PAYMESH LTDA
Anti-Money Laundering, Counter-Terrorist Financing, Sanctions and Financial Crime Policy
Brazil
| Version | 2.0 |
| Jurisdiction | Brazil |
| Entity | Paymesh LTDA |
| Policy Owner | Compliance / AML Officer |
| Designated AML Officer | Nelson Sanchez |
| Effective Date | August 2026 |
| Review Frequency | At least annually and upon any material regulatory, product or operating-model change |
1. Purpose
This Policy establishes the anti-money laundering, counter-terrorist financing, sanctions, fraud-prevention and financial-crime controls applied by Paymesh LTDA ("Paymesh") in connection with its Brazilian cardholder stablecoin wallet-loading programme (the "Programme").
The Programme enables eligible, verified cardholders to use an eligible payment card to acquire fiat-referenced stablecoins, including USDC and USDT where supported, with the corresponding virtual assets credited to a custodial wallet associated with the relevant customer and maintained by Avenia.
Paymesh operates the technology, integration, customer-interface, risk-control and transaction-orchestration layer supporting the Programme. Paymesh does not, in connection with this Programme, act as the regulated provider of virtual asset intermediation or custody services.
The purpose of this Policy is to ensure that Paymesh:
- maintains effective controls to prevent its technology and payment infrastructure from being used for money laundering, terrorist financing, sanctions evasion, fraud or other financial crime;
- performs customer identification, screening, transaction monitoring and operational risk controls to an appropriate standard;
- supports Avenia in satisfying the regulatory obligations applicable to Avenia as the regulated virtual asset service provider;
- promptly escalates relevant customer, transaction and financial-crime information to Avenia;
- keeps complete and auditable records of the compliance controls performed through Paymesh systems; and
- preserves a clear separation between Paymesh's operational compliance functions and the ultimate regulatory authority retained by Avenia.
This Policy must be read together with the applicable Paymesh information-security, data-protection, fraud-management, sanctions, risk-management and incident-response procedures.
2. Regulatory and Operating Position
The Programme is structured on the basis that Avenia is the entity legally responsible for the regulated virtual asset services underlying the Programme, including intermediation relating to the acquisition of virtual assets and custody of those virtual assets.
Paymesh acts as a technology and operational service provider supporting those regulated services and may constitute a Relevant Service Provider ("RSP") to Avenia for purposes of BCB Resolution No. 520/25.
Paymesh's activities may include:
- operation of the customer-facing technology interface;
- collection and transmission of customer information;
- customer identification and verification;
- biometric verification;
- sanctions, PEP and risk screening;
- customer eligibility assessment;
- transaction and fraud monitoring;
- operational approvals;
- card-transaction connectivity and orchestration;
- transaction-state management;
- transmission of information and technological instructions between systems;
- reconciliation of transaction records; and
- customer communications and operational support.
These activities do not give Paymesh independent regulatory authority over the virtual asset service.
Paymesh performs relevant AML/CFT controls within policies, rules, limits, risk parameters and decision frameworks established or approved by Avenia. Avenia retains ultimate authority over regulated customer eligibility, continued customer acceptance, virtual-asset transaction approval, AML/CFT regulatory determinations, suspicious-transaction analysis, legally required restrictions or blocking and reporting to competent authorities.
Nothing in this Policy shall be interpreted as permitting Paymesh to exercise a function that would cause Paymesh itself to become the purchaser, seller, intermediary, custodian, transferor, economic counterparty or liquidity provider in respect of customer virtual assets.
3. Roles and Responsibilities
3.1 Paymesh
Paymesh is responsible for the effective operation of the compliance controls incorporated into its technology and operational infrastructure.
