MIKEPAY INC.
company code 155764322
address of registration
Global Bank Tower, 18th Floor, Suite No. 1801, 50th Street,
Panama City, Republic of Panama
[email protected]
Risk Management & Sanctions Compliance Policy
1. Purpose
This Risk Management & Sanctions Compliance Policy (the "Policy") describes the financial crime prevention measures voluntarily implemented by MIKEPAY INC. ( "Company") in connection with its non-custodial digital wallet platform.
The Company is a technology provider that develops and operates software enabling retail users to create and manage non-custodial digital wallets. The Company does not hold or safeguard customer assets, execute blockchain transactions on behalf of users, or otherwise provide custodial virtual asset services.
As a consequence of its non-custodial business model, many anti-money laundering ("AML"), counter-terrorist financing ("CTF") and transaction monitoring obligations that typically apply to custodial financial institutions or virtual asset service providers do not apply to the Company in the same manner.
Nevertheless, the Company recognizes that digital asset platforms may be exposed to financial crime risks and acknowledges the importance of maintaining appropriate safeguards against the misuse of its services. Accordingly, the Company has voluntarily implemented a number of proportionate financial crime controls designed to:
● promote the responsible use of its platform;
● reduce the risk of fraud, sanctions evasion and other illicit activity;
● support compliance with the onboarding and risk management requirements of regulated service providers integrated into the platform; and
● satisfy the compliance expectations of the Company's banking and institutional partners.
The controls described in this Policy are intended to complement Company's non-custodial business model and should not be interpreted as indicating that the Company performs, or assumes responsibility for, regulatory obligations that remain the responsibility of regulated custodians, exchanges or other financial institutions providing regulated financial services through or alongside the Company’s platform.
2. Business model
The Company develops and operates a non-custodial digital wallet platform for retail users.
The Company's wallet infrastructure is designed so that the Company does not take custody of customer assets or obtain unilateral control over customers' digital assets. Users retain control over the authorization of transactions executed through their wallets, while the Company provides the underlying software and user interface enabling access to the platform.
Accordingly, the Company:
● does not hold customer assets;
● does not have unilateral authority to access or transfer customer assets;
● cannot independently authorize or execute blockchain transactions on behalf of users;
● does not operate as a custodian of customer assets.
Certain financial services that may be accessible through the platform, such as cryptocurrency purchases, sales or swaps, are provided by independent regulated financial service providers. Those providers remain responsible for compliance with their own legal and regulatory obligations, including customer due diligence, sanctions screening and transaction monitoring.
3. Identity Verification
The creation and use of a non-custodial wallet does not, in itself, give rise to statutory customer identification obligations of the kind applicable to custodial financial institutions or virtual asset service providers.
However, certain services made available through the platform are provided by regulated third-party service providers that are subject to applicable AML/CFT, sanctions and customer due diligence obligations.
To facilitate user access to such services and support compliance with the onboarding requirements of those regulated providers, the Company integrates electronic identity verification into its onboarding process. As part of its voluntary risk management framework, and to facilitate user access to such services, the Company has integrated electronic identity verification into the Services. The stage at which identity verification is requested depends on the features and services accessed by the user and may be adjusted by the Company from time to time in light of risk considerations and the requirements of integrated service providers.
Identity verification is performed using a specialized third-party electronic identity verification solution.
Depending on the services requested and applicable compliance requirements, users may be requested to provide:
● full legal name;
● date of birth;
● nationality;
● residential address;
● government-issued identification document;
● liveness verification;
● email address; and
● telephone number.
The identity verification process includes automated document authentication, biometric comparison, liveness detection, sanctions screening, politically exposed person ("PEP") screening and fraud detection checks.
Information collected during the verification process is used solely for identity verification, fraud prevention, compliance purposes and facilitating access to regulated services available through the platform.
Identity verification performed by the Company constitutes an additional layer of risk management and does not replace, and is not intended to discharge, the customer due diligence obligations of regulated service providers. Where necessary for the provision of regulated services, customer identification information and verification results may be made available to the relevant regulated service provider as input information, subject to applicable contractual obligations and data protection requirements. Regulated service providers remain responsible for performing their own independent customer due diligence in accordance with their respective legal and regulatory obligations.
4. Identity Verification Outcomes
Users may access regulated services made available through the platform once identity verification has been successfully completed and no material compliance concerns have been identified.
Identity verification is deemed not be successful in the following, but not limited to, cases:
● government-issued identification documents cannot be authenticated;
● submitted identity documents are expired, altered or otherwise appear fraudulent;
● photographs or documents are incomplete, blurred or unreadable;
● liveness verification cannot be successfully completed;
● biometric comparison does not establish a sufficient match between the user and the submitted identification document;
● duplicate, synthetic or otherwise fraudulent identities are detected;
● mandatory verification information is incomplete or materially inconsistent;
● confirmed sanctions matches are identified; or
● fraud indicators identified during the verification process cannot be satisfactorily resolved.
