provided;
  • Service delivery channel;
  • Business structure;
  • Nature of business; and
  • Jurisdiction.

Clients are divided into three categories during risk assessment evaluation and are assigned to low, medium, and high categories each with specific parameters surrounding onboarding requirements and compliance monitoring procedures related to transaction monitoring and Client maintenance schedules and practices.

Low Risk:Profile presents an overall low risk for money laundering for all identified risk factors with no presence of high-risk or eliminating factors governed by this policy. Low risk Clients are subject to standard transaction monitoring procedures, and a client maintenance reassessment every 36 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.

Medium Risk:Profile presents an overall medium risk for money laundering for all identified risk factors with presence of increased risk factors such as vulnerable demographics or nature of business with no presence of high-risk or eliminating factors governed by this policy. Medium risk Clients are subject to standard transaction monitoring procedures, and a client maintenance reassessment every 24 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.

High Risk:High risk classifications are subject to Enhanced Due Diligence, increased monitoring, and schedule reassessment to monitor and mitigate risk associated with this classification category. High risk classifications may be triggered by a single factor, such as a presence or association with a high-risk jurisdiction or entities, adverse media, or business entity structure. Multiple, high-risk factors can also accumulate to lead to high-risk rating. High risk Clients are subject to increased transaction monitoring procedures, and a client maintenance reassessment every 12 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.

Reputed Customers:Profile presents an established, verifiable, and favorable standing that warrants recognition as a low-risk, trusted relationship. These are typically well-known, publicly listed, regulated, or otherwise reputable entities (e.g., publicly traded companies, regulated financial institutions, government bodies, or long-standing clients with a demonstrated history of compliant activity and transparent ownership structures) with no presence of high-risk, adverse media, or eliminating factors governed by this policy. Reputed Customers benefit from a verified track record, strong public reputation, and transparent beneficial ownership. Such Clients are subject to standard transaction monitoring procedures, and a client maintenance reassessment every 36 months to update client information, assess for newly presented risks, and ensure verification documents are kept up to date.

Applicants and clients deemed to present unacceptable risk are declined or offboarded for services due to the presence of factors that are outside of the TransFi Canada's risk appetite. All assessments of this nature must be escalated to the Chief Compliance Officer for review and determination whether an Attempted Suspicious Transaction Report (ASTR) or a Suspicious Transaction Report (STR) will be filed with FINTRAC.

Customer Identification Triggers

Identification requirements are triggered by specific Money Services Business (MSB) activities, including:

  • Issuing or redeeming money orders/traveller's checks of $3,000 or more.(not applicable on Transfi Canada)
  • Foreign exchange transactions of $3,000 or more.
  • The opening of a service agreement or business relationship.
  • Any instance of suspicious activity, regardless of dollar value.

Address Verification Standards

TransFi Canada must obtain the full mailing address for all customers.

Note:The use of a Post Office (PO) box or "general delivery" address is strictly prohibited as a primary residence/place of business address.

Corporate and Entity Verification

For all corporate clients, TransFi shall ensure that the name, address, and directors' names collected during onboarding are fully consistent with the official government documents used to verify the corporation's existence (e.g., Articles of Incorporation).

Non-Profit Organizations (NPO) and Charities

During onboarding, staff must confirm if an entity is an NPO.

  • Documentation: While the question may be asked verbally, the answer must be recorded in the client file.
  • Registered Charities: If the entity is an NPO, staff must determine if it is a registered charity in Canada. If so, the Charitable Registration Number must be collected and documented.

Beneficial Ownership Unavailability

TransFi Canada may, under exceptional circumstances, onboard customers whose beneficial ownership cannot be confirmed provided that:

  1. The customer is automatically classified as High Risk.
  2. All "reasonable efforts" to confirm beneficial ownership are documented.
  3. TransFi takes reasonable steps to verify the identity of the Chief Executive Officer (CEO) or the person fulfilling that equivalent role.
  4. It will be reviewed by the Compliance Officer.

Trust Organizations

When identifying trusts, TransFi must collect the full name (no initials or abbreviations), role (full description), and full physical address (no PO boxes) for:

  • All Trustees.
  • All known Beneficiaries.
  • Non-Compliance Rule: Any trust failing to provide this complete information must be classified as High Risk.

