Anti-Money Laundering and Anti-Terrorist Financing Policy

Payoro Finance Ltd., 300 – 22420 Dewdney Trunk Road, Maple Ridge, British Columbia, V2X 3J5

1.0 Policy Details

1.1 Document Objective

The objective of this document is to establish and communicate PAYORO FINANCE LTD.’s Anti-Money Laundering and Anti-Terrorist Financing (AML/ATF) framework in accordance with the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its associated regulations in Canada.

This policy defines the standards, controls, and responsibilities required to detect, prevent, and report money laundering (ML), terrorist financing (TF), sanctions evasion, and related financial crimes. It outlines the company’s approach to:

  • Assessing and documenting inherent and residual ML/TF risks associated with its products, services, clients, delivery channels, and geographic exposure.
  • Implementing mitigation measures to reduce those risks to an acceptable level.
  • Maintaining policies, procedures, and internal controls to ensure full compliance with Canadian regulatory expectations.
  • Ensuring that new technologies, business models, and delivery channels are evaluated for ML/TF risks before deployment.
  • Providing clear accountability for senior management oversight, chief compliance officer responsibilities, and periodic review of the AML/ATF program.

The goal is to maintain an effective, risk-based compliance program that protects PAYORO FINANCE LTD. from being used for illicit activity and ensures that all regulatory obligations under FINTRAC regulations are met.

1.2 Scope & Applicability

This AML/ATF Policy applies to PAYORO FINANCE LTD. (“Payoro”) and all business units, brands, delivery channels, employees, contractors, agents and service providers involved in activities that may expose Payoro to money laundering, terrorist financing, sanctions evasion or related financial crime risk.

The policy covers operations conducted under Payoro’s Canadian Money Services Business registration and applies to services delivered directly by Payoro or through Payoro-operated, white-label, branded or partner-facing interfaces, subject in each case to applicable legal-entity disclosures and regulatory requirements.

This policy applies to all Payoro activities, including but not limited to:

  • Virtual currency exchange services, including the exchange of fiat currency for virtual currency, virtual currency for fiat currency, and, where supported, one virtual currency for another virtual currency;
  • Virtual currency transfer services, including sending virtual currency from a Client’s Payoro-hosted balance to the Client’s own external wallet or to an approved third-party beneficiary wallet at the Client’s instruction;
  • Hosted wallet and custodial virtual currency services, including the holding, safeguarding, internal allocation, withdrawal and transfer of Supported Virtual Currency acquired through Payoro or otherwise credited through approved Payoro-controlled product flows;
  • Money transmission, remittance, foreign exchange and account-based payment facilitation through regulated banking, payment-service and electronic money institution partners;
  • Fiat funding and payout services for individual and business clients, including bank transfer, payment card and other approved fiat funding methods;
  • Client onboarding, identity verification, beneficial ownership, sanctions and PEP screening, blockchain analytics and transaction monitoring; and
  • Regulatory reporting, record keeping, Travel Rule compliance and other obligations arising under Canadian AML/ATF law.

The policy applies to all client relationships, counterparties and transactions regardless of channel or geography, subject to Payoro’s Country Acceptance Policy, Industry Acceptance Policy, sanctions obligations and product-specific risk controls.

This policy forms part of Payoro’s broader compliance framework and should be read together with the Risk Assessment Framework, Record Keeping and Audit Policy, Transaction Monitoring Policy, Country Acceptance Policy, sanctions controls, safeguarding framework where applicable, and AML Compliance Training Program.

1.3 Governance & Compliance Oversight

PAYORO FINANCE LTD. maintains a formal governance framework to ensure effective oversight of its Anti-Money Laundering and Anti-Terrorist Financing (AML/ATF) program. Senior management and the appointed Chief Compliance Officer share responsibility for establishing, maintaining, and monitoring a robust compliance regime that meets regulatory expectations in Canada.

1.3.1 The Board of Directors/Senior Management

The Board of Directors and Senior management provide strategic direction and oversight to ensure that the AML/ATF program remains effective, adequately resourced, and integrated across all business lines. Their responsibilities include:

  • Approving the AML/ATF policy, risk assessment, and related procedures prior to implementation and upon each significant revision;
  • Ensuring sufficient human, technological, and financial resources are dedicated to AML/ATF compliance;
  • Reviewing regular compliance reports outlining monitoring results, reporting statistics, and remediation activities;
  • Overseeing the prompt correction of deficiencies identified through audits, internal reviews, or regulatory examinations; and
  • Promoting a strong compliance culture that emphasizes integrity, accountability, and regulatory adherence at all levels of the organization.

1.3.2 Chief Compliance Officer Responsibilities

The Chief Compliance Officer, formally appointed by senior management, has full responsibility for developing and maintaining the AML/ATF program. Specific duties include:

  • Designing and updating the AML/ATF policies, procedures, and internal controls in accordance with the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and its associated Regulations;
  • Overseeing the effectiveness of client due diligence, record-keeping, and reporting processes, while delegating operational tasks to qualified compliance and operations personnel;
  • Testing that appropriate systems, controls, and staffing in place to identify, assess, and mitigate ML/TF and sanctions risks across all business lines;
  • Developing and approving the company’s enterprise-wide risk assessment, as well as any subsequent updates due to product, service, or technology changes;
  • Acting as the primary liaison with FINTRAC, and law enforcement or regulatory agencies;
  • Overseeing the development and delivery of AML/ATF training programs for staff, management, and contractors;
  • Receiving and reviewing reports of material compliance breaches, internal audit findings, or regulatory communications, and ensuring timely remediation; and
  • Providing regular compliance reports and updates to senior management and the Board summarizing risk exposure, regulatory changes, and program performance.

The Chief Compliance Officer has unrestricted authority to access all information, records, systems, and personnel necessary to carry out oversight and testing duties effectively and independently.

1.3.3 Compliance Staff

The Compliance Team supports the Compliance Officer in implementing and maintaining PAYORO FINANCE LTD.’s AML/ATF program. Compliance team members perform day-to-day operational tasks under the direction of the Compliance Officer, ensuring that the company’s obligations under Canadian law are met consistently and effectively.

The Compliance Team is responsible for:

  • Conducting client onboarding due diligence, including verification, screening, and documentation in accordance with approved procedures;
  • Performing ongoing transaction monitoring and identifying unusual or potentially suspicious activity for escalation;
  • Preparing and submitting required regulatory reports such as Suspicious Transaction Reports (STRs), Large Virtual Currency Transaction Reports (LVCTRs), and equivalent filings;
  • Maintaining accurate and complete records in accordance with record-keeping and retention requirements;
  • Escalating any compliance concerns, operational issues, or detected breaches promptly to the Chief Compliance Officer; and
  • Assisting with internal and external reviews, audits, and examinations as directed.

All compliance staff must complete AML/ATF training appropriate to their role and remain current on relevant regulatory developments, internal policies, and typologies affecting PAYORO FINANCE LTD.’s business model. Staff are expected to perform their duties with integrity, independence, and diligence at all times.

1.3.4 All Staff

All PAYORO FINANCE LTD. employees, agents, contractors, and third-party representatives share responsibility for supporting the company’s Anti-Money Laundering and Anti-Terrorist Financing (AML/ATF) program. Each employee, regardless of position or function, must understand the regulatory obligations relevant to their role and act in accordance with the company’s compliance policies and procedures.

Staff are expected to:

  • Complete AML/ATF training upon hiring and participate in mandatory refresher training at least annually, or more frequently as required by regulatory changes or business developments;
  • Apply due diligence when interacting with clients, counterparties, and transactions to identify potential indicators of money laundering, terrorist financing, or sanctions evasion;
  • Promptly escalate any unusual, suspicious, or non-compliant activity to the Compliance Team or Chief Compliance Officer through established reporting channels;
  • Maintain the confidentiality of all compliance-related information and client data; and
  • Cooperate fully with internal investigations, independent reviews, and regulatory examinations.

Failure to adhere to AML/ATF policies, procedures, or training requirements may result in disciplinary action, up to and including termination of employment. Compliance is a condition of employment at PAYORO FINANCE LTD., and all staff are expected to contribute to a culture of compliance, integrity and regulatory accountability.

1.4 Definitions

For the purpose of this policy, the following definitions apply:

Anti-Money Laundering (AML): The set of laws, regulations, and internal controls designed to detect, prevent, and report money laundering and terrorist financing activities.

Beneficial Ownership: The natural person or persons who ultimately own or control a client or on whose behalf a transaction is conducted. This includes any individual who directly or indirectly owns or controls 25% or more of a corporation or other legal entity, or who exercises ultimate effective control through ownership interests, voting rights, or other means.

Business Relationship: A relationship established between PAYORO FINANCE LTD. and a client when two or more transactions requiring identification occur, or when an account, service, or ongoing arrangement is opened or maintained with the expectation of continuity. For the purposes of this policy, all ongoing service arrangements with individual or business clients constitute a business relationship.

Anti-Terrorist Financing (ATF): Measures and controls implemented to detect, prevent, and report the movement or use of funds intended to support terrorist acts or organizations.

Client Due Diligence (CDD): The process of identifying and verifying the identity of clients, understanding the purpose and intended nature of a business relationship, and assessing the risk of money laundering, terrorist financing, or sanctions evasion.

Enhanced Due Diligence (EDD): Additional verification and monitoring measures applied to high-risk clients, products, or transactions to better understand the source of funds, the nature of activity, and the legitimacy of relationships.

Financial Action Task Force (FATF): The intergovernmental body that sets international standards and promotes effective implementation of legal, regulatory, and operational measures for combating money laundering, terrorist financing, and the financing of proliferation of weapons of mass destruction. FATF’s recommendations form the foundation of Canada’s AML/ATF regulatory frameworks and are used by PAYORO FINANCE LTD. as a reference for maintaining alignment with global best practices.

FINTRAC: The Financial Transactions and Reports Analysis Centre of Canada, Canada’s financial intelligence unit (FIU) responsible for ensuring compliance with the PCMLTFA and associated regulations.

Global Affairs Canada (GAC): The federal department responsible for administering and enforcing Canada’s economic sanctions regime, including measures imposed under the United Nations Act, Special Economic Measures Act (SEMA), and the Justice for Victims of Corrupt Foreign Officials Act (JVCFOA). GAC issues and maintains Canada’s Consolidated Autonomous Sanctions List, which forms part of PAYORO FINANCE LTD.’s sanctions screening process.

Inherent Risk: The level of exposure to ML/TF/sanctions risk that exists in the absence of any mitigating controls. Inherent risk reflects the natural vulnerabilities associated with a product, service, client type, delivery channel, and geographic or sanctions exposure.

Ministerial Directive: Directives issued by the Minister of Finance under Part 1.1 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) requiring reporting entities to apply specific countermeasures to transactions or relationships involving designated jurisdictions, individuals, or entities. Ministerial Directives are issued when certain jurisdictions or activities are determined to pose a significant risk of money laundering or terrorist financing.

