AREGHE PAYMENT NETWORK

ANTI-FRAUD MANAGEMENT POLICY

1. INTRODUCTION

Fraud can have a devastating effect on our company because it could result in significant financial loss and other long-term business repercussions. Any allegations of fraud will be taken seriously, with no exceptions. All individuals, regardless of position, title, or tenure with the company are expected to remain vigilant and report any suspicious activity to the compliance hotline.

This Anti-Fraud Management Policy establishes a clear framework to prevent, detect, report, and respond to fraud and corruption risks within the Company. As a registered Money Services Business (MSB) in Canada, the Company is committed to maintaining the highest standards of integrity and compliance with the PCMLTFA, FINTRAC guidelines, OFAC/UN sanctions, and applicable Canadian laws.

2. SCOPE

The company upholds a zero-tolerance approach regarding fraud and corruption. This policy applies to:

  • All directors, officers, employees, contractors, consultants, and temporary staff
  • Vendors, agents, and third parties acting on behalf of the Company
  • Any person or entity with a business relationship with the Company

It applies to fraud, attempted fraud, account takeover, card testing, synthetic identity fraud, friendly fraud, or any other irregularity involving the Company's operations, assets, data, or reputation.

3. RESPONSIBILITIES

Management: Ensure effective internal controls and technical safeguards. Approve escalations.

Employees: Act honestly, protect credentials, and report suspicions immediately.

Compliance Department: Administer policy, lead investigations, report to regulators (FINTRAC/OFAC).

IT / Security Team: Implement, monitor, and maintain technical controls (firewalls, WAF, SIEM, fraud scoring engines, encryption). Conduct penetration tests.

Risk Committee: Review high-risk EDD cases and approve/decline high-value transactions.

4. TECHNICAL CONTROLS

The Company deploys a layered defense-in-depth strategy to combat fraud:

  • IP Verification & Intelligence: Geo-IP validation, Proxy/VPN/Tor detection, IP reputation screening, velocity checks
  • OTP Strategy: 6-digit tokens, 5-minute validity, max 3 resend attempts
  • Device Verification: Device fingerprinting (100+ attributes), emulator/simulator detection, TLS fingerprinting
  • IP Blocking: Automated blacklists, greylisting for suspicious IPs, geo-blocking for sanctioned nations
  • Real-Time Transaction Monitoring: Risk scoring 0-100, auto-approve/review/block/SCA required
  • 3D Secure 2.x / Strong Customer Authentication (SCA)

5. KYC / CDD / EDD

The Company applies a tiered identification approach based on risk (Standard, Medium, High).

6. SANCTIONS SCREENING

Real-time screening of all customers, beneficiaries, and counterparties against OFAC (SDN List), UN Consolidated List, and Canadian DFATD list.

7. DISPUTE HANDLING

Automated dispute monitoring, representment process, and prevention measures for high-risk accounts.

8. INCIDENT RESPONSE

Strict SLA adherence for all fraud-related incidents.

9. REGULATORY COMPLIANCE

This policy supports compliance with FINTRAC MSB Registration, Canadian Criminal Code, PIPEDA, OFAC/UN Sanctions, and PCI DSS.

10. REPORTING FRAUD

Any person with reasonable basis for believing fraudulent acts have occurred must report to the Compliance Department immediately. Failure to report is subject to disciplinary action. Retaliation is strictly prohibited.

11. CORRECTIVE & DISCIPLINARY ACTION

Depending on severity, actions range from written warnings to immediate termination, recovery of losses, and referral to law enforcement.

12. CONTACT

For questions about this policy, contact us at:

Email: [email protected]