Anti-Money Laundering and Counter-Terrorist Financing Policy

Mundpay reaffirms its non-negotiable commitment to preventing and combating money laundering, terrorist financing, and any other illicit practices that could compromise the integrity of the national and international financial system. This commitment is one of the fundamental pillars of its corporate governance, risk management, and compliance program structure, and is observed in all its activities, operations, and business relationships.

In line with applicable Brazilian legislation, guidelines from competent regulatory authorities, and key international standards for preventing financial crimes, Mundpay adopts a risk-based approach, supported by internal controls, diligence procedures, monitoring mechanisms, and ongoing evaluation processes designed to identify, mitigate, and report potential risks related to money laundering, terrorist financing, financing the proliferation of weapons of mass destruction, fraud, corruption, and other illicit conduct.

The purpose of this public, summarized version is to provide transparency regarding the principles, guidelines, and structural elements that make up Mundpay's Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) Program, demonstrating the Company's ongoing commitment to integrity, operational safety, client and partner protection, compliance with best market practices, and strict adherence to its legal, regulatory, and contractual obligations.

2. Legal and Regulatory Framework

Mundpay's Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) Program was developed in compliance with applicable Brazilian legislation, observing rules and guidelines issued by competent regulatory and supervisory bodies, as well as key international risk management and financial crime prevention frameworks.

Within this context, the Company's control structure is based, among other regulatory statutes, on Law No. 9,613/1998, which governs crimes of money laundering and concealment of assets, rights, and values; Law No. 13,810/2019, relating to compliance with sanctions imposed by the United Nations Security Council; Law No. 12,846/2013 (Anti-Corruption Law); BACEN Circular No. 3,978/2020, which establishes guidelines for internal policies, procedures, and controls to prevent money laundering and terrorist financing; BCB Resolution No. 2,025/2023, which regulates procedures for identifying and qualifying clients and ultimate beneficial owners; COAF Resolution No. 29/2017, concerning the treatment of Politically Exposed Persons (PEPs); and Law No. 13,709/2018 (General Data Protection Law – LGPD).

Additionally, the Program complies with the Recommendations of the Financial Action Task Force (FATF/GAFI), the global benchmark in preventing money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction, as well as the principles established by ISO 31000:2018 for risk management and ISO/IEC 27001:2022 for information security.

3. Structure of the AML/CFT Program

Mundpay's AML/CFT Program is structured in accordance with the Risk-Based Approach (RBA) methodology, widely adopted by national and international financial regulators. This methodology ensures that prevention, monitoring, and control resources are directed proportionally to the identified risks, considering factors related to clients, partners, products, services, operations, distribution channels, and involved jurisdictions.

To ensure the effectiveness of the Program, Mundpay maintains an integrated set of corporate policies, internal procedures, and governance mechanisms designed to prevent financial crimes. The structure includes ongoing internal risk assessment processes, identification and diligence of clients, partners, and ultimate beneficial owners, continuous monitoring of transactions, checks against national and international restrictive lists, reporting of suspicious transactions to competent authorities, regular training for employees, and periodic assessments of the effectiveness of implemented controls.

This structure is continuously reviewed and improved to reflect regulatory changes, emerging risks, new typologies of money laundering, and market best practices, ensuring that controls remain compatible with the complexity of the operations conducted by the Company and the risks inherent to its business environment.

4. Know Your Customer (KYC)

As an essential part of its compliance structure, Mundpay adopts identification, qualification, verification, and continuous monitoring procedures for clients, in compliance with Know Your Customer (KYC) principles and applicable regulatory requirements.

Before establishing any business relationship, procedures are conducted to validate client identities, analyze the registration information provided, and identify their respective ultimate beneficial owners, when applicable. These procedures aim to ensure a proper understanding of the corporate structure, the nature of the activities conducted, and the risks associated with the intended relationship.

