AML, CTF and Sanctions Policy

Anti-Money Laundering Policy

Effective from 12 August 2026 · Approved by the Board · Reviewed annually

The compliance programme Cashcows Labs Ltd. operates to prevent money laundering, terrorist financing and sanctions evasion across the platform, the treasury and the token.

Issued by
Cashcows Labs Ltd.
Effective date
12 August 2026
Framework
PCMLTFA · FINTRAC · FATF
Compliance contact
support@cash-cows.com

Contents

Twenty sections setting out our obligations, our controls, and what we expect of every customer. This document is approved by the Board and reviewed at least annually.

No.SectionNo.Section
01Purpose and Commitment11Sanctions Compliance
02Scope12Blockchain Analytics and Wallet Screening
03Legal and Regulatory Framework13Ongoing Monitoring
04Governance and Accountability14Reporting Obligations
05The Risk-Based Approach15Tipping Off and Confidentiality
06Enterprise Risk Assessment16Record Keeping
07Customer Due Diligence17Third Parties and Outsourcing
08Enhanced Due Diligence18Training and Awareness
09Politically Exposed Persons19Independent Testing and Review
10Source of Funds and Source of Wealth20Prohibited Customers and Enforcement

1. Purpose and Commitment

1.1 Cashcows Labs Ltd. ("CashCows") is committed to preventing its platform, its treasury and the $CASHCOWS token from being used to launder the proceeds of crime, to finance terrorism, to evade sanctions, or to conceal the origin of assets.

1.2 This Policy sets out the programme by which we meet that commitment. It applies to every director, officer, employee, contractor and agent of CashCows, and it establishes the standards every customer must satisfy.

1.3 CashCows takes a zero-tolerance position on financial crime. We would rather decline business, close an account or forgo revenue than accept a customer or a transaction we cannot satisfy ourselves about. Commercial targets never override a compliance decision.

1.4 This Policy is approved by the Board of Directors, owned by the Compliance Officer, and reviewed at least annually and whenever the law, our products or our risk profile materially change.

2. Scope

2.1 This Policy applies to all business lines and activities, including: the sale of Bufala Interests; the receipt of fiat and digital-asset payments; the payment of Platform Distributions; the operation of the secondary market interface; the provisioning of wallets; treasury operations including buybacks; and any listing, liquidity or partnership arrangement involving $CASHCOWS.

2.2 It applies to every customer irrespective of jurisdiction, and to every counterparty, supplier, distributor, introducer, market maker and partner with whom we transact.

2.3 Where a jurisdiction in which we operate imposes a stricter requirement than this Policy, the stricter requirement applies. This Policy sets a floor, not a ceiling.

3. Legal and Regulatory Framework

3.1 CashCows is incorporated and administered in Ontario, Canada. Our programme is built to the standard of the Canadian regime and to international norms.

InstrumentRelevance
Proceeds of Crime (Money Laundering) and Terrorist Financing ActThe principal Canadian statute. Establishes customer identification, record-keeping, reporting and compliance-programme obligations.
PCMLTFA RegulationsPrescribe identification methods, reporting thresholds and record content, including for dealers in virtual currency.
FINTRAC guidanceCanada's financial intelligence unit. We follow its published guidance on virtual currency, verification methods and suspicious transaction reporting.
Criminal Code of CanadaMoney laundering and terrorist financing offences, and terrorist entity listings.
Special Economic Measures Act; United Nations Act; Justice for Victims of Corrupt Foreign Officials ActThe Canadian sanctions regime, including country, sectoral and person-specific measures.
FATF RecommendationsThe international standard, including the Travel Rule for virtual asset transfers and guidance on virtual asset service providers.
Foreign regimesWhere we serve customers in other territories we observe the applicable local requirements, and we screen against United States, United Kingdom, European Union and United Nations sanctions lists.

3.2 Where our activities require registration as a money services business or as a dealer in virtual currency, CashCows will register with the competent authority and maintain that registration in good standing before conducting the activity in question.

4. Governance and Accountability

4.1 The Board of Directors owns this Policy. It approves it, receives compliance reporting at least twice a year, and is accountable for the adequacy of the programme.

4.2 The Compliance Officer is appointed by the Board, holds sufficient seniority, authority and independence to act, and has direct access to the Board without management filtering. The Compliance Officer is responsible for maintaining this Policy, running the risk assessment, overseeing due diligence and monitoring, deciding on escalations, filing regulatory reports, delivering training and commissioning independent review.

4.3 The Compliance Officer has unilateral authority to refuse a customer, freeze an account, block a transaction, or terminate a relationship. That decision cannot be overruled by any commercial function.

4.4 Operational staff form the first line of defence and must escalate concerns immediately. Compliance forms the second line. Independent testing under section 19 forms the third.