Money Laundering: As defined under the Criminal Code and the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), money laundering is the process used to disguise, or attempt to disguise, the source, nature, or ownership of funds or assets derived from criminal or illicit activity. Money laundering typically occurs in three stages:

  • Placement: The introduction of illicit funds into the financial system.
  • Layering: The movement or conversion of funds through multiple transactions or assets to obscure their origin.
  • Integration: The reintroduction of laundered funds into the legitimate economy, often appearing as clean, lawful proceeds.

Money Services Business (MSB): A person or entity engaged in money transmission, foreign exchange dealing, or the exchange or transfer of virtual currencies, as defined by the PCMLTFA.

National Risk Assessment (NRA): A comprehensive assessment conducted by FINTRAC and the Department of Finance that identifies and evaluates the money laundering and terrorist financing risks affecting Canada’s financial system. PAYORO FINANCE LTD. uses the NRA as a foundational input when determining its own enterprise-level risks and control priorities.

Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA): The principal federal legislation in Canada that establishes the AML/ATF regulatory framework and defines the compliance obligations of reporting entities.

Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations (PCMLTFR): The supporting regulations under the PCMLTFA that prescribe detailed compliance requirements, including record-keeping, reporting, and the specific factors that must be considered in conducting a risk assessment.

Residual Risk: The level of money laundering (ML), terrorist financing (TF), or sanctions risk that remains after mitigating controls have been applied. Residual risk represents PAYORO FINANCE LTD.’s remaining exposure once policies, procedures, monitoring systems, and other control measures have been implemented and assessed for effectiveness.

Sanctions Evasion: The deliberate act of concealing, facilitating, or attempting to conduct transactions that circumvent economic or trade sanctions imposed under Canadian or international law.

Sanctions Screening: The process of reviewing clients, transactions, and counterparties against global sanctions, watchlists, and law enforcement databases to identify potential exposure to prohibited or restricted activities.

Terrorist Financing: As defined in the Criminal Code of Canada and recognized by FINTRAC, terrorist financing refers to the use or movement of funds or assets, whether legally or illegally obtained, with the intention of supporting terrorist activities or organizations. Funds may originate from legitimate sources such as donations or commercial operations, or from criminal activities including drug trafficking, smuggling, or other predicate offences. Terrorist financing can mimic the money laundering process, using similar channels to conceal the origin, destination, or intended purpose of funds.

Virtual Asset (VA): A digital representation of value that can be used for payment, investment, or transfer and is not considered legal tender.

Custodial or Hosted Virtual Currency Wallet: A wallet service in which Payoro or an approved custody provider controls or participates in control of the cryptographic keys or transaction-authorisation process and records the client’s entitlement to supported virtual currency through Payoro’s systems and internal ledger.

Custody: The safeguarding, holding, administration or control of virtual currency for or on behalf of a client, whether directly by Payoro or through an approved third-party custody provider. Custody may use omnibus, segregated, hot, warm or cold wallet structures, provided that client entitlements are accurately recorded and reconciled.

Internal Ledger Representation: An internal accounting or settlement entry, including a denomination such as vBTC, used to record value, transaction status or client entitlement within Payoro’s systems. An internal ledger representation is not itself a blockchain token or separately transferable virtual currency. Depending on the product and transaction stage, it may reflect either a temporary settlement value or a client entitlement to underlying virtual currency held in custody.

Stablecoin: A virtual asset designed to maintain a reference value to a fiat currency, commodity or other asset or basket of assets. A stablecoin may be supported by Payoro only after legal, compliance, technology and risk approval and is treated according to its applicable legal and regulatory classification.

Supported Virtual Currency: Bitcoin and any other cryptocurrency, token, stablecoin or virtual asset that Payoro has approved for a particular service following legal, compliance, sanctions, technology, custody, liquidity and financial-crime risk assessment.

Virtual Currency (VC): A digital representation of value that falls within the applicable Canadian definition of virtual currency and may be exchanged, transferred or used for payment or investment purposes. For purposes of this policy, the term includes Bitcoin and other Supported Virtual Currencies where applicable.

2.0 Business Model

2.1 Business Model Brief

This section provides an overview of PAYORO FINANCE LTD., doing business as “Payoro”, its business model, products, and operational structure to establish the foundation for its risk assessment and compliance framework. Understanding the company’s services, delivery channels, and client base is essential to identifying and managing inherent and residual risks associated with money laundering, terrorist financing, and sanctions evasion.

2.1.1 Services

Payoro operates as a digital money services business providing fiat and virtual currency services to individuals and legal entities. Payoro’s services may include money transmission, remittance, foreign exchange, payment facilitation, virtual currency exchange, virtual currency transfer, and hosted wallet and custodial virtual currency services.

Payoro’s virtual currency exchange services may include:

  • Buying virtual currency from, or selling virtual currency to, clients against fiat currency;
  • Exchanging fiat currency for virtual currency and virtual currency for fiat currency;
  • Where approved and supported, exchanging one virtual currency for another virtual currency, including transactions involving stablecoins;
  • Executing exchange transactions as principal against Payoro inventory or through approved liquidity providers and execution counterparties.

Payoro’s virtual currency transfer and custody services may include:

  • Providing one or more hosted virtual currency wallets in which Clients can hold, track, manage, send and withdraw Supported Virtual Currency acquired through Payoro or otherwise credited through approved Payoro-controlled product flows;
  • Sending virtual currency from a Client’s Payoro-hosted balance to the Client’s own external wallet or to a third-party beneficiary wallet at the Client’s instruction, subject to applicable controls;
  • Holding Supported Virtual Currency in custody directly or through approved custody providers using appropriate hot, warm and cold storage arrangements;
  • Using omnibus or segregated wallet structures and internal sub-ledgers, provided client entitlements and proprietary assets are distinguishable in Payoro’s books and records and reconciled in accordance with applicable procedures.

Bitcoin is expected to be a principal Supported Virtual Currency, but Payoro is not limited to Bitcoin. Other cryptocurrencies and stablecoins may be supported from time to time following documented product approval and risk assessment. Asset support may be limited, suspended or withdrawn where required by law, sanctions, technology, custody, liquidity, financial-crime risk or counterparty constraints.

Payoro may use internal ledger denominations, including vBTC or equivalent representations, for operational, reconciliation, custody-accounting or settlement purposes. Such ledger entries do not constitute separately issued virtual currencies. The legal and operational nature of a ledger entry depends on the underlying product: it may evidence a custodial client entitlement to underlying virtual currency or may function solely as a temporary settlement representation pending execution or conversion.

Payoro’s fiat services are delivered through regulated banking, payment and electronic money institution partners. Where Payoro performs retail payment activities involving electronic funds transfers in fiat currency that fall within the Retail Payment Activities Act (RPAA), Payoro applies the applicable Bank of Canada registration, operational-risk and safeguarding requirements. Virtual currency exchange, transfer and custody activities are assessed separately under the applicable AML/ATF and other legal frameworks.

Payoro does not provide securities, derivatives, investment-management or portfolio-management services unless separately authorised and approved. New products, assets and delivery channels must complete legal, regulatory, AML/ATF, sanctions, operational and technology review before launch.

2.1.3 Registrations and Licensing

Payoro is registered as a Money Services Business (MSB) with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) under registration number M23010441. Payoro maintains its FINTRAC registration information so that it accurately reflects the MSB services it provides, including dealing in virtual currency, remitting or transmitting funds and foreign exchange activities where applicable.

For purposes of the PCMLTFA framework, dealing in virtual currency includes virtual currency exchange services and virtual currency transfer services. Payoro’s AML/ATF controls therefore apply to fiat-to-virtual-currency, virtual-currency-to-fiat, approved virtual-currency-to-virtual-currency transactions, and transfers of virtual currency at a client’s request or for remittance to a beneficiary.

FINTRAC registration is distinct from registration or supervision under the Retail Payment Activities Act. Where Payoro performs in-scope retail payment activities involving electronic funds transfers in fiat currency, Payoro maintains or obtains the required Bank of Canada registration and complies with applicable RPAA obligations, including operational-risk, incident-response and end-user-funds safeguarding requirements where those requirements apply.

Payoro ensures that all registrations, filings and renewals remain current and accurate. Material changes to ownership, business activities, services, asset support, payment functions or operational structure that may affect a registration or regulatory filing are assessed and reported within applicable timeframes.

The Chief Compliance Officer is responsible for coordinating regulatory-registration updates with senior management and legal counsel and for ensuring that the AML/ATF program reflects Payoro’s current products and services before material new activities are launched.

2.2 Commitment

Payoro is committed to maintaining the highest standards of integrity and regulatory compliance in all aspects of its operations. Payoro recognizes that strong Anti-Money Laundering and Counter-Terrorist Financing (AML/ATF) controls are essential to protecting the integrity of the financial system and maintaining the trust of clients, partners, and regulators.

Payoro will comply with all applicable laws, regulations, and guidance issued by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC). In particular, Payoro’s AML/ATF program is developed and maintained in accordance with:

  • The Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its associated Regulations;
  • The Criminal Code of Canada, as it relates to money laundering and terrorist financing offences; and
  • Canadian sanctions legislation, including the United Nations Act, the Special Economic Measures Act (SEMA), and the Justice for Victims of Corrupt Foreign Officials Act (JVCFOA).

All employees, officers, and contractors are expected to uphold this commitment by adhering to the company’s AML/ATF policies and procedures, reporting any suspicious or non-compliant activity, and participating in regular training designed to maintain awareness of regulatory obligations and emerging risks.

2.3 Non-Compliance

Payoro maintains a zero-tolerance approach to non-compliance with Anti-Money Laundering and Anti-Terrorist Financing (AML/ATF) obligations. Compliance with all applicable laws, regulations, and internal policies is mandatory for all directors, officers, employees, contractors, and agents.

Failure to comply with this policy, related procedures, or any regulatory requirement under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), or associated legislation may expose Payoro and its personnel to significant legal, regulatory, and reputational consequences.

Non-compliance may result in:

  • Internal disciplinary action, up to and including termination of employment or contract;
  • Mandatory reporting of the breach to regulatory authorities, where required; and
  • Civil or criminal penalties imposed under applicable Canadian law, including potential fines, Administrative Monetary Penalties (AMPs) under the PCMLTFA, or prosecution.

Payoro acknowledges that FINTRAC may impose Administrative Monetary Penalties for non-compliance which classifies violations as minor, serious, or very serious, and considers both severity and recurrence in determining the appropriate penalty.

All employees are required to promptly report suspected or actual breaches of this policy or related procedures to the Compliance Officer. Reports will be handled confidentially to the extent permitted by law and investigated in accordance with internal escalation and corrective-action procedures.

2.3.1 Voluntary Self Disclosure of Non-Compliance

Payoro may voluntarily self-disclose instances of non-compliance with AML/ATF regulatory requirements to FINTRAC or other competent authorities, where appropriate.

Non-compliance may include breaches of regulatory obligations, deficiencies in internal controls, failures in reporting, or other compliance gaps identified through internal reviews, testing, or day-to-day operations.

