Compliance
A compliance-oriented
control framework
Rampay is designed with compliance-oriented controls as part of the transaction journey rather than as an afterthought. This page describes the framework in principle. It does not describe licences, registrations, approvals or certifications, and none should be inferred.
Customer due diligence
KYC and customer verification
Know Your Customer (KYC) means identifying you and verifying your identity before, or as part of, a transaction. Identity and eligibility requirements may vary depending on jurisdiction, your profile, transaction characteristics and applicable requirements.
Identity verification
Your identity information may be collected and verified using appropriate verification methods and data sources.
Document review
Identity documentation may be requested and reviewed where required by applicable requirements or risk assessment.
Liveness and authenticity
Additional authenticity or presence checks may be applied depending on your profile and transaction characteristics.
Enhanced due diligence
Enhanced measures, including additional information or source-of-funds enquiries, may be required in certain cases.
Ongoing review
Your information may be reviewed periodically or upon trigger events.
Data minimisation
Information requested is intended to be limited to what is appropriate for the applicable verification and control purposes.
What may be reviewed
- Identity information
- Date of birth
- Address information
- Identity documentation
- Liveness or biometric verification where applicable
- Eligibility to use the service
- Transaction-specific verification
- Additional information where required
- Enhanced review where applicable
AML/CFT principles
Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT)
AML/CFT controls are intended to address the risk that a financial or virtual-asset service is misused for money laundering, terrorist financing or sanctions evasion. The AML/CFT control principles below inform the design of the service and are not a statement of regulatory status.
Risk-based approach
Controls are intended to be applied proportionately, informed by your profile, jurisdictional factors and transaction characteristics.
Customer due diligence
Due diligence measures may be applied before and during a transaction, with enhanced measures in higher-risk cases.
Screening
Screening may be performed against applicable sanctions, watchlist and politically exposed person data sources.
Transaction monitoring
Transaction activity may be monitored for patterns that require further assessment or escalation.
Escalation and review
Cases requiring further assessment may be escalated for internal review before a transaction can proceed.
Record keeping
Records relating to verification, screening and transaction activity may be retained in accordance with applicable requirements.
Screening
Sanctions and screening
Screening is designed to form part of the control framework. Data sources, scope and frequency depend on applicable requirements.
- Screening of customers and, where applicable, associated parties
- Screening against applicable sanctions and watchlist data sources
- Politically exposed person considerations where relevant
- Adverse media considerations where relevant to the risk assessment
- Re-screening upon relevant trigger events or profile changes
- Blocking, decline or escalation where a screening outcome requires it
Virtual asset transfers
Originator & Beneficiary Information
Certain virtual asset transfers may be subject to requirements concerning originator and beneficiary information, depending on the jurisdictions and parties involved. Applicable requirements are determined by the relevant legal and regulatory framework.
No representation of Travel Rule implementation or compliance is made on this website unless expressly stated.
Risk controls
Risk-based transaction controls
Controls are intended to be proportionate. Certain transactions may require additional review, may be restricted or may be declined.
Customer risk factors
Profile, verification outcome, jurisdictional exposure and behavioural indicators may inform the assessment.
Transaction risk factors
Amount, frequency, payment characteristics, destination characteristics and pattern indicators may be considered.
Control outcomes
A risk assessment may result in additional verification, additional information requests, review, restriction or decline.
Crypto-specific considerations
Digital asset transactions may involve destination-related and transfer-related considerations relevant to applicable requirements.
Third-party service components
Where regulated components are performed by others
Certain identity verification, payment, screening, conversion or digital asset transfer activities may be performed by third-party service providers as part of the transaction journey.
Where regulated services are performed by third parties, those services remain subject to the regulatory framework and permissions applicable to the relevant provider.
Certain payment, verification, conversion and digital asset services may be provided through third-party service providers, depending on jurisdiction. Rampay does not represent that a third-party provider’s regulatory status automatically applies to Rampay.
Rampay is a brand operated by Dealflow Capital Ltd. (British Columbia Incorporation No. BC1532649), 2-1130 Hachey Ave, Coquitlam, British Columbia, V3K 2H4, Canada. Dealflow Capital Ltd. is registered with FINTRAC as a Money Services Business (Registration No. C100000907) for foreign exchange, money transferring, virtual currency and payment service provider activities. FINTRAC registration is not a licence and is not an endorsement by FINTRAC or the Government of Canada.