Institutional document
IA TECH PAY
IA TECH MARKETING DIRETO LTDA.
CNPJ: 63.051.871/0001-54
Institutional Document — IA TECH PAY
ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING POLICY (AML/CFT)
Version 1.0
Document control
- Responsible entity
- IA TECH PAY
- Classification
- Institutional document for public disclosure
- Version
- 1.0
- Approval date
- 01/07/2026
- Next review
- Within 12 months, or earlier in the event of a relevant regulatory change
- Approval
- Board of Directors / Management of IA TECH PAY
1. Objective and Institutional Commitment
IA TECH PAY operates in the digital payments and virtual asset services market in Brazil and the Southern Cone. This Anti-Money Laundering and Counter-Terrorism Financing Policy ("AML/CFT Policy") establishes the principles, guidelines and internal controls adopted by the company to prevent its products, services and infrastructure from being used to commit money laundering, concealment of assets, rights and valuables, terrorism financing or financing of the proliferation of weapons of mass destruction.
IA TECH PAY is committed to conducting its operations with integrity, transparency and responsibility, aligning its practices with the best market references and the regulations applicable in the jurisdictions in which it operates, whether directly or indirectly, be it as a payment services operator or as a distributor and country operator ("Master-Distributor") of virtual asset infrastructure of authorized partners.
This Policy is publicly available and mandatory for all employees, officers, partners and relevant service providers involved in the operation of IA TECH PAY.
2. Scope of Application
This Policy applies to all lines of business, products and channels operated under the IA TECH PAY brand, including, but not limited to:
- Receipts and payments via PIX (PIX IN and PIX OUT);
- Issuance and settlement of bank slips (boleto bancário);
- Purchase, sale, transfer and swap transactions involving virtual assets (crypto-assets and stablecoins);
- Foreign exchange and conversion transactions between fiat currencies (FIAT-FIAT) and between fiat currency and virtual asset (Crypto-FIAT);
- Distribution, in certain countries, of payment rails (BaaS) and the stablecoin of authorized partners, under a Master-Distributor / country operator model.
This Policy covers own employees, officers, operating partners, business partners, sub-participants of the distribution network and relevant service providers engaged by IA TECH PAY, in Brazil and abroad, subject to the local obligations of each jurisdiction in which the company operates.
3. Definitions
- Money laundering:
- The process by which funds, assets or valuables of illicit origin are introduced into the financial system and subjected to successive transactions with the aim of concealing their origin and giving them an appearance of legitimacy, typically structured in three internationally recognized stages: placement, layering and integration.
- Terrorism financing:
- The provision, deposit, distribution or making available of funds, assets or valuables, directly or indirectly, for the planning or commission of terrorist acts, even if the funds used have a lawful origin.
- AML/CFT:
- Acronym for Anti-Money Laundering and Counter-Terrorism Financing, the set of policies, procedures and internal controls adopted to mitigate these risks.
- PEP (Politically Exposed Person):
- A public official who holds or has held, within the last five years, a relevant public office, position or function, in Brazil or abroad, as well as their direct family members and close associates, according to risk criteria defined by current regulations.
- Ultimate beneficial owner:
- A natural person who, ultimately, directly or indirectly, owns, controls or significantly influences a legal entity or contractual arrangement, or on whose behalf a transaction is conducted.
- VASP:
- Virtual Asset Service Provider, a natural or legal person that carries out, on a habitual basis and on behalf of third parties, activities of exchange, transfer, custody, administration or intermediation of virtual assets.
- Travel Rule:
- International requirement, set out in FATF Recommendation 16, that originator and beneficiary information accompany virtual asset transfers between service providers, in a manner equivalent to what already occurs in electronic transfers within the traditional financial system.
4. Applicable Regulatory Framework
This Policy was built based on the legislation and regulations in force in the jurisdictions in which IA TECH PAY operates, as well as the recommendations of leading international AML/CFT bodies. The table below summarizes the main regulatory sources considered.
| Jurisdiction | Authority | Main reference rules |
|---|---|---|
| Brazil | Central Bank of Brazil (BCB) and COAF | Law No. 9,613/1998; Law No. 13,260/2016; BCB Circular No. 3,978/2020 (amended by BCB Resolution No. 282/2022); Law No. 14,478/2022 (Crypto-Assets Legal Framework); BCB Resolutions No. 519, 520 and 521/2025 (virtual asset regime, effective from 2/2/2026) |
| Paraguay | SEPRELAD (Paraguay FIU) | Law No. 1,015/1997 and amendments; regulation of obligated parties regarding virtual assets under development, monitored by GAFILAT |
| Uruguay | SENACLAFT / Superintendencia de Servicios Financieros (BCU) | Current AML/CFT law; BCU/SSF regulatory proposal on Virtual Asset Service Providers (VASPs), under consultation since 2025 |
| Argentina | UIF Argentina | UIF Resolution No. 49/2024 — obligated parties: Virtual Asset Service Providers (VASPs) |
| International | FATF | Recommendation 15 (risk-based approach for VASPs) and Recommendation 16 (Travel Rule) |
4.1 Brazil
In Brazil, Law No. 9,613/1998 defines the crime of money laundering and Law No. 13,260/2016 governs the financing of terrorism. BCB Circular No. 3,978/2020, amended by BCB Resolution No. 282/2022, establishes the AML/CFT policy, procedures and internal controls required of institutions authorized to operate by the Central Bank, under a risk-based approach. With the enactment of Law No. 14,478/2022 (Crypto-Assets Legal Framework) and, more recently, BCB Resolutions No. 519, 520 and 521, of November 10, 2025 — effective as of February 2, 2026 — virtual asset service providers became subject to a prudential regime equivalent to that of traditional financial institutions, including governance requirements, minimum capital, asset segregation, cybersecurity and AML/CFT controls.
