Anti-Money Laundering and Bank Secrecy Act (AML/BSA) Policy

Last updated: July 15, 2026

Policy details

Policy nameAnti-Money Laundering and Bank Secrecy Act Policy
Policy No.PM 001
Creation year2021
ModificationJuly 15, 2026
Responsible areaCompliance & Risk
Version4.4
Related policies & proceduresP-006 Risk Management Policy
P-007 Ethics Policy
PM-001-01 KYC/-SDD-/-EDD Procedure
P-014 Third-Party Risk Management Policy
P-004 Record Retention Policy

Policy summary. The purpose of the AML/BSA Policy is to help detect and report suspicious activity including the predicate offenses to money laundering and terrorist financing.

1. Purpose: AML Program

Ontop is committed to complying with all applicable global laws and regulations that are binding to Ontop in the jurisdictions where it operates, including laws relating to money laundering, terrorism financing, and proliferation of weapons of mass destruction.

Through this AML/BSA Policy Ontop seeks to ensure that risks associated with money laundering, terrorism financing, and proliferation of weapons of mass destruction are properly identified, addressed, and mitigated. At the parent company level, Ontop establishes policies that define the minimum standards, governing policies, principles, and controls which Ontop must comply with.

The aim of our AML/BSA program is to offer comprehensive protection to Ontop, its employees and first-party contractors, shareholders, and customers from money laundering, terrorism financing, and proliferation of weapons of mass destruction.

2. Effective Date

This Policy is effective immediately upon publication.

3. Related Policy Documents

This policy must be read in conjunction with the Anti-Bribery and Corruption Policy, the Risk Management Policy, Third-Party Risk Management Policy, Ethics Policy, KYC/-SDD/-EDD Procedure.

4. Approval

This version of the policy was approved by Stephan Tschabold, Chief Compliance & Risk Officer (β€œCCRO”) on Jul 15, 2026.

Approved by Stephan Tschabold-CCRO

Signature /s/

5. Key Concepts

This AML/BSA Policy includes terms in capital initials. Those expressions will have the meaning given to them in this definition section.

β€œAML” means anti-money laundering.

β€œAML Compliance Officer” or β€œAMLCO” means the Anti-Money Laundering Compliance Officer.

β€œAML/BSA Policy” means this Anti-Money Laundering and Bank Secrecy Act policy.

β€œAML/BSA Program” or β€œAML/BSA Compliance Program” means the set of Ontop internal policies and procedures through which the AMLCO guarantees compliance with this AML/BSA Policy and its goals, namely the prevention of money laundering and terrorist financing.

β€œChief Compliance & Risk Officer” or β€œCCRO” oversees risk management and compliance, ensuring alignment with regulatory standards. The CCRO also addresses escalations from the AML Compliance Officer (AMLCO), providing guidance on complex money laundering risks and ensuring appropriate controls are in place.

β€œFinancial Action Task Force (FATF)” refers to an intergovernmental organization founded in 1989 on the initiative of the G7 to develop policies to combat money laundering and terrorist financing. They set international standards that aim to prevent those illegal activities and have developed the FATF recommendations which ensure a coordinated global response to prevent organized crime, corruption, and terrorism. (https://www.fatf-gafi.org/)

β€œFinCEN” means the Financial Crimes Enforcement Network, a bureau of the United States Department of the Treasury that collects and analyzes information about financial transactions in order to combat domestic and international money laundering, terrorist financing, and other financial crimes. (https://www.fincen.gov )

β€œKYC” means Know Your Customer, a banking term relating to due diligence conducted before engaging with clients.

β€œOntop Group” or simply β€œOntop” means Ontop Holdings Inc., as well as its affiliates and subsidiaries that form a part of its economic group of companies, along with its employees (or first-party contractors directly engaged to perform services on behalf of Ontop).

β€œOFAC” means the Office of Foreign Assets Control of the US Department of the Treasury, which administers and enforces economic and trade sanctions based on US foreign policy and national security goals against targeted foreign countries and regimes, terrorists, international narcotics traffickers, those engaged in activities related to the proliferation of weapons of mass destruction, and other threats to the national security, foreign policy or economy of the United States (https://home.treasury.gov/policy-issues/office-of-foreign-assets-control-sanctions-programs-and-information).

β€œPEP” means Politically Exposed Persons, which refers to an individual who is or has been entrusted with a prominent public function. Due to their position and influence, PEPs are at higher risk to be involved in money laundering and related predicate offenses, including corruption and bribery. Immediate family members and close associates of the PEP are considered to be PEP as well.

β€œSAR” means Suspicious Activity Report, which is a report made by a financial institution regarding suspicious or potentially suspicious activity.

β€œSFPF” means Senior Foreign Public Figure, which refers to a senior official in the executive legislative, administrative, military, or judicial branches of a foreign government; A senior official of a major political party; a senior executive of a government-owned or government-funded corporation, institution or charity; immediate family members and close associates of the SFPF are considered to be SFPF as well.

β€œUltimate Beneficial Owner” or simply β€œUBO”, for the purposes of this AML/BSA Policy, will mean the natural person who ultimately owns or controls a customer and/or the natural person on whose behalf a transaction is conducted,

β€œUSA PATRIOT Act” or simply β€œPatriot Act” refers to an act which was passed by Congress on 26 October 2001 in response to the September 11 terror attacks. The Patriot Act provided law enforcement agencies with a new range of investigative powers and introduced measures to address the financial crimes associated with terrorism, including money laundering and the financing of terrorism.

β€œBank Secrecy Act”, β€œMoney Laundering Control Act”, and the β€œMoney Laundering Suppression Act” refer to specific pieces of legislation that have been enacted to aid in the detection and prevention of money laundering.

6. Statutory Overview, Review, and Approval Requirements

6.1. Statutory Overview

6.1.1. Anti-Money Laundering Overview

The United States Congress has enacted a number of statutes to combat money laundering including: The Bank Secrecy Act, which provides for the Department of Treasury to monitor domestic and international money flows; the Money Laundering Control Act; the Money Laundering Suppression Act; and the USA PATRIOT Act. Several agencies of the Department of Treasury assist in preventing and detecting money laundering, most notably FinCEN and OFAC. A number of foreign countries also have money laundering laws and regulations.

6.1.2. State Securities Law

The various states where Ontop conducts business have laws concerning AML that are applicable to Ontop’s business within the respective states. Ontop intends to register with the state of Delaware for a transfer license and as such Delaware Code Title 11. Crimes and Criminal Procedure Β§ 951. Money Laundering would apply to their business.1

6.1.3. Note Concerning Review And Approval Requirements

The AML Compliance Officer designated herein shall perform all due diligence reviews, AML procedure reviews, and approvals required by this AML/BSA Policy.

7. Prevention and Detection of Money Laundering

Please refer to the Appendix A for an AML/BSA processes schematic.

7.1. Background

Ontop’s AML/BSA Policy establishes fundamental principles that are intended to prevent misuse of Ontop’s facilities and resources for prohibited money laundering transactions. All employees and first-party contractors are subject to the general purposes of this AML/BSA Policy, which, are: (1) to uphold the law; (2) to detect, deter and prevent violations of this AML/BSA Policy; (3) to protect Ontop and its employees and first-party contractors from persons who would misuse Ontop’s facilities and resources; and (4) to safeguard Ontop’s business and reputation. The AML/BSA Policy, and any amendments hereto, must be approved in writing by a member of Ontop’s senior management. Such approval shall be maintained electronically by Ontop’s AML Compliance Officer.

The task of safeguarding Ontop from money laundering rests with all Ontop personnel. The AML Compliance Officer is responsible for implementing, maintaining, and enforcing this AML/BSA Policy. Employees and first-party contractors who have direct dealings with customers, third parties, and consultants play an especially important role in detecting and preventing money laundering through compliance with Ontop’s general KYC obligations.

7.2. Description of Rules

Pursuant to its registration with FinCEN as an MSB, Ontop must develop and implement a written anti-money laundering program, which a member of senior management must approve. The AML/BSA Program needs to be reasonably designed to achieve and monitor Ontop’s compliance with the requirements of the Bank Secrecy Act, as amended, and the implementing regulations promulgated thereunder by the Department of Treasury.

Besides the original Bank Secrecy Act, which provides for the Department of the Treasury to monitor domestic and international money flows, The United States Congress has enacted a number of statutes to combat money laundering that have amended the Bank Secrecy Act over the years, including the Money Laundering Control Act, the Money Laundering Suppression Act, and the USA PATRIOT Act. Several agencies of the Department of the Treasury assist in preventing and detecting money laundering, most notably FinCEN. A number of foreign countries have also enacted anti-money laundering laws and regulations.

Money laundering often begins with the placement of illegally obtained cash into legitimate financial channels. Money laundering is not limited to cash transactions. Government regulators generally take the position that money laundering involves any of the following activities:

a) Dealing in the proceeds of criminal activity.

b) Dealing in funds to facilitate criminal activity.

c) Being involved in any activity designed to hide the nature, location, source, ownership, or control of proceeds of criminal activity.

d) Advising a customer, third party or consultant on how to structure a transaction to avoid reporting and record-keeping requirements.