Where non-compliance is identified, Payoro:

  • Assesses the nature, scope, and potential impact of the issue, including any regulatory or reporting implications;
  • Takes appropriate steps to contain and remediate the issue;
  • Documents the root cause, affected transactions or clients, and corrective actions taken; and
  • Determines whether voluntary self-disclosure is warranted based on materiality, severity, and regulatory expectations.

Where a voluntary self-disclosure is made, it must include a clear description of the issue, its impact, and remediation measures implemented.

All instances of non-compliance and related decisions regarding self-disclosure are documented and retained in accordance with Payoro’s record keeping requirements.

3.0 Risk Assessment Framework

Payoro maintains a comprehensive risk assessment framework designed to identify, assess, and mitigate the risks of money laundering, terrorist financing, and sanctions evasion associated with its products, services, clients, delivery channels, and geographic exposure.

The framework forms a core component of the company’s AML/ATF compliance program and is reviewed and updated at least annually, or whenever there are material changes in Payoro’s operations, products, technology, or regulatory environment.

The purpose of the risk assessment framework is to:

  • Identify inherent ML/TF risks relevant to Payoro’s business activities;
  • Evaluate the effectiveness of existing controls and determine residual risk;
  • Ensure that identified risks are mitigated through proportionate measures; and
  • Support informed decision-making by management on resource allocation, risk appetite, and ongoing monitoring priorities.

This framework ensures that risk management is embedded in all aspects of Payoro’s operations and that the company can demonstrate a clear, documented rationale for its risk-based approach. The results of each review are used to inform ongoing monitoring, training, and internal review activities, ensuring that Payoro’s risk-based controls remain proportionate to the nature and complexity of its business. Documentation of each review cycle, including the approval date and summary of key updates, is maintained and made available to regulators upon request.

The risk assessment framework is overseen by the Chief Compliance Officer, who is responsible for ensuring that it remains accurate, comprehensive, and aligned with applicable regulatory requirements and guidance. All updates to the risk assessment are reviewed and approved by senior management to confirm that identified risks and corresponding mitigation strategies are appropriate and effective.

The Chief Compliance Officer ensures that the methodology, supporting data, and rationale used to determine risk ratings are fully documented and retained in accordance with Payoro’s record-keeping standards.

3.1 Risk Assessment Methodology

Payoro uses a structured, multi-factor methodology that considers both inherent and residual risk exposure. Each business area is evaluated based on the following dimensions:

  1. Products and Services: The nature and purpose of each product or service, including its potential to facilitate anonymity, rapid value movement, or cross-border transactions.
  2. Clients and Business Relationships: The types of clients served (individuals, corporations, or other business entities), including their occupation, industry, ownership structure, and risk profile.
  3. Delivery Channels: The method of service delivery, such as online onboarding, reliance arrangements, or verification through partners.
  4. Geographic Exposure: The jurisdictions of clients, counterparties, and transactions, considering sanctions, corruption indices, and FATF risk assessments.
  5. New Technologies and Developments: Emerging technologies, platforms, or vendors (such as identity verification tools or blockchain analytics) that may introduce new risks or control challenges.
  6. Sanctions Exposure: The extent to which clients, transactions, or counterparties may involve jurisdictions, entities, or individuals subject to economic sanctions, including the potential for sanctions evasion through indirect ownership or complex transaction structures.

Each factor is assigned a qualitative risk rating (low, moderate, or high) based on likelihood and potential impact. Ratings are supported by documented justifications and updated as business conditions evolve.

3.2 Integration with Canada’s National Risk Assessment

Payoro incorporates Canada’s National Risk Assessment (NRA) into its risk assessment framework as an ongoing reference point for understanding national money laundering, terrorist financing, and related sanctions evasion risks. The NRA provides context on sectoral threats and vulnerabilities and supports Payoro in maintaining alignment with Canada’s national AML/ATF priorities.

Key findings from the 2025 National Inherent Risk Assessment that are particularly relevant to Payoro’s business model include:

  • Organized crime and third-party facilitators remain the primary sources of money-laundering activity in Canada.
  • Illegal drug trafficking, fraud, commercial trade fraud, and tax crimes continue to represent the highest-risk predicate offences generating illicit proceeds.
  • Money Services Businesses (MSBs) and Virtual Asset Service Providers (VASPs) are identified as sectors with high inherent vulnerability to money laundering and terrorist financing due to transaction speed, cross-border exposure, and the potential for anonymity.
  • Virtual assets and digital financial services introduce elevated risk associated with technological complexity, online delivery, and emerging products.
  • Technology-enabled fraud and cybercrime are increasing in scale and sophistication, creating additional exposure for MSBs operating online.

Payoro reviews each new NRA publication and applies its findings to inform ongoing risk identification, evaluation, and control development within its AML/ATF program.

4.0 Written Policies and Procedures

Payoro maintains comprehensive written policies and procedures that outline the measures, controls, and processes established to detect, prevent, and deter money laundering, terrorist financing, and sanctions evasion within its operations. These policies and procedures form the operational foundation of Payoro’s Anti-Money Laundering and Anti-Terrorist Financing (AML/ATF) program and are designed to ensure ongoing compliance with applicable regulatory obligations in Canada.

Payoro’s policies are:

  • Documented and approved by senior management prior to implementation;
  • Maintained and reviewed at least annually, or more frequently when material changes occur in Payoro’s business model, technology, or regulatory environment;
  • Accessible to all relevant staff and business partners; and
  • Enforced consistently across all business units.

The purpose of these policies and procedures is to:

  • Define the operational standards for compliance with AML/TF and sanctions laws;
  • Provide employees with clear instructions on identifying, escalating, and reporting suspicious or unusual activity;
  • Ensure consistent application of due diligence and record-keeping requirements; and
  • Support the effective implementation of Payoro’s risk-based approach across all service lines.

4.1 Client Due Diligence (CDD)

Payoro applies a risk-based client Due Diligence (CDD) process to identify and verify all clients, understand the purpose and intended nature of their business relationships, and monitor activity for consistency with established risk profiles. The CDD process supports the detection and deterrence of money laundering, terrorist financing, and sanctions evasion across all products and services.

Payoro establishes a business relationship when two or more transactions occur that require client identification, or when services are provided through a contract to support ongoing service delivery. Upon establishing a business relationship, the purpose and intended nature of the relationship are documented, and sufficient information is maintained to understand the client’s source of funds, expected activity, and associated risk level.

4.1.1 Identification and Verification

Payoro verifies the identity of all clients before establishing a business relationship or conducting a transaction that triggers a verification requirement. Identification and verification are completed using reliable, independent sources and documented in accordance with applicable record-keeping standards.

All identification documents and information obtained must be authentic, valid, and current. Verification must confirm that the document is genuine, has not expired, and corresponds to the individual or entity being identified. Identification and verification is required prior to accessing Payoro services.

Verification may be completed through one or more of the following methods:

  • Examination of original, government-issued photo identification with liveness captured;
  • Remote verification using third-party digital identity verification tools or dual-source electronic verification that meets regulatory standards;
  • Confirmation of existence through reliable, independent data sources for entities; and
  • Verification conducted under a formal reliance arrangement with an affiliated foreign business that is a regulated financial institution or Money Services Business (MSB) that meets Canadian and Payoro’s due diligence and enhanced measures requirements.

If Payoro relies on a regulated partner or service provider to perform identification or verification, the arrangement must be documented, and the partner must be subject to equivalent AML/ATF obligations. Payoro retains ultimate responsibility for ensuring the accuracy and adequacy of client identification.

Individuals

For individuals, the following information must be collected and verified:

  • Full legal name;
  • Date of birth;
  • Residential address;
  • Valid government-issued photo identification number and issuing jurisdiction; and
  • Occupation or principal business activity.

Entities

For corporations, partnerships, or other legal entities, the following information must be collected and verified:

  • Full legal name of the entity;
  • Business address and jurisdiction of incorporation or registration;
  • Nature of business or principal activity;
  • Confirmation of existence through public registries, government databases, or other reliable independent sources;
  • Name, date of birth, and address of authorized representatives;
  • Names and information of directors (for corporations); and
  • Identification of individuals who own or control 25% or more of the entity, or otherwise exercise effective control.

Where identification or verification cannot be satisfactorily completed, Payoro will not proceed with the transaction or establish the relationship and will consider filing a suspicious transaction report if warranted.

4.1.2 Beneficial Ownership

Payoro identifies and verifies the beneficial ownership of all entity clients to ensure transparency regarding the natural persons who ultimately own or control the client. This requirement applies to corporations, partnerships, trusts, charities, and other non-profit organizations, and aims to prevent the misuse of legal structures for money laundering, terrorist financing, or sanctions evasion.

A beneficial owner is any natural person who, directly or indirectly:

  • Owns or controls 25% or more of the corporation, partnership, or other legal entity; or
  • Otherwise exercises control through ownership interests, voting rights, agreements, or other means.

Payoro collects the following information for each identified beneficial owner:

  • Full legal name;
  • Date of birth;
  • Address (residential or business); and
  • Nature and extent of ownership or control.

Corporations and Partnerships

For corporations and partnerships, Payoro identifies all individuals who directly or indirectly own or control 25% or more of the entity or exercise significant control through voting rights or contractual arrangements.

If no individual meets the 25% threshold, Payoro records the senior managing official(s) of the entity as the beneficial owner(s) along with the reasonable measures taken to determine that no beneficial owner of 25% or more exists.

Trusts

For trusts, beneficial ownership extends to all persons with authority or benefit under the trust arrangement. Payoro identifies and verifies:

  • All trustees responsible for controlling or administering the trust;
  • The settlor, creator or contributor of trust assets; and
  • All known beneficiaries, or classes of beneficiaries, with a direct or contingent interest in the trust.

Where a trust is part of a more complex structure, such as layered ownership, Payoro obtains documentation sufficient to understand and confirm the chain of control and beneficial interest.

Charities and Non-Profit Organizations

For registered charities and non-profit entities, beneficial ownership is interpreted as control or authority rather than equity interest. Payoro identifies and verifies:

  • Individuals who direct, influence, or have decision-making authority over the organization such as directors, officers, or senior management;
  • Any founders or principal donors who exert ongoing influence over governance or operations; and
  • Any other persons who control or direct the use of the organization’s funds or assets.
4.1.2.1 Beneficial Ownership Discrepancy Reports

Payoro identifies, assesses, and reports discrepancies in beneficial ownership information in accordance with reporting material discrepancies in beneficial ownership.

A discrepancy is identified where there is a material difference between beneficial ownership information obtained through Payoro’s client due diligence processes and information available from a reliable source, including the federal corporate registry of Canada or documentation provided by the client.

Where a discrepancy is identified, Payoro:

  • Takes reasonable measures to verify the discrepancy;
  • Assesses whether the discrepancy impacts the client’s risk rating or triggers enhanced due diligence;
  • Documents the nature of the discrepancy, steps taken to resolve it, and the outcome; and
  • For federally incorporated entities under the Canada Business Corporations Act (CBCA), reports material discrepancies between Payoro’s records and the federal beneficial ownership registry (Individuals with Significant Control registry) to Corporations Canada, where required.

