InovaNexo InovaNexo ← Back to site
Legal

Compliance

Last updated 8 September 2026

Draft pending legal and compliance review. This page describes an intended compliance posture and has not yet been verified against the programme as operated. Every statement must be confirmed accurate before publication — describing controls that are not in place would be worse than saying nothing.

We work with sectors other providers decline. That only works if the underwriting behind it is serious. This page describes how we approach financial crime compliance and what we expect from merchants.

1. Regulatory framework

Payments in Brazil operate inside a well-defined regulatory perimeter. The framework most relevant to our activity includes:

Where we route transactions through a Banking Partner, that institution's own regulatory obligations also apply to your account. Our onboarding is designed to satisfy both our requirements and theirs, which is why we ask for documentation in the form they expect.

2. Our AML and CFT programme

We operate a risk-based programme covering customer identification and verification, risk assessment and classification, ongoing due diligence, transaction monitoring, sanctions screening, suspicious activity reporting, record keeping, staff training and independent review. Risk is assessed on the sector, jurisdictions, ownership, product mix, expected volumes and distribution model of each merchant, and determines the depth of diligence applied and the frequency of review.

3. Merchant due diligence

Before a merchant can transact, we complete know-your-business checks. Depending on risk these cover:

Enhanced due diligence applies where risk is higher — for example complex or opaque ownership, higher-risk jurisdictions, PEP involvement, or a sector with elevated chargeback or fraud exposure. We may decline an application, and we may decline without giving detailed reasons where explaining would prejudice a legal or regulatory obligation.

4. How we underwrite high-risk sectors

CFD and trading platforms are our core book. We treat them as a sector with specific, well-understood risks rather than as an exception to be handled case by case, which is what makes it possible to support them consistently.

Supporting a sector is not the same as supporting every business in it. We decline businesses whose licensing, conduct or transparency does not meet the standard our Banking Partners require.

5. Sanctions and PEP screening

We screen merchants, their beneficial owners, directors and authorised representatives against applicable sanctions and watchlists at onboarding and on an ongoing basis, and we screen for politically exposed persons and close associates. Screening covers the lists we are required to apply and those our Banking Partners require, including United Nations and applicable national and regional regimes.

A positive match is reviewed before any action is taken. Where a genuine match is confirmed, we will not onboard the merchant, or will suspend an existing relationship, and will make any report the law requires. PEP status does not automatically mean refusal; it triggers enhanced due diligence and senior approval.

6. Transaction monitoring and reporting

Transactions are monitored for patterns inconsistent with the merchant's expected profile — unusual volumes or velocity, structuring, mismatches between stated and observed business activity, unexpected counterparties or geographies, and indicators of transaction laundering.

Alerts are reviewed by our compliance function. Where review does not resolve a concern, we report to COAF within the timeframes set by law. Brazilian law prohibits tipping off: we will not tell a merchant that a suspicious activity report has been made. A merchant may be asked for further information, or may have activity restricted, without being given the reason.

7. Record keeping

We retain identification records, due diligence files, transaction data and the supporting documentation for our reports for the minimum periods required by Brazilian anti-money-laundering and payments legislation, calculated from the end of the relationship or the date of the transaction, and for longer where an investigation, audit, regulatory request or legal claim requires it. Retention continues after a merchant relationship ends, and a request to delete data does not override it.

8. Governance and training

Responsibility for the compliance programme sits with a designated officer with direct access to senior management. Staff receive training on financial crime, sanctions, data protection and confidentiality when they join and periodically thereafter, proportionate to their role. Policies are reviewed at least annually and whenever there is a material change in law, in our Banking Partner arrangements, or in the risks we face.

9. Data protection

Compliance processing involves personal data, and it is handled under the LGPD like any other processing we carry out. Where we process data to meet an anti-money-laundering obligation we act as controller and rely on compliance with a legal obligation as our basis, which means some data subject rights — deletion in particular — are limited. Our Privacy Policy explains this in full.

10. Regulatory and law enforcement requests

We respond to lawful requests from the Banco Central do Brasil, COAF, tax authorities, courts and law enforcement. We check that a request is valid and properly served, provide only what is required, and keep a record of what was disclosed. Where we are legally permitted to notify the merchant, we do; frequently we are not.

Requests should be directed to operations@inovanexo.com.

11. Reporting a concern

If you believe an account is being used for fraud, money laundering or any other unlawful purpose, tell us at operations@inovanexo.com. Reports can be made anonymously. We investigate every report and do not tolerate retaliation against anyone who raises a concern in good faith.