Skip to content
RONPAY

AML Policy

Home / AML Policy

This is a translation for information purposes. The Romanian version of this document is the official one and prevails in case of any discrepancy.

Anti-Money Laundering Policy (AML/CFT)

The official RONPay policy setting out the principles, procedures and controls adopted to prevent and combat money laundering, terrorist financing and breaches of international restrictive measures.

1. Overview

Main regulations and guidelines:

This document sets out the RONPay Policy on combating money laundering, terrorist financing and breaches of restrictive measures, and applies to RONPay and its operations.

The standards are considered complementary and applicable to the extent that they do not conflict with provisions issued by local authorities.

2. General principles

The AML-CFT regulatory framework:

Laundering the proceeds of illegal and criminal activity is one of the most serious forms of crime in financial markets and is an area of specific interest for organised crime.

Money laundering has a significant negative impact on the whole economy: reinvesting illicit proceeds in legitimate activities, and arrangements between individuals or financial institutions and criminal organisations, deeply affect market mechanisms, undermine the efficiency and fairness of financial activity and have a weakening effect on the economy. The financing of terrorist activities may involve the use of lawfully obtained funds and/or the proceeds of crime.

The constantly changing nature of money laundering and terrorist financing, facilitated by the continuous evolution of technology, requires constant adaptation of prevention and enforcement measures.

The regulatory framework for anti-money laundering (AML) and counter-terrorist financing (CFT) is based on a comprehensive set of national, European and international regulatory sources.

At international level, an essential contribution to the harmonisation of regulation has come from the Financial Action Task Force (FATF), the main international body active in the fight against money laundering, terrorist financing and the proliferation of weapons of mass destruction.

1 As defined in the EBA Guidelines (EBA/GL/2024/14): “Union restrictive measures referred to in Article 2(1) of Directive (EU) 2024/1226 and national restrictive measures adopted by Member States in accordance with their national legal order (to the extent that they apply to financial institutions).

In fulfilling its responsibilities, the FATF has established a set of international standards, the “40 Recommendations”, to which 9 further special recommendations for combating international terrorist financing were added in 2001. The subject was fully revised in February 2012, with the adoption of the International Standards on Combating Money Laundering and the Financing of Terrorism and Proliferation, subsequently consolidated into the “40 Recommendations” referred to above.

In the fight against the proliferation of weapons of mass destruction, the United Nations has developed a set of measures to combat the financing of proliferation programmes, including a prohibition on supporting or financing any person involved in such activities.

In implementing the resolutions adopted within the United Nations, the European Union has issued a set of provisions to give effect to restrictive measures, such as the freezing of funds and economic resources of persons or entities involved in sensitive proliferation activities relating to weapons of mass destruction.

The FATF has developed guidance for implementing the financial sanctions adopted by the United Nations.

Specific measures on the proliferation of weapons of mass destruction have recently been included in the recommendations, in line with the resolutions of the United Nations Security Council.

The European Union's guidelines on preventing the use of the financial system for money laundering and terrorist financing are set out in Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015 (the Fourth Anti-Money Laundering Directive), as amended by Directive (EU) 2018/843 (the Fifth Anti-Money Laundering Directive), as well as in the regulations and guidelines issued periodically by the European Union and by the European Banking Authority (EBA) respectively.

At a general level, the Company has adopted this “Anti-Money Laundering and Counter-Terrorist Financing Policy” (hereinafter the “Policy”), as an expression of its commitment to combating the criminal phenomena referred to above at international level, paying particular attention to countering them, in the awareness that the pursuit of profitability and efficiency must be combined with continuous and effective monitoring of the integrity of corporate structures.

The Policy applied within the Company describes the policy adopted by RONPay in accordance with the rules and principles established by national and European regulatory provisions, in compliance with the relevant international standards, and is implemented together with the internal anti-money laundering and counter-terrorist financing procedures, the Code of Ethics and the internal procedures that transpose the primary and secondary local legislation in force, specifying the processes, roles and responsibilities.

This Policy has been approved by the Company's Board of Directors. The AML and CFT guidelines are applied by RONPay in line with the applicable legislation.

The Company undertakes to comply with this regulatory framework, as well as with any implementing provisions issued by the Bank on customer due diligence, record keeping of data and information, organisation, procedures, controls and enhanced controls against the financing of programmes intended for the proliferation of weapons of mass destruction.

The Company is fully committed to ensuring that its operational organisation and control system are complete, adequate, functional and reliable for strategic oversight, protecting the Company from tolerating or being drawn into forms of illegality that could affect its reputation and stability.

For these reasons, RONPay has adopted organisational and conduct rules, as well as monitoring and control systems, designed to ensure compliance with the legislation in force by the Company's administrative and control bodies, staff, collaborators and consultants. These controls are also consistent with the rules and procedures established by personal data protection regulations.

The Company also relies on the anomaly indicators and patterns of irregular behaviour in the economic and financial environment issued periodically by the National Office for the Prevention and Control of Money Laundering (ONPCSB), as the financial intelligence unit, in relation to potential money laundering and terrorist financing activity.

