AML / CFT Policy Summary
Version 1.0 · Last updated:
As a licensed Money Service Operator, Rainbow Pay must know who its merchants are, understand what they do, and watch for and report suspicious activity. This page summarises how we do that. It is a public summary, not our internal policy, and it deliberately does not publish operational detail.
1. Our commitment
Rainbow Pay Limited is committed to preventing its services from being used for money laundering, terrorist financing, proliferation financing or sanctions evasion. We maintain a risk-based anti-money laundering and counter-terrorist financing ("AML/CFT") programme designed to meet our obligations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) ("AMLO") and related guidance issued by the Hong Kong Customs & Excise Department, and applicable sanctions requirements.
The programme is approved and overseen by senior management, is supported by a designated compliance function, and is reviewed periodically to reflect changes in law, guidance and our business.
2. Customer due diligence
Before we establish a business relationship, and at other times required by law, we carry out customer due diligence. Our merchants are businesses, so this is primarily Know Your Business (KYB) review, supported by Know Your Customer (KYC) checks on the individuals connected with the business. This typically involves:
- verifying the legal existence, registration and ownership of the business;
- identifying and verifying directors, authorised signatories and other persons acting for the business;
- identifying the beneficial owners who ultimately own or control the business, and taking reasonable measures to verify their identity;
- understanding the nature of the business, its products and services, and the purpose and intended nature of the relationship with us; and
- applying enhanced due diligence where our risk assessment or the law requires it.
We may request further information or documents at any time. Where we cannot complete due diligence to our satisfaction, we will not establish the relationship, or we may restrict or end an existing one.
3. Sanctions and PEP screening
We screen merchants and relevant connected individuals against applicable sanctions lists, both at onboarding and on an ongoing basis. We do not provide services that would breach sanctions that apply to us or to our payment partners.
Where applicable, we also identify politically exposed persons (PEPs) connected with a merchant and apply the additional measures the law requires.
4. Ongoing monitoring and review
Where applicable to the services provided, we monitor activity to identify transactions or behaviour that is unusual or inconsistent with what we know about the merchant. We keep customer information up to date and review business relationships periodically and when circumstances change.
5. Suspicious transaction reporting
Where we know or suspect that property represents the proceeds of crime or is connected with terrorism, we are required by law to report it to the Joint Financial Intelligence Unit (JFIU), which is operated jointly by the Hong Kong Police Force and the Customs and Excise Department.
6. Record keeping
We keep customer due diligence records and transaction records for the periods required by the AMLO and other applicable law, so that they can be made available to competent authorities when lawfully requested. See our Privacy Notice for how this affects personal data.
7. Staff and governance
Relevant staff receive AML/CFT training appropriate to their role, and we apply screening to staff in positions where it is appropriate. Our programme is subject to periodic independent review or audit.
8. Cooperation with authorities
We cooperate with lawful requests from regulators, law enforcement agencies and courts, and we may share information with our payment partners where the law and our agreements permit or require it.
9. Businesses we do not support
Some types of business are outside our risk appetite, or cannot be supported under applicable law or the rules of our payment partners and payment schemes. See Restricted & Prohibited Businesses.
10. What we do not publish
To protect the effectiveness of our controls, we do not publish operational detail, including thresholds, screening rules and data sources, monitoring scenarios, risk scoring methods or our internal procedures for suspicious transaction reporting. Requests for this information will be declined.
Merchants and payment partners with a legitimate need for further information about our AML/CFT controls, for example as part of their own due diligence, can contact compliance@rainbowpay.hk.