4.2 Paraguay, Uruguay and Argentina
In the countries where IA TECH PAY acts as a participant in virtual asset infrastructure, the company monitors local regulatory developments: in Argentina, UIF Resolution No. 49/2024 incorporated Virtual Asset Service Providers (VASPs) as obligated parties before the Unidad de Información Financiera; in Uruguay, the Banco Central del Uruguay, through the Superintendencia de Servicios Financieros, has since 2025 been conducting a specific regulatory process for VASPs, under the supervision of SENACLAFT on AML/CFT matters; in Paraguay, SEPRELAD (Paraguay FIU) is the authority responsible for preventing asset laundering and terrorism financing, with active participation in GAFILAT regional discussions on digital assets. IA TECH PAY monitors these initiatives and adapts its local procedures as each regime enters into force.
4.3 International Standards — FATF
This Policy incorporates the guidelines of the Financial Action Task Force (FATF), in particular Recommendation 15, which extends to VASPs the same AML/CFT obligations applicable to financial institutions, and Recommendation 16, which establishes the Travel Rule for virtual asset transfers, with an international reference threshold of around USD/EUR 1,000.00 for requiring complete originator and beneficiary data.
5. Governance Structure and Responsibilities
The Board of Directors of IA TECH PAY is responsible for approving, keeping up to date and ensuring the effectiveness of this Policy. The Board will formally designate an officer or person responsible for compliance with AML/CFT obligations, who will answer to the competent authorities for the implementation of the procedures and controls set out in this document.
The responsibilities of IA TECH PAY's AML/CFT governance structure are:
- Approve and periodically review this Policy and the Internal Risk Assessment (IRA);
- Ensure human, technological and financial resources compatible with the complexity and risk of the operations;
- Formally designate the person responsible for AML/CFT before the applicable regulatory bodies;
- Approve the reporting of suspicious transactions to the competent authorities;
- Monitor the annual effectiveness report on AML/CFT controls and the corresponding action plan.
6. Risk-Based Approach (Internal Risk Assessment)
IA TECH PAY adopts the risk-based approach recommended by FATF and Brazilian regulations, under which the intensity of controls is proportional to the risk identified for each customer, product, distribution channel and geographic area. To this end, the company maintains an Internal Risk Assessment (IRA), documented and periodically reviewed, which considers, among other factors:
- The profile and transaction history of customers and partners;
- The nature of the products and services offered (payments, foreign exchange, virtual assets);
- Distribution channels, including the network of sub-participants and business partners;
- Geographic exposure to countries or regions with a higher risk of money laundering or terrorism financing.
Based on this assessment, the company classifies customers and relationships into risk categories, which correspond to different levels of due diligence, as summarized in the table below.
| Category | Typical profile | Applicable due diligence |
|---|---|---|
| Low risk | Natural person, volume and frequency compatible with the declared profile, no alerts on restrictive lists | Simplified due diligence (CDD), with standard periodic monitoring |
| Medium risk | Legal entity, occasional international transactions, moderate increase in transaction volume | Standard due diligence with more frequent registration review and enhanced transaction monitoring |
| High risk | Politically Exposed Persons (PEPs) and related parties; customers from high-risk jurisdictions; atypical volumes; counterparties with a history of alerts | Enhanced due diligence (EDD): source of funds, senior-level approval, intensified ongoing monitoring |
7. Know Your Customer, Know Your Partner and Know Your Employee Procedures (KYC / KYP / KYE)
IA TECH PAY implements identification and qualification procedures ("Know Your Customer" — KYC) prior to the start of the relationship and throughout its duration, including:
- Collection and verification of registration data of natural and legal persons, including identification of the ultimate beneficial owner;
- Verification of the authenticity of the documentation submitted, using document validation tools;
- Classification of the customer into a risk category, according to the methodology described in Section 6;
- Screening against international sanctions lists (UN, OFAC and equivalents), Politically Exposed Persons lists and adverse media databases;
- Periodic registration updates, with greater frequency for customers classified as high risk.
The same principles are applied, with the necessary adaptations, to Know Your Partner (KYP) processes, aimed at business partners, customers and relevant service providers, and Know Your Employee (KYE) processes, aimed at the selection and monitoring of the company's officers and employees.
