1. Compliance Officer
This document provides procedural guidance for 1001148579 ONTARIO CORPORATION (ONTARIO )'s Compliance Officer and any delegates performing tasks on the Compliance Officer's behalf.
2. Staff
For the purposes of this document, references to staff and employees include any other third-party companies that perform relevant functions including customer interactions, customer identification, and transaction related functions.
3. AML Compliance Program Updates
The Compliance Officer will update the anti-money laundering (AML) and counter terrorist financing (CTF) compliance program:
- Annually in the fourth quarter of every calendar year
- Where there are changes to ONTARIO's business model
- Where there are changes to Canadian AML or CTF legislation
- Following AML Compliance Effectiveness Reviews (required every two years) to address any deficiencies identified by the reviewer
- Following regulatory reviews to address any deficiencies identified by the regulator
- In the event of internal process or performance issues requiring remediation
All program updates will be logged and tracked by the Compliance Officer. Records of program updates will be maintained for a minimum of five years.
4. AML Compliance Training & Training Plan
The Compliance Officer will ensure that all staff have received sufficient training to be effective in their roles. Minimum standards for training are set out in the AML & CTF Compliance Policy.
The Compliance Officer or a delegate will maintain a training plan and records of all training sessions conducted, including training sessions outside of new hire and annual employee training for a minimum of five years. The Compliance Officer will also maintain records of all external training sessions attended for the purpose of maintaining up to date knowledge of Canadian AML and CTF legislation and best practices.
5. AML Compliance Effectiveness Reviews
The Compliance Officer will ensure that an AML Compliance Effectiveness Review is conducted at least every two years. The resulting report will be signed-off by Senior Management within 30 days of issue. At a minimum the following must be completed:
- A review of our AML policy and procedure
- A review and testing the effectiveness of our risk assessment
- Interviews with the front desk staff to determine their knowledge of the legislative requirements and company's policies and procedures
- A review of the criteria and process for identifying and reporting attempted suspicious transactions and suspicious transactions
- A sampling of large virtual currency transactions followed by a review of the reporting of such transactions
- A test of the record keeping system for compliance with the legislation
- A test of the customer/client identification procedures for compliance with the legislation
Reviewer Qualifications (minimum requirements):
- Demonstrate sufficient understanding of the Canadian regulatory context
- Have sufficient experience in conducting AML Compliance Effectiveness Reviews in Canada
- Have maintained up to date training and professional qualifications, including the Certified Anti-Money Laundering Specialist designation
6. FINTRAC Registration & Communication
The Compliance Officer will maintain ONTARIO's registration with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) by:
- Ensuring that the renewal of the registration is completed in the time and manner specified by FINTRAC (generally every two years)
- Updating relevant information within 30 days following any changes to ONTARIO's business activities or key personnel
- Responding to any FINTRAC requests for clarification within the required timeframes (generally 30 business days)
- Cancelling our FMSB registration with FINTRAC if ONTARIO ceases to offer MSB services to Canadians (within 30 days)
Updates and renewals are completed using the online money services business (MSB) registry. Records of all updates and renewals are maintained for five years.
7. Ministerial Directives
Under Part 1.1 of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), the Minister of Finance may issue directives requiring reporting entities to apply countermeasures to transactions from designated foreign jurisdictions or entities.
7.1 Ministerial Directive on North Korea (DPRK)
All transactions to and from North Korea must be treated as high-risk, regardless of the amounts.
Measures to mitigate risk include:
- Keeping a record of all transactions to and from North Korea, regardless of amount
- Ensuring customer identity information is up to date
- Exercising customer due diligence (source of funds, purpose of transactions, beneficial ownership)
- Conducting enhanced ongoing monitoring
- Keeping records of all actions
- Reporting suspicious transactions
7.2 Ministerial Directive on Iran
All transactions to and from Iran must be treated as high-risk, regardless of the amounts.