3. Regulatory framework on restrictive measures and embargoes

All restrictive measures established to combat terrorist financing and all unlawful or suspicious activity threatening international peace and security may be either commercial, such as restrictions on imports/exports from/to a country, or financial, such as partial or total blocking of fund transfers, as well as operational limitations and the freezing of funds.

Restrictive measures include international financial sanctions, also known as embargoes, implemented by the Romanian state, by foreign agencies (for example, OFAC, UKSL) and by supranational organisations (UN, EU), through a series of obligations the Company is required to observe. Certain restrictive measures (sanctions) are imposed on all UN member states by the Council, to implement the resolutions adopted by the UN Security Council under Chapter VII of the UN Charter. Sanctions may also be adopted or decided autonomously by the European Union through Council regulations, directly applicable in each Member State, to ensure their prompt and simultaneous application.

At international level there are regulations that impose specific prohibitions or restrictions on investment in certain industrial sectors, or on imports/exports from/to “high-risk or significant-risk countries”. In particular, these are the UN Security Council resolutions adopted under Article 41 of Chapter VII of the UN Charter, imposing restrictive measures in relation to persons and/or countries.

As regards Community legislation, the main provisions are:

· Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 and subsequent amendments, establishing a Union regime for the control of exports, transfer, brokering and transit of dual-use items

· Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets and amending Directive (EU) 2015/849 (recast)

· Regulation (EU) 2024/886 of the European Parliament and of the Council of 13 March 2024 amending Regulations (EU) No 260/2012 and (EU) 2021/1230 and Directives 98/26/EC and (EU) 2015/2366 as regards instant credit transfers in euro

· Directive (EU) 2024/1226 of the European Parliament and of the Council of 24 April 2024 on the definition of criminal offences and penalties for the violation of Union restrictive measures and amending Directive (EU) 2018/1673, transposed into Romanian law

· European Banking Authority Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (EBA/GL/2024/14)4

· European Banking Authority Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures, in accordance with Regulation (EU) 2023/1113 (EBA/GL/2024/15) on information accompanying transfers of funds and certain crypto-assets and amending Directive (EU) 2015/8495

Finally, at national level, embargoes are regulated as follows:

Primary legislation:

· Government Emergency Ordinance No 202/2008 on the implementation of international sanctions, together with the legislation on the control of exports of dual-use items, which governs the authorisation procedures for the export of dual-use goods and technologies, as well as the penalties applicable to trade embargoes and to all types of export operations involving materials that contribute to proliferation

Secondary legislation:

The regulations issued by United States authorities are relevant to the Company's activity given the reputational aspects and the references to those regulations in contractual commitments involving the potential application of sanctions with extraterritorial effect (so-called US “secondary sanctions”). These regulatory provisions are set out in the USA Patriot Act 6 and in the economic and trade sanctions measures issued by the US Government through the Office of Foreign Assets Control (OFAC) of the Department of the Treasury.

4. Group-level models and methodologies

General aspects

The national regulatory framework established for preventive action against money laundering, terrorist financing and breaches of restrictive measures is based on a series of obligations that the addressees are required to observe:

· the obligation to adopt adequate organisational structures, procedures and internal control measures

· the obligation to adopt consistent and coherent procedures for analysing and assessing the risks of money laundering, terrorist financing and breaches of restrictive measures, and to establish the supervision, controls and procedures necessary to mitigate and manage those risks

· the customer due diligence obligation, whereby the Company obtains and verifies information on the identity of the customer and of any beneficial owner, as well as the purpose and intended nature of the relationship or transaction, while ensuring ongoing monitoring of all transactions carried out by the customer

· a risk-based approach, under which customer due diligence obligations are divided into different degrees of diligence, proportionate to the customer's risk profile

· the obligation to retain documents, data and information so as to ensure they can be obtained promptly, and to guarantee transparency, completeness, non-alterability and integrity, as well as general and rapid accessibility

· the obligation to report suspicious transactions

· the obligation to refrain from establishing any new customer relationship, from carrying out occasional transactions or from maintaining an existing customer relationship where customer due diligence measures have not been applied, or where there is a suspicion of a possible link to money laundering or terrorist financing

· the obligation to notify the competent authorities of breaches of the regime on cash transactions and bearer instruments, and to comply with the limits on the use of cash laid down by applicable Romanian legislation

· monitoring of all transactions with natural and legal persons and/or countries included on the lists of the Council of the European Union (EU), on the list of the Office of Foreign Assets Control (OFAC), on the United Kingdom Sanctions List (UKSL)7, on the UN Security Council Consolidated Sanctions List, and in provisions issued by national authorities containing specific restrictive measures to combat terrorism

· monitoring of transactions concluded with countries considered non-cooperative in tax matters, financial supervision and anti-money laundering, generally referred to as “tax havens” or “offshore financial centres”

· the adoption of adequate staff training programmes to ensure the proper implementation and application of laws and regulations

· the obligation to submit “objective communications” to the financial intelligence unit, in accordance with specific instructions

· instructions on the means and frequency of communications

· the obligation to report any breaches or irregularities that the control bodies become aware of in the exercise of their duties;

· the obligation to adopt procedures for handling internal reports of breaches submitted by employees (whistleblowing)

