Skip to content

Compliance

A compliance-oriented
control framework

Rampay is designed with compliance-oriented controls as part of the transaction journey rather than as an afterthought. This page describes the framework in principle. It does not describe licences, registrations, approvals or certifications, and none should be inferred.

Customer due diligence

KYC and customer verification

Know Your Customer (KYC) means identifying you and verifying your identity before, or as part of, a transaction. Identity and eligibility requirements may vary depending on jurisdiction, your profile, transaction characteristics and applicable requirements.

Identity verification

Your identity information may be collected and verified using appropriate verification methods and data sources.

Document review

Identity documentation may be requested and reviewed where required by applicable requirements or risk assessment.

Liveness and authenticity

Additional authenticity or presence checks may be applied depending on your profile and transaction characteristics.

Enhanced due diligence

Enhanced measures, including additional information or source-of-funds enquiries, may be required in certain cases.

Ongoing review

Your information may be reviewed periodically or upon trigger events.

Data minimisation

Information requested is intended to be limited to what is appropriate for the applicable verification and control purposes.

What may be reviewed

  • Identity information
  • Date of birth
  • Address information
  • Identity documentation
  • Liveness or biometric verification where applicable
  • Eligibility to use the service
  • Transaction-specific verification
  • Additional information where required
  • Enhanced review where applicable

AML/CFT principles

Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT)

AML/CFT controls are intended to address the risk that a financial or virtual-asset service is misused for money laundering, terrorist financing or sanctions evasion. The AML/CFT control principles below inform the design of the service and are not a statement of regulatory status.

Risk-based approach

Controls are intended to be applied proportionately, informed by your profile, jurisdictional factors and transaction characteristics.

Customer due diligence

Due diligence measures may be applied before and during a transaction, with enhanced measures in higher-risk cases.

Screening

Screening may be performed against applicable sanctions, watchlist and politically exposed person data sources.

Transaction monitoring

Transaction activity may be monitored for patterns that require further assessment or escalation.

Escalation and review

Cases requiring further assessment may be escalated for internal review before a transaction can proceed.

Record keeping

Records relating to verification, screening and transaction activity may be retained in accordance with applicable requirements.

Screening

Sanctions and screening

Screening is designed to form part of the control framework. Data sources, scope and frequency depend on applicable requirements.

  • Screening of customers and, where applicable, associated parties
  • Screening against applicable sanctions and watchlist data sources
  • Politically exposed person considerations where relevant
  • Adverse media considerations where relevant to the risk assessment
  • Re-screening upon relevant trigger events or profile changes
  • Blocking, decline or escalation where a screening outcome requires it

Virtual asset transfers

Originator & Beneficiary Information

Certain virtual asset transfers may be subject to requirements concerning originator and beneficiary information, depending on the jurisdictions and parties involved. Applicable requirements are determined by the relevant legal and regulatory framework.

No representation of Travel Rule implementation or compliance is made on this website unless expressly stated.

Risk controls

Risk-based transaction controls

Controls are intended to be proportionate. Certain transactions may require additional review, may be restricted or may be declined.

Customer risk factors

Profile, verification outcome, jurisdictional exposure and behavioural indicators may inform the assessment.

Transaction risk factors

Amount, frequency, payment characteristics, destination characteristics and pattern indicators may be considered.

Control outcomes

A risk assessment may result in additional verification, additional information requests, review, restriction or decline.

Crypto-specific considerations

Digital asset transactions may involve destination-related and transfer-related considerations relevant to applicable requirements.

Third-party service components

Where regulated components are performed by others

Certain identity verification, payment, screening, conversion or digital asset transfer activities may be performed by third-party service providers as part of the transaction journey.

Where regulated services are performed by third parties, those services remain subject to the regulatory framework and permissions applicable to the relevant provider.

Certain payment, verification, conversion and digital asset services may be provided through third-party service providers, depending on jurisdiction. Rampay does not represent that a third-party provider’s regulatory status automatically applies to Rampay.

Rampay is a brand operated by Dealflow Capital Ltd. (British Columbia Incorporation No. BC1532649), 2-1130 Hachey Ave, Coquitlam, British Columbia, V3K 2H4, Canada. Dealflow Capital Ltd. is registered with FINTRAC as a Money Services Business (Registration No. C100000907) for foreign exchange, money transferring, virtual currency and payment service provider activities. FINTRAC registration is not a licence and is not an endorsement by FINTRAC or the Government of Canada.