Indicators related to Iran:
- Payment for products by electronic funds transfers that include an Iranian originating or destination address
- Receiving Iranian rial as part of a transaction
- Accepting bank drafts or other negotiable instruments that include an Iranian rial component
8. Reporting
Certain types of transactions must be reported to FINTRAC. Reporting should always be completed by the Compliance Officer, or a designate. All reports have specific timelines.
8.1 Suspicious Transactions & Attempted Suspicious Transactions
STRs and ASTRs are submitted to FINTRAC where there are reasonable grounds to suspect that an activity is related to money laundering or terrorist financing. These reports must be submitted as soon as practicable after completing measures to establish reasonable grounds to suspect.
Simple Suspicion
A "gut feeling" or "hunch" without facts, context or indicators to support it. Lower threshold than reasonable grounds to suspect.
Reasonable Grounds to Suspect
Required threshold to submit an STR. Possibility that an ML/TF offence has occurred. Based on facts, context and ML/TF indicators.
Reasonable Grounds to Believe
Higher threshold than reasonable grounds to suspect. Verified facts supporting the probability that an ML/TF offence has occurred.
Important: It is against the law to deliberately "tip off" a customer about a potential investigation. ONTARIO and all staff are protected under Canadian law from any action when submitting a report "in good faith."
8.2 Large Virtual Currency Transactions
LVCTRs must be submitted to FINTRAC when a customer conducts transactions valued at CAD 10,000 or more in the same 24-hour period. Reports must be submitted within five working days after the transfer/receipt.
8.3 Terrorist Property
TPRs are completed if ONTARIO is in possession of funds or property belonging to a terrorist. TPRs are submitted immediately to FINTRAC, RCMP, and CSIS via fax.
TPR Fax Numbers:
- FINTRAC: 866-226-2346
- RCMP Anti-Terrorist Financing Team: 613-825-7030
- CSIS Financing Unit: 613-369-2303
8.4 Multiple Reports
More than one report may be required for a single transaction. The Compliance Officer will ensure that all applicable report types are filed. All reports must be completed in full and filed on time.
9. Responding to Law Enforcement Requests
ONTARIO may be required to disclose personal information without consent to comply with a subpoena, warrant, court order or other law enforcement request.
If ONTARIO receives a request from law enforcement, the Compliance Officer must be notified immediately. The Compliance Officer will request a subpoena, Court Order, or other evidence in writing. The request should be analyzed and clarification sought if necessary before any information is disclosed.
ONTARIO will retain copies of any and all information disclosed during this process for a minimum of five years.
10. Voluntary Self-Declaration of Non-Compliance
If ONTARIO becomes aware of a non-compliance event, a voluntary self-declaration will be made to FINTRAC in writing by the Compliance Officer.
The declaration must include:
- Company name and Compliance Officer's contact information
- What is the issue and how was it discovered
- For reporting issues: type of report, number of reports impacted, time period, and reason
- For other issues: period of time, reason for occurrence, and resolution plan
Email: VSDONC.ADVNC@fintrac-canafe.gc.ca
11. Customer & Business Relationship Risk Ranking
All customers are required to provide KYC information and identification in order to complete transactions. Customers are divided into low, medium and high risk buckets based on their activities.
Customer and business relationship risk ranking is conducted on an ongoing basis, considering: customer characteristics, products/services/delivery channels used, customer geography (including destination of funds), and any other relevant factors.
12. Customer & Business Relationship Information Updates
Customer information updates include: name, address, email, telephone number, occupation/principal business, and nature/purpose of the business relationship.
Inactive Customers
Required to update information before completing any prescribed transactions (no transactions within past year).
Low/Medium Risk
Required to update information when identification document expires.
High Risk
Required to update information every two years. Subject to enhanced transaction monitoring and enhanced due diligence.
13. Transaction Monitoring
Transactions are monitored to ensure consistency with customer's declared scope and purpose, risk profile, and transactional history. Transactions are monitored for activities that may indicate money laundering or terrorist financing.
