1. Scope and Purpose
This Anti-Money Laundering and Counter-Terrorism Financing Policy (the "Policy") establishes the framework, principles, and operational procedures adopted by PagaSul (the "PagaSul") to prevent, detect, and report activities related to money laundering ("ML"), terrorism financing ("TF"), and proliferation financing ("PF").
The Policy applies to all operations of PagaSul, including its branches, subsidiaries, and any affiliated entities. All employees, officers, contractors, and agents acting on behalf of PagaSul are bound by the provisions set forth herein.
PagaSul is committed to maintaining full cooperation with law enforcement agencies, regulatory bodies, and supervisory authorities in the jurisdictions in which it operates. This Policy is subject to an annual review and may be updated at any time to reflect changes in applicable legislation, regulatory guidance, or PagaSul's risk profile.
2. Regulatory Framework and Guiding Principles
PagaSul aligns its AML/CTF programme with the following regulatory standards and international frameworks:
- Applicable domestic AML/CTF legislation in each jurisdiction where PagaSul operates;
- Recommendations issued by the Financial Action Task Force (FATF);
- The AML principles endorsed by the Wolfsberg Group;
- Relevant United Nations Security Council resolutions;
- Sanctions regimes administered by the Office of Foreign Assets Control (OFAC), the European Union, and other competent bodies.
PagaSul adopts a risk-based approach to the design and implementation of its AML/CTF controls, ensuring that resources and preventive measures are proportionate to the identified risks.
3. Key Definitions
3.1 Money Laundering
Money laundering is the process by which the proceeds of criminal activity are converted, transferred, or otherwise manipulated to conceal their illicit origin and create an appearance of legitimacy. The process typically involves three stages:
- Placement — introducing the proceeds of crime into the financial system;
- Layering — conducting a series of transactions designed to obscure the audit trail and distance the funds from their criminal source;
- Integration — reintroducing the laundered proceeds into the legitimate economy in a manner that appears to be lawful.
3.2 Terrorism Financing
Terrorism financing refers to the provision, collection, or making available of funds or other assets — whether from legitimate or illegitimate sources — with the knowledge or intention that such funds will be used, in whole or in part, to carry out terrorist acts or to support terrorist organisations or their associates.
3.3 Proliferation Financing
As defined by the FATF, proliferation financing encompasses the transfer and export of nuclear, chemical, or biological weapons, their means of delivery, and related materials, as well as the financing of such activities.
4. Governance and Organisational Structure
4.1 Senior Management Oversight
The Director of PagaSul bears ultimate responsibility for the effectiveness of PagaSul's AML/CTF programme. Senior management is responsible for establishing a culture of compliance, allocating adequate resources, and ensuring that AML/CTF obligations are integrated into PagaSul's business operations.
4.2 Compliance Officer / MLRO
The Director shall appoint a Compliance Officer who also serves as the Money Laundering Reporting Officer (MLRO). The Compliance Officer is responsible for:
- Overseeing the day-to-day operation of the AML/CTF compliance programme;
- Receiving, evaluating, and filing suspicious transaction reports (STRs);
- Maintaining ongoing liaison with regulatory and law enforcement authorities;
- Ensuring that AML/CTF policies, procedures, and controls remain current and effective;
- Reporting directly to senior management on compliance matters.
4.3 Three Lines of Defence
PagaSul adheres to the three lines of defence model in managing ML/TF risks. The first line comprises business units that own and manage risk as part of their daily operations. The second line consists of the compliance and risk management functions that provide oversight, guidance, and independent challenge. The third line is an independent audit function that provides objective assurance on the effectiveness of the overall framework.
4.4 Audit Function
PagaSul conducts periodic independent reviews of its AML/CTF systems and controls. The scope and frequency of such reviews are determined by PagaSul's risk profile and the scale of its operations. Where appropriate, external auditors may be engaged to provide an independent assessment.
5. Risk-Based Approach
PagaSul employs a risk-based approach to identify, assess, and mitigate ML/TF risks across its operations. This approach enables PagaSul to allocate resources effectively and to apply enhanced controls where risks are elevated, while streamlining processes for lower-risk relationships.