As regards counter-terrorist financing activities, Romanian legislation requires reporting entities to:

· freeze the funds and economic resources of certain persons included on EU lists

· inform the National Office for the Prevention and Control of Money Laundering (ONPCSB), as the financial intelligence unit, of the measures applied to freeze funds or, in the case of economic resources, inform the National Agency for Fiscal Administration

· inform the financial intelligence unit of suspicious transactions, business relationships and any other available information concerning persons included on the lists it publishes

· report suspicious transactions which, on the basis of the information available, are directly or indirectly connected with terrorist financing activities

As regards international sanctions (so-called embargoes) and exposure to restrictive measures, the legislation requires the adoption of certain measures, including but not limited to:

· checks on personal data and on transactions relating to import and/or export operations carried out by customers, designed to block imports/exports from or to a country, and the corresponding regulations. The prohibition may be general, covering all types of goods except those expressly authorised, or limited to certain types of goods, for example armaments (see the customs code)

· total or partial restrictions on financial transfers from/to a country

· the requirement to obtain prior authorisation to carry out transfers

· the obligation to notify transfers (made or received)

· the prohibition on financing, providing financial assistance to, or making subsidised loans available to the government (directly or, in some cases, indirectly, through affiliated companies or through participation in international financial institutions)

· the prohibition on financing customers that carry out operations with countries subject to sanctions

· the implementation of restrictive measures against Russian and Belarusian persons

· traceability of the checks carried out on operations originating from or directed towards countries, persons and entities subject to restrictions

5. Customer due diligence

General aspects

The Company applies all customer due diligence measures when it:

· establishes business relationships

· carries out occasional transactions ordered by customers, such as bank transfers or other transactions equal to or above the applicable threshold established, whether the transaction is carried out through a single operation or through several operations that appear to be linked, or whether it consists of a transfer of funds exceeding the legal limits

· there is a suspicion of money laundering or terrorist financing, irrespective of any applicable derogation, exemption or threshold

· there are doubts as to the completeness, reliability and truthfulness of the information or documents previously obtained for the purpose of identifying a customer

Customer due diligence obligations:

· are fulfilled

· in relation to new customers, before establishing a business relationship or executing an occasional transaction

· in relation to existing customers, whenever applying customer due diligence measures is appropriate in view of a change in the level of money laundering or terrorist financing risk associated with the customer, or where there are suspicions or doubts as to the accuracy or adequacy of the information previously obtained from the customer, and consist of the following activities:

· identifying the customer, the beneficial owner and the person carrying out the operation, and verifying their identity on the basis of documents, data or information obtained from a reliable and independent source

· obtaining and assessing information on the purpose and intended nature of the business relationship

· carrying out ongoing monitoring throughout the duration of the customer relationship.

To that end, the Company — through its employees and/or through agents/financial advisers authorised to make offers away from business premises and who come into direct contact with the customer — obtains the information required by the regulations and collects any other relevant documentation, as specified in this Policy and in the Company's procedural documents.

The Company applies standard, simplified or enhanced customer due diligence measures, depending on the risk-based approach applied to customers.

Remote customer onboarding

Where the Company uses remote identification methods, under the conditions permitted by Law No 129/2019, it adopts special procedures for fulfilling customer due diligence obligations, taking into account the fraud risk associated with identity theft. In that case, identification is based on obtaining a qualified electronic signature certificate, generated following an identification process carried out through:

· use of the national electronic identity system or of the electronic identity card;

· secure and regulated electronic identification techniques and procedures, authorised or recognised by the Authority for the Digitalisation of Romania.

In all cases, the remote identification process involves collecting in electronic format the identification data of the customer and of any person carrying out the operation, and performing verifications and checks on the authenticity of the data, in addition to those provided for face-to-face identification, following a risk-based approach, including by telephone contact on a certified number (welcome call) or by a money transfer made by the customer through a banking and financial intermediary.

In order to limit exposure to potential money laundering and/or fraud risks, it is not permitted to establish banking relationships remotely with legal entities or with natural persons acting on behalf of a legal entity, unless they have been identified directly (face to face).

It is not permitted to establish banking relationships remotely with customers who are not resident in Romania.

Pre-implementation assessment and ongoing monitoring of remote relationship-opening processes.

The processes for remote customer identification and onboarding are formalised and detailed in the internal regulations. The oversight model for these processes comprises:

· prior assessment of the remote onboarding solution (the so-called pre-implementation assessment 8), which aims to:

· assess the adequacy of the solution in terms of the completeness and accuracy of the data and documents to be collected, and the reliability and independence of the information sources used

· assess the impact of using the solution on business risks, including operational, reputational and legal risks, by involving the relevant technical and specialist functions

· identify mitigating measures and corrective actions for each risk identified

· define ex-ante tests to assess ICT and fraud risks, and end-to-end tests of how the solution operates

· ongoing monitoring of the onboarding solution adopted, through periodic and event-driven controls, to ensure it continues to work properly over time (so-called continuous monitoring)

· review of the prior assessment of the remote onboarding solution (the so-called pre-implementation assessment) where structural changes to the adopted solution occur, or on certain events, such as:

· changes in exposure to risks in the area of anti-money laundering and counter-terrorist financing, and of embargoes

· deficiencies identified in the operation of our solution

· an increase in attempted fraud

Simplified customer due diligence obligations

In general, the Company uses a risk-based approach to identify the types of customers to whom simplified customer due diligence measures may be applied. This includes situations where “low-risk indicators” are present, as provided for in Annex 1 on customer due diligence of the applicable regulations (hereinafter the “Regulation”).

