Sanctions and Prohibited Jurisdictions Policy
Effective date: September 26, 2026
Approved by Amrish Jibodh, Director, Karma Fintech LTD, on 26 September 2026.
| Entity | Karma Fintech LTD (England and Wales, company no. 16581945) ("Karma") |
|---|---|
| Version | 1.0, effective September 26, 2026 |
| Responsible Officer | Amrish Jibodh, Founder & CEO ("Responsible Officer") |
| Next review | 12 months from the effective date, or earlier under Section 8 |
1. Purpose and scope
1.1 This Policy sets out how Karma prevents its software and services from being used by or for sanctioned persons, or by persons in jurisdictions where Karma or its partners do not permit access.
1.2 It applies to the Karma mobile app, websites, and APIs (the "Interface"), and to all directors, employees, and contractors of Karma.
1.3 Karma's operating model limits what controls can do. The Karma Wallet is non-custodial: Karma cannot sign, freeze, seize, move, or reverse users' assets. Karma's controls therefore act on access to the Interface and on transactions before a user authorises them. Fiat accounts and cards are provided by regulated partners (Bridge and Rain). Ondo tokenised securities are executed by third-party venues (Treasures and Relay). Each partner runs its own compliance programme under its own terms. Partner controls supplement Karma's controls and do not replace them.
2. Sanctions lists
2.1 Karma complies with, and this Policy covers, the following sanctions regimes and lists (together, "Sanctions Lists"):
- United States: OFAC Specially Designated Nationals and Blocked Persons List and other OFAC sanctions lists;
- United Nations: UN Security Council Consolidated List;
- European Union: EU Consolidated Financial Sanctions List;
- United Kingdom: UK Sanctions List and HM Treasury OFSI Consolidated List;
- Switzerland: SECO sanctions lists.
2.2 Karma treats a person as sanctioned if they are listed, are owned 50% or more (individually or in aggregate) or controlled by listed persons, or are located, resident, or organised in a country or territory subject to comprehensive sanctions under any regime in 2.1.
2.3 Coverage limits. Wallet screening under Section 4 is address-based. It detects only addresses that are included in the screening provider's sanctions data, which is derived mainly from designations that publish digital-asset addresses (principally OFAC). Name-based screening against all lists in 2.1 is carried out only by partners, for users who complete their KYC. Karma must not describe its own screening as covering a list unless the provider has confirmed that coverage in writing.
3. Prohibited and restricted jurisdictions
3.1 Ondo assets. Persons located or resident in any jurisdiction prohibited under Ondo's eligibility criteria (https://docs.ondo.finance/ondo-global-markets/eligibility), and U.S. persons within the meaning of Regulation S, must not acquire Ondo assets through the Interface. Karma applies this list, plus all of Ukraine and any additional jurisdictions restricted by Treasures, as its Ondo blocklist (Annex A).
3.2 Restricted jurisdictions. For the EEA, UK, Switzerland, Singapore, Hong Kong, Malaysia, and Brazil, Ondo assets are available only where the user confirms eligibility under local law and Ondo's criteria, as set out in Clause 9A of Karma's Terms of Service.
3.3 Partner services. Bridge and Rain apply their own jurisdiction lists to fiat and card services. Karma publishes the card programme list on its Prohibited Activities page.
3.4 Personnel. Karma must not maintain offices or material personnel in any Ondo-prohibited jurisdiction without prior counsel review.
4. Controls
4.1 IP geo-blocking (Ondo assets). Before any Ondo buy and any Ondo eligibility declaration, the Interface checks the request's network location, as set by the hosting edge, against the Ondo blocklist on the server side. If the location cannot be determined, the request must be refused (fail closed). Ondo catalog and detail data must not be served to requests from blocked locations. The block must apply to Ondo tokens on every supported chain and on every trading route.
4.2 Residence and eligibility declarations. Before a user's first Ondo acquisition, the user must state their country of residence and confirm, in a versioned in-app declaration, that they are not a U.S. person, not a prohibited or sanctioned person, and eligible under local law. Declarations are stored append-only with version and timestamp. A declared residence in a blocked jurisdiction refuses Ondo buys.
4.3 Wallet sanctions screening. Karma screens users' EVM wallet addresses using the Chainalysis Sanctions Oracle:
- (a) at wallet registration (creation or import);
- (b) in real time at every Ondo buy, failing closed if screening is unavailable; and
- (c) in a daily batch rescreen of registered wallets.
Solana addresses are not covered by this oracle. Karma must record that gap and must not claim Solana screening until a covering tool is deployed.