All beneficial ownership discrepancies and related actions are recorded and retained in accordance with Payoro’s record keeping requirements.

4.1.2.2 Verification and Recordkeeping

Reasonable measures are taken to confirm the accuracy of beneficial ownership information using reliable documentation such as:

  • shareholder registers,
  • partnership agreements,
  • trust deeds, or
  • public corporate filings.

Where verification cannot be completed, Payoro documents the steps taken, the reasons verification was not possible, and the mitigating measures applied.

Beneficial ownership information must be reviewed and updated as part of ongoing monitoring to ensure continued accuracy. All records are maintained in accordance with applicable regulatory record-keeping requirements.

4.1.3 Third-Party Determination

Payoro determines whether any client is acting on behalf of a third party when a transaction is conducted or a business relationship is established. This requirement ensures transparency regarding the true origin and purpose of funds entering or moving through Payoro’s services.

A third party is any individual or entity, other than the client, who provides instructions, directs the activity, or has a beneficial interest in the transaction or account. The determination applies to all clients, including individuals, entities, trusts, and non-profit organizations.

Payoro takes reasonable measures to determine whether a third party is involved. This includes:

  • Asking the client directly whether they are acting on behalf of another person or entity;
  • Reviewing transaction patterns and documentation for indications of third-party control or funding; and
  • Obtaining additional information when a transaction or relationship appears inconsistent with the client’s profile.

When a third party is identified or reasonably suspected, Payoro records:

  • Full legal name of the third party;
  • Address and date of birth (for individuals);
  • Nature of the relationship between the third party and the client; and
  • Occupation, business activity, or principal purpose of the third party.

Where the third party is a legal entity, Payoro collects information sufficient to confirm its existence and beneficial ownership.

If a client refuses or is unable to provide required third-party information, the relationship will not proceed, and the matter will be escalated to the Chief Compliance Officer for review and potential suspicious transaction reporting.

Third-party information is retained in accordance with record-keeping requirements and reviewed periodically as part of ongoing monitoring.

4.1.4 Client Risk Classification

Payoro assigns a risk rating to each client as part of the onboarding and due diligence process. The risk rating reflects the potential exposure of the client to money laundering, terrorist financing, or sanctions evasion based on a combination of inherent and behavioural factors.

Risk classification is determined using a documented methodology that evaluates the following:

  • Client Type and Activity: The nature of the client whether individual, business, charity, or trust and its occupation or operational activities.
  • Geographic Exposure: The client’s country of residence, registration, or transactional activity, including exposure to high-risk or sanctioned jurisdictions.
  • Products and Services Used: The types of services accessed through Payoro, including virtual currency exchange, remittance, or foreign exchange.
  • Delivery Channel: The manner in which the client interacts with Payoro including in-person, online, or through reliance partners.
  • Transaction Behaviour: Expected activity patterns, transaction volume, and frequency relative to the client’s profile and stated purpose.

Each client is assigned a risk rating of Low, Medium, or High, which determines the level of due diligence and ongoing monitoring required.

Low Risk: The client presents a low overall risk across all identified risk factors, with no high-risk indicators or prohibitive factors identified under this policy. Low risk clients are subject to standard transaction monitoring.

Medium Risk: The client presents a moderate level of risk due to the presence of elevated risk factors, such as client profile characteristics or nature of business, but without any high-risk or prohibitive factors. Medium risk clients are subject to standard transaction monitoring with a more frequent review period to confirm the accuracy of client information, assess for newly identified risks, and ensure documentation remains current.

High Risk: The client presents a high level of risk and is subject to enhanced due diligence, increased monitoring, and more frequent reassessment. High-risk classification may result from a single significant risk factor, such as connections to high-risk jurisdictions, adverse media, or complex business structures, or from the accumulation of multiple risk factors.

Clients identified as high risk are subject to Enhanced Due Diligence (EDD) measures, including:

  1. More frequent review of client information and transaction activity;
  2. Compliance Officer approval before establishing or continuing the business relationship; and
  3. Additional measures to verify source of funds or wealth.

Client risk ratings are reviewed periodically, and whenever material changes occur in a client’s profile, ownership, or transactional behaviour. Adjustments to risk ratings are documented and supported by clear rationale.

Payoro’s risk classification methodology is reviewed annually to ensure it remains current, effective, and aligned with regulatory expectations.

4.1.5 Funding Source and Payment Instrument Controls

Payoro applies risk-based controls to fiat funding sources, payment instruments, hosted wallet activity, virtual currency withdrawals and beneficiaries to ensure that activity is consistent with the Client’s identity, expected activity and risk profile.

Fiat funding may be accepted through bank accounts, payment cards, existing balances or other approved payment methods. Funding instruments should ordinarily be attributable to the Client. Third-party funding may be permitted only where supported by the relevant product and after appropriate third-party determination, fraud controls, due diligence and Compliance approval or rules-based approval.

Payoro does not accept customer deposits of virtual currency from external wallets into the exchange or hosted-wallet environment. Client virtual currency balances are established through purchases executed by Payoro, approved conversions, or other Payoro-controlled internal product flows. Outgoing transfers may be made to a Client’s own external wallet or to an approved third-party beneficiary wallet, subject to applicable controls.

Payoro may require proof of wallet ownership or control where warranted by risk, including for high-risk transactions, unusual activity, source-of-funds verification, fraud prevention or sanctions concerns.

Payoro applies blockchain analytics, sanctions screening and transaction-risk assessment to relevant virtual currency withdrawals, transfers, exchanges and custody activity. Controls may be applied before execution, before an internal custody credit becomes available, or through a combination of these methods depending on the technical flow and risk level.

Where a funding source, wallet, payment instrument, beneficiary or transaction is inconsistent with the Client’s profile or presents elevated risk, Payoro may request additional information, apply enhanced due diligence, place a temporary restriction, delay processing where lawful, reject the transaction, return funds or virtual currency where lawful and operationally possible, or terminate the relationship.

Funding-source and wallet information forms part of Payoro’s ongoing monitoring framework and may result in an updated Client risk classification or additional controls.

4.2 Ongoing Monitoring

Payoro conducts ongoing monitoring of all business relationships to ensure client information remains current and that activity is consistent with the client’s known profile and risk rating. The purpose of ongoing monitoring is to mitigate money laundering, terrorist financing, and sanctions evasion risks by detecting changes in client behaviour, maintaining accurate information, and ensuring that risk-based controls remain effective.

Ongoing monitoring at Payoro is conducted through several complementary processes designed to identify and respond to potential risk changes in real time.

4.2.1 Scheduled Reviews

All clients are subject to periodic reviews based on their risk classification.

  • High-risk clients are reviewed at least every 12 months.
  • Medium-risk clients are reviewed at least every 24 months.
  • Low-risk clients are reviewed at least every 36 months.

Scheduled reviews confirm that client identification, beneficial ownership, and third-party information remain accurate and that the client’s activity continues to align with expected patterns and declared purpose.

4.2.2 Trigger-Based Reviews

Trigger-based reviews are initiated when a defined event, change, or indicator suggests that a client’s risk profile may have increased. These reviews ensure that emerging risks are addressed promptly, even outside the normal review schedule.

Triggers include:

  • Changes in ownership, control, or authorized representatives;
  • Significant deviations from expected transaction volumes, frequency, or counterparties;
  • Adverse media, sanctions screening matches, or law enforcement inquiries;
  • Discovery of incomplete, inaccurate, or outdated client information; or
  • Expansion into new products, services, or delivery channels not previously disclosed.

4.2.3 Event-Driven Monitoring and Escalation

Payoro continuously monitors transactions and client activity using automated systems and manual review processes designed to detect patterns inconsistent with established risk profiles. When potentially suspicious or unusual activity is identified, it is escalated to the Compliance Team for review and determination of next steps.

If warranted, the Chief Compliance Officer will file a Suspicious Transaction Report (STR) or equivalent regulatory filing with FINTRAC. All findings, escalations, and resulting actions are documented and form part of the client’s compliance record.

4.3 Transaction Monitoring

Payoro conducts transaction monitoring across fiat and virtual currency activity, including exchange transactions, hosted wallet balances, custody credits, internal transfers, external withdrawals, remittance and payment activity. Monitoring is designed to identify reportable transactions, support regulatory reporting obligations, and detect indicators of money laundering, terrorist financing, sanctions evasion, fraud and misuse of custodial or transfer services.

Transaction monitoring includes the identification and assessment of:

  • Transactions with no apparent economic or lawful purpose;
  • Rapid movement of funds between accounts;
  • Transactions involving high-risk individuals, entities, or jurisdictions;
  • Repetitive or structured transaction patterns; and
  • Activity that is inconsistent with the client’s established profile.

High-risk clients are subject to enhanced transaction monitoring, including increased sensitivity thresholds and heightened consideration of identified red flags.

Payoro utilizes system-generated alerts and triggers to identify unusual activity related to fiat transactions. Reviews of high-volume and high-velocity transactions are conducted on a periodic basis to support ongoing client monitoring and reporting obligations.

Transaction monitoring activities include both automated and manual reviews. Manual reviews are conducted by the Compliance team to identify reportable transactions, assess red flags, and evaluate whether activity deviates from expected client behaviour.

Virtual currency activity is assessed using blockchain analytics and other risk data. Pre-defined and risk-based parameters generate alerts for Compliance review. Analysis may include origin and destination of funds relevant to the transaction, direct and indirect exposure, transaction velocity, chain-hopping, mixers or obfuscation services, high-risk services, sanctions exposure, smart-contract or bridge activity, stablecoin-specific risk, unusual custody-credit, conversion or withdrawal patterns, and inconsistencies between on-chain activity and the Client profile. Identified risks may result in further investigation, restrictions, enhanced due diligence or regulatory reporting where applicable.

4.3.1 Virtual Currency Know Your Transaction (KYT) Framework

Payoro applies the following factors when assessing virtual currency transactions:

  • Exposure Percentage: The proportion of transaction activity associated with identified risk exposure;
  • Transaction Volume: The amount of virtual currency involved;
  • Asset Type: Characteristics of the virtual asset, including functionality, velocity, and usage patterns;
  • Hop Radius: The proximity of the transaction to identified risk exposure, including both direct and indirect interactions; and
  • Exposure Direction: Whether the transaction involves sending or receiving funds.

Findings from these factors are assessed against the client’s economic profile to develop a source and destination of funds narrative, supporting the identification of expected activity and the assessment of potential suspicious behaviour.

4.4 Enhanced Due Diligence (EDD)

Enhanced Due Diligence (EDD) is conducted to further verify the identity, legitimacy, and risk profile of a client, business entity, or source of funds. EDD measures may be applied at onboarding or at any stage of the client relationship where elevated risk is identified.

Payoro applies Enhanced Due Diligence (EDD) measures to clients and transactions that present a higher risk of money laundering, terrorist financing, or sanctions evasion. The purpose of EDD is to ensure that risk-mitigating controls are proportional to the level of exposure identified through Payoro’s risk assessment and monitoring processes.