8. Enhanced Due Diligence and Politically Exposed Persons (PEPs)
Customers, partners and counterparties classified as high risk — including Politically Exposed Persons and their relatives, customers from jurisdictions considered higher risk, and relationships with atypical transaction volumes or patterns — are subject to Enhanced Due Diligence (EDD), which includes:
- A more thorough verification of the source of funds and declared assets;
- Approval of the start or continuation of the relationship by a senior hierarchical level;
- Continuous and more frequent monitoring of transactions carried out;
- Periodic reassessment of the assigned risk classification.
9. Transaction Monitoring and the Travel Rule
IA TECH PAY maintains continuous monitoring of transactions carried out by its customers, with the aim of identifying atypical transactions that are incompatible with the declared profile or that show indications of structuring, use of third parties or other techniques associated with money laundering, using the resources available through the API of the ETHER Exchange and DEX Pay platforms as a basis for such monitoring and observability.
In transactions involving virtual assets, and in line with FATF Recommendation 16 and the Travel Rule introduced into Brazilian regulation by BCB Resolution No. 521/2025, IA TECH PAY and its infrastructure partners adopt procedures to identify the holder of wallets involved in the transaction — including self-custodied wallets —, to record the origin and destination of the virtual assets transferred, and to transmit, when applicable, the originator and beneficiary data to the counterparty's service provider, using the resources available through the API of the ETHER Exchange and DEX Pay platforms as a basis for such monitoring and observability.
Cash deposits, withdrawals or contributions, as well as transactions exceeding the thresholds defined in applicable regulations, are subject to recording and, where applicable, reporting to the competent authorities within the legal deadlines, without notifying those involved.
10. Reporting Suspicious Transactions to Authorities
Transactions or proposed transactions showing indications of money laundering or terrorism financing are analyzed by the department responsible for AML/CFT and, when such indications are confirmed, reported to the competent authorities — in Brazil, to the Council for Financial Activities Control (COAF) — within the deadlines and in the manner required by the regulations, without those involved being made aware of the report.
Reports made in good faith, in compliance with this Policy and applicable law, do not give rise to civil or administrative liability for IA TECH PAY, its officers or employees. Information relating to such reports is for the exclusive use of regulatory bodies and is not disclosed to customers or third parties.
11. Sanctions, Restrictive Lists and Prohibitions
IA TECH PAY prohibits establishing or maintaining a relationship with natural or legal persons included on sanctions lists issued by the United Nations, the Office of Foreign Assets Control (OFAC) of the United States, or other competent authorities, as well as with jurisdictions subject to recognized international embargoes or restrictions.
Screening against restrictive lists is performed at the time of customer or partner registration and continuously throughout the relationship, in order to identify any subsequent inclusions.
12. Record Keeping and Retention
All records relating to customer, partner and employee identification procedures (KYC, KYP, KYE), transactions carried out, and analyses conducted due to indications of money laundering or terrorism financing are kept for the minimum period required by applicable regulations in each jurisdiction — currently ten years in Brazil — and made available to competent authorities upon formal request.
Such records are stored using the resources available through the API of the ETHER Exchange and DEX Key platforms.
13. Training and Compliance Culture
IA TECH PAY promotes periodic AML/CFT training for officers and employees, with content adapted to the roles performed and the sensitive activities of the business, in order to ensure that the entire organization understands its role in preventing money laundering and terrorism financing. Compliance culture is treated as a responsibility of senior management and extends to the product, technology, operations and customer service departments.
14. Effectiveness Assessment and Audit
The effectiveness of the AML/CFT policy, procedures and internal controls is periodically assessed through testing and monitoring mechanisms, with an annual report prepared and submitted to the Board of Directors. Any deficiencies identified are addressed through a specific action plan, with deadlines, persons responsible and monitoring of implementation.
15. Relationship with Partners and Relevant Service Providers
In transactions where IA TECH PAY acts as a participant and country operator of the virtual asset infrastructure of authorized partners, the company assesses the technical, operational and regulatory capacity of such partners before formalizing the business relationship, including verification of their authorization to operate, their status as a supervised entity in their respective home jurisdictions, and the existence of their own AML/CFT controls compatible with the standards adopted in this Policy.
Likewise, the engagement of relevant service providers — such as technology, liquidity or custody providers — is conditional on such parties observing AML/CFT and security standards compatible with the risks of the activity, with IA TECH PAY responsible for the ongoing monitoring of such compliance throughout the contractual relationship.
16. Update and Review of this Policy
This Policy is reviewed at least annually, or whenever relevant changes occur in legislation, applicable regulations, or the risk profile of IA TECH PAY's activities, including the entry into force of new regulatory regimes in the jurisdictions in which the company operates. Reviews are submitted for approval by the Board of Directors and take effect upon publication.
17. Communication Channel and Contact
Questions about this Policy, as well as reports related to indications of misuse of IA TECH PAY's products and services for money laundering or terrorism financing purposes, may be directed to the company's compliance channel: [email/channel to be defined by the Board of Directors].
Document approved by the Board of Directors of IA TECH PAY for public disclosure.