Customer Identification Triggers (FINTRAC)

Applicable MSB triggers per FINTRAC's guidance, including:

  • virtual currency transactions of $10,000 or more (as a separate identification trigger, distinct from the LVCTR threshold),
  • Foreign exchange transactions of $3,000 or more, and
  • any suspicious activity regardless of value.
  • When a client transacts at $1,000 or more on a second occasion within five years, that independently triggers identification (confirming a business relationship)

Section 6: Enhanced Due Diligence (EDD)

An Enhanced Due Diligence assessment aims to confirm the legitimacy and further verify an individual, business entity, or source of funds. TransFi Canada's Compliance may apply enhanced due diligence efforts at any stage of a client relationship and for a number of reasons including but not limited to:

  • Individuals of a vulnerable or high-risk demographic.
  • Associations with banned or high-risk industries or clients base for business entities.
  • Associations with banned or high-risk jurisdictions.
  • Transaction patterns or volumes that are outside of established client profiles.
  • Data inconsistencies or missing information.
  • Additional due diligence required to mitigate various red flags at the description of the Compliance Analyst conducting the assessment.

The following customer types are subjected to Enhanced due diligence:

  • Custodial crypto / digital assets services
  • Other crypto / digital assets services that are non-custodial
  • Money services / Payments / other financial services
  • Licensed Gambling services
  • Any customer with a politically exposed beneficial owner

6.1 Enhanced Measures

6.1.1 Elevated Verification

Individual or Business Entity verification includes obtaining more information or documents to confirm the legitimacy of a business entity or individual. This can include obtaining a second Government issued Photo ID, a business plan, certificate of good standing, or licensing and AML Policy, if applicable.

6.1.2 Source of Funds/Wealth

Obtaining documents from the applicant/Client regarding the source of funds or wealth from their client in the form of the most recent three months of unredacted bank statements or audited corporate financials. Acceptable sources of funds:

  • Salary /Business income;
  • Pension releases;
  • Personal savings from legal sources;
  • Share sales and dividends;
  • Property sales;
  • Inheritances and gifts allowed by law;
  • Tax return receipts and other incomes from government;
6.1.3 Online Source Intelligence

Using public databases and search engines to confirm or obtain new information. Confirmation of entity registration or license verification with registration authorities where possible. Searching for social media accounts, highlighting search phrases to include "Scam", "Fraud", "Theft", "Criminal" "Court" and "Warning". Searching addresses and locations in google maps street view to assess whether the location matched the information for the applicant/Client.

6.1.4 PEP specific EDD measures

Source of wealth must be established within 30 days of the business relationship being formed. Source of funds and source of wealth must be obtained for any virtual currency transaction of $100,000 or more. Senior management must review all VC transactions of $100,000 or more involving a PEP before they are carried out or within a reasonable period after.

Section 7: Reporting Requirements

Compliance with reporting obligations is mandatory. Qualified transactions to FINTRAC and other agencies as required. Each report has specific conditions for which types of transactions must be reported and a specific timeline within which a report must be submitted to FINTRAC. FINTRAC reports are submitted electronically through the FINTRAC Web Reporting System (FWR) or FINTRAC Reporting Ingest API. Listed Person or Entity Property Reports are submitted online or offline and through Forms available for download online. Additionally an STR must be filled with FINTRAC through conventional methods. Reports must also be submitted to the Canadian Security Intelligence Service (CSIS) by fax at 613-369-2303 and the Royal Canadian Mounted Police (RCMP) by fax at 613-825-7030. Additionally an STR must be filled with FINTRAC through conventional methods. Tipping off a client associated with a report may be perceived as interfering with a possible investigation. This restriction applies regardless of whether the investigation is active. To avoid inadvertently tipping off a client, all requests for information to support reporting submissions must follow procedures outlined in this policy or be approved by the Chief Compliance Officer. Volume based reports subject to FINTRAC's 24-hour rule are confined to a static 24 hour period that matches any calendar day from 0:00 to 23:59. Multiple transactions from a single Client outside of this timeframe will not be considered for volume based reporting under FINTRAC's 24 hour rule.