The “low-risk indicators” relevant to applying a simplified customer due diligence procedure are based on the type of customer, of person carrying out the operation or of beneficial owner, on the geographical area of residence or where the registered office is established, and on the specific product, service or distribution channel.

In detail, the types of customer considered to present a low risk of money laundering, to whom the simplified customer due diligence procedure may be applied, include:

· public administrations, institutions or bodies performing public functions, in accordance with European Union law

· companies listed on a regulated market and subject to transparency requirements, including those ensuring adequate transparency of beneficial ownership

· credit and financial institutions in the European Community provided for by Law No 129/2019 on preventing and combating money laundering — with the exception of those under points (i), (o), (s), (v)9 — as well as credit and financial institutions established in Member States or in third countries that have effective anti-money laundering and counter-terrorist financing systems

· customers, persons carrying out the operation or beneficial owners resident or established in geographical areas with a low risk of money laundering

The Company does not apply simplified customer due diligence measures where:

· doubts, uncertainties or inconsistencies arise regarding the identification data and information obtained during the identification of the customer, of the person carrying out the operation or of the beneficial owner

· the conditions for applying simplified customer due diligence measures are no longer met, based on the risk indicators provided by anti-money laundering legislation and the relevant secondary regulations

· monitoring of the customer's overall operations and the information obtained during the relationship rules out classification in the low-risk category;

· a suspicion of money laundering or terrorist financing persists.

The anti-money laundering compliance function has sole responsibility for assessing and authorising simplified customer due diligence measures, which are applied by completing all the steps required for the standard customer due diligence process — including the obligation to identify and verify the identity of the customer, of the person carrying out the operation and of the beneficial owner, and to obtain all the data and documents necessary for their complete registration (for example, name, legal form, registered office and, where applicable, tax identification code) — while reducing their level of detail, scope and frequency.

Enhanced customer due diligence obligations

The Company applies enhanced customer due diligence measures in the presence of customers or situations presenting a heightened risk of money laundering or terrorist financing, and in all cases provided for by law. These enhanced measures include, among others, involving management functions commensurate with the level of risk identified in relation to the customer.

As regards private banking customers, the Company assesses the specific risk factors inherent in the nature of their activity and applies enhanced customer due diligence measures based on all available information and the assessments carried out.

Involvement of the anti-money laundering compliance function is required in the following cases:

· natural and legal persons included on the lists of persons or entities subject to fund-freezing measures under European regulations or under acts issued pursuant to Government Emergency Ordinance No 202/2008 on the implementation of international sanctions, and persons closely associated with them

· a cross-border correspondent banking relationship established with a bank or institution located in a third country, based on high geographical risk factors (as set out in Annex 2 to the National Bank of Romania's customer due diligence regulations)

· relationships or transactions where the customer or the beneficial owner is a politically exposed person10

· situations involving risk elements that require the application of specific confidentiality measures

· situations with a heightened risk of money laundering or terrorist financing, as a result of objective, environmental or subjective circumstances

· customers classified as trusts, money transfer services and virtual currency exchange offices

· fiduciary companies, with the exception of those referred to in point 3.4

In addition, before entering into, continuing or maintaining a business relationship with politically exposed persons or with correspondent entities from third countries, appropriate authorisation must be obtained from the chief executive officer or their delegate, following the opinion of the anti-money laundering compliance function. In the case of persons designated under Law No 129/2019 who are part of the anti-money laundering compliance function, this authorisation is included in the enhanced customer due diligence process.

In all other cases, the application of enhanced measures is proportionate to the level of risk assigned to the customer. Where the risk is considered medium/high, or where certain risk factors are present regardless of the score assigned, the involvement of the head of the business unit responsible for the commercial management of the customer is required.

Examples of such cases are:

· corporate customers whose person carrying out the operation is identified as a politically exposed person or an indirectly politically exposed person, regardless of the risk profile

· services offered through networks of financial agents, financial advisers, contractors and agents

· customers classified as foundations/non-profit organisations

· corporate customers, at the onboarding stage

· customers with negative information at the onboarding stage (“adverse news”)

· politically exposed persons (PEPs): as listed by Law No 129/2019

· customers resident or established in high-risk third countries or, in the case of ongoing business relationships, professional services and operations involving high-risk countries

· companies that have issued bearer shares, or that have in their control chain a company issuing bearer shares

· relationships or transactions where the customer and the beneficial owner hold a public office other than those listed for politically exposed persons

· companies owned by trusts, fiduciary companies, foundations or joint-stock companies, through multiple layers of holdings or through cross-shareholdings

· customers carrying out a type of economic activity particularly exposed to money laundering risk, or operating in “controversial” sectors12 or in cash-intensive business activities, such as gold pawnbroking, currency exchange, gambling/betting including online, the armaments industry, mining, waste collection and disposal, renewable energy production, companies active in the crypto-asset sector, construction, and the procurement of pharmaceutical products