In addition, money laundering may include failure to act when required, or seemingly indirect acts such as willfully ignoring (sometimes called β€œwillful blindness” of (1) the source of customer, third-party and consultant assets, or the nature of transactions involving said parties; and (2) failing to report suspicious activities that may involve money laundering and failing to maintain required records of transactions.

7.3. Anti-Money Laundering Compliance Officer

Ontop has a designated AML Compliance Officer. This person is vested with full responsibility and authority to make and enforce Ontop’s policies and procedures relating to money laundering. The AMLCO will:

a) Monitor compliance with this AML/BSA Policy.

b) Help develop communication and training tools for Ontop employees and first-party contractors.

c) Regularly assist in helping to resolve or address heightened due diligence and β€œred flag” issues.

d) Seek to ensure that any background checks undertaken are completed to the extent reasonably practicable and documented.

e) Seek to ensure that AML/BSA records are maintained properly.

f) Seek to ensure that any required reports (e.g., Suspicious Activity Reports) are made in compliance with the applicable law.

g) Report to Ontop’s Senior Management on AML/BSA compliance issues, as deemed appropriate.

h) Coordinate the independent testing of the AML/BSA Program.

i) Respond to any questions regarding this AML/BSA Policy from Ontop employees and first-party contractors.

j) Respond to any request for information from a federal law enforcement agency or financial institution.

7.4. AML Self-Assessment

On at least an annual basis, the AML Compliance Officer or the CCRO will conduct formal and documented AML self-assessments. Ontop, at its sole discretion, may engage outside counsel and/or a designated compliance consultant in order to conduct an independent assessment. The purpose of the self-assessments is to consider changes in Ontop products and/or services, or to involve their customers, third parties and consultants in the self-assessment process, which may require updates to the AML/BSA procedures. In addition, the self-assessment is designed to update this and other policies, where and if applicable. The AML self-assessments may consider the following risk categories, among others:

7.4.1. Client Risk

Client risk considers the type of customers, third parties, and consultants Ontop provides services to. The assessment may consider, among other things, the number of foreign or domestic customers, third parties, and consultants, as well as the number of new customers, third parties, and consultants that Ontop has a business relationship with.

This would also include whether the client is a legal entity versus an individual (i.e., natural person), the type of business the client is involved in, their location and their source of wealth.

Client risk also takes into account exposure to industries identified by FinCEN and the Federal banking agencies as presenting elevated risk for the unlawful employment of non-work authorized individuals, identity theft, and payroll fraud schemesβ€”namely agriculture, construction, domestic service, hospitality, and staffingβ€”as well as to labor brokers and other staffing intermediaries that recruit, supply, or pay workers on behalf of employers (see Joint Advisory FIN-2026-A002, June 5, 2026).

7.4.2. Geographic Risk

Geographic risk is measured by customer, third party, and consultant physical locations.2 The assessment may consider whether or not changes in the geographic distribution of the customer base creates more risk to Ontop from an AML perspective.

7.4.3. Business Risk

Business risk is measured by an assessment of how easy it is for customers, third parties, and consultants to use the services offered by Ontop to launder money or commit a crime. The assessment may consider the amount of time customers, third parties, and consultants are required to maintain their relationship with Ontop as well as whether there are any changes to the way Ontop maintains customer accounts and acceptance of modifications in customer funds. If, at some point in the future, Ontop decides to change the manner in which they handle customer accounts or accept, collect, or hold funds and/or securities, this AML/BSA Policy will be amended to include the following additional policies, among others:

a) Customer due diligence when opening an account includes but is not limited to a verification of the customer and their business activities.

b) Third party fund transfer risk includes but is not limited to transaction types such as ACH, bank wires, and credit card transactions. This also takes into consideration transfers to third parties such as Stripe and PayPal, among others

c) Bank Secrecy Act reporting and recordkeeping requirements includes but is not limited to documentation and support for AML and KYC checks.

d) Monitoring accounts for suspicious activity includes but is not limited to activity that is identified as suspicious and requires further investigation and/or reporting.

e) Internal controls to detect any attempt to open a correspondent account of a foreign shell bank includes but is not limited to reviewing fund destination information as well as type of entity per transaction.

7.5. Training

All appropriate associated persons of Ontop must attend an annual training session. The training sessions may include, but are not limited to the following topics:

a) General description of money laundering including descriptions of the three stages of money laundering; placement, layering and integration.

b) How to identify β€œred flags” and possible signs of money laundering that could arise during the course of their duties.

c) What to do once the risk is identified.

d) What roles employees and first-party contractors have in Ontop’s compliance efforts.

e) How to perform these roles.

f) Ontop’s record retention policy.

g) Disciplinary consequences, including civil and criminal penalties for non-compliance with this AML/BSA Policy.

h) Typologies and red flags associated with the unlawful employment of non-work authorized individuals, identity theft, payroll tax evasion, and workers’ compensation fraud, as described in Joint Advisory FIN-2026-A002 and FinCEN’s 2023 Payroll Tax Fraud Notice (FIN-2023-NTC1).

Failure to attend such training will result in disciplinary action, which may include disciplinary actions up to termination of an employee, or first-party contractor as deemed appropriate under the circumstances by senior management. The AMLCO must retain documentation of the content of such training programs and attendance log of associated persons attending each year.

7.6. Independent Testing

At least once a year, Ontop will contract with a qualified outside party to review and assess the adequacy of Ontop’s AML/BSA Compliance Program. A written report will be prepared and presented to the AMLCO and/or senior management, who will direct the implementation of any of the qualified outside party’s recommendations, as well as corrective and/or disciplinary action, as deemed appropriate.

7.7. Specific Policies

The following policies have been established to ensure that Ontop employees and first-party contractors know the identity of their customers, third parties, and consultants and take the appropriate steps to prevent funds that derive from illegitimate sources from being funneled through Ontop. Ontop employees and first-party contractors are prohibited from carrying out a transaction if they suspect that Ontop’s facilities would thereby be misused for illegal money laundering.

a) It is the policy of Ontop neither to participate nor to otherwise assist in money laundering. Any employee or first-party contractor found to have assisted in money laundering, either knowingly or by disregarding plainly suspicious circumstances, will be disciplined and/or terminated, as deemed appropriate under the circumstances by senior management.

b) Money laundering often begins with the placement of illegally obtained cash into legitimate financial channels. To deter and monitor the movement of illegally obtained cash, many jurisdictions have instituted reporting and record-keeping laws that require financial institutions to obtain detailed information about large cash transactions. These laws also prohibit the structuring of cash transactions for the purpose of evading reporting and record- keeping requirements. Ontop does not accept cash or cash equivalents.

c) If an Ontop employee or first-party contractor suspects money laundering, Ontop employee or first-party contractor must bring those concerns to the attention of the AMLCO. Such reporting will be held in the strictest confidence. Ontop’s policy is to support an environment in which such reporting is done without fear of retaliation.

d) Ontop also works with third-party cash transfer firms such as Stripe, PayPal among others. These vendors are to receive due diligence on at least an annual basis, which includes AML/BSA policies, adverse media, criminal and civil litigation, as well as cybersecurity.

e) Ontop will not knowingly establish, maintain, administer, or manage a β€œcorrespondent account” for an unregulated foreign shell bank (a foreign bank with no physical presence in any country) or a private banking account which has been defined by the USA PATRIOT Act as an account that is established or maintained for the benefit of one of more non-U.S. persons, requires a minimum aggregate deposit of funds or other assets of not less than $1,000,000, and is assigned to a bank employee who is a liaison between the financial institution and the non-U.S. person. Ontop personnel must notify the AMLCO upon discovery or suspicion that Ontop may be maintaining or establishing a β€œcorrespondent account” for a foreign shell bank or a private banking account.

f) Ontop will not issue, remit, or transfer currency, checks, other monetary instruments, investment securities or credit of more than $10,000 in physical currency to a consultant or foreign bank account outside of the United States, without an extra level of authorization and written approval from the AMLCO. This would also apply to aggregate amounts going to the same name destination.

g) Ontop will comply with all OFAC economic and trade sanctions.

h) Ontop will respond to a summons or subpoena from the Secretary of the Treasury or the Attorney General for records related to a correspondent account within seven days after receipt of a request. Any correspondent relationship with a foreign bank will be terminated not later than ten business days after Ontop receives notification from the Secretary of the Treasury or the Attorney General.

7.8. Customer Identification Program

Customers, third parties, and consultants of Ontop are any parties that engage in a business relationship with Ontop.

