Compliance
A compliance-oriented
control framework
Rampay is designed with compliance-oriented controls as part of the transaction journey rather than as an afterthought. This page describes the framework in principle. It does not describe licences, registrations, approvals or certifications, and none should be inferred.
Rampay does not claim any licence, registration, authorization, approval or certification on this website. Requirements applicable to any integration are confirmed during onboarding.
Two levels of due diligence
Business onboarding and customer verification serve different purposes.
Rampay’s operating model distinguishes between the onboarding of an integrating business relationship and the verification requirements that may apply to an individual end user completing a fiat-to-digital-asset transaction.
Business / Partner — KYB
- Legal entity information
- Incorporation details
- Ownership and control
- Beneficial owners
- Directors and authorized representatives
- Business model
- Website and digital presence
- Target markets
- Customer profile
- Expected transaction activity
- Regulatory status where relevant
- Jurisdictional exposure
End User — KYC
- Identity information
- Date of birth
- Address information
- Identity documentation
- Liveness or biometric verification where applicable
- Customer eligibility
- Transaction-specific verification
- Additional information where required
- Enhanced review where applicable
Exact requirements depend on jurisdiction, transaction characteristics, service configuration and the requirements of the relevant service providers.
Customer due diligence
KYC and customer verification
Know Your Customer (KYC) means identifying an individual customer and verifying that identity before, or as part of, a transaction. Identity and eligibility requirements may vary depending on jurisdiction, customer profile, transaction characteristics and applicable requirements.
Identity verification
Customer identity information may be collected and verified using appropriate verification methods and data sources.
Document review
Identity documentation may be requested and reviewed where required by applicable requirements or risk assessment.
Liveness and authenticity
Additional authenticity or presence checks may be applied depending on the customer profile and transaction characteristics.
Enhanced due diligence
Enhanced measures, including additional information or source-of-funds enquiries, may be required in certain cases.
Ongoing review
Customer information may be reviewed periodically or upon trigger events during the relationship.
Data minimisation
Information requested is intended to be limited to what is appropriate for the applicable verification and control purposes.
Business onboarding
KYB and ownership review
Know Your Business (KYB) means identifying a business counterparty, understanding its ownership and control — including beneficial owners, the individuals who ultimately own or control the entity — and assessing its business model. Production access is subject to successful completion of applicable requirements.
- Business identity, registration details and corporate documentation
- Ownership structure, including beneficial ownership where applicable
- Directors, controllers and authorized representatives
- Business model, product description and intended use case
- Customer base characteristics and target jurisdictions
- Expected transaction activity and operational profile
- Relevant screening of the business and associated individuals
- Ongoing review of the business relationship where applicable
AML/CFT principles
Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT)
AML/CFT controls are intended to address the risk that a financial or virtual-asset service is misused for money laundering, terrorist financing or sanctions evasion. The AML/CFT control principles below inform the design of the service and are not a statement of regulatory status.
Risk-based approach
Controls are intended to be applied proportionately, informed by the customer profile, jurisdictional factors and transaction characteristics.
Customer due diligence
Due diligence measures may be applied at onboarding and during the relationship, with enhanced measures in higher-risk cases.
Screening
Screening may be performed against applicable sanctions, watchlist and politically exposed person data sources.
Transaction monitoring
Transaction activity may be monitored for patterns that require further assessment or escalation.
Escalation and review
Cases requiring further assessment may be escalated for internal review before a transaction can proceed.
Record keeping
Records relating to verification, screening and transaction activity may be retained in accordance with applicable requirements.
Screening
Sanctions and screening
Screening is designed to form part of the control framework, subject to the applicable service configuration. Data sources, scope and frequency depend on the applicable configuration and requirements.
- Screening of customers and, where applicable, associated parties
- Screening against applicable sanctions and watchlist data sources
- Politically exposed person considerations where relevant
- Adverse media considerations where relevant to the risk assessment
- Re-screening upon relevant trigger events or profile changes
- Blocking, decline or escalation where a screening outcome requires it
Virtual asset transfers
Originator & Beneficiary Information
Certain virtual asset transfers may be subject to requirements concerning originator and beneficiary information, depending on the jurisdictions, parties and service model involved. Applicable requirements are determined by the relevant legal, regulatory and service framework.
No representation of Travel Rule implementation or compliance is made on this website unless expressly stated.
Risk controls
Risk-based transaction controls
Controls are intended to be proportionate. Certain transactions may require additional review, may be restricted or may be declined.
Customer risk factors
Profile, verification outcome, jurisdictional exposure and behavioural indicators may inform the assessment.
Transaction risk factors
Amount, frequency, payment characteristics, destination characteristics and pattern indicators may be considered.
Control outcomes
A risk assessment may result in additional verification, additional information requests, review, restriction or decline.
Crypto-specific considerations
Digital asset transactions may involve destination-related and transfer-related considerations relevant to applicable requirements.
Responsibilities
Shared compliance responsibilities
Compliance in an integrated journey is shared. Responsibilities are defined during onboarding and in the applicable contractual documentation.
Rampay
Is designed to coordinate the structured transaction journey and the applicable control stages within the service configuration.
Integrating business
Remains responsible for its own legal and regulatory obligations, its own customer relationship and the accuracy of information it submits.
Service providers
Certain verification, payment, conversion or transfer components may be performed by third parties under the applicable service configuration.
Third-party service components
Where regulated components are performed by others
Certain identity verification, payment, screening, conversion or digital asset transfer activities may be performed by third-party service providers as part of the transaction journey.
Where regulated services are performed by third parties, those services remain subject to the regulatory framework and permissions applicable to the relevant provider.
Certain payment, verification, conversion and digital asset services may be provided through appropriately authorized third-party service providers, depending on jurisdiction and service configuration. Rampay does not represent that a third-party provider’s regulatory status or authorization automatically applies to Rampay.
This page is provided for information purposes only and does not constitute legal, regulatory or compliance advice. It is not a representation of regulatory status, licensing, registration, authorization or certification. Applicable requirements depend on jurisdiction, customer profile, transaction characteristics, service configuration and applicable law.