KYC Policy
DEVEDGE PAYMENTS LTD. client onboarding, identity verification and due diligence standards.
Last updated: 9 October 2026
1. Purpose and Regulatory Basis
DEVEDGE PAYMENTS LTD. ("DevEdge" or the "Company") is registered as a Money Services Business with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) under MSB registration number N300001689. This Know Your Customer Policy sets out how we identify and verify the clients we serve, and how we assess and manage the risks they present. It is designed to meet the requirements of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its regulations, FINTRAC guidance, and internationally recognized standards issued by the Financial Action Task Force (FATF).
The policy forms part of a broader compliance program of verification, screening and monitoring controls intended to protect DevEdge, its clients and its banking partners against fraud, money laundering, terrorist financing and sanctions evasion. No business relationship is established and no transaction is executed until the applicable verification steps have been completed successfully.
2. Verification of Individuals
Know Your Customer checks apply from the moment an account is first registered and cover every individual who acts for or controls a client, including directors, authorized signatories and beneficial owners. We collect each person's full legal name, date of birth, nationality and residential address, obtain a valid government-issued photo identification document and a recent proof of address, and verify identity using one of the methods permitted under Canadian law, such as the government-issued photo identification method supported by liveness and biometric checks, the credit file method or the dual-process method.
3. Verification of Businesses and Due Diligence Levels
Because DevEdge serves corporate clients, Know Your Business (KYB) verification is at the core of our onboarding. We confirm the legal existence, structure and operating status of every client entity and identify all individuals who directly or indirectly own or control 25 percent or more of it. The depth of review depends on the client's risk profile.
At the basic level, applied to low-risk clients, we verify the entity's legal existence, organizational structure and operational status and identify its directors. At the intermediate level, applied to medium-risk clients, we additionally obtain a complete register of directors and shareholders, identify every ultimate beneficial owner and review an ownership chart showing the full chain of control. Enhanced due diligence is applied to high-risk clients and adds signed source of funds and source of wealth declarations with supporting evidence, background profiles of the beneficial owners, extended sanctions and adverse media screening and open-source research.
4. Risks Addressed at Onboarding
Our onboarding controls are designed around specific risk scenarios. To counter identity fraud we combine government-issued photo identification, proof of address and real-time identity verification, and we use document authentication technology to detect altered or counterfeit documents. To prevent third-party funding, we require source of funds and source of wealth documentation and accept payments only from accounts held in the client's own name.
Complex or opaque corporate structures are addressed by requiring certificates of incorporation, registers of directors and shareholders and other KYB documentation until ownership is fully understood. Clients expected to process high volumes or high-value transactions are subject to enhanced due diligence, which includes a review of financial statements and a documented assessment of their source of funds and wealth.
5. Sanctions, PEP and Adverse Media Screening
All clients, their related persons and, where appropriate, their counterparties are screened at onboarding and on an ongoing basis. Screening covers Canadian sanctions administered by Global Affairs Canada, including measures under the Special Economic Measures Act and the Justice for Victims of Corrupt Foreign Officials Act, the Criminal Code list of terrorist entities, United Nations Security Council sanctions, the OFAC lists maintained by the United States and FATF public statements.
We also determine whether any individual is a politically exposed person, the head of an international organization, or a family member or close associate of such a person, and apply the additional measures the PCMLTFA requires, including senior management approval. Adverse media searches and reviews of transaction behaviour complete the screening process.
6. Client Risk Rating and Periodic Review
Every client receives a risk rating based on its geographic exposure, business sector, ownership structure, expected and actual transaction patterns and background. Ratings are dynamic and are reassessed whenever new information comes to light. Low-risk clients are subject to standard due diligence and are reviewed at least every three years, medium-risk clients receive increased scrutiny and are reviewed annually, and high-risk clients are subject to enhanced due diligence and are reviewed every six months.
Independently of the review cycle, we request updated documents and information when an identity document expires, when a client's risk profile or transaction behaviour changes materially, or when there is a change in the client's beneficial ownership, shareholding or directors. Failure to provide requested updates may lead to restriction or termination of services.
7. Restricted and High-Risk Jurisdictions
DevEdge does not provide services to individuals, entities or businesses located in, incorporated in or otherwise connected with North Korea, Iran, Syria, Sudan, South Sudan, Cuba, Afghanistan, Belarus, Myanmar, Venezuela, Yemen or Russia, or with the territories of Ukraine currently occupied by Russia. Clients with links to jurisdictions identified by FATF as having strategic AML/CFT deficiencies, or otherwise assessed as high risk, are subject to enhanced due diligence and may be declined. This list is kept under review and may be updated as sanctions and risk assessments change.
8. Transaction Monitoring and Regulatory Reporting
Client activity is monitored on an ongoing basis against the profile established at onboarding. Unusual or potentially suspicious activity is escalated to the Compliance Officer for review. In accordance with the PCMLTFA, DevEdge submits suspicious transaction reports, terrorist property reports, large cash transaction reports, electronic funds transfer reports and large virtual currency transaction reports to FINTRAC where the legal thresholds or conditions are met, and applies any ministerial directives in force.
Client information is shared with third parties only where this is required for these regulatory reports or where disclosure is compelled by law, regulation, subpoena or court order. Outside these legal duties, information is not shared without the client's explicit consent.
9. Record Keeping and Data Security
Identification documents, verification records, transaction records, risk assessments, due diligence files and copies of reports are retained for at least five years from the date of the last transaction or the closure of the account, as required by the PCMLTFA. Records are held in a manner that allows them to be provided to FINTRAC within 30 days of a request, and are protected in line with PIPEDA through access controls, encryption and secure storage.
10. Compliance Officer and Staff Training
A designated Compliance Officer is responsible for implementing this policy, approving high-risk relationships and maintaining contact with FINTRAC. All staff involved in onboarding and compliance complete training every quarter covering Canadian customer due diligence standards, the validation of identification documents, the recognition of red flags and the reporting obligations that apply under the PCMLTFA. Training attendance and content are documented and reviewed as part of the two-year effectiveness review of the compliance program.
11. Contact
Questions about this KYC Policy or about the documents required for onboarding may be sent to the DevEdge compliance team at compliance@devedgepay.com. DEVEDGE PAYMENTS LTD., company number BC1579238, jurisdiction British Columbia, Canada, 5780 Victoria Dr Unit #170, Vancouver BC V5P 3W7, Canada, website https://devedgepay.com.