Additionally, the Company performs risk classification processes and continuous monitoring, allowing for the identification of significant changes in client profiles throughout the business relationship. In situations involving Politically Exposed Persons (PEPs), complex corporate structures, jurisdictions deemed higher risk, or any other factors requiring additional attention, enhanced due diligence measures may be applied, according to internal compliance criteria and current regulations.

Mundpay also maintains periodic procedures for updating registration records and reviewing collected information to preserve the quality, integrity, and currency of the data used in its money laundering and terrorist financing prevention processes.

5. Transaction Monitoring

Mundpay maintains continuous monitoring mechanisms aimed at identifying, preventing, and mitigating risks related to money laundering, terrorist financing, financing the proliferation of weapons of mass destruction, fraud, and other financial illicit acts. The controls adopted include the continuous analysis of operations conducted within the scope of its activities, considering factors related to the client profile, the nature of transaction, the jurisdictions involved, and the inherent risks of the products and services offered.

As part of its risk-based approach, the Company utilizes technological tools, supervisory processes, and review procedures to identify atypical, inconsistent, or incompatible operations based on expected economic, financial, or operational profiles. Whenever evidence requiring further analysis is identified, complementary diligence and compliance reviews are performed, adhering to internal governance criteria and applicable regulatory requirements.

6. Reporting Suspicious Transactions

In compliance with current legal and regulatory provisions, Mundpay maintains procedures designed to identify, analyze, escalate, and report transactions or situations that may show signs of money laundering, terrorist financing, or other illicit activities.

Detected events are submitted to the Compliance area for evaluation. Compliance conducts the appropriate analyses independently and with proper justification, which may involve additional diligence procedures and document reviews. When applicable legal requirements are met, communications are forwarded to the competent authorities, in strict compliance with the regulatory duties imposed on the Company.

The entire process is conducted under strict standards of confidentiality and information security, and it is forbidden to disclose information related to analyses, investigations, or any reports made to competent authorities to third parties, in compliance with applicable law.

7. Due Diligence of Business Partners

Recognizing the importance of integrity across the entire corporate relationship chain, Mundpay adopts assessment and diligence procedures applicable to suppliers, business partners, service providers, and other third parties with whom it maintains significant relationships.

Due diligence processes aim to evaluate aspects related to legal standing, reputation, integrity, corporate structure, ultimate beneficial owners, compliance with regulatory obligations, and exposure to money laundering, terrorist financing, corruption, and other practices incompatible with the ethical and compliance principles adopted by the Company.

Assessments are conducted before the start of the business relationship and may be renewed periodically, in accordance with the risk profile and the nature of the established relationship.

8. Education and Training

Mundpay understands that the effectiveness of any financial crime prevention program depends directly on fostering an organizational culture based on ethics, integrity, and regulatory compliance. Within this context, the Company promotes ongoing training and awareness programs for employees, managers, and other internal audiences subject to compliance guidelines.

Training sessions cover topics related to money laundering prevention, terrorist financing, fraud prevention, data protection, international sanctions, and other applicable regulatory obligations, considering the nature of the activities performed and the level of risk exposure inherent to each role.

In addition to periodic training, the Company promotes updates and awareness initiatives aimed at tracking regulatory changes, emerging privileges, and national and international best practices.

9. Audits and Regular Reviews

Mundpay conducts periodic assessments to verify the adequacy, effectiveness, and adherence of its AML/CFT Program to legal and regulatory requirements, as well as to market best practices. These assessments include reviewing policies, procedures, internal controls, and monitoring mechanisms, as well as analyzing the evolution of the risks to which the Company is exposed.

As part of its governance process, management reports and effectiveness evaluations are prepared to support decision-making by Senior Management and the bodies responsible for overseeing the Compliance Program.

The control structure is subject to continuous improvement and is reviewed whenever necessary due to regulatory changes, significant changes in the business environment, updates in identified risks, or opportunities to strengthen the prevention and control mechanisms adopted by the Company.

10. Consequences of Violations

Compliance with Anti-Money Laundering and Counter-Terrorist Financing guidelines is an essential obligation for all employees, directors, business partners, suppliers, and other third parties acting on behalf of or for the benefit of Mundpay. Non-compliance with the provisions of internal policies, corporate procedures, or applicable legislation could compromise the Company's integrity, institutional reputation, and compliance with its regulatory obligations.

In this context, potential violations will be analyzed according to their nature, severity, recurrence, and potential impact on the organization, which may lead to the adoption of appropriate administrative, disciplinary, and contractual measures, without prejudice to reporting to competent authorities when required by law or when evidence of civil, administrative, or criminal illicit activities is identified.

Mundpay takes a zero-tolerance stance toward behavior that may encourage, facilitate, or conceal activities related to money laundering, terrorist financing, corruption, fraud, evasion of international sanctions, or any other practices incompatible with its ethical and compliance standards.

11. Restrictive Lists and Sanctions

As an integral part of its financial crime prevention framework, Mundpay carries out ongoing checking and monitoring procedures to identify individuals and legal entities subject to regulatory restrictions, economic sanctions, international restrictive measures, or other situations that may pose risks to the integrity of its business relationships.

These checks include querying recognized national and international databases, such as lists of Politically Exposed Persons (PEPs), economic and financial sanction programs, government restriction lists, relevant public records, and reputational monitoring mechanisms, always observing applicable regulations and the principles of the Risk-Based Approach.

The identification of relevant risk factors may lead to additional diligence measures, a review of the business relationship, the implementation of enhanced controls, or, when necessary, the rejection, suspension, or termination of the business relationship, in line with applicable legal, regulatory, and contractual obligations.

12. Review and Update

Mundpay recognizes that preventing money laundering and terrorist financing requires constant evolution in light of regulatory changes, the emergence of new financial crime typologies, and the continuous transformation of the business environment. For this reason, this Policy is subject to periodic review and update processes to ensure its alignment with legal and regulatory requirements, as well as with national and international compliance and risk management best practices.

Reviews are conducted by the Compliance Department and submitted to Senior Management for approval. They can occur more frequently than the standard cycle whenever there are significant alterations in applicable legislation, major changes in the activities carried out by the Company, the identification of opportunities to improve internal controls, or directives issued by competent regulatory authorities.

The public version of this Policy is for informational purposes only and aims to promote institutional transparency regarding the principles and guidelines that guide Mundpay's Anti-Money Laundering and Counter-Terrorist Financing Program. The complete version of the corporate regulations, including internal procedures, operational controls, and applicable governance mechanisms, is available upon formal request to the Compliance Department.

Anti-Money Laundering and Counter-Terrorist Financing Policy

Mundpay reaffirms its non-negotiable commitment to preventing and combating money laundering, terrorist financing, and any other illicit practices that could compromise the integrity of the national and international financial system. This commitment is one of the fundamental pillars of its corporate governance, risk management, and compliance program structure, and is observed in all its activities, operations, and business relationships.

In line with applicable Brazilian legislation, guidelines from competent regulatory authorities, and key international standards for preventing financial crimes, Mundpay adopts a risk-based approach, supported by internal controls, diligence procedures, monitoring mechanisms, and ongoing evaluation processes designed to identify, mitigate, and report potential risks related to money laundering, terrorist financing, financing the proliferation of weapons of mass destruction, fraud, corruption, and other illicit conduct.

The purpose of this public, summarized version is to provide transparency regarding the principles, guidelines, and structural elements that make up Mundpay's Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) Program, demonstrating the Company's ongoing commitment to integrity, operational safety, client and partner protection, compliance with best market practices, and strict adherence to its legal, regulatory, and contractual obligations.

2. Legal and Regulatory Framework

Mundpay's Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) Program was developed in compliance with applicable Brazilian legislation, observing rules and guidelines issued by competent regulatory and supervisory bodies, as well as key international risk management and financial crime prevention frameworks.

Within this context, the Company's control structure is based, among other regulatory statutes, on Law No. 9,613/1998, which governs crimes of money laundering and concealment of assets, rights, and values; Law No. 13,810/2019, relating to compliance with sanctions imposed by the United Nations Security Council; Law No. 12,846/2013 (Anti-Corruption Law); BACEN Circular No. 3,978/2020, which establishes guidelines for internal policies, procedures, and controls to prevent money laundering and terrorist financing; BCB Resolution No. 2,025/2023, which regulates procedures for identifying and qualifying clients and ultimate beneficial owners; COAF Resolution No. 29/2017, concerning the treatment of Politically Exposed Persons (PEPs); and Law No. 13,709/2018 (General Data Protection Law – LGPD).

Additionally, the Program complies with the Recommendations of the Financial Action Task Force (FATF/GAFI), the global benchmark in preventing money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction, as well as the principles established by ISO 31000:2018 for risk management and ISO/IEC 27001:2022 for information security.

3. Structure of the AML/CFT Program

Mundpay's AML/CFT Program is structured in accordance with the Risk-Based Approach (RBA) methodology, widely adopted by national and international financial regulators. This methodology ensures that prevention, monitoring, and control resources are directed proportionally to the identified risks, considering factors related to clients, partners, products, services, operations, distribution channels, and involved jurisdictions.

To ensure the effectiveness of the Program, Mundpay maintains an integrated set of corporate policies, internal procedures, and governance mechanisms designed to prevent financial crimes. The structure includes ongoing internal risk assessment processes, identification and diligence of clients, partners, and ultimate beneficial owners, continuous monitoring of transactions, checks against national and international restrictive lists, reporting of suspicious transactions to competent authorities, regular training for employees, and periodic assessments of the effectiveness of implemented controls.

This structure is continuously reviewed and improved to reflect regulatory changes, emerging risks, new typologies of money laundering, and market best practices, ensuring that controls remain compatible with the complexity of the operations conducted by the Company and the risks inherent to its business environment.

4. Know Your Customer (KYC)

As an essential part of its compliance structure, Mundpay adopts identification, qualification, verification, and continuous monitoring procedures for clients, in compliance with Know Your Customer (KYC) principles and applicable regulatory requirements.

Before establishing any business relationship, procedures are conducted to validate client identities, analyze the registration information provided, and identify their respective ultimate beneficial owners, when applicable. These procedures aim to ensure a proper understanding of the corporate structure, the nature of the activities conducted, and the risks associated with the intended relationship.

Additionally, the Company performs risk classification processes and continuous monitoring, allowing for the identification of significant changes in client profiles throughout the business relationship. In situations involving Politically Exposed Persons (PEPs), complex corporate structures, jurisdictions deemed higher risk, or any other factors requiring additional attention, enhanced due diligence measures may be applied, according to internal compliance criteria and current regulations.

Mundpay also maintains periodic procedures for updating registration records and reviewing collected information to preserve the quality, integrity, and currency of the data used in its money laundering and terrorist financing prevention processes.

5. Transaction Monitoring

Mundpay maintains continuous monitoring mechanisms aimed at identifying, preventing, and mitigating risks related to money laundering, terrorist financing, financing the proliferation of weapons of mass destruction, fraud, and other financial illicit acts. The controls adopted include the continuous analysis of operations conducted within the scope of its activities, considering factors related to the client profile, the nature of transaction, the jurisdictions involved, and the inherent risks of the products and services offered.

As part of its risk-based approach, the Company utilizes technological tools, supervisory processes, and review procedures to identify atypical, inconsistent, or incompatible operations based on expected economic, financial, or operational profiles. Whenever evidence requiring further analysis is identified, complementary diligence and compliance reviews are performed, adhering to internal governance criteria and applicable regulatory requirements.

6. Reporting Suspicious Transactions

In compliance with current legal and regulatory provisions, Mundpay maintains procedures designed to identify, analyze, escalate, and report transactions or situations that may show signs of money laundering, terrorist financing, or other illicit activities.

Detected events are submitted to the Compliance area for evaluation. Compliance conducts the appropriate analyses independently and with proper justification, which may involve additional diligence procedures and document reviews. When applicable legal requirements are met, communications are forwarded to the competent authorities, in strict compliance with the regulatory duties imposed on the Company.

The entire process is conducted under strict standards of confidentiality and information security, and it is forbidden to disclose information related to analyses, investigations, or any reports made to competent authorities to third parties, in compliance with applicable law.

7. Due Diligence of Business Partners

Recognizing the importance of integrity across the entire corporate relationship chain, Mundpay adopts assessment and diligence procedures applicable to suppliers, business partners, service providers, and other third parties with whom it maintains significant relationships.

Due diligence processes aim to evaluate aspects related to legal standing, reputation, integrity, corporate structure, ultimate beneficial owners, compliance with regulatory obligations, and exposure to money laundering, terrorist financing, corruption, and other practices incompatible with the ethical and compliance principles adopted by the Company.

Assessments are conducted before the start of the business relationship and may be renewed periodically, in accordance with the risk profile and the nature of the established relationship.

8. Education and Training

Mundpay understands that the effectiveness of any financial crime prevention program depends directly on fostering an organizational culture based on ethics, integrity, and regulatory compliance. Within this context, the Company promotes ongoing training and awareness programs for employees, managers, and other internal audiences subject to compliance guidelines.

Training sessions cover topics related to money laundering prevention, terrorist financing, fraud prevention, data protection, international sanctions, and other applicable regulatory obligations, considering the nature of the activities performed and the level of risk exposure inherent to each role.

In addition to periodic training, the Company promotes updates and awareness initiatives aimed at tracking regulatory changes, emerging privileges, and national and international best practices.

9. Audits and Regular Reviews

Mundpay conducts periodic assessments to verify the adequacy, effectiveness, and adherence of its AML/CFT Program to legal and regulatory requirements, as well as to market best practices. These assessments include reviewing policies, procedures, internal controls, and monitoring mechanisms, as well as analyzing the evolution of the risks to which the Company is exposed.

As part of its governance process, management reports and effectiveness evaluations are prepared to support decision-making by Senior Management and the bodies responsible for overseeing the Compliance Program.

The control structure is subject to continuous improvement and is reviewed whenever necessary due to regulatory changes, significant changes in the business environment, updates in identified risks, or opportunities to strengthen the prevention and control mechanisms adopted by the Company.

10. Consequences of Violations

Compliance with Anti-Money Laundering and Counter-Terrorist Financing guidelines is an essential obligation for all employees, directors, business partners, suppliers, and other third parties acting on behalf of or for the benefit of Mundpay. Non-compliance with the provisions of internal policies, corporate procedures, or applicable legislation could compromise the Company's integrity, institutional reputation, and compliance with its regulatory obligations.

In this context, potential violations will be analyzed according to their nature, severity, recurrence, and potential impact on the organization, which may lead to the adoption of appropriate administrative, disciplinary, and contractual measures, without prejudice to reporting to competent authorities when required by law or when evidence of civil, administrative, or criminal illicit activities is identified.

Mundpay takes a zero-tolerance stance toward behavior that may encourage, facilitate, or conceal activities related to money laundering, terrorist financing, corruption, fraud, evasion of international sanctions, or any other practices incompatible with its ethical and compliance standards.

11. Restrictive Lists and Sanctions

As an integral part of its financial crime prevention framework, Mundpay carries out ongoing checking and monitoring procedures to identify individuals and legal entities subject to regulatory restrictions, economic sanctions, international restrictive measures, or other situations that may pose risks to the integrity of its business relationships.

These checks include querying recognized national and international databases, such as lists of Politically Exposed Persons (PEPs), economic and financial sanction programs, government restriction lists, relevant public records, and reputational monitoring mechanisms, always observing applicable regulations and the principles of the Risk-Based Approach.

The identification of relevant risk factors may lead to additional diligence measures, a review of the business relationship, the implementation of enhanced controls, or, when necessary, the rejection, suspension, or termination of the business relationship, in line with applicable legal, regulatory, and contractual obligations.

12. Review and Update

Mundpay recognizes that preventing money laundering and terrorist financing requires constant evolution in light of regulatory changes, the emergence of new financial crime typologies, and the continuous transformation of the business environment. For this reason, this Policy is subject to periodic review and update processes to ensure its alignment with legal and regulatory requirements, as well as with national and international compliance and risk management best practices.

Reviews are conducted by the Compliance Department and submitted to Senior Management for approval. They can occur more frequently than the standard cycle whenever there are significant alterations in applicable legislation, major changes in the activities carried out by the Company, the identification of opportunities to improve internal controls, or directives issued by competent regulatory authorities.

The public version of this Policy is for informational purposes only and aims to promote institutional transparency regarding the principles and guidelines that guide Mundpay's Anti-Money Laundering and Counter-Terrorist Financing Program. The complete version of the corporate regulations, including internal procedures, operational controls, and applicable governance mechanisms, is available upon formal request to the Compliance Department.

Anti-Money Laundering and Counter-Terrorist Financing Policy

Mundpay reaffirms its non-negotiable commitment to preventing and combating money laundering, terrorist financing, and any other illicit practices that could compromise the integrity of the national and international financial system. This commitment is one of the fundamental pillars of its corporate governance, risk management, and compliance program structure, and is observed in all its activities, operations, and business relationships.

In line with applicable Brazilian legislation, guidelines from competent regulatory authorities, and key international standards for preventing financial crimes, Mundpay adopts a risk-based approach, supported by internal controls, diligence procedures, monitoring mechanisms, and ongoing evaluation processes designed to identify, mitigate, and report potential risks related to money laundering, terrorist financing, financing the proliferation of weapons of mass destruction, fraud, corruption, and other illicit conduct.

The purpose of this public, summarized version is to provide transparency regarding the principles, guidelines, and structural elements that make up Mundpay's Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) Program, demonstrating the Company's ongoing commitment to integrity, operational safety, client and partner protection, compliance with best market practices, and strict adherence to its legal, regulatory, and contractual obligations.

2. Legal and Regulatory Framework

Mundpay's Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) Program was developed in compliance with applicable Brazilian legislation, observing rules and guidelines issued by competent regulatory and supervisory bodies, as well as key international risk management and financial crime prevention frameworks.

Within this context, the Company's control structure is based, among other regulatory statutes, on Law No. 9,613/1998, which governs crimes of money laundering and concealment of assets, rights, and values; Law No. 13,810/2019, relating to compliance with sanctions imposed by the United Nations Security Council; Law No. 12,846/2013 (Anti-Corruption Law); BACEN Circular No. 3,978/2020, which establishes guidelines for internal policies, procedures, and controls to prevent money laundering and terrorist financing; BCB Resolution No. 2,025/2023, which regulates procedures for identifying and qualifying clients and ultimate beneficial owners; COAF Resolution No. 29/2017, concerning the treatment of Politically Exposed Persons (PEPs); and Law No. 13,709/2018 (General Data Protection Law – LGPD).

Additionally, the Program complies with the Recommendations of the Financial Action Task Force (FATF/GAFI), the global benchmark in preventing money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction, as well as the principles established by ISO 31000:2018 for risk management and ISO/IEC 27001:2022 for information security.

3. Structure of the AML/CFT Program

Mundpay's AML/CFT Program is structured in accordance with the Risk-Based Approach (RBA) methodology, widely adopted by national and international financial regulators. This methodology ensures that prevention, monitoring, and control resources are directed proportionally to the identified risks, considering factors related to clients, partners, products, services, operations, distribution channels, and involved jurisdictions.

To ensure the effectiveness of the Program, Mundpay maintains an integrated set of corporate policies, internal procedures, and governance mechanisms designed to prevent financial crimes. The structure includes ongoing internal risk assessment processes, identification and diligence of clients, partners, and ultimate beneficial owners, continuous monitoring of transactions, checks against national and international restrictive lists, reporting of suspicious transactions to competent authorities, regular training for employees, and periodic assessments of the effectiveness of implemented controls.

This structure is continuously reviewed and improved to reflect regulatory changes, emerging risks, new typologies of money laundering, and market best practices, ensuring that controls remain compatible with the complexity of the operations conducted by the Company and the risks inherent to its business environment.

4. Know Your Customer (KYC)

As an essential part of its compliance structure, Mundpay adopts identification, qualification, verification, and continuous monitoring procedures for clients, in compliance with Know Your Customer (KYC) principles and applicable regulatory requirements.

Before establishing any business relationship, procedures are conducted to validate client identities, analyze the registration information provided, and identify their respective ultimate beneficial owners, when applicable. These procedures aim to ensure a proper understanding of the corporate structure, the nature of the activities conducted, and the risks associated with the intended relationship.

Additionally, the Company performs risk classification processes and continuous monitoring, allowing for the identification of significant changes in client profiles throughout the business relationship. In situations involving Politically Exposed Persons (PEPs), complex corporate structures, jurisdictions deemed higher risk, or any other factors requiring additional attention, enhanced due diligence measures may be applied, according to internal compliance criteria and current regulations.

Mundpay also maintains periodic procedures for updating registration records and reviewing collected information to preserve the quality, integrity, and currency of the data used in its money laundering and terrorist financing prevention processes.

5. Transaction Monitoring

Mundpay maintains continuous monitoring mechanisms aimed at identifying, preventing, and mitigating risks related to money laundering, terrorist financing, financing the proliferation of weapons of mass destruction, fraud, and other financial illicit acts. The controls adopted include the continuous analysis of operations conducted within the scope of its activities, considering factors related to the client profile, the nature of transaction, the jurisdictions involved, and the inherent risks of the products and services offered.

As part of its risk-based approach, the Company utilizes technological tools, supervisory processes, and review procedures to identify atypical, inconsistent, or incompatible operations based on expected economic, financial, or operational profiles. Whenever evidence requiring further analysis is identified, complementary diligence and compliance reviews are performed, adhering to internal governance criteria and applicable regulatory requirements.

6. Reporting Suspicious Transactions

In compliance with current legal and regulatory provisions, Mundpay maintains procedures designed to identify, analyze, escalate, and report transactions or situations that may show signs of money laundering, terrorist financing, or other illicit activities.

Detected events are submitted to the Compliance area for evaluation. Compliance conducts the appropriate analyses independently and with proper justification, which may involve additional diligence procedures and document reviews. When applicable legal requirements are met, communications are forwarded to the competent authorities, in strict compliance with the regulatory duties imposed on the Company.

The entire process is conducted under strict standards of confidentiality and information security, and it is forbidden to disclose information related to analyses, investigations, or any reports made to competent authorities to third parties, in compliance with applicable law.

7. Due Diligence of Business Partners

Recognizing the importance of integrity across the entire corporate relationship chain, Mundpay adopts assessment and diligence procedures applicable to suppliers, business partners, service providers, and other third parties with whom it maintains significant relationships.

Due diligence processes aim to evaluate aspects related to legal standing, reputation, integrity, corporate structure, ultimate beneficial owners, compliance with regulatory obligations, and exposure to money laundering, terrorist financing, corruption, and other practices incompatible with the ethical and compliance principles adopted by the Company.

Assessments are conducted before the start of the business relationship and may be renewed periodically, in accordance with the risk profile and the nature of the established relationship.

8. Education and Training

Mundpay understands that the effectiveness of any financial crime prevention program depends directly on fostering an organizational culture based on ethics, integrity, and regulatory compliance. Within this context, the Company promotes ongoing training and awareness programs for employees, managers, and other internal audiences subject to compliance guidelines.

Training sessions cover topics related to money laundering prevention, terrorist financing, fraud prevention, data protection, international sanctions, and other applicable regulatory obligations, considering the nature of the activities performed and the level of risk exposure inherent to each role.

In addition to periodic training, the Company promotes updates and awareness initiatives aimed at tracking regulatory changes, emerging privileges, and national and international best practices.

9. Audits and Regular Reviews

Mundpay conducts periodic assessments to verify the adequacy, effectiveness, and adherence of its AML/CFT Program to legal and regulatory requirements, as well as to market best practices. These assessments include reviewing policies, procedures, internal controls, and monitoring mechanisms, as well as analyzing the evolution of the risks to which the Company is exposed.

As part of its governance process, management reports and effectiveness evaluations are prepared to support decision-making by Senior Management and the bodies responsible for overseeing the Compliance Program.

The control structure is subject to continuous improvement and is reviewed whenever necessary due to regulatory changes, significant changes in the business environment, updates in identified risks, or opportunities to strengthen the prevention and control mechanisms adopted by the Company.

10. Consequences of Violations

Compliance with Anti-Money Laundering and Counter-Terrorist Financing guidelines is an essential obligation for all employees, directors, business partners, suppliers, and other third parties acting on behalf of or for the benefit of Mundpay. Non-compliance with the provisions of internal policies, corporate procedures, or applicable legislation could compromise the Company's integrity, institutional reputation, and compliance with its regulatory obligations.

In this context, potential violations will be analyzed according to their nature, severity, recurrence, and potential impact on the organization, which may lead to the adoption of appropriate administrative, disciplinary, and contractual measures, without prejudice to reporting to competent authorities when required by law or when evidence of civil, administrative, or criminal illicit activities is identified.

Mundpay takes a zero-tolerance stance toward behavior that may encourage, facilitate, or conceal activities related to money laundering, terrorist financing, corruption, fraud, evasion of international sanctions, or any other practices incompatible with its ethical and compliance standards.

11. Restrictive Lists and Sanctions

As an integral part of its financial crime prevention framework, Mundpay carries out ongoing checking and monitoring procedures to identify individuals and legal entities subject to regulatory restrictions, economic sanctions, international restrictive measures, or other situations that may pose risks to the integrity of its business relationships.

These checks include querying recognized national and international databases, such as lists of Politically Exposed Persons (PEPs), economic and financial sanction programs, government restriction lists, relevant public records, and reputational monitoring mechanisms, always observing applicable regulations and the principles of the Risk-Based Approach.

The identification of relevant risk factors may lead to additional diligence measures, a review of the business relationship, the implementation of enhanced controls, or, when necessary, the rejection, suspension, or termination of the business relationship, in line with applicable legal, regulatory, and contractual obligations.

12. Review and Update

Mundpay recognizes that preventing money laundering and terrorist financing requires constant evolution in light of regulatory changes, the emergence of new financial crime typologies, and the continuous transformation of the business environment. For this reason, this Policy is subject to periodic review and update processes to ensure its alignment with legal and regulatory requirements, as well as with national and international compliance and risk management best practices.

Reviews are conducted by the Compliance Department and submitted to Senior Management for approval. They can occur more frequently than the standard cycle whenever there are significant alterations in applicable legislation, major changes in the activities carried out by the Company, the identification of opportunities to improve internal controls, or directives issued by competent regulatory authorities.

The public version of this Policy is for informational purposes only and aims to promote institutional transparency regarding the principles and guidelines that guide Mundpay's Anti-Money Laundering and Counter-Terrorist Financing Program. The complete version of the corporate regulations, including internal procedures, operational controls, and applicable governance mechanisms, is available upon formal request to the Compliance Department.