AML Policy

OEX Canada Limited — Anti-Money Laundering & Anti-Terrorist Financing Policy

OEX CANADA LIMITED

ANTI-MONEY LAUNDERING (AML) & ANTI-TERRORIST FINANCING (ATF) POLICY

1. PURPOSE

1.1 Purpose of this Policy

This Anti-Money Laundering and Anti-Terrorist Financing Policy (the “Policy”) establishes the framework adopted by OEX CANADA LIMITED (the “Company”) to identify, assess, mitigate, monitor and manage money laundering, terrorist activity financing, sanctions-evasion and related financial crime risks arising from its business activities.

The Company is incorporated under the Canada Business Corporations Act under corporation number 1425293-3, with its registered office at 20 Teagarden Court, Whitby, Ontario L1R 2H9, Canada. The Company is registered with the Financial Transactions and Reports Analysis Centre of Canada (“FINTRAC”) as a money services business under MSB Registration Number M22760780.

The Company provides virtual currency-related services, including virtual currency exchange, virtual currency transfer and hosted-wallet services, and may hold or control virtual currency on behalf of customers. These activities may expose the Company to financial crime risks arising from customers, beneficial owners, counterparties, third-party payers, wallet addresses, blockchain transactions, jurisdictions, products, technologies and delivery channels.

The purpose of this Policy is to establish a documented and effective compliance framework proportionate to the nature, size and complexity of the Company’s business and to ensure that applicable risks and obligations are managed consistently.

The Company shall not knowingly permit its business, systems, accounts, wallets, products, personnel or third-party relationships to be used to facilitate money laundering, terrorist activity financing, sanctions evasion or other unlawful conduct. Where the Company cannot obtain sufficient information to understand or adequately mitigate the risks associated with a customer, transaction, beneficial owner, source of funds, third party, counterparty or wallet, it shall decline, restrict, suspend or terminate the relevant activity or business relationship, as appropriate.

1.2 Risk-Based Approach

The Company adopts a risk-based approach under which the nature and extent of the controls applied to a customer, transaction, service, wallet, product, jurisdiction or business relationship shall be proportionate to the risks identified.

The risk-based approach does not permit the Company to disregard or reduce any mandatory legal requirement. Greater attention, scrutiny and resources shall be applied to higher-risk circumstances, while proportionate controls shall be applied to lower-risk circumstances.

The Company’s approach shall be informed by its enterprise-wide risk assessment, customer risk-rating methodology, ongoing and transaction monitoring, blockchain analytics, sanctions screening, relevant regulatory guidance, typologies and information obtained throughout the customer relationship.

No single risk factor shall automatically determine whether a customer or transaction is acceptable or suspicious. The Company shall assess the overall facts, context, behaviour and relevant indicators and shall document the rationale for material decisions.

1.3 Application and Accountability

Compliance with this Policy is mandatory. It applies to all directors, officers, employees, contractors, consultants, agents, mandataries, authorised representatives and relevant outsourced service providers involved in the Company’s activities.

Every person subject to this Policy is responsible for understanding and complying with the requirements relevant to their role. No person may disregard or override a compliance requirement for commercial, operational or customer-service reasons.

Any uncertainty concerning the interpretation or application of this Policy must be referred to the Compliance Officer. Actual or suspected breaches must be escalated promptly. Failure to comply may result in disciplinary action, termination of appointment or engagement, regulatory notification or other legal action, as appropriate.

2. REGULATORY AND LEGAL FRAMEWORK

2.1 Applicable Canadian Requirements

The Company shall conduct its activities in accordance with the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, the regulations made under that Act and all other applicable Canadian legal and regulatory requirements.

The Company shall also comply with applicable Canadian sanctions, terrorist-property and Ministerial Directive requirements, including any applicable obligation to restrict or prohibit transactions, freeze or disclose property, conduct screening or submit reports to FINTRAC or another competent authority.

The Compliance Officer shall monitor material legal and regulatory developments and shall ensure that this Policy, the supporting procedures and relevant controls are updated where required.

2.2 FINTRAC Registration

The Company is registered with FINTRAC as a money services business under MSB Registration Number M22760780. Its registered activities include dealing in virtual currency.

The Company shall conduct only those money services activities that it is legally permitted and appropriately registered to provide.

The Compliance Officer shall ensure that the Company’s FINTRAC registration information remains accurate, complete and current and that any required changes relating to its ownership, directors, senior management, activities, locations, agents or other registration particulars are submitted within the applicable timeframe.

The Company shall retain appropriate records relating to its registration, renewal and amendments.

2.3 FINTRAC Guidance and International Standards

The Company shall have regard to current FINTRAC guidance, operational alerts, special bulletins, sector-specific indicators, examination findings and other relevant regulatory publications when designing and reviewing its compliance programme.

The Company may also consider relevant international standards and guidance, including publications issued by the Financial Action Task Force and other competent authorities, where these assist in identifying emerging risks or strengthening controls.

Regulatory guidance and international standards do not replace applicable Canadian law. Where there is any inconsistency, the applicable Canadian legal requirement shall prevail.

The Company may apply additional controls required by a banking partner, payment service provider, custodian, counterparty or relevant jurisdiction, provided that those controls do not conflict with Canadian law.

2.4 Conflicts and Interpretation

Where this Policy is inconsistent with applicable law or regulation, the law or regulation shall prevail.

Where there is uncertainty regarding the interpretation of a requirement, the matter shall be referred to the Compliance Officer. The Compliance Officer may obtain external legal or professional advice where appropriate.

No person may interpret an ambiguity in a manner intended to avoid a reporting, identification, monitoring or record-keeping obligation.

3. SCOPE AND BUSINESS MODEL

3.1 Scope of Application

This Policy applies to all activities undertaken by or on behalf of the Company that give rise, or may give rise, to obligations under applicable Canadian AML/ATF requirements.

It applies to the Company’s virtual-currency exchange, transfer and related payment or settlement activities, including customer onboarding, deposits, withdrawals, conversions and completed or attempted transactions.

Where the Company provides hosted-wallet, custody or other services involving the holding or control of customer virtual currency or wallet credentials, those activities shall also fall within the scope of this Policy.

The Policy applies to customers in Canada and other permitted jurisdictions and to completed, attempted, rejected, suspended, cancelled or otherwise uncompleted transactions.

Where an agent, contractor or service provider performs an activity on behalf of the Company, the Company remains responsible for ensuring that the activity is conducted in accordance with applicable law and this Policy.

3.2 Virtual Currency Services

The Company provides, or may provide where legally and operationally supported, virtual-currency exchange and transfer services, including conversion between virtual currencies and transactions involving fiat currency and virtual currency.

Where the Company provides hosted-wallet or custody-related services, it may hold, safeguard, administer or control virtual currency or wallet credentials on behalf of customers.

The Company shall maintain customer due diligence, transaction-monitoring, wallet-screening, blockchain-analytics and other controls proportionate to the nature and risk of the services provided.

The Company shall not offer a service, asset, network or functionality that it cannot adequately identify, screen, monitor and control.

3.3 Cash

The Company does not accept physical cash.

Any attempted physical-cash payment shall be rejected and escalated to Compliance where the circumstances are unusual, suspicious or inconsistent with the customer’s expected activity.

3.4 Geographic Scope

The Company may provide services in Canada and other jurisdictions where legally and operationally permissible.

The Company shall maintain a documented jurisdiction-risk framework classifying countries and territories as approved, restricted or prohibited.

The classification shall reflect applicable Canadian sanctions and Ministerial Directives, relevant international standards, financial crime risk, local regulatory conditions and the Company’s ability to conduct effective due diligence and monitoring.

Customers or transactions connected with restricted jurisdictions shall be subject to enhanced measures and approval requirements.

The Company shall not establish or maintain relationships involving prohibited jurisdictions or activities.

4. GOVERNANCE AND COMPLIANCE OFFICER

4.1 Governance and Responsibility

Senior management is responsible for ensuring that the Company maintains a reasonably designed, risk-based and effective AML/ATF compliance programme proportionate to its business and risk profile.

Business personnel are responsible for implementing controls relevant to their activities. The Compliance Officer is responsible for implementing and overseeing the compliance programme, and its effectiveness shall be independently reviewed in accordance with this Policy.

Compliance with AML/ATF requirements is a core business responsibility and shall not be overridden by commercial, operational or customer-service considerations.

Senior Officer Oversight

The Company’s written compliance policies and procedures, including this Policy and any material amendments, shall be approved by a Senior Officer in accordance with applicable requirements.

The Senior Officer shall be provided with sufficient information to exercise appropriate oversight, including material compliance issues, significant control deficiencies, remediation and the results of effectiveness reviews.

The Company shall retain evidence of the approval, effective date, applicable version and scheduled review date of this Policy.

Management Information and Escalation

The Compliance Officer shall provide senior management with periodic information appropriate to the Company’s size, activities and risk profile.

Material breaches, regulatory concerns, reporting failures, sanctions issues and significant control deficiencies shall be escalated promptly and shall not be deferred until the next periodic report.

4.4 Compliance Officer Appointment

The Company shall appoint a Compliance Officer responsible for implementing and overseeing its AML/ATF compliance programme.

The Compliance Officer shall possess sufficient knowledge of the Company’s business, customers, services, systems and financial crime risks and an appropriate understanding of applicable Canadian AML/ATF and sanctions requirements.

The Compliance Officer shall have sufficient authority, independence, access to information and resources to perform the role effectively and shall have direct access to the Senior Officer and senior management.

4.5 Independence and Conflict

The Compliance Officer shall perform the role with sufficient independence from commercial and operational pressures.

Any actual or potential conflict arising from another role performed by the Compliance Officer shall be identified and appropriately managed. The role shall not be structured in a manner that compromises objective challenge, escalation or reporting decisions.

5. AML/ATF COMPLIANCE PROGRAMME

The Company shall maintain an AML/ATF compliance programme comprising:

(a) the appointment of a Compliance Officer;

(b) written policies and procedures;

(c) a documented risk assessment;

(d) an ongoing written training programme; and

(e) a documented plan for reviewing the effectiveness of the programme at least once every two years.

