AML Program Policy
The umbrella anti-money laundering program: its five pillars, the designated officer, governance and board oversight, and how the Company coordinates with the sponsor bank.
| Field | Value |
|---|---|
| Document | AML Program Policy |
| Version | 1.0 |
| Owner | AML Compliance Officer |
| Review | Annual, or on material program change |
Authorities
This policy implements, within the sponsor bank's program:
- 31 U.S.C. 5318(h) and 31 CFR 1020.210, the anti-money laundering program requirements: a written program with internal controls, independent testing, a designated individual, training, and risk-based customer due diligence.
- USA PATRIOT Act section 352, which made the anti-money laundering program a requirement for every financial institution and set its minimum elements.
- FFIEC BSA/AML Examination Manual, the BSA/AML Compliance Program section, which sets the expectations an examiner applies to the program's design, its officer, its training, and its testing.
- The sponsor bank's program agreement, which allocates BSA obligations between the bank and the Company and governs escalation, information sharing, and reporting.
1. Purpose and Scope
This policy describes the Company's anti-money laundering (AML) and Bank Secrecy Act (BSA) compliance program. The Company operates as a program manager under a program agreement with the sponsor bank, a chartered institution supervised by its federal regulator. The program identifies and escalates unusual activity, conducts due diligence on customers, screens for sanctions exposure, maintains records, and coordinates with the sponsor bank on the operational obligations the program agreement assigns to the Company.
The policy applies to every employee, contractor, and service provider involved in operating the sponsor bank program, across the full product suite the Company offers through the bank: operating accounts and managed balances, payment rails, and any credit products the bank originates for the Company's customers. The Company's direct customers are businesses. Where consumers reach the Company through a customer's platform, they are the customer's customers; consumer identification, disclosures, and the other consumer-program obligations sit with the customer under its own licensing, and the Company's program is built for that model with monitoring controls calibrated for the pass-through consumer flows.
2. Regulatory Framework and the Sponsor Bank Relationship
The program is designed consistent with the Bank Secrecy Act (31 U.S.C. 5311 and following) and its implementing regulations at 31 CFR Chapter X, the regulations FinCEN applies to covered financial institutions, the guidance the sponsor bank's regulator applies to bank-partnered program managers, and the sanctions requirements administered by the Office of Foreign Assets Control.
The program agreement between the Company and the sponsor bank governs operational coordination on suspicious activity escalation, sanctions match handling, information-sharing requests, and reporting. The Company operates a program-manager-level AML program designed to fulfill its obligations under that agreement and to give the sponsor bank the records, alerts, and operational support its own BSA program requires. The allocation of BSA obligations under the agreement is confirmed with outside counsel before program launch, and the sponsor bank's program agreement controls wherever it conflicts with this policy.
3. Program Pillars
The program consists of the five elements required of the sponsor bank under 31 CFR 1020.210, implemented at the Company's level so the bank can rely on them.
| Pillar | Company implementation |
|---|---|
| Internal policies, procedures, and controls | This policy and the supporting document suite: the KYC / CIP / KYB Policy, the Transaction Monitoring and Unusual Activity Escalation Procedures, the Sanctions Policy, the Recordkeeping Policy, the Law Enforcement Response Procedures, and the AML Quality Assurance Procedures |
| Designated AML Compliance Officer | A named individual with the authority, resources, and system access to administer the program (section 4) |
| Ongoing employee training | New-hire training within 30 days of start, an annual refresher, and role-specific modules for higher-risk functions |
| Independent testing | An annual independent test by a qualified firm, with the first test scoped within six months of program launch as the sponsor bank requires |
| Customer due diligence | The KYC / CIP / KYB Policy: customer onboarding with risk-tiered due diligence, beneficial ownership verification, and ongoing monitoring |
3.1 Internal Policies, Procedures, and Controls
The Company maintains written policies and procedures for each control in section 6, keeps them current through the review cycle in section 8.2, and tests them through the quality assurance program and the independent test. Each supporting document names its owner and its review cadence.
3.2 Designated AML Compliance Officer
The Company designates one individual as the AML Compliance Officer, with the authority and responsibilities set out in section 4. The designation is made in writing, and the sponsor bank is notified in writing of the designation and of any change to it.