7.1 MSB Reporting Requirements Overview

Report Type Information Timeline
Large Cash Transaction Report (LCTR) Upon receipt of Cash (paper or coin money) from a single client in an amount greater than or equivalent to $10,000 CAD in a single transaction or multiple transactions within a 24 hour period. 15 calendar days
Large Virtual Currency Transactions Report (LVCTR) Upon receipt of virtual currency from a single client or commission payment in an amount greater than or equivalent to $10,000 CAD in a single transaction or multiple transactions within a static 24 hour period. 5 working days
Suspicious Transaction Report (STR) In the event that there is reasonable grounds to suspect suspicion related to money laundering has occurred for completed transactions.

Automatic High Risk: Any client for whom an STR is filed will be re-classified as High Risk.

Subsequent Reporting: Once an STR is filed, all subsequent suspicious transactions for that client must continue to be reported.

Correction Timeline: Any requested changes to a filed STR must be submitted within 20 days of the request.

Non-Reported Unusual Activity: Transactions identified as "unusual" but not escalated to an STR must be documented with a clear rationale explaining why they were deemed not suspicious.

Note: An STR remains reportable even when an LVCTR has been filed for the same transaction
As soon as practicable, no longer than 30 days.
Attempted Suspicious Transaction Report (ASTR) In the event that there is reasonable grounds to suspect suspicion related to money laundering for without the occurrence of a transaction. As soon as practicable, no longer than 30 days.
Listed Person or Entity Property Report In the event the company identifies funds or property that is affiliated with terrorist activity (either an individual or an organization) a Listed Person or Entity Property Report report must be filed immediately with FINTRAC and additionally with CSIS and RCMP. Immediately.

Electronic Funds Transfer Reports (EFTRs)EFTRs are not applicable to TransFi Canada services and will not be filed as TransFi Canada does not accept Cash.

Large Cash Transaction Reports (LCTRs)Large Cash Transaction Reports are not applicable to TransFi Canada services and will not be filed as TransFi Canada does not accept Cash.

Large Virtual Currency Transaction Reports (LVCTRs)As a Money Service Business Dealing in Virtual Currency, TransFi Canada is required to file Large Virtual Currency Transaction Reports (LVCTRs) when Virtual Currency is received from a client or in the form of a commission payment equal to or in excess of $10,000 CAD in a single transaction or multiple transactions within a single calendar day. TransFi Canada must use the Canadian dollar exchange rate established at the time of the virtual currency transaction to determine whether the reporting threshold is met. Due to the fluctuating value of virtual currencies, this rate will vary based on a per trade basis.

Suspicious Transactions & Attempted Suspicious TransactionsThe threshold to report a suspicious transaction or attempted suspicious transaction is reasonable grounds to suspect that a money laundering or terrorist financing offence might have occurred. Reasonable grounds to suspect does not require confirmation of details to prove that an offence has occurred, however, the suspicion needs to be reasonable and unbiased and have considered; facts, context and risk indicators supporting suspicion. Suspicious reports must be filed when measures and investigation have been conducted with outcomes that reach the reasonable grounds to suspect threshold at minimum. Suspicious Transaction Reports must be treated as a priority as they are complex and must include clear, simple and concise language outlining grounds for suspicion including with the facts, context, and indicators that allowed you to reach reasonable grounds for suspicion.

Listed Person or Entity Property ReportsListed Person or Entity Property Reports are submitted offline and exclusively through fax or paper mail with Paper Report Forms available for download online. Additionally an STR must be filled with FINTRAC through conventional methods. Reports must also be submitted to the Canadian Security Intelligence Service (CSIS) by fax at 613-369-2303 and the Royal Canadian Mounted Police (RCMP) by fax at 613-825-7030. Additionally an STR must be filled with FINTRAC through conventional methods. The Chief Compliance officer must escalate activity related to Listed Person or Entity Property to senior management and General Counsel immediately.

