Legal

Risk Appetite, AML/CFT & Sanctions Policy

Last Updated: 31.01.2026

1. Purpose

This Risk Appetite, AML/CFT & Sanctions Policy (the "Policy") describes TRAPAY's internal framework for identifying, assessing, restricting, and managing business, counterparty, fraud, sanctions, legal, and compliance risks.

The purpose of this Policy is to support:

  • responsible business acceptance;
  • fraud prevention;
  • sanctions compliance;
  • AML/CFT-related risk management;
  • partner/provider requirements;
  • legal and reputational risk management.

TRAPAY applies a risk-based approach to determine whether certain merchants, business customers, counterparties, activities, use cases, structures, or jurisdictions are:

  • acceptable;
  • restricted;
  • or prohibited.

2. About TRAPAY

TRAPAY LTD ("TRAPAY", "we", "us", "our") provides:

  • payment software;
  • technical integrations;
  • routing and automation tools;
  • analytics and reporting;
  • fraud-prevention tooling;
  • technical support and maintenance;
  • related technology services.

TRAPAY is not a bank, payment institution, acquiring bank, issuer, electronic money institution, or payment service provider, and does not itself process, settle, hold, or transfer end-customer funds.

Because TRAPAY operates in a payment-related software environment, it maintains proportionate internal controls relating to business acceptance, sanctions exposure, fraud risk, counterparty transparency, and misuse prevention.

3. Risk-Based Approach

TRAPAY uses a risk-based approach when evaluating merchants, customers, partners, suppliers, and service use cases.

Risk assessment may take into account factors including:

  • business model;
  • products and services offered;
  • transaction and chargeback profile;
  • ownership and control structure;
  • geography and sanctions exposure;
  • licensing and regulatory sensitivity;
  • provider restrictions;
  • technical abuse indicators;
  • complaints and dispute patterns;
  • reputation and public information;
  • transparency and quality of due diligence information.

TRAPAY may approve, decline, restrict, suspend, or terminate access based on the outcome of such risk assessment.

4. Prohibited Counterparties and Structures

TRAPAY does not knowingly engage with or support:

  • sanctioned persons or entities;
  • prohibited counterparties under applicable sanctions law;
  • shell banks;
  • anonymous account structures;
  • opaque ownership structures where beneficial ownership cannot be reasonably established;
  • bearer share structures or equivalent arrangements where unacceptable risk exists;
  • entities or persons that provide false, misleading, or materially incomplete due diligence information.

TRAPAY may refuse relationships where ownership, control, purpose, or source of business cannot be reasonably understood.

5. Prohibited Jurisdictions and Sanctions Exposure

TRAPAY does not knowingly provide services in breach of applicable sanctions laws or where prohibited by internal policy, partner requirements, or legal restrictions.

TRAPAY may prohibit or restrict exposure involving:

  • sanctioned jurisdictions;
  • high-risk jurisdictions;
  • jurisdictions subject to elevated AML/CFT concern;
  • jurisdictions associated with elevated fraud, abuse, enforcement, or reputational risk.

Jurisdictional controls are dynamic and may change over time. TRAPAY may update its approach without prior notice.

Illustrative examples of jurisdictions that may be prohibited or highly restricted depending on applicable law, sanctions, and internal policy at the relevant time include:

  • Afghanistan
  • Belarus
  • Burma
  • Central African Republic
  • Congo
  • Cuba
  • Ethiopia
  • Iran
  • Lebanon
  • Libya
  • Mali
  • Nicaragua
  • North Korea
  • Russia
  • Somalia
  • South Sudan
  • Sudan
  • Syria
  • Venezuela
  • Yemen
  • Zimbabwe

TRAPAY may also apply enhanced restrictions to other jurisdictions depending on legal, provider, fraud, or sanctions considerations.

6. Restricted Business Categories

Certain sectors are considered sensitive or higher risk and may require enhanced due diligence, additional controls, provider approvals, contractual safeguards, or may be declined entirely.

