ANTI-MONEY LAUNDERING AND
COUNTER-TERRORIST FINANCING POLICY

SONATA PAYMENTS SOLUTIONS FZE

License No. L-4739 | Payment Services Provider | Dubai World Trade Centre (DWTC), Emirate of Dubai, United Arab Emirates

Last updated: 28.08.2026

1. Purpose and Scope

This Anti-Money Laundering and Counter-Terrorist Financing Policy (“AML Policy”) sets out the framework adopted by SONATA PAYMENTS SOLUTIONS FZE (“Company”) to prevent the use of its Services for money laundering, terrorist financing, proliferation financing, or other financial crime, in accordance with UAE Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism (as amended or superseded), Cabinet Decision No. 10 of 2019 and its amendments, and other Applicable Law, guidance, and rules issued by competent UAE authorities and the relevant Free Zone Authority.

This AML Policy applies to all Clients, Merchants, and transactions processed through the Services, and forms an integral part of the contractual relationship between the Company and its Clients.

2. Governance and Compliance Officer

2.1. The Company’s senior management bears ultimate responsibility for AML/CFT compliance and shall approve this AML Policy and any material amendments thereto.

2.2. The Company shall appoint a Compliance Officer / Money Laundering Reporting Officer (“MLRO”) responsible for the day-to-day implementation of this AML Policy, including receipt and escalation of internal suspicious activity reports, filing of Suspicious Transaction Reports (“STRs”) with the UAE Financial Intelligence Unit (“UAIFIU”) via the goAML platform, and liaison with regulators.

2.3. The Company shall maintain an independent audit function to periodically test the effectiveness of this AML Policy and related controls.

3. Risk-Based Approach

3.1. The Company applies a risk-based approach to AML/CFT, and shall conduct and document a business-wide risk assessment covering its products, customers, delivery channels, and geographic exposure, reviewed at least annually or upon any material change to the business.

3.2. Clients, Merchants, and transactions shall be risk-rated (low, medium, high) based on factors including: nature of business activity; geographic exposure to high-risk jurisdictions; payment methods and delivery channels; and the Client’s ownership and control structure.

4. Customer Due Diligence (CDD)

4.1. The Company shall conduct CDD prior to establishing a business relationship with any Client and prior to processing any occasional transaction above the threshold set by Applicable Law (currently AED 55,000 or its equivalent), including:

  • verifying the identity of the Client using reliable, independent source documents (e.g., passport, Emirates ID, trade license, certificate of incorporation);
  • identifying and verifying the identity of UBOs holding, directly or indirectly, 25% or more of the Client (where the Client is a legal entity);
  • understanding the purpose and intended nature of the business relationship;
  • screening the Client, its UBOs, directors, and authorized signatories against applicable sanctions lists, PEP databases, and adverse media;
  • obtaining information on the source of funds and source of wealth, where relevant to the Client’s risk rating.

4.2. The Client Questionnaire, completed as part of onboarding under the applicable service agreement, forms part of the Company’s CDD process and shall be updated periodically or upon any material change in the Client’s circumstances.

5. Enhanced Due Diligence (EDD)

5.1. EDD shall be applied, at a minimum, in respect of: PEPs and their close associates and family members; Clients or transactions connected with high-risk or non-cooperative jurisdictions identified by the Financial Action Task Force (FATF) or competent UAE authorities; correspondent relationships; and any Client or transaction otherwise classified as high-risk under the Company’s risk assessment.

5.2. Onboarding of a PEP, or continuation of a relationship where a Client becomes a PEP, shall require senior management approval and shall be subject to enhanced ongoing monitoring.

6. Ongoing Monitoring

6.1. The Company shall monitor transactions and the business relationship on an ongoing basis throughout its duration, in order to ensure that transactions are consistent with the Company’s knowledge of the Client, its business, and risk profile.

6.2. The Company shall employ automated and/or manual monitoring systems designed to detect unusual patterns, structuring, and other indicators of potential money laundering or terrorist financing, and shall periodically re-screen Clients against sanctions and PEP lists.

7. Reporting Obligations

7.1. Any employee who knows, suspects, or has reasonable grounds to suspect that funds or a transaction are connected to money laundering, terrorist financing, or the proceeds of crime, regardless of the amount involved, shall escalate the matter internally to the MLRO without delay.

7.2. Where the MLRO determines that a Suspicious Transaction Report is warranted, it shall be filed with the UAIFIU via the goAML platform promptly, and in any event within the timeframe expected by the regulator (typically 24-48 hours from the point suspicion is formed).

7.3. The Company shall report cash transactions exceeding AED 40,000 (or the applicable threshold under Applicable Law) to the UAIFIU as required.

7.4. The Company, its officers, and employees shall not disclose to a Client or any third party (“tipping-off”) that an STR has been filed or that an investigation is being or may be conducted, save as permitted under Applicable Law.

8. Sanctions Compliance

8.1. The Company shall not establish or maintain a business relationship, or process any transaction, involving a person, entity, vessel, or jurisdiction subject to applicable UAE, United Nations, or other sanctions regimes to which the Company is subject.

8.2. Sanctions screening shall be performed at onboarding, on an ongoing basis, and prior to processing transactions, using screening tools and updated sanctions lists.

9. Record-Keeping

9.1. The Company shall retain all CDD/EDD records, transaction records, correspondence, and internal/external reports for a minimum of five (5) years from the date the business relationship ends or the date of the transaction, whichever is later, or such longer period as required by Applicable Law or a competent authority.

9.2. Records shall be maintained in a manner that allows them to be promptly retrieved and made available to competent authorities upon lawful request.

10. Training

10.1. The Company shall provide AML/CFT training to relevant employees upon induction and at least annually thereafter, tailored to their role and covering applicable legal requirements, red flags, and internal escalation procedures.

11. Refusal and Termination of Relationships

11.1. The Company reserves the right to refuse to onboard, to suspend, or to terminate its relationship with any Client, and to decline or reverse any transaction, where it reasonably suspects money laundering, terrorist financing, or any other breach of this AML Policy or Applicable Law.

12. Group-Wide Application

12.1. Where the Company forms part of a group of companies, the principles of this AML Policy shall, to the extent permitted by local law, be applied on a group-wide basis to overseas branches and majority-owned subsidiaries.

13. Review and Amendment

13.1. This AML Policy shall be reviewed at least annually, and updated as necessary to reflect changes in Applicable Law, regulatory guidance, or the Company’s risk assessment. The current version shall be made available to Clients upon request and published as part of the Company’s compliance documentation.

14. Contact

Questions regarding this AML Policy or reports of suspected financial crime may be directed to the Compliance Officer / MLRO at: info@sonatapayment.com or Office 4.07-COW5-135, Sheikh Rashid Tower, Dubai World Trade Centre, Dubai, United Arab Emirates.