Section 8: Identifying Suspicious Activity & Investigations

Identifying suspicious transactions begins with screening and identifying any transactions that appear unusual based on risk flags and detection measures, assessing the facts and context surrounding these transactions and linking any indicators of money laundering or terrorist financing to your evaluation. Examples of red flags for suspicion include but are not limited to:

  • Transaction volumes and frequency outside of the established client profile.
  • Client opens multiple accounts.
  • Customers that frequently change their credentials, including email addresses, IP addresses, or financial information.
  • Structuring transactions in small amounts and under the record-keeping or reporting thresholds.
  • Making multiple high-value transactions that are not in line with the expected activity for that client.
  • Frequent transfers occurring in a certain period of time to the same virtual asset account either by more than one person, from the same location, or concerning large amounts.
  • Fraud or risk alert triggers through automated transaction review software.

Grounds for suspicion must be outlined in an investigation report outlining how the facts, context, and indicators resulted in the conclusion:

  • "Fact" refers to an objective detail or event such as the red flag or trigger that led to the investigation, a fact cannot be an opinion.
  • "Context" provides clarity on the circumstances surrounding a transaction, including details regarding the client profile, client financial background and the investigation steps taken to determine suspicion.

Transactions alone may not seem suspicious, however, context can outline the conditions that support suspicious activity. Established Client profiles, including assigned risk ratings, must be assessed and leveraged during the investigation to identify indicators specific to the Client. The Chief Compliance Officer must review and approve all suspicious activity investigations prior to filing an STR with FINTRAC to ensure the reasonable grounds to suspect threshold has been met and adequate facts, context and indicators are included in the investigation.

8.1 Investigation Framework

The standard investigation process includes the following measures:

Transaction Reviews:Analysis of client's last 90 days transactional data assessing volume, frequency, beneficiary information and account data.

Sanctions Screening and Review:Screening business entities, directors, UBOs, and authorized users against sanctions lists and comprehensive review of related compliance requirements are conducted at the time of onboarding as well as on an ongoing basis

OSINT Investigation:Open-source intelligence (OSINT) gathering to gather relevant information including examination of social media profiles and associated websites for additional context.

Enhanced due diligence:Obtaining further information from the client to support verification through a Request for Information (RFI) process adhering to the terms outlined in this policy and only with the approval of the Chief Compliance Officer. Requests must be reasonable and avoid any instances of "tipping off".

8.1.1 Investigation Outcomes
  • No Further Action: Red flags and suspicions dismissed, no further issues or concerns are identified.
  • Flagged for Further Monitoring and Due Diligence: Requires increased monitoring, additional due diligence, and a new client risk assessment.
  • Client Relationship Terminated: Decision to cease business relations with the client.
  • Suspicious Transaction Report (STR) Filed: Suspicious activities suspected, reporting to regulatory authorities is required.

Section 9: Compliance Monitoring

TransFi Canada conducts ongoing compliance monitoring to evaluate Business Relationships and risks through Client maintenance reviews, and through transaction monitoring to identify and report any suspicious activity. The primary focus and scope of compliance monitoring is determined by the risks identified in the enterprise wide risk assessment, company AML policies, and established procedures.

9.1 Client Maintenance Reviews

Client Maintenance reviews are a key function of the Client Management framework. Review frequency is governed by established client risk profiles or triggered by various factors including but not limited to:

  • The presence of unusual transactional activity.
  • Client communications of a suspicious nature.
  • Changes in an established Client profile such as occupation, nature of business, or company structure.
  • An escalation from an external partner, regulator or law enforcement agency.
  • Identification of new risks related to Client profiles or services offered.

Client profiles must be maintained, valid, accurate, and complete throughout the Business Relationship. This involves sourcing updated Client documents and information surrounding the intended use of services.

9.2 Transaction Monitoring

Transaction Monitoring is focused on all transactions on behalf of Clients, commissions, or referral payment transactions to support money service offerings. Transaction reviews facilitate reporting obligations and identify transactions that meet the parameters for volume based reporting. These reviews also assist with suspicious activity monitoring under general guideline identifiers that include:

  • Transactions with no apparent economic or business purpose.
  • Rapid movement of funds between accounts.
  • Transactions involving high-risk individuals or entities.
  • Transactions conducted with repetitive patterns.
  • Transactions that are inconsistent with the Client's established profile.

