AML & CTF Compliance Policy

Last updated
Last updated: August 2026
Implementation Date: August 2026
Version: 1.0
Next Update: August 2027
Approved By: Zineb El Moustaooui, Compliance Officer
Document Classification: Public
Contents
  1. 1. Policy Statement
  2. 1.1 Our Commitment
  3. 1.2 Anti-Bribery
  4. 1.3 Canadian Regulatory Background & Context
  5. 1.4 Compliance Program
  6. 1.5 Operational Compliance
  7. 2. AML & CTF Basics
  8. 2.1 How Money Laundering & Terrorist Financing Work
  9. 3. Canadian Regulatory Background & Requirements
  10. 3.1 Money Services Businesses
  11. 3.2 FINTRAC
  12. 3.3 Revenu Québec
  13. 3.4 Provincial Securities Regulators
  14. 3.5 Regulator Examinations
  15. 3.6 Ministerial Directives
  16. 4. Roles & Responsibilities
  17. Senior Management & Board of Directors
  18. 5. Canadian AML Compliance Program Components
  19. 5.1 Policy & Procedures
  20. 5.2 Risk Assessment
  21. 5.3 Compliance Officer
  22. 5.4 AML Compliance Effectiveness Review
  23. 5.5 Training & Training Plan
  24. 6. Operational Compliance
  25. 6.1 FINTRAC Foreign MSB Registration
  26. 6.2 Reporting
  27. 6.3 Responding to Law Enforcement Requests
  28. 6.4 Record Keeping
  29. 6.5 Customer Authentication & KYC
  30. 6.6 Business Relationships
  31. 6.7 Risk Ranking & Transaction Monitoring
  32. 7. Penalties for Non-Compliance
  33. Criminal Penalties
  34. Administrative Monetary Penalties (AMPs)
  35. 8. Appendix: Definitions & Acronyms
  36. Contact

1. Policy Statement

1.1 Our Commitment

1001148579 ONTARIO CORPORATION . (ONTARIO) is committed to preventing, detecting and deterring money laundering and terrorist financing and has a zero-tolerance policy in regard to money laundering and terrorist financing. To that end, it is the responsibility of every employee (including contract and part-time employees) to comply with this program and all related Canadian legislation.

While ONTARIO is committed to having an effective compliance program in place, if we become aware of a non-compliant event, a voluntary self-declaration of non-compliance will be made to FINTRAC.

Our procedures for implementing this policy are described in separate documents, as is our Risk Assessment. This policy pertains to Anti-Money Laundering (AML) obligations in Canada only. Other AML obligations that we may have to comply with, based on jurisdictions we operate in, are contained in separate documents.

This policy applies to all individuals working at all levels of ONTARIO including directors, senior managers, officers, employees, consultants, contractors, part-time and fixed-term workers and casual staff, all of whom are collectively referred to as 'staff' in this document.

Every staff member of ONTARIO receives, at a minimum, annual basic AML & Counter Terrorist Financing (CTF) training as well as anti-fraud and anti-bribery training.

1.2 Anti-Bribery

ONTARIO is committed to conducting business in an ethical and honest manner and is committed to implementing and enforcing systems that ensure bribery is prevented. ONTARIO has zero-tolerance for bribery and corrupt activities. We are committed to acting professionally, fairly, and with integrity in all business dealings and relationships, wherever we operate.

1.3 Canadian Regulatory Background & Context

On July 10, 2019, an amendment to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its enacted regulations was published. The amended regulations state that persons or entities engaged in the business of exchanging, at the request of another person or entity, of virtual currency for funds, funds for virtual currency or one virtual currency for another are considered FMSBs and MSBs, effective June 1, 2020.

Additional provisions, including the requirement to report large virtual currency transactions to FINTRAC and other virtual currency specific obligations set out in the regulations became effective June 1, 2021.