The programme shall remain appropriate to the Company’s business activities, size and risk profile and shall be updated following material legal, regulatory or business changes.

6. ENTERPRISE-WIDE MONEY LAUNDERING AND TERRORIST FINANCING RISK ASSESSMENT

6.1 Purpose of the Risk Assessment

The Company shall conduct and maintain a documented enterprise-wide assessment of the money laundering, terrorist activity financing, sanctions evasion and related financial crime risks arising from its business activities.

The purpose of the assessment is to enable the Company to understand where and how its services may be exposed to financial crime, to determine whether its existing controls are adequate and to apply resources and enhanced measures proportionately to the risks identified.

The risk assessment shall reflect the Company’s actual business model, including its provision of virtual currency exchange, virtual currency transfer and hosted wallet services, its custody or control of customer virtual currency, its acceptance of approved third-party payments and its provision of services to customers in Canada and other permitted jurisdictions.

The risk assessment shall not be treated as a static or generic document. It shall be sufficiently detailed to demonstrate how the Company has identified material risks, how those risks have been assessed and what controls have been implemented to mitigate them.

6.2 Risk Assessment Methodology

The Company shall use a documented methodology to assess inherent risk, the effectiveness of mitigating controls and residual risk.

Inherent risk is the level of financial crime risk that would arise in the absence of controls. Control effectiveness is the extent to which the Company’s systems, procedures, personnel and oversight reduce the identified risk. Residual risk is the level of risk remaining after the relevant controls have been applied.

The methodology shall provide a clear and consistent basis for assigning risk ratings and shall document the reasons for material judgements. Risk ratings shall not be determined solely by automated scoring or by reference to a single factor. The Company shall consider the overall interaction between relevant risks and controls.

Where reliable information is limited or where uncertainty remains, the Company shall adopt a cautious approach and may apply a higher risk rating until sufficient information has been obtained.

6.3 Customer Risk

The Company shall assess the risks associated with the types of customers it serves and the nature of their activities.

Relevant factors may include whether the customer is an individual or entity, the customer’s occupation or business, the nature and complexity of the customer’s ownership and control structure, the customer’s regulatory status, the purpose of the relationship, the expected source and use of funds, the anticipated volume and frequency of transactions and the jurisdictions connected with the customer.

The Company shall also consider whether the customer’s profile presents an increased risk because of political exposure, adverse information, sanctions exposure, financial crime allegations, nominee arrangements, unexplained intermediaries, cash-intensive activities, high-risk industries or difficulty in verifying identity, ownership or source of funds.

Customers whose identity, ownership, purpose or expected activity cannot be adequately understood shall not be treated as lower risk merely because no adverse information has been identified.

6.4 Product and Service Risk

The Company shall assess the financial crime risks associated with each product and service it provides.

Virtual currency exchange, virtual currency transfer, hosted wallet and custody services may present elevated risks because virtual currency can be transferred rapidly, across borders and through multiple wallet addresses, and may be used to obscure the source, destination or beneficial ownership of assets.

The assessment shall consider whether a product permits rapid deposits and withdrawals, conversion between assets, transfers to external wallets, interaction with decentralised protocols, exposure to anonymity-enhancing technologies, automated transactions, cross-chain transfers or other features that may increase financial crime risk.

The Company shall also consider the extent to which the relevant virtual currency, network or service can be effectively monitored through transaction-monitoring and blockchain-analytics controls.

Where a product or service cannot be adequately monitored, the Company shall not offer it unless suitable alternative controls are implemented and approved.

6.5 Delivery Channel and Technology Risk

The Company shall assess the risks arising from the methods by which customers access and use its services.

Non-face-to-face onboarding, remote account access, mobile or online services, application programming interfaces, automated transfers and reliance on electronic identity-verification methods may increase the risk of impersonation, synthetic identity fraud, account takeover, mule activity or misuse by unauthorised third parties.

The assessment shall consider the adequacy of device, network, login, authentication, geolocation and behavioural controls, where relevant. It shall also consider the risks arising from new technologies, outsourced systems, cloud infrastructure and dependencies on external data or service providers.

The use of technology does not remove the need for human judgement. Automated systems shall be subject to appropriate governance, calibration, testing, exception handling and oversight.

6.6 Geographic Risk

The Company shall assess the risks associated with each jurisdiction connected with its customers, counterparties, transactions, payment routes, wallet activity and business relationships.

The assessment shall consider applicable sanctions, ministerial directives, FATF publications, the strength of local anti-money laundering controls, regulatory transparency, corruption levels, terrorist financing concerns, virtual asset regulation, law-enforcement effectiveness and the Company’s ability to obtain reliable customer and transaction information.

A jurisdiction shall not be treated as acceptable solely because it is not prohibited by law. Jurisdictions presenting elevated but manageable risk may be classified as restricted and made subject to enhanced due diligence, approval, limits or monitoring.

Where the Company cannot obtain sufficient information or cannot effectively monitor the risks associated with a jurisdiction, the jurisdiction may be prohibited notwithstanding the absence of a specific legal prohibition.

6.7 Transaction Risk

The Company shall assess the risks associated with the size, volume, frequency, velocity, complexity and pattern of transactions conducted through its services.

Relevant factors may include rapid movement of funds, repeated deposits and withdrawals, transfers inconsistent with the customer’s expected activity, transactions involving multiple wallets or third parties, activity structured below reporting or identification thresholds, circular transfers, pass-through activity, transactions with no apparent economic purpose and transactions involving high-risk services or jurisdictions.

For virtual currency activity, the Company shall consider wallet exposure, blockchain transaction history, links to illicit services, sanctions exposure, use of mixers or tumblers, ransomware indicators, scam or fraud exposure, darknet market activity, stolen assets, chain hopping and other methods used to obscure transaction flows.

The assessment shall also take account of attempted, rejected, cancelled or failed transactions, as these may provide relevant information regarding customer intention or financial crime risk.

6.8 Third-Party and Outsourcing Risk

The Company shall assess the financial crime and compliance risks arising from its relationships with agents, payment service providers, wallet providers, custodians, virtual asset service providers, identity-verification providers, blockchain-analytics providers, technology providers and other outsourced service providers.

The assessment shall consider the provider’s regulatory status, ownership, reputation, jurisdiction, control environment, technical capability, information security, auditability, service continuity and ability to provide records promptly.

The Company shall not assume that the use of a regulated or reputable provider removes the need for its own risk assessment and oversight. The Company remains responsible for compliance with its statutory obligations even where an external provider performs operational tasks on its behalf.

6.9 Review and Approval

The enterprise-wide risk assessment shall be reviewed formally at least annually and whenever a material change occurs.

A review shall also be undertaken before the Company introduces a new product, virtual currency, blockchain network, service, customer segment, jurisdiction, delivery channel or material third-party arrangement.

The assessment shall be approved in accordance with the Company’s governance framework. Material findings, control gaps and residual risks shall be reported to the Senior Officer and shall be addressed through documented remediation or formally accepted in accordance with the Company’s risk appetite.

FINTRAC requires reporting entities to assess and document the risks of money laundering and terrorist activity financing arising in the course of their activities and to apply enhanced measures to high-risk situations.

7. CUSTOMER ACCEPTANCE AND RISK CLASSIFICATION

7.1 Customer Acceptance Principles

The Company shall establish a business relationship only where it has obtained sufficient information to understand the customer’s identity, ownership and control, purpose of the relationship, expected activity and overall financial crime risk.

Customer acceptance shall be based on an assessment of whether the information obtained is complete, credible and consistent, whether the proposed use of the Company’s services is reasonable and whether the identified risks can be adequately managed.

The Company may decline an application where mandatory information cannot be obtained, the customer falls outside the Company’s risk appetite or the relationship would expose the Company to unacceptable legal, regulatory or financial crime risk.

7.2 Risk Classification

The Company shall classify customers as low, medium or high risk using a documented risk-rating methodology.

The classification shall take account of relevant customer, ownership, product, geographic, delivery-channel, transaction, sanctions and virtual-currency risk factors, including the reliability of the information obtained and any material inconsistency or adverse indicator.

A customer’s risk classification shall determine the level of due diligence, approval, ongoing monitoring and review applied to the relationship.

Risk classifications shall be reviewed and updated where new information, transaction activity, screening results, ownership changes or other material developments affect the customer’s risk profile.

7.3 Low- and Medium-Risk Customers

A customer may be classified as low risk only where the customer, ownership structure, intended activity, jurisdictions, payment methods and expected transaction behaviour present relatively limited financial crime risk.

Low-risk classification does not remove or reduce any mandatory identification, verification, screening, monitoring, reporting or record-keeping requirement.

A medium-risk classification shall apply where the relationship presents ordinary or moderate risk that can be managed through the Company’s standard due diligence and monitoring controls.

Where additional risk indicators arise, the customer shall be reassessed and may be reclassified or subjected to enhanced measures.

7.4 High-Risk Customers

The Company shall maintain documented criteria identifying restricted and prohibited customers, activities and relationships.

A restricted relationship may be accepted only where enhanced due diligence has been completed, the risks can be adequately controlled and the required approval has been obtained.

The Company shall not establish or maintain a relationship involving:

(a) a person or activity prohibited by applicable law or sanctions;

(b) a prohibited jurisdiction;

(c) a shell bank;

(d) an anonymous or fictitious identity;

(e) known criminal property or unlawful activity; or

(f) any other risk outside the Company’s approved risk appetite.

7.5 Approval and Documentation

Customer acceptance and risk-classification decisions shall be documented in a manner proportionate to the risks involved.

Where approval is required, the record shall identify the approver, the date, the material risks considered and any conditions imposed.

No risk classification or approval may be used to override a mandatory legal requirement or justify acceptance where required information remains incomplete.

