Russia Sanctions Compliance and Risk Prevention Policy

Payoro Finance Ltd., Doing Business As (DBA) “Frontnode”, is registered as a Money Services Business (MSB) in Canada, Incorporation number BC1439769, with FINTRAC registration number M23010441. Payoro Finance Ltd. is registered with the Bank of Canada under the Retail Payment Activities Act (RPAA).

1. Purpose

Frontnode is committed to complying with applicable sanctions laws and preventing its services from being used to evade sanctions, conceal prohibited property, or support activities connected with Russia’s war against Ukraine.

This policy explains:

  • the sanctions and anti-money laundering framework applied by Frontnode;
  • which customers, counterparties, assets and transactions are subject to screening;
  • how Frontnode identifies and manages Russia-related sanctions risk;
  • how suspected matches and prohibited property are restricted and reported; and
  • how Frontnode maintains records, governance and staff awareness.

This policy applies to Frontnode’s customers, beneficial owners, authorized representatives, counterparties, transactions, virtual currency wallets, business partners, vendors and personnel.

2. Legal and Regulatory Framework

Frontnode applies Canadian sanctions requirements and related anti-money laundering obligations relevant to its activities as a Canadian MSB. These include, as amended from time to time:

  • the Special Economic Measures Act and the Special Economic Measures (Russia) Regulations;
  • the Justice for Victims of Corrupt Foreign Officials Act and its regulations;
  • the United Nations Act and regulations implementing United Nations sanctions;
  • the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its regulations;
  • the Ministerial Directive on Financial Transactions Associated with Russia, effective 24 February 2024; and
  • applicable sanctions, reporting, property restriction and record-keeping requirements administered or enforced by Canadian authorities, including FINTRAC.

Where a transaction, customer, counterparty, service provider or payment route has a material connection to another jurisdiction, Frontnode may also consider relevant European Union, United Kingdom, United States and United Nations sanctions measures. These additional lists and restrictions are used as risk controls and to meet applicable contractual, banking, payment or correspondent requirements.

Frontnode monitors regulatory developments, including sanctions directed at crypto-asset service providers, wallets, exchanges, stablecoins and other mechanisms used to facilitate sanctions evasion. This includes measures concerning A7A5 and other Russia-linked or ruble-linked crypto-assets where their use is prohibited or presents an unacceptable sanctions risk.

3. Risk Appetite and Service Restrictions

Frontnode does not knowingly provide services to a listed or sanctioned person or entity, process prohibited property, or facilitate a transaction that would breach applicable sanctions. Frontnode also does not support activity intended to circumvent or avoid a sanctions restriction.

Frontnode may reject, restrict or discontinue services involving:

  • persons or entities located or ordinarily resident in Russia where the relationship falls outside Frontnode’s risk appetite or service availability;
  • the Government of the Russian Federation, its representatives, or entities owned or controlled by them;
  • listed persons, listed entities, sanctioned financial institutions, or persons acting on their behalf or for their benefit;
  • Russian ruble transactions, ruble-linked virtual currencies, or crypto-assets subject to sanctions restrictions;
  • wallets, exchanges, custodians, payment channels or counterparties presenting a material Russia-related sanctions-evasion risk; and
  • transactions whose purpose, source of funds or virtual currency, destination, ownership or control cannot be satisfactorily established.

A customer’s nationality, place of birth, name, language or use of a Russian identity document does not, by itself, establish that the customer is sanctioned or that a transaction originates from or is bound for Russia. Frontnode assesses the complete facts and context and may nevertheless apply restrictions where required by law or justified by its documented risk appetite.

4. Customer and Counterparty Screening

Frontnode screens customers and relevant connected persons at onboarding and on an ongoing basis. Screening may include:

  • the customer, directors, beneficial owners, authorized representatives and relevant counterparties;
  • Canadian, United Nations, European Union, United Kingdom and United States sanctions lists, as appropriate;
  • ownership, control, agency and benefit relationships involving a listed person or entity;
  • politically exposed person and adverse media information where relevant to sanctions risk;
  • country of residence, location, business activities, source of wealth, source of funds or virtual currency, and anticipated transaction activity; and
  • changes in customer information, ownership, control, risk profile or sanctions status throughout the relationship.

Potential matches are reviewed using identifying information sufficient to distinguish a true match from a false positive. Frontnode does not rely solely on name matching and may request additional information or documentation before completing its assessment.

5. Russia-Related Transactions

In accordance with the applicable Canadian Ministerial Directive, Frontnode treats every financial transaction determined to originate from or be bound for Russia as high risk, regardless of amount.

For such a transaction, Frontnode applies measures that may include:

  • verifying the identity of every person or entity requesting or benefiting from the transaction;
  • establishing the purpose of the transaction and the source of funds or virtual currency;
  • obtaining and verifying beneficial ownership or control information;
  • examining the sender, beneficiary, wallet, financial institution, payment route and relevant intermediaries;
  • assessing whether there are reasonable grounds to suspect money laundering, terrorist financing or sanctions evasion;
  • obtaining additional documents or information and applying enhanced ongoing monitoring; and
  • declining, restricting, suspending or reporting the transaction where required or appropriate.

