AML/CFT/CPF POLICY
Public version for tranza.io
Last updated: 5 October 2026
1. Purpose and Scope
This public Policy outlines the principles adopted by TRANZA L.L.C-FZ (“TRANZA” or the “Company”) to prevent money laundering, terrorist financing and the financing of proliferation of weapons of mass destruction (AML/CFT/CPF). The Company seeks to prevent the misuse of its payment, technology and settlement-information infrastructure for unlawful purposes.
This Policy is a summary of the Company’s internal approach. Detailed procedures, risk-assessment criteria and allocation of responsibilities are set out in TRANZA’s internal documents, taking into account its actual operating model, applicable legal requirements and the arrangements with servicing banks and payment partners.
2. The Company’s Status and Role in Settlement
TRANZA is incorporated in Meydan Free Zone, Dubai, UAE, and holds Business Licence No. 2649230.01, which includes the activity Payment Services Provider (code 8291.98). The Company provides legal-entity clients with technology, operational and settlement-information infrastructure to support payment acceptance, the exchange of payment information, reconciliation, reporting and settlement coordination.
A Meydan Free Zone business licence does not, by itself, evidence separate authorisation from the Central Bank of the UAE to carry on regulated financial services. Payment-chain functions requiring special authorisation are performed by the relevant banks and payment partners within their permissions, or subject to the necessary authorisations. The application of specific requirements is assessed separately for each operating model.
3. Risk-Based Approach
TRANZA assesses AML/CFT/CPF, sanctions, fraud and related risks in light of each client’s ownership and control, goods and services, jurisdictions, business reputation, expected volumes, payment methods, settlement beneficiaries and the roles of payment-chain participants. The depth of due diligence and subsequent controls depend on the level of risk.
The Company provides for periodic assessment of its business-wide risks and review of client profiles when circumstances change. Higher-risk relationships may require additional checks, limits, special terms and management approval. Unacceptable risk is grounds for declining onboarding or terminating services.
4. Merchant Due Diligence (KYB/CDD)
Before processing live payments, TRANZA conducts the minimum necessary KYB/CDD checks on its legal-entity clients and merchants. Depending on risk, these checks cover corporate and licensing documents, ownership and control, ultimate beneficial owners, directors and authorised representatives, business model, websites and sales channels, goods and services, expected volumes and settlement arrangements. Limited technical testing without live payments may be permitted only after preliminary screening for critical risks.
Customers paying for a merchant’s goods or services do not become TRANZA clients merely by making a payment. Information about payers and transactions that is available to TRANZA may be considered in checks depending on the payment model, assessed risk and applicable requirements.
5. Enhanced Checks and Business Categories
Where a high risk rating or significant red flags are identified, TRANZA applies enhanced due diligence (EDD), including additional information on beneficial owners, source of funds and, where necessary, source of wealth, the economic purpose of transactions and evidence of genuine business operations. Special attention is paid to politically exposed persons (PEPs) and related persons, complex ownership structures, adverse media and unusual settlement models.
The Company does not service unlawful activity, fraud schemes, evasion of applicable sanctions, fictitious structures or transactions lacking a clear economic purpose. Certain lawful but sensitive activities may be considered only following additional due diligence and approval, including approval by a bank or payment partner where required.
6. Sanctions Controls
TRANZA takes account of applicable targeted financial sanctions and other mandatory restrictions, including the UAE and UN Security Council lists. Depending on geography, currency, payment route, risk and partner requirements, the Company may also consider OFAC, EU, UK/OFSI, SECO and other relevant sanctions regimes.
Controls extend to merchants and connected persons, beneficial owners, management, settlement beneficiaries and, within the limits of available information and applicable requirements, other transaction participants. If a potential match is identified, TRANZA assesses it, records its decision and applies measures available within its authority; any holding or blocking of funds may be carried out through the relevant bank or payment partner.
7. Transaction Review and Internal Escalation
Within its technical and contractual role, the Company conducts ongoing risk-based monitoring of payment and settlement information available to it. Attention may be given to discrepancies with declared business activity, unexplained increases in volumes, unusual payment structures, frequent refunds and complaints, changes in settlement beneficiaries and other risk indicators.
Unusual circumstances and potential violations are escalated internally to the person coordinating AML/CFT/CPF functions and/or management. Following review, the Company may request documentation, reassess risk, restrict or suspend services within its authority, initiate action through a payment partner or terminate a relationship. Applicable confidentiality requirements and restrictions on improper disclosure of information about investigations (tipping-off) are observed.
8. Cooperation with Banks and Payment Partners
Banks, acquirers, payment providers and other payment-chain participants perform their own payment processing, control and reporting functions in accordance with their regulatory status and applicable requirements. TRANZA works with them on merchant due diligence, payment purposes, the economic basis of transactions, refunds, sanctions matches and suspicious activity.
The Company provides information and explanations available to it, subject to applicable legal and contractual grounds. Reliance on partner checks and data does not replace TRANZA’s own risk assessment. Direct regulatory reporting obligations are determined by applicable law and each participant’s actual role, not by this public Policy.
9. Record Keeping and Confidentiality
TRANZA retains KYB/CDD and EDD documentation it creates or obtains, results of checks undertaken, payment information available to it and material compliance correspondence. Its baseline internal retention period is at least five years after the end of the business relationship or the relevant transaction, whichever occurs later, unless applicable requirements prescribe a longer period.
Access to data is restricted on a need-to-know basis. Information is shared with banks, payment partners and other authorised recipients only to the extent necessary, subject to confidentiality, data protection and applicable restrictions.
10. Governance and Review
TRANZA’s management retains overall responsibility for organising AML/CFT/CPF controls. Internal responsibility for coordinating checks, considering elevated risks and liaising with banks is assigned in accordance with the Company’s organisational structure. This does not constitute a representation that any officer has been separately appointed or registered with a regulator.
Internal procedures provide for training of relevant employees and contractors before access is granted and at least annually. The Policy, business-wide risk assessment and key controls are reviewed at least once a year and following material changes to the operating model or applicable requirements.
11. Contact Information
For enquiries concerning this Policy: info@tranza.io TRANZA L.L.C-FZ | Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.