1.4 Compliance Program

Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations, FMSBs and MSBs are required to have an AML & CTF program that consists of these five elements:

  • Written policies and procedures: these list our responsibilities under the law, and what we are doing to meet them

  • A documented Risk Assessment: a document that describes and assesses the risk that our business could be used to launder money or finance terrorism

  • The appointment of a Compliance Officer: the person who is ultimately responsible to develop and maintain our AML and CTF compliance program

  • AML Compliance Effectiveness Reviews: testing and reporting completed either annually or every two years that assesses how well our compliance program is working

  • Training & Training Plan: training must be conducted at least annually to ensure that everyone understands their roles and responsibilities

1.5 Operational Compliance

In addition to our documented program, FMSBs and MSBs are required to operate in a compliant manner. This includes:

  • Collecting and recording customer identification information

  • Know Your Customer (KYC) information

  • Transaction monitoring and customer risk scoring

  • Reporting certain transactions to regulators and government agencies

  • Complying with Ministerial Directives

  • Maintaining appropriate registration and licensing

  • Keeping records

2. AML & CTF Basics

Money laundering is the process of taking money (including virtual currency) obtained by committing a crime and disguising the source to make it appear legitimate. Under the Criminal Code of Canada, it is illegal to launder money or to knowingly assist in laundering money. Under the PCMLTFA and Regulations, we must take steps to be sure that our business is not used to launder money and if we suspect that money laundering may be taking place, we must report it.

Terrorist financing is the process of moving funds in order to pay for terrorist activities. Unlike money laundering, the source of the funds is not always criminal, but the intended use of the funds is criminal. Under the Criminal Code of Canada, it is illegal to knowingly assist in the financing of terrorism, including the possession of terrorist funds or property.

2.1 How Money Laundering & Terrorist Financing Work

Money laundering is described as having three phases by the Financial Action Task Force (FATF):

Placement

In the initial stage, the launderer introduces illegal profits into the financial system. This might be done by breaking up large amounts of cash into less conspicuous smaller sums that are then deposited directly into a bank account, or by purchasing monetary instruments.

Layering

In this phase, the launderer engages in a series of conversions or movements of the funds to distance them from their source. The funds might be channeled through the purchase and sales of investment instruments, or wired through accounts at various banks across the globe.

Integration

The funds re-enter the legitimate economy. The launderer might choose to invest the funds into real estate, luxury assets, or business ventures.

It is not necessary to identify the stage, or even to know that money laundering is taking place, to consider a transaction to be suspicious. It is enough to have "reasonable grounds to suspect" that money laundering may be occurring. If something seems unusual, trust your instincts, and escalate the issue to the Compliance Officer.

3. Canadian Regulatory Background & Requirements

3.1 Money Services Businesses

Based on our service offering to Canadians, ONTARIO is considered a Foreign Money Services Business (FMSB). FMSBs are considered reporting entities under the law in Canada. You are considered to be a FMSB if:

  • Foreign exchange dealing: conducting transactions where one type of currency is exchanged for another

  • Money transfer service: transferring funds using an electronic funds transfer network

  • Dealing in Virtual Currency: exchange of virtual currency for funds, funds for virtual currency or one virtual currency for another

  • You do not have a place of business in Canada

  • You direct your MSB services at persons or entities in Canada

3.2 FINTRAC

The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) is the agency that regulates our industry to ensure that we are meeting our obligations. FINTRAC provides guidance on the obligations set out by the PCMLTFA and how reporting entities should incorporate these obligations into their operations. They have the power to review our documentation and to levy significant penalties if we are not compliant.

FINTRAC is also Canada's financial intelligence unit (FIU). The agency receives reports from reporting entities about transactions and analyses the data. This data is used to assist law enforcement investigations into crimes related to money laundering and terrorist financing.

3.3 Revenu Québec

The Minister of Revenue and Revenu Québec assumed responsibility for the application of the Money-Services Businesses Act from the Autorité des marchés financiers on September 13, 2021. Revenu Québec enforces Québec's Money-Services Business Act (MSB Act) and its enacted regulations.

3.4 Provincial Securities Regulators

Provincial bodies regulate securities dealers and derivatives markets. These bodies require reporting from FMSBs and MSBs that conduct foreign exchange transactions that:

  • Settle over a period longer than 2 business days

  • Contain a rollover provision

  • Are conducted for the purpose of financial speculation

3.5 Regulator Examinations

FINTRAC is responsible for ensuring that we are meeting our obligations. They will periodically request information. Most requests will be time sensitive with 30 calendar days to respond. If we do not respond or respond late, we may be subject to penalties.