Paymesh shall:
- collect customer information required under the approved onboarding framework;
- perform identity and biometric verification using approved systems;
- apply customer eligibility and risk-scoring criteria;
- conduct sanctions, PEP and other screening required by the approved control framework;
- operate transaction-level fraud and financial-crime monitoring;
- identify and flag activity that falls outside expected customer behaviour;
- suspend the Paymesh technology workflow where an applicable Paymesh control is triggered;
- escalate relevant alerts, cases and supporting information to Avenia;
- preserve the audit trail relating to customer onboarding and transactions;
- implement approved changes to regulatory and transaction-monitoring parameters;
- cooperate with Avenia in investigations and regulatory enquiries;
- protect the integrity and confidentiality of AML/CFT data; and
- maintain adequate trained personnel, systems, continuity arrangements and oversight over relevant third-party technology providers.
Paymesh may apply stricter internal fraud, security or risk controls than the minimum controls required by Avenia where reasonably necessary to protect Paymesh, its payment infrastructure, cardholders, the Ramp Provider, acquiring partners or the Programme.
Such controls do not alter Avenia's regulatory responsibility for the underlying virtual asset service.
3.2 Avenia
Avenia remains responsible, in its capacity as the regulated VASP, for the regulatory AML/CFT responsibilities attached to the virtual asset service.
This includes responsibility for:
- establishing or approving the AML/CFT policies and regulatory parameters applicable to customers using the Programme;
- establishing or approving customer and transaction risk criteria;
- determining final regulatory eligibility of customers;
- overriding or modifying automated parameters where appropriate;
- conducting final suspicious-transaction analysis;
- determining whether a transaction must be blocked, rejected, suspended or subjected to additional investigation on regulatory grounds;
- undertaking reporting required to Brazilian competent authorities;
- maintaining regulatory records required of the VASP;
- conducting on-chain controls applicable to assets under its custody;
- determining whether a wallet or virtual-asset transaction may lawfully be accepted or executed; and
- maintaining ongoing regulatory oversight over Paymesh as a relevant service provider.
Paymesh shall provide Avenia with the information and system access reasonably necessary for Avenia to discharge these responsibilities.
4. Risk-Based Approach
Paymesh applies a risk-based approach to the Programme.
Customer Risk
Relevant factors include customer identity, residence, nationality where legally relevant, occupation or business activity, source of funds, expected transaction activity, PEP status, sanctions exposure, adverse information, previous account behaviour and consistency between the customer profile and transaction activity.
Geographic Risk
Paymesh may consider the customer's location, card-issuing jurisdiction, IP location, device location, relevant transaction geography and exposure to jurisdictions presenting elevated financial-crime or sanctions risk.
Product Risk
The Programme is limited to the acquisition of approved fiat-referenced virtual assets and delivery to the customer's associated custodial wallet.
The Programme does not permit, within the transaction flow covered by this Policy:
- merchant settlement;
- cash withdrawal;
- anonymous wallet loading;
- P2P payments;
- direct third-party payments; or
- delivery of purchased virtual assets to an unrelated third-party wallet.
Transaction Risk
Relevant factors include transaction size, velocity, frequency, aggregate value, card usage patterns, changes from historical behaviour, device characteristics, authentication data, declined or reversed transactions, payment credentials, wallet characteristics and other available risk indicators.
Channel Risk
Paymesh shall consider risks associated with remote onboarding, card-not-present payments, account takeover, synthetic identity, stolen payment credentials, device manipulation and other risks associated with online card-funded virtual-asset transactions.
5. Customer Acceptance
No customer may access the transactional functionality of the Programme until the customer has successfully completed the applicable identification and verification process.
The customer must establish an account associated with an identifiable natural person or other eligible customer type supported under the Programme.
Anonymous or fictitious accounts are prohibited.
Paymesh shall not knowingly permit a person to use another person's verified Paymesh account or custodial wallet.
Customer onboarding shall be declined, suspended or referred for further review when:
- identity cannot be satisfactorily established;
- required verification cannot be completed;
- screening produces a confirmed sanctions match;
- material information provided by the customer is false or materially inconsistent;
- required enhanced due diligence cannot be completed;
- there are reasonable indicators of identity theft, impersonation or account takeover;
- the proposed activity falls outside the Programme's permitted use cases; or
- continued servicing would conflict with an applicable Avenia-approved regulatory restriction.
