Skip to content

Compliance

A compliance-oriented
control framework

Rampay is designed with compliance-oriented controls as part of the transaction journey rather than as an afterthought. This page describes the framework in principle. It does not describe licences, registrations, approvals or certifications, and none should be inferred.

Rampay does not claim any licence, registration, authorization, approval or certification on this website. Requirements applicable to any integration are confirmed during onboarding.

Two levels of due diligence

Business onboarding and customer verification serve different purposes.

Rampay’s operating model distinguishes between the onboarding of an integrating business relationship and the verification requirements that may apply to an individual end user completing a fiat-to-digital-asset transaction.

Business / Partner — KYB

  • Legal entity information
  • Incorporation details
  • Ownership and control
  • Beneficial owners
  • Directors and authorized representatives
  • Business model
  • Website and digital presence
  • Target markets
  • Customer profile
  • Expected transaction activity
  • Regulatory status where relevant
  • Jurisdictional exposure

End User — KYC

  • Identity information
  • Date of birth
  • Address information
  • Identity documentation
  • Liveness or biometric verification where applicable
  • Customer eligibility
  • Transaction-specific verification
  • Additional information where required
  • Enhanced review where applicable

Exact requirements depend on jurisdiction, transaction characteristics, service configuration and the requirements of the relevant service providers.

Customer due diligence

KYC and customer verification

Know Your Customer (KYC) means identifying an individual customer and verifying that identity before, or as part of, a transaction. Identity and eligibility requirements may vary depending on jurisdiction, customer profile, transaction characteristics and applicable requirements.

Identity verification

Customer identity information may be collected and verified using appropriate verification methods and data sources.

Document review

Identity documentation may be requested and reviewed where required by applicable requirements or risk assessment.

Liveness and authenticity

Additional authenticity or presence checks may be applied depending on the customer profile and transaction characteristics.

Enhanced due diligence

Enhanced measures, including additional information or source-of-funds enquiries, may be required in certain cases.

Ongoing review

Customer information may be reviewed periodically or upon trigger events during the relationship.

Data minimisation

Information requested is intended to be limited to what is appropriate for the applicable verification and control purposes.

Business onboarding

KYB and ownership review

Know Your Business (KYB) means identifying a business counterparty, understanding its ownership and control — including beneficial owners, the individuals who ultimately own or control the entity — and assessing its business model. Production access is subject to successful completion of applicable requirements.

  • Business identity, registration details and corporate documentation
  • Ownership structure, including beneficial ownership where applicable
  • Directors, controllers and authorized representatives
  • Business model, product description and intended use case
  • Customer base characteristics and target jurisdictions
  • Expected transaction activity and operational profile
  • Relevant screening of the business and associated individuals
  • Ongoing review of the business relationship where applicable

AML/CFT principles

Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT)

AML/CFT controls are intended to address the risk that a financial or virtual-asset service is misused for money laundering, terrorist financing or sanctions evasion. The AML/CFT control principles below inform the design of the service and are not a statement of regulatory status.

Risk-based approach

Controls are intended to be applied proportionately, informed by the customer profile, jurisdictional factors and transaction characteristics.

Customer due diligence

Due diligence measures may be applied at onboarding and during the relationship, with enhanced measures in higher-risk cases.

Screening

Screening may be performed against applicable sanctions, watchlist and politically exposed person data sources.

Transaction monitoring

Transaction activity may be monitored for patterns that require further assessment or escalation.

Escalation and review

Cases requiring further assessment may be escalated for internal review before a transaction can proceed.

Record keeping

Records relating to verification, screening and transaction activity may be retained in accordance with applicable requirements.

Screening

Sanctions and screening

Screening is designed to form part of the control framework, subject to the applicable service configuration. Data sources, scope and frequency depend on the applicable configuration and requirements.

  • Screening of customers and, where applicable, associated parties
  • Screening against applicable sanctions and watchlist data sources
  • Politically exposed person considerations where relevant
  • Adverse media considerations where relevant to the risk assessment
  • Re-screening upon relevant trigger events or profile changes
  • Blocking, decline or escalation where a screening outcome requires it

Virtual asset transfers

Originator & Beneficiary Information

Certain virtual asset transfers may be subject to requirements concerning originator and beneficiary information, depending on the jurisdictions, parties and service model involved. Applicable requirements are determined by the relevant legal, regulatory and service framework.

No representation of Travel Rule implementation or compliance is made on this website unless expressly stated.

Risk controls

Risk-based transaction controls

Controls are intended to be proportionate. Certain transactions may require additional review, may be restricted or may be declined.

Customer risk factors

Profile, verification outcome, jurisdictional exposure and behavioural indicators may inform the assessment.

Transaction risk factors

Amount, frequency, payment characteristics, destination characteristics and pattern indicators may be considered.

Control outcomes

A risk assessment may result in additional verification, additional information requests, review, restriction or decline.

Crypto-specific considerations

Digital asset transactions may involve destination-related and transfer-related considerations relevant to applicable requirements.

Responsibilities

Shared compliance responsibilities

Compliance in an integrated journey is shared. Responsibilities are defined during onboarding and in the applicable contractual documentation.

Rampay

Is designed to coordinate the structured transaction journey and the applicable control stages within the service configuration.

Integrating business

Remains responsible for its own legal and regulatory obligations, its own customer relationship and the accuracy of information it submits.

Service providers

Certain verification, payment, conversion or transfer components may be performed by third parties under the applicable service configuration.

Third-party service components

Where regulated components are performed by others

Certain identity verification, payment, screening, conversion or digital asset transfer activities may be performed by third-party service providers as part of the transaction journey.

Where regulated services are performed by third parties, those services remain subject to the regulatory framework and permissions applicable to the relevant provider.

Certain payment, verification, conversion and digital asset services may be provided through appropriately authorized third-party service providers, depending on jurisdiction and service configuration. Rampay does not represent that a third-party provider’s regulatory status or authorization automatically applies to Rampay.

This page is provided for information purposes only and does not constitute legal, regulatory or compliance advice. It is not a representation of regulatory status, licensing, registration, authorization or certification. Applicable requirements depend on jurisdiction, customer profile, transaction characteristics, service configuration and applicable law.