Sandbox environment: no real transactions are processed.

Public document

Compliance and AML/CFT Policy

This Policy describes internal, contractual, and operational controls adopted by Raims for registration, risk review, anti-money laundering and counter-terrorism financing, fraud prevention, operational monitoring, and cooperation with regulated partners and competent authorities when applicable. Raims' approach values context, evidence, and proportionality to protect the payment ecosystem without turning isolated signals into unnecessary blocks against legitimate businesses. It does not characterize Raims as a bank, financial institution, or payment institution authorized by the Central Bank of Brazil.

1

Purpose and scope

Raims maintains internal, contractual, and operational compliance, AML/CFT, fraud prevention, and operational security controls to reduce the risk of misuse of the platform and protect business customers, payers, partners, and the payment ecosystem without creating unnecessary blocks that harm legitimate businesses.

This Policy applies to Raims, its administrators, employees, service providers, business customers, authorized users, partners, suppliers, and other parties that interact with the platform, according to context, contracts, regulated partner rules, and legal or regulatory obligations applicable to each party.

2

Governance and risk-based approach

Raims adopts a risk-based approach to define internal and operational controls that are proportional to size, segment, registration profile, operational behavior, transaction history, intended platform use, and contractual requirements from regulated partners.

Authorized teams may work together to review registrations, monitor alerts, request evidence, document decisions, and maintain a culture of prevention against illicit activity, fraud, and misuse.

  • Classify accounts, operations, segments, and risk signals proportionally to the level of exposure identified.
  • Record relevant evidence, decisions, and justifications for audit, support, investigation, and defense of rights.
  • Apply risk-based internal diligence (KYE, Know Your Employee) to employees and service providers with privileged access to sensitive data, production, payment systems, critical code, or AML/CFT controls, observing legal basis, necessity, transparency, and non-discrimination.
  • Periodically review policies, procedures, controls, and review criteria according to product, legal, and risk-profile changes.
3

Registration, KYC, KYB, and diligence

The registration process may involve collecting and validating company data, representatives, beneficial owners, contacts, documents, economic activity, website, products, expected volume, commercial evidence, and other information required for review.

Raims may request registration updates, additional documents, or clarifications at any time, especially when there are inconsistencies, activity changes, relevant volume increases, ownership changes, risk indications, or contractual or operational requirements from a regulated financial partner.

  • Assess the existence, regularity, segment, declared activity, and compatibility of the business customer with the intended operation.
  • Validate legal representatives, authorized responsible persons, beneficial owners, and information required for identification and security.
  • Check, according to risk, legal basis, contract, and operational applicability, sanctions, PEP, and integrity lists and databases, including United Nations Security Council (UNSC/UN) sanctions, official Politically Exposed Persons (PEP) databases, CEIS/CNEP, and, when required by a regulated partner, international exposure, or risk appetite, OFAC lists and other relevant public or private databases.
  • Apply enhanced diligence to segments, operations, or profiles with higher risk, legal restrictions, higher fraud exposure, or additional documentation requirements.
4

Operational scope of accounts and APIs

Raims accounts and APIs are intended for the own commercial operations of each approved business customer. Charges must arise from products or services sold or provided by that business, with identification, documentation, and consistency among the declared activity, payers, volume, and purpose of the operation.

Use of Raims proprietary APIs does not authorize financial intermediation on behalf of third parties, the creation of account structures for the contracting business's customers, or the offering of the underlying regulated infrastructure as the business customer's own product.

  • Do not receive, hold, pool, or move funds belonging to third parties or received for the benefit of third parties in the business customer's account.
  • Do not open or offer payment accounts, subaccounts, wallets, individualized balances, or equivalent means to consumers, merchants, service providers, partners, or users of the business customer.
  • Do not pool sales proceeds from sellers, merchants, or service providers for later payout, or use the Raims account as a pooled or pass-through account.
  • Do not resell, sublicense, assign, or white-label Raims features as the business customer's own financial service.
5

Monitoring and review of atypical situations

Raims may monitor registration data, transaction behavior, charges, disputes, chargebacks, refunds, balances, limits, activity records, technical signals, and other available information for internal, contractual, antifraud, AML/CFT controls and to meet regulated partner requirements.

Raims does not treat risk as a crude trigger based only on balance, volume, revenue, or account age. Automated alerts should support contextual review, objective evidence, and proportionality to the impact of the measure.

For security reasons, Raims does not disclose internal parameters, sensitive rules, risk weights, internal lists, blocking criteria, or details that could facilitate evasion of controls.

  • Relevant changes in volume, frequency, average value, recurrence, concentration, disputes, refunds, or payer behavior may trigger internal alerts.
  • Alerts, analytical models, and artificial intelligence technologies may support review prioritization, and atypical or higher-impact situations may be reviewed by humans with requests for additional information, commercial evidence, or operational validation.
  • New accounts or accounts without sufficient history may receive initial limits, enhanced monitoring, and more frequent review until they demonstrate consistent and healthy operation.
  • Legitimate operations from high-volume customers, fast-growing businesses, or automatic withdrawal flows may require contextual monitoring, not automatic blocking based on a single indicator.
6

Prohibited or restricted activities

Raims must not be used for illegal, fraudulent, deceptive, or restricted activities, or any activity incompatible with laws, sanctions, third-party rights, applicable platform rules, financial partner obligations, or the risk appetite defined by Raims.