High Risk Clients are subject to increased transaction monitoring which include a higher sensitivity threshold with increased considerations on identified red flags. TransFi Canada's IT systems have pre-programmed notifications and triggers that notify the compliance team of unusual activity related to Fiat transactions. Reviews of high volume/high velocity transfers are conducted bi-weekly to support client monitoring and reporting initiatives. TransFi Canada's transaction reviews are conducted manually by the compliance to identify reportable transactions and to review to identify money laundering red-flags and transactions that deviate from what is expected with established client profiles.

Know Your Transaction - KYT

TransFi has a robust inhouse Transaction Monitoring (TM) program as a rules engine designed to identify and report unusual or suspicious transaction activity. These rules applies to both fiat transactions and crypto transactions, leveraging a mix of automated and manual processes to ensure comprehensive monitoring and compliance.

Fiat TM Program

TransFi employs real-time and post-transaction monitoring to analyze fiat transactions, focusing on the following aspects: Transactions that exceed predefined thresholds are flagged for manual review and subjected to due diligence. Transactions originating from or destined for prohibited jurisdictions are automatically rejected and reported in Suspicious Transaction Reports (STRs). We have TM rules which indicates suspicious patterns. Below are the example of such rules:

  • More than 3 transaction within 5 minutes
  • More than 5 transactions attempted in one hour
  • More than 10 transactions attempted in 24 hours
  • Transaction value is 5x or more than the average of the last 10 transaction
  • Transactions deviating from expected behavior or declared activity are scrutinized, with appropriate action taken as necessary.

Crypto TM Program

For cryptocurrency transactions, we have implemented additional measures tailored to the unique risks of virtual assets: Wallets are analyzed based on the source of funds and sanctions screening through our blockchain monitoring partner Chainalysis. Wallets flagged as high-risk result in rejection of transactions. Transactions involving virtual currencies are monitored for compliance with international sanctions. Suspicious activity is flagged for further investigation. Similar to fiat, unusual patterns in crypto transactions trigger additional review to assess potential risks.

Section 10: Record Keeping

To facilitate information requests, and to be aligned with compliance best practices, records must be maintained in an organized and accessible format and be retained for a minimum of 5 years after the date the record was created. Access to records maintained on company servers is granted on an as-needed basis and is accessible only through two factor authentication. In the event of a FINTRAC request for information, the request must be fulfilled within 30 calendar days. Documents to meet record keeping requirements with the information supported in this policy include, but are not limited to:

  • Copies of every report submitted to FINTRAC.
  • Records relating to transactions over $1000.00 CAD or equivalent conducted by TransFi Canada.
  • Records related to Government Issued Photo ID verification.
  • Business relationship records outlining services and client profiles and risk rating used to anticipate transactions and activity used to support suspicion identification.
  • Records related to compliance onboarding and monitoring policies, procedures, and methodology.
  • Entity verification and Beneficial Ownership records.
  • Records of any verifications, transactions
  • Sanctions and PEP screening records.
  • Record requirements related to measures implemented by Ministerial Directives.
  • Copies of Independent reviews, FINTRAC Exams, and Law Enforcement Requests.

Access to Record Keeping must be protected, granted on a need to know basis, and accessed through company databases with Two Factor Authentication enabled at all times.

Section 11: AML Staff Training Plan

Employees, directors, agents or mandataries, or other persons authorized to act on the company's behalf must complete mandatory written and ongoing AML compliance training. A documented training program for ongoing AML compliance training must be maintained with a defined methodology on training delivery. Training must include:

  • Money Laundering and Terrorist Financing definitions.
  • Background information on money laundering and terrorist financing such as definitions and activity models.
  • Company vulnerabilities to Money Laundering and Terrorist Financing.
  • Responsibilities under PCMLTFA and associated regulations.
  • Compliance policies and procedures aligned with PCMLTFA.
  • Reporting requirements and transaction limits.
  • Identification and reporting of suspicious activities.
  • Handling suspicious activities or transactions.
  • Roles and responsibilities of employees in detecting and deterring illicit activities.