3.6 Ministerial Directives

Currently, there are two ministerial directives pertaining to transactions that originate from, or are destined to North Korea (DPRK) and Iran. We do not serve North Korea, Iran or other regions noted in FINTRAC's operational briefs.

4. Roles & Responsibilities

Everyone at ONTARIO has a responsibility to ensure that our AML and CTF compliance program runs smoothly.

Senior Management & Board of Directors

  • Overseeing the AML and CTF compliance program on a high level

  • Receiving regular (at least annual) status reports on the AML and CTF compliance program

  • Being accessible to the Compliance Officer as needed

  • Ensuring the Compliance Officer has adequate resources

  • Ensuring the Compliance Officer is adequately qualified

  • Signing off on AML Compliance Effectiveness Reviews (within 30 days)

Compliance Officer

  • Developing and maintaining the AML and CTF Compliance Program and Risk Assessment

  • Ensuring all employees receive appropriate AML and CTF training at least annually

  • Reporting to Senior Management and Board of Directors on program status

  • Overseeing AML Compliance Effectiveness Reviews

  • Maintaining complete and accurate records

  • Maintaining up to date registration with FINTRAC

  • Maintaining up to date licensing with Revenu Québec

  • Corresponding with FINTRAC and Revenu Québec

All Employees

  • Complying with the requirements set out in the AML and CTF compliance program

  • Reporting certain types of transactions to the Compliance Officer

  • Keeping up to date and accurate customer records

  • Obtaining customer identification when required

  • Completing AML and CTF training when required (at least annually)

  • Being vigilant in identifying potential money laundering or terrorist financing activities

5. Canadian AML Compliance Program Components

As a FMSB directing our services to Canadians, we are required to have in place a Compliance Program made of the elements described below. Our AML/CTF program has been designed to conform to the elements required under Canadian legislation.

5.1 Policy & Procedures

Our policy statements describe what we are required to do, while our procedures describe how we will meet these obligations. Our procedures should be detailed enough that someone could read and follow the steps described.

5.2 Risk Assessment

Our company's Risk Assessment is summarized in a separate document. It describes in detail the risk that our activities could make us vulnerable to terrorist financing or money laundering and the controls that we have in place to prevent, detect and deter money laundering and terrorist financing. The Risk Assessment is reviewed and updated by the Compliance Officer at least every two years.

5.3 Compliance Officer

Senior Management must approve the Compliance Officer's appointment. While the Compliance Officer may or may not be a member of the Senior Management team, the Compliance Officer must always have access to management and the authority to carry out their duties. The Compliance Officer must be accessible to all staff members who may have questions about anti-money laundering, counter terrorist financing or compliance related processes.

5.4 AML Compliance Effectiveness Review

An AML Compliance Effectiveness Review is like an audit that tests our company's AML and CTF compliance program. The review tests two elements: our program documentation (what we say we're doing) and our operations (what we've actually done during a specific period of time). These reviews must be completed at least once every two years.

The Compliance Officer will work to correct any issues noted in the report, which may include updating the AML Compliance Program, creating new controls, updating processes, updating customer records, and providing additional staff training.

5.5 Training & Training Plan

All ONTARIO staff (and any third-party contractors) are required to attend annual training. Management is required to attend bi-annual training and the compliance team attends quarterly training.

New hires receive basic AML and CTF, anti-fraud and anti-bribery training within their first 30 days on the job, as well as specific role-based training carried out by operations and compliance divisions, prior to dealing with customers or customer funds independently.

A minimum score of 80% is required for any training quizzes. The completion of this training is mandatory (non-negotiable).

6. Operational Compliance

Operational Compliance is everything that we do in order to meet our obligations. This includes identifying our customers in some cases, reporting certain types of transactions to FINTRAC and other agencies, and keeping records.

6.1 FINTRAC Foreign MSB Registration

We must register as an FMSB with FINTRAC before conducting any transactions for any Canadian customers. The registration must be maintained, and we must keep registration information up to date, respond to requests within 30 days, renew our registration before it expires, and let FINTRAC know if we stop offering MSB services.