  • Perform, facilitate, or conceal money laundering, terrorism financing, corruption, control evasion, scams, pyramid schemes, illegal sales, or operations without required authorization.
  • Act on behalf of people, entities, countries, products, segments, or operations subject to sanctions, blocks, restricted lists, or applicable prohibitions, including determinations of the United Nations Security Council (UNSC/UN), designations by its sanctions committees, and other applicable national or international lists under the platform's internal policy or a regulated partner requirement.
  • Create false charges, simulate transactions, manipulate receipts, misuse identity, bypass limits, cause abusive disputes, or exploit security failures.
7

Measures, review, blocking, or suspension

When there is an indication of risk, inconsistency, fraud, policy breach, applicable legal obligation, authority order, contractual or operational requirement from a regulated partner, or need to protect the platform, Raims may adopt proportionate and documented technical measures over access, features, integrations, charges, and operational flow, and may notify or escalate the case to the BaaS/IP partner responsible for regulated services.

Preventive measures such as operational limits, feature restrictions, withdrawal review, operational reserve or hold labels in the dashboard, and escalation are adopted by Raims in proportion to the identified risk, aiming to protect the payment ecosystem against structured fraud and pass-through accounts. Blocks, holds, returns, refunds, reserves, or restrictions over regulated funds will follow the rules, decisions, procedures, or requirements of the BaaS/IP partner, authorities, or applicable contracts, and are not applied to legitimate revenue variation or consistent commercial operations of homologated partners. When a balance hold or restriction arises from an applicable procedure, the operational window may observe the period consolidated in the Platform Terms of Use, currently up to 180 (one hundred eighty) days, to cover disputes, refunds, reimbursements, contingencies, or rights defense.

Ordinary suspensions or terminations of Platform access or proprietary features, when they do not involve urgency, will be communicated with at least 1 month of prior notice. Immediate measures may be adopted without prior notice in cases of fraud, relevant risk, policy breach, legal obligation, or platform protection. Termination of a payment account or restriction over regulated funds will follow the rule, decision, or procedure of the BaaS/IP partner, competent authority, or applicable contract.

  • Request documents, receipts, contracts, invoices, proof of delivery, commercial justifications, registration review, or access revalidation.
  • Apply operational limits, reserve or hold labels in the dashboard, feature restrictions, withdrawal review, enhanced monitoring, or escalation to the BaaS/IP partner when justified by risk.
  • Suspend, refuse, terminate, or limit Platform access, charge, integration, user, proprietary operation, or technical feature when justified by risk.
  • Notify or escalate cases to regulated financial partners, authorities, auditors, or operationally responsible parties when applicable.
8

Records, retention, and cooperation

Raims may retain registration, operational, financial, and technical records, documents, evidence, logs, and audit trails for as long as necessary to comply with legal and contractual obligations, regulated partner requirements, antifraud controls, accounting and tax duties, and rights defense.

Business customers must cooperate with reasonable compliance, security, audit, dispute, chargeback, reconciliation, investigation, or regulated financial partner and competent authority requests when applicable.

When a human or otherwise authorized review confirms a relevant indication of money laundering, terrorism financing, structured fraud, or an incompatible operation, Raims may compile a sanitized dossier containing the minimum case data, transaction history, available evidence, and review decision and send it to the regulated financial partner within 24 hours after human confirmation for assessment, contractual measures, and possible reporting to COAF/SISCOAF, when applicable. Regulatory reporting will be made by the applicable legally responsible or regulated party, or directly by Raims only when Raims has its own obligation.

9

Training, communication, and updates

Raims may maintain guidance, training, internal communications, and reporting flows so employees and authorized teams can recognize signs of risk, fraud, money laundering, terrorism financing, and other misuse within the platform's internal, contractual, and operational controls.

Suspected platform misuse, fraud against payers, false charges, or operational abuse may be reported through Raims official service and support channels or by email to compliance@raims.com. Applicable reports will be routed to Compliance/Risk, security, or other authorized responsible parties.

This Policy may be updated to reflect legal, regulatory, contractual, operational, or product changes. When a material change affects rights, obligations, or relevant controls applicable to business customers, Raims will notify active businesses through their registered email, a dashboard notice, or another reasonable channel, with reasonable advance notice where applicable. Merely editorial changes, corrections, or clarifications without a material change may be made by updating the version and date without individual notice. Urgent changes required by law, an authority, security, or a regulated partner may take effect immediately, with notice as soon as reasonably possible. Questions about compliance, AML/CFT, KYB/KYC, risk, or operational documentation may be sent to compliance@raims.com.