4.5 Every employee and contractor must read this Policy on joining and annually thereafter, and must confirm in writing that they have done so.

5. The Risk-Based Approach

5.1 We allocate compliance effort in proportion to risk. Higher-risk customers, products, channels and geographies receive deeper scrutiny, more evidence and more frequent review; lower-risk relationships receive proportionate treatment.

5.2 Every customer is assigned a risk rating of low, medium or high at onboarding, and that rating is refreshed on a trigger event and on a periodic cycle.

RatingReview cycleTreatment
LowEvery 36 monthsStandard due diligence and automated monitoring
MediumEvery 24 monthsStandard due diligence with periodic manual review
HighEvery 12 monthsEnhanced due diligence, senior approval, and heightened monitoring

5.3 Factors raising a rating include: residence or nationality connected to a higher-risk jurisdiction; status as a politically exposed person or a close associate; complex or opaque ownership structures; use of privacy-enhancing tools or mixing services; funds originating from high-risk counterparties; unusual transaction size or velocity; adverse media; and reluctance to provide requested information.

6. Enterprise Risk Assessment

6.1 CashCows maintains a documented enterprise-wide risk assessment covering products and services, customer types, delivery channels, geographic exposure, and new technology.

6.2 The assessment identifies inherent risk, records the controls applied, and states residual risk. Where residual risk exceeds our appetite, the Compliance Officer must implement additional controls or withdraw from the activity.

6.3 The assessment addresses risks specific to our model, including: the location of the herd in the Bolivarian Republic of Venezuela, a jurisdiction of elevated corruption, sanctions and currency-control risk; the receipt of digital assets from unknown origin; pseudonymous wallet activity; the potential for the secondary market to be used to transfer value between parties; and reliance on third-party wallet and payment infrastructure.

6.4 The assessment is reviewed at least annually, and whenever we launch a product, enter a market, change a distribution channel, or experience a material incident.

7. Customer Due Diligence

7.1 We do not permit anonymous accounts, accounts in fictitious names, or accounts opened by a person who refuses to identify themselves.

7.2 Before a customer may transact — and in any event before we pay a distribution, permit a secondary market trade, or process a withdrawal — we identify the customer and verify that identity using reliable, independent source material.

7.3 For a natural person we collect and verify full legal name, date of birth, residential address and nationality, using a valid government-issued photographic identity document together with a liveness or biometric check confirming the document belongs to the person presenting it.

7.4 For a legal entity we collect and verify the registered name, number, registered and operating addresses, constitutional documents, the nature of the business, the names of directors and senior officers, and evidence of the authority of the person acting. We identify and verify every beneficial owner holding twenty-five per cent (25%) or more, directly or indirectly, and where no such owner exists we identify the senior managing official.

7.5 We record the intended purpose and nature of the relationship, and the expected pattern of activity, so that deviation can be recognised later.

7.6 Verification may be performed by a qualified third-party provider on our behalf. We remain fully responsible for the outcome and retain the underlying records.

7.7 Where due diligence cannot be completed satisfactorily, we will not open the account; where an existing relationship is affected, we will restrict it and consider termination and a suspicious transaction report.

8. Enhanced Due Diligence

8.1 Enhanced due diligence is mandatory for every high-risk relationship. It requires the additional measures set out below and written approval from the Compliance Officer before onboarding or continuation.

  • Additional identity evidence and independent corroboration of the information provided.
  • Documentary establishment of source of funds and source of wealth under section 10.
  • Adverse media, litigation and regulatory-history screening.
  • Verification of the ownership and control structure to ultimate beneficial owner in entity cases.
  • A documented rationale for the relationship, retained on file.
  • Heightened transaction monitoring with lowered alert thresholds.
  • Annual refresh of the full customer file.

8.2 Triggers include: any politically exposed person or close associate; connection to a jurisdiction subject to a FATF call for action or increased monitoring; funds traced to a sanctioned, darknet, mixing or high-risk service; unexplained third-party funding; and any relationship the Compliance Officer designates as high risk.

9. Politically Exposed Persons

9.1 A politically exposed person is an individual who holds or has held a prominent public function, together with their family members and close associates. We screen every customer against politically-exposed-person data at onboarding and on an ongoing basis.

9.2 Where a customer is identified as a politically exposed person, a head of an international organisation, or a family member or close associate of either, we apply enhanced due diligence, take reasonable measures to establish source of wealth and source of funds, and obtain senior management approval before establishing or continuing the relationship.

9.3 Politically exposed person status is not itself a reason to refuse business. It is a reason to understand the relationship properly and to monitor it more closely for the duration.

10. Source of Funds and Source of Wealth

10.1 Source of funds means the origin of the specific money or digital assets used in a transaction. Source of wealth means how the customer's overall wealth was accumulated. They are distinct and both may be required.