Where verification cannot be completed successfully, access to regulated services will not be approved.
Where verification issues appear capable of being resolved, such as poor image quality or incomplete documentation, users may be invited to repeat or complete the verification process.
Certain verification outcomes, including potential PEP status or other elevated compliance indicators, may require additional review by the relevant regulated financial service provider before access to regulated services is granted.
5. Blockchain Risk Screening
As the Company provides a non-custodial cryptocurrency wallet, it does not have the technical ability to independently monitor, authorize, approve, prevent, or otherwise control blockchain transactions initiated by users through their Wallets.
However, where users access certain features or Third-Party Services made available through the Services, the Company may utilize blockchain analytics tools to assess publicly available risk indicators associated with blockchain wallet addresses involved in such interactions. Such screening is intended to support fraud prevention, sanctions compliance, and the responsible operation of the Services, and does not constitute monitoring or control of users' blockchain transactions.
The Company utilizes a specialized third-party blockchain analytics solution to perform blockchain wallet risk screening based on publicly available blockchain data.
Blockchain analytics may identify publicly available indicators associated with wallet addresses, including potential exposure to:
● sanctions;
● ransomware;
● darknet marketplaces;
● fraud and scams;
● stolen assets;
● mixers or obfuscation services; and
● other categories of elevated blockchain-related risk.
Blockchain wallet risk screening forms part of the Company's proportionate financial crime risk management measures implemented in connection with the Services. The results of such screening may be taken into account when determining whether certain features or Third-Party Services should be made available to a user and, where appropriate, may be shared with the relevant regulated Third-Party Service provider in accordance with applicable contractual arrangements and legal requirements.
For the avoidance of doubt, the absence of custody or control over users' digital assets and blockchain transactions does not affect the Company's ability to control access to its own software and Services. The Company may restrict, suspend or limit a user's access to certain features or Third-Party Services made available through the platform, including on the basis of the results of identity verification or blockchain wallet risk screening, without thereby taking custody of, or exercising any control over, users' digital assets.
6. Response to Identified Risks and Cooperation with Authorities
Where identity verification outcomes, sanctions screening or blockchain wallet risk screening identify elevated financial crime risk indicators, the Company may take proportionate measures, which may include requesting additional information from the user, restricting, suspending or terminating access to certain features or Third-Party Services, and notifying the relevant regulated Third-Party Service provider in accordance with applicable contractual arrangements and legal requirements.
The Company cooperates with law enforcement agencies and other competent authorities and responds to lawful and duly authorized requests for information in accordance with applicable law. Where required or permitted by applicable law, the Company may preserve and disclose records and information relating to the use of the Services to such authorities.
7. Record Keeping
The Company maintains records relating to identity verification, sanctions screening, blockchain wallet risk screening, and other compliance-related activities performed in connection with the Services.
Such records are generally retained for a period of at least five (5) years following the completion of the relevant verification or screening activity or the termination of the relevant user relationship, or for such longer periods as may be required by applicable legal requirements, the contractual obligations with Third-Party Service providers, and the Company’s legitimate business needs, including security, fraud prevention, dispute resolution, and compliance support.
Access to such records is restricted to authorized personnel and is subject to appropriate technical and organizational measures designed to protect the confidentiality, integrity, and availability of the information.
8. Internal Governance
The Company maintains internal governance and operational procedures designed to support the implementation of the measures described in this Policy.
Responsibility for oversight of the financial crime controls described in this Policy is assigned to the Company's Director, who is responsible for the implementation and maintenance of these measures, for the escalation and resolution of material compliance concerns, and for liaison with the Company's banking and institutional partners on compliance matters.
The Company's internal governance measures include: periodic review of this Policy and the related internal procedures, performed at least annually and additionally upon material changes to the Services or the applicable legal environment; training of relevant personnel on financial crime risks pertinent to the Company's business model; oversight of third-party compliance service providers; and defined escalation procedures for material compliance concerns.
The Company periodically reviews its onboarding processes, compliance controls, and relationships with third-party service providers to ensure that such measures remain appropriate for the Company's business model, the Services offered, and the applicable legal and regulatory environment.
9. Review
This document is reviewed periodically and updated as necessary to reflect changes in Company’s business model, integrated services, applicable legal requirements and financial crime risk profile.
Disclaimer
This document provides a general overview of Company’s financial crime controls for informational purposes. It does not constitute a comprehensive AML policy and may be updated by the Company from time to time to reflect changes in its services, compliance framework or applicable legal and regulatory requirements.