KeynoBite
Restaurant Operating Ecosystem
Legal & Compliance

Audit, Compliance Governance & Risk Escalation Policy

Operated by: Keynoverse FZC Platform: KeynoBite Contact: onboarding@keynobite.com

Operated by: Keynoverse FZC Platform: KeynoBite Contact: onboarding@keynobite.com

Primary intent: Audit, Compliance Governance & Risk Escalation Policy policy Entity: audit-compliance-governance-risk-escalation-policy

Operated by: Keynoverse FZC
Platform: KeynoBite
Contact: onboarding@keynobite.com


Part A — Compliance Governance Framework

A.1 Overview

This document is the KeynoBite Compliance Governance Framework. It describes how Keynoverse FZC governs merchant compliance, maintains audit trails, preserves records, escalates and resolves risk, and supports PSP partner and regulatory oversight.

KeynoBite operates as a non-custodial technology platform. It is not a payment service provider, merchant acquirer, payment facilitator, or merchant-of-record.

A.2 Policy Document Suite

# Document Scope
1 Merchant Onboarding & Compliance Policy KYB/KYC, eligibility, acceptable use, PSP coordination, monitoring — primary PSP submission document
2 Fraud Prevention, Transaction Security & AML Policy Fraud, transaction security, sanctions, AML — customers and merchants
3 This Policy Compliance framework, audit trails, retention, risk escalation & enforcement, regulatory cooperation

A.3 Framework Coverage Matrix

Requirement Primary Document
Risk-based merchant onboarding Onboarding Policy §7
KYB / KYC / UBO / PEP Onboarding Policy §5–6
Enhanced Due Diligence (EDD) Onboarding Policy §8
PSP coordination Onboarding Policy §9
Permitted & prohibited use Onboarding Policy §11–13
Ongoing monitoring & re-verification Onboarding Policy §14
Sanctions / AML / fraud Fraud & Security Policy
Suspension / termination / escalation This Policy — Part C
Audit logging & retention This Policy — Part B
Non-custodial positioning Onboarding Policy §2

A.4 Suggested Public URLs

Page Suggested slug
Merchant Onboarding & Compliance /page/merchant-onboarding-compliance
Fraud Prevention & Transaction Security /page/fraud-prevention-transaction-security
Audit, Compliance Governance & Risk Escalation (this document) /page/audit-compliance-governance

Minimum for PSP submission: Merchant Onboarding & Compliance URL + this URL.

A.5 Platform Capabilities Referenced

  • 9-step merchant onboarding (KB-VAPP-XXXXXX references)
  • Review states: kyc_reviewpsp_reviewapprovedpushed
  • UBO collection with PEP declarations
  • Document packages: trade license, MOA, tenancy, DEWA, premises photos, bank letter, passport, Emirates ID
  • PSP API bridge review states: pending_review, needs_correction, credential_submitted, review_completed
  • Structured audit_logs for onboarding and admin actions

Part B — Audit & Record-Keeping

B.1 Introduction

Keynoverse FZC maintains audit trails, operational logs, compliance records, and retention practices to support merchant onboarding integrity, platform security, payment partner oversight, and regulatory cooperation.

This applies to the merchant onboarding portal, restaurant operations platform, PSP onboarding API bridges, and administrative/agency activities.

B.2 Purpose

  1. Maintain reliable audit trails for onboarding, compliance, and administrative actions
  2. Support investigation and dispute resolution for merchants, customers, and PSP partners
  3. Enable risk monitoring and detection of suspicious activity
  4. Satisfy PSP partner audit and compliance expectations
  5. Preserve records for regulatory, legal, and contractual obligations

B.3 Scope of Audited Activities

Domain Examples of logged activity
Merchant onboarding Application creation, submissions, document uploads, status changes
KYC & compliance review Approvals, rejections, correction requests
UBO & document changes UBO updates, document replacements
PSP integration Review status updates, credential submissions, API key management
Authentication & access Admin/agency login events, privileged actions
Platform provisioning Merchant activation to live environment
Payment configuration Gateway credential changes (metadata only; secrets not logged)
Risk escalation Tier assignments, suspension/termination decisions, PSP notifications

B.4 Onboarding Portal Audit Logging

Structured audit logs capture timestamp (UTC), acting user ID, action type, target entity, payload summary, IP address, and user agent.

Examples: admin logins, status transitions (kyc_review, psp_review, approved, rejected, pushed), agency approvals, PSP API key rotation, escalation tier changes.

Logs are stored in audit_logs with indexed action and target fields.

B.5 Merchant Application Audit Trail

Each application maintains unique reference (e.g. KB-VAPP-XXXXXX), section statuses, UBO/PEP declarations, document timestamps, reviewer milestones, rejection/correction history, and provisioning log.

