AML & counter-terrorist financing policy
A public summary of the anti-money-laundering and counter-terrorist-financing programme operated by Onyx Bridge Pay Inc.. It explains the controls we apply, what we ask of clients and partners, and the obligations we cannot waive.
- Effective
- 25 August 2026
- Version
- Draft 1.0 — pre-launch
- Applies to
- Clients, partners, staff
Purpose and scope
Onyx Bridge Pay Inc. has zero tolerance for money laundering, terrorist financing, sanctions evasion and the use of our platform for any criminal purpose. This policy summarises the programme we operate to identify, assess, mitigate and report those risks.
It applies to every part of our business: personal and business accounts, transfers, currency exchange, fiat-to-stablecoin conversion, card issuing, the open API, and every White Label partner instance operated on our platform. It binds all directors, employees, contractors and agents.
This page is a summary written for clients and partners. The full internal programme, including our detailed risk assessment, monitoring rules and thresholds, is confidential because disclosing it would help bad actors circumvent our controls.
Regulatory framework
Our programme is built on the requirements applicable to a Canadian money services business and payment service provider, and on international standards.
- The Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations, supervised by FINTRAC.
- Canada’s sanctions legislation, including the Special Economic Measures Act, the Justice for Victims of Corrupt Foreign Officials Act, the United Nations Act and the Criminal Code listings.
- The Retail Payment Activities Act framework for payment service providers, as it applies to our operations.
- The Financial Action Task Force (FATF) Recommendations, including the risk-based approach and the Travel Rule for virtual asset transfers.
- The EU Anti-Money Laundering Directives and the EU Transfer of Funds Regulation, where we serve clients in the European Economic Area or work with EEA partners.
- The sanctions regimes of the United Nations, the European Union, the United Kingdom (OFSI) and the United States (OFAC), which we screen against as a matter of policy.
Governance and accountability
The board of directors owns the programme and approves this policy and the enterprise risk assessment at least annually. Day-to-day responsibility sits with an appointed Chief Anti-Money Laundering Officer (CAMLO) who has direct access to the board, sufficient seniority and resources, and authority to block or exit any relationship.
We operate a three-lines-of-defence model:
- First line — business and operations
- Client-facing and operational teams apply the controls, complete due diligence, escalate concerns and own the risk they create.
- Second line — compliance and risk
- The CAMLO and compliance function set policy, calibrate monitoring, review alerts and escalations, decide reporting, and challenge the first line.
- Third line — independent review
- An internal audit function or external specialist tests the effectiveness of the programme independently of the first two lines.
Risk-based approach
We maintain a documented enterprise-wide risk assessment and assign every client a risk rating that drives the depth of due diligence, the monitoring applied and the frequency of review. The assessment considers:
Scroll the table sideways to see all columns
| Risk factor | Examples we assess |
|---|---|
| Client risk | Legal form, complexity and transparency of ownership, PEP status, adverse media, cash intensity, industry |
| Product risk | Cross-border transfers, stablecoin conversion, card issuing, White Label distribution, API-initiated volume |
| Geographic risk | FATF-listed jurisdictions, countries with weak AML controls, sanctioned or high-corruption territories, tax havens |
| Channel risk | Non-face-to-face onboarding, third-party introducers, partner-distributed relationships |
| Transaction risk | Value, volume, velocity, counterparty concentration, round-sum patterns, unexplained changes in behaviour |
Ratings are refreshed on a defined cycle — high risk at least annually, medium every two years, low every three — and immediately on a trigger event such as a sanctions hit, adverse media, a change of control or unexpected activity.
Customer due diligence
We do not open anonymous, numbered or nominee accounts, and we verify every client before allowing activity.
Individuals
- Verification of full name, date of birth and address using a government-issued photo identity document.
- Document authenticity checks and a biometric liveness check to confirm the applicant is the document holder.
- Determination of tax residence, occupation, source of funds and expected use of the account.
- Screening against sanctions, PEP and adverse media data before activation.
Businesses
- Verification of legal existence through registry evidence, incorporation documents and current standing.
- Identification and verification of all beneficial owners holding 25% or more, directly or indirectly, and of anyone otherwise exercising control.
- Where no individual meets the threshold, identification of the senior managing official.
