AML / KYC Policy
This policy explains the controls we operate to keep FotifyPay clean of money laundering and terrorist financing. It is the customer-facing summary of our internal AML/CTF Manual, approved by our Money Laundering Reporting Officer (MLRO).
1. Regulatory anchors
- EU: Regulation (EU) 2023/1114 (MiCA), Regulation (EU) 2023/1113 (TFR / Travel Rule), Regulation (EU) 2024/1624 (AMLR), Directive (EU) 2024/1640 (AMLD6), Regulation (EU) 2024/1620 (AMLA).
- UK: Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (SI 2017/692); FCA Cryptoasset Register; UK Travel Rule (from 1 September 2023).
- Canada: Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA); FINTRAC MSB registration; Travel Rule for virtual currency (from 1 June 2021).
- International: FATF 40 Recommendations, in particular Recommendation 16 (Wire Transfers).
2. Customer due diligence (CDD)
Standard CDD โ all customers
- Full name, date of birth, residential address.
- Government-issued photo ID + selfie liveness check.
- Sanctions, PEP and adverse-media screening via ComplyAdvantage.
- Email and phone verification.
Enhanced due diligence (EDD)
Triggered when any of the following apply: orders above โฌ1,000 / CA$1,500 / ยฃ900 in a calendar month, jurisdictional risk (FATF grey-listed countries), PEP status, adverse-media hit, or unusual transaction patterns. EDD adds:
- Source-of-funds questionnaire with supporting documents.
- Source-of-wealth questionnaire above โฌ15,000 lifetime volume.
- MLRO sign-off before the order is released.
3. The Travel Rule (Reg. (EU) 2023/1113 / FATF R.16)
For every crypto transfer above the de-minimis threshold, FotifyPay attaches: originator name, account number (your wallet address), originator address (or date of birth + customer ID), beneficiary name, beneficiary account. Inbound transfers without the required data are routed to a sunrise-rule holding state pending counterparty information โ funds are not co-mingled.
4. On-chain screening โ Chainalysis Sanctions Oracle
Every destination wallet address you submit is screened in real time against the Chainalysis on-chain Sanctions Oracle โ the same compliance feed used by Uniswap, Aave and Circle. The Oracle returns a boolean indicating whether the address is on the OFAC Specially Designated Nationals (SDN) list. SDN-listed addresses are refused at the order screen with a polite explanation; no personal data is sent on-chain. Reference: U.S. Treasury OFAC at home.treasury.gov.
5. Ongoing monitoring
We score every transaction in real time using rule-based and ML signals: velocity, structuring patterns, mixer exposure, peel-chain detection, geographic risk. Alerts are triaged by the AML team within four business hours and within one hour for high-severity hits.
6. Suspicious activity reporting (SAR/STR)
We report suspicious transactions to the relevant Financial Intelligence Unit without prior notice to the customer (the "tipping-off" prohibition under Art. 39 AMLD/AMLR). EU SARs go via FIU.net; UK SARs via NCA SAR Online; Canadian STRs via FINTRAC F2R.
7. Record-keeping
CDD documents and transaction records are kept for five years after the end of the customer relationship (Art. 21 AMLR; reg. 40 UK MLR 2017; s. 12.1 PCMLTFA Regulations). Records are encrypted at rest and access-logged.
8. Sanctions framework
We block transactions where any party is listed on:
- EU consolidated financial sanctions list (CFSP).
- UK consolidated list maintained by OFSI.
- Canadian sanctions under SEMA, JVCFOA and the UN Act.
- U.S. OFAC SDN list (screened via Chainalysis Oracle).
9. Governance
- MLRO: appointed under FCA MLR 2017 reg. 21 and PCMLTFA s. 9.6 โ responsible for the AML program, SARs and regulator liaison.
- Compliance Officer: day-to-day operation, training, second-line testing.
- Annual independent review: external audit of the AML program โ required by FINTRAC and best practice in the EU.
- Board oversight: quarterly AML metrics, risk-appetite review, audit findings.
10. Customer awareness
You can help us keep FotifyPay clean by:
- Using your own wallet address โ never a third party's.
- Funding orders from a bank account in your own name.
- Answering source-of-funds questions honestly and promptly.
- Reporting suspicious phishing or impersonation to abuse@fotifypay.com.