Indicators of a transaction originating from or bound for Russia may include Russian originator or beneficiary details, Russian addresses, a Russian ruble component, Russia-linked wallets or service providers, or other facts showing a substantive connection to Russia. Frontnode considers the circumstances as a whole.

6. Wallet and Blockchain Monitoring

Frontnode applies transaction monitoring and blockchain analytics, where appropriate, to identify sanctions exposure and attempts to obscure the origin, destination, ownership or control of virtual currency.

Monitoring may consider exposure to:

  • wallet addresses attributed to listed persons, entities or sanctioned services;
  • sanctioned or high-risk exchanges, custodians, brokers and payment providers;
  • mixers, tumblers, darknet services, ransomware, scams and other illicit typologies;
  • Russia-linked services, ruble-linked assets and mechanisms associated with sanctions evasion;
  • rapid transfers, layering, chain hopping, intermediary wallets and other obfuscation techniques; and
  • indirect exposure through connected wallets or transaction clusters.

Blockchain analytics and risk scores support, but do not replace, human assessment. Frontnode considers the nature, proximity, value, timing and context of identified exposure before deciding what action is appropriate.

7. Product, Access and Third-Party Controls

Frontnode applies proportionate controls across its products and delivery channels, which may include:

  • excluding sanctioned or unsupported virtual currencies and payment methods;
  • blocking access from prohibited or unsupported locations;
  • using IP address, device, payment and geolocation information to identify circumvention attempts;
  • restricting the use of anonymizing technologies where they conceal a prohibited location or relationship;
  • screening relevant vendors, liquidity providers, banking partners and other counterparties; and
  • including sanctions compliance, notification and termination obligations in relevant agreements.

The use of a virtual private network or other privacy technology is not automatically treated as unlawful. Frontnode may, however, refuse or restrict access where such technology prevents required verification or appears to be used to circumvent geographic, sanctions or security controls.

8. Escalation, Restrictions and Reporting

A potential sanctions match, prohibited property concern or suspected sanctions-evasion activity is escalated promptly to Frontnode’s compliance function. Frontnode may pause onboarding, delay or decline a transaction, restrict an account, prevent withdrawal or transfer, or take other protective measures while the matter is reviewed.

Where required by applicable law, Frontnode will:

  • deal with property only as permitted by law and any applicable authorization;
  • make reports or disclosures to FINTRAC or other competent authorities;
  • submit a Suspicious Transaction Report or Listed Person or Entity Property Report where the applicable reporting test is met;
  • preserve relevant funds, virtual currency, information and audit trails; and
  • cooperate with lawful requests from regulators, law enforcement and other competent authorities.

Frontnode will not disclose a report, investigation or restriction where disclosure is prohibited, could prejudice an investigation, or could expose confidential monitoring or security controls.

9. Record-Keeping

Frontnode maintains records sufficient to demonstrate how Russia-related sanctions risks, screening results, transactions and decisions were identified, assessed and resolved.

Depending on the circumstances, these records may include:

  • customer, beneficial ownership and identity verification information;
  • sanctions screening results, potential matches and false-positive assessments;
  • transaction records, wallet addresses and blockchain transaction identifiers;
  • the purpose of a transaction and the source of funds or virtual currency;
  • enhanced due diligence, supporting documents and internal approvals;
  • restrictions, rejections, account actions and compliance decisions;
  • reports, disclosures and communications with competent authorities; and
  • training, monitoring, testing and policy-review records.

Frontnode retains relevant records for at least five years from the date the record was created, the relevant transaction, or the end of the customer relationship, as applicable. Records may be retained for a longer period where required or permitted by law, regulatory direction, legal proceedings, fraud prevention, or the establishment, exercise or defence of legal claims.

Records are protected using appropriate technical and organizational measures. Access is limited to authorized personnel and service providers with a legitimate compliance, legal, security or operational need.

10. Governance, Training and Testing

Frontnode’s compliance function oversees the sanctions compliance framework and escalates material matters to senior management. Responsibilities are allocated through internal policies, procedures and approval authorities.

Frontnode’s governance arrangements include, as appropriate:

  • risk assessments covering customers, products, jurisdictions, delivery channels and virtual currency exposure;
  • documented screening, escalation, reporting and record-keeping procedures;
  • role-based sanctions and sanctions-evasion training for relevant personnel;
  • updates following material legal, regulatory, product or risk developments;
  • quality assurance, control testing and periodic independent review; and
  • management reporting on material matches, incidents, trends and remediation.

Employees and contractors must report suspected sanctions exposure or control failures promptly and must not override, conceal or assist in circumventing a sanctions control. Breaches may result in disciplinary action, termination of access or engagement, account closure, contractual remedies and reporting to competent authorities.

11. Updates to This Policy

Frontnode may update this policy to reflect changes in applicable law, sanctions designations, regulatory guidance, services, delivery channels or identified risk.

The current version will be published on Frontnode’s website. Customers and business partners are encouraged to review this policy periodically.