B.6 Restaurant Platform Operational Records

  • Order identifiers, status history, amounts, PSP payment status references
  • Refund and cancellation events with merchant order number integrity
  • Firebase phone authentication audit records (where enabled)
  • Admin configuration changes (roles, menus, gateway settings metadata)

B.7 PSP & Payment Partner Audit Support

KeynoBite maintains records for KYC package retrieval, PSP review tracking, secure credential handoff (secrets not in logs), order reference preservation, and refund traceability.

KeynoBite does not store full card PANs, CVV, or wallet PINs. PSPs remain the system of record for authorization and settlement.

B.8 Access Controls

Role Typical access
Merchant / vendor Own application and restaurant data
Agency / referral partner Applications they manage
KeynoBite admin / compliance Full review, audit logs, provisioning, escalation
PSP integration (API) Scoped merchant onboarding packages

B.9 Monitoring & Review

Periodic and event-driven audit review covers unauthorized access, unusual approval patterns, document inconsistencies, abnormal order/refund velocity, agency anomalies, and escalation outcomes.

B.10 Record Retention

Record type Minimum retention
Merchant KYC application packages 5 years after offboarding
Onboarding audit logs 5 years
Escalation register & investigation files Duration of matter + 5 years
PSP review and credential metadata 5 years or per PSP contract
Order and payment status records 5 years or per applicable law
Authentication audit records ≥ 2 years or as needed

B.11 Data Security & Integrity

Records protected via HTTPS/TLS, access-controlled storage, environment separation, restricted admin access, and backup procedures. Audit logs are append-oriented; corrections tracked through updated records and review notes.

B.12 Internal Audit & Compliance Review

Keynoverse FZC may internally review onboarding quality, KYC completeness, audit log coverage, escalation consistency, PSP integration compliance, and incident response effectiveness.

B.13 External Audit & Regulatory Cooperation

KeynoBite cooperates with lawful requests from licensed PSP/wallet partners, regulatory authorities, and external auditors, subject to authority verification and data protection law.

B.14 Incident Documentation

Incidents documented with identifier, affected systems, evidence reviewed, containment actions, PSP/regulatory notifications, and post-incident review.

B.15 Merchant Cooperation

Merchants must preserve business records, cooperate with audit and escalation inquiries, provide accurate information, and not tamper with records relevant to ongoing inquiries.

B.16 Limitations

KeynoBite audit records reflect platform activity. They do not replace PSP settlement records, bank statements, or merchant accounting systems.


Part C — Merchant Risk & Escalation Framework

C.1 Purpose

This section defines how KeynoBite identifies, escalates, and resolves merchant-related compliance and operational risks — from onboarding through offboarding — with consistent, documented, and auditable decision-making.

C.2 Risk Governance Structure

Function Responsibility
Platform compliance KYB review, risk scoring, EDD, periodic reviews
Master admin / operations Application status management, provisioning controls
PSP integration PSP review coordination, credential governance
Senior management High-risk approvals, termination decisions, authority cooperation

Merchant lifecycle: Application → KYC Review → PSP Review → Approved → Live → Monitor → Review/Refresh → [Suspend] → Offboard

Each stage transition is audit-logged with actor, timestamp, and rationale.

C.3 Risk Classification Summary

Merchants are classified Low, Medium, or High risk per the Merchant Onboarding & Compliance Policy §7.

Tier Review Cycle Approval Authority Monitoring
Low 24 months Compliance reviewer Standard
Medium 12 months Compliance lead Enhanced
High 6 months Senior compliance + PSP clearance Continuous

Risk tier may be upgraded immediately upon trigger events; downgrades require compliance review.

C.4 Escalation Tiers

Tier 1 — Information Request (IR)

Triggers: Incomplete documentation, minor inconsistencies, expiring license (≤30 days), low-severity profile variance.

Actions: Request correction via onboarding portal; set deadline (7–14 business days); pause PSP credential activation if applicable.

Outcome: Resolved → continue; Unresolved → Tier 2

Tier 2 — Compliance Hold (CH)

Triggers: Unresolved Tier 1 past deadline, medium-risk EDD, moderate transaction deviation, elevated complaints, PSP info request, potential sanctions/adverse media match.

Actions: Restrict payment or limit to COD; assign compliance owner; document investigation; notify PSP if channels active.

Outcome: Cleared → release hold; Confirmed risk → Tier 3

Tier 3 — Suspension (SUSP)

Triggers: Suspected fraudulent documents, confirmed sanctions/unacceptable PEP, transaction laundering, PSP credential revocation/fraud alert, prohibited category, serious policy violations, failed mandatory re-verification.

Actions: Immediate suspension of platform and/or payment access; preserve records; notify PSP; initiate investigation; notify merchant where practicable.