Our FINTRAC registration information:

  • FMSB registration number: C10001709
  • Initial date of registration: 2026-02-19
  • Expiry date of registration: 2029-02-28

6.2 Reporting

ONTARIO must report certain transactions to FINTRAC and other agencies as necessary. All reports have specific timelines in which they must be submitted to FINTRAC.

Report Type Applicability Timing
Electronic Funds Transfer Report (EFTR) Does not apply to ONTARIO 5 working days
Large Cash Transaction Report (LCTR) Does not apply to ONTARIO 15 calendar days
Large Virtual Currency Transactions Report (LVCTR) Applies to ONTARIO 5 working days
Suspicious Transaction Report (STR) Applies to ONTARIO As soon as practicable
Attempted Suspicious Transaction Report (ASTR) Applies to ONTARIO As soon as practicable
Terrorist Property Report (TPR) Applies to ONTARIO Immediately

6.2.1 Electronic Funds Transfers (EFTs)

Financial entities, money services businesses and casinos have to report incoming and outgoing international EFTs of CAD 10,000 or more in a single transaction. Electronic funds transfers must be reported to FINTRAC within five (5) business days.

6.2.2 Large Cash Transactions

Large Cash Transaction Reports (LCTRs) are submitted when a customer conducts transactions, in cash, valued at CAD 10,000 or more in the same 24-hour period. LCTRs must be submitted to FINTRAC within 15 calendar days.

6.2.3 Large Virtual Currency Transactions

Large Virtual Currency Transaction Reports will have to be submitted to FINTRAC when a customer conducts transactions, in virtual currency, valued at CAD 10,000 or more in the same 24-hour period. These reports must be submitted within 5 working days.

6.2.4 Suspicious Transactions & Attempted Suspicious Transactions

STRs and ASTRs are submitted to FINTRAC where there are 'reasonable grounds' to suspect that an activity is related to money laundering or terrorist financing. These reports must be submitted whether or not the transaction is completed.

Important: It is against the law to deliberately "tip off" a customer about a potential investigation. We are, however, protected under Canadian law from any action when we submit a report "in good faith."

6.2.5 Terrorist Property

If we know that we possess property owned or controlled by a terrorist or a terrorist group, we are required to report this immediately to FINTRAC, the RCMP and CSIS using a Terrorist Property Report. These reports are submitted on paper via fax.

6.3 Responding to Law Enforcement Requests

If we receive a request from law enforcement regarding a customer's activities, we must respond as soon as possible. The Compliance Officer handles all law enforcement requests. If you receive a request from law enforcement, contact the Compliance Officer immediately.

6.4 Record Keeping

All records must be kept for at least 5 years from the date the record was created, or the date the last transaction was conducted in the case of accounts. Records required to be kept include:

  • Complete customer identification information

  • Records for Politically Exposed Persons (PEPs) and Heads of International Organizations (HIOs)

  • Copies of every report sent to FINTRAC

  • Large Cash Transaction records

  • Large Virtual Currency Transaction records

  • Internal unusual transaction forms

  • Training records

  • AML Compliance Effectiveness Review reports

  • All FINTRAC correspondence

  • All AML and CTF compliance program documents

  • Customer and business relationship risk ranking documentation

  • Records of enhanced due diligence for higher risk customers

6.5 Customer Authentication & KYC

Every individual or corporate entity must undergo an onboarding process comprised of a questionnaire, customer identification as well as certain additional information. We need to identify our customers and record specific information in the following cases:

  • Any customer with whom we have an ongoing service agreement

  • Virtual currency exchange transactions valued at CAD 1,000 or more

  • Large virtual currency transactions (valued at CAD 10,000 or more)

  • Suspected money laundering or terrorist financing activity

  • Terrorist property

6.5.1 Identification Methods for Individuals

Method Description Status
Government-Issued Photo ID Photo identification document issued by a government that is authentic, valid and current Not currently in use
Credit File Valid and current information from a Canadian credit file in existence for at least three years Not currently in use
Dual Process Valid and current information from two different reliable sources Currently in use
Reliance Information from another RE or affiliated foreign entity Not currently in use
Agents or Mandataries Information in the records of the agent or mandatary Not currently in use

6.5.2 Organizations

When our customers are organizations, we must collect and record the following information:

  • Full legal name (no initials, short forms or abbreviations)

  • Organization's structure (incorporated company, trust, partnership, etc.)