6. Customer Due Diligence
Paymesh shall collect and verify the information required by the approved customer due-diligence framework.
For individual customers this may include, as applicable:
- full legal name;
- date of birth;
- residential address;
- nationality and country of residence where required;
- government-issued identity-document information;
- contact information;
- tax or national identification information where required;
- biometric verification;
- device and technical information;
- source-of-funds information where required; and
- other information necessary to establish the customer's identity and risk profile.
Paymesh currently uses Persona as a primary component of its identity, document and biometric-verification architecture.
Verification controls may include document-authenticity assessment, biometric/liveness checks, duplicate-account detection, identity-data consistency checks and other technology-enabled verification measures.
A customer shall not be treated as successfully verified solely because an automated provider has returned a positive result where other information held by Paymesh gives rise to material doubt regarding the customer's identity.
7. Enhanced Due Diligence
Enhanced Due Diligence ("EDD") shall be applied where the customer or transaction presents elevated money-laundering, terrorist-financing, sanctions or fraud risk.
EDD may include:
- additional identity evidence;
- verification of residential address;
- additional biometric verification;
- source-of-funds evidence;
- source-of-wealth information where proportionate;
- explanation of expected transaction activity;
- verification of employment, occupation or business activity;
- additional sanctions, PEP or adverse-information screening;
- manual review of payment activity;
- review of previous transactions;
- additional confirmation concerning the payment card;
- additional review of wallet activity or blockchain exposure by Avenia; and
- approval by designated compliance personnel or Avenia where required.
Failure to satisfactorily complete required EDD may result in rejection, restriction or termination of access to the Programme.
8. Sanctions, PEP and Screening Controls
Paymesh shall operate appropriate screening as part of customer onboarding and ongoing monitoring.
Screening shall be performed against sanctions and other lists required under the approved compliance framework.
Potential matches must not be cleared solely on the basis of incomplete data where material uncertainty remains.
Confirmed or credible potential sanctions matches must be immediately escalated to the Compliance function and Avenia.
Where regulatory blocking or reporting obligations may apply, Avenia shall make the applicable regulatory determination in its capacity as VASP unless Paymesh itself is independently subject to a direct legal obligation requiring action.
PEP status does not automatically prohibit use of the Programme. PEP customers must, however, be treated in accordance with the applicable enhanced due-diligence and approval requirements.
9. Cardholder and Payment Controls
The Programme is intended to operate as a cardholder-to-own-wallet model.
Paymesh shall maintain controls reasonably designed to establish consistency among the verified customer, the card transaction, the customer account, the associated custodial wallet and the stablecoin credit.
Paymesh shall use card-authentication and fraud-control information available through its acquiring and processing infrastructure.
Controls may include:
- 3DS and other applicable cardholder-authentication data;
- cardholder/customer identity consistency;
- issuer country and customer-country comparison;
- transaction velocity;
- repeated card usage;
- multiple cards associated with a single customer;
- the same card associated with multiple customer accounts;
- excessive authorization attempts;
- unusual decline patterns;
- device fingerprinting;
- IP and geolocation information;
- proxy or VPN indicators where relevant;
- account age;
- behavioural analysis; and
- information supplied by acquirers, processors, issuers, Visa or the applicable Ramp Provider.
Paymesh currently uses nSure.ai as part of its transaction-level fraud and risk-monitoring architecture.
Third-party payment behaviour, suspected card misuse or payment activity materially inconsistent with the verified customer profile shall trigger rejection, restriction or escalation as appropriate.
10. Wallet and Virtual-Asset Controls
The stablecoin acquired through the Programme may only be delivered in accordance with the approved Programme architecture to the custodial wallet associated with the relevant customer.
Avenia maintains the relevant custodial relationship and remains responsible for custody, wallet control and regulated execution of the virtual-asset leg.
Paymesh:
- does not hold customer private keys;
- does not control customer virtual assets;
- does not independently move virtual assets;
- does not execute blockchain transactions;
- does not independently determine the final legal settlement of a virtual-asset transaction; and
- does not provide the stablecoin inventory used to fulfil customer purchases.