8. CUSTOMER DUE DILIGENCE AND IDENTITY VERIFICATION

8.1 General Requirement

The Company shall conduct customer due diligence to understand who its customers are, why they wish to use the Company’s services and whether their intended and actual activity is consistent with the information provided.

Customer due diligence shall be completed when required by law and before the customer is permitted to use the Company’s services, except where the applicable legislation expressly permits verification to occur at a later point and the relevant conditions are satisfied.

The scope of due diligence shall be proportionate to risk, but mandatory statutory requirements shall always be completed.

8.2 Individual Customers

For an individual customer, the Company shall obtain the customer’s full legal name, residential address, date of birth, occupation or nature of principal activity, contact details and any other information required to understand and assess the relationship.

The Company shall verify the individual’s identity using a method permitted under applicable Canadian requirements. The verification method, source, reference information and date of verification shall be recorded.

The Company shall take reasonable steps to ensure that the person presenting the identification is the person to whom the information relates. Where onboarding is conducted remotely, the Company shall apply appropriate controls to address impersonation, identity fraud, document manipulation and unauthorised account opening.

Where information is inconsistent, incomplete or unreliable, the Company shall obtain clarification or additional evidence before completing onboarding.

8.3 Entity Customers

For an entity customer, the Company shall obtain sufficient information to understand the entity’s legal existence, ownership, control, activities and purpose.

This shall include the entity’s legal name, registration or incorporation details, registered address, principal business address, nature of business, constitutional or formation documents, directors or equivalent governing persons and the authority of individuals acting on behalf of the entity.

The Company shall verify the entity’s existence using reliable and independent records or sources permitted under applicable requirements.

The Company shall also verify the identity of persons acting for the entity and confirm that they are authorised to establish and operate the relationship.

8.4 Purpose and Intended Nature of the Relationship

The Company shall establish and record the purpose and intended nature of each business relationship.

The information obtained shall be sufficiently specific to enable the Company to understand how the customer is expected to use its services. Generic descriptions such as “investment”, “business” or “personal use” shall not be accepted without further explanation where they do not provide a meaningful understanding of the intended activity.

The Company shall establish, as appropriate, the expected transaction values, frequency, counterparties, jurisdictions, payment methods, wallet usage, source of funds and anticipated withdrawal or transfer destinations.

This information shall form the baseline against which the customer’s subsequent activity is monitored.

8.5 Source of Funds and Source of Wealth

The Company shall obtain source-of-funds information where required by law, under its risk-based procedures or where necessary to understand a transaction or relationship.

Source of funds means the immediate origin of the funds or virtual currency used in a transaction or relationship. Source of wealth means the manner in which the customer accumulated their overall wealth.

Source-of-wealth information may be required for high-risk customers, politically exposed persons, significant-value activity or other circumstances in which the customer’s financial position requires further explanation.

The Company shall obtain supporting evidence where a customer’s explanation alone is insufficient, taking account of the risk, value and complexity of the activity.

Where source of funds or source of wealth cannot be adequately established, the Company may decline, restrict or terminate the transaction or relationship and shall consider whether an assessment for suspicious transaction reporting is required.

8.6 Reliance on Technology and Service Providers

The Company may use electronic verification tools or external providers to support identity verification and customer due diligence.

Such use does not transfer the Company’s responsibility for determining whether the legal requirements have been satisfied.

The Company shall understand the method used, the information relied upon, the limitations of the service and the evidence available to demonstrate that verification was completed appropriately.

The Company shall maintain contingency arrangements where a provider or system is unavailable or produces an inconclusive result.

8.7 Failure to Complete Due Diligence

Where the Company cannot complete required customer due diligence or identity verification, it shall not establish or continue the relationship unless expressly permitted by law and approved under documented procedures.

The Company shall consider whether the inability to obtain information is itself unusual or suspicious.

The Company may restrict services, freeze further activity where legally permissible, reject or return funds, terminate the relationship or submit a report to FINTRAC where the relevant threshold is met.

9. BENEFICIAL OWNERSHIP AND CONTROL

9.1 General Requirement

The Company shall identify the natural persons who ultimately own or control an entity customer and shall take reasonable measures to confirm the accuracy of the information obtained.

The Company shall not rely solely on the identity of the immediate shareholder, nominee, trustee, corporate director or authorised representative where further ownership or control exists.

The beneficial ownership review shall be sufficient to enable the Company to understand the entity’s ownership and control structure and to identify any person who ultimately exercises material ownership or control.

9.2 Corporations

For a corporation, the Company shall obtain the names of all directors and the names and addresses of persons who directly or indirectly own or control 25 per cent or more of the corporation’s shares.

The Company shall obtain information sufficient to understand how ownership and control are exercised, including through intermediary entities, voting arrangements, trusts, partnerships, nominee arrangements or other legal structures.

Where ownership is distributed and no person meets the relevant ownership threshold, the Company shall nevertheless consider whether any person exercises control through other means.

9.3 Trusts

For a trust, the Company shall obtain the names and addresses of all trustees, known beneficiaries and settlors, together with sufficient information to understand the nature, purpose and control of the trust.

Where beneficiaries are defined by class rather than individually named, the Company shall obtain sufficient information to understand the class and identify relevant persons when distributions or control arise.

The Company shall pay particular attention to trusts involving nominees, protectors, complex cross-border structures or unexplained changes of trustee, settlor or beneficiary.

9.4 Other Entities

For partnerships and other entities, the Company shall identify the persons who directly or indirectly own or control 25 per cent or more and shall understand the arrangements through which control is exercised.

The Company shall also identify the persons responsible for the entity’s management where relevant to understanding its ownership, authority and risk.

9.5 Measures to Confirm Accuracy

The Company shall take reasonable measures to confirm the accuracy of beneficial ownership information.

Such measures may include reviewing constitutional documents, registers, partnership agreements, trust deeds, corporate filings, audited financial statements, ownership charts, shareholder records, independent databases and other reliable information.

The Company shall document the measures taken, the sources reviewed and the conclusions reached.

A self-declaration may form part of the process but shall not be treated as conclusive where the ownership structure is complex, inconsistent or high risk.

9.6 Inability to Confirm Beneficial Ownership

Where the Company is unable to obtain the prescribed beneficial ownership information, keep that information up to date during ongoing monitoring or confirm its accuracy, the Company shall:

(a) take reasonable measures to verify the identity of the entity’s chief executive officer or the person who performs that function; and

(b) apply the special measures required for high-risk clients, including enhanced ongoing monitoring.

The Company shall also consider the deficiency when assessing the customer’s risk and determining whether to restrict the services provided, impose additional controls, require senior management approval, decline the application or terminate the relationship.

9.7 Ongoing Maintenance

Beneficial ownership information shall be kept current through periodic review and event-driven monitoring.

Changes in ownership, directors, trustees, authorised persons, control arrangements or corporate structure shall trigger reassessment where material.

The Company shall not continue to rely upon information that it knows or suspects is outdated, incomplete or inaccurate.

10. THIRD-PARTY DETERMINATIONS AND THIRD-PARTY PAYMENTS

10.1 Third-Party Determination

The Company shall take reasonable measures to determine whether a person conducting or attempting a transaction is acting on behalf of a third party whenever required by law or where the circumstances indicate that another person may be directing, funding or benefiting from the activity.

The Company shall not assume that a transaction is conducted solely for the customer’s benefit merely because it is initiated through the customer’s account or wallet.

10.2 Information to Be Obtained

Where the Company determines that a third party is involved, it shall take reasonable measures to obtain and record the information prescribed by applicable law.

For an individual third party, this shall include the person’s name, address, date of birth, occupation or nature of principal business and, where prescribed, telephone number.

For a corporate or other entity third party, this shall include its name, address, nature of principal business, registration or incorporation number, the jurisdiction and country in which that number was issued and, where prescribed, telephone number.

The Company shall also record the relationship between the third party and the customer, conductor, account holder or other relevant person or entity.

10.3 Reasonable Measures and Unsuccessful Determinations

Where the Company is unable to determine whether a third party is involved, but has reasonable grounds to suspect that a person or entity is acting on behalf of a third party, the Company shall retain a record:

(a) stating whether, according to the relevant person or entity, they are acting on their own behalf only; and

(b) describing the reasonable grounds for suspecting that a third party is involved.

The Company shall also document the reasonable measures taken to make the determination.

10.4 Third-Party Payments

Third-party payments are restricted and may be accepted only where the arrangement is lawful, transparent, consistent with the customer’s profile and business purpose, and capable of being adequately identified, screened and monitored.

The Company reserves the right to prohibit third-party payments for particular products, customer categories, jurisdictions or payment methods.

10.5 Higher-Risk Third-Party Arrangements

Third-party payments shall be treated as higher risk where they involve unrelated persons, multiple intermediaries, complex corporate structures, high-risk jurisdictions, rapid onward transfers, multiple customer accounts, common wallets or payment methods, or inconsistent explanations.

Payments originating from a person or entity that appears to be conducting money services, payment services, brokerage, investment or virtual asset activity without appropriate authorisation shall be escalated.

The Company shall not knowingly permit its services to be used as a pass-through facility for undisclosed customers or to enable one customer to conduct transactions on behalf of multiple unidentified persons.

10.6 Withdrawals and Returns

As a general principle, funds or virtual currency shall be returned to the verified account or wallet from which they originated. Where return to the original source is not reasonably possible, the Company may permit an alternative destination only where:

(a) the customer has provided a credible and documented explanation;

(b) the alternative account or wallet is verified as being owned or controlled by the customer or another legitimately entitled recipient;

(c) applicable screening and enhanced review have been completed; and

(d) the arrangement has been approved in accordance with the Company’s procedures.

11. ENHANCED DUE DILIGENCE AND ENHANCED MEASURES

11.1 Application of Enhanced Measures

The Company shall apply enhanced measures where a customer, business relationship, transaction, product, jurisdiction, wallet or other circumstance is assessed as high risk.

Enhanced due diligence shall be tailored to the specific risks identified. It shall not consist solely of obtaining additional documents without considering whether those documents meaningfully address the relevant risk.