· customers participating in public contracts or benefiting from public funding (healthcare, construction, waste collection and disposal, renewable energy production, mining, supply of pharmaceutical products)

· customers who have acquired the citizenship of a Member State or obtained a right of residence in a Member State (EU) through a citizenship-by-investment programme or a residence-by-investment programme

· corporate customers resident in an EU country, where ownership rights in the company are held — directly or indirectly — to more than 40% by a legal entity, organisation or body established in Russia, or by a natural person resident in or holding the citizenship of Russia

The involvement of the head of the business unit responsible for the commercial management of the customer is also required in the event of any IT errors that could prevent real-time determination of the money laundering risk associated with the customer.

Enhanced customer due diligence measures include obtaining additional information on the customer, the person carrying out the operation and the beneficial owner, investigating the purpose and nature of the relationship, and increasing the frequency of the procedures intended to ensure ongoing monitoring throughout the business relationship.

In full compliance with the legislation in force and with the provisions of the internal anti-money laundering and counter-terrorist financing procedures, and in line with the Company's Code of Ethics, the Company does not support transactions with customers operating in controversial sectors that are not compliant with the national legislation in force and (ii) are not, where applicable, previously authorised by the competent Romanian national authorities, in particular:

· the production, transit and/or trade of armaments

· the production and sale of light marijuana, and adult entertainment venues

· cash-intensive business activities other than those listed above, such as unregulated charities and NGOs, the production of precious metals and stones, and money remittance.

These measures may be commercial in nature (for example, blocking imports/exports) or financial in nature, such as partial/total blocking of money transfers from or to a particular country, or limitations on operations and/or the freezing of funds held with financial intermediaries.

In order to comply with the obligations laid down by Government Emergency Ordinance No 202/2008 on the implementation of international sanctions — which aims to prevent and combat the financing of terrorism and the activities of countries that threaten international peace and security, by applying restrictive measures to “freeze” the funds and economic resources held by natural and legal persons, groups and entities expressly identified by the United Nations and the European Union (“designated persons”) — and with the enhanced customer due diligence obligations laid down by Law No 129/2019, the Company has adopted automated control procedures. These procedures make it possible to verify the correspondence between the customer identification data obtained through the customer due diligence process and the data contained in the lists drawn up by the EU and by other international institutions and bodies, such as:

· persons who have been entrusted with prominent public functions or who ceased to hold such functions less than a year ago (PEPs), their family members and persons known to be their close associates, as defined in Law No 129/2019 (resident and non-resident PEPs)

· persons resident in Romania who hold public offices that do not fall within the PEP definition but who are nevertheless exposed to a significant risk of corruption and money laundering

· natural and legal persons subject to embargo measures or to the freezing of funds/economic resources and financial assets (UN, EU, UKSL, OFAC sanctions lists).

6. Customer profiling

The Company adopts appropriate procedures for defining the money laundering and terrorist financing risk profile (RP) attributable to each customer, based on the information obtained and the analyses carried out, with reference both to the assessment elements indicated in the Regulation and to other elements the Company may adopt over time (so-called profiling).

On the basis of customer profiling, also carried out periodically, the Company applies standard or enhanced measures, which include involving management functions commensurate with the identified level of customer risk. The prior opinion of the anti-money laundering compliance function is required in accordance with the responsibilities set out in the internal document “Internal anti-money laundering and counter-terrorist financing procedures”.

Classifying customers in the category subject to simplified customer due diligence measures is authorised by the anti-money laundering compliance function, at the request of the head of the operational business unit.

In such a case, the scope and frequency of the requirements are reduced, with the verification expiring after 8 years regardless of the risk score, unless the conditions for applying simplified customer due diligence measures are no longer met.

The Company has also implemented an IT procedure for assessing the customer's risk profile and for consistently setting a reassessment interval appropriate to the calculated risk level; the frequency of reassessment depends on the process identified in the last assessment carried out or, in the absence of a customer due diligence questionnaire, on the customer's risk profile, as set out below:

(*) provided where the risk score calculated or resulting from the customer due diligence questionnaire is at least medium. (**) provided even in the presence of defined risk elements that keep the risk profile below the medium level.

(***) provided even in the case of legal entities with an RP >39, if they carry out commercial activities related to the purchase of gold, gambling and betting, and waste collection and disposal (high-risk NACE codes) and/or if they are subject to audits/investigations.

