1. Program status
This page describes the intended control architecture for a future U.S. operating entity. It is not a representation that the program has been implemented, independently tested, or accepted by a regulator.
2. Governance and licensing
- Board-approved risk appetite, BSA/AML program, OFAC program, compliance policies, and documented escalation and reporting.
- Qualified BSA Officer and compliance leadership with authority, resources, access to information, and direct escalation to governing management.
- Federal and state regulatory inventory, NMLS and license calendar, surety bond and permissible-investment monitoring, examination readiness, and change-control review.
- Enterprise risk assessment covering customers, products, assets, services, transactions, geographies, delivery channels, and vendors.
- Employee screening, role-based training, issue management, management information, and independent BSA/AML testing.
3. KYC and customer due diligence
- Identity, address, date-of-birth, taxpayer identification, government-ID, bank ownership, and authenticity checks appropriate to the customer and product.
- Beneficial ownership and control-person review for legal entities, with final procedures aligned to effective federal requirements and exemptions.
- Risk classification using expected activity, occupation or business, source of funds, geography, products, counterparties, and adverse information.
- Enhanced due diligence for higher-risk customers, politically exposed persons, complex ownership, high-risk jurisdictions, unusual activity, or other elevated risk.
- Periodic and event-driven refresh, ongoing due diligence, and restrictions where required information cannot be verified.
4. Transaction monitoring and reporting
- Fiat and on-chain monitoring for scams, fraud, ransomware, darknet markets, mixers, sanctions, structuring, rapid movement, account takeover, mule activity, and behavior inconsistent with the customer profile.
- Alert investigation, documented disposition, escalation, Suspicious Activity Report processes, confidentiality, quality assurance, and lawful information-request handling.
- Currency Transaction Report and cash controls if cash activity is ever supported, plus recordkeeping and funds-transfer information requirements where applicable.
- Travel Rule and counterparty institution processes, including risk-based treatment of self-hosted wallet transfers.
5. OFAC sanctions
- Real-time and periodic customer, counterparty, geographic, IP, wallet-address, and transaction screening against applicable sanctions data.
- Risk-based blockchain analytics, potential-match review, blocking or rejecting controls, required reporting, historical lookbacks, and escalation to sanctions counsel.
- No geographic control will rely solely on customer self-certification; device, network, payment, identity, and transaction indicators will be assessed together.
6. Records, safeguarding, and resilience
- Tamper-evident audit trails and retention aligned with BSA, OFAC, licensing, tax, litigation, privacy, security, and customer dispute duties.
- Customer sub-ledgers, daily fiat and digital asset reconciliation, exception management, withdrawal approvals, segregation controls, and reserve reporting.
- Hot, warm, and cold-wallet governance; key management; vendor assurance; incident response; disaster recovery; and business continuity testing.
- State unclaimed-property, complaint, error-resolution, and books-and-records procedures where applicable.
7. Asset listing and market integrity
- Legal classification under securities, commodities, stablecoin, sanctions, and state regimes before listing.
- Assessment of technology, issuer, reserve, custody, liquidity, concentration, smart-contract, governance, manipulation, and consumer risk.
- Conflicts controls, employee dealing restrictions, confidential-information controls, surveillance, periodic review, and orderly delisting.
- No derivatives, leverage, lending, yield, staking, or securities functionality without a separate legal and licensing workstream.
8. Tax, privacy, cybersecurity, and vendors
The planned program includes Form 1099-DA and backup-withholding readiness, tax data controls, state privacy mapping, data minimization, access controls, encryption, secure development, vulnerability management, incident response, breach-notification analysis, vendor diligence, and contractual safeguards.
Critical outsourcing will be monitored according to risk and will not transfer Sovra’s accountability for compliance or customer outcomes.