- Mapping of the ownership and control structure, including intermediate holding entities and trusts.
- Verification of directors and authorised signatories, and of the authority of the person acting for the business.
- Understanding the nature of the business, its customers, its expected corridors and volumes, and its own regulatory status.
Due diligence is ongoing, not a one-off gate. We keep records current, re-verify on triggers and on cycle, and require clients to notify us of relevant changes within 30 days.
Enhanced due diligence
Enhanced due diligence, approved by the CAMLO or a delegated senior committee, applies where risk is elevated. Triggers include:
- A domestic or foreign politically exposed person, a head of an international organisation, or a close associate or family member of one.
- Any connection to a FATF-listed or otherwise high-risk jurisdiction.
- Credible adverse media alleging financial crime, corruption or serious criminality.
- Complex, opaque or frequently changing ownership structures, or the use of bearer instruments.
- Significant or unexplained stablecoin and digital asset activity.
- Transaction volumes or patterns materially inconsistent with the stated profile.
- Clients in sectors we treat as higher risk, such as gaming, precious metals, arms-adjacent trade or unregulated financial intermediation.
Enhanced measures include corroborating source of funds and source of wealth with documentary evidence, obtaining senior management approval before onboarding and for continuation, tightening limits, applying reduced monitoring thresholds, and reviewing the relationship more frequently.
Sanctions and watchlist screening
We screen clients, beneficial owners, directors, authorised users, counterparties and payment message data against consolidated sanctions and watchlist data at onboarding, in real time before executing payments, and on an ongoing basis whenever list data changes.
Potential matches are queued for human review by trained analysts. Confirmed matches are frozen immediately, not returned to the sender, and reported to the competent authority. We do not process any transaction that would breach an applicable sanctions regime, regardless of the commercial consequence.
Stablecoins and digital assets
Where we convert between fiat currency and stablecoins, we apply controls appropriate to virtual asset activity in addition to our standard programme.
- Blockchain analytics screening of every counterparty address, scoring exposure to sanctioned entities, darknet markets, ransomware, mixers, fraud and stolen funds.
- Application of the FATF Travel Rule, collecting and transmitting originator and beneficiary information for qualifying transfers, and refusing transfers where required information is missing.
- Counterparty diligence on the exchanges and virtual asset service providers involved, including whether they are licensed and whether they permit anonymous accounts.
- A prohibition on the use of mixers, tumblers, privacy-enhancing protocols and chain-hopping to obscure provenance.
- Source of funds evidence for significant inbound digital asset value, including on-chain history where necessary.
- Freezing and reporting of assets traced to illicit activity, and refusal to return them to the sending address where doing so would launder the proceeds.
Transaction monitoring
All activity is monitored by automated rules and models combined with human investigation. Rules are calibrated against client risk rating and expected profile, tested for effectiveness and tuned to manage false positives without weakening coverage.
Typologies we monitor for include:
- Structuring and smurfing to stay below reporting thresholds.
- Rapid pass-through activity, where funds arrive and leave with no economic purpose.
- Transactions inconsistent with the client’s stated profile, sector or expected corridors.
- Unexplained third-party funding, or funds that appear to belong to someone other than the account holder.
- Round-sum, repetitive or mirrored payments suggestive of invoice fraud or trade-based laundering.
- Sudden changes in volume, velocity, geography or counterparty concentration.
- Links between apparently unrelated accounts through shared devices, addresses or beneficiaries.
- Activity involving high-risk jurisdictions or newly created counterparties.
Alerts are triaged, investigated with a documented rationale and either closed with reasons or escalated to the CAMLO. Escalation can result in a request for information, restriction of the account, a report to the authorities, or termination of the relationship.
Reporting obligations
We submit the reports required of us, within the statutory deadlines, whether or not the client is aware of them.