TransFi Canada's Chief Compliance Officer will maintain the annual training plan, track the completion of all training and implement additional training sessions if compliance issues arise. This includes documenting the steps taken to ensure appropriate training is conducted and is relevant to employee roles on an ongoing basis. This includes:

  • Training recipients
       
          Front line staff or staff involved in client transaction activities.
  • Staff involved in handling of cash, funds or virtual currency in any way.
  • Staff responsible for implementing or overseeing the compliance program.
  • Outline of the topics covered in the training program with sources to the training material addressing these topics.
  • May include self-directed learning, information sessions, face-to-face meetings, conferences, and on the job training where instruction is provided.
  • Tailored to the size, structure and money laundering and terrorist financing risk of the company.

Relevant new hires must receive training within 60 days of beginning their position. Anyone that is on a leave of absence that causes them to miss regularly scheduled training will complete training within 30 days of their return to work. A record of all training materials must be maintained at all times and include the training source materials, the date of the training, a list of attendees, and the topics covered to support training management and demonstrate that the training is being conducted on an ongoing basis.

Section 12: Two Year Effectiveness Review

A two-year effectiveness review supports an independent evaluation of the company's written and operational compliance program with higher-risk business areas receiving focused attention during the review. This to test the effectiveness of the program, identify any instances of non-compliance, and identify areas for improvement based on regulation or compliance best practices. An independent review supports preparation for a FINTRAC Exam, determines if operational practices reflect the TransFi Canada's written compliance program, and examines the effectiveness of TransFi Canada's enterprise-wide risk assessment and mitigation measures.

Independent effectiveness reviews must begin no later than two years from the start of any previous reviews or initial MSB registration. TransFi Canada's independent effectiveness reviews must be completed by a compliance professional with knowledge and experience in the PCMLTFA and Canadian regulations. The review must include at minimum:

  • Start date, completion date, and audit period utilized during the review.
  • Interviews with compliance staff to ensure adequate knowledge of the established compliance program and applicable regulations.
  • Interviews with compliance staff.
  • Customer Identification Testing.
  • Transaction and Reporting Testing.
  • AML Policy and procedure assessment.
  • TransFi Canada's EWRA assessment.

The Chief Compliance Officer must review and report on the external review to management within 30 days of completion, detail any deficiencies, and any remediations required in a remediation plan including set timelines for implementation. The Chief Compliance officer must determine whether a Voluntary Self-Declaration of Non-Compliance (VSDONC) should be submitted to FINTRAC based on the findings of the review.

Section 13: Voluntary Self-Declaration of Non-Compliance (VSDONC)

FINTRAC promotes a regulatory approach that is based on the promotion of compliance and not to penalize reporting entities with fines and penalties. Unreported transactions may hold value for FINTRAC and law enforcement, and must be reported even when missed, late, or uncovered during a scheduled or independent effectiveness review.

Submitting a VSDONC, an entity officially acknowledges compliance obligation short-comings and lists implemented measures to regain compliance. FINTRAC will work with a reporting entity to guide and correct instances of non-compliance without proposing administrative penalties, if:

  • The voluntarily declared non-compliance issues are not a repeated instance of a previous, voluntarily disclosed issue.
  • The VSDONC submission is after a reporting entity has been notified of a FINTRAC Examination.

Voluntary self-declarations of non-compliance must be sent to: VSDONC.ADVNC@fintrac-canafe.gc.ca and include:

  • TransFi Canada's MSB details and contact details for submitting the report.
  • The number of reports impacted, type, and the time period during which the issues occurred, as well as the reason why the reports were not submitted, were late, or incorrect.
  • The period of time during which the instances of non-compliance unrelated to reporting occurred and the reason for occurrence.
  • A detailed plan to resolve the issues and submit all outstanding reports, including measures and timelines for corrective action.

Personal information regarding instances of non-compliance must be protected and not included in VSDONC reports or submission email. If private information is pertinent to the investigation, FINTRAC will provide secure information sources.

Section 14: Law Enforcement Requests

Supporting law enforcement is a key factor in mitigating money laundering, terrorist financing, fraud, and illegal activity where possible. Validly served requests for Client information and assistance must be handled with priority. Requests from individual users or requests from law enforcement without a formal legal document detailing the requested information will not be accommodated.

Law Enforcement requests must follow a structured process including multiple stakeholders to establish validity, formulate a timely and detailed response, and report and document the request for internal and external management.

