Version: 2.0
Effective date: January 1, 2020
Scope: This policy applies to all merchants and partners using TIB Finance services
1. Introduction and Objectives
This Risk Management Policy defines the framework within which TIB Finance identifies, assesses, and manages risks associated with payment services provided to all its merchants and partners. This policy aims to ensure the stability and security of our payment ecosystem while preserving service quality for all our users.
1.1 Policy Objectives
This policy aims to:
- Establish a transparent and fair framework for risk management
- Define objective risk assessment criteria
- Specify preventive and corrective measures that may be applied
- Ensure compliance with regulatory and contractual requirements
- Protect the financial integrity of the entire payment ecosystem
This policy is established pursuant to the contractual provisions between TIB Finance and its partners/merchants, including Section 7.2 of the Payment Processing Agreement which provides that TIB may, at its sole discretion, impose risk management controls in accordance with its policies in effect.
2. Types of Risks and Their Assessment
2.1 Financial Risks
Financial risks include all elements that may affect the financial stability of our payment ecosystem:
- Credit risk: Non-payment of financial obligations (service fees, chargebacks, etc.)
- Liquidity risk: Inability to meet financial obligations in a timely manner
- NSF risk: Transactions rejected due to insufficient funds
- Dispute risk: Transaction disputes by end users
2.2 Operational Risks
Operational risks relate to processes, systems, and activities associated with payment services:
- Fraud risk: Potential or proven fraudulent activities, suspicions of fraud attempts, unusual transaction manipulation
- Technical risk: Technical failures or recurring errors in the platform, repetitive errors caused by third-party software integrated into our system
- Compliance risk: Non-compliance with established procedures or regulatory requirements, abnormally long processing times for correction requests
- Volume risk: Significant and unanticipated variations in transaction volumes
- Integration risk: Repetitive errors in APIs or interfaces from third-party software integrated into our ecosystem
2.3 Risk Levels
TIB Finance assesses risks according to three severity levels, determined by objective criteria:
| Risk Level |
Indicators |
Examples of Measures |
| High |
- Repeated non-payment of service fees (all payment methods combined)
- High rate of NSF or disputes (>3% of volume)
- High rate of NSF or disputes from merchants managed by the partner
- Potentially fraudulent activities or founded suspicion of fraud attempts
- Repetitive technical errors unresolved after multiple notifications
- Recurring failures in third-party software integration
- Serious violations of contractual terms
- Persistent non-cooperation in addressing identified issues
- Systematically excessive response times to critical requests
- Poor management of merchant files resulting in financial losses
|
- Temporary suspension of services
- Mandatory switch to D+3 mode
- Security deposit requirement
- Limitation of authorized transaction types
- Review of commercial terms
|
| Medium |
- Occasional delay in fee payment
- Moderate rate of NSF or disputes (1-3% of volume)
- Recurring but non-critical technical errors
- Minor breaches of contractual terms
- Limited cooperation in resolving issues
|
- Formal notice of non-compliance
- Enhanced transaction monitoring
- Review of technical parameters
- Process improvement recommendations
- Additional training on best practices
|
| Low |
- Regular payment of service fees
- Low rate of NSF or disputes (<1% of volume)
- Quick resolution of any issues
- Compliance with contractual terms
- Proactive communication
|
- Maintenance of standard terms
- Normal monitoring
- Possibility of access to advanced features
- Eligibility for preferred programs
|
3. Risk Control Measures
3.1 Preventive Measures
TIB Finance implements various preventive measures to mitigate risks, including:
- Initial assessment: Thorough verification during the onboarding of new partners and merchants
- Continuous monitoring: Regular monitoring of activities and risk indicators
- Security parameters: Account configuration based on risk profile (D+1 vs D+3, transaction limits, etc.)
- Security deposits: Requirement of financial reserves for certain risk profiles or features
- Fraud detection: Automated systems to identify suspicious patterns and fraud attempts
- Technical error monitoring: Monitoring of repetitive errors from third-party software or integrations
- Training and documentation: Resources to help partners optimize their processes
3.2 Payment Default Management
In the event of non-payment of service fees (regardless of payment method: bank debit, credit card, wire transfer, or other), TIB Finance applies a progressive procedure from the first day of payment default:
- First reminder: Email notification upon detection of the delay (day 1 of payment default)
- Second reminder: Contact by email and phone 7 days after the first reminder
- Formal notice: Official non-compliance notification 8 days after the first reminder
- Suspension notice: Notice of intent to suspend services 14 days after the first reminder
- Effective suspension: Implementation of temporary suspension 15 days after the first reminder
- Contract termination: Definitive cancellation of the contract 30 days after the first reminder
For any credit card or other payment method transaction rejection, the procedure also applies with the same timelines, but may be accelerated in cases of repeated rejections or suspected fraud.