EDD is required when:

  • A client has been classified as high risk through the client risk assessment process;
  • A transaction or activity involves a high-risk jurisdiction, product, or delivery channel;
  • Transaction activity that is inconsistent with the client’s known profile;
  • Data inconsistencies, incomplete information, or inability to verify key details is present;
  • A client is identified as a politically exposed person (PEP), head of an international organization (HIO), or a close associate or family member of such a person; or
  • Compliance Staff determines that enhanced scrutiny is warranted based on trigger events, adverse information, or unusual activity.

Where EDD is applied, Payoro applies additional measures proportionate to the level of risk, which may include, but are not limited to:

  • Obtaining additional information on the client’s identity, ownership structure, and source of funds or wealth;
  • Verifying the accuracy of client and beneficial ownership information through independent documentation or data sources;
  • Conducting more frequent reviews of client activity and profile information;
  • Requiring Chief Compliance Officer or Senior Management approval before establishing or maintaining the relationship; and
  • Applying enhanced transaction monitoring parameters or temporary restrictions on certain activities until risk is mitigated.

Elevated Verification may include obtaining additional information or documentation to verify the identity and legitimacy of the client or business entity. This may include secondary government-issued identification, corporate documentation such as certificates of good standing, business plans, licensing information, or AML policies, where applicable.

Source of Funds and Wealth Verification may include obtaining information and supporting documentation to understand the origin of funds or wealth such as recent bank statements, financial records, or audited financial statements, as appropriate to the client profile.

Open Source Intelligence may include conducting independent research using publicly available sources to verify client information and identify potential risk indicators such as confirmation of corporate registration or licensing, review of online presence, and adverse media searches for indicators of fraud, criminal activity, or regulatory concerns.

All EDD activities are documented in the client’s compliance record, including the rationale for applying enhanced measures, the results of additional verification, and any actions taken.

The Chief Compliance Officer reviews high-risk relationships at least annually to confirm the adequacy of controls and determine whether the relationship should continue, be restricted, or be terminated.

4.5 Applicant & Client Screening

Payoro conducts applicant, client and counterparty screening to identify individuals or entities subject to Ministerial Directives, financial sanctions, politically exposed person (PEP) designations, heads of international organizations (HIOs), or other classifications that indicate heightened exposure to money laundering, terrorist financing, or sanctions evasion risk. Screening is applied to all new applicants during onboarding and to all existing clients on a continuous basis to ensure compliance with applicable Canadian regulatory requirements.

Payoro applies risk-based controls to counterparties and beneficiaries involved in transactions. Prior to executing a payout, Payoro screens counterparties against applicable sanctions lists and internal watchlists to identify potential exposure to sanctions, terrorist financing, or other prohibited activity. Payoro takes reasonable measures to validate beneficiary information, including name and account details, and to ensure consistency with the Client’s known profile and expected activity. Counterparty and beneficiary information is subject to ongoing monitoring and review as part of Payoro’s transaction monitoring and risk management framework.

Screening results are documented as part of onboarding and ongoing monitoring records. Applicants, clients, authorized representatives, and beneficial owners who match a sanctions list, are subject to a Ministerial Directive, or otherwise present a prohibited relationship are immediately declined. The case is escalated to the Chief Compliance Officer for verification and, if required, regulatory reporting.

4.6 Travel Rule Compliance

Payoro provides virtual currency exchange, outgoing transfer and custodial services and may maintain hosted virtual currency wallets and client virtual currency balances. Payoro applies the Travel Rule requirements established under the PCMLTFA and associated FINTRAC guidance to qualifying electronic funds transfers and outgoing virtual currency transfers.

For qualifying transfers, Payoro collects, retains, transmits and takes reasonable measures to obtain the required originator and beneficiary information, including names, addresses, account or wallet identifiers and transaction information, as applicable.

Where Payoro initiates an outgoing virtual currency transfer, required Travel Rule information is included with the transfer or otherwise transmitted through an approved Travel Rule or counterparty communication mechanism where technically and legally appropriate.

Outgoing virtual currency transfers may be directed to a Client’s own external wallet or to an approved third-party beneficiary wallet. Payoro applies third-party determination, sanctions screening, blockchain analytics, counterparty risk assessment and enhanced due diligence as appropriate. External-wallet ownership by the Client is not a universal condition for an outgoing transfer where the relevant product permits payment to a third-party beneficiary.

Payoro maintains risk-based procedures for outgoing transfers to self-hosted wallets, including collection of additional wallet, counterparty, purpose, source-of-funds or proof-of-control information where warranted by the risk profile.

Transactions that lack required information or present elevated risk may be restricted, delayed where lawful, rejected, returned where lawful and operationally possible, or escalated for enhanced due diligence or suspicious transaction assessment.

4.7 FINTRAC Reporting Obligations

Payoro fulfills all regulatory reporting obligations in accordance with Canadian Anti-Money Laundering and Anti-Terrorist Financing (AML/ATF) regulations. Reporting ensures transparency and supports law enforcement and intelligence efforts to detect and deter money laundering, terrorist financing, and sanctions evasion.

The Chief Compliance Officer is responsible for overseeing the reporting framework and ensuring that all required reports are submitted accurately, securely, and within prescribed timeframes by designated compliance staff.

Reports are submitted through approved regulatory reporting systems, including FINTRAC’s web reporting system (FWR), using secure transmission methods that meet applicable data protection and confidentiality requirements.

4.7.1 24-Hour Aggregation Rule

Payoro applies the 24-hour rule to determine when multiple transactions must be aggregated and reported to FINTRAC as a single transaction. Under the 24-hour rule, Payoro must aggregate multiple transactions that:

  • Total CAD 10,000 or more when combined;
  • Occur within a consecutive 24-hour period; and
  • Share the same aggregation type, meaning they involve the same conductor, beneficiary, or are conducted on behalf of the same third party.

Payoro uses a static 24-hour window from 00:00 to 23:59 Eastern Time (ET) to identify and aggregate reportable transactions. This window is applied uniformly across all Payoro business lines and systems. Any transactions meeting the above criteria within that defined period are treated as a single transaction for reporting purposes. Once the 24-hour window ends, a new window begins automatically for any subsequent activity.

4.7.2 Large Virtual Currency Transaction Reports (LVCTR)

Payoro files a Large Virtual Currency Transaction Report (LVCTR) with FINTRAC when it receives an amount of virtual currency equivalent to CAD 10,000 or more in a single transaction, or when multiple transactions that meet the 24-hour rule total CAD 10,000 or more within 5 business days of the transaction occurring.

This reporting requirement applies to reportable receipts arising through permitted Payoro operational or counterparty flows and does not mean that Payoro accepts customer deposits of virtual currency from external wallets into the exchange or hosted-wallet environment. Virtual currency held solely as Payoro’s own property is treated in accordance with applicable reporting rules.

For the purpose of determining whether a transaction meets the CAD 10,000 reporting threshold, Payoro converts the value of the virtual currency to Canadian dollars using the prevailing market exchange rate at the time the transaction is received.

  • Exchange rates are obtained from a reliable and independent data source that reflects the market rate at the exact transaction timestamp.
  • The source and rate used are recorded in the transaction record and retained as part of the supporting documentation for the LVCTR.
  • Where conversion involves multiple currencies, Payoro uses sequential conversion rates consistent with transparent market pricing and documents the calculation method applied.

4.7.3 Electronic Funds Transfer Reports (EFTR)

Payoro files an Electronic Funds Transfer Report (EFTR) when it initiates, finally receives, or performs both roles in relation to an international electronic funds transfer of CAD 10,000 or more, whether as a single transaction or when multiple transactions total that amount under the 24 hour rule. In cases where Payoro both initiates and finally receives a reportable transfer, an EFTR is filed for each respective role in accordance with FINTRAC’s reporting requirements.

Reports are submitted to FINTRAC within five (5) business days of the transfer being initiated or finally received, or within five (5) business days following the end of the 24-hour aggregation window for aggregated transactions.

This requirement applies only to client transactions and excludes transfers conducted for Payoro’s own business or operational purposes.

4.7.4 Suspicious Transaction Reports (STRs and ASTRs)

Payoro files a Suspicious Transaction Report (STR) or Attempted Suspicious Transaction Report (ASTR) when there are reasonable grounds to suspect that a transaction, or an attempted transaction, is related to the commission or attempted commission of a money laundering, terrorist financing, or sanctions evasion offense. All staff are required to escalate any unusual or suspicious activity immediately to the Compliance Team without delay.

Reports must be filed as soon as practicably possible after reasonable grounds to suspect have been established, regardless of whether the transaction is completed. STRs must include all relevant facts, supporting documentation, and a clear explanation of the basis for suspicion.

Payoro and its employees are strictly prohibited from disclosing to any person, including the client, that an investigation, STR, or ASTR has been completed or that information related to an STR/ASTR has been submitted to FINTRAC. This prohibition applies to any communication that could reasonably reveal the existence, content, or intent to file an STR, or that an investigation related to suspicious activity is being conducted.

All STR-related information must be handled on a strictly confidential basis and only shared internally on a need-to-know basis for compliance purposes.

4.7.5 Listed Person or Entity Property Report (LPEPR)

Payoro submits a Listed Person or Entity Property Report (LPEPR) when property in its possession or control is owned or controlled, directly or indirectly, by a person or entity that is subject to a list under the United Nations Act, the Special Economic Measures Act (SEMA), the Justice for Victims of Corrupt Foreign Officials Act (Magnitsky Law), or a terrorist group as defined under the Criminal Code. This reporting obligation arises from the existence of property, not the completion of a transaction.

LPEPRs must be submitted immediately and without delay once Payoro is aware of the ownership or control connection to a listed person or entity. Payoro submits the report using the designated FINTRAC form through fax or physical mail.

In addition to the LPEPR submission, Payoro must immediately disclose the same information to the Royal Canadian Mounted Police (RCMP) and the Canadian Security Intelligence Service (CSIS) in accordance with federal disclosure obligations under the Criminal Code and related sanctions legislation.

If a transaction or attempted transaction involving such property also gives rise to reasonable grounds to suspect money laundering, terrorist financing, or sanctions evasion, a separate Suspicious Transaction Report (STR) must be filed with FINTRAC.

4.7.6 Large Cash Transaction Reports (LCTR)

A Large Cash Transaction Report (LCTR) is required when a reporting entity receives coin or paper money amounting to CAD 10,000 or more in a single transaction, or when multiple cash transactions under the 24-hour rule total CAD 10,000 or more. LCTRs must be filed within 15 calendar days.

Payoro does not accept or handle cash for client transactions. As a result, LCTR obligations do not apply to Payoro’s services. If Payoro’s business model changes to accept cash in any form, this policy will be updated and LCTR controls will be implemented before any such activity begins.

4.7.7 Determining Suspicion

Payoro determines suspicion based on the presence of facts, patterns, or behaviors that give rise to reasonable grounds to suspect money laundering, terrorist financing, or sanctions evasion activity. The determination of suspicion does not require proof of criminal conduct but must be supported by objective indicators and sound judgment. Suspicious indicators must be treated as high-priority and thoroughly assessed to support suspicious reporting obligations.

