Compliance

Designed around the obligations, not retrofitted to them

eterfaceID is built for reporting entities under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and for payment service providers registering under the Retail Payment Activities Act.

FINTRAC obligations

Client identification

Every verification is executed and labelled as one of the recognised methods — government-issued photo identification, the credit file method, or the dual-process method — with the source and date captured.

Beneficial ownership

For entity customers, ownership and control information is obtained, confirmed where possible, and where it cannot be confirmed the reasonable measures taken are recorded instead of left blank.

PEP and HIO determination

Screening covers domestic and foreign politically exposed persons, heads of international organisations, and their relatives and close associates, with the determination date stored on the file.

Ongoing monitoring

Customers are rescreened continuously and risk ratings are refreshed as new information arrives, with alerts routed to the analyst queue.

Record keeping

Records are retained for seven years by default. Retention is configurable upward, and deletion is blocked while a record is inside its retention window.

Examination readiness

Any customer file can be exported with its full evidence chain: the source documents, the checks run, the results, the reviewer and the timestamps.

Bank of Canada PSP registration (RPAA)

End-user identification

Retail payment activity requires you to know your end users. eterfaceID supplies the identification and the evidence in the form the registration process expects.

Risk management framework

Screening configuration, thresholds and escalation paths are documented and versioned, which supports the operational risk and incident response framework you must maintain.

Incident readiness

Access logs and an append-only audit trail give you the record needed when an incident has to be reported and reconstructed.

Annual reporting

Volume, outcome and alert-disposition reporting can be exported for the annual report and for supervisory requests.

Data handling and security

Data residency

Canadian customer data is stored in Canadian regions. [Confirm the exact regions and any regional options before publishing]

Encryption

Data is encrypted in transit and at rest. Document images and biometric artefacts are access-controlled and logged on every read.

Privacy

Handling is aligned with PIPEDA and applicable provincial privacy legislation, with consent captured at the point of collection. [Have counsel review this section]

Certifications

[SOC 2 Type II, ISO 27001 and any other certifications — list only what has actually been awarded; nothing is claimed here yet]

This page describes how the platform supports your obligations. It is not legal advice, and it does not transfer your obligations to eterfaceID.

Bring your compliance officer to the first call

The conversation usually goes faster when the person who owns the programme is in the room. We will go obligation by obligation.