The Company shall document the reasons enhanced measures were required, the measures applied, the information obtained and the conclusion reached.

FINTRAC requires reporting entities to implement enhanced measures for high-risk activities and business relationships, including measures to identify and mitigate the relevant risk.

11.2 Enhanced Customer Information

Enhanced measures may include obtaining additional information regarding the customer’s identity, occupation, business activities, regulatory status, ownership and control, financial position, expected activity, counterparties, jurisdictions and reasons for using the Company’s services.

The Company may also obtain independent information to corroborate customer representations, including corporate records, regulatory registers, financial statements, tax records, transaction evidence, contracts, invoices and reliable public information.

Where material information is inconsistent, cannot be reasonably explained or cannot be corroborated to the extent appropriate having regard to the customer’s risk, the Company shall assess whether additional controls can adequately mitigate the risk and whether the relationship may be accepted or continued.

11.3 Source of Funds and Source of Wealth

Where appropriate having regard to the identified risk, and whenever required by applicable law, the Company shall establish and take reasonable measures to corroborate the source of funds, source of virtual currency and source of wealth of the customer or other relevant person.

The nature and extent of the evidence required shall be proportionate to the value, complexity, circumstances and risk of the relationship or transaction.

Where virtual currency is received, the Company shall consider the acquisition history, relevant wallet activity, blockchain exposure and any available evidence showing how the assets were obtained.

11.4 Senior Approval

High-risk relationships shall be approved by the Compliance Officer or other designated senior person in accordance with the Company’s procedures before onboarding and, where appropriate, before continuation following a material increase in risk. Senior management approval shall be obtained whenever specifically required by applicable law.

The approval record shall identify the material risks, due diligence completed, mitigating controls, conditions imposed and reasons the residual risk is considered acceptable.

Approval shall not be treated as a substitute for missing information or ineffective controls.

Conditions may be imposed, including transaction limits, restricted services, approved wallets, first-party funding requirements, enhanced review frequency or additional monitoring.

11.5 Enhanced Monitoring

High-risk business relationships shall be subject to enhanced ongoing monitoring at a frequency and intensity proportionate to the identified risks.

Enhanced monitoring shall be designed to detect transactions or attempted transactions that may require reporting, keep customer and beneficial ownership information current, reassess the customer’s risk and determine whether activity remains consistent with the Company’s knowledge of the customer, the purpose of the relationship and the customer’s expected activity.

Enhanced monitoring may include more frequent transaction review, closer scrutiny of counterparties and wallets, adjusted alert thresholds, manual review, additional source-of-funds enquiries and more frequent customer-file refreshes.

11.6 Restrictions and Exit

Where enhanced measures do not reduce the residual risk to a level acceptable under the Company’s risk appetite, the Company shall decline the application or consider restricting, suspending or terminating the relationship, subject to applicable legal, regulatory, contractual and reporting requirements.

Before taking such action, the Company shall consider whether any completed or attempted transaction gives rise to an STR, sanctions-related report, terrorist-property report or other legal obligation, and whether any restriction applies to returning or transferring funds or virtual currency.

11.7 Ministerial Directives and Prescribed Measures

The Company shall comply with any applicable Ministerial Directive, transaction restriction, countermeasure, enhanced due diligence requirement or other prescribed measure relating to a jurisdiction, person, entity, product, transaction or activity.

The Company shall maintain procedures to identify relevant regulatory developments and update its controls promptly. Where a prescribed measure imposes requirements exceeding the Company’s ordinary enhanced due diligence procedures, the prescribed measure shall prevail.

12. BUSINESS RELATIONSHIPS, ONGOING MONITORING AND PERIODIC REVIEW

12.1 Business Relationships

The Company shall identify when a business relationship is established under applicable Canadian requirements and shall maintain prescribed records relating to that relationship.

The Company shall record the purpose and intended nature of the relationship and shall ensure that the information is sufficiently detailed to support meaningful ongoing monitoring.

Where the relationship changes materially, the purpose and intended nature shall be reassessed and updated.

12.2 Purpose of Ongoing Monitoring

The Company shall conduct ongoing monitoring of business relationships on a risk-sensitive basis.

Ongoing monitoring is intended to enable the Company to detect reportable transactions, maintain current customer and beneficial ownership information, reassess risk and determine whether actual activity is consistent with the Company’s knowledge of the customer.

Monitoring shall consider customer transactions, deposits, withdrawals, wallet activity, counterparties, jurisdictions, payment methods, device or access indicators, screening results, source of funds and other relevant information.

12.3 Transaction Consistency

The Company shall assess whether customer activity is consistent with the stated purpose of the relationship, expected transaction profile, occupation or business, source of funds and known financial circumstances.

Activity that is unusual, inconsistent or insufficiently explained shall be reviewed.

The Company shall consider the overall facts and context rather than relying solely on fixed thresholds or isolated alerts.

FINTRAC guidance emphasises that suspicious activity assessments should take account of facts, context and relevant money laundering or terrorist financing indicators, rather than treating a single indicator as determinative.

12.4 Periodic Review Frequency

The Company shall conduct periodic reviews according to customer risk.

High-risk customers shall be reviewed at least annually. Medium-risk customers shall be reviewed at least every two years. Low-risk customers shall be reviewed at least every three years.

These intervals represent maximum routine review periods. A review shall be conducted sooner where an event or change indicates that the customer’s information or risk profile may no longer be accurate.

The periodic review shall be proportionate to the customer’s risk and activity. A review shall not be treated as complete merely because the customer confirms that no information has changed.

12.5 Event-Driven Review

An event-driven review shall be initiated whenever information arises that may materially affect the customer’s identity, ownership, control, purpose, activity or risk classification.

Trigger events may include a change of ownership or management, a new authorised person, material changes in transaction behaviour, unusual wallet activity, sanctions or adverse-media alerts, law-enforcement enquiries, new jurisdictions, changes in source of funds, unexplained third-party payments, suspected account compromise or concerns regarding the accuracy of information previously provided.

The Company shall not wait until the next scheduled review where a material trigger has occurred.

12.6 Information Refresh

The Company shall take reasonable measures to keep customer identification, beneficial ownership, third-party, business relationship and risk information current.

The extent of refresh shall reflect the customer’s risk and the nature of the change.

Where the customer does not provide requested information within a reasonable period, the Company may restrict transactions, suspend services, decline further activity or terminate the relationship.

The Company shall consider whether refusal or delay in providing information is itself suspicious.

12.7 Monitoring of High-Risk Relationships

High-risk business relationships shall be subject to enhanced ongoing monitoring in accordance with the Company’s documented procedures.

The Company shall determine and record the monitoring measures applied, including the frequency of review and any specific transaction, wallet, counterparty, geographic or value-based restrictions.

The effectiveness of enhanced monitoring shall be reassessed periodically. Where the controls no longer adequately mitigate the risk, the relationship shall be escalated, restricted or terminated.

12.8 Monitoring Records

The Company shall retain records sufficient to demonstrate that ongoing monitoring and periodic reviews have been completed.

Records shall include the information reviewed, alerts considered, enquiries made, explanations obtained, risk-rating changes, decisions reached, approvals granted and actions taken.

Where unusual activity is identified, the matter shall be escalated in accordance with the Company’s suspicious activity procedures.

FINTRAC’s MSB guidance requires appropriate records to be maintained in relation to business relationships, ongoing monitoring, transactions, beneficial ownership and related reporting obligations.

13. TRANSACTION MONITORING AND BLOCKCHAIN ANALYTICS

13.1 Transaction Monitoring Framework

The Company shall maintain a risk-based transaction monitoring framework designed to identify activity that is unusual, inconsistent with the customer’s known profile or potentially connected with money laundering, terrorist activity financing, sanctions evasion or other financial crime.

The framework shall cover completed and attempted transactions and shall apply throughout the customer relationship. It shall take account of deposits, withdrawals, virtual currency exchanges, transfers between hosted and external wallets, third-party payments, rejected transactions, cancelled instructions and other activity conducted or attempted through the Company’s services.

Transaction monitoring may be conducted through automated systems, manual controls or a combination of both. Where any element of automated monitoring is unavailable, undergoing implementation or temporarily disrupted, the Company shall apply documented alternative controls sufficient to identify, review and escalate unusual or potentially reportable activity. The absence or unavailability of an automated tool shall not relieve the Company of its monitoring, escalation or reporting obligations.

The Company shall ensure that transaction monitoring is not limited to checking whether an individual transaction exceeds a fixed monetary threshold. The assessment shall consider the customer’s overall behaviour, transaction history, source of funds, counterparties, wallet exposure, geographic connections and the purpose and intended nature of the relationship.

13.2 Monitoring Against the Customer Profile

The Company shall compare actual customer activity against the information obtained during onboarding and subsequent reviews.

The monitoring framework shall consider whether the value, volume, frequency, velocity, purpose and direction of transactions are consistent with the customer’s occupation or business, source of funds, expected activity, stated use of the Company’s services and known financial circumstances.

Activity that materially exceeds the expected profile, involves new or unexplained counterparties, introduces higher-risk jurisdictions or differs significantly from the customer’s previous behaviour shall be reviewed.

13.3 Monitoring Scenarios and Indicators

The Company shall maintain monitoring scenarios appropriate to its products, services and risk profile. Monitoring shall be capable of identifying unusual transaction activity, rapid movement of funds, activity inconsistent with the customer profile, high-risk jurisdictions, unusual wallet activity, third-party involvement, potential structuring and other indicators of money laundering, terrorist financing or sanctions evasion.

Monitoring scenarios shall be informed by FINTRAC guidance, regulatory developments and emerging financial crime typologies.

A single indicator shall not, by itself, be treated as conclusive evidence of suspicious activity. The Company shall assess all relevant facts, context and money laundering or terrorist financing indicators. Where one or more indicators, considered together with the surrounding circumstances, give rise to reasonable grounds to suspect that a completed or attempted transaction is related to a money laundering or terrorist activity financing offence, the matter shall be reported in accordance with the Company’s suspicious transaction reporting procedures.