14.1 Notification

The Chief Compliance officer remains the primary point of contact for all Law Enforcement requests. Upon receipt of any requests, the Chief Compliance Officer must notify Senior Management and General Counsel with all provided documentation. Access to this information and details therein must remain confidential and on a need to know basis.

14.2 Review

Chief Compliance officer and General Counsel must review the Law Enforcement Request to ensure that it originates from a real law enforcement agency and that it is a formal legal request, such as a subpoena or search warrant.

14.3 Investigation

The Chief Compliance Officer must conduct an investigation on the Client(s) and information with priority pursuant to the established investigation protocols directed by this policy. Additional information that must be included in these investigations include:

  • The date the request was received;
  • The type of formal legal document received;
  • The name, department and information from which the request was received;
  • Specifics of the Client details and/or transactional information requested;
  • Timelines which the requested information must be delivered; and
  • Any required data or documents to support the requested deliverables.

Copies of investigations must be provided to Senior Management and General Counsel for review prior to any formal response. General Counsel must verify that the details in the investigation are required by the formal requests, and that the obligations outlined in the request are met. General Counsel must provide any investigation amendments or deviations from Law Enforcement Request Policy in written format to the Chief Compliance Officer and Senior Management for review and implementation.

14.4 Response

All external response communications must be approved by TransFi Canada's General Counsel. Law Enforcement responses must include a cover letter outlining the requested information, parameters of the request, a summary of the investigation, and list the records to be provided. Responses must be sent through official company channels, be factual, and delivered before the due date outlined in the formal law enforcement request document.

14.5 Actions

The Chief Compliance Officer must submit a Suspicious Activity Report (SAR) to FINTRAC under suspicion of "Reasonable Grounds to Suspect.". Accounts posing any identified risk of illegal activity, money laundering, reputational harm, or other risks that may cause harm to the company are reviewed for closure. TransFi Canada will follow law enforcement recommendations for account closures. All records of law enforcement requests, investigations, responses and internal and external communications surrounding the request will be maintained for a minimum of 5 years after the submission of the response.

Section 15: Country Acceptance Policy

This Country Acceptance Policy aims to provide a comprehensive delineation of acceptable jurisdictions for services. This framework ensures clarity and adherence to regulatory standards across operations and promotes a robust and compliant approach to jurisdictional considerations for Client Intake and Client Monitoring procedures. For the purposes of this policy, "location" is defined broadly to ensure a risk-based approach is applied during the Client boarding process. It encompasses any world area, country, region, state, or similar where a significant aspect of business operations is situated. Such aspects may include office locations, the residence of a majority owner, fulfillment or shipping warehouses, bank accounts, suppliers, home addresses, countries of identity document issuance, IP addresses, email domains, and other relevant factors. The policy outlines various types of location risks that are considered critical:

  • Tax Evasion: Jurisdictions that maintain outdated or poor legislation and banking secrecy laws that facilitate tax crimes and the illicit flight of capital.
  • Money Laundering: Jurisdictions that fail to comply with international standards for financial reporting and transparency. Money laundering risks often intersect with predicate offenses such as drug trafficking, human trafficking, and war plunder.
  • Terrorist Financing: Payments associated with terrorist financing may or may not involve money laundering. These transactions typically involve the movement of funds intended to directly or indirectly support terrorist groups.
  • Source Countries: Certain countries or jurisdictions serve as source countries for narcotics or trafficked humans. Due to the prevalence of predicate offenses in these locations, they pose heightened risks for money laundering and are treated accordingly.
  • Countries or Territories in Conflict: Regions experiencing armed conflict are particularly susceptible to predicate offenses such as human trafficking, money laundering, corruption, and others.