Avenia is responsible for the on-chain controls applicable to the virtual assets and wallets under its regulated control, including blockchain analytics and any restrictions required by its AML/CFT framework.
Where Paymesh receives information from Avenia identifying an unacceptable wallet, virtual-asset exposure or transaction, Paymesh shall prevent further progression through the Paymesh technology workflow in accordance with Avenia's instruction.
11. Transaction Monitoring
All transactions processed through the Programme shall be subject to automated and, where appropriate, manual transaction monitoring.
Monitoring shall be capable of considering customer, card, transaction, device and available wallet-related information.
Paymesh monitoring shall be calibrated to identify indicators including:
- activity inconsistent with the customer's known profile;
- unexpectedly high transaction values;
- rapid increases in transactional volume;
- repeated transactions structured immediately below applicable limits;
- unusually high transaction velocity;
- rapid use of multiple payment cards;
- repeated failed authentication or authorization;
- multiple customer accounts linked to the same card, device or identifying information;
- suspected third-party card funding;
- unusual geolocation or device changes;
- abnormal account-access patterns;
- potential account takeover;
- transactions inconsistent with declared source of funds;
- known fraud typologies;
- sanctions or restricted-geography exposure;
- attempts to circumvent account or transaction limits;
- repeated creation of accounts following restriction or termination;
- unusual relationship between transaction size and customer profile;
- transaction patterns associated with layering or laundering activity; and
- other risk indicators identified by Paymesh, Avenia, acquiring partners, Visa, the Ramp Provider or relevant authorities.
Monitoring rules and thresholds shall be reviewed periodically and adjusted in response to observed risk, typology changes, regulatory requirements, fraud trends and Programme performance.
Where the rule relates to Avenia's regulatory AML/CFT obligations, the applicable parameters shall be established or approved by Avenia.
12. Alert Investigation and Escalation
An automated monitoring alert is an indicator requiring assessment and does not by itself constitute a determination that suspicious activity has occurred.
Paymesh Compliance shall review alerts generated within Paymesh systems and collect relevant information available through the Programme.
An escalation to Avenia should contain sufficient information to permit regulatory analysis, including where available:
- customer identification information;
- KYC and verification results;
- transaction history;
- relevant card-transaction information;
- transaction amount and timestamps;
- risk-monitoring results;
- device and IP information;
- linked-account information;
- relevant wallet identifiers or Avenia transaction references;
- reason for escalation;
- supporting documents;
- prior alerts; and
- any material findings from Paymesh's review.
Avenia retains responsibility for the final regulatory assessment of suspicious activity relating to the regulated virtual asset service.
13. Suspicious Activity and Regulatory Reporting
Paymesh personnel must immediately escalate any activity that they know, suspect or have reasonable grounds to consider potentially connected with money laundering, terrorist financing, sanctions evasion or other material financial crime.
Paymesh shall not represent that it has completed the regulated suspicious-transaction determination on behalf of Avenia merely because Paymesh has generated, reviewed or escalated an alert.
Avenia remains responsible for suspicious-transaction analysis and regulatory reporting arising from its status as the VASP.
Where Avenia determines that a report to a competent authority is required, Paymesh shall provide all relevant records and assistance reasonably required to support that filing.
Nothing in this allocation prevents Paymesh from complying with any direct reporting obligation that may independently apply to Paymesh under applicable law.
Employees must not disclose to the customer or an unauthorized third party that the customer is the subject of a suspicious-activity review, escalation or regulatory report where such disclosure is prohibited.
14. Transaction Holds, Rejections and Restrictions
Paymesh may stop or hold progression of a transaction through its technology where:
- Paymesh fraud controls have triggered;
- required KYC or authentication has failed;
- transaction information is incomplete;
- the transaction violates Paymesh security or operational limits;
- an Avenia-approved compliance parameter has triggered;
- Avenia has instructed Paymesh to restrict the customer or transaction; or
- continued processing would create a material legal, financial-crime or security risk.