Suspicion may be established through:

  • Transaction monitoring alerts, internal reviews, or client interactions;
  • Unusual account activity inconsistent with a client’s known profile, business model, or risk classification;
  • Information received from third-party partners, law enforcement, or public sources; or
  • Connections identified through sanctions screening, adverse media, or other due diligence findings.

Employees are not expected to investigate suspected activity beyond their role but are required to immediately escalate any potential concern to the Compliance Team for review. The Chief Compliance Officer is responsible for confirming whether the facts meet the threshold for filing a Suspicious Transaction Report (STR) or Attempted Suspicious Transaction Report (SAR).

4.7.7.1 Reasonable Grounds to Suspect (RGS)

Reasonable Grounds to Suspect (RGS) is the threshold applied when determining whether to file a Suspicious Report. RGS exists when there is a factual basis supported by objective indicators or observed behavior that would lead a reasonable person with similar knowledge and experience to suspect that a transaction or attempted transaction is related to money laundering, terrorist financing, or sanctions evasion. RGS does not require proof or confirmation of criminal activity. The suspicion must be based on facts or patterns observed during the normal course of business, not personal opinion or intuition.

Indicators that may contribute to forming RGS within Payoro’s business model include:

  • Transactions inconsistent with the client’s known financial activity or stated purpose;
  • Structuring or breaking transactions to avoid reporting thresholds;
  • Rapid or repeated conversions between fiat and virtual currency without clear economic purpose;
  • Use of privacy-enhancing technologies, anonymizing services, or unregulated exchanges;
  • Activity involving high-risk or sanctioned jurisdictions; and
  • Information received from reliable third parties, law enforcement, or public sources indicating potential illicit activity.

All employees are required to remain alert to potential suspicious activity and must immediately escalate any concern to the Compliance Team for review. The Chief Compliance Officer is responsible for determining whether the RGS threshold has been met and for authorizing the appropriate regulatory filing.

4.7.7.2 Reasonable Grounds to Believe (RGB)

Reasonable Grounds to Believe (RGB) is a higher evidentiary threshold than RGS. RGB exists when credible and reliable information would lead a reasonable person with similar knowledge and experience to conclude that a fact or connection is true. RGB is applied where law or regulation requires a belief standard, including circumstances related to sanctions, terrorist property, ministerial directives, or sanctions evasion or circumvention activity.

RGB may be established through corroborated information from multiple sources, verified documentary evidence, official designations or list entries, confirmations from competent authorities, or other reliable data that substantiate ownership, control, direction, or prohibited conduct.

When RGB is established, Payoro takes immediate action consistent with applicable legal and regulatory requirements, which may include:

  • Restricting or freezing access to property or accounts associated with the identified person, entity, or jurisdiction;
  • Notifying the appropriate law enforcement, intelligence, or regulatory authorities as required under applicable law;
  • Submitting any required regulatory or sanctions-related reports through designated channels; and
  • Implementing any measures required under relevant directives, sanctions programs, or enforcement orders.

All RGB determinations and actions taken are documented, including the sources relied upon and the rationale for the conclusion. These records are retained in accordance with Payoro’s record-keeping requirements.

4.8 Escalation and Internal Review

Payoro maintains a structured internal escalation and review process to ensure that all potential cases of money laundering, terrorist financing, or sanctions-related activity are assessed accurately and consistently before any regulatory report or disclosure is filed.

All employees are required to remain alert to unusual or suspicious activity and to immediately escalate any concerns to the Compliance Team through designated internal channels. Employees must not discuss, delay, or disclose the escalation outside approved reporting lines.

Employees are strictly prohibited from disclosing or implying to any client, counterparty, or external party that a suspicious transaction or activity has been identified, reviewed, or reported. This prohibition applies before, during, and after a report is filed and extends to all forms of communication. Breaches of this requirement may result in disciplinary action and potential legal consequences under applicable law.

The Compliance Team conducts an initial review of each escalation to determine whether additional information or clarification is required. If indicators suggest the presence of reasonable grounds to suspect (RGS) or reasonable grounds to believe (RGB), the matter is referred to the Chief Compliance Officer for final determination.

The Chief Compliance Officer is responsible for:

  • Reviewing all available facts, documentation, and contextual information;
  • Confirming whether regulatory thresholds have been met;
  • Authorizing the preparation and submission of required reports or disclosures; and
  • Ensuring reports are filed within prescribed timelines and through the appropriate reporting systems.

All escalations, determinations, and related documentation are logged and retained for a minimum of five (5) years after the date of the termination of the Business relationship to which the escalation applies. The escalation process is subject to independent review as part of Payoro’s periodic compliance effectiveness assessments.

4.8.1 Investigation Framework

Payoro applies a structured investigation framework to assess alerts, red flags, and potentially suspicious activity. Investigations are conducted using a risk-based approach and may include the following measures:

  • Transaction Reviews: Analysis of client transactional activity, including volume, frequency, counterparties, beneficiary information, and account behaviour, to identify inconsistencies or unusual patterns.
  • Sanctions Screening and Review: Screening of clients, business entities, directors, ultimate beneficial owners (UBOs), authorized signatories, and known associates against applicable sanctions lists, along with a review of related compliance obligations.
  • Open Source Intelligence (OSINT): Collection and analysis of publicly available information to support the investigation, including review of online presence, social media, and associated websites for additional context or risk indicators.
  • Elevated Verification: Requests for additional information or documentation from the client through a Request for Information (RFI) process, where appropriate. All requests must be reasonable, proportionate, and approved by the Chief Compliance Officer, and must not result in tipping off.
  • Blockchain Analytics: Analysis of client wallet activity and virtual currency transactions using blockchain analytics tools, assessing factors such as asset type, transaction velocity, volume, and exposure to high-risk entities or services.

Following completion of an investigation, one or more of the following outcomes may be determined:

  • No Further Action: No reasonable grounds for suspicion are identified and no further action is required.
  • Enhanced Monitoring and Due Diligence: The client is subject to increased monitoring, additional due diligence measures, and a reassessment of the client’s risk rating.
  • Termination of Client Relationship: A decision is made to cease the business relationship based on identified risks or policy considerations.
  • Suspicious Transaction Report (STR): Where there are reasonable grounds to suspect that a transaction is related to money laundering or terrorist financing, a report is submitted to FINTRAC in accordance with regulatory requirements.

4.9 Sanctions Compliance

Payoro maintains a comprehensive Sanctions Compliance framework designed to identify, prevent, and report dealings with sanctioned individuals, entities, jurisdictions, or activities. The framework ensures adherence to all applicable Canadian sanctions laws and regulations.

Payoro complies with sanctions obligations imposed under the following frameworks:

  • Canada: the United Nations Act, the Special Economic Measures Act (SEMA), and the Justice for Victims of Corrupt Foreign Officials Act (JVCFOA);
  • United States: the Office of Foreign Assets Control (OFAC) regulations under 31 C.F.R. Chapter V and related executive orders; and
  • Other applicable international or supranational sanctions regimes where Payoro operates or engages in cross-border activity.

Payoro screens all clients, beneficial owners, counterparties, and transactions against applicable sanctions lists at onboarding and on an ongoing basis. Screening includes:

  • Global and jurisdiction-specific sanctions lists (e.g., UN, OFAC, EU, UK, and Canada);
  • Politically exposed persons (PEPs) and Heads of International Organizations (HIOs); and
  • Ministerial directives or other regulatory restrictions issued by competent authorities.

Screening is conducted using automated systems supported by manual review where required. Potential matches or alerts are escalated to the Compliance Team for investigation and validation before any transaction is processed.

Payoro prohibits:

  • Any dealings, transactions, or services involving listed or sanctioned persons, entities, or jurisdictions;
  • Activities intended to evade, circumvent, or facilitate violations of sanctions laws; and
  • The facilitation or indirect participation in transactions prohibited by any applicable sanctions program.

Where sanctions-related activity or property is identified, Payoro takes immediate action consistent with legal and regulatory requirements. This may include freezing or restricting access to assets, declining or blocking transactions, and notifying the appropriate authorities.

4.9.1 Ministerial Directives

Ministerial Directives are issued by the Minister of Finance (Canada) under section 11.42 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). These directives require reporting entities to apply specific measures to transactions or relationships involving prescribed foreign jurisdictions, financial institutions, or classes of transactions that pose a high risk of money laundering or terrorist financing.

Payoro reviews and applies all active Ministerial Directives as published by the Department of Finance and FINTRAC. These directives may require Payoro to:

  • Prohibit or restrict transactions involving specified jurisdictions or entities;
  • Apply enhanced due diligence and ongoing monitoring measures;
  • Retain additional records or submit specific transaction reports; or
  • Cease business relationships with affected clients or counterparties.

As of the date of this policy, active Ministerial Directives apply to:

  1. The Islamic Republic of Iran;
  2. The Democratic People’s Republic of Korea (North Korea); and
  3. Russia.

Payoro does not engage in any transactions, business relationships, or financial activity involving jurisdictions, institutions, or persons subject to a Ministerial Directive. Any attempted transaction or onboarding connected to these jurisdictions is automatically declined and escalated to the Chief Compliance Officer.

Ministerial Directives are monitored on an ongoing basis, and any updates or new issuances are implemented immediately upon publication to ensure continued compliance with all regulatory obligations.

4.10 Politically Exposed Persons (PEPs) and Heads of International Organizations (HIOs)

Payoro identifies and manages relationships involving Politically Exposed Persons (PEPs) and Heads of International Organizations (HIOs) in accordance with the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), and its associated Regulations.

The objective of this process is to ensure that individuals who hold or have held prominent public functions, or those closely associated with them, are subject to enhanced due diligence, monitoring, and senior management oversight.

Payoro screens all new clients, beneficial owners, counterparties and third-party controllers for PEP and HIO status during onboarding and on an ongoing basis. Screening includes both direct and indirect associations such as close family members or known associates under the following categories:

  • Foreign PEPs: individuals who hold or have held senior public positions in a foreign state.
  • Domestic PEPs: individuals who hold or have held senior public positions in Canada.
  • Heads of International Organizations (HIOs): individuals who hold or have held the highest position in an international organization.
  • Family Members or Close Associates: persons who are related to, or known to be closely connected with, a PEP or HIO.

When a client, beneficial owner, counterparty, or third-party controller is identified as a PEP or HIO, Payoro applies enhanced due diligence (EDD) measures, including:

  • Chief Compliance Officer review and approval before establishing or continuing the relationship;
  • Determining the source of funds and, where applicable, the source of wealth;
  • Ongoing transaction monitoring and periodic review proportionate to a high-risk classification; and
  • Documenting all findings, approvals, and monitoring actions.

Foreign PEPs and Heads of International Organizations (HIOs) remain subject to enhanced due diligence (EDD) measures indefinitely once identified. Domestic PEPs are subject to EDD for a period of five (5) years after leaving their position, after which enhanced measures may be discontinued unless other risk factors or indicators of elevated risk are present.

Payoro applies a risk-based approach to relationships involving PEPs and HIOs, including clients, beneficial owners, and counterparties. Such relationships require enhanced due diligence, senior management approval, and ongoing monitoring proportionate to the level of risk identified.