7.8.1. Client and Customer Information

Ontop has identification and verification procedures for its customers, third parties, and consultants. For these customers, third parties, and consultants, Ontop will collect the information set forth below, as applicable.

a) Name;

b) Date of birth (for an individual);

c) Address, which will be a residential or business street address (for an individual), an Army Post Office (β€œAPO”) or Fleet Post Office (β€œFPO”) number, or residential or business street address of next of kin or another contact individual (for an individual who does not have a residential or business street address), or a principal place of business, local office, or other physical location (for a person other than an individual); and

d) Identification number, which will be a taxpayer identification number (for U.S. persons) or one or more of the following (for non-U.S. persons): (i) a taxpayer identification number, (ii) passport number and country of issuance, (iii) alien identification card number, or (iv) number and country of issuance of any other government-issued document evidencing nationality or residence and bearing a photograph or other similar safeguard.

e) In connection with a client that is a foreign business or enterprise that does not have an identification number, Ontop will request alternative government-issued documentation certifying the existence of the business or enterprise.

Enhanced due diligence for ITINs. An Individual Taxpayer Identification Number (β€œITIN”)β€”a nine-digit number beginning with β€œ9” (format 9XX-7X-XXXX) issued by the IRS solely for Federal tax purposesβ€”does not provide evidence of legal status in the United States, does not authorize the recipient to work in the United States, and does not serve as identification outside of the Federal tax system. Where a customer, third party, or consultant presents an ITIN in lieu of a Social Security Number (β€œSSN”) or valid employment authorization documentation to open an account or obtain access to Ontop’s services, Ontop will treat the use of the ITIN as a potential risk factor and will assessβ€”in light of the totality of other factors and information availableβ€”whether enhanced due diligence is required to ensure the account is not being utilized to facilitate the unlawful employment of non-work authorized individuals, consistent with Executive Order 14406 (Restoring Integrity to America’s Financial System) and Joint Advisory FIN-2026-A002. The outcome of this assessment will be reflected in the customer’s risk profile and in ongoing monitoring.

SSN verification. Where Ontop has risk-based concerns about the authenticity of an SSN presented by a customer, third party, or consultant that prevent Ontop from forming a reasonable belief that it knows the true identity of that party, Ontop will verify the SSNβ€”directly or through its contracted screening providersβ€”to determine whether it matches Social Security Administration records.

Business address verification. A Commercial Mail Receiving Agency (β€œCMRA”) address is not acceptable as a substitute for the verified residential or business street address required by this section, and an attempt to use a CMRA address during onboarding will be treated as a red flag under Section 7.13.

7.8.2. Beneficial Ownership

For customers, third parties, and consultants that are legal entities, Ontop will seek to identify and verify the identity of beneficial owners of the legal entity. This verification will be conducted before the time of the wire transfer, subject to certain exceptions.

Customers, third parties, and consultants that have an existing relationship with Ontop are not subject to the beneficial ownership rules unless the client makes a subsequent wire transfer on or after the rule date which is defined as the date that rule first became effective.

The identification of β€œbeneficial owners” consists of two prongs: Under the ownership prong, a beneficial owner is each individual (if any) who, directly or indirectly, owns 25% or more of the equity interests of a legal entity.3 This prong would require identification of no more than four individuals and, if no individual meets the 25 percent threshold, no individuals will need to be identified.

Under the control prong, a beneficial owner is a single individual with significant responsibility to control, manage or direct a legal entity customer, including (i) an executive officer or senior manager (e.g., a chief executive officer, chief financial officer, chief operating officer, managing member, general partner, president, vice president or treasurer) or (ii) any other individual who regularly performs similar functions.

Ontop will obtain the required information that has been outlined in this policy (including Appendices). The information will be obtained from an individual commencing a business relationship on behalf of the legal entity. Ontop will generally seek to use a documentary verification method for beneficial owners. Documentary verification may include an unexpired government-issued identification, such as a driver’s license or passport. In instances where a documentary verification method is not available, Ontop will use a non-documentary method of verification. Non-documentary methods of verification may include a written representation letter from another financial institution that is also subject to an AML/BSA compliance program rule. The AMLCO will review the information provided to Ontop that the beneficial owners listed on the certification satisfy both identification prongs listed above.

7.8.3. Customer Risk Analysis

Following a risk-based approach, as a part of the Customer Due Diligence rule, Ontop will gather sufficient customer information to gain a reasonable understanding of what type of risk the client presents to Ontop. Please refer to the Appendix A Ontop AML/BSA processes schematic.

Screening is conducted on new customers, third parties, and consultants with each new party or customer agreement, notwithstanding any prior existing relationship with or prior commitments by the party or customer. Ontop has established contractual relationships with the third-party service provider Metamap and Sumsub for initial onboarding of subject screenings. In addition, Ontop has contractual relationships with Truora, Kroll and Refinitiv for any necessary follow-up secondary screenings. Where necessary and determined by the AMLCO, Metamaps, Veriff, Refinitiv and TRUORA will also be used for periodic ongoing screenings.4 Upon notification of an alert corresponding to an apparent match, the AMLCO or CCRO will investigate the match to determine whether it is a credible match or a false positive. Based on screening results, the AMLCO will assign appropriate risk rating, which includes the following levels:

a) Low Risk: No alerts generated during initial customer on-boarding;

b) Medium Risk: An alert is generated, or any red flag is identified, e.g. (i) the customer, any of its customers and any of the beneficial owners of such customer or customer is or is a family member or close associate5 of, a PEP/SFPF; (ii) adverse media relating to the customer, or any of its customers, has been identified; (iii) the customer is, or any of its customers, is located in a High-Risk Country. Post investigation and enhanced due diligence (β€œEDD”) by Compliance, such alert or red flag is deemed non-impactful (i.e., immaterial, non-AML related matter highlighted in the alert has been settled or otherwise concluded, or fine has been paid, etc.);

c) High Risk: An alert is generated on a customer that is deemed material (i.e., match to OFAC or other global sanctions or blacklist; allegations relating to money laundering, terrorist financing, bribery, or corruption).

For the current list of high-risk countries please see Appendix B. For additional information, please refer here to: (https://www.fatf-gafi.org/publications/high-riskandnon-cooperativejurisdictions/?hf=10&b=0&s=desc(fatf_releasedate) and https://home.treasury.gov/policy-issues/office-of-foreign-assets-control-sanctions-programs-and-information).

If warranted, alternate or supplemental reviews may be conducted, by the AMLCO or CCRO and/or external counsel. Documentation shall be maintained for record keeping accordingly.

The risk ratings must be reviewed and reassessed at least once annually.

Risk assessments may change over time. All documentation relating to risk rating of customers, shall be maintained for record keeping accordingly.

7.8.4. Prohibited and restricted relationships

Ontop prohibits the establishment of client relationships that subject the business to significant legal, regulatory or franchise risk. Prohibited relationships include relationships with clients in industries related to:

a) Shell Banks (Banks incorporated in jurisdictions in which it has no physical presence, and which is not affiliated with a regulated financial institution) as defined in Section 1010.605 of Title 31 of the U.S. C.F.R;

b) Shell companies with no independent operations, significant assets, ongoing business activities and/or employees;

c) Child pornography (An individual or entity providing or associated with the visual depiction of a minor engaged in obscene or sexually explicit conduct whether made or produced by electronic, mechanical or other means;

d) Payday lending (A company that lends customers money at high interest rates on the agreement that the loan will be repaid when the borrower receives their next pay-check);

e) Prostitution/Escort services (Business, agency or person who, for a fee, provides or offers to provide an escort or similar services);

f) Production, sale or distribution of guns, accessories, ammunition, and other weapons;

g) Production, sale, or distribution of illegal material;

h) Production, sale, or distribution of Peptides, research chemicals, and other toxic, flammable and radioactive materials;

i) Illegal Wildlife Trade;

j) Fake references or ID-providing services;

k) Unlicensed /Unregulated remittance agents, exchange houses, casa de cambios, bureau de change or money transfer agents;

l) Payments involving third-party payment processors or money transmitters that provide downstream processing for MSBs, financial institutions and Payment Service Providers that do not have an AML and Sanctions Program in place;

m) Payments arising from, or related to, transactions in Russian-origin oil or in other Russian-origin oil or petroleum products (as defined under HS codes 2709 and 2710), irrespective of their price;

n) Payments associated with payable through accounts;

o) Sale of counterfeit or β€œgrey market” goods or services;

p) Unlicensed, illegal, unregulated gambling, lotteries, contests and/or sweepstakes, whether online or otherwise, such as bookmakers, sports parlay cards, numbers and illegal casinos, among others.

q) Marijuana-related business (An individual or entity that manufactures, processes distribute, or dispenses marijuana, or byproducts or derivatives of marijuana, for recreational purposes);

r) Illegal prescription drug sales, illegal tobacco or e-cigarette sales, substances designed to mimic illegal drugs, and any other illegal substances;

s) Online or other non-face-to-face pharmacies or pharmacy referral services, or pseudo pharmaceuticals;

t) Any product or service that infringes upon the intellectual property or trade secrets of Ontop or any third party;

u) An individual or entity providing bail bond services, bail bond agents, bounty hunters and/or bail bondsmen;

v) Any activity, product/service that includes underage labor;

w) Ponzi or pyramid schemes, or other unfair, predatory or deceptive activities;

x) Businesses that use the Informal Value Transfer System, as defined in the U.S. Department of Treasury Financial Crimes Enforcement Network (FinCEN) Advisory FIN-2010-A011, such as hawalas or money transmitters who do not comply with applicable registration or license requirements; and

y) Payments involving any Virtual Asset Service Providers (VASPs) as direct clients, including virtual currency exchanges, administrators and miners if such clients:

  • Are in a jurisdiction with strategic deficiencies as designated by the FATF: or
  • Are not compliant with applicable regulatory money transmission licensing, money service business registration, and AML program requirements within the local jurisdiction: and/or
  • Do not have an AML program generally consistent with FATF requirements.

z) Labor brokers, staffing intermediaries, or other persons operating as unregistered money services businesses that provide off-the-books payroll, check cashing, or payment processing services on behalf of employers, including shell companies established for such purposes (see Joint Advisory FIN-2026-A002 and FinCEN Notice FIN-2023-NTC1).

In certain cases, exceptions to this section may be granted if justified by a comprehensive risk assessment. Such exceptions can only be considered through the submission of a formal risk memo, which must be approved by the Chief of Compliance & Risk Officer (CCRO), the Chief Legal Officer (CLO), and the Chief Executive Officer (CEO). This process ensures that all exceptions are subject to a thorough review and receive appropriate oversight to mitigate any potential risks to Ontop’s business.

Restricted relationships with clients engaged or related to the following industries are subject to EDD and to AMLCO approval.

a) Other Gambling (The wagering of money or something of value on an event with an uncertain outcome, with the primary intent of winning money or material goods (e.g. betting, online casinos, lotteries etc.);

b) Marijuana-related business (An individual or entity that manufactures, processes distribute, or dispenses marijuana, or byproducts or derivatives of marijuana, for medical purposes, with a government issued license);

c) Business related to microchips and/or other electronic components that have due use potential, but are not otherwise subject to export control requirements;

d) Charity (A non-profit, non-political organization that collects donations, including fundraising);

e) Dealers in precious metal, shipping and general trading companies that operate out of free trade zones, travel and tour companies, used motor vehicles dealer businesses, auction organizers/managers and crowdfunding platforms;

f) MSB or MVTS Businesses; and

g) Real Estate and Construction businesses (companies engaged in property development, construction contracting, land acquisition, or real estate brokerage, including project management firms whose revenues are predominantly derived from real estate transactions); and

h) Staffing agencies and labor brokers (intermediaries that recruit, hire, supply, transport, house, or pay workers on behalf of employers), particularly those serving the agriculture, construction, domestic service, or hospitality industries.

Acceptance of restricted relationships requires documented EDD and written approval from the AMLCO prior to onboarding.

7.8.5. Mandatory Enhanced Due Diligence (see PM-001-01 KYC/-SDD/-EDD Procedure details)

Enhanced due diligence requirements of 31 C.F.R. Β§103.176 (b) (https://www.federalregister.gov/documents/2007/08/09/E7-15467/financial-crimes-enforcement-network-anti-money-laundering-programs-special-due-diligence-programs), are set forth in detail in Ontops KYC/-SDD/-EDD Procedure.6

Documentation as to all due diligence steps undertaken as well as the rationale for any final decision will be maintained by the AMLCO, or the CCRO.

7.8.6. Customer, Third-Party, and Consultant Identification and Verification as Needed

Ontop will seek to verify the identity of each customer, third-party, and consultant through documentary evidence when reasonably possible, including through defined documents provided by said party. Customer, third-party, or consultant identity will otherwise be verified through non-documentary evidence or through payment intermediary firms (e.g., PayPal). For customers, third parties, and consultants that have previously entered into business relationships through Ontop’s affiliates or related persons within the past 12 months, said contact itself may enable Ontop to form a reasonable belief that it knows the identity of the customer, third-party, or consultant depending on the information originally obtained. For customers, third parties, and consultants assigned a medium or high AML risk ranking, Ontop will require identification verification to go beyond the customary scope of information and will vary its due diligence according to the risk posed by each customer. Finally, Ontop will comply with OFAC rules by screening the names of all customers, third parties, and consultants as described below.

7.8.7. Customers, Third Parties, and Consultants Who Refuse to Provide Information

If any party, potential party, or customer refuses to provide any information requested in connection with a transaction or appears to have intentionally provided misleading information to Ontop, the AMLCO must be notified immediately, and will be responsible for determining an appropriate course of action (including whether the situation should be reported to FinCEN).

In cases where such customers, third parties, and consultants have a pre existing relationship with Ontop, Ontop will, after considering the risks involved, determine whether relationships with such parties should be terminated to the extent practicable.

7.8.8. Lack of Verification

Where a reasonable belief concerning the true identity of a party or customer cannot be reached, Ontop will not establish the relationship. Any party or customer who cannot provide verification of their identity will be classified as high-risk. The AMLCO maintains ultimate and final responsibility for determining a business outcome.

7.8.9. Party and Customer Approval

The AMLCO must approve the acceptance of customers, third parties, and consultants assigned a medium or high AML risk ranking. The AMLCO must review standard and enhanced customer identification documents, the results of standard and enhanced screenings as well as any identified red flags and additional due diligence conducted when determining if approval is warranted. Approval, if appropriate, will be recorded electronically on Ontop’s systems, which are defined as any system that records, maintains, or otherwise retains electronic records, data, or approvals for this purpose.

7.8.10. Recordkeeping

Ontop will document all identity verification for parties reviewed, including all identifying information provided by a customer, third-party, or consultant, the methods used and results of verification, and the resolution of any discrepancy in the identifying information. Ontop will keep the following records, as applicable:

a) Any materials and identifying information through which customers, third parties, and consultants enter into a business relationship with Ontop. These documents typically include extensive representations and warranties related to AML/BSA matters and require delivery of copies of a customer’s Form W-9 (or W-8BEN, W-8 EXP, or W-8IMY for a foreign customer).

b) A copy of the parties’ corporate governance documents, financial statements, proof of regulatory/public listing or other documentation evidencing the issuer’s identity.

c) With respect to non-documentary verification, Ontop will retain documentation of the methods and the results of any measures taken to verify the identity of a customer.

d) Records of all identification information will be retained for a period of five years after the party relationship has ceased; and records made about verification of identity will be kept for five years after the record is made. The AMLCO is responsible for ensuring that all records required to be maintained pursuant to this AML/BSA Policy are retained for the appropriate time periods.

7.8.11. Notice to Customers, Third Parties, and Consultants

A notice that Ontop is requesting information from them to verify their identities as required by Federal law must be provided to each customer before establishing a customer relationship or before granting trading authority. Such notice may be oral or in writing, and should contain substantially the following information, depending on the circumstances:

β€œImportant Information About Procedures for Opening a New Account

To help the Federal Government fight the funding of terrorism and money laundering activities, Federal law requires all financial institutions to obtain, verify, and record information that identifies each person who opens an account.

What this means for you: When you establish a customer relationship with us, we will ask you for your name, address, date of birth and other information that will allow us to identify you. We may also ask to see your driver’s license or other identifying documents.”

7.8.12. Comparison with Government Provided Lists of Terrorists and Other Criminals; Compliance with OFAC Sanctions

From time to time, Ontop may receive notice that a Federal government agency has issued a list of known or suspected terrorists. Ontop must determine, before a client relationship is established (or earlier, if required by another Federal law or regulation or Federal directive issued in connection with an applicable list), whether a client appears on any such list of known or suspected terrorists or terrorist organizations issued by any Federal government agency and designated as such by Treasury in consultation with the Federal functional regulators. Ontop will follow all Federal directives issued in connection with such lists.

Ontop will continue to comply with the OFAC rules prohibiting transactions with certain foreign countries or their nationals. The AMLCO or CCRO must have knowledge of all customer and issuer customer names which have been checked against the OFAC list of Specially Designated Nationals and Blocked Persons (www.ustreas.gov/ofac; click on the box marked β€œSDN list”). Such checks will be conducted by those Ontop employees and first-party contractors as delegated by AMLCO or CCRO. The AMLCO will promptly contact federal law enforcement by telephone (the OFAC Compliance Hotline for financial institutions at 1-800-540-6322) when:

a) A party or customer is listed on the OFAC list;

b) A party’s legal or beneficial account owner, or a 50 percent or more owner of a party, is listed on the OFAC list;

c) A party attempts to use bribery, coercion, undue influence, or other inappropriate means to induce Ontop to establish a relationship or proceed with a suspicious or unlawful activity; or

d) Any other situation arises that the AMLCO reasonably determines requires immediate government intervention.

Ontop will also screen against other lists, such as the Financial Action Task Force (β€œFATF”) list of non- compliant countries (the β€œNCCT list”) (https://www.fatf-gafi.org/publications/high-riskandnon-cooperativejurisdictions/?hf=10&b=0&s=desc(fatf_releasedate) ). The AMLCO will maintain a list of the FATF non-cooperative countries and territories on file and review the FATF releases on a periodic basis. Please refer to Appendix B for high-risk or prohibited jurisdictions.

Sanctions governance and documentation. The AMLCO (or delegate) shall provide periodic reporting to senior management and, where applicable, the Board regarding sanctions compliance, including (i) sanctions screening performance and tuning, (ii) significant sanctions alerts/hits, (iii) confirmed matches and actions taken (reject/block, offboarding, reporting), (iv) emerging sanctions risks and control enhancements, and (v) any material issues, exceptions, or backlogs. Such reporting and related decisions (including rationale and any action items/owners) must be documented in formal meeting minutes and/or an auditable sanctions governance log retained in accordance with the Record Retention Policy.

ACH Sanctions Return Handling (NACHA Return Code R90). Effective upon NACHA's introduction of Return Code R90, any ACH entry returned by a Receiving Depository Financial Institution under R90 β€” indicating a sanctions-based return β€” shall be treated as a potential OFAC match and handled as follows: (i) the returned funds shall be placed on hold immediately and the entry shall not be re-presented pending resolution; (ii) the AMLCO shall cause all transaction parties (originator, beneficiary, and any intermediary payout partner) to be screened against the OFAC SDN list and all applicable sanctions programs without delay; (iii) if the AMLCO determines the return reflects a false positive, the determination and supporting analysis shall be documented and the transaction may be cleared for re-initiation through an alternative channel subject to CCRO approval; (iv) if the AMLCO determines a true or probable OFAC match exists, the funds shall remain blocked, OFAC shall be notified within 10 calendar days of the blocking event using the OFAC reporting portal (https://ofac.treasury.gov), and an Annual Report of Blocked Property shall be filed with OFAC by September 30 of each year for any funds remaining blocked; (v) the AMLCO shall assess whether a SAR filing is warranted in accordance with Section 7.14; and (vi) all R90 returns, screening outcomes, determinations, and actions taken shall be documented in the sanctions governance log referenced above and retained in accordance with the Record Retention Policy (P-004). Client-facing communications regarding R90 returns shall be approved by the CCRO prior to issuance and shall not disclose the identity of any SDN match or the existence of any OFAC investigation. Ontop's JPM CMA banking relationship and applicable payout partner agreements shall be reviewed periodically to ensure R90 handling obligations and escalation protocols are aligned across all ACH origination channels.

7.8.13. Accounts for Senior Foreign Officials (β€œSFPF”) and Politically Exposed Persons (β€œPEP”)

Section 312 of the USA PATRIOT Act requires broker-dealers, as well as other institutions, to ascertain whether their customers, third parties, and consultants may be a SFPF or a PEP. An SFPF is a current or former senior official in one of the branches of foreign government. Enhanced due diligence is required for any account maintained on behalf of either a SFPF or a Politically Exposed Person (β€œPEP”). A PEP is a person who is, or has been, entrusted with prominent public functions domestically or for a foreign country. Examples of domestic PEPs can include heads of state or of government, senior politicians, senior officials in the government, judiciary, or military, senior executives of state-owned corporations, and important political party officials. Examples of foreign PEPs can include heads of state or government, senior politicians, senior officials in the government, judiciary, or military, senior executives of state-owned corporations, and important political party officials.

Under the CIP Rules, Ontop will include monitoring for the existence of SFPFs or PEPs and their immediate family members. Ontop will review public information, including information available in Internet databases, to determine whether any customers, third parties, and consultants are SFPFs or PEPs. If Ontop discovers information indicating that a particular customer may be a SFPF or PEP, and upon taking additional reasonable steps to confirm this information, Ontop determines that the individual is, in fact, a SFPF or PEP, Ontop will conduct additional enhanced due diligence to detect and report transactions that may involve money laundering or the proceeds of foreign corruption.

7.9. Joint and Travel Rules

FinCEN and the Board of Governors of the Federal Reserve System jointly adopted a β€œJoint Rule” that imposed recordkeeping requirements for transmittals of funds by banks and other financial institutions (60 FR 220, January 3, 1995). FinCEN also adopted the β€œTravel Rule” requiring financial institutions (including banks) to include in transmittal orders certain information collected under the Joint Rule (60 FR 234, January 3, 1995).

Ontop is subject to the Joint and Travel Rules and observes the respective record retention periods. The AMLCO will review for compliance of this section on a regular basis.

7.10. Federal Law Enforcement Agencies

FinCEN may require Ontop to search its records to determine whether it maintains or has maintained any account for, or has engaged in any transaction with certain individuals, entities, or organizations. If Ontop identifies such an account, the AMLCO will report the identity of the individual, entity or organization, the account number, all identifying information provided by the account holder when the account was established, and the date and type of transaction. Such report must be made as soon as possible, but not later than seven days after receiving a written enforcement agency request either by email to patriot@fincen.treas.gov, by calling the Financial Institutions Hotline (1-866-556-3974), or by any other means that FinCEN specifies.

7.11. Voluntary Sharing Among Financial Institutions

With the approval of the AMLCO, Ontop may voluntarily share information with other financial institutions about those suspected of terrorism and money laundering. If such information is shared, the AMLCO will serve as the designated point of contact and Ontop must file an annual notice with FinCEN, which requires Ontop to take steps necessary to protect the confidentiality of the information and to use the information only for purposes specified in Treasury’s interim rule. The notice form can be found at: www.fincen.gov. The AMLCO is responsible for protecting the security and confidentiality of such information. Any information sharing arrangements with other financial institutions will be handled in accordance with Ontop’s existing privacy policies and procedures.

7.12. Emergency Notification To The Government By Telephone

When conducting due diligence or initiating a party or customer relationship, Ontop will immediately call Federal law enforcement when necessary, and especially in these emergencies: a legal or beneficial party or customer is listed on the OFAC list, a party or customer is owned or controlled by a person or entity listed on the OFAC list, a party or customer tries to use bribery, coercion, or similar means to initiate a relationship or carry out a suspicious activity, Ontop has reason to believe the party or customer is trying to move illicit cash out of the government’s reach, or Ontop has reason to believe the party or customer is about to use the funds to further an act of terrorism. Ontop will first call the OFAC Hotline at 1-800-540-6322. Other law enforcement agencies that Ontop may contact as appropriate are the Financial Institutions hotline, the local U.S. Attorney’s office, the local FBI office and local SEC office.

7.13. Red Flags

Ontop personnel will look for signs of suspicious activity or behavior that suggests money laundering. Examples of β€œred flags” that Ontop personnel can encounter may include, but are not limited to those described below:

a) The party or customer exhibits unusual concern about Ontop’s compliance with government reporting requirements and the AML/BSA Policy (particularly concerning his or her identity, type of business and assets), or is reluctant or refuses to reveal any information concerning business activities or furnishes unusual or suspicious identification or business documents.

b) The party or customer wishes to engage in transactions that lack business sense or apparent investment strategy or are inconsistent with stated business or investment strategy.

c) Information provided by the party or customer is false, misleading, or substantially incorrect.

d) Upon request, the party or customer refuses to identify or fails to indicate any legitimate source for his or her funds and other assets.

e) The party or (or a person publicly associated with the party or customer) or customer has a questionable background or is the subject of news reports indicating possible criminal, civil, or regulatory violations.

f) The party or customer is publicly known or known to Ontop to have criminal, civil or regulatory proceedings against him or her for crime, corruption, or misuse of public funds, or is known to associate with such persons. Sources for this information could include news items, the Internet or commercial database searches. The customer’s background is questionable or differs from expectations based on business activities.

g) The party or customer exhibits a lack of concern regarding risks or costs.

h) The party or customer appears to be acting as an agent for an undisclosed principal, but declines or is reluctant, without legitimate commercial reasons, to provide information or is otherwise evasive regarding that person or entity.

i) The party or customer has difficulty describing the nature of his or her business or lacks general knowledge of his or her industry.

j) The party or customer is a Politically Exposed Person (PEP) particularly in conjunction with one or more additional risk factors, such as the account being opened by a shell company, beneficially owned, or controlled by the PEP, the PEP is from a country which has been identified by FATF as having strategic AML regime deficiencies, or the PEP is from a country known to have a high level of corruption.7

k) The party or customer is a trust, shell company or private investment company that is reluctant to provide information on controlling parties and underlying beneficiaries.

l) The party or customer is from a country identified as a non-cooperative country or territory by the Financial Action Task Force.8

m) The party or customer attempts to avoid Ontop’s normal documentation requirements.

n) The party or customer commits to transfer an amount which appears to be well beyond their known income or resources.

o) The party or customer uses an SSN that, upon verification, does not match or is inconsistent with Social Security Administration records, or presents identification documents inconsistent with other information known about the party or customer.

p) The party or customer opens an account using a non-U.S. passport or an ITIN, claiming to be self-employed or operating a small business in the agriculture, construction, domestic service, hospitality, or staffing industries, and receives a significant amount and volume of recurring deposits or payments from multiple companies before making significant and repetitive structured withdrawals or issuing low-dollar payments to multiple individuals.

q) The party or customer works in the agriculture, construction, domestic service, hospitality, or staffing industries and maintains an account opened with an ITIN that shows little to no transactional activity other than remittances to foreign jurisdictions.

r) The party or customer receives recurring peer-to-peer (P2P) payments from a small, recently established company in the agriculture, construction, domestic service, hospitality, or staffing industries.

s) The party or customer attempts to use a Commercial Mail Receiving Agency address instead of a verified business address when opening an account for a company in the agriculture, construction, domestic service, hospitality, or staffing industries, or has no known prior involvement in those industries and provides a non-U.S. passport or ITIN as a form of identification when opening an account for a new company in those industries.

t) A company customer has significant business operations and transactional activity but little to no payroll activity commensurate with its profile, or makes payroll-related payments (including Federal and state payroll tax payments) that are significantly less than would be expected based on its business operations and workforce size.

u) A company customer issues a significant and repetitive volume of payments or checks to a singular or small number of recently established companies with little to no online presence, or issues recurring, large volumes of payments under $1,000 made payable to a significant number of separate individuals.

v) Transactions are repetitive, appear designed to fall below BSA reporting and recordkeeping thresholds (β€œstructuring” or β€œmicrostructuring”), and correlate to payroll cycles outside of standard payroll processing systems.

w) A company customer is newly established (less than two years old) with minimal to no online presence and exhibits indicators of being a shell company, or has beneficial owners with no known prior involvement in the company’s industry or with prior fraud convictions.

x) The party or customer (or its beneficial owners) has been identified in Immigration and Customs Enforcement (ICE) worksite enforcement actions, news releases, or other credible open-source reporting as having a history of worksite compliance violations, or has recently acquired a workers’ compensation policy covering a small number of workers that is not commensurate with its customer profile and transactional activity.

When a member of Ontop detects any red flag, he or she will investigate further under the direction of the AMLCO. This may include gathering additional information internally or from third- party sources, contacting the government, freezing the account, or filing a SAR.

Consistent with FinCEN guidance, no single red flag is determinative of illicit or suspicious activity, and no red flag should be taken in isolation. Ontop personnel will consider the surrounding facts and circumstancesβ€”such as the customer’s historical financial activity, whether transactions are in line with prevailing business practices, and whether the customer exhibits multiple red flagsβ€”before determining whether a behavior or transaction is suspicious. No customer type presents a single level of uniform risk or a particular risk profile.

7.14. When to File a SAR

Ontop will file electronically a Suspicious Activity Report (SAR)9, which is a document that financial institutions, and those associated with their business, must file with FinCEN whenever there is a suspected case of money laundering or fraud. This will be done through using the BSA E-Filing System (http://bsaefiling.fincen.treas.gov/main.html), or any other means authorized by FinCEN, for any activity conducted or attempted through Ontop where Ontop knows, suspects, or has reason to suspect that the activity:

a) Involves funds derived from illegal activity or is intended or conducted in order to hide or disguise funds or assets derived from illegal activity as part of a plan to violate or evade federal law or regulation or to avoid any transaction reporting requirement under federal law or regulation;

b) Is designed, whether through structuring or otherwise, to evade any requirements of the BSA regulations;

c) An attempt to compromise or gain unauthorized electronic access to electronic systems, services, resources, or information;

d) Has no business or apparent lawful purpose or is not the sort in which the party or customer would normally be expected to engage, and we know, after examining the background, possible purpose of the activity and other facts, of no reasonable explanation for the activity; or

e) Involves the use of Ontop to facilitate criminal activity.

Ontop will not base the decision on whether to file a SAR solely on whether the activity falls above a set threshold. Ontop will file a SAR and notify law enforcement of any activity that raises an identifiable suspicion of criminal, terrorist, or corrupt activities. In high-risk situations, Ontop will notify the government immediately and will file a SAR with FinCEN. Securities law violations that are reported to the SEC or an SRO may also be reported promptly to the local U.S. Attorney, as appropriate.

SAR key terms. When filing a SAR in connection with activity highlighted in a FinCEN advisory, alert, or notice, Ontop will include the applicable key term in SAR field 2 (Filing Institution Note to FinCEN) and in the SAR narrative. For suspicious activity connected to fraud schemes involving the unlawful employment of non-work authorized individualsβ€”including related identity theft, payroll fraud, and structuring typologiesβ€”Ontop will include the key term β€œFINANCIALINTEGRITY-2026-A002” in accordance with Joint Advisory FIN-2026-A002. Where appropriate and permitted by law, Ontop may additionally report tips or complaints regarding employers that knowingly employ or exploit unauthorized workers through ICE’s Tip Form or tip line at (866) 347-2423.

Ontop will not file a SAR to report violations of Federal securities laws or SRO rules by its employees and/or first-party contractors or registered representatives that do not involve money laundering or terrorism but will report them to the SEC or SRO.

All SARs will be periodically reported to senior management, with a clear reminder of the need to maintain the confidentiality of the SAR.

Ontop will report suspicious transactions by completing a SAR and will collect and maintain supporting documentation as required by the BSA regulations. SAR filings will be handled by the AMLCO. The AMLCO will file the FinCEN Form 111 – Universal SAR electronically through the BSA E-Filing System. Ontop will file a SAR no later than 30 calendar days after the date of the initial detection of the facts that constitute a basis for filing a SAR. If no suspect is identified on the date of initial detection, Ontop may delay filing the SAR for an additional 30 calendar days pending identification of a suspect, but in no case, will the reporting be delayed more than 60 calendar days after the date of initial detection.

Ontop will retain copies of any SAR filed and the original or business record equivalent of any supporting documentation for five years from the date of filing the SAR. Ontop will identify and maintain supporting documentation and make such information available to FinCEN, any other appropriate law enforcement agencies, or federal or state securities regulators, upon request. The SAR will be maintained in a password protected file to ensure the confidentiality of the filing. The AMLCO will be responsible for granting permission to Ontop personnel to access the files.

Ontop will not notify any person involved in the transaction that the transaction has been reported, except as permitted by the BSA regulations. Ontop understands that anyone who is subpoenaed or required to disclose a SAR, or the information contained in the SAR, except where disclosure is requested by FinCEN, the SEC, or another appropriate law enforcement or regulatory agency or an SRO registered with the SEC, will decline to produce to the SAR or to provide any information that would disclose that a SAR was prepared or filed. Ontop will notify FinCEN of any such request and its response.

7.15. Currency Transaction Reporting (CTR)

Ontop does not accept, pay out, or otherwise process physical currency (cash) transactions. As a result, CTR filing requirements are not applicable to Ontop’s current business model. Ontop maintains controls designed to prevent currency transactions from occurring, including (i) restricting funding and disbursement methods to approved electronic rails and approved counterparties, (ii) prohibiting customers and staff from using Ontop products/services to facilitate cash deposits/withdrawals, and (iii) monitoring for indicators of attempted cash-equivalent structuring or conversion activity through transaction monitoring and case management. If Ontop introduces any product feature or partner flow involving the acceptance or disbursement of currency, Ontop will implement CTR procedures and staff training prior to launch.

7.16. Compliance With Fincen’s Issuance Of Special Measures Against Foreign Jurisdictions, Financial Institutions, Or International Transactions Of Primary Money Laundering Concern

For any final rule imposing a special measure against one or more foreign jurisdictions or financial institutions, classes of international transactions or types of accounts deeming them to be of primary money laundering concern, the AMLCO will follow any prescriptions or prohibitions contained in that rule as it applies to Ontop’s business.

7.17. Detecting And Closing Correspondent Accounts Of Foreign Shell Banks

Ontop does not maintain or establish correspondent accounts, and it is Ontop’s policy not to establish, maintain, administer, or manage correspondent accounts. If in the future Ontop establishes correspondent accounts, Ontop will develop internal controls to prevent a foreign shell bank from opening such an account.

8. Specific AMLCO Responsibilities

Note: This section is not meant to be an exhaustive list of AMLCO responsibilities, but rather discusses only those specific AMLCO responsibilities that are not discussed elsewhere within this policy manual.

8.1. Ontop Procedures

8.1.1. Delegation of Duties

The AMLCO, in consultation with the CCRO, may delegate the duties specifically assigned to other Ontop team members within the organization.

Ontop may outsource certain functions or activities to a third-party service provider. The AMLCO is responsible for supervising all arrangements that Ontop has entered into whereby a third-party service provider performs activities or functions related to Ontop AML/BSA responsibilities. All third-party outsourcing contracts or agreements along with all reports, notes, and comments relating to the above supervisory procedures will be maintained with Ontop books and records. The AMLCO or CCRO will ensure that any applicable regulatory bodies have the same access to the service provider’s work product as they would have had had the service not been outsourced and instead had been performed by Ontop. The AMLCO or CCRO will review, on a periodic basis, any Ontop outsourcing arrangements to determine if they continue to be appropriate, considering such factors as: the service provider’s compliance with any agreements, the service provider’s continued fitness and ability to perform the activities, the impact on Ontop if the third-party service provider fails to perform, the impact of outsourcing on the quality of Ontop’s customer service, and the impact of outsourcing on the ability of Ontop to conform with regulatory requirements and changes in regulatory requirements. All such reviews shall be documented in writing, including the date the review was conducted, comments on the review and a notation of any action initiated as a result of the review.