A Paymesh technological hold is not the same as a final regulatory determination concerning the underlying virtual-asset service.
Avenia retains ultimate authority to approve, reject, suspend or decline execution of the regulated virtual-asset transaction and may override or modify the regulatory criteria applied through Paymesh systems.
Paymesh shall implement such instructions promptly.
15. Prohibited Activity
The Programme must not knowingly be used for:
- money laundering;
- terrorist financing;
- proliferation financing;
- sanctions evasion;
- fraud or use of stolen payment credentials;
- transactions on behalf of undisclosed third parties;
- identity theft or synthetic identity;
- circumvention of transaction or customer limits;
- anonymous customer activity;
- use of fictitious identities;
- merchant settlement disguised as wallet loading;
- P2P transfers within the wallet-loading transaction flow;
- cash withdrawal;
- transfers to unrelated third-party wallets through the Programme;
- transactions associated with prohibited or illegal activity; or
- any activity prohibited under Paymesh's, Avenia's, the Ramp Provider's or applicable acquiring partner's approved risk framework.
Paymesh may apply additional restrictions where required by card-network rules, acquiring requirements or its internal risk appetite.
16. Ongoing Customer Monitoring
CDD is not limited to onboarding.
Paymesh shall maintain ongoing controls designed to identify material changes in:
- customer information;
- transactional behaviour;
- device characteristics;
- payment-card usage;
- geography;
- sanctions or PEP status;
- fraud-risk indicators; and
- other information relevant to customer risk.
Customer information shall be refreshed periodically according to risk and whenever a material event makes existing information unreliable or outdated.
Higher-risk customers may be subject to more frequent review.
Avenia may require Paymesh to obtain additional information or re-perform customer verification where necessary to support Avenia's regulatory obligations.
17. Source of Funds and Source of Wealth
Paymesh may obtain source-of-funds information where warranted by customer or transaction risk.
Evidence may include, where proportionate:
- employment income;
- business income;
- savings;
- investment proceeds;
- sale of assets;
- inheritance;
- bank records; or
- other credible evidence explaining the origin of funds used through the Programme.
Source-of-wealth review may be undertaken in higher-risk cases, including where expected transaction activity is materially disproportionate to known customer circumstances.
Information obtained by Paymesh shall be made available to Avenia where relevant to Avenia's regulatory assessment.
18. Reconciliation and Audit Trail
Paymesh shall maintain transaction-level reconciliation sufficient to correlate the material stages of the Programme, including, where available, the customer order, KYC status, card authorization, risk decision, acquiring reference, Avenia reference, stablecoin-credit status and reconciliation status.
Paymesh reconciliation is a technology and information-control function.
Paymesh reconciliation personnel and systems do not have authority to alter Avenia custodial positions, move virtual assets, reverse blockchain transfers or independently determine the legal completion of a virtual-asset transaction.
Material inconsistencies shall be investigated and referred to Avenia or the relevant payment participant where appropriate.
19. Record Keeping
Paymesh shall retain adequate records to demonstrate the operation of controls under this Policy.
Records shall include, where applicable:
- customer identification information;
- KYC documentation;
- biometric-verification results;
- screening results;
- risk scores and customer classifications;
- transaction records;
- fraud-monitoring results;
- transaction-monitoring alerts;
- investigations;
- EDD documentation;
- escalation records;
- decisions and approvals;
- communications with Avenia concerning AML/CFT matters;
- relevant system logs; and
- evidence of compliance-control configuration and changes.
Records shall be retained securely for the period required under applicable law, contractual obligations and the regulatory framework approved by Avenia.
Records must be retrievable within a reasonable period for audit, regulatory review, investigation or law-enforcement requests lawfully transmitted through the appropriate channel.
20. Data Protection, Confidentiality and Security
AML/CFT information shall be treated as confidential information and shall only be accessible to personnel or service providers with an appropriate business, legal or regulatory need.