15.1 Banned Countries

The following countries subject to current sanctions imposed by Canada, that are outside of TransFi Canada's risk appetite include:

  • Cuba
  • Iran
  • North Korea (DPRK)
  • Syria
  • Crimea, Donetsk & Luhansk (Ukraine regions)
  • Russia
  • Belarus
  • Venezuela
  • Myanmar (Burma)
  • Nicaragua
  • Iraq
  • Lebanon
  • Libya
  • Somalia
  • Sudan
  • South Sudan
  • Yemen
  • Mali
  • Central African Republic
  • Democratic Republic of the Congo
  • Afghanistan
  • Haiti
  • Zimbabwe
  • Tunisia
  • Eritrea
  • Guinea-Bissau

15.2 Restricted Countries

The following countries and jurisdictions require enhanced due diligence prior to boarding: Algeria, Bulgaria, Burkina Faso, China, Cameroon, Comoros, Ivory Coast, Kenya, Lao People's Democratic Republic, Monaco, Mozambique, Namibia, Nepal, Sri Lanka, South Africa, Tanzania, Trinidad and Tobago, Uganda, and Vietnam,

15.3 Onboarding Exceptions

Exceptions apply solely to Clients domiciled in restricted locations, contingent on the implementation of enhanced due diligence and robust fraud/risk controls. Under no circumstances will Clients located in banned countries be considered for onboarding. The review process for restricted countries must undergo rigorous review verification that goods/services are fulfilled.

  • Detailed reporting of beneficial ownership.
  • Increased entity verification.
  • Confirmation that owners are not politically exposed persons (PEPs) or listed on watch lists.
  • Accurate reporting of business income to tax authorities.

Exceptions are evaluated individually and must be approved by TransFi Canada's Chief Compliance Officer. A risk-based approach is used to determine location risk, considering that clients may have multiple locations, such as corporate addresses, physical addresses, bank account locations, fulfillment warehouses, and home addresses. The highest risk location among these is used to score the Client's overall location risk. For Clients located in restricted countries and operating within high-risk industries or offering high-risk products, service will be denied

Section 16: Prohibited Industries

Adult content, airlines; collection agencies; marijuana dispensaries; CBD oil and related products; cash advances or cash gifting; charities; check cashing; cruises; debt consolidation; drug paraphernalia; firearms; fulfillment centers; government grant assistance; mail order brides; medical benefits or discounts; mortgage modification or reduction; multi-level marketing schemes; payday lending; replica or counterfeit goods; precious metal dealers; guns, arms, and ammunition; bearer share ownership companies; unlicensed MSBs, unlicensed gambling, shell banks, and timeshares. TransFi Canada does not onboard:

  • Known beneficiaries of Corruption or Illegal Activities;
  • Shell companies/shell banks;
  • Unregulated casinos or gambling companies;
  • Incomplete or failed KYB (Know your business);
  • Unlicensed money transmitters / payments / financial services companies; and
  • Customers with bearer shares in the ownership structure.
  • Marijuana/cannabis;
  • Guns, Arms and ammunition;
  • Precious metals;
  • Cash Intensive Businesses;
  • Adult content or Pornography;

Clients with multiple products or services may be approved with enhanced due diligence and only with the Chief Compliance Officer's approval.

16.1 Restricted Industries

Restricted industries are only onboarded when accompanied by enhanced due diligence. In some cases, additional controls, such as transaction or volume restrictions with heightened transaction monitoring, may be implemented as necessary and determined by the Chief Compliance Officer. Clients in restricted categories often pose higher risks due to extended fulfillment times, advance payments, or frequent customer complaints and disputes. This includes clients trading in products subject to frequent or pending regulation changes by national health, safety, or regulatory bodies. The following business types are subject to increased scrutiny; educational programs, modeling agencies, money services businesses, pharmaceuticals, gaming, betting, and wagers, gemstones, vape supplies, pawnbrokers, ticket brokers, travel agents and clubs, used car dealerships, and vitamins and herbal remedies.

16.2 Onboarding Exceptions

Exceptions to client onboarding apply only to those trading in restricted industries and only after the completion of due diligence and fraud/risk controls. Clients involved in prohibited products will not be considered for onboarding under any circumstances. Exceptions are evaluated on a case-by-case basis and upon the written approval of the Chief Compliance Officer.

Section 17: Policy Review Schedule

TransFi Canada must update this AML ATF Policy upon any material change in services or regulatory requirements affecting business operations. In addition, a scheduled annual review must be conducted to measure policy adherence in day-to-day operations.

17.1 Next Scheduled Update

July 1st, 2027

Authorized Signatory

Raj Kamal