7. Support tools for customer due diligence

The Company has implemented technologically advanced tools to support anti-money laundering processes, alongside the traditional applications already in use:

· Robotic Process Automation (RPA), applied to data collection activities in the area of customer due diligence and suspicious transaction reporting

· an artificial intelligence engine, based on statistical components and predictive indicators (Predict Index AML, Reputational Index and Criminal Infiltration Index), built with data analysis techniques and applied to the periodic customer review process

· the Cogito intelligence platform, an application used to collect news, documents and textual information in order to search for adverse news about customers subject to the customer due diligence process

· Rozes, a data analysis tool which, by analysing financial statements in real time, makes it possible to identify companies whose balance sheet and financial indicators are similar to those found in companies subject to criminal infiltration

In addition, within the advanced tools referred to above, certain “trigger events” have been identified, designed to capture events concerning the customer and/or related relationships, which result in a change to the expiry date of the “Customer Assessment – KYC”, for example:

· where the identification data of the beneficial owner and of the legal representative change

· where the risk profile changes as a result of the presence of certain high-risk factors among those provided for by the Regulation

· where a beneficial owner becomes a politically exposed person, or where a new beneficial owner who is a politically exposed person is registered

· where a power of attorney over a relationship with an individual customer is granted to a person classified as a politically exposed person

· where there is a discrepancy between the beneficial owner recorded in the register and the information obtained from trade register extracts

· in the case of second-level controls carried out by the anti-money laundering compliance function

Responsibility for the customer due diligence process lies with the unit that manages the customer relationship, which ordinarily handles the establishment of new business relationships, executes any occasional transactions, periodically reassesses existing customers and ensures ongoing monitoring of the customer relationship.

8. Abstention obligations

The Company refrains from establishing, executing or continuing a business relationship, operations and professional services (the so-called abstention obligation) where it is objectively impossible to apply customer due diligence measures, while also assessing whether a suspicious transaction report to the financial intelligence unit is required.

In cases where abstention is not possible, because there is a legal obligation to execute the operation which cannot be deferred, or where refusing it could hinder the investigation, the Company is nevertheless required to report the suspicious transaction immediately.

In addition, if following a further assessment, or as a result of the enhanced customer due diligence process, high-risk elements emerge that could affect the Company's legal and/or reputational profile, the Company reserves the right to limit or terminate the business relationship with the customer. Such limitations may concern, for example, the customer's access to certain types of product, or may lead to the interruption of the services offered by the Company in connection with the account/relationship in question.

The customer due diligence measures adopted by the Company do not, however, prevent or refuse access to financial services for customers or entire categories of high-risk customers who would be entitled to them under the legislation in force, except in the cases expressly provided for by Law No 129/2019 concerning the prohibition on maintaining relationships with certain types of entity.

The Company does not establish a correspondent relationship with a shell bank and refrains from establishing relationships with entities that allow a shell bank access to correspondent relationships. The Company will not enter into a business relationship with entities whose ownership structure (corporate, tax and financial) is characterised by a high degree of opacity, which prevents clear identification of the beneficial owner or of the nature and purpose of the structure.

To that end, the Company takes all measures to ensure that it does not deliberately and knowingly work with financial institutions which, in turn, operate with shell banks.

In addition, the Company refrains from establishing or continuing a business relationship with persons particularly exposed to money laundering/terrorist financing risk, such as:

· fiduciary companies with their registered office in a country identified by the FATF as presenting a high risk of money laundering, or which do not adopt measures compliant with the obligations imposed by Law No 129/2019 or by the European directives

· trusts for which adequate, accurate and up-to-date information on the beneficial owner of the trust, and on its nature and purpose, is not available

· betting companies, including online gambling, casinos and bingo operators, for which the authorisations and/or licences required by Romanian and international legislation have not been issued and/or verified

· affiliated entities and agents of payment service providers, and electronic money institutions that do not comply with the applicable provisions of Law No 129/2019

· limited liability companies or companies controlled through bearer shares, with their head office in high-risk countries

· customers active in the production and sale of light marijuana, or adult entertainment venues, where the authorisations required by law cannot be verified

The Company uses all the information obtained through the customer due diligence process about its customers and their transactions to determine whether a transaction or business relationship is connected, directly or indirectly, with persons or entities involved in money laundering, terrorist financing or the development of weapons of mass destruction, and in no way supports transactions involving weapons that are controversial and/or prohibited by international treaties, for example nuclear, biological and chemical weapons, cluster bombs, weapons containing depleted uranium, and anti-personnel mines.

As regards the production, transit and/or trade of armament materials other than those referred to above, the Company may support transactions that have been duly authorised by the competent authorities and that comply with the applicable legislation in force.

9. Reporting suspicious transactions

Whenever the Company suspects, or has reasonable grounds to suspect, that a money laundering or terrorist financing operation has been or is being carried out or attempted:

· it submits a suspicious transaction report to the financial intelligence unit, if the transaction is located in Romania

· if the transaction is located in another country, the Company complies with the provisions of local legislation and, where that legislation provides for the application of measures equivalent to those established by EU law, it immediately informs the head of the anti-money laundering function, taking all necessary precautions to protect the identity of the persons reporting the suspicious transaction

The Company has established procedures and processes for monitoring, identifying and reporting suspicious activity, within the deadlines and in the manner provided for by the applicable legislation.

Employees immediately report any knowledge or suspicion of money laundering, terrorist financing or other criminal activity, or of the proceeds of criminal activity, regardless of its scale, in accordance with the updated organisational model and the operating arrangements set out in the relevant internal regulations. Until the reporting process is completed, the Company refrains from executing the transaction, unless this is impossible because there is a legal obligation to accept the instrument, or because execution of the operation cannot be deferred given the normal course of business, or where abstention could hinder investigations. In those cases, the report is submitted immediately after the transaction has been executed.