3.3 Training
Every employee and contractor whose role touches the program completes AML training within 30 days of starting, and again at least annually. Staff in higher-risk functions, including onboarding, transaction monitoring, sanctions screening, and payments operations, complete role-specific modules covering the typologies and procedures of their function. Training content is reviewed annually and updated for regulatory changes, product changes, and findings from testing. Completion is tracked by individual, and the completion rate is reported to the board and the sponsor bank.
3.4 Independent Testing
The program is tested at least annually by a qualified firm independent of the program's operation. The first test is scoped and engaged within six months of program launch. The scope covers the pillars in this section, the controls in section 6, and the sponsor bank's program requirements. Findings are assigned an owner and a target date, remediation is tracked to closure, and the report and the remediation status go to the board and the sponsor bank.
3.5 Customer Due Diligence
The program includes risk-based customer identification, beneficial ownership verification, due diligence tiers, and ongoing monitoring and periodic review of every customer, as set out in the KYC / CIP / KYB Policy.
4. Designated AML Compliance Officer
4.1 Designation and Authority
The Company designates an AML Compliance Officer responsible for the day-to-day oversight and administration of this program. The officer has full authority to administer, update, and enforce the program, to make escalation decisions, and to serve as the primary point of contact for the sponsor bank's BSA team, together with the resources and the access to systems and information those responsibilities require. Where the role is filled on an interim basis, the interim designation remains in effect until a permanent officer is hired; the successor is designated in writing and the sponsor bank is notified.
4.2 Responsibilities
The AML Compliance Officer:
- administers and updates this program in response to regulatory changes, product changes, and sponsor bank feedback;
- oversees customer onboarding and the due diligence procedures;
- reviews and approves each unusual activity escalation package before it is sent to the sponsor bank's BSA team;
- coordinates with the sponsor bank's compliance team on suspicious activity inquiries, sanctions match investigations, and section 314(a) requests;
- oversees the training program and tracks completion;
- manages the independent test and oversees remediation of its findings;
- reports on program performance to the chief executive and the board at least quarterly; and
- stays current with BSA/AML regulatory developments affecting the program.
5. Customer and Product Risk Profile
The Company serves business customers. Where the Company's initial customers concentrate in a single industry, the risk profile and the supporting controls are written for that industry and updated before the program expands to a new customer category.
5.1 Customer Risk
The Company's customers can present elevated inherent AML risk relative to general commercial customers. The factors the program is calibrated for include high transaction volumes with variable counterparty exposure; consumer-facing funds that flow through the customer and into the Company's payment infrastructure, which exposes the Company to consumer-level money laundering typologies; variation across jurisdictions in the licensing and legality of a customer's business; business models that occupy a legally uncertain position under state law and warrant additional scrutiny at onboarding and in monitoring; and, where digital asset rails are offered, blockchain-specific typologies including mixers, high-risk addresses, and cross-chain obfuscation.
5.2 Product Risk
Each product line carries its own risk considerations. Operating accounts and managed balances carry lower inherent risk, elevated where a customer uses the account to aggregate and move proceeds at scale. Payments carry moderate to elevated risk by rail: domestic ACH and wire carry standard commercial risk; digital asset pay-in and payout carry elevated risk from pseudonymity, speed, and consumer funding; international wire carries geographic risk that depends on the customer's counterparties. Credit products, such as early-settlement advances and working capital, carry the transaction risk of the underlying settlement flows, and cross-border prefunding raises geographic questions that depend on where the customer routes funds.
6. Program Controls
Each control below is addressed in a standalone supporting document, and this policy governs how those documents fit together.
| Control | Document |
|---|---|
| Customer onboarding and due diligence | KYC / CIP / KYB Policy |
| Beneficial ownership verification | KYC / CIP / KYB Policy |
| Ongoing customer monitoring and periodic review | KYC / CIP / KYB Policy |
| Transaction monitoring, on-chain and fiat | Transaction Monitoring and Unusual Activity Escalation Procedures |
| Unusual activity investigation and escalation to the sponsor bank | Transaction Monitoring and Unusual Activity Escalation Procedures |
| Sanctions screening, coordinated with the sponsor bank | Sanctions Policy |
| Recordkeeping and retention | Recordkeeping Policy |
| Law enforcement response and section 314(a) support | Law Enforcement Response Procedures |
| Staff AML training | AML Training Program |
| Independent testing | Independent AML Audit Plan |
| Quality assurance and ongoing self-testing | AML Quality Assurance Procedures |
7. Coordination with the Sponsor Bank
The relationship with the sponsor bank requires ongoing information sharing on several fronts.