Examples may include:

  • gambling and gaming;
  • forex and speculative trading;
  • adult content;
  • lending and debt-related services;
  • crowdfunding and investment-adjacent models;
  • IPTV and content distribution;
  • VOIP and airtime;
  • future delivery and pre-order models;
  • high-risk digital goods;
  • unregulated or borderline financial activity;
  • businesses with elevated refund, dispute, or chargeback risk.

Restriction does not imply acceptance.

7. AML/CFT and Source-of-Risk Review

Although TRAPAY is not itself a regulated payment institution, it may apply proportionate AML/CFT-related controls where relevant to:

  • business acceptance;
  • counterparty due diligence;
  • provider onboarding requirements;
  • sanctions and fraud risk assessment;
  • suspicious or abnormal activity review.

Depending on the case, TRAPAY may request or review:

  • company registration documents;
  • ownership and UBO information;
  • ID documents;
  • proof of address;
  • licensing information;
  • business model explanations;
  • source of funds or source of wealth information;
  • website and product information;
  • compliance screening results;
  • fraud/risk indicators;
  • supporting technical or operational data.

Failure to provide satisfactory information may result in refusal, restriction, suspension, or termination.

8. Ongoing Monitoring

Risk is not assessed only once.

TRAPAY may monitor and reassess counterparties and activity on an ongoing basis, including in light of:

  • fraud patterns;
  • dispute and chargeback trends;
  • provider feedback;
  • new sanctions developments;
  • ownership changes;
  • complaint patterns;
  • technical abuse indicators;
  • media or public information;
  • regulatory or legal developments.

If risk changes materially, TRAPAY may apply new restrictions or terminate access.

9. Provider, Partner, and Scheme Requirements

TRAPAY may apply restrictions or controls because of:

  • provider onboarding rules;
  • acquirer limitations;
  • bank requirements;
  • scheme expectations;
  • partner compliance frameworks;
  • technical or legal requirements imposed by third parties relevant to the Service.

A business model that is theoretically lawful may still be unacceptable within TRAPAY's ecosystem if it conflicts with provider or partner requirements.

10. Enhanced Review Triggers

Enhanced review may be triggered by factors such as:

  • high-risk business model;
  • unexplained ownership structure;
  • sensitive jurisdiction;
  • mismatch between declared and actual activity;
  • unusual traffic profile;
  • suspicious device/payment behavior;
  • elevated dispute or chargeback rates;
  • sanctions screening alerts;
  • poor-quality or inconsistent documentation;
  • adverse media or integrity concerns;
  • requests to obscure counterparties or transaction purpose.

TRAPAY may require further documentation, explanations, or controls before allowing continued access.

11. Enforcement Measures

Where TRAPAY identifies unacceptable or elevated risk, TRAPAY may, at its sole discretion:

  • refuse onboarding;
  • suspend or restrict access;
  • disable routing or integrations;
  • restrict dashboard functionality;
  • request additional due diligence;
  • terminate the relationship;
  • report information where appropriate or required by law or provider obligations.

TRAPAY may act without prior notice where immediate action is reasonably necessary.

12. Reporting Concerns

Questions or concerns about whether a business, counterparty, transaction profile, or jurisdiction may violate this Policy can be directed to:

info@trapay.uk

TRAPAY may review such concerns internally and determine the appropriate response.

13. Updates

This Policy may be updated from time to time to reflect:

  • changes in sanctions laws;
  • changes in legal or regulatory expectations;
  • provider or partner requirements;
  • fraud and abuse developments;
  • changes in TRAPAY's risk appetite or business model.

The latest version applies upon publication unless otherwise stated.

14. Contact

TRAPAY LTD

Company Number: 17003899

Registered address: 128 City Road, London, United Kingdom, EC1V 2NX

Email: info@trapay.uk