10.2 We may request source-of-funds and source-of-wealth evidence at any time and at our discretion, including at onboarding, on reaching a threshold, on a risk trigger, on periodic refresh, or where a regulator or financial institution requires it.

10.3 Acceptable evidence includes employment income documentation, audited financial statements, tax filings, sale-of-asset or business-disposal documentation, inheritance or gift documentation, and verifiable blockchain provenance for digital assets.

10.4 Customers must warrant that all funds and digital assets they use are lawfully derived, are beneficially owned by them, and are not the proceeds of crime. Where a satisfactory explanation is not provided, we will decline or restrict the relationship and will consider whether a suspicious transaction report is required.

11. Sanctions Compliance

11.1 CashCows will not establish or maintain a relationship with, or process a transaction for, any person who is designated under, or owned or controlled by a person designated under, the sanctions regimes of Canada, the United States, the United Kingdom, the European Union or the United Nations.

11.2 We screen customers, beneficial owners, directors, counterparties and suppliers against consolidated sanctions lists at onboarding, on every material change, and on an ongoing basis as lists are updated. Wallet addresses are screened against designated-address data including the OFAC Specially Designated Nationals list.

11.3 We do not conduct business with, or facilitate transactions involving, comprehensively sanctioned jurisdictions. We maintain and publish a list of restricted jurisdictions, apply geolocation and IP-based controls, and prohibit the use of tools intended to disguise location.

11.4 A confirmed match results in immediate blocking of the account and assets, notification to the competent authority as required, and a prohibition on dealing with the assets except as authorised by that authority. Potential matches are escalated to the Compliance Officer for adjudication within one business day.

11.5 Any attempt to evade sanctions through the platform — including structuring, use of intermediaries, or misrepresentation of location or identity — results in immediate termination and referral to the authorities.

12. Blockchain Analytics and Wallet Screening

12.1 Because value moves on public ledgers, we use blockchain analytics to assess the provenance and destination of digital assets, in addition to conventional customer due diligence.

12.2 Every wallet address linked to an account is screened before use and monitored thereafter. We assess exposure to darknet markets, ransomware, fraud and scam addresses, sanctioned entities, mixing and tumbling services, high-risk exchanges, and services offering anonymity-enhancing features.

12.3 Where exposure exceeds our tolerance, we will decline the deposit, freeze the account, require source-of-funds evidence, and consider a suspicious transaction report. We may refuse to return assets where doing so would breach sanctions or facilitate an offence, and will act on the instruction of the competent authority.

12.4 Where the Travel Rule applies to a transfer, we will obtain, hold and transmit the required originator and beneficiary information to the counterparty institution, and will not execute a transfer where required information is missing and cannot be obtained.

13. Ongoing Monitoring

13.1 Due diligence is not a one-off exercise. We monitor relationships throughout their life to ensure activity remains consistent with what we know of the customer.

13.2 Automated monitoring generates alerts on: transactions inconsistent with the expected profile; rapid movement of value in and out; structuring below thresholds; unusual velocity or frequency; multiple accounts sharing device, address or funding characteristics; secondary market activity suggestive of value transfer rather than genuine trade; and dormancy followed by sudden activity.

13.3 Alerts are triaged by trained analysts within defined service levels, escalated to the Compliance Officer where warranted, and closed with a written rationale that is retained. Every alert outcome is documented, whether or not it results in a report.

13.4 We keep customer information current, and require customers to notify us of changes to identity, address, control or beneficial ownership.

14. Reporting Obligations

14.1 Where we have reasonable grounds to suspect that a transaction, or an attempted transaction, is related to the commission or attempted commission of a money laundering or terrorist financing offence, we will submit a suspicious transaction report to the competent financial intelligence unit. A report is required whether or not the transaction was completed, and no minimum threshold applies.

14.2 We also file the other reports required of us, including large virtual currency and large cash transaction reports at the prescribed thresholds, electronic funds transfer reports where applicable, and terrorist property reports where we know or believe property is owned or controlled by a listed person.

14.3 Reports are prepared by the Compliance Officer or a delegate, filed within the prescribed deadlines, and retained with the supporting analysis.

14.4 Customers are not notified that a report has been made. The submission of a report does not of itself require us to terminate the relationship; that decision is taken separately on the facts.

15. Tipping Off and Confidentiality

15.1 It is a criminal offence to disclose to a customer or any third party that a suspicious transaction report has been or may be made, or that an investigation is contemplated or underway, where that disclosure is likely to prejudice the investigation.

15.2 No director, officer, employee, contractor or agent may make such a disclosure. Where a customer asks why an account has been restricted, staff must confine themselves to the approved response and escalate to the Compliance Officer.

15.3 Compliance records, reports and case files are confidential, access-restricted, and disclosed only to the Compliance Officer, authorised personnel, external counsel, auditors and the competent authorities.