13.4 Blockchain Analytics Capability

Where proportionate to the nature, scale and risk of the Company’s virtual-currency activities, the Company shall use blockchain analytics tools, blockchain intelligence or other appropriate investigative methods to support transaction monitoring, wallet assessment and suspicious activity review.

The capability may be provided internally or through a third-party service provider.

Blockchain analytics shall be used, where appropriate, to assess wallet addresses, transaction histories, source and destination exposure, counterparties, clusters and links to known or suspected illicit activity.

Blockchain analytics may be used to identify exposure to sanctions, illicit activity and other financial crime risks.

The Company shall not treat a blockchain risk score or vendor classification as conclusive. Such information shall be considered alongside customer information, transaction context, source-of-funds evidence and other relevant facts.

Where blockchain analytics produces an alert, the Company shall assess the nature, proximity, value, timing and relevance of the exposure and shall document the basis for the action taken.

13.5 Wallet Ownership and Control

Where appropriate, the Company may take reasonable measures to understand the ownership or control of external wallets. The level of verification shall be proportionate to the identified risk. Transactions involving third-party wallets shall be subject to additional review and due diligence where required.

13.6 Alert Review and Documentation

Transaction monitoring alerts shall be reviewed within a timeframe proportionate to their risk and urgency.

Alerts involving suspected terrorist activity financing, sanctions exposure, significant fraud, active dissipation of assets or immediate threats shall receive priority.

The reviewer shall document the transactions and information considered, the relevant facts and context, the indicators identified, any enquiries made, the customer’s explanation, the blockchain or screening results and the conclusion reached.

Where an alert is closed without escalation, the rationale must be sufficiently clear to allow another appropriately trained person to understand why the activity was considered reasonable.

Where suspicion remains or the activity cannot be adequately explained, the matter shall be escalated to the Compliance Officer in accordance with Section 15.

Calibration and Effectiveness

The Company shall periodically review the effectiveness of its transaction monitoring and blockchain analytics controls. Monitoring scenarios, thresholds and parameters shall be adjusted where necessary to reflect changes in products, customers, jurisdictions, transaction volumes or emerging risks. Material changes shall be documented and approved through the Company’s governance framework.

14. SANCTIONS, LISTED PROPERTY AND MINISTERIAL DIRECTIVES

14.1 Sanctions Compliance Framework

The Company shall maintain risk-based controls designed to prevent transactions, services or dealings prohibited under applicable Canadian sanctions, terrorist-listing and related laws, and to identify, restrict, freeze and report property or activity where required by applicable law.

Sanctions compliance shall form part of the Company’s customer onboarding, transaction monitoring, wallet screening, ongoing monitoring and payment-control framework.

The Company shall screen customers, beneficial owners, directors, authorised persons, third-party payers, counterparties, originators, beneficiaries and other relevant parties against applicable lists and restrictions.

Where virtual currency is involved, the Company shall also screen relevant wallet addresses and blockchain exposure where appropriate.

Screening shall be conducted before onboarding or permitting relevant activity and shall be repeated on an ongoing basis to identify changes in status or new designations.

14.2 Applicable Lists and Restrictions

The Company shall comply with sanctions and terrorist-listing requirements applicable under Canadian law.

The Company may also have regard to other internationally recognised sanctions lists where appropriate to its business, counterparties, banking relationships or risk assessment, provided that the application of such lists does not conflict with Canadian law.

The Company shall maintain procedures for identifying changes to relevant lists, implementing updated restrictions and reviewing customers or transactions potentially affected by a new designation.

The Company shall not limit its controls to name screening. It shall consider ownership, control, indirect involvement, aliases, wallet exposure and other information indicating that property or activity may be connected with a listed or sanctioned person or entity.

The Company shall screen against and have regard to all lists, regulations, directives and restrictions applicable under Canadian law. A consolidated screening list may be used as an operational tool but shall not be treated as replacing the underlying legislation, regulations or applicable designation instruments.

14.3 Potential Matches

Potential sanctions or listed-person matches shall be escalated promptly to Compliance and shall not be dismissed solely because the name is common or the initial screening information is incomplete.

The Company shall assess relevant identifiers, including date of birth, nationality, address, incorporation details, ownership, control, aliases, identification numbers and wallet or transaction information.

Pending resolution of a potential match, the Company shall apply any restriction, prohibition, freezing measure or other action required by applicable law. Where no immediate legal prohibition applies, the Company may delay, reject, suspend or restrict the relevant transaction or relationship in accordance with its contractual rights, risk controls and escalation procedures.

The Company shall document the information considered and the basis on which the match was confirmed or discounted.

14.4 Property of a Listed Person or Entity

Where the Company knows that property in its possession or control is owned or controlled by or on behalf of a listed person or entity, it shall immediately apply all prohibitions, restrictions, freezing measures, disclosure and reporting requirements imposed by applicable law.

The Company shall submit a Listed Person or Entity Property Report to FINTRAC immediately where required and shall make any separate disclosure or report required under the applicable sanctions, terrorist-property or listing legislation to the competent authority.

The reporting obligation may arise even where no transaction has occurred. Where a completed or attempted transaction is also involved, the Company shall separately assess whether an STR is required.

Access to information concerning listed property shall be restricted to those who require it for the performance of their duties.

14.5 Suspected Sanctions Evasion

The Company shall assess completed and attempted transactions for indicators of sanctions evasion.

Relevant indicators may include the use of intermediaries, shell companies, nominees, false ownership information, indirect payment routes, newly created entities, unexplained changes in counterparties, transfers through jurisdictions commonly used to circumvent restrictions and the use of multiple wallets or blockchain networks to obscure the source or destination of assets.

Where the Company has reasonable grounds to suspect that a completed or attempted transaction is related to the commission or attempted commission of a sanctions-evasion offence, money laundering offence or terrorist activity financing offence, it shall submit an STR as soon as practicable in accordance with Section 15 and identify all relevant grounds of suspicion.

14.6 Ministerial Directives and Transaction Restrictions

The Company shall distinguish between legally binding Ministerial Directives and regulatory advisories, bulletins or international statements. Advisories and bulletins shall be considered in the Company’s risk assessment and controls, while any applicable Ministerial Directive shall be implemented in accordance with its specific legal requirements.

Where a directive imposes enhanced identification, due diligence, reporting, record-keeping or transaction restrictions, the Company shall incorporate those requirements into its procedures and systems.

The Compliance Officer shall assess whether new or amended ministerial directives affect the Company’s customers, services, jurisdictions or risk appetite and shall arrange appropriate implementation.

15. INTERNAL ESCALATION AND SUSPICIOUS TRANSACTION REPORTING

15.1 Internal Reporting Obligation

All directors, officers, employees, contractors, agents and other persons acting for the Company must promptly escalate unusual or potentially suspicious activity to Compliance.

A person is not required to establish that money laundering, terrorist activity financing or sanctions evasion has occurred before raising an internal report.

An internal escalation should be made whenever the person becomes aware of facts, behaviour, transactions or circumstances that cannot be reasonably explained or that may indicate financial crime.

Internal reports shall be treated confidentially and shall be submitted through the Company’s approved escalation process.

No person shall suppress, delay or discourage an internal report because of commercial considerations, customer importance, transaction value or concern about damaging a customer relationship.

15.2 Compliance Review

The Compliance Officer or an authorised Compliance reviewer shall assess internal reports and other unusual activity to determine whether further enquiries, enhanced due diligence, transaction restrictions, relationship action or regulatory reporting are required.

The review shall consider the known facts, the context of the customer relationship, transaction history, customer explanations, source of funds, beneficial ownership, third-party involvement, geographic exposure, sanctions results, blockchain analytics and relevant money laundering or terrorist financing indicators.

The Company is not required to prove that an offence has occurred. The relevant threshold for submitting an STR is reasonable grounds to suspect, which is higher than a mere hunch but lower than reasonable grounds to believe.

The reviewer must be able to articulate how the relevant facts, context and indicators support or do not support the conclusion reached. FINTRAC expressly requires the measures used to identify and assess suspicious transactions to be described in the reporting entity’s policies and procedures.

15.3 Reasonable Grounds to Suspect

The Company shall submit an STR where a financial transaction occurs or is attempted in the course of its activities and there are reasonable grounds to suspect that the transaction is related to the commission or attempted commission of a money laundering offence, terrorist activity financing offence or, where applicable, sanctions evasion offence.

There is no monetary threshold for an STR.

The reasonable grounds to suspect assessment shall be objective, evidence-based and free from bias or prejudice. It shall be capable of being understood by another appropriately trained person reviewing the same information.

The Company need not verify every fact or establish the underlying predicate offence before filing. However, it must complete the measures reasonably necessary to reach and articulate the reporting threshold.

15.4 Timing of Submission

An STR shall be submitted to FINTRAC as soon as practicable after the Company has completed the measures that enabled it to establish reasonable grounds to suspect.

Once that threshold has been reached, preparation and submission of the report shall be treated as a priority.

The greater the delay between reaching the threshold and filing the report, the greater the need for a documented explanation.

Reports concerning suspected terrorist activity financing, threats to national security or other urgent matters shall be expedited wherever practicable.

15.5 Responsibility for Filing

The Compliance Officer is responsible for reviewing, approving and arranging the submission of STRs to FINTRAC.

The Company may use an authorised employee or service provider to prepare, submit or correct a report. However, the legal responsibility for compliance remains with the Company and cannot be delegated.

Reports shall be submitted using the method prescribed or approved by FINTRAC from time to time.

The Company shall maintain appropriate controls over system access, authorisation, quality assurance, submission confirmation and business continuity.

15.6 STR Content and Narrative

The Company shall ensure that STRs are complete, accurate and sufficiently detailed to support FINTRAC’s analysis.

The narrative shall explain in clear and concise language who was involved, what occurred or was attempted, when and where the activity took place, how the funds or virtual currency moved and why the Company considers the activity suspicious.