8.1.2. Third-Party Due Diligence

Prior to onboarding any third party that is integral to Ontop’s regulated financial services and/or payment-related activitiesβ€”including, as applicable, banking partners, issuers, program managers, processors, payment service providers, custodians, wallet/virtual account providers, settlement partners, and other critical platformsβ€”Ontop shall perform documented due diligence proportionate to the assessed risk in accordance with its Third-Party Risk Management Policy (P-014). Due diligence shall, as applicable, evaluate: (i) licensing/registration status and regulatory standing; (ii) adequacy of the provider’s AML, sanctions, and fraud control framework; (iii) sanctions screening approach and watchlist governance; (iv) transaction monitoring and investigations responsibilities and interfaces with Ontop; (v) SAR cooperation, escalation, and permissible information-sharing mechanics; and (vi) incident management and escalation arrangements, including applicable service levels. Ontop shall also perform periodic ongoing due diligence (at least annually, and more frequently based on risk, material changes, or issues identified), documenting outcomes, follow-up actions, and remediation.

8.1.3. Regulatory Requests

The AMLCO will be responsible for responding, on a timely basis, to requests for information from any regulatory agency or organization.

8.1.4. Reporting

The AMLCO will be responsible for reporting disciplinary actions against Ontop or any person associated with Ontop to the appropriate regulatory bodies in writing.

8.1.5. Compliance Policy Changes

The AMLCO will circulate a memorandum of each compliance policy change by appropriate means, including e-mail, to firm staff and will maintain a copy of each compliance policy change with approvals by the CCRO, if required. A full and updated version of the Policy Manual will be attached to any such communication. The AMLCO will monitor FinCEN advisories, alerts, notices, and related Executive Orders on an ongoing basis, and will assess and incorporate relevant typologies, red flags, due diligence expectations, transaction monitoring rules, and SAR key terms into this AML/BSA Policy, its related procedures, and the training program within ninety (90) days of publication (e.g., Joint Advisory FIN-2026-A002; FinCEN Alert FIN-2025-Alert003 on cross-border funds transfers; FinCEN Notice FIN-2023-NTC1 on payroll tax evasion and workers’ compensation fraud).

8.1.6. Enforcement

To ensure that the policies and directives contained in the policy manual and those issued by the AMLCO are complied with, the AMLCO shall take such action and administer such sanctions (including letters of reprimand and fines as they deem appropriate) against any employee or first-party contractor who fails to comply with a compliance directive or otherwise obstructs the activities of the AMLCO. In the case of sanctions involving suspension or dismissal, the AMLCO will recommend such sanctions in writing to the CCRO who will have the final authority to decide whether or not to impose such sanction.

Training and Annual Compliance Meeting: The AMLCO or CCRO will be responsible for initially training employees and first-party contractors, and for conducting annual compliance meetings of employees and first-party contractors to discuss relevant compliance matters, in accordance with Section 7.5 of this policy manual. Documentation of such meetings shall be retained in accordance with the same section. During the initial training and at the annual reoccurring sessions, the AMLCO will discuss such issues as:

Business: Review the Ontop business model and methods of operation and the AML/BSA compliance issues related thereto.

Questions: Provide each training participant with an opportunity to ask questions he or she may have concerning compliance requirements.

New Developments: Inform each employee and/or first-party contractor as to regulatory developments, new Ontop policies, and related information. Regulatory developments will include matters such as AML, customer KYC onboarding, transaction monitoring and consultant / third-party relationships.

9. Supervisory Control System

9.1. Annual Review Of The Ontop Businesses And Supervisory Systems And Procedures

The AMLCO will be responsible for reviewing annually:

a) The businesses in which Ontop engages, in a manner reasonably designed to assist in detecting and preventing violations of, and achieving compliance with, applicable securities laws and regulations and applicable AML/BSA rules;

b) Ontop’s compliance and supervisory systems and procedures, including ensuring that such supervisory systems and procedures comply with the requirements of global requirements, and recommending changes or additions thereto, as necessary, to the CCRO on at least an annual basis;

c) The performance of compliance functions and persons assigned to such functions with respect to transactions effected during the period under review; and

d) The adequacy and currency of Ontop’s required filings with the federal regulators and states. The Legal department together with the AMLCO, based on external counsel’s filings, shall maintain a centralized, auditable β€œMSB Registration File” containing, as applicable: (i) FinCEN MSB registration filings and renewals (including signed forms and submission confirmations), (ii) state licensing/registration documentation and renewals, (iii) correspondence with regulators, (iv) evidence of required updates (or the documented determination that no update was required), and (v) an index/log enabling retrieval within a reasonable timeframe for audits, partner due diligence, or regulatory requests.

9.2. Annual Meeting With The Chief Compliance and Risk Officer (CCRO)

At least annually and separate to day-to-day work, trainings and similar collaborative efforts, the AMLCO shall meet with the CCRO to discuss Ontop’s processes to (i) establish, maintain and review policies and procedures reasonably designed to achieve compliance with applicable rules and federal securities laws and regulations; (ii) modify such policies and procedures as business, regulatory and legislative changes and events dictate; and (iii) test the effectiveness of such policies and procedures on a periodic basis, the timing and extent of which is reasonably designed to ensure continuing compliance with applicable rules, along with all relevant federal securities laws and regulations. The AMLCO shall be responsible for performing such additional tests and reviews and for implementing such additional procedures or modifications as shall be determined necessary or appropriate as a result of these meetings.

9.3. Annual Report On Written Supervisory Procedures

The AMLCO or CCRO shall be responsible for annually evidencing Ontop processes in a report reviewed by senior management, the AMLCO and such other persons as Ontop may deem necessary to enable the CCRO to make a certification that such processes are reasonably designed to ensure compliance with the applicable securities laws and regulations. Such a report shall be submitted annually to Ontop’s senior management for review.

10. General Recordkeeping

10.1. Description Of The Rule

Ontop will β€œmake and preserve books and records” in accordance with industry best practices. Preservation of all records and supporting documentation shall be no less than 5-years.

10.2. Ontop Procedures

The AMLCO shall have responsibility for overseeing Ontop’s record-keeping system and ensuring that the requirements applicable regulatory rules are satisfied. The AMLCO and CCRO shall each have responsibility for maintaining certain records and reporting periodically to senior management.

10.3. Electronic Record Retention

10.3.1. Standard

Any records required to be maintained and preserved by the Ontop may be maintained and preserved in electronic format, subject to the relevant requirements of Bank Secrecy Act (BSA) recordkeeping requirement found in 31 C.F.R. Β§1010.430.

10.3.2. Appropriate Electronic Storage Media

Any electronic storage media used by the Ontop to store required records must meet the following criteria:

a) All such records must be maintained in a WORM (write once, read many) format.

b) The quality and accuracy of the storage media recording process media used must be automatically verified.

c) The media must serialize the original and, if applicable, duplicate units of storage media, and time-date for the required period of retention the information placed on such electronic storage media.

d) The storage media used must have the capacity to readily download indices and records preserved on the electronic storage media.

e) In the event that a cloud provider is used to provide a WORM service, Ontop strives for that such selected cloud service complies with SEC Rule 17a-4(f), FINRA Rule 4511 or CFTC Regulation 1.31.

10.3.3. Additional Ontop Procedures

Ontop will also:

a) At all times have available, for examination any applicable regulatory body, facilities for immediate, easily readable projection or production of electronic storage media images and for producing easily readable images.

b) Store, separately from the original, a duplicate copy of the record stored on any medium acceptable under Rule 17a-4 for the time required.

c) Organize and index accurately all information maintained on both the original and any duplicate storage media.

d) The Ontop must at all times be able to have such indices available for examination by the staff of the applicable regulators.

e) Each index must be duplicated, and the duplicate copies must be stored separately from the original copy of each index.

f) Original and duplicate indexes must be preserved for the time required for the indexed records.

g) Ontop must have in place an audit system providing for accountability regarding inputting of records required to be maintained and preserved for electronic storage media and inputting of any changes made to every original and duplicate record maintained and preserved thereby.

h) Ontop must at all times be able to have the results of such an audit system available for examination by regulatory staff.

i) The audit results must be preserved for the time required for the audited records.

j) Ontop must maintain, keep current, and provide promptly upon request by the staffs of applicable regulators all information necessary to access records and indices stored on the electronic storage media; or place in escrow and keep current a copy of the physical and logical file format of the electronic storage media, the field format of all different information types written on the electronic storage media and the source code, together with the appropriate documentation and information necessary to access records and indexes.

