AML/KYC Policy

Last Updated: September 1, 2026

1. Introduction and Commitment

Paygatex.io (hereinafter — "Paygatex.io", "we", "us", "our") maintains a policy of zero tolerance for money laundering, terrorist financing, and any other form of illicit financial activity. This AML/KYC Policy (hereinafter — the "Policy") describes the measures we apply to identify our clients, assess risk, monitor activity, and report suspicious behaviour in line with recognised international anti-money laundering and counter-terrorist financing (AML/CTF) standards, including the recommendations of the Financial Action Task Force (FATF).

This Policy applies to all clients, individual and corporate, and is binding on all Paygatex.io employees, officers, contractors, and service providers involved in onboarding, transaction processing, or client support.

2. Definitions

  • "AML/CTF" — Anti-Money Laundering and Counter-Terrorist Financing.
  • "KYC" — Know Your Customer, the process of verifying the identity of a client.
  • "CDD" — Customer Due Diligence.
  • "EDD" — Enhanced Due Diligence.
  • "PEP" — Politically Exposed Person.
  • "UBO" — Ultimate Beneficial Owner.
  • "SAR" — Suspicious Activity Report.

3. Risk-Based Approach

We apply a risk-based approach to AML/CTF compliance, allocating due diligence resources in proportion to the level of risk presented by each client relationship. Risk is assessed across several factors, including:

  • Customer risk — the nature of the client (individual or corporate), source of funds, and business activity;
  • Geographic risk — the client's country of residence, nationality, or place of incorporation, and its associated AML/CTF risk rating;
  • Product/service risk — the specific Services used and their inherent exposure to misuse;
  • Delivery channel risk — whether the relationship is established and conducted remotely or through intermediaries.

Risk profiles are reassessed periodically and whenever we become aware of new information relevant to a client's risk level.

4. Customer Due Diligence (KYC)

4.1. We apply identity verification on a risk basis rather than as a default requirement for every client or transaction. Verification is triggered by factors such as the nature of the Service used, transaction volume or patterns, applicable legal requirements, or the outcome of the risk assessment described in Section 3.

4.2. Where verification is required, we perform Customer Due Diligence, which includes:

  • Verifying the client's identity using reliable, independent documentation or electronic identification means (for individuals: government-issued identity documents; for corporate clients: incorporation documents and identification of directors and Ultimate Beneficial Owners);
  • Understanding the purpose and intended nature of the business relationship;
  • Screening the client against sanctions and Politically Exposed Persons lists;
  • Verifying, where relevant, the source of funds and source of wealth.

4.3. We do not open or maintain anonymous accounts or accounts under obviously fictitious names, regardless of whether full verification has otherwise been triggered.

4.4. Where verification has been requested, clients are required to keep the information provided to us accurate and up to date, and to notify us promptly of any changes.

5. Enhanced Due Diligence (EDD)

We apply Enhanced Due Diligence in higher-risk situations, including where:

  • There are doubts about the veracity or adequacy of previously obtained identification data;
  • The client is identified as a Politically Exposed Person or a close associate/family member of a PEP;
  • The client is a resident of, or the transaction involves, a jurisdiction identified as high-risk by FATF or subject to applicable sanctions regimes;
  • Our risk assessment otherwise indicates an elevated risk of money laundering or terrorist financing.

EDD measures may include obtaining additional identification documents, verifying the source of funds and wealth in greater detail, obtaining senior management approval to establish or continue the relationship, and conducting more frequent ongoing monitoring.

6. Politically Exposed Persons (PEPs)

We screen clients to identify Politically Exposed Persons, including individuals who hold or have held prominent public functions (such as heads of state or government, senior politicians, senior government, judicial, or military officials, senior executives of state-owned enterprises, and senior political party officials), as well as their immediate family members and known close associates. Business relationships with PEPs are subject to Enhanced Due Diligence and senior management approval.

7. Sanctions Screening

We screen clients and transactions against applicable sanctions lists, including those maintained by the United Nations, the European Union, the U.S. Office of Foreign Assets Control (OFAC), and other relevant national or international authorities. We do not establish or maintain business relationships with individuals or entities that are subject to applicable sanctions, and any confirmed match is escalated for immediate review.

8. Ongoing Monitoring

8.1. We monitor client activity on an ongoing basis to ensure that transactions are consistent with our knowledge of the client, their business profile, and their expected pattern of activity.

8.2. We use automated systems to detect unusual or suspicious transaction patterns, including structuring, rapid movement of funds, and transactions inconsistent with a client's declared activity.

8.3. Client identification data is periodically re-verified. The frequency of re-verification depends on the client's risk classification, with higher-risk clients subject to more frequent review.

9. Suspicious Activity Reporting

9.1. Where we know, suspect, or have reasonable grounds to suspect that funds are the proceeds of criminal activity or are related to terrorist financing, we will file a report with the competent authorities in accordance with applicable law.

9.2. In line with applicable "tipping-off" prohibitions, we do not disclose to a client, or to any third party, that a Suspicious Activity Report has been or is being filed, or that we are conducting a related investigation.

9.3. We reserve the right to suspend, restrict, or terminate the provision of Services, and to freeze or block funds, where necessary to comply with our AML/CTF obligations.

10. Restricted Jurisdictions and Prohibited Customers

We do not provide Services to individuals or entities located in, or resident of, jurisdictions subject to comprehensive international sanctions, or where providing the Services would violate applicable law. We apply enhanced scrutiny to clients connected with jurisdictions identified by FATF as high-risk or subject to increased monitoring. A non-exhaustive list of prohibited business categories and activities is set out in Appendix 1 to our .

11. Record Keeping

We retain client identification data, account files, transaction records, and correspondence for a minimum of five (5) years following the termination of the business relationship, or longer where required by applicable law, to enable reconstruction of individual transactions if requested by competent authorities.

12. Staff Training

Employees involved in client onboarding, transaction processing, or compliance functions receive regular training on AML/CTF obligations, red flags for suspicious activity, and internal reporting procedures, updated to reflect changes in applicable law and regulatory guidance.

13. Cooperation with Authorities

We cooperate with law enforcement, regulatory, and supervisory authorities and respond to lawful requests for information within the timeframes required by applicable law.

14. Policy Updates

We review and update this Policy periodically to reflect changes in applicable law, regulatory guidance, and our risk assessment. The current version of this Policy is always available on the Website.

15. Contact Us

If you have any questions about this Policy, please contact us at: