AML & KYC Notice
This AML & KYC Notice explains how Novolut approaches onboarding, client verification, business activity review, sanctions screening, transaction monitoring and financial crime risk controls.
This notice applies to the Novolut website, request forms, onboarding processes, platform access, product workflows, partner inquiries, use cases and any proposed business, technical or commercial relationship with Novolut.
1. Purpose of this notice
Novolut is designed for qualified B2B financial flows across international trade, treasury, cards, payouts and settlement.
Because the platform may support access to financial infrastructure, payment workflows, settlement routes, corporate card programs, payment acceptance, liquidity coordination and approved stablecoin-related workflows, Novolut applies a risk-based onboarding and compliance review process.
The purpose of this notice is to explain that access to Novolut is not automatic and may require verification, documentation, screening, monitoring and approval by Novolut and, where applicable, by approved infrastructure partners.
2. Risk-based approach
Novolut applies a risk-based approach to onboarding and ongoing monitoring.
This means that the level of review may depend on:
- the client’s jurisdiction;
- ownership and control structure;
- business activity;
- expected transaction volume;
- source of funds or source of activity;
- payment corridors;
- currencies;
- counterparties;
- settlement method;
- use of digital assets or stablecoins;
- card, payment acceptance or payout activity;
- infrastructure partner requirements;
- transaction behavior;
- regulatory, sanctions and financial crime risk indicators.
Novolut may request additional information or documents where a client, partner, transaction, route, wallet record, merchant profile, card program, supplier payment, settlement flow or operating model requires further review.
3. KYB, KYC and UBO verification
Before access is granted, Novolut may require company-level and individual-level verification.
This may include:
- company registration documents;
- certificate of incorporation or equivalent;
- corporate registry extract;
- constitutional documents;
- ownership structure;
- UBO information;
- director information;
- authorized representative information;
- proof of address;
- identity verification for relevant individuals;
- board resolutions or authorization documents;
- group structure chart;
- business description;
- website or online presence;
- licenses, permits or regulatory registrations where applicable;
- expected transaction profile;
- supporting commercial documents.
Novolut may verify the identity of directors, beneficial owners, controllers, signatories, administrators, platform users or other individuals connected to a client or partner.
Where a client operates multiple companies, entities, card programs, merchant profiles, settlement structures or payment channels, each structure may be reviewed separately.
4. Business activity review
Novolut may review the nature, purpose and legitimacy of the business activity connected to any request for access.
This review may include:
- business model;
- target markets;
- customer type;
- supplier type;
- transaction purpose;
- expected monthly volume;
- average transaction size;
- payment corridors;
- settlement currencies;
- source of funds;
- source of activity;
- commercial contracts;
- invoices;
- supplier documents;
- customer payment flows;
- card use cases;
- payout use cases;
- payment acceptance channels;
- stablecoin settlement purpose where applicable.
Novolut may decline access where the business activity is unclear, unsupported, inconsistent with the submitted documents, outside risk appetite or not acceptable to Novolut or its infrastructure partners.
5. Sanctions, PEP and adverse media screening
Novolut may screen clients, beneficial owners, directors, representatives, users, counterparties, suppliers, wallets, transactions and related parties against sanctions lists, PEP databases, adverse media sources and other risk databases.
Screening may be conducted during onboarding and on an ongoing basis.
Novolut may restrict, pause, review or reject access where screening identifies sanctions exposure, high-risk political exposure, adverse media, financial crime concerns, ownership risk, counterparty risk or other indicators requiring further review.
Novolut does not support activity involving sanctioned persons, sanctioned entities, sanctioned jurisdictions or attempts to bypass sanctions restrictions.
6. Source of funds and source of activity
Novolut may request information and documents to understand the source of funds, source of activity or commercial purpose behind a transaction or operating model.
This may include:
- invoices;
- contracts;
- purchase orders;
- supplier agreements;
- shipping documents;
- customs documents;
- transaction history;
- bank statements;
- proof of business revenue;
- proof of ownership of funds;
- wallet ownership evidence;
- explanation of counterparties;
- explanation of transaction purpose;
- supporting documents for trade, treasury, settlement, payout or payment acceptance flows.
For international trade and supplier payment workflows, Novolut may require documents showing the relationship between the company, supplier, invoice currency, payment purpose, funding source and settlement route.
For stablecoin-related workflows, Novolut may require additional information regarding wallet ownership, transaction source, blockchain activity, conversion purpose and downstream fiat payment use.
7. Transaction monitoring
Novolut may monitor transactions, workflows, payment instructions, settlement records, card activity, payment acceptance records, wallet-related activity and other platform activity.
Monitoring may include review of:
- transaction amount;
- transaction frequency;
- currency;
- payment route;
- counterparty;
- supplier;
- merchant profile;
- wallet address;
- settlement method;
- transaction status;
- documentation;
- user activity;
- approval history;
- unusual patterns;
- deviations from the approved business profile;
- high-risk jurisdictions;
- high-risk counterparties;
- rejected or failed transactions;
- chargebacks, disputes or refunds;
- card activity;
- payment acceptance activity.
Novolut may request additional information before processing, routing, approving, reporting or allowing a workflow to continue.
8. Wallet and digital asset screening
Where digital asset or stablecoin-related workflows are supported, Novolut may apply wallet and transaction screening.
This may include review of:
- wallet ownership;
- source wallet;
- destination wallet;
- blockchain transaction history;
- exposure to sanctioned addresses;
- exposure to mixers, tumblers or obfuscation tools;
- darknet exposure;
- scam, fraud, theft or ransomware exposure;
- high-risk exchange exposure;
- unhosted wallet risk;
- transaction pattern;
- source-of-funds evidence;
- conversion purpose;
- downstream payment purpose.
Novolut does not support anonymous stablecoin flows, undocumented wallet activity, sanctions exposure, wallet obfuscation, payment laundering, fraud-related flows or unrestricted digital asset activity.
Stablecoin-related workflows are only considered where linked to an approved business purpose, approved company profile, documented source of funds and permitted settlement use case.
9. Infrastructure partner requirements
Novolut works with approved infrastructure partners that may provide banking, payment, EMI, issuing, acquiring, custody, settlement, liquidity, FX, OTC, compliance or other regulated services.
Each infrastructure partner may apply its own onboarding, KYB, KYC, UBO, sanctions screening, transaction monitoring, documentation, risk and approval requirements.
Approval by Novolut does not guarantee approval by any infrastructure partner.
A client, partner, company, route, account, wallet structure, card program, merchant profile, payment method, settlement workflow, transaction or use case may be approved by Novolut but still rejected, restricted, reviewed or declined by an infrastructure partner.
Novolut may share relevant onboarding information, compliance documents, risk information, transaction records or supporting materials with infrastructure partners where required or permitted for onboarding, service delivery, monitoring, reporting, compliance or risk-management purposes.
10. Prohibited and restricted activity
Novolut does not support:
- anonymous activity;
- undocumented flows;
- misleading business activity;
- unauthorized third-party processing;
- transaction miscoding;
- payment laundering;
- sanctions evasion;
- shell-company abuse;
- fake invoices;
- unsupported supplier payments;
- unsupported merchant activity;
- illegal goods or services;
- fraud-related activity;
- scam-related activity;
- ransomware-related activity;
- darknet-related activity;
- mixer or tumbler-related activity;
- unsupported gambling activity;
- adult content where prohibited or unsupported;
- weapons, explosives or prohibited dual-use goods;
- high-risk financial services without approval;
- activity inconsistent with the approved business profile;
- any activity that conflicts with Novolut’s risk appetite, infrastructure partner requirements or applicable law.
Novolut may maintain internal restricted business categories that are not publicly disclosed.
11. Right to reject, pause, restrict or terminate
Novolut may reject, pause, restrict, suspend, terminate or refuse to process any request, client, partner, user, company profile, account structure, wallet record, card program, merchant profile, payment acceptance channel, transaction, payment route, settlement workflow, corridor or infrastructure access where required.
This may occur where:
- information is incomplete;
- documents are inconsistent;
- ownership is unclear;
- source of funds is not verified;
- business activity is unsupported;
- sanctions or financial crime risk is identified;
- transaction behavior differs from the approved profile;
- infrastructure partner approval is not available;
- requested activity is outside Novolut’s risk appetite;
- regulatory, legal, compliance or operational requirements prevent service;
- Novolut determines that continued access may create unacceptable risk.
Novolut is not required to onboard any client or partner and is not required to provide reasons where disclosure may conflict with legal, compliance, risk, security or partner requirements.
12. Ongoing review
Onboarding approval is not permanent or unconditional.
Novolut may conduct ongoing review of clients, partners, users, transactions, counterparties, business activity, ownership structures, wallet activity, payment routes, card programs, merchant profiles, settlement workflows and infrastructure usage.
Novolut may request updated documents, refreshed KYB/KYC information, revised ownership details, new proof of address, transaction explanations, supplier documents, wallet information, financial statements or other supporting materials.
A client or partner must promptly notify Novolut of material changes, including changes to ownership, control, directors, business activity, licensing status, jurisdictions, expected volumes, payment corridors, supplier base, customer base, settlement methods or risk profile.
13. Record keeping
Novolut may retain onboarding records, verification records, compliance documents, transaction records, screening results, monitoring records, communications, approvals, restrictions, review notes and related compliance materials where required or permitted.
Record retention may be necessary for legal, regulatory, contractual, audit, fraud prevention, dispute resolution, operational, infrastructure partner or compliance purposes.
The processing of personal data is governed by the Novolut Privacy Policy.
14. No guarantee of approval or execution
Submitting information, documents or a request form does not guarantee onboarding, platform access, product availability, infrastructure partner approval, account opening, payment execution, settlement access, card issuing, payment acceptance, liquidity access, stablecoin workflow approval or any commercial arrangement.
Access remains subject to review, approval, infrastructure availability, provider coverage, contractual terms, technical feasibility and compliance approval.
15. Contact
Questions about this AML & KYC Notice may be submitted through the Novolut request form.
Novolut reviews compliance-related inquiries according to the nature of the request, the onboarding status, the relevant business activity and the applicable infrastructure partner requirements.
Submission of a request does not create platform access, onboarding approval, transaction approval or any commercial relationship with Novolut.
For legal or compliance matters, contact: [email protected]