15.4 Staff may raise concerns confidentially and, where they wish, anonymously. CashCows prohibits retaliation of any kind against a person who reports a concern in good faith.

16. Record Keeping

16.1 We maintain complete, accurate and retrievable records of identification and verification material, beneficial ownership determinations, risk assessments and ratings, transaction records, monitoring alerts and their disposition, reports filed, training completion, and independent testing results.

16.2 Records are retained for a minimum of five (5) years from the end of the relationship or the date of the transaction, whichever is later, and longer where another law, an investigation or litigation requires it.

16.3 Records are held securely, protected against unauthorised access and alteration, and are capable of being produced to a competent authority within thirty (30) days of a lawful request.

16.4 Retention under this Policy takes precedence over a deletion request made under our Privacy Policy, as permitted by data protection law.

17. Third Parties and Outsourcing

17.1 We may rely on qualified third parties to perform elements of customer due diligence, including identity verification, screening and blockchain analytics. Reliance does not transfer responsibility. CashCows remains fully accountable.

17.2 Before engaging a provider we assess its regulatory standing, methodology, data sources, coverage, security and business continuity. Engagements are documented in a written agreement requiring immediate access to underlying records, defined service levels, audit rights and prompt notification of failures.

17.3 Provider performance is reviewed at least annually, including sample testing of outcomes.

17.4 Introducers, distributors, affiliates, market makers and partners are subject to due diligence before engagement, must contractually commit to standards equivalent to this Policy, and are terminated where they fail to meet them.

18. Training and Awareness

18.1 Every director, officer, employee and contractor receives anti-money-laundering, counter-terrorist-financing and sanctions training on joining and at least annually thereafter. Training is role-specific, with deeper content for customer-facing, operations, treasury and compliance staff.

18.2 Training covers the law and our obligations, the risks specific to our products and our geographic footprint, red flags in digital-asset and real-world-asset activity, escalation procedures, tipping-off restrictions, and the personal criminal liability that can attach to individuals.

18.3 Completion is recorded and tested. Additional training is delivered when the law changes, when we launch a product, and following any incident or control failure. Failure to complete mandatory training is a disciplinary matter.

19. Independent Testing and Review

19.1 The effectiveness of this programme is tested at least every two (2) years by a party independent of the functions being tested — an internal audit function, or a qualified external firm where no such function exists.

19.2 Testing covers the adequacy of the risk assessment, the operation of due diligence and enhanced due diligence, the calibration and effectiveness of monitoring, the completeness and timeliness of reporting, record keeping, training, and the adequacy of resourcing.

19.3 Findings are reported directly to the Board together with a remediation plan, named owners and deadlines. The Compliance Officer tracks remediation to closure and reports progress to the Board.

19.4 This Policy is reviewed at least annually and updated on legislative change, regulatory guidance, product launch, geographic expansion, or a material incident.

20. Prohibited Customers and Enforcement

20.1 CashCows will not knowingly establish or maintain a relationship with:

  • a person designated under any sanctions regime we observe, or an entity owned or controlled by such a person;
  • a person resident in, located in, or acting from a comprehensively sanctioned or restricted jurisdiction;
  • a person who refuses to provide identification, beneficial ownership information, or a satisfactory explanation of source of funds or wealth;
  • a person who provides false, forged or misleading information, or who impersonates another;
  • a shell company with no discernible economic purpose, or a structure designed to obscure beneficial ownership;
  • a person whose funds are traced to darknet markets, ransomware, fraud, sanctioned addresses or mixing services;
  • a person known or reasonably suspected to be engaged in criminal activity; or
  • a person who attempts to evade our controls, including by disguising location, structuring transactions, or using another person's identity.

20.2 Where a prohibited relationship is identified, we will freeze the account immediately, preserve all records, file any required report, dispose of assets only as permitted by law or as directed by a competent authority, and terminate the relationship.

20.3 Breach of this Policy by a director, officer, employee or contractor is a serious disciplinary matter and may result in dismissal and referral to law enforcement. Individuals should understand that money laundering, terrorist financing and sanctions offences carry personal criminal liability, including imprisonment.

20.4 Customers who breach this Policy face immediate termination, forfeiture of platform access, reporting to the competent authorities, and — where the law permits — retention of assets pending direction from those authorities.

Approved and issued by

Cashcows Labs Ltd. — approved by the Board of Directors and owned by the Compliance Officer. Effective 12 August 2026. Reviewed at least annually and on any material change to the law, our products or our risk profile. Independent testing is performed at least every two years.

Compliance enquiries, requests from financial institutions and correspondence from competent authorities should be directed to the Compliance Officer at the address below and will be acknowledged within two business days.

Compliance officer
support@cash-cows.com
Entity
Cashcows Labs Ltd.
Website
cash-cows.com
Channels
linktr.ee/cashcowsoffical