7.1 Unusual Activity Escalation
When transaction monitoring or manual review produces an alert that investigation does not resolve to a business-purpose explanation, the Company prepares an escalation package and routes it to the sponsor bank's BSA team within the timeframes in the Transaction Monitoring and Unusual Activity Escalation Procedures. The sponsor bank makes the suspicious activity report filing determination. The Company answers the bank's follow-up inquiries on any escalation, and never notifies the subject of an escalation or investigation.
7.2 Information Requests
FinCEN section 314(a) requests are directed to the sponsor bank as the BSA-obligated institution. When the bank receives a request that covers the Company's program, the Company searches its customer records and transaction history and returns responsive information to the bank's compliance team within the timeframe the bank specifies. Records are kept in a format that allows a rapid response. The Law Enforcement Response Procedures set out the detail.
7.3 Sanctions Coordination
The Company screens for sanctions exposure at customer onboarding and on an ongoing basis. When a potential match is identified, the Company freezes the relevant transaction or account activity pending investigation and notifies the sponsor bank immediately. The bank makes the determination on blocking, reporting, and account disposition. The Sanctions Policy sets out the detail.
7.4 Periodic Reporting
The Company provides the sponsor bank with periodic compliance reports on the program, including metrics on onboarding completions, enhanced due diligence completions, transaction monitoring alert volumes and disposition rates, training completion rates, and quality assurance findings. The cadence and format are agreed with the bank's compliance team at program launch, and reporting is no less frequent than quarterly.
8. Program Governance
8.1 Program Ownership
The AML Compliance Officer owns this program and is responsible for its day-to-day operation and maintenance. The officer reports directly to the chief executive and has independent authority to enforce the program; individual compliance decisions do not require the chief executive's approval.
8.2 Policy Review and Updates
This policy is reviewed at least annually and updated as needed to reflect changes in the Company's product suite or business model; changes in the sponsor bank agreement or the bank's compliance requirements; regulatory developments affecting BSA/AML requirements; findings from the independent test or the quality assurance program; and regulatory guidance or examination findings relevant to bank-partnered program managers. The AML Compliance Officer approves material changes, and the Company gives the sponsor bank notice of each material change under the change management protocols in the program agreement and the Compliance Management System Policy.
8.3 Board Oversight and Approval
The board and the chief executive hold ultimate responsibility for the program. The board approves this policy at adoption and re-approves it after each annual review or material change. The AML Compliance Officer delivers a compliance report to the board, or its designated committee, at least quarterly and within 30 days of quarter close, covering program performance, material issues, test findings and remediation status, training completion, regulatory developments, and open items with the sponsor bank. The board reviews the report and acts on the material issues it raises, and its review is minuted.
8.4 Program Records
Copies of this policy, every supporting procedure, the officer designation and the sponsor bank's acknowledgment of it, training records, independent test reports and remediation logs, quality assurance reports, and board compliance reports and minutes are retained for at least five years in a format accessible for sponsor bank review and regulatory examination. The Recordkeeping Policy sets the complete retention schedule.
9. Reporting Violations
Any employee, contractor, or service provider who becomes aware of a suspected violation of this policy or of applicable AML law reports it to the AML Compliance Officer immediately, verbally or in writing. No one who makes a good-faith report is retaliated against. A violation may result in disciplinary action up to and including termination of employment or engagement. Where a violation involves potential criminal conduct, the AML Compliance Officer coordinates the response with the sponsor bank and outside counsel.
10. Effective Date and Approval
This policy is approved by the AML Compliance Officer and the board, reviewed annually or on any material program change, distributed to all employees and applicable contractors, and provided to the sponsor bank's compliance team. It supersedes any prior AML policy of the Company. Where this policy conflicts with the sponsor bank's program agreement, the agreement controls and the AML Compliance Officer updates this policy to conform.