ANTI-FRAUD MANAGEMENT POLICY
1. INTRODUCTION
Fraud can have a devastating effect on our company because it could result in significant financial loss and other long-term business repercussions. Any allegations of fraud will be taken seriously, with no exceptions. All individuals, regardless of position, title, or tenure with the company are expected to remain vigilant and report any suspicious activity to the compliance hotline.
This Anti-Fraud Management Policy establishes a clear framework to prevent, detect, report, and respond to fraud and corruption risks within the Company. As a registered Money Services Business (MSB) in Canada, the Company is committed to maintaining the highest standards of integrity and compliance with the PCMLTFA, FINTRAC guidelines, OFAC/UN sanctions, and applicable Canadian laws.
2. SCOPE
The company upholds a zero-tolerance approach regarding fraud and corruption. This policy applies to:
- All directors, officers, employees, contractors, consultants, and temporary staff
- Vendors, agents, and third parties acting on behalf of the Company
- Any person or entity with a business relationship with the Company
It applies to fraud, attempted fraud, account takeover, card testing, synthetic identity fraud, friendly fraud, or any other irregularity involving the Company's operations, assets, data, or reputation.
3. RESPONSIBILITIES
Management: Ensure effective internal controls and technical safeguards. Approve escalations.
Employees: Act honestly, protect credentials, and report suspicions immediately.
Compliance Department: Administer policy, lead investigations, report to regulators (FINTRAC/OFAC).
IT / Security Team: Implement, monitor, and maintain technical controls (firewalls, WAF, SIEM, fraud scoring engines, encryption). Conduct penetration tests.
Risk Committee: Review high-risk EDD cases and approve/decline high-value transactions.
4. TECHNICAL CONTROLS
The Company deploys a layered defense-in-depth strategy to combat fraud:
- IP Verification & Intelligence: Geo-IP validation, Proxy/VPN/Tor detection, IP reputation screening, velocity checks
- OTP Strategy: 6-digit tokens, 5-minute validity, max 3 resend attempts
- Device Verification: Device fingerprinting (100+ attributes), emulator/simulator detection, TLS fingerprinting
- IP Blocking: Automated blacklists, greylisting for suspicious IPs, geo-blocking for sanctioned nations
- Real-Time Transaction Monitoring: Risk scoring 0-100, auto-approve/review/block/SCA required
- 3D Secure 2.x / Strong Customer Authentication (SCA)
5. KYC / CDD / EDD
The Company applies a tiered identification approach based on risk (Standard, Medium, High).
6. SANCTIONS SCREENING
Real-time screening of all customers, beneficiaries, and counterparties against OFAC (SDN List), UN Consolidated List, and Canadian DFATD list.
7. DISPUTE HANDLING
Automated dispute monitoring, representment process, and prevention measures for high-risk accounts.
8. INCIDENT RESPONSE
Strict SLA adherence for all fraud-related incidents.
9. REGULATORY COMPLIANCE
This policy supports compliance with FINTRAC MSB Registration, Canadian Criminal Code, PIPEDA, OFAC/UN Sanctions, and PCI DSS.
10. REPORTING FRAUD
Any person with reasonable basis for believing fraudulent acts have occurred must report to the Compliance Department immediately. Failure to report is subject to disciplinary action. Retaliation is strictly prohibited.
11. CORRECTIVE & DISCIPLINARY ACTION
Depending on severity, actions range from written warnings to immediate termination, recovery of losses, and referral to law enforcement.
12. CONTACT
For questions about this policy, contact us at:
Email: [email protected]