Appendix A – AML/BSA Processes Schematic

AML process schematic: customers, third parties and consultants move through Request, Review and Implement stages
Figure 1. AML Process Schematic
Natural person onboarding process flow
Figure 2. Natural Person Onboarding Process
Legal entity onboarding process flow
Figure 3. Legal Entity Onboarding Process

Appendix B – List Of High-Risk Countries And Specific Restrictions

ISO codeCountryAML risk
AFGAfghanistanProhibited Country
BLRBelarusProhibited Country
BDIBurundiProhibited Country
CAFCentral African RepublicProhibited Country
TCDChadProhibited Country
CODCongo, the Democratic Republic of theProhibited Country
CUBCubaProhibited Country
ERIEritreaProhibited Country
IRNIran, Islamic Republic ofProhibited Country
IRQIraqProhibited Country
PRKKorea, Democratic People's Republic ofProhibited Country
MMRMyanmarProhibited Country
NERNigerProhibited Country
RUSRussian FederationProhibited Country (Sanctions in constant evolution)
SSDSouth SudanProhibited Country
SDNSudanProhibited Country
SYRSyrian Arab RepublicProhibited Country
YEMYemenProhibited Country
UKRUkraineHigh/Prohibited (Crimea, Donetzk, Luhansk, Cherson, Saporischschja)
ALBAlbaniaHigh
DZAAlgeriaHigh
ASMAmerican SamoaHigh
AGOAngolaHigh
ARMArmeniaHigh
BHSBahamasHigh
BLZBelizeHigh
BOLBoliviaHigh
BIHBosnia and HerzegovinaHigh
BGRBulgariaHigh
BFABurkina FasoHigh
KHMCambodiaHigh
CMRCameroonHigh
COGCongoHigh
HRVCroatiaHigh
CYPCyprusHigh
ETHEthiopiaHigh
PSEGaza StripHigh
GHAGhanaHigh
GUMGuamHigh
GNBGuinea-BissauHigh
HTIHaitiHigh
HKGHong KongHigh
ISLIcelandHigh
CIVIvory Coast (CΓ΄te d'Ivoire)High
KENKenyaHigh
XKXKosovoHigh
KWTKuwaitHigh
LAOLao People's Democratic RepublicHigh
LBNLebanonHigh
LBYLibyan Arab JamahiriyaHigh
MDVMaldivesHigh
MLIMaliHigh
MCOMonacoHigh
MNGMongoliaHigh
MNEMontenegroHigh
MOZMozambiqueHigh
NAMNamibiaHigh
NPLNepalHigh
NICNicaraguaHigh, no Clients
NGANigeriaHigh
MKDNorth MacedoniaHigh
PAKPakistanHigh
PSEPalestinian TerritoryHigh
PNGPapua New GuineaHigh
PANPanamaHigh
ROURomaniaHigh
WSMSamoaHigh
SAUSaudi ArabiaHigh
SRBSerbiaHigh
SVNSloveniaHigh
SOMSomaliaHigh
ZAFSouth AfricaHigh
LKASri LankaHigh
TZATanzania, United republic ofHigh
TTOTrinidad and TobagoHigh
TUNTunisiaHigh
VNMVietnamHigh
VENVenezuelaHigh, no Clients*
VIRVirgin Islands, U.s.High
PSEWest BankHigh
ESHWestern SaharaHigh
ZWEZimbabweHigh

*Subject to OFAC General License 57 and applicable conditions. Transactions with clients in Venezuela may be permissible with prior AMLCO/CCRO approval and EDD.

Appendix C – AML/BSA Compliance Governance Structure

AML/BSA compliance governance structure: Board of Directors, Top Management Team, Chief Compliance & Risk Officer, AMLCO and AML Compliance Manager
AML/BSA Compliance Governance Structure

Board of Directors: ultimate accountability and strategic direction.
Top Management Team: oversight and resource allocation.
Chief Compliance & Risk Officer: program implementation and risk assessment.
AMLCO: day-to-day operations and policy enforcement.
AML Compliance Manager: first point of contact and transaction review.

Footnotes

1 Del. Code tit. 11, Β§ 951.

2 A list of high-risk jurisdictions has been attached to this policy as Appendix B.

3 β€œLegal entity” is defined as any of the following entities which make an investment: a corporation, limited liability company, or other entity that is created by the filing of a public document with a secretary of state or similar office; a general partnership; or any similar entity formed under the laws of a foreign jurisdiction. Such definition includes limited partnerships and business trusts that are created by a filing with a state office. Legal entities do not include sole proprietorships, unincorporated associations, trusts (other than statutory trusts that are created through a state filing) or natural persons opening accounts on their own behalf. The following is a list of entities that are excluded from the definition of β€œlegal entity,” since beneficial ownership information for these entities is generally available from other credible sources: (i) a financial institution regulated by a federal functional regulator or a bank regulated by a state bank regulator; (i) a department or agency of the United States, of any state, or of any political subdivision of any state; (iii) any entity established under the laws of the United States, of any state, or of any political subdivision of any state, or under an interstate compact between two or more states, that exercises governmental authority on behalf of the United States or any such state or political subdivision; (iv) any entity (other than a bank) whose common stock or analogous equity interests are listed on the New York, American or NASDAQ stock exchanges (each, a β€œListed Entity”); (v) any entity organized under the laws of the United States or of any state, and at least 51 percent of whose common stock or analogous equity interest is owned by a Listed Entity; (vi) an issuer of a class of securities registered under section 12 of the Securities Exchange Act of 1934 or that is required to file reports under section 15(d) of that Act; (vii) an investment company, as defined in section 3 of the Investment Company Act of 1940, that is registered with the Securities and Exchange Commission (β€œSEC”) under that Act; (viii) an investment adviser, as defined in section 202(a)(11) of the Investment Advisers Act of 1940, that is registered with the SEC under that Act; (ix) an exchange or clearing agency, as defined in section 3 of the Securities Exchange Act of 1934, that is registered under Section 6 or 17A of that Act; (x) any other entity registered with the SEC under the Securities Exchange Act of 1934; (xi) a registered entity, commodity pool operator, commodity trading advisor, retail foreign exchange dealer, swap dealer or major swap participant, each as defined in section 1a of the Commodity Exchange Act, that is registered with the Commodity Futures Trading Commission; (xii) a public accounting firm registered under section 102 of the Sarbanes-Oxley Act; (xiii) a bank holding company, as defined in section 2 of the Bank Holding Company Act of 1956 (12 U.S.C. 1841) or savings and loan holding company, as defined in section 10(n) of the Home Owners’ Loan Act (12 U.S.C. 1467a(n)); (xiv) a pooled investment vehicle that is operated or advised by a financial institution that is an β€œExcluded Legal Entity;” (xv) an insurance company that is regulated by a state; (xvi) a financial market utility designated by the Financial Stability Oversight Council under Title VIII of the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010; (xvii) a foreign financial institution established in a jurisdiction where the regulator of such institution maintains beneficial ownership information regarding such institution; (xviii) a non-U.S. governmental department, agency or political subdivision that engages only in governmental, rather than commercial, activities; and (xix) any legal entity, only to the extent that it opens a private banking account subject to 31 C.F.R Β§1010.620.

4 All contracted third party providers will consider the personal identity, criminal record and history, legal background, and international background of the client and/or customer/worker resulting in a proprietary risk ranking.

5 A β€œclose associate” of a senior foreign political figure is a person who is widely and publicly known to maintain an unusually close relationship with the senior foreign political figure, and includes a person who is in a position to conduct substantial domestic and international foreign transactions on their behalf

6 EDD procedures will be applied as well for a foreign bank that operates under offshore banking licenses or under a banking license issued by certain jurisdictions which include enhanced scrutiny, a determination whether the foreign bank maintains its own correspondent accounts for other foreign banks, and identification of certain owners of the foreign bank. EDD applying enhanced scrutiny will include obtaining and reviewing documentation from the foreign bank about its own AML program and evaluating the effectiveness of such AML program at detecting and preventing money laundering. If deemed appropriate by the parties involved, the enhanced scrutiny may also include closer monitoring of account activity, obtaining information about sources and beneficial ownership of funds, and identifying persons with trading authority. Ontop will not automatically apply these enhanced due diligence procedures for foreign banks operating under offshore branch licenses if the bank is located or charted in a jurisdiction that has been found by the Federal Reserve to be subject to comprehensive supervision or regulation on a consolidated basis by relevant supervisors in that jurisdiction, provided that the jurisdiction is not on the FATF list or Treasury’s list of jurisdictions requiring special measures. Instead, we will follow the risk-based assessment specified below for whether any enhanced scrutiny is appropriate or necessary.

7 Please see the following links for a list of those jurisdictions that FATF has recommended either increased monitoring for or considers to be high-risk: https://www.fatf-gafi.org/publications/high-risk-and-other-monitored-jurisdictions/documents/increased-monitoring-june-2021.html & https://www.fatf-gafi.org/publications/high-risk-and-other-monitored-jurisdictions/documents/call-for-action-february-2020.html

8 Please see the following for further information regarding those countries or territories that FATF considers to be non-cooperative: https://www.fatf-gafi.org/publications/high-riskandnon-cooperativejurisdictions/?hf=10&b=0&s=desc(fatf_releasedate)

9 Defined here: What Is a Suspicious Activity Report (SAR)? Triggers and Filing

Table of contents
Landscape earth planet
Γ—Talk to an expert

Let's get you on board

Drop your details and a teammate from Ontop will reach out.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.