Outcome: Reinstatement (rare) or Tier 4 termination

Tier 4 — Termination (TERM)

Triggers: Confirmed fraud/forged docs, confirmed sanctions/prohibited business, repeated Tier 3 violations, legal/regulatory directive, PSP permanent rejection, failure to cooperate.

Actions: Permanent access revocation; credential deactivation; internal denial list entry; PSP/authority notification; records retained per Part B.

C.5 Operational Risk Indicators

Indicator Example Threshold Typical Tier
Volume variance Sustained >50% above declared monthly volume Tier 2
Refund rate Abnormally high vs. category baseline Tier 2
Chargeback rate PSP alert or threshold breach Tier 3
Onboarding velocity Multiple apps from same agency/IP Tier 2–3
Credential changes Unauthorized PSP key modification Tier 3
Authentication anomalies Repeated login failures, impossible geo Tier 2
Duplicate entity signals Matching license/IBAN/UBO on rejected apps Tier 3
Complaint clustering Multiple fraud reports in short window Tier 2–3
Undeclared branch Orders from undeclared locations Tier 2

Thresholds are internal guidelines applied with human review — not automated termination.

C.6 Re-Verification Triggers

Event-driven re-verification may escalate to Tier 1 or Tier 2: license expiry, ownership/UBO change, bank account change, new branch, business model change, PSP KYC refresh, risk tier upgrade, periodic review due date.

Failure to complete re-verification → Tier 2 holdTier 3 suspension if unresolved.

C.7 Multi-Branch & API Onboarding Escalation

Multi-branch: Undeclared branches, licensing gaps, or inconsistent premises evidence → require per-branch documentation; restrict undeclared branches.

API/agency onboarding: Audit log review of submission source; cross-reference rejected applications; elevated monitoring first 90 days. Non-compliant referral patterns → agency suspension (Tier 3/4).

C.8 PSP Coordination Escalation

PSP Signal KeynoBite Response
KYC additional info request Tier 1 — coordinate merchant response
Review delay / pending Tier 2 — hold credential activation
Credential revoked Tier 3 — suspend payment integration
Fraud alert Tier 3 — suspend + investigate
Permanent merchant rejection Tier 4 — terminate; assess platform termination

KeynoBite does not override PSP compliance decisions.

C.9 Suspicious Activity Reporting

Report to onboarding@keynobite.com with merchant/application reference, date, description, evidence (audit log IDs), and recommended tier.

Compliance maintains an escalation register with resolution status, decision maker, and timestamps. Regulated SAR obligations for payment transactions remain with licensed PSPs.

C.10 Merchant Notification & Appeals

Where practicable, merchants receive email notice of Tier 2 holds and Tier 3 suspensions with general reason category and compliance contact.

Appeals may be submitted within 14 business days to onboarding@keynobite.com with reference, point-by-point response, and supporting documentation. Appeals do not guarantee reinstatement.

C.11 Offboarding Procedure

Upon Tier 4 termination or voluntary exit:

  1. Deactivate platform access and payment integrations
  2. Retain all KYB/KYC and audit records
  3. Notify PSP to revoke credentials
  4. Add entity/UBO to internal denial list where appropriate
  5. Confirm subscription/billing cessation
  6. Retain records minimum 5 years

C.12 Escalation Documentation Requirements

Every escalation must record:

Field Required
Escalation ID / reference Yes
Merchant application ID Yes
Tier assigned Yes
Trigger description Yes
Date/time opened Yes
Assigned reviewer Yes
Actions taken Yes
PSP notifications Where applicable
Resolution date & outcome Yes
Approving authority (Tier 3/4) Yes

Part D — Policy Governance

D.1 Updates

This Policy may be updated to reflect platform changes, PSP requirements, security enhancements, or legal developments. Continued use constitutes acceptance. Reviewed at least annually and after material incidents or significant onboarding volume growth.

D.2 Contact

Channel Details
Audit, compliance & escalations onboarding@keynobite.com
Operator Keynoverse FZC
Platform KeynoBite

KeynoBite is a technology platform operated by Keynoverse FZC. This document combines compliance governance, audit and record-keeping, and merchant risk escalation controls.

The Challenge

What challenge does Audit, Compliance Governance & Risk Escalation Policy address?

Operated by: Keynoverse FZC Platform: KeynoBite Contact: onboarding@keynobite.com

The KeynoBite Approach

How KeynoBite approaches Audit, Compliance Governance & Risk Escalation Policy

Operated by: Keynoverse FZC Platform: KeynoBite Contact: onboarding@keynobite.com

Need a walkthrough?

Map Audit, Compliance Governance & Risk Escalation Policy to your restaurant setup

Book a walkthrough with the KeynoBite team to see how this area fits your operating model.