Scroll the table sideways to see all columns
| Report | Trigger | Timing |
|---|---|---|
| Suspicious transaction report | Reasonable grounds to suspect a transaction is related to money laundering or terrorist financing, including attempted transactions | As soon as practicable after the measures that established suspicion |
| Large cash transaction report | Receipt of CAD 10,000 or more in cash in a single transaction or in aggregate within 24 hours | Within 15 days |
| Electronic funds transfer report | Qualifying incoming or outgoing international transfers of CAD 10,000 or more | Within 5 working days |
| Large virtual currency transaction report | Receipt of virtual currency equivalent to CAD 10,000 or more | Within 5 working days |
| Terrorist property report | Knowledge or belief that property is owned or controlled by a listed person or terrorist group | Immediately |
Record keeping
We retain identification records, account files, transaction records, risk assessments, screening results, alert investigations, reports filed and supporting evidence for at least five years after the end of the client relationship or the date of the transaction, whichever is later, and longer where another law or an ongoing investigation requires it.
Records are stored securely with integrity controls and audit trails, and can be retrieved and provided to FINTRAC or another competent authority within 30 days of a request. Retention for AML purposes overrides a request for erasure under data protection law, as explained in our privacy policy.
Training and awareness
Every employee and contractor completes AML, sanctions and fraud training before handling client activity and at least annually thereafter, with role-specific modules for onboarding, operations, engineering and partner management.
- Training covers the law, our internal procedures, current typologies and red flags, escalation routes, tipping-off rules and personal criminal liability.
- Comprehension is tested, results recorded and remediation required where an individual does not pass.
- Targeted refreshers are issued when a new typology, regulation or product risk emerges.
- Attendance and completion records form part of the evidence reviewed in our independent review.
Independent review and testing
The effectiveness of the programme is tested by a party independent of the compliance function at least every two years, as required for Canadian reporting entities, and more often where risk or regulatory change warrants it.
The review covers policies and procedures, the risk assessment, the adequacy of due diligence files, screening and monitoring effectiveness, reporting quality and timeliness, training, and record keeping. Findings are reported to the board with owners and deadlines, and remediation is tracked to closure.
Obligations of White Label partners
Partners distributing services on our platform operate inside our compliance perimeter. Before launch, each partner completes full due diligence covering ownership and control, licensing status, target market, product design, and the adequacy of its own financial-crime controls.
- Partners must apply the mandatory onboarding, screening and monitoring standards we specify, and may set stricter controls but never weaker ones.
- Partners must not disable, bypass, delay or mask any control, and must not onboard clients outside the agreed market, sector or geography.
- Partners must appoint a named compliance contact, escalate suspicions to us without delay, and cooperate fully with our investigations and with regulatory requests.
- Partners must retain records to the same standard and make them available to us on request.
- We reserve the right to audit a partner, to require remediation, to suspend onboarding or transaction processing, and to terminate the relationship where controls are inadequate.
Reliance on a partner never transfers our own legal responsibility. Where a partner is itself a regulated entity, we agree in writing which party performs each obligation and how evidence is shared.
Prohibited relationships and activity
We will not establish or maintain a relationship involving:
- Any person, entity or territory subject to applicable financial sanctions.
- Shell banks, or institutions that permit anonymous or unverified accounts.
- Anonymous, nominee or numbered accounts, or accounts operated for an undisclosed principal.
- Unlicensed money service businesses, payment institutions or virtual asset service providers.
- Unlicensed gambling, darknet marketplaces, ransomware, mixers, tumblers and similar obfuscation services.
- Narcotics, illegal weapons, human trafficking, forced labour, child sexual abuse material and other serious criminality.
- Clients who refuse to provide required due diligence information, or who provide false, forged or misleading information.
- Any structure whose apparent purpose is to conceal beneficial ownership or the origin of funds.
Where such a relationship is identified after onboarding, we exit it in a controlled manner consistent with our legal duties, which may include freezing rather than returning funds and filing a report.
Cooperation and contact
We cooperate fully and promptly with FINTRAC, law enforcement, tax authorities, courts and foreign counterparts acting under a lawful request, and we respond to production orders and information requests within the deadlines set.
Staff, clients and partners can raise financial-crime concerns confidentially, including anonymously, through our whistleblowing channel. We prohibit retaliation against anyone who reports a concern in good faith.
- AML and financial crime team
- aml@onyxbridgepay.com
- Chief Anti-Money Laundering Officer
- compliance@onyxbridgepay.com
- Postal address
- Onyx Bridge Pay Inc., 100 King Street West, Suite 5700, Toronto, Ontario M5X 1C7, Canada