The grounds for suspicion include the characteristics, scale and nature of the transaction, any attempt to split it, and any other circumstance that employees become aware of in the exercise of their duties, also taking into account the financial size and the nature of the activity carried out by the person concerned by the suspicious transaction, on the basis of the elements obtained under anti-money laundering legislation (for example, during the customer due diligence process).

In order to limit the risk of the Company being involved — even unintentionally — in the illegal activities referred to above, an enhanced customer due diligence process is triggered for fund transfer operations where the participants in that type of transaction (the originator, the beneficiary, the banks involved in the transfer) may give rise to a suspicion of money laundering, terrorist financing or breach of the international restrictions applicable to certain goods, persons or entities.

Following the reporting process, the Company may limit and/or interrupt the business relationship with customers, in particular where that relationship may constitute a significant legal or reputational risk for RONPay.

10. Record keeping

The Company retains all documents and records all data obtained through the customer due diligence process, ensuring the traceability of customer transactions in order to facilitate the control functions of the Bank and of the financial intelligence unit, including inspections.

To that end, RONPay, as a financial intermediary established in Romania, has set up a single electronic archive that enables it to provide information to the Bank and to the financial intelligence unit in accordance with the technical standards set out in Annex 2 to the record-keeping regulations. This archive stores in electronic format all identification data and other information relating to ongoing business relationships and to customer transactions, as required by the applicable legislation.

In this respect, in response to the recent updates introduced by the “Regulations on record keeping and access to documents, data and information” and by the “Regulations on the submission of aggregated data”, the Company has decided to adopt certain principles exempting it from recording obligations, as expressly provided. In particular, data and information on transactions ordered by banking and financial intermediaries, which fall within the situations provided for in Article 8 of the Record-Keeping Regulations and Article 3 of the Aggregated Data Regulations, are not recorded in the single electronic archive.

As regards customer due diligence requirements, the Company retains copies or records of all necessary documents for a period of ten years from the end of the business relationship.

As regards transactions and ongoing business relationships, all supporting documents and records, for example original documents or copies admissible in judicial proceedings, are retained for a period of ten years from the execution of the transaction or from the end of the business relationship.

11. Prevention in the area of restrictive measures

Given the nature, size and complexity of its activity, and the range and type of services provided, the Company is exposed to the risk of breaching restrictive measures.

In order to maintain an organisational and procedural system designed to ensure compliance with EU and national international restrictive measures, the risk of breaching restrictive measures is assessed by the anti-money laundering compliance function on the basis of geographical, customer, product/service and distribution channel factors, ensuring constant monitoring of the system's effectiveness, also guaranteed by periodically carrying out a self-assessment exercise, which makes it possible to identify any corrective actions in response to identified deficiencies and/or to adopt appropriate measures to prevent and mitigate the risk.

The Company has established procedures and processes for monitoring, identifying and reporting activities that breach restrictive measures, within deadlines and in ways that comply with legal requirements.

The existing controls on persons/entities and transactions are carried out through an automated screening process, performed both daily and at the onboarding stage, using specific lists — updated twice a day — relating to customers, counterparties, countries and transactions.

Processes are in place to monitor incoming or outgoing flows with countries and/or entities subject to international financial sanctions, with defined responsibilities across the competent departments.

It is ensured that staff are appropriately trained and informed about policies, procedures and controls, with a view to complying with restrictive measures.

12. List of main processes

MANAGEMENT OF MONEY LAUNDERING AND TERRORIST FINANCING RISK

The “Management of money laundering and terrorist financing risk” process is the process through which the following activities are carried out within the Company, with a view to mitigating the risk of non-compliance with anti-money laundering and counter-terrorist financing requirements:

· the risk of non-compliance with AML-CFT requirements, through continuous oversight of legislative changes and assessment of their impact on business processes and procedures, and the identification and assessment of AML-CFT risk using a risk-based approach

· managing and mitigating money laundering and terrorist financing risk, by implementing and monitoring the actions to mitigate compliance risk set out in the annual plan (the AML plan) or identified by the Company's management, as applied by all the relevant business functions in implementing the procedures (internal regulations, IT applications, operational processes, controls)

· compliance checks (ex ante and ex post) in the assigned regulatory areas, by defining and monitoring risk indicators and their evolution over time. The aim is to identify any instances of non-compliance and to carry out ex-ante and ex-post control activities

· providing AML/CFT advice and support, by taking part in cross-functional working groups and supporting business structures or senior management bodies in the business matters and processes where money laundering and terrorist financing risk is relevant, by fulfilling the obligations laid down by supervisory regulations and by carrying out a prior compliance assessment in this area when new products/services are launched

· monitoring and controlling AML/CFT risk, by analysing the information flows received from level I and from other control functions concerning operational anti-money laundering requirements, and by implementing risk monitoring controls and constantly verifying their adequacy

· carrying out the AML self-assessment, by performing the preliminary activities needed to complete the so-called “system” and “operational” questionnaires, and to determine residual risk

· reporting to senior management bodies and to the supervisory authorities, specifically preparing the annual report to the corporate bodies and the supervisory board, and preparing periodic reporting on the activities carried out and on any specific requests from the supervisory authorities

· providing specific AML/CFT training, by organising an appropriate training plan together with the other corporate functions responsible for training. The aim is to ensure the continuous training of employees and collaborators

The Company's specific rules and responsibilities for this process are detailed in the internal document

“Internal anti-money laundering and counter-terrorist financing procedures”.