The report should identify relevant customers, conductors, third parties, beneficial owners, counterparties, originators, beneficiaries, bank accounts, wallet addresses, transaction hashes and related persons or entities where that information is available.

The narrative shall distinguish facts from assumptions and shall explain the relevant context and indicators rather than merely listing alerts or stating that activity is “unusual”.

Internal jargon, unexplained abbreviations and references that cannot be understood outside the Company shall be avoided.

The Company shall also record the action taken or proposed in response to the activity.

15.7 Subsequent Transactions

Where suspicion remains and further completed or attempted transactions occur, the Company shall continue to assess and report those transactions as required.

Subsequent reports should reference related earlier reports where appropriate and should identify new transactions, persons, entities, facts, context or indicators.

The customer’s risk and the continued basis for suspicion shall be reassessed periodically.

15.8 Corrections and Amendments

Where the Company identifies missing or inaccurate information in a submitted STR, it shall make the necessary correction or amendment through the applicable FINTRAC reporting method and shall provide an explanation for the change.

Corrections shall be completed within the applicable system or regulatory timeframe.

Material reporting errors or delays shall be escalated to the Compliance Officer, who shall consider whether further remediation, retrospective review or a voluntary self-declaration of non-compliance is appropriate.

15.9 No Tipping Off and Confidentiality

The Company shall not disclose to a customer or unauthorised person the contents of an STR or the fact that an STR has been or will be submitted where the disclosure could prejudice a criminal investigation.

Personnel shall not make unusual or unnecessary enquiries that may alert the customer to a potential report.

Where additional information is required, enquiries shall be conducted in a manner consistent with ordinary due diligence and customer-service processes.

STRs, internal suspicious activity reports, supporting analysis and reporting decisions shall be subject to restricted access and enhanced confidentiality controls.

16. PRESCRIBED FINTRAC REPORTING AND THE 23-HOUR RULE

16.1 General Reporting Obligation

In addition to STRs, the Company shall submit any other transaction or property reports required under applicable Canadian law.

Depending on the Company’s activities and the relevant transaction, these may include Large Cash Transaction Reports, Large Virtual Currency Transaction Reports, Electronic Funds Transfer Reports and Listed Person or Entity Property Reports.

Each reporting obligation shall be assessed independently. Submission of one type of report does not remove the obligation to submit another report in relation to the same transaction or property.

The Company shall maintain documented procedures identifying the relevant trigger, aggregation rule, reporting timeframe, required information, responsible person and evidence of submission for each report type.

16.2 Large Cash Transactions

The Company does not accept physical cash as part of its ordinary business model.

Any attempted cash payment shall be rejected and escalated where the circumstances are unusual or suspicious.

If the Company nevertheless receives cash or otherwise becomes subject to large cash transaction reporting obligations, it shall comply with the applicable reporting, identity-verification, third-party determination and record-keeping requirements.

The Company’s procedures shall ensure that linked cash transactions are identified and aggregated where required under the 23-hour rule.

16.3 Large Virtual Currency Transactions

The Company shall submit a Large Virtual Currency Transaction Report where it receives virtual currency in an amount that meets the applicable statutory threshold, whether through a single receipt or through receipts required to be aggregated under the 23-hour rule.

The Company shall determine and record the Canadian-dollar equivalent using the applicable valuation methodology and shall retain the exchange rate and source used.

The report and related record shall include the prescribed customer, transaction, account, wallet, sending address, receiving address and transaction identifier information.

The Company shall maintain controls capable of identifying linked virtual currency receipts across accounts, wallets, networks or channels where aggregation is legally required.

16.4 Electronic Funds Transfers

Where the Company initiates, sends, receives or otherwise participates in an electronic funds transfer that is subject to FINTRAC reporting requirements, it shall determine whether an Electronic Funds Transfer Report is required.

The Company shall maintain procedures for identifying reportable international electronic funds transfers, applying any relevant aggregation rules and submitting reports within the applicable timeframe.

The reporting assessment shall take account of the Company’s role in the transfer and shall not be based solely on whether the customer directly initiated the payment through the Company’s interface.

16.5 Listed Person or Entity Property Reports

Where the Company is required to make a disclosure concerning property owned or controlled by or on behalf of a listed person or entity, it shall submit the relevant property report to FINTRAC immediately.

This obligation is addressed further in Section 14 and shall be assessed separately from any STR obligation.

16.6 The 23-Hour Rule

The Company shall apply the 23-hour rule where required to determine whether multiple transactions must be aggregated and reported as a single reportable amount.

The Company’s procedures shall identify the legally relevant linking factors, which may include transactions conducted by or on behalf of the same person or entity, for the same third party, or for the same beneficiary.

The aggregation assessment shall consider linked activity conducted through different accounts, wallets, payment routes, currencies, virtual currencies, devices, channels or agents where the available information indicates that the transactions form part of the same activity.

The Company shall not permit customers or third parties to avoid identification, reporting or monitoring obligations by dividing activity into smaller transactions.

16.7 Structuring and Avoidance

The Company prohibits the deliberate structuring, splitting or arrangement of transactions for the purpose of avoiding a legal threshold, customer due diligence requirement, transaction monitoring control or regulatory report.

Potential structuring shall be assessed as suspicious activity even where no individual transaction exceeds the applicable threshold.

Where the Company identifies repeated transactions below a threshold, use of multiple customers or wallets, coordinated transactions, unusual timing or other avoidance behaviour, the matter shall be escalated to Compliance and considered for an STR.

16.8 Reporting Quality and Control

The Company shall maintain controls to support the completeness, accuracy and timeliness of prescribed reports.

Such controls shall include appropriate data capture, maker-checker review where proportionate, reconciliation of reportable activity against submitted reports, management of rejected or failed submissions and retention of submission confirmations.

Late, inaccurate, incomplete or missed reports shall be escalated promptly and remediated.

The Compliance Officer shall consider whether affected transactions require retrospective reporting and whether the matter should be disclosed voluntarily to FINTRAC.

17. TRAVEL RULE

17.1 Application

The Company shall comply with the travel rule when initiating, sending, receiving or acting as an intermediary in an electronic funds transfer or virtual currency transfer to which the applicable Canadian requirements apply.

The Company shall ensure that prescribed originator and beneficiary information accompanies the transfer and is retained in the Company’s records.

The travel rule applies independently from customer due diligence and transaction reporting obligations. Compliance with the travel rule does not remove the need to assess the transaction for sanctions exposure, unusual activity or reporting requirements.

17.2 Required Transfer Information

For relevant virtual currency transfers, the Company shall collect, record and transmit the prescribed information concerning the person or entity requesting the transfer and the beneficiary.

The Company shall also retain relevant transfer information, including the date, amount and type of virtual currency, account information where applicable, wallet addresses, transaction identifiers and transaction hashes.

The information retained must be sufficient to identify the relevant parties and reconstruct the transfer.

MSB record-keeping requirements expressly require records of virtual currency transfers and receipts to include sending and receiving addresses and transaction hashes or similar identifiers, where applicable.

17.3 Incoming Transfers

Where the Company receives a transfer, it shall take reasonable measures to determine whether the prescribed information accompanies the transfer.

The Company shall not assume that the information is complete merely because it has been transmitted by another financial institution or virtual asset service provider.

Missing, incomplete, inconsistent or clearly inaccurate information shall be identified and escalated in accordance with the Company’s procedures.

17.4 Missing or Incomplete Information

The Company shall maintain written, risk-based procedures setting out when a transfer with missing or incomplete travel-rule information may be accepted, delayed, suspended, rejected or returned.

The decision shall take account of the nature and extent of the missing information, the parties involved, the relevant jurisdictions, prior deficiencies, the transaction value, the customer’s risk rating and any other unusual or suspicious factors.

The Company may request additional information from the customer, counterparty or relevant service provider.

Repeated receipt of transfers with missing information from the same counterparty shall be assessed as a control deficiency and potential financial crime indicator.

17.5 Counterparty Arrangements

Where the Company transmits travel-rule information to, or receives it from, another financial institution, virtual asset service provider, wallet provider or intermediary, it shall take reasonable steps to understand the counterparty’s role and the information-sharing method used.

The Company shall maintain appropriate confidentiality, information security, data minimisation and record-retention controls.

The use of an external travel-rule solution does not transfer the Company’s legal responsibility for compliance.

17.6 Suspicious or Prohibited Transfers

A transfer that satisfies the travel rule is not automatically acceptable.

The Company shall continue to assess the customer, counterparty, wallet, transaction and jurisdiction under its customer due diligence, sanctions, blockchain analytics and transaction monitoring controls.

Where the available information gives rise to reasonable grounds to suspect money laundering, terrorist activity financing or sanctions evasion, an STR shall be submitted in accordance with Section 15.

18. RECORD KEEPING, RETENTION AND RETRIEVAL

18.1 General Record-Keeping Standard

The Company shall create and maintain accurate, complete and intelligible records in accordance with the PCMLTFA, the applicable regulations and FINTRAC guidance.

Records shall be sufficient to demonstrate what information was obtained, what verification or assessment was undertaken, what transactions occurred, what decisions were made and how the Company fulfilled its legal and regulatory obligations.

The Company shall not rely solely on information held by a customer, employee, agent or service provider where that information is required to be maintained by the Company.

18.2 Customer and Business Relationship Records

The Company shall maintain required customer identification and verification records, entity records, beneficial ownership information, authority-to-act documentation, third-party determination records, PEP and HIO records, source-of-funds and source-of-wealth evidence where applicable and the purpose and intended nature of business relationships.

Records shall also include customer risk assessments, approvals, enhanced due diligence, ongoing monitoring, periodic reviews and material changes to customer information or risk.

The information recorded concerning an occupation or principal business shall be sufficiently descriptive to support meaningful monitoring and should not be limited to vague terms that do not explain the customer’s activity.

18.3 Transaction Records

The Company shall maintain the prescribed records relating to transactions and services relevant to its business.

