Transaction Monitoring Policy
How the Company watches the transactions on its rails, investigates what its rules flag, and refers activity it cannot explain to the sponsor bank, which decides whether to file.
| Field | Value |
|---|---|
| Document | Transaction Monitoring Policy |
| Version | 1.0 |
| Owner | AML Compliance Officer |
| Review | Annual, with a calibration review 90 days after launch |
Authorities
This policy implements, within the sponsor bank's program:
- 31 CFR 1020.210, the anti-money-laundering program rule for banks, whose internal-controls and monitoring elements the sponsor bank extends to the program and the Company performs for the transactions on its rails.
- 31 CFR 1020.320, the suspicious activity reporting rule. The sponsor bank is the filer; the Company investigates and refers, and keeps every referral confidential under paragraph (e).
- FFIEC BSA/AML Examination Manual, the Suspicious Activity Reporting section, which sets the expectations for identification, alert management, investigation timeliness, decision documentation, and rule tuning that the program is examined against.
- The sponsor bank's program agreement, which assigns monitoring and investigation to the Company, the filing determination to the bank, and sets the referral, reporting, and change-notice duties between them.
1. Purpose and Scope
This policy sets out how the Company monitors the transactions it processes for unusual or suspicious activity, investigates the alerts its rules produce, and refers activity that cannot be resolved to a legitimate business purpose to the sponsor bank. The Company acts as program manager under its agreement with the sponsor bank. Under that agreement the Company runs transaction monitoring, investigates every alert to a documented resolution, and prepares complete referral packages; the sponsor bank receives those packages and makes the suspicious activity report filing determination.
The policy applies to every transaction processed through the program: settlement flows between the Company and its business customers, and the consumer funds that pass through the Company's rails as customers of those businesses. Monitoring must detect suspicious patterns at both levels, because the Company does not identify consumers itself and sees their activity only as it crosses its rails.
2. Roles and the Sponsor Bank
| Role | Responsibility |
|---|---|
| AML Compliance Officer | Owns the rule library and its thresholds, assigns and oversees investigations, signs off on every referral, approves rule changes, and reports to the sponsor bank |
| Investigator | An analyst designated by the AML Compliance Officer who works alerts to resolution and drafts referral recommendations; at launch this may be the Officer |
| Operations | Delivers the daily transaction populations, maintains the connections to the monitoring systems, and keeps the monitoring log |
| Sponsor bank BSA team | Receives referral packages, makes the filing determination, provides bank-level monitoring as a backstop, and reviews the program's rule calibration |
3. Monitoring Infrastructure
3.1 On-Chain Monitoring
A blockchain analytics platform screens every inbound and outbound stablecoin transaction on the Company's pay-in, payout, and on/off-ramp products in real time. It scores wallet addresses and transactions, identifies exposure to high-risk counterparties such as mixers, darknet markets, ransomware wallets, and sanctioned entities, and flags anomalous on-chain patterns. Before launch the AML Compliance Officer sets the risk categories that block, hold, or alert a transaction and aligns them with the sponsor bank's own blockchain monitoring standards. Alerts are reviewed each business day.
3.2 Fiat Transaction Monitoring
Fiat monitoring runs on the sponsor bank's daily transaction reports covering every ACH, wire, and real-time payment in the program. Until a fiat monitoring platform is deployed, the AML Compliance Officer or a designated analyst reviews each business day's report against the rule library in Section 4, and the sponsor bank's bank-level monitoring serves as a backstop. Once a platform is live, the same rules run in it and the daily review shifts to the alerts it produces.
3.3 Manual Review
Some indicators cannot be captured by rules. The AML Compliance Officer conducts periodic manual reviews of customer account activity, with attention to:
- New customers in their first 90 days after activation, when the relationship and its baseline are still forming
- Tier 2 and Tier 3 customers on the enhanced monitoring schedules in the Customer Identification and Due Diligence Policy
- Customers whose transaction patterns have changed materially from the profile recorded at onboarding
- Any customer about which the Company has received an internal or external concern
4. Rule Library and Its Governance
4.1 Rule Families
Each rule in the library carries an identifier, its logic and launch threshold, the typology it targets, and the rationale for its threshold, so every threshold decision is documented and defensible in sponsor bank testing and independent audit. The library is organized into four families.
| Family | Population | Rules |
|---|---|---|
| A. Business settlement | Funds the Company's direct business customers move for operations and settlement | Volume spike above three times the 30-day rolling average; outgoing wire in a round or near-round amount above the library's dollar floor without a clear justification; a new beneficiary above the floor that is not on the customer's established list; a dormant account of 30 or more days that turns active; five or more transactions with different counterparties in five days, each below the $10,000 reporting threshold, aggregating above the library's floor; any cross-border transfer to a country not disclosed at onboarding |
| B. Consumer pay-in and payout | Consumer funds that pass through the Company's rails as customers of a business customer | Deposit followed by withdrawal of 80 percent or more within 24 hours on a different rail; aggregate consumer volume above twice the expected monthly volume for seven or more days; more than five distinct wallets funding one consumer account in 30 days; a single consumer transaction above the library's floor for its rail; a stablecoin payout where the deposits were fiat; three or more rail-switching cycles in 30 days |
| C. Stablecoin and blockchain | Every stablecoin transaction, screened in real time | Sanctioned address or blocked-list exposure: automatic block, no override below the AML Compliance Officer; severe risk category: held pending review; high risk category: processed with a same-day alert; direct or two-hop exposure to a mixer; clustered-address smurfing velocity; funds bridged from another chain within three hops with an unresolvable or high-risk origin; a wallet funded predominantly from peer-to-peer or decentralized exchanges without identification |
| D. ACH rail integrity | Return and notification-of-change data from the sponsor bank's exception files | Unauthorized return rate alerting at 0.3 percent against the network's 0.5 percent threshold on a rolling 60-day window; overall return rate alerting at 10 percent against 15 percent and administrative returns at 2 percent against 3 percent; a cycle of three or more offsetting credit and debit pairs between related accounts in ten business days; more than three notifications of change for one customer in a month |
Until a customer has a 30-day baseline, the volume rule runs against the expected volume in its onboarding file. Family D runs in observation mode for the first 60 days of operation, because a single return can move a new customer's rate significantly.
4.2 Calibration Context
Thresholds are calibrated to the launch operating profile: a small number of business customers, a modest daily transaction count split across fiat and stablecoin rails, and an expected alert volume of a few alerts per day at most. Sustained alert volume well above that expectation is itself a signal, either that a rule needs tuning or that a genuine cluster of anomalies is under way. Earlier recalibration is triggered if daily transaction volume sustains materially above the launch profile, a new customer type or rail is added, or alert data shows a rule producing persistent noise or persistent silence.
4.3 Rule Execution and the Monitoring Log
Each business day's rule execution, automated and manual, is recorded in the monitoring log: the rules run, the transaction population reviewed, the alerts generated, and the alerts carried open. Where a rule runs manually, the log records that fact per rule per day. The log is the evidence that monitoring operated and is retrievable for sponsor bank testing. Known limitations, such as manual fiat monitoring pending a platform, a single-reviewer dependency, or consumer patterns visible only as they cross the Company's rails, are disclosed to the sponsor bank and factored into the audit scope.
5. Alert Handling and Clocks
5.1 Intake and Assignment
Every alert from the blockchain analytics platform, the fiat monitoring platform once deployed, and manual review is logged in the Company's case management system on the day it is detected; manual alerts are logged the same business day. Each alert is assigned to an investigator within one business day of generation. The AML Compliance Officer assigns or self-assigns.
5.2 Initial Review
Within two business days of assignment the investigator determines whether the alert can be resolved at initial review. An alert may be closed at this stage only as a known exception (the activity matches a documented and approved pattern for the customer), an obvious business explanation (the activity is explained by public information or a simple inquiry to the customer), or a technical error (a system or data quality issue). The resolution reason is documented; no alert is closed without written justification. Anything else opens a full investigation case.
5.3 Investigation Timeline
| Stage | Clock | Notes |
|---|---|---|
| Alert generated and logged | Same day as detection | Automated alerts log automatically; manual alerts log the same business day |
| Alert assigned to investigator | Within 1 business day | AML Compliance Officer assigns or self-assigns |
| Initial review: resolve or open a case | Within 2 business days of assignment | Written resolution, or a full investigation case opened |
| Full investigation completed | Within 10 business days of case opening | The AML Compliance Officer may extend a complex case to 20 business days with documentation |
| Referral package sent to the sponsor bank, if warranted | Within 2 business days of the investigation's conclusion | Complete and signed off by the AML Compliance Officer before transmission |
| Sponsor bank filing determination | On the bank's internal timeline | The Company answers any bank follow-up within 2 business days and chases any referral with no response after 30 days |
Alerts and cases past their clock are aged in the case management system and reported in the monthly operating report.
