AML / CTF Policy Statement

1. WHO WE ARE

StableOne is a trading name owned and operated by ATLPay INC, a corporation incorporated in Canada with Business Number 1001261031, registered at Office 195, 145½ Church Street, Unit 5, Toronto, Ontario, M5B 1Y4, Canada.

ATLPay INC is registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) as a Money Services Business (MSB) under registration number C10001574, and is supervised by the Bank of Canada as a registered Payment Service Provider (PSP) under the Retail Payment Activities Act (RPAA).

We provide funds transfer and foreign currency exchange services to business clients through the StableOne platform. We are committed to the highest standards of Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) compliance, in full accordance with Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and all applicable regulations.

Services to residents of Quebec or Quebec-registered entities are strictly prohibited. All transactions are initiated exclusively through the StableOne secure online web portal

2. OUR COMMITMENT

StableOne (operated by ATLPay INC) is fully committed to preventing our platform from being used for money laundering, terrorist financing, or any other financial crime. This policy reflects that commitment and applies to all employees, contractors, consultants, and business affiliates of the Company.

Our AML/CTF Programme is designed to ensure that:

  • We comply fully with the PCMLTFA and all FINTRAC and Bank of Canada requirements;
  • We only enter into business relationships with clients whose identities, activities, and funds can reasonably be established as legitimate;
  • All staff are trained to identify and respond appropriately to suspicious activity; and
  • Accurate records are retained and made available to regulators as required.

3. OUR COMPLIANCE PROGRAMME

ATLPay INC maintains a formal AML/CTF Compliance Programme for the StableOne platform comprising five core elements:

01 Written compliance policies and procedures, reviewed and approved by Senior Management
02 A designated Compliance Officer with full responsibility for Programme implementation
03 A Risk-Based Assessment (RBA) identifying and mitigating ML/TF risks across our operations
04 Ongoing AML/CTF staff training to ensure all employees understand their obligations
05 Periodic effectiveness reviews conducted at least every two years

4. KNOW YOUR CLIENT (KYC) & CUSTOMER DUE DILIGENCE

Before establishing any business relationship, StableOne verifies the identity of all clients. Our KYC process is risk-based and proportionate to the level of risk each client and transaction presents.

Standard Client Due Diligence (CDD)

Applies to all new clients and includes collection and verification of:

  • Full legal name, registered address, and contact details
  • Nature of principal business or occupation
  • Source of funds and expected transaction profile
  • Beneficial ownership information (for corporate clients)
  • Identification documents verified against reliable, independent sources

Enhanced Due Diligence (EDD)

Additional scrutiny is applied to clients identified as higher risk, including:

  • Politically Exposed Persons (PEPs) — foreign, domestic, or heads of international organisations
  • Family members and close associates of PEPs
  • Clients operating in or transacting with higher-risk jurisdictions
  • Clients where the source of funds or the purpose of the transaction is unclear
  • Any client or transaction assessed as high-risk under our Risk-Based Approach

All PEPs, Heads of International Organisations (HIOs), and their family members and close associates are automatically classified as high-risk and subject to Enhanced Due Diligence, regardless of the value of the transaction

5. TRANSACTION MONITORING & SUSPICIOUS ACTIVITY

StableOne monitors all transactions on an ongoing basis. Our monitoring programme is designed to detect activity that is inconsistent with a client's known profile, unusual in nature, or which may indicate money laundering or terrorist financing.

Reporting Obligations

We are required by law to report the following transactions to FINTRAC:

  • Suspicious Transaction Reports (STRs) — for any transaction or attempted transaction suspected to involve the proceeds of crime or terrorist financing, regardless of value
  • Terrorist Property Reports (TPRs) — where we know or believe that property in our possession is owned or controlled by a terrorist or terrorist group
  • Large Cash Transaction Reports (LCTRs) — for cash transactions of CAD $10,000 or more
  • Electronic Funds Transfer Reports (EFTs) — for international transfers of CAD $10,000 or more

Sanctions Screening

All clients and transactions are screened against applicable Canadian sanctions lists, including those maintained under the Criminal Code, United Nations Act, and the Special Economic Measures Act (SEMA). We do not process transactions involving Listed Individuals or sanctioned entities.

6. RECORD KEEPING

ATLPay INC maintains comprehensive records of all client identification, transaction, and compliance activities for a minimum of five (5) years. Records are stored securely and can be retrieved and submitted to FINTRAC within 30 days upon request.

Records maintained include client identification documents, transaction records, risk assessments, monitoring activities, STRs, EFT reports, and all FINTRAC correspondence.

7. COMPLIANCE OFFICER

A designated Compliance Officer (CO) is responsible for the implementation, maintenance, and oversight of our AML/CTF Programme. The CO has unrestricted access to all records and reports, and acts as the primary point of contact for FINTRAC, the Bank of Canada, and other regulatory authorities.

The CO reports to Senior Management at least monthly on compliance matters, including high-risk client activity, FINTRAC reporting metrics, and any material changes to the Company's risk profile.

8. STAFF TRAINING

All employees — including new hires and contractors — receive mandatory AML/CTF training appropriate to their role. Training covers recognition of suspicious activity, client identification obligations, reporting procedures, and the consequences of non-compliance. Records of all training are maintained by the Compliance Officer.

9. CONSEQUENCES OF NON-COMPLIANCE

ATLPay INC takes non-compliance with AML/CTF obligations extremely seriously. Failure to comply with the PCMLTFA may result in:

  • Administrative monetary penalties from FINTRAC of $1,000 to $500,000 per violation
  • Criminal prosecution with fines of up to $2 million and/or imprisonment of up to five years
  • Sanctions enforcement by the RCMP or the Minister of Foreign Affairs, with fines of up to $100,000 and/or imprisonment

Employees are reminded that criminal liability may attach personally where an individual fails to report a suspicious transaction or directs, authorises, or participates in a compliance offence.

10. CONTACT & FURTHER INFORMATION

This Policy Summary is published for transparency and public information purposes. For queries relating to our AML/CTF compliance programme, or to report a concern, please contact: compliance@stableone.net