These shall include virtual currency exchange transaction tickets, virtual currency transfer and receipt records, account and hosted wallet records, deposits, withdrawals, payment instructions, exchange rates and sources, relevant third-party information, transaction identifiers, transaction hashes and sending and receiving wallet addresses.

The Company shall maintain virtual currency exchange transaction tickets for each virtual currency exchange transaction, regardless of amount, and shall include the prescribed information applicable to the transaction.

Where the Company becomes subject to electronic funds transfer, large virtual currency transaction or other prescribed transaction record requirements, it shall maintain all required information.

18.4 Regulatory Reporting Records

The Company shall retain copies of reports submitted to FINTRAC and the associated information required by law.

This shall include STRs, Large Virtual Currency Transaction Reports, Electronic Funds Transfer Reports, Listed Person or Entity Property Reports and any Large Cash Transaction Reports that may arise notwithstanding the Company’s no-cash policy.

The Company shall also retain submission confirmations, report reference numbers, corrections, amendments, internal review records and supporting documentation.

Access to STRs and related internal analysis shall be restricted because of their sensitive and confidential nature.

18.5 Compliance and Governance Records

The Company shall retain this Policy and prior versions, procedures, enterprise-wide risk assessments, customer risk methodologies, training materials and records, effectiveness-review plans and reports, management information, senior officer approvals, remediation records and regulatory correspondence.

It shall also retain records of transaction monitoring alerts, blockchain analytics reviews, sanctions screening, internal unusual activity reports, reporting decisions, no-file decisions and relevant management approvals.

Records shall permit the Company to demonstrate that its documented programme is implemented in practice.

18.6 Retention Period

Required records shall be retained for at least the period prescribed by applicable law.

Unless a different statutory calculation applies, the Company shall generally retain required AML/ATF records for at least five years from the relevant transaction, creation, submission, account closure, termination of the business relationship or other prescribed event.

Where another legal, regulatory, contractual, litigation or investigation requirement requires a longer retention period, the longer period shall apply.

The Company shall maintain a separate record-retention schedule identifying the applicable retention trigger for each category of record.

FINTRAC’s MSB guidance prescribes a minimum five-year retention period for numerous transaction records, including virtual currency transfer, receipt and exchange records.

18.7 Format and Integrity

Records may be maintained electronically, provided that they remain complete, secure, readable and capable of being reproduced in paper form.

The Company shall implement appropriate controls to protect records against unauthorised access, alteration, deletion, corruption, loss or destruction.

Records shall be subject to access controls, backup, recovery and audit-trail arrangements proportionate to their sensitivity.

The Company shall ensure that material decisions and reviews are not recorded solely in informal or temporary communication channels that cannot be reliably retained and retrieved.

18.8 Retrieval and Regulatory Access

Records shall be organised in a manner that enables them to be located and produced promptly.

The Company shall be capable of providing required records to FINTRAC within 30 days of a request.

Requests from FINTRAC, law enforcement or another competent authority shall be coordinated by the Compliance Officer or another authorised person.

The Company shall verify the authority and scope of a request where appropriate and shall preserve the confidentiality of the request and the information produced.

18.9 Records Held by Employees and Service Providers

Where an employee, contractor, agent or service provider maintains records on behalf of the Company, the Company shall ensure that it retains ownership, access and control of those records.

Before the relevant employment, engagement or service arrangement ends, the Company shall obtain all records required to be retained on its behalf.

FINTRAC guidance expressly provides that the reporting entity must obtain and retain records held by an employee or contractor before the employment or contractual relationship ends.

The Company shall not rely on a terminated service provider to satisfy its continuing legal obligations.

18.10 Record Destruction

Records shall not be destroyed before the applicable retention period has expired or while they are subject to a legal hold, regulatory request, investigation, litigation or remediation exercise.

At the end of the retention period, records shall be destroyed securely and in accordance with applicable privacy, information security and records-management requirements.

19. AGENTS, OUTSOURCING AND THIRD-PARTY SERVICE PROVIDERS

19.1 General Principle

The Company may engage agents, mandataries, contractors and third-party service providers to support its business and compliance activities.

Such arrangements may include identity verification, screening, payment processing, banking, custody, hosted wallet infrastructure, blockchain analytics, transaction monitoring, travel-rule messaging, cloud hosting, customer support and regulatory reporting support.

The use of a third party does not reduce or transfer the Company’s legal responsibility for compliance with the PCMLTFA, the applicable regulations or this Policy.

The Company remains accountable for determining whether its obligations have been satisfied and for the completeness, accuracy and timeliness of reports submitted on its behalf.

19.2 Pre-Appointment Due Diligence

Before appointing a material service provider or agent, the Company shall conduct due diligence proportionate to the nature, significance and risk of the proposed service.

The review shall consider the provider’s ownership, management, reputation, regulatory status, jurisdiction, experience, technical competence, financial stability, information security, business continuity, compliance framework and history of material regulatory or legal issues.

Where the provider will perform customer identification, transaction monitoring, sanctions screening, blockchain analytics, custody, wallet or reporting functions, the Company shall assess whether the provider’s methodology and systems are appropriate for the Company’s legal obligations and business model.

The Company shall not appoint a provider solely because it is widely used or commercially convenient.

19.3 Written Agreements

Material outsourcing and agency arrangements shall be governed by written agreements.

The agreement shall clearly describe the services, responsibilities, performance standards, information requirements, escalation arrangements, confidentiality obligations, record-keeping responsibilities and rights of access.

Where relevant, the agreement shall require the provider to comply with applicable AML/ATF requirements and the Company’s policies, maintain adequate systems and trained personnel, notify the Company of material incidents or deficiencies and cooperate with audits, reviews and regulatory requests.

The agreement shall also address subcontracting, data ownership, information security, business continuity, termination assistance and the return or transfer of Company records.

19.4 Oversight and Monitoring

The Company shall monitor material service providers and agents on an ongoing basis.

Oversight may include service-level reporting, sample testing, quality assurance, incident review, due diligence refresh, audit reports, control attestations and review of regulatory developments affecting the provider.

The scope and frequency of monitoring shall reflect the importance of the service and the risks identified.

The Company shall not assume that the existence of a contract is sufficient evidence that the provider is performing the required controls effectively.

Where deficiencies are identified, the Company shall require remediation, impose additional controls, restrict the provider’s role or terminate the arrangement where necessary.

19.5 Customer Identification and Verification Providers

Where the Company uses a service provider to support customer identification or verification, it shall understand the verification method used, the sources relied upon and the evidence generated.

The Company shall determine whether the method satisfies applicable Canadian requirements and shall retain access to the information required to demonstrate compliance.

An automated pass result shall not prevent the Company from undertaking further review where the customer, document, device, behaviour or surrounding circumstances present risk indicators.

19.6 Transaction Monitoring and Blockchain Analytics Providers

Where the Company relies on an external transaction monitoring or blockchain analytics provider, it shall understand the scope, coverage, methodology and material limitations of the service.

The Company shall determine whether supported assets, networks, risk categories, data sources and alert logic are appropriate to its business.

The provider’s alert, rating or classification shall support, but shall not replace, the Company’s own judgement and reporting decision.

The Company shall maintain procedures for managing service outages, incomplete coverage, false positives, false negatives, data-quality issues and material methodology changes.

19.7 Reporting Service Providers

A service provider may prepare, submit or correct reports to FINTRAC on the Company’s behalf where legally and operationally appropriate.

The Compliance Officer must retain sufficient oversight to approve reporting decisions and ensure that reports are complete, accurate and timely.

The Company shall maintain direct access to submission records, confirmations, reference numbers and report content.

FINTRAC guidance makes clear that although a service provider may submit and correct an STR on behalf of a reporting entity, the legal responsibility remains with the reporting entity and cannot be delegated.

19.8 Information Security and Confidentiality

Service providers shall be given access only to the information necessary to perform their authorised functions.

The Company shall assess the security, privacy and confidentiality risks associated with sharing customer, transaction, wallet, screening or reporting information.

STRs and internal suspicious activity information shall not be disclosed to a service provider unless the disclosure is necessary, lawful and subject to appropriate confidentiality and access controls.

19.9 Business Continuity and Exit

The Company shall maintain contingency arrangements for the failure, disruption or termination of a material service provider.

The arrangements shall address continued access to customer and transaction records, alternative processing or monitoring, regulatory reporting continuity, security of customer assets and transition to another provider.

Before termination, the Company shall ensure that all required records, data, configurations, reports and evidence are returned or made accessible in a usable format.

19.10 Agents and Mandataries

Where the Company appoints agents or mandataries to conduct activities on its behalf, it shall document their role and include them within the scope of the compliance programme where required.

Agents and mandataries shall receive appropriate training, follow the Company’s procedures, maintain required records and escalate unusual or suspicious activity promptly.

The Company shall monitor their compliance and shall include relevant agency arrangements and records within the scope of the two-year effectiveness review where appropriate. FINTRAC specifically identifies review of agent or mandatary agreements and customer-identification records as a relevant component of effectiveness testing.

20. AML/ATF TRAINING PROGRAMME

20.1 Purpose of Training

The Company shall maintain a written and ongoing anti-money laundering and anti-terrorist financing training programme designed to ensure that all relevant personnel understand the legal obligations applicable to the Company, the financial crime risks arising from its business model and the controls they are required to operate.

The Company shall ensure that persons performing relevant functions are able to recognise unusual or suspicious activity, understand when and how to escalate concerns and appreciate the consequences of failing to comply with applicable requirements.

20.2 Persons Required to Receive Training

Training shall be provided to employees, officers, contractors, agents, mandataries and other persons authorised to act on behalf of the Company where their duties may affect the Company’s compliance with the PCMLTFA, the applicable regulations or this Policy.

The scope and depth of training shall be tailored to the individual’s role. Personnel involved in customer onboarding, customer support, payment processing, wallet operations, transaction monitoring, sanctions screening, compliance, reporting, technology, product development, senior management and oversight functions shall receive training relevant to their responsibilities.