  • Principal business (detailed, without abbreviations)

  • Physical address (not P.O. boxes)

  • Information about Directors and Beneficial Owners

6.6 Business Relationships

We have a business relationship with anyone that has conducted two or more transactions that require identification or any customers that are entities with whom we have entered into an ongoing service agreement.

We must also conduct a Politically Exposed Foreign Person (PEFP), Politically Exposed Person (PEP), Head of an International Organization (HIO), close associate or family member of a PEP determination when we enter into a business relationship with a customer.

6.7 Risk Ranking & Transaction Monitoring

Most of our customers are considered low-risk, however, certain customers will be considered higher risk (medium or high-risk). High-risk customers are subject to regular transaction monitoring and enhanced due diligence.

Transaction monitoring involves the review of customer transaction patterns to look for suspicious indicators. Enhanced due diligence involves additional investigation.

7. Penalties for Non-Compliance

Non-compliance with Parts 1 and 1.1 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act may result in criminal or administrative penalties. FINTRAC has legislative authority to issue an administrative monetary penalty (AMP) to reporting entities that are in non-compliance.

Criminal Penalties

  • Failure to report suspicious transactions: up to CAD 2 million and/or five years imprisonment

  • Failure to report large cash transactions or EFTs: up to CAD 500,000 for first offence, CAD 1 million for subsequent offences

  • Failure to meet record keeping requirements: up to CAD 500,000 and/or five years imprisonment

  • Failure to provide assistance during compliance examination: up to CAD 500,000 and/or five years imprisonment

  • Disclosing STR with intent to prejudice investigation: up to two years imprisonment

Administrative Monetary Penalties (AMPs)

Category of Violation Penalty Range (CAD)
Minor violation $1 to $1,000 per violation
Serious violation $1 to $100,000 per violation
Very serious violation (individual) $1 to $100,000 per violation
Very serious violation (entity) $1 to $500,000 per violation

Warning: FINTRAC may disclose cases of non-compliance to law enforcement when there is extensive non-compliance or little expectation of immediate or future compliance.

8. Appendix: Definitions & Acronyms

AML (Anti-Money Laundering)

Actions taken to detect, deter and prevent money laundering from occurring through our business.

ASTR (Attempted Suspicious Transaction Report)

A report filed with FINTRAC when we have reasonable grounds to suspect that a customer's activities may be related to money laundering or terrorist financing when no transaction was completed.

CTF (Counter Terrorist Financing)

Actions taken to detect, deter and prevent terrorist financing from occurring through our business.

FINTRAC

The Financial Transactions and Reports Analysis Centre of Canada - Canada's financial intelligence unit and our regulator for AML and CTF.

LCTR (Large Cash Transaction Report)

A report filed with FINTRAC when a large cash transaction (CAD 10,000 or more) has taken place. Must be filed within 15 calendar days.

LVCTR (Large Virtual Currency Transaction Report)

A report filed with FINTRAC when a large virtual currency transaction has taken place. Must be filed within 5 working days.

Money Laundering

The process of taking money obtained by committing a crime and disguising the source to make it appear legitimate.

MSB (Money Services Business)

A business that provides services in Canada: foreign exchange, remittance and/or issuing or redeeming monetary instruments.

STR (Suspicious Transaction Report)

A report filed with FINTRAC when we have reasonable grounds to suspect that a transaction is related to money laundering or terrorist financing.

Terrorist Financing

Funding any act of terrorism or committing any act or omission that facilitates the funding of terrorism.

TPR (Terrorist Property Report)

A report filed with several government bodies when we believe that we may be in possession of property or funds owned or controlled by terrorists.

UTR (Unusual Transaction Report)

An internal form used to record the details of any transactions suspected of being related to money laundering or terrorist financing.

Contact

For any questions regarding this policy, please contact the Compliance Officer: compliance@altivest.io


This document forms part of the compliance programme of 1001148579 Ontario Corporation, trading as Altivest, FINTRAC registration C10001709. Questions may be directed to compliance@altivest.io.