Paymesh shall maintain appropriate technical and organizational safeguards to protect customer and transactional information against unauthorized access, alteration, loss or disclosure.
Data exchanged with Avenia and other approved providers shall use secure integration methods and appropriate access controls.
Paymesh shall support Avenia in providing information, documents and system access required for regulatory supervision of services performed through Paymesh.
21. Third-Party Service Providers
Paymesh may use specialist providers to perform components of the compliance and risk-control framework.
Use of a third-party provider does not remove Paymesh's responsibility for ensuring that the technology and operational controls delegated by Avenia are correctly implemented within Paymesh systems.
Paymesh shall perform proportionate due diligence and ongoing oversight over material third parties supporting compliance functions.
22. Avenia Oversight of Paymesh
Paymesh acknowledges that, where it acts as an RSP to Avenia, Avenia must maintain oversight of the relevant services performed by Paymesh.
Paymesh shall therefore reasonably cooperate with:
- Avenia due diligence;
- periodic compliance reviews;
- information requests;
- control testing;
- access required for regulatory purposes;
- remediation plans;
- business-continuity assessment; and
- regulatory or independent audit requests applicable to the delegated services.
Paymesh shall promptly inform Avenia of a material compliance, systems, fraud, data or operational event that could affect the regulated services provided by Avenia.
23. Regulatory Status Monitoring
Because the Programme relies on Avenia being legally entitled to provide the applicable regulated virtual-asset services, Paymesh Compliance shall maintain reasonable oversight of Avenia's relevant regulatory status.
Paymesh shall obtain appropriate evidence concerning Avenia's continued regulatory entitlement and shall require notification of any material restriction, regulatory determination, authorization issue or other event that could affect Avenia's ability to provide the services required by the Programme.
Any material change in Avenia's regulatory status shall be escalated to Paymesh senior management and legal counsel and may require suspension or modification of the Programme.
24. Training
Relevant Paymesh personnel shall receive AML/CFT and financial-crime training appropriate to their responsibilities.
Training shall address, as applicable:
- money laundering and terrorist-financing risks;
- virtual-asset risk;
- card-funded crypto-ramp typologies;
- customer due diligence;
- sanctions;
- PEPs;
- fraud;
- account takeover;
- source-of-funds review;
- transaction-monitoring alerts;
- internal escalation;
- confidentiality;
- prohibition on tipping off; and
- the respective responsibilities of Paymesh and Avenia.
Training shall be provided at onboarding and periodically thereafter, with additional targeted training following material regulatory or operational changes.
25. Employee Responsibilities
All employees and contractors involved in the Programme are responsible for complying with this Policy.
No employee may bypass, disable or intentionally circumvent an AML/CFT, sanctions, KYC, fraud or transaction-monitoring control without documented authorization under the applicable change-management or exception process.
Personnel must escalate concerns promptly even where automated systems have not generated an alert.
Retaliation against a person who raises a financial-crime concern in good faith is prohibited.
26. Quality Assurance and Testing
Paymesh shall periodically test the effectiveness of controls implemented under this Policy.
Testing may include:
- sampling of customer files;
- KYC quality review;
- biometric-control review;
- sanctions-screening testing;
- alert disposition review;
- transaction-monitoring effectiveness;
- fraud-rule performance;
- system-access testing;
- reconciliation testing;
- escalation timeliness; and
- confirmation that Avenia-approved parameters are correctly implemented.
Material deficiencies shall be documented, assigned an owner and remediated within an appropriate timeframe.
27. Change Management
Material changes to AML/CFT systems, rules, thresholds, customer eligibility or transaction controls must be subject to controlled implementation.
Where a change concerns regulatory AML/CFT criteria belonging to Avenia, it shall not be implemented as a Paymesh unilateral regulatory determination.
The relevant parameter must be established, approved or otherwise authorized by Avenia.
Avenia must retain the technical or procedural ability to modify, suspend or override such regulatory parameters.
28. Governance and Reporting
The Paymesh AML Officer shall oversee the implementation of this Policy within Paymesh.