6. Full Investigation
An alert not resolved at initial review proceeds to full investigation. The investigator:
- Pulls the complete transaction history for the customer, consumer account, or wallet address for at least the prior 90 days
- Reviews prior alerts and cases on the same customer and related accounts
- Compares the customer's expected transaction profile from onboarding against its actual activity
- Runs or refreshes watchlist screening on the customer, its beneficial owners, and any new counterparties the investigation identifies
- Reviews open-source information, including news and public records, for relevant context
- Makes a limited, non-leading inquiry to the customer where an explanation is needed. The inquiry must not reveal that an investigation is under way or suggest that a report may be filed
The case file records each step, its result, and the investigator's conclusion, to the workpaper standard the sponsor bank can test.
7. Referral to the Sponsor Bank
7.1 Referral Decision and Sign-off
If the full investigation concludes that the activity cannot be explained by a legitimate business purpose, or that a legitimate explanation exists but does not fully account for the observed pattern, the investigator prepares a referral recommendation. The AML Compliance Officer reviews every recommendation and every package before it is transmitted. No referral package leaves the Company without the Officer's sign-off, and a decision not to refer is documented with the same care as a decision to refer.
7.2 Referral Package Contents
The package sent to the sponsor bank's BSA team includes:
- A narrative summary of the activity: the typology, the facts observed, and why the activity cannot be explained by a legitimate purpose
- The identity of the customer, its beneficial owners, and any other parties involved
- Complete relevant transaction records for the investigation period
- Copies of all alerts, prior cases, and prior referrals on the same customer
- The results of watchlist screening conducted during the investigation
- Any explanation the customer provided
- The investigator's recommendation on urgency: standard, or expedited for time-sensitive activity
7.3 Channels and Follow-up
Before launch the AML Compliance Officer establishes the referral channel and contact protocol with the sponsor bank's BSA team: a secure address for standard referrals, a named contact and phone number for urgent situations, and an agreed acknowledgment timeline for the bank to confirm receipt. The Company tracks every open referral, answers any bank follow-up within two business days, and follows up with the bank on any referral with no response after 30 days. A confirmed sanctions match is a separate emergency: it is blocked and notified to the sponsor bank under the Sanctions Policy's one-hour clock, not routed through the standard referral timeline.
7.4 Confidentiality
The existence of a referral, an investigation, or a suspicious activity report is confidential. The Company does not disclose to any customer, consumer, or other third party that activity has been referred to the sponsor bank or that a report may have been filed. The prohibition binds every employee and contractor, and a breach of report confidentiality is a federal crime.
7.5 Account Handling Pending the Bank's Determination
Between referral and the sponsor bank's filing determination, the Company continues normal account operations unless the bank instructs otherwise, or unless the Company identifies a sanctions match or another emergency that requires an account freeze. The Company does not close or restrict a customer account on the strength of a pending referral alone without coordinating with the sponsor bank.
8. Tuning, Testing, and Change Control
8.1 Calibration Reviews
The launch rule set is a starting point. The AML Compliance Officer conducts a formal calibration review of every threshold in the library 90 days after launch and annually thereafter, evaluating:
- Alert volume and false positive rate by rule
- Referral rate by rule: the alerts that resulted in a referral to the sponsor bank
- Typologies seen in the operating period that no existing rule covers
- The sponsor bank's feedback on the quality and completeness of referral packages
- Regulatory guidance on typologies specific to the Company's customer base and to stablecoins
Findings and threshold changes are recorded in a calibration memo. The monthly operating report in Section 10 supplies the rule-level data the review draws on.
8.2 Change Control
Threshold and rule changes follow the Change Management Policy. A material change, meaning a new rule family, a disabled rule, a threshold raised by more than half, or any change to the sanctioned-address blocking logic, requires the AML Compliance Officer's written approval with its rationale, and is reported to the sponsor bank's compliance team in advance under the Change Management Policy. Lesser changes are documented in the library's change history.
9. Recordkeeping
The following records are retained for at least five years:
- Every alert generated, with its resolution documentation
- Every full investigation case file
- Every referral package transmitted to the sponsor bank
- The sponsor bank's response or filing confirmation for each referral
- The monitoring log
- Calibration review memos and rule change approvals
Records are kept in a form the Company can produce for sponsor bank testing and regulatory examination. The Recordkeeping Policy governs the complete retention schedule.
10. Reporting
The Company delivers a monthly transaction monitoring operating report to the sponsor bank covering rule-level alert counts, the false positive rate, the disposition mix, open case and referral aging against the clocks in Section 5.3, and any threshold breaches. Material rule changes, calibration findings, and known monitoring limitations are reported as Sections 4.3 and 8 require.
11. Effective Date and Approval
This policy is approved by the AML Compliance Officer, reviewed annually and at the 90-day calibration review, and provided to the sponsor bank's compliance team.