4.4 Partner screening. Bridge and Rain screen their KYC'd customers. Treasures screens wallets on quotes, trades, and bridge requests, and refuses blocked addresses. Relay refuses sanctioned wallet addresses. Karma treats a partner refusal as a potential match under Section 5.
4.5 Terms and circumvention. Karma's Terms prohibit use by sanctioned and prohibited persons, and prohibit VPNs and other location masking. Karma does not currently detect VPN or proxy use. A VPN exit located in a blocked jurisdiction is caught by 4.1.
5. Escalation and response
5.1 Potential match. Any positive screening result, partner sanctions refusal, or credible report is a potential match. The affected action is blocked automatically.
5.2 Review. The Responsible Officer reviews each potential match within one business day, decides whether it is a true match or a false positive, and records the evidence and reasoning.
5.3 True match. Karma must:
- block all Interface transaction functions for the user's Account, including any Karma-sponsored network fees (no sell-only access);
- keep the block in place until counsel confirms it can be lifted;
- notify affected partners where their agreements require it; and
- report to OFSI, OFAC, or another competent authority where required by law, on counsel's advice.
Karma must not tell the user the reason for the block where doing so could amount to tipping off or is otherwise prohibited.
5.4 Jurisdiction or eligibility cases (not sanctions). Karma may hide Ondo assets, refuse buys, or restrict the user to sell-only, as permitted by the Terms.
5.5 False positive. The Responsible Officer lifts the block and records the basis.
5.6 Control failures. If a control fails, for example geo data is missing or the screening provider is down, Ondo buys must fail closed. The Responsible Officer must log the incident and review it within five business days.
6. Recordkeeping
6.1 Karma retains the following for at least five years:
- screening results, with address, timestamp, and provider or oracle reference;
- Ondo location decisions (country, source, and outcome);
- user declarations and their versions;
- potential-match reviews and decisions;
- reports to authorities; and
- versions of this Policy and its annexes.
6.2 Records are stored with access limited to the Responsible Officer and authorised personnel, in line with Karma's Privacy Policy.
7. Training and responsibility
7.1 The Responsible Officer owns this Policy, keeps Annex A and Annex B current, and is the contact for partners and authorities on sanctions matters.
7.2 Anyone who operates or changes these controls must read this Policy on joining and after each material update.
8. Review
8.1 This Policy is reviewed at least annually. It is also reviewed:
- when a regime in 2.1 makes a material change;
- when Ondo, Treasures, Bridge, or Rain change their jurisdiction lists;
- before launching a new product, chain, or venue; and
- after any true match or control failure.
8.2 The Responsible Officer checks Ondo's eligibility page at least monthly.
Annex A: Ondo blocklist (as at September 26, 2026)
Afghanistan; Belarus; Canada; Crimea, DNR, LNR, Kherson and Zaporizhzhia regions and Sevastopol (Karma blocks all of Ukraine); Cuba; North Korea; Iran; Libya; Myanmar; Russia; Somalia; South Sudan; Sudan; Syria; United States, including Puerto Rico, Guam, U.S. Virgin Islands, American Samoa, Northern Mariana Islands and U.S. Minor Outlying Islands. Plus any jurisdiction restricted by Treasures.
Annex B: Control status (as at September 26, 2026)
This annex is updated when each item goes live.
| Control | Status |
|---|---|
| 4.1 IP geo-block on Ondo buys and declarations | Live |
| 4.1 Fail closed when location is absent | Live for Ondo buys |
| 4.1 Ondo buys gated on every chain and trading route | Live. Legacy swap routes refuse all Ondo buys |
| 4.1 Ondo catalog and detail data hidden in blocked locations | Partly live. The app hides Ondo assets unless the account has Ondo access and the request comes from a permitted location. Public catalog data is not yet filtered by location |
| 4.2 Residence check and versioned declarations | Live |
| 4.3(a) Chainalysis Sanctions Oracle at wallet import | Live |
| 4.3(a) Chainalysis Sanctions Oracle at wallet creation | Not live. New wallets are screened before any Ondo buy |
| 4.3(b) Chainalysis Sanctions Oracle at every Ondo buy, fail closed | Live |
| 4.3(c) Daily rescreen | Live for the wallets of users with an Ondo declaration, Ondo access, or an Ondo holding |
| 4.3 Solana address screening | Not live |
| 4.4 Partner screening (Bridge, Rain, Treasures, Relay) | Live (partner-operated) |
| 4.5 Terms clause on prohibited persons and VPNs | Live (Clause 9A of the Terms of Service) |
| 4.5 VPN or proxy detection | Not live |
| 6.1 Ondo location decision log | Not live |
Contact
Questions about this Policy can be sent to compliance@karmapay.xyz.