MANAGEMENT OF RELATIONS WITH THE SUPERVISORY AUTHORITIES IN THE AREA OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORIST FINANCING

The AML/CFT regulatory relations management process is the process through which the Company carries out the activities of managing, analysing, directing and monitoring all communications with the regulatory authorities on matters relating to anti-money laundering and counter-terrorist financing. The objective is to oversee these activities, including archiving documents in a single repository.

The following activities are carried out within this process:

· managing relations with the supervisory authorities (anti-money laundering), by managing, analysing and resolving communications and requests from the supervisory authorities concerning compliance in this area

· managing anti-money laundering supervisory reporting, by preparing the flow and submitting the supervisory reports in this area

· managing administrative procedures related to anti-money laundering, by examining appeals concerning administrative procedures notified to the Company by the competent authorities (ONPCSB and the other competent authorities), and representing the Company before the Ministry of Finance, being responsible for recording the procedures in the relevant application, for setting up the provision for risks and charges and for any payment of penalties, in coordination with the budget function

The Company's specific rules and responsibilities for this process are detailed in the internal document “Internal anti-money laundering and counter-terrorist financing procedures”.

MANAGEMENT OF OPERATIONAL REQUIREMENTS IN THE AREA OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORIST FINANCING

The AML/CFT operational requirements management process is the process through which the following activities are carried out within the Company, with a view to complying with regulatory requirements:

· limiting the use of cash and bearer instruments, by meeting the regulatory requirements on limits to the use of cash and bearer bonds/instruments

· managing adequate customer due diligence obligations, by carrying out customer due diligence (or enhanced due diligence) activities in the cases established by Romanian legislation (Law No 129/2019, as subsequently amended), depending on customers' risk profiles, supporting the Company's network in fulfilling the obligations imposed by the laws and regulations in force, and providing support to the Company's structures that manage relationships with customers and with banking and financial counterparties, so that relationships can be established and maintained

· managing suspicious transaction reporting obligations, by carrying out suspicious transaction reporting activities, exercising the delegations of authority granted by the board of directors under Law No 129/2019, and monitoring requests received from the financial intelligence unit

· managing counter-terrorist financing obligations, by defining the screening methodology intended to ensure the implementation of Union and national restrictive measures, verifying the transposition of updates to the sanctions lists, and reporting to the competent authorities (national and supervisory) on restrictive measures (ONPCSB, the Ministry of Foreign Affairs and the Ministry of Finance) concerning capital-freezing measures (under Government Emergency Ordinance No 202/2008) and fulfilling the necessary operational requirements

· managing record-keeping obligations, by verifying the reliability of the IT system, updating the single electronic archive, carrying out any reviews, periodically submitting aggregated data to the financial intelligence unit and submitting to it and to the National Bank of Romania the notifications required by the regulations;

· monitoring the proper implementation of international financial sanctions (financial embargoes)

· ongoing monitoring of the customers with the highest money laundering and terrorist financing risk, monitoring requests for further investigation of customers who may expose the Company to high money laundering risks, activating, where necessary, the suspicious transaction assessment process and the screening process for customers who may expose the Company to high money laundering risks

13. Organisational framework and control bodies

For the effective management of money laundering and terrorist financing risk, and of the risk of breaching restrictive measures, the Company has identified the organisational functions, resources and procedures that are consistent with and proportionate to the type and size of the activity carried out, the organisational complexity and the operational characteristics.

Monitoring of money laundering and terrorist financing risks is ensured:

Monitoring of risks relating to breaches of restrictive measures:

· is ensured by the member of senior management responsible for restrictive measures, a responsibility assigned to the head of the AML department, who oversees the adequacy and effectiveness of the policies, internal procedures and controls concerning the management of restrictive measures, sanctions and embargoes. They propose, in cooperation with the relevant corporate functions, the organisational and procedural changes necessary and/or appropriate to ensure adequate monitoring of the risk of breaching restrictive measures, sanctions and embargoes

In accordance with the regulations in force, the Company has established its organisational structure and corporate governance so as to protect the Company's interests, while ensuring sound and prudent management and avoiding the risk — even unintentional

— of any direct involvement in acts of money laundering and/or terrorist financing.

To that end, in accordance with the internal control system adopted by the Company, the board of directors and the statutory auditors are involved in mitigating the risks referred to above, through clearly defined duties and responsibilities.

The Company has also established a centralised unit for managing the internal breach reporting system, responsible for overseeing the activities of receiving, analysing and assessing the alerts submitted by employees through the whistleblowing procedure.

14. Review and update of the policy

The anti-money laundering function reviews the policy at least annually, updates it if and when necessary, and prepares the text for approval by the board of directors, on a proposal from the chief executive officer.

Any changes to the Policy approved by RONPay's board of directors are subsequently implemented across the whole Company by a decision of senior management, aligning responsibilities, processes and internal rules.