All PEP and HIO determinations, reviews, and approvals are documented and retained in accordance with Payoro’s record-keeping requirements.

4.10.1 PEP and HIO Screening Scenarios

Payoro conducts targeted PEP and HIO screening under the following scenarios:

  • When a client requests that Payoro initiate an international electronic funds transfer of $100,000 or more.
  • When Payoro finally receives an international electronic funds transfer of $100,000 or more for a beneficiary.
  • When a client requests that Payoro transfer virtual currency in an amount of $100,000 or more.

4.11 Record Keeping

Payoro maintains comprehensive records to demonstrate compliance with all applicable Anti-Money Laundering (AML), Anti-Terrorist Financing (ATF), and sanctions obligations. Accurate and complete record keeping supports the ability to detect, investigate, and report suspicious or prohibited activity and ensures that information is readily available to regulators and law enforcement upon request.

Records are maintained in a manner that is secure, retrievable, and tamper-resistant. All AML/ATF and sanctions-related records are retained for a minimum of five (5) years from the date they are created or from the date an account is closed, whichever is later, unless a longer period is required by applicable law.

Payoro retains, at a minimum:

  • Client identification and verification records, including supporting documents and data used to confirm identity;
  • Beneficial ownership and control information for all legal entities;
  • Risk assessments, due diligence documentation, and ongoing monitoring records;
  • Details of all transactions, including amounts, dates, parties, purpose, and method of payment or transfer;
  • Hosted wallet and custody records, including wallet identifiers, internal ledger entries, client entitlements, custody credits, withdrawals, internal transfers, transaction hashes, destination addresses, custody-provider records and reconciliation information sufficient to connect client balances to underlying Supported Virtual Currency;
  • Transaction review records, including 24-hour aggregation determinations and supporting data used to assess reporting thresholds;
  • Logs of all law enforcement, regulatory, or FINTRAC information requests and corresponding responses;
  • Internal compliance memoranda, investigative notes, and decision records supporting report filings or non-filings;
  • Copies of all reports filed with regulators, including Suspicious Transaction Reports (STRs), Attempted Suspicious Transaction Reports (ASTRs), Large Virtual Currency Transaction Reports (LVCTRs), Electronic Funds Transfer Reports (EFTRs), and other required filings;
  • Record of suspicious alerts, alert handling, determination, rationale and exception handling;
  • Records identifying whether a client is acting on behalf of a third party, including the name, address, and relationship of that third party;
  • Documentation of compliance reviews related to threshold determinations, data validation, or system tuning;
  • Training records, independent effectiveness review reports, and compliance review findings; and
  • All correspondence and documentation related to sanctions, PEP/HIO reviews, and internal escalations.

Records are accessible only to authorized personnel and regulatory authorities. Access to client and compliance records is restricted, logged, and reviewed periodically to ensure confidentiality and integrity.

Payoro protects all personal and transactional data in accordance with applicable privacy and data protection laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada.

Electronic records must be securely stored, backed up, and capable of being reproduced in a readable format upon request by a regulator or law enforcement agency. Payoro’s systems ensure that all data is time-stamped, traceable, and protected from unauthorized alteration or deletion.

Records must be made available and accessible to be provided within 30 days upon request from FINTRAC or other legal authority.

5.0 AML Training Program

Payoro maintains a structured and ongoing training program to ensure that all employees, contractors, and agents understand their responsibilities under applicable Anti-Money Laundering (AML), Anti-Terrorist Financing (ATF), and sanctions laws. The training program is designed to promote a culture of compliance, enhance risk awareness, and ensure that all staff can identify and escalate potential suspicious or prohibited activity.

5.1 Purpose and Objectives

The purpose of the training program is to:

  • Ensure all personnel are familiar with the requirements of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), its associated Regulations.
  • Provide practical guidance for recognizing, preventing, and reporting money laundering, terrorist financing, and sanctions evasion;
  • Reinforce the importance of the risk-based approach to client due diligence, monitoring, and escalation; and
  • Maintain consistency and accountability in the implementation of Payoro’s AML/ATF framework.

5.2 Training Scope

Training is mandatory for all Payoro employees, including management, compliance, operations, client support, and technology staff. Agents, mandataries, contractors, consultants, and third-party service providers performing functions on behalf of Payoro, or who have access to client or transactional data, also receive AML/ATF training appropriate to their role and level of responsibility.

Training ensures that all individuals acting for or on behalf of Payoro understand their obligations to identify, prevent, and report suspicious or prohibited activity, and to comply with the company’s policies, procedures, and applicable regulatory requirements.

Training covers, at a minimum:

  • Overview of applicable AML/ATF and sanctions legislation and regulatory expectations;
  • Payoro’s internal policies and procedures;
  • Identification of suspicious transactions, unusual patterns, and red flags specific to Payoro’s business model;
  • Procedures for client identification, verification, and due diligence;
  • Escalation protocols and reporting obligations;
  • Privacy, data protection, and record-keeping obligations; and
  • Prohibitions on tipping-off and disclosure of confidential compliance activity.

5.3 Frequency and Method

All new employees must complete AML/ATF training before or within 30 days of commencing employment. Refresher training is conducted annually, or more frequently when there are material changes in regulatory requirements, risk exposure, or Payoro’s operations.

Training may be delivered through a combination of online modules, live sessions, workshops, and targeted compliance briefings. Attendance and completion are tracked electronically and form part of each employee’s compliance record.

5.4 Oversight and Evaluation

The Chief Compliance Officer is responsible for developing, maintaining, and approving the training curriculum. The Compliance Team monitors participation, evaluates effectiveness through assessments and feedback, and updates training content as regulatory requirements evolve.

Training materials, attendance logs, completion certificates, and assessment results are retained for a minimum of five (5) years in accordance with Payoro’s record-keeping standards.

6.0 Review and Effectiveness Testing

6.1 Independent Reviews

Payoro conducts independent reviews of its Anti-Money Laundering and Anti-Terrorist Financing (AML/ATF) compliance program to assess its effectiveness and ensure ongoing alignment with regulatory requirements, internal policies, and industry best practices.

The objective of the independent review is to evaluate the adequacy of Payoro’s AML/ATF controls, the implementation of its risk-based approach, and the overall effectiveness of compliance procedures across all business lines.

An independent review is conducted at least every two (2) years, or more frequently if required by regulatory changes, material business growth, or identified compliance concerns.

The review must be performed by a qualified individual or external party who is independent of the day-to-day operation and management of Payoro’s AML/ATF program. Independence ensures that findings are objective, unbiased, and free from conflicts of interest.

6.1.1 Scope of Review

The independent review evaluates:

  • The adequacy and implementation of AML/ATF policies, procedures, and internal controls;
  • The effectiveness of risk assessments, client due diligence, and ongoing monitoring processes;
  • The accuracy, completeness, and timeliness of regulatory reporting to FINTRAC, and other authorities;
  • The sufficiency of training programs and staff understanding of compliance obligations;
  • Alert management, escalations processes, and staff exception handling;
  • The reliability of data management, record keeping, and transaction monitoring systems; and
  • The timeliness and effectiveness of remediation for any previously identified deficiencies.

Upon completion, the reviewer issues a written report summarizing findings, conclusions, and recommendations for improvement, including:

  • The purpose, scope, and methodology of the review;
  • The testing results and observations for each element of Payoro’s AML/ATF compliance program;
  • Identified deficiencies, control gaps, or weaknesses, along with root-cause analysis;
  • Recommendations for corrective action and process enhancement;
  • The reviewer’s independence, qualifications, and confirmation of objectivity; and
  • A summary of management’s responses, proposed timelines, and accountability for remediation, where applicable.

The report is presented to senior management and the Compliance Officer for review and approval. Management must prepare a documented response within 30 days of receiving the final report, outlining agreed corrective actions, assigned responsibilities, and timelines for remediation.

All corrective actions are tracked to completion and verified by the Chief Compliance Officer. Significant deficiencies or control weaknesses are escalated to executive leadership for oversight and resolution.

All independent review reports and related documentation are retained for a minimum of five (5) years and made available to FINTRAC or other competent authorities upon request.

6.2 Internal Testing and Ongoing Effectiveness Reviews

Payoro conducts internal testing and ongoing effectiveness reviews of its AML/ATF compliance program to ensure controls are functioning as intended and regulatory obligations are consistently met.

Internal testing is performed on a periodic basis, using a risk-based approach, and may be conducted more frequently in response to regulatory changes, operational updates, or identified compliance risks.

The internal testing program includes:

  • Sample testing of client onboarding, due diligence, and ongoing monitoring processes to assess compliance with internal policies and regulatory requirements;
  • Review of transaction monitoring alerts, escalations, and case handling to ensure appropriate investigation and decision-making;
  • Verification of the accuracy, completeness, and timeliness of regulatory reporting, including suspicious transaction reports and large virtual currency transaction reports;
  • Validation of system configurations, rules, and thresholds to ensure transaction monitoring systems are appropriately calibrated and generating alerts as intended;
  • Assessment of record keeping practices and data integrity across systems;
  • Testing of controls related to high-risk clients, including PEPs, HIOs, and higher-risk jurisdictions; and
  • Follow-up testing to confirm the effective remediation of previously identified deficiencies.

Findings from internal testing are documented and reported to the Chief Compliance Officer and senior management. Where deficiencies or control gaps are identified, corrective actions are assigned with defined timelines and tracked to completion.

Internal testing results are used to support continuous improvement of Payoro’s AML/ATF compliance program and inform updates to policies, procedures, risk assessments, and training programs.

7.0 Law Enforcement and Regulatory Requests

Payoro cooperates fully with all lawful requests for information or documentation made by regulatory authorities, law enforcement agencies, or other competent bodies in accordance with applicable legislation. Requests may include information production orders, inquiries, summonses, or other forms of official correspondence.

The Chief Compliance Officer is responsible for managing all law enforcement and regulatory requests on behalf of Payoro. This includes reviewing the nature and scope of each request, verifying its validity, and coordinating an appropriate and timely response in accordance with applicable legal and regulatory requirements.

All requests are logged in a Regulatory and Law Enforcement Request Register, which records the:

  • date received;
  • requesting authority;
  • type of request;
  • scope of information provided; and
  • the date of response.

Requests are acknowledged promptly upon receipt and responded to within the timeframe prescribed by the requesting authority or within a reasonable period consistent with regulatory expectations.

Payoro ensures that:

  • Information is disclosed only to authorized parties in accordance with applicable privacy and confidentiality obligations;
  • Data is transmitted securely using encrypted channels or other approved secure methods;
  • The scope of disclosure is limited strictly to the information requested; and
  • All communications and supporting materials are retained for a minimum of five (5) years from the date of response.

If a request involves or may involve suspicious activity, designated persons, or sanctions-related property, the Chief Compliance Officer ensures appropriate escalation and determines whether additional reporting obligations to FINTRAC, or other authorities apply.