Unusual activity is escalated via electronic transaction monitoring alerts and manual staff escalation. Transaction monitoring alerts are resolved by the Compliance Officer or a designate.
Enhanced Due Diligence: For high-risk customers, the Compliance Officer conducts a full review of account activities. Internet-based searches may be performed looking for information related to ML/TF, financial crime, or discrepancies with publicly available information.
14. PEP & HIO Checks
PEP/HIO determinations are required when entering business relationships, conducting periodic monitoring, detecting PEP/HIO connections, or when transferring/receiving CAD 100,000 or more.
Foreign PEPs
Anyone who holds or has ever held positions on behalf of a foreign government. A person determined to be a foreign PEP is forever a foreign PEP.
Domestic PEPs
Anyone who holds or has held (in the last five years) specified positions in Canadian federal, provincial, or municipal government.
Foreign PEPs, their family members and close associates are automatically considered high-risk customers. Senior Management must be notified and sign-off documented within 30 days.
15. List Screening
All customers are screened against publicly available lists including: OFAC list, UNSC consolidated lists, Consolidated Canadian Autonomous Sanctions List, and Public Safety Canada list.
Screening is conducted via third-party service provider (SumSub) at onboarding and periodically thereafter. Potential matches are resolved by the Compliance Officer. In the event of a true match, the account is frozen and reports sent to FINTRAC, CSIS and RCMP.
16. Record Keeping
ONTARIO must maintain specific records to meet legislative obligations. The Compliance Officer will ensure records retention policies are sufficient in:
- Maintaining records required under the PCMLTFA and regulations for at least five years
- Storing all official records in a form and manner that allows retrieval in a timely manner
Generally, if FINTRAC makes a request, information must be delivered within 30 calendar days.
17. Compliance Program Monitoring & Testing
ONTARIO ensures adequacy, adherence, and effectiveness of day-to-day AML & CTF compliance procedures using a risk-based approach. Testing identifies patterns, themes, or trends that may indicate weaknesses.
The Compliance Officer (or designate) will plan and execute testing considering risk and business model changes. Where deficiencies are observed, remediation action plans are created and tracked. Depending on the nature of deficiencies, the Compliance Officer may report findings to Senior Management.
Appendices
18. Sample Compliance Officer Quick Reference
There are 5 key elements that must all be documented:
- 1
- Compliance Officer: A person responsible for the compliance program including communication with regulators
- 2
- Policies & Procedures: Documents explaining obligations and how they are met
- 3
- Risk Assessment: Document describing and quantifying ML/TF risk and controls
- 4
- Training & Training Plan: For all staff handling customers/transactions, delivered at least annually
- 5
- AML Compliance Effectiveness Review: Review testing all elements of the compliance program and operations
Reporting Summary
| Report Type | Timing | Submitted To |
|---|---|---|
| Large Virtual Currency Transaction Report (LVCTR) | 5 working days after transfer/receipt | FINTRAC (electronic) |
| Suspicious Transaction Report (STR) | As soon as practicable | FINTRAC (electronic) |
| Attempted Suspicious Transaction Report (ASTR) | As soon as practicable | FINTRAC (electronic) |
| Terrorist Property Report (TPR) | Immediately | FINTRAC, RCMP, CSIS (fax) |
Record Keeping Requirements
- Records of virtual currency transactions of CAD 1,000 or more
- Complete customer identification information
- Complete records for Politically Exposed Persons (PEPs)
- A copy of every report sent to FINTRAC
- Internal unusual transaction forms and investigation records
- Training session records and attendance
- AML Compliance Effectiveness Review reports
- All FINTRAC correspondence and reporting
- All AML/CTF compliance program documents
- Customer risk ranking documentation
- Enhanced due diligence records for high-risk customers
- Transaction monitoring records
- Signed agreements with service providers
This document forms part of the compliance programme of 1001148579 Ontario Corporation, trading as Altivest, FINTRAC registration C10001709. Questions may be directed to compliance@altivest.io.