3.3 NSF and Dispute Management
NSF (Non-Sufficient Funds) and disputes receive particular attention:
- Any NSF or dispute is immediately reported to the relevant partner
- A high rate of NSF or disputes automatically triggers a risk level reassessment
- Fees associated with NSF and disputes are passed on in accordance with contractual provisions
- Corrective measures may be required in cases of abnormally high rates
3.3.1 NSF and Disputes from Merchants Managed by Partners
For partners who manage multiple merchants or retailers on their platform:
- NSF and disputes generated by the partner's merchants are under the partner's responsibility
- These NSF and disputes are billed to the partner in accordance with contractual provisions
- A high rate of NSF and disputes from the partner's merchants may indicate poor file management or lack of due diligence in the acceptance process
- The partner is required to implement adequate procedures to properly manage their merchants' accounts and prevent NSF and disputes
- Failure to take corrective measures to reduce recurring NSF and disputes from merchants constitutes a high risk factor that may lead to control measures
4. Suspension and Reinstatement of Services
4.1 Types of Suspension and Contractual Distinction
TIB Finance clearly distinguishes between two types of measures in its risk management:
4.1.1 Temporary Suspension of Services
Temporary suspension is a conservative measure provided for by Section 7.2 of the contract, which allows TIB Finance to impose risk management controls at its sole discretion:
- Contractual basis: Section 7.2 - "TIB may, at its sole discretion, impose risk management controls and terminate Merchant Services in accordance with TIB's current policies."
- Application timeline: May be immediate, depending on the severity of the identified risk
- Duration: Generally 1 to 30 days, depending on the nature and severity of the risk
- Scope: May apply to all services or only certain features
- Legal effect: The contract remains in force; only the provision of services is temporarily interrupted
- Objective: Allow resolution of identified issues while limiting risk exposure
4.1.2 Contract Termination
Contract termination is a definitive measure provided for by Section 12.2.1 of the contract, which ends the contractual relationship:
- Contractual basis: Section 12.2.1(a) - "A Party may terminate this Agreement immediately upon notice if the other Party commits a material breach of any term of this Agreement and, being capable of remedy, fails to remedy such breach within forty-five (45) days after being notified in writing."
- Application timeline: Requires notice and a 45-day remediation period
- Legal effect: Complete termination of the contractual relationship
- Consequences: Definitive cessation of services, settlement of amounts owed, end of contractual obligations (except provisions that survive termination)
Important distinction: Temporary suspension of services pursuant to Section 7.2 is a risk management measure that can be implemented immediately, without affecting the validity of the contract. It may precede a formal termination under Section 12.2.1, which requires a 45-day period to allow the defaulting party to remedy the breach. The two measures are complementary in risk management: suspension allows immediate action to limit risks, while the termination procedure provides a formal framework for ending the contract if necessary.
4.2 Reinstatement Conditions
Reinstatement of services after a temporary suspension is subject to the following conditions:
- Financial regularization: Full payment of amounts owed (service fees, NSF, disputes, etc.)
- Technical compliance: Resolution of technical issues that contributed to the risk
- Guarantees: Implementation of required guarantees based on risk profile (security deposit, change of payment method, etc.)
- Action plan: Commitment to preventive measures to avoid recurrence of issues
4.3 Probationary Period
After reinstatement of services, a probationary period may be established:
- Enhanced monitoring of activities during a determined period (generally 30 to 90 days)
- Temporary specific conditions (transaction limits, extended settlement timelines, etc.)
- Regular assessments to confirm return to an acceptable risk level
5. Specific Provisions
5.1 Special Conditions for D+1 Accounts
D+1 accounts (1-day settlement) have a particular risk profile and are subject to specific conditions:
- Mandatory financial reserve to cover potential risks
- Transaction history demonstrating sound management and a low incident rate
- Strict compliance with financial and contractual obligations
- Automatic switch to D+3 mode in case of default or increased risk level
5.2 Management of Multi-Transaction Accounts
For partners managing multiple merchants or transaction types:
- Separate risk assessment for each category of transactions or merchant
- Possibility of applying differentiated measures based on risk profiles
- Partner responsibility for managing risks related to their merchants
- Obligation to promptly report any detected suspicious or fraudulent activity
5.3 Processing Times and Response to Requests
TIB Finance commits to processing requests and incidents within reasonable timeframes:
- Acknowledgment of receipt of requests within 1 business day
- Processing of standard requests within 5 business days
- Response to critical incidents within 48 hours
Partners and merchants are also required to respond within reasonable timelines to TIB Finance requests concerning risk management. An excessive response time may be considered a risk factor.
5.4 Management of Repetitive Technical Errors
Repetitive technical errors, particularly those caused by third-party software, represent a significant operational risk:
- Obligation to promptly report recurring technical errors
- Implementation of a correction plan with a precise timeline
- Possible suspension of affected features in cases of persistent unresolved errors
- Possible billing of additional fees for excessive technical support required
5.5 Payment