All employees, agents, and service providers must immediately forward any regulatory or law enforcement request they receive to the Chief Compliance Officer without review, discussion, or disclosure to any external party. Unauthorized disclosure or interference with a request is strictly prohibited.

8.0 Whistleblower Policy

Payoro is committed to maintaining a culture of integrity, transparency, and accountability. The Whistleblower Function supports the identification and escalation of potential misconduct, including fraud, regulatory breaches, and violations of internal policies.

All employees and relevant stakeholders are encouraged to report concerns in good faith. Payoro prohibits retaliation, victimization, or adverse consequences against any individual who raises a concern. Reports may be submitted on an identified or anonymous basis.

Payoro handles all whistleblower disclosures in a confidential manner. Information is restricted to individuals with a need to know for the purpose of assessment and investigation. Where confidentiality cannot be maintained, the reporting individual will be informed, where possible.

Whistleblower reports and related personal information are handled in accordance with applicable Canadian employment, privacy, confidentiality and legal requirements. Nothing in this policy limits any statutory right to report misconduct to a regulator, law enforcement authority or other competent body.

Concerns should be reported through internal channels unless not feasible. Reports may be submitted to the Chief Compliance Officer, Chief Executive Officer, or Board of Directors.

8.1 Handling of Whistleblower Reports

All reports are documented, assessed, and addressed in a timely and independent manner. Investigations are conducted proportionate to the nature and severity of the concern and may include:

  • Review of relevant records and documentation;
  • Internal inquiries and engagement with relevant stakeholders;
  • Audit or forensic review, where appropriate; and
  • Follow-up with the reporting individual, where possible.

Where sufficient information is available, reports should include:

  • Date(s) of the incident(s);
  • Identities of individuals involved or witnesses, where known;
  • Description of the conduct or concern;
  • Details of how the issue was identified;
  • Actions taken at the time of the incident; and
  • Any supporting documentation or evidence.

All whistleblower reports and related documentation are retained in accordance with Payoro’s record keeping requirements.

9.0 Country Acceptance Policy

Payoro maintains a Country Acceptance Policy to define acceptable jurisdictions for services and to support a risk-based approach to client onboarding and ongoing monitoring.

For the purposes of this policy, “location” includes any jurisdiction connected to the client, including but not limited to business operations, physical or registered addresses, beneficial ownership, bank account locations, identity document issuance, IP addresses, and other relevant factors.

Location risk is assessed based on identified financial crime risk factors, including:

  • Tax evasion: Jurisdictions that maintain outdated or poor legislation and banking secrecy laws that facilitate tax crimes and the illicit flight of capital.
  • Money Laundering: Jurisdictions that fail to comply with international standards for financial reporting and transparency. Money laundering risks often intersect with predicate offenses such as drug trafficking, human trafficking, and war plunder.
  • Terrorist Financing: Payments associated with terrorist financing may or may not involve money laundering. These transactions typically involve the movement of funds intended to directly or indirectly support terrorist groups.
  • Source Country Risks: Certain countries or jurisdictions serve as source countries for narcotics or trafficked humans. Due to the prevalence of predicate offenses in these locations, they pose heightened risks for money laundering and are treated accordingly.
  • Jurisdictions Affected by Conflict or Sanctions: Regions experiencing armed conflict are particularly susceptible to predicate offenses such as human trafficking, money laundering, corruption, and others.

9.1 Banned Countries

Clients located in jurisdictions subject to Canadian sanctions or otherwise outside of Payoro’s risk appetite are prohibited from onboarding or continued service, including: Belarus, Central African Republic, China, Democratic People’s Republic of Korea, Democratic Republic of the Congo, Guatemala, Haiti, Iran, Iraq, Lebanon, Libya, Moldova, Nicaragua, Russia, Somalia, South Sudan, Sri Lanka, Sudan, Syria, Ukraine (linked to Russia’s ongoing violations of Ukraine’s sovereignty and territorial integrity), Venezuela, and Yemen.

Banned countries due to increased risk that is outside of Payoro’s risk appetite include: Abkhazia, Afghanistan, Algeria, Angola, Bangladesh, Bosnia & Herzegovina, Burundi, Burkina Faso, Cambodia, Colombia, Cuba, Egypt, Eritrea, Ethiopia, Ecuador, Guyana, Guinea, Guinea-Bissau, the Holy See, Ivory Coast, Kosovo, Laos, Liberia, Macedonia, Mali, Nagorno-Karabakh, Pakistan, Palestine, Papua New Guinea, Sahrawi Arab Democratic Republic, Sierra Leone, Somaliland, South Ossetia, Uganda, Vanuatu and Vietnam.

9.2 Restricted Countries

Clients associated with restricted jurisdictions may be onboarded subject to enhanced due diligence and additional risk mitigation measures. These jurisdictions present elevated risk and require additional verification prior to establishing a business relationship.

Restricted countries include: Albania, Andorra, Antigua and Barbuda, Argentina, Armenia, Azerbaijan, the Bahamas, Bahrain, Barbados, Belize, Benin, Bolivia, Botswana, Brunei Darussalam, Bulgaria, Cape Verde, Cameroon, the Cayman Islands, Chad, Comoros, the Cook Islands, Costa Rica, Curacao, Cyprus, Dominica, the Dominican Republic, El Salvador, Eswatini, Equatorial Guinea, Fiji, Gabon, Georgia, Ghana, Grenada, Guernsey, Serbia, Honduras, Hong Kong, India, the Isle of Man, Israel, Jamaica, Jersey, Jordan, Kazakhstan, Kenya, Kuwait, Kyrgyzstan, Lesotho, Madagascar, Malawi, Malaysia, the Maldives, Malta, Mauritania, Mauritius, Mongolia, Montenegro, Morocco, Mozambique, Namibia, Nauru, Nepal, Niger, Nigeria, Niue, Oman, Panama, Paraguay, Peru, the Philippines, Qatar, Rwanda, Saint Kitts and Nevis, Saint Lucia, Saint Vincent and the Grenadines, Samoa, San Marino, Sao Tome and Principe, Saudi Arabia, Senegal, the Seychelles, Singapore, Sint Maarten, South Africa, Suriname, Tajikistan, Tanzania, Thailand, Timor-Leste, Togo, Trinidad and Tobago, Tonga, Turkey, Turkmenistan, the Turks and Caicos Islands, the United Arab Emirates, Uruguay, Uzbekistan, the Virgin Islands, and Zambia.

9.3 Onboarding Exceptions

Exceptions apply only to clients associated with restricted jurisdictions and must be approved by the Chief Compliance Officer. A risk-based approach is applied across all relevant client locations, with the highest-risk jurisdiction determining the overall location risk rating.

The review process for restricted countries must undergo rigorous review verification that goods/services are fulfilled.

  • Detailed reporting of beneficial ownership.
  • Increased entity verification.
  • Confirmation that owners are not politically exposed persons (PEPs) or listed on watch lists.
  • Accurate reporting of business income to tax authorities.

Exceptions are evaluated individually and must be approved by the Chief Compliance Officer. A risk-based approach is used to determine location risk, considering that clients may have multiple locations, such as corporate addresses, physical addresses, bank account locations, fulfillment warehouses, and home addresses. The highest risk location among these is used to score the Client’s overall location risk. For Clients located in restricted countries and operating within high-risk industries or offering high-risk products, service will be denied.

10.0 Industry Acceptance Policy

Payoro does not provide services to certain industries or business types that present elevated risks of money laundering, terrorist financing, fraud, or reputational harm, or that are incompatible with banking relationships and payment channels. These industries are considered outside of Payoro’s risk appetite and are prohibited from onboarding or continued service.

Adult content, animal trade, advance payment for delayed fulfillment services, subscriptions; airlines; collection agencies; marijuana dispensaries; CBD oil and related products; cash advances or cash gifting; check cashing; cruises; debt consolidation; drug paraphernalia; firearms; fulfillment centers; government grant assistance; mail order brides; medical benefits or discounts; mortgage modification or reduction; multi-level marketing schemes; payday lending; replica or counterfeit goods; and timeshares.

Clients with multiple products or services may be approved with enhanced due diligence and only with the Chief Compliance Officer’s approval.

10.1 Restricted Industries

Clients operating in restricted industries may be onboarded subject to enhanced due diligence and additional risk mitigation measures. Where appropriate, further controls may be applied, including transaction or volume limits and increased transaction monitoring, as determined by the Chief Compliance Officer.

Restricted industries present elevated risk due to factors such as extended fulfillment timelines, advance payment models, increased dispute or chargeback exposure, or evolving regulatory requirements related to health, safety, or consumer protection.

The following business types are subject to increased scrutiny: auction houses; prepaid and gift cards; diet programs; insurance agents and brokers; educational programs; modeling agencies; pharmaceuticals; precious metals and gemstones; collectible clubs; vape products; pawnbrokers; ticket brokers; travel agencies and clubs; used car dealerships; and vitamins and herbal remedies.

10.2 Onboarding Exceptions

Exceptions to onboarding apply only to clients operating in restricted industries and are subject to the completion of enhanced due diligence and implementation of appropriate risk mitigation controls applied at the client level.

Clients engaged in prohibited products or activities are not eligible for onboarding under any circumstances.

All exceptions are assessed on a case-by-case basis and require documented approval from the Chief Compliance Officer.

11.0 Continuous Improvement and Program Updates

Payoro treats expansion into new virtual currencies, stablecoins, custody models, blockchain networks, wallet architectures, liquidity arrangements and payment functionality as material product changes requiring documented legal, regulatory, AML/ATF, sanctions, operational and technology assessment before launch.

Payoro is committed to maintaining a dynamic and responsive Anti-Money Laundering and Anti-Terrorist Financing (AML/ATF) program that evolves in line with regulatory developments, business growth, emerging risks, and industry best practices.

The AML/ATF program is reviewed and updated regularly to ensure its continued effectiveness, accuracy, and alignment with applicable laws and regulatory expectations in Canada.

Payoro continuously evaluates its compliance framework through:

  • Analysis of regulatory updates, guidance, and enforcement actions issued by FINTRAC, the Department of Finance, and other competent authorities;
  • Ongoing assessment of internal and external risk factors, including technological developments and new product offerings;
  • Feedback and findings from independent reviews, internal audits, and supervisory examinations; and
  • Input from senior management, compliance staff, and operational teams to identify areas for process enhancement or additional control development.

All AML/ATF policies, procedures, and supporting documentation are reviewed at least annually, or more frequently when material changes occur to business operations, regulations, or identified risks. Updates are coordinated by the Compliance Officer and approved by Senior Management before implementation.

Revisions are communicated promptly to all relevant employees, agents, and third parties. Updated versions are maintained in a controlled format to ensure traceability, with previous versions archived in accordance with Payoro’s record-keeping standards.

Payoro promotes a culture of continuous learning and compliance awareness. Lessons learned from regulatory findings, emerging typologies, and internal case reviews are integrated into future training, monitoring, and risk assessment activities. The Chief Compliance Officer ensures that program enhancements are data-driven, proportionate to risk, and fully documented to demonstrate Payoro’s commitment to maintaining a robust and adaptive compliance environment.