Management information should periodically address:
- onboarding volumes;
- KYC rejection rates;
- EDD volumes;
- sanctions and PEP alerts;
- transaction-monitoring alerts;
- fraud indicators;
- escalations to Avenia;
- restricted or terminated accounts;
- significant incidents;
- material control deficiencies;
- rule changes; and
- relevant regulatory or typology developments.
Material matters shall be escalated to senior management promptly.
29. Separation of Paymesh and Avenia Regulatory Responsibilities
For avoidance of doubt, the following allocation shall apply to the Programme.
| Function | Paymesh | Avenia |
|---|---|---|
| Customer interface | Operates technology and communications | Regulatory oversight |
| KYC collection | Performs | Establishes/approves relevant regulatory framework |
| Identity/biometric verification | Performs through approved technology | May review, reject or require further verification |
| Customer risk scoring | Applies approved controls | Establishes/approves regulatory parameters and retains override |
| Fraud monitoring | Performs | Receives relevant escalations |
| Transaction monitoring | Performs first-line technology monitoring | Retains ultimate AML/CFT regulatory assessment |
| Operational transaction hold | May apply | May require or override regulatory restriction |
| Suspicious-activity identification | Detects and escalates | Performs final regulated suspicious-transaction analysis |
| Regulatory reporting | Provides supporting information | Responsible as VASP, subject to applicable law |
| Regulatory blocking/restrictions | Implements instructions and applicable system controls | Makes final regulatory determination |
| Card transaction orchestration | Performs technology function | Not applicable except where linked to VASP decision |
| Stablecoin sale/intermediation | Does not perform | Performs or arranges as regulated provider |
| Stablecoin liquidity | Does not provide | Avenia or another legally qualified provider |
| Wallet custody | No | Yes |
| Private-key control | No | Avenia/custody infrastructure |
| Blockchain execution | No | Avenia or approved provider |
| On-chain AML analysis | Receives relevant results | Responsible for custody/on-chain controls |
| Client fiat custody | No | Avenia and/or appropriately authorized institution |
| Legal settlement of crypto transaction | Does not determine | Avenia |
| AML/CFT regulatory policy | Implements applicable controls | Retains regulatory responsibility for VASP service |
This allocation shall be reflected consistently in Paymesh systems, operational procedures, contracts, customer disclosures and staff training.
30. Programme-Specific Control Principle
The compliance architecture of the Programme shall preserve a complete and auditable relationship between:
- one verified customer;
- one authenticated customer account;
- one authorized payment transaction;
- one associated custodial wallet; and
- one corresponding stablecoin acquisition.
Any material break or inconsistency in that relationship shall be treated as a risk indicator requiring rejection, review or escalation.
Paymesh systems shall not be designed or operated to facilitate the use of the Programme as a mechanism for undisclosed third-party payments, merchant settlement, P2P transfers or delivery of purchased stablecoins to unrelated third-party wallets.
31. Policy Review
This Policy shall be reviewed at least annually and sooner where there is:
- a material amendment to applicable Brazilian regulation;
- a change to BCB requirements applicable to Avenia or RSPs;
- a material change in Avenia's authorization status;
- a material change in the Paymesh/Avenia operating model;
- addition of a new stablecoin or virtual-asset service;
- change in the card-acquiring or Visa Ramp Provider structure;
- introduction of materially different customer categories;
- material change to transaction flows;
- significant AML/CFT or fraud incidents; or
- a material finding arising from audit, legal review or regulatory assessment.
Any change that would cause Paymesh to hold customer fiat or virtual assets, control private keys, independently provide virtual-asset liquidity, independently intermediate the purchase or sale of virtual assets, execute blockchain transactions or exercise final regulatory control over regulated virtual-asset transactions must be referred to Legal and Compliance for regulatory reassessment before implementation.
Approval
This Policy has been adopted by Paymesh LTDA as the governing AML/CFT and financial-crime policy applicable to the Paymesh Cardholder Stablecoin Wallet-Loading Programme in Brazil.