Directors and Senior Officers shall receive sufficient training to understand the Company’s principal financial crime risks, the operation of the compliance programme, the significance of regulatory reporting and their governance and oversight responsibilities.

20.3 Training Content

The training programme shall cover applicable AML/ATF legal and regulatory requirements, the Company’s policies and procedures, customer due diligence, beneficial ownership, ongoing monitoring, sanctions screening, suspicious transaction reporting, record keeping and the financial crime risks associated with virtual currency services. Personnel shall receive training relevant to their responsibilities and any systems or tools used in their role.

20.4 Induction and Role-Based Training

Relevant personnel shall complete appropriate AML/ATF training before performing regulated or compliance-sensitive duties without supervision.

Where a person changes role or assumes additional responsibilities, the Company shall assess whether further role-specific training is required before the new duties are performed.

20.5 Refresher and Event-Driven Training

Relevant personnel shall receive refresher training at least annually.

Additional training shall be provided where there is a material change in legal requirements, Company procedures, products, services or identified financial crime risks.

20.6 Training Delivery and Assessment

Training may be delivered through a variety of methods, including instructor-led sessions, online learning and practical exercises. The Company may assess training effectiveness through testing, quality assurance reviews or other appropriate means.

20.7 Training Plan and Records

The Compliance Officer shall maintain a documented training plan identifying the intended audience, subject matter, delivery method, timing, responsible trainer and expected learning outcome.

The Company shall retain records of the date of training, the persons who attended or completed it, the content delivered, the method used, the trainer or provider and any assessment results.

Training records shall be sufficiently detailed to demonstrate that the programme is ongoing, role-appropriate and implemented in practice.

FINTRAC requires reporting entities to maintain a written, ongoing training programme and a documented training plan for employees, agents, mandataries and other authorised persons.

21. TWO-YEAR EFFECTIVENESS REVIEW

21.1 Requirement for Effectiveness Testing

The Company shall establish and document a plan for reviewing the effectiveness of its AML/ATF compliance programme.

An effectiveness review shall be undertaken at least every two years. Annual internal review does not replace the statutory requirement for a formal effectiveness review.

The purpose of the effectiveness review is to determine whether the compliance programme is appropriately designed, adequately implemented and operating effectively in practice.

21.2 Scope of the Review

The effectiveness review shall cover the mandatory elements of the compliance programme, including the appointment and responsibilities of the Compliance Officer, written policies and procedures, the enterprise-wide risk assessment, the training programme and training plan.

The review shall also test the operation of the Company’s customer due diligence, identity verification, beneficial ownership, third-party determination, business relationship, ongoing monitoring, enhanced due diligence, PEP and HIO, sanctions, transaction monitoring, blockchain analytics, travel rule, regulatory reporting and record-keeping controls.

21.3 Review Plan

Before commencing the review, the Company shall document the scope, methodology, review period and persons responsible for conducting the review.

21.4 Reviewer Competence and Independence

The review shall be conducted by a person or persons with sufficient knowledge of Canadian AML/ATF requirements, FINTRAC expectations, virtual currency risks and the Company’s business model.

As a matter of good governance, the reviewer should be independent from the day-to-day administration of the controls being tested.

21.5 Testing of Customer and Transaction Controls

The review shall assess the effectiveness of customer due diligence, transaction monitoring, sanctions controls, regulatory reporting, record keeping and other key compliance controls.

21.6 Testing of Regulatory Reports

The review shall assess the effectiveness of customer due diligence, transaction monitoring, sanctions controls, regulatory reporting, record keeping and other key compliance controls.

21.7 Findings and Report

The reviewer shall prepare a written report summarising the scope, testing performed, findings, conclusions and recommended remediation actions.

21.8 Senior Officer Reporting and Remediation

The findings of the effectiveness review, relevant policy or procedural changes and the status of implementation shall be reported in writing to the Senior Officer within 30 days after completion of the review.

Management shall consider the findings and ensure that remediation is appropriately prioritised, resourced and tracked.

The Company shall confirm that the remedial control has been implemented and is operating effectively.

FINTRAC’s compliance programme guidance requires a documented review plan, an effectiveness review at least every two years and written reporting of findings to a senior officer.

22. BREACHES, INCIDENTS AND REGULATORY ENGAGEMENT

22.1 Identification and Escalation of Breaches

Any actual or suspected breach of this Policy, the supporting procedures or applicable AML/ATF requirements shall be escalated promptly to the Compliance Officer.

A breach may include failure to verify identity, incomplete beneficial ownership information, missed or late customer reviews, inadequate transaction monitoring, delayed alert review, inaccurate or late regulatory reporting, insufficient record keeping, sanctions-control failures, unauthorised disclosure or failure to follow an approved procedure.

Personnel shall not conceal, correct informally or disregard an error without informing the appropriate control function where the matter may affect legal or regulatory compliance.

The Company shall foster a culture in which errors and concerns are reported promptly and in good faith.

22.2 Incident Assessment

The Compliance Officer shall assess the nature, scope and potential impact of any breach or incident and determine whether remediation, escalation or further review is required.

22.3 Containment and Remediation

The Company shall take prompt and proportionate action to address identified deficiencies and implement appropriate remediation measures. Material remediation activities shall be tracked to completion.

22.4 Missed, Late or Inaccurate Reports

Where the Company identifies a missed, late, incomplete or inaccurate FINTRAC report, the matter shall be escalated immediately to the Compliance Officer. Appropriate corrective action, including filing, correction or amendment, shall be completed without unnecessary delay. Material reporting deficiencies shall be documented and, where appropriate, subject to retrospective review.

22.5 Voluntary Self-Declaration of Non-Compliance

The Compliance Officer shall consider whether a material or systemic breach should be disclosed voluntarily to FINTRAC.

The decision shall take account of the nature, duration, cause and impact of the breach, the number of affected transactions or customers, the status of remediation and any applicable FINTRAC guidance.

A voluntary self-declaration shall be accurate, complete and supported by a clear remediation plan.

The Company shall not delay corrective action while deciding whether voluntary disclosure is appropriate.

22.6 Regulatory Examinations and Information Requests

The Company shall cooperate with FINTRAC examinations and lawful regulatory requests. The Compliance Officer shall coordinate responses and ensure information provided is accurate, complete and timely. Records of material regulatory interactions shall be maintained.

22.7 Law-Enforcement Requests

Law-enforcement requests shall be referred promptly to the Compliance Officer and, where appropriate, legal counsel. The Company shall maintain confidentiality and comply with applicable legal requirements.

22.8 Consequences of Non-Compliance

Failure to comply with this Policy may result in disciplinary action, up to and including termination of employment or engagement, regulatory notification or other legal action where appropriate.

23. CONFIDENTIALITY, PRIVACY AND INFORMATION SECURITY

23.1 General Confidentiality

The Company shall protect AML/ATF information through appropriate confidentiality, access, privacy and information-security controls. Access shall be limited to persons requiring the information for their duties. Any loss, unauthorised disclosure, alteration or unavailability of required records shall be escalated and remediated promptly.

24. MANAGEMENT INFORMATION, GOVERNANCE REPORTING AND OVERSIGHT

24.1 Purpose of Management Information

The Company shall maintain management information sufficient to enable the Senior Officer and senior management to understand the Company’s financial crime risk profile and the effectiveness of the compliance programme.

Management information shall be accurate, timely, proportionate and capable of supporting informed decisions.

24.2 Periodic Compliance Reporting

The Compliance Officer shall provide periodic reports to the Senior Officer and, where applicable, the Board or relevant governance committee.

Reports shall include material changes in the Company’s risk profile, compliance activities, regulatory reporting, significant incidents, monitoring outcomes and remediation activities.

24.3 Reporting of Regulatory Reports

Management information shall include the number and type of reports submitted to FINTRAC, the timeliness of submission, material corrections or rejections and any potential missed-reporting issues.

Where the Company has submitted no STRs or other reports over a material period, the Compliance Officer shall consider whether this is consistent with the Company’s risk profile and transaction activity.

24.4 Material Escalation

Material compliance matters shall be escalated promptly and shall not wait for the next scheduled report.

Matters requiring immediate or expedited escalation may include confirmed sanctions matches, listed property, suspected terrorist activity financing, systemic monitoring failure, significant underreporting, loss of required records, material cyber incidents, serious employee misconduct, regulatory examination findings or circumstances presenting significant legal or reputational risk.

24.5 Oversight of Remediation

Senior management shall oversee the remediation of material compliance deficiencies and ensure that corrective actions are completed within an appropriate timeframe.

24.6 Records of Governance

The Company shall retain records of material compliance reports, meeting papers, minutes, decisions, approvals, challenges and remediation oversight.

25. POLICY REVIEW, APPROVAL AND DOCUMENT CONTROL

25.1 Annual Review

This Policy shall be reviewed at least annually and whenever necessary to reflect changes in applicable law, regulatory requirements, the Company's business activities or financial crime risks.

The review and any resulting amendments shall be documented.

25.2 Event-Driven Review

The Policy shall also be reviewed following any material change to the Company's business, products, services, systems, regulatory requirements or risk profile.

The Compliance Officer shall determine whether amendments to the Policy, procedures or training programme are required.

25.3 Approval

This Policy and all material amendments shall be approved by a Senior Officer.

The approval record shall identify the version, effective date and review date.

25.4 Communication and Implementation

The Compliance Officer shall ensure that material amendments are communicated to relevant personnel and that any required updates to procedures, controls or training are implemented.

25.5 Version Control

The Company shall maintain a version history recording the date, nature and approval of material amendments.

Superseded versions shall be retained in accordance with the Company’s record-retention requirements.

25.6 Exceptions

Exceptions to this Policy shall be rare, lawful and supported by a documented risk assessment.

No exception may waive or reduce a mandatory statutory or regulatory requirement.

Any permitted exception shall be approved at an appropriate level, subject to defined conditions and retained as part of the relevant compliance record.