The risk assessment process considers, among other factors:
- The nature, scale, and complexity of PagaSul's products and services;
- The types and profiles of customers, including their geographic locations;
- The volume and value of transactions;
- The delivery channels and technologies used;
- The jurisdictions in which PagaSul and its customers operate.
6. Customer Due Diligence (CDD)
6.1 General Principles
PagaSul does not maintain anonymous accounts, accounts in fictitious names, or correspondent relationships with shell banks. PagaSul applies CDD measures before establishing a business relationship, before carrying out occasional transactions, and whenever there are doubts about the veracity of previously obtained identification data.
6.2 Identification and Verification of Natural Persons
For natural persons, PagaSul obtains and verifies the following information:
- Full legal name;
- Date of birth;
- Nationality;
- Type and number of identity document (passport or national ID card);
- Residential address, verified through a recent utility bill, government correspondence, or bank statement issued within the preceding three months.
6.3 Identification and Verification of Legal Entities
For legal entities, PagaSul obtains and verifies:
- Full legal name and any trading names;
- Date and place of incorporation;
- Registration or incorporation number;
- Registered office address;
- Certificate of incorporation and constitutional documents;
- Details of ownership and control structure;
- Names of all directors;
- Confirmation that the entity remains in good standing and has not been dissolved or struck off.
For merchants and business customers, PagaSul additionally reviews the customer's website and Terms & Conditions to verify that company details, registration data, licensing information (where applicable), and refund/privacy policies are disclosed.
6.4 Beneficial Ownership
PagaSul identifies and records the identity of all beneficial owners. Beneficial owners are defined as natural persons who ultimately own or control 25% or more of the shares or voting rights of a legal entity, or who otherwise exercise ultimate control over the entity's management. For high-risk relationships, this threshold is reduced to 10%.
Where an individual is identified as a beneficial owner, PagaSul obtains: full name, date of birth, nationality, identity document details, and residential address.
6.5 Purpose and Nature of Business Relationship
PagaSul obtains and records information regarding the intended purpose and nature of each business relationship. This may include the nature of the customer's business or occupation, the anticipated volume and types of transactions, the expected source and origin of funds, and the geographic scope of the customer's activities.
6.6 Ongoing Monitoring and Record Updates
PagaSul undertakes periodic reviews of customer records to ensure that identification and verification data remains current and accurate. Reviews are triggered by significant transactions, material changes in account activity patterns, changes in documentation standards, or where PagaSul identifies gaps in existing records.
7. Enhanced Due Diligence (EDD)
Where a customer, product, service, or geographic factor presents a heightened ML/TF risk, PagaSul applies Enhanced Due Diligence measures. The specific nature and extent of EDD measures are proportionate to the identified risk and may include:
- Obtaining additional information on the customer, connected parties, and related accounts;
- Establishing and verifying the source of wealth and source of funds;
- Obtaining senior management approval to commence or continue the relationship;
- Applying enhanced transaction monitoring with increased frequency and scrutiny.
7.1 Politically Exposed Persons (PEPs)
A Politically Exposed Person is an individual who holds or has held a prominent public function, including heads of state, senior government or military officials, senior executives of state-owned enterprises, and important political party officials. The definition extends to immediate family members and known close associates.
When PagaSul identifies a customer or beneficial owner as a PEP, PagaSul:
- Obtains senior management approval for the relationship;
- Takes reasonable measures to establish the source of wealth and source of funds;
- Applies enhanced ongoing monitoring commensurate with the assessed risk;
- Screens the individual against commercially available PEP databases and publicly available information.
7.2 Source of Wealth and Source of Funds
Source of wealth refers to the origin of an individual's total accumulated assets, while source of funds relates to the origin of specific funds involved in a particular business relationship or transaction. PagaSul collects and, where warranted by the risk level, takes reasonable steps to verify information on both, using documents such as audited financial statements, bank statements, payslips, sale or purchase agreements, inheritance documentation, or confirmation letters from professional advisors.
7.3 High-Risk Jurisdictions
PagaSul applies heightened scrutiny to business relationships and transactions involving jurisdictions that:
- Are subject to OFAC, UN, or EU sanctions;
- Are identified as supporting international terrorism;
- Are designated as having strategic AML/CTF deficiencies by the FATF;
- Are classified as offshore financial centres;
- Present elevated corruption risk as indicated by credible international indices (e.g., Transparency International CPI).
In determining the risk associated with a jurisdiction, PagaSul considers circulars from relevant authorities, assessments published by the FATF and FATF-style regional bodies, reports from supranational organisations such as the IMF and the Egmont Group, and other credible governmental and non-governmental sources.
8. Sanctions Compliance
PagaSul maintains a robust sanctions screening programme to ensure that it does not facilitate transactions or maintain relationships with sanctioned individuals, entities, or jurisdictions.
PagaSul screens customers and transactions against the following lists:
- Consolidated United Nations Security Council Sanctions List;
- OFAC Specially Designated Nationals and Blocked Persons List (SDN);
- Other applicable OFAC sanctions lists;
- EU Consolidated Financial Sanctions List.
Screening is performed at the outset of each business relationship, upon any update to the sanctions databases, and prior to executing cross-border transfers. Potential matches are escalated to the Compliance Officer for review and resolution. False positive matches are documented and retained.
In the event that a confirmed match is identified, PagaSul will immediately freeze the relevant funds or assets, refrain from processing the transaction, and report the matter to the appropriate authorities in accordance with applicable law.
9. Prohibited Business Categories
PagaSul does not establish or maintain business relationships with customers operating in the following categories:
- Adult content and pornography;
- Online or offline sale of alcohol and tobacco products;
- Trade in weapons, firearms, munitions, and explosives;
- Non-prescription pharmaceutical products, steroids, diet pills, and unlicensed drug stores;
- Drug paraphernalia;
- Counterfeit goods and intellectual property infringement;
- Financial and other pyramid schemes;
- Fortune-telling, tarot, and similar services;
- Child exploitation material of any kind;
- Escort services and sexual encounter establishments;
- Political organisations and campaign fundraising;
- Unregulated charities and non-profit organisations;
- Unlicensed financial institutions and money service businesses;
- Trade in precious metals, stones, antiques, and high-value collectibles;
- Production or recycling of explosive or nuclear materials;
- Wholesale distribution of unclassified chemicals and allied industrial products;
- Religious organisations (excluding nationally recognised faiths);
This list is non-exhaustive and may be expanded at PagaSul's discretion based on evolving risk assessments.
10. Employee Obligations and Training
10.1 Know Your Employee
PagaSul applies due diligence measures during the hiring process to minimise the risk of insider abuse. This includes identity verification, criminal background checks (where legally permissible), credit checks, and online background research.
10.2 Zero Tolerance
PagaSul maintains a zero-tolerance policy with respect to intentional violations of AML/CTF laws. Any employee found to have committed such violations will face immediate disciplinary action, up to and including termination of employment, and the matter will be referred to the competent authorities.
10.3 Reporting Suspicious Activity
Any employee who suspects or identifies unusual or potentially suspicious activity must immediately report the matter to the Compliance Officer. The Compliance Officer, in conjunction with senior management, will investigate the matter, document all findings, and determine whether a suspicious transaction report should be filed.
10.4 Training Programme
All employees receive AML/CTF training upon joining PagaSul and on an annual basis thereafter. Training covers the legal and regulatory framework, PagaSul's internal policies and procedures, methods of recognising suspicious activity, reporting obligations, and the consequences of non-compliance. Ad-hoc training is provided when regulatory changes occur or when PagaSul's policies are amended. Training effectiveness is assessed through periodic testing, and all training records are retained for the duration of employment and for at least five years following its termination.
11. Record Keeping
PagaSul maintains comprehensive records of all customer identification and verification documents, transaction records, internal reports, and correspondence with regulatory authorities. Records are retained for a minimum of five years following the termination of the business relationship or the completion of the relevant transaction, or for such longer period as may be required by applicable law.
12. Policy Review
This Policy is reviewed at least annually, and more frequently where warranted by changes in legislation, regulatory guidance, PagaSul's risk profile, or the nature of its business activities.
Any amendments to this Policy require the approval of senior management.
© PagaSul. All rights reserved.
