AML / CFT Policy and Procedures

Last updated: December 2025

1. Purpose

The purpose of this Anti-Money Laundering and Counter-Financing of Terrorism (AML/CFT) Policy is to ensure that Zennopay Inc. ("Zennopay", "Company", "we") maintains robust controls to prevent its platform from being used for money laundering, terrorist financing, fraud, or other financial crimes.

This policy establishes a risk-based framework aligned with:

2. Scope

This policy applies to:

3. Business Overview

Zennopay is a fintech platform enabling cross-border payments for travelers and global users. Core activities include:

Zennopay acts as Merchant of Record where applicable and partners with regulated PSPs for collection, custody, and payout.

4. AML/CFT Governance

4.1 Compliance Officer

Zennopay has appointed a Chief Compliance Officer (CCO) responsible for:

CCO: Aman Pal

4.2 Board & Senior Management Oversight

Senior management is responsible for:

5. Risk-Based Approach

Zennopay adopts a risk-based approach considering:

5.1 Customer Risk

5.2 Geographic Risk

5.3 Product & Transaction Risk

Controls are proportionate to the assessed risk level.

6. Customer Due Diligence (CDD)

6.1 Individual Customers

At onboarding, Zennopay collects and verifies customer identity using Stripe Identity, a regulated identity verification service. Stripe Identity enables automated KYC checks including document verification and biometric validation.

Information collected and verified includes:

6.2 Business Customers (If Applicable)

For merchants or partners, Zennopay collects:

7. Enhanced Due Diligence (EDD)

EDD is applied to high-risk customers, including:

EDD measures may include:

8. Sanctions & Watchlist Screening

Zennopay screens customers and transactions against:

Matches are reviewed and escalated prior to transaction approval.

9. Transaction Monitoring

Zennopay implements a combination of automated and manual transaction monitoring controls to detect and prevent suspicious activity.

9.1 Automated Monitoring

Zennopay leverages Stripe Radar, Stripe's machine-learning-based fraud detection and monitoring system, to:

Stripe Radar signals are used as an initial risk filter before funds are accepted or settled.

9.2 Internal Monitoring Controls

In addition to Stripe Radar, Zennopay applies internal monitoring to identify:

Alerts generated by Stripe Radar or internal systems are reviewed by the compliance team and documented with appropriate actions taken.

10. Suspicious Activity Reporting (SAR)

Zennopay files Suspicious Activity Reports (SARs) with FinCEN when:

SARs are filed confidentially and within regulatory timelines.

11. Record Keeping

Zennopay maintains records for a minimum of 5 years, including:

12. Training & Awareness

All relevant personnel receive:

Training completion is documented.

13. Third-Party & Partner Risk Management

Zennopay conducts due diligence on:

Only regulated and reputable partners are engaged.

14. Data Protection & Confidentiality

All AML/CFT data is:

SARs and investigations are strictly confidential.

15. Policy Review & Updates

This policy is reviewed:

Updates require senior management approval.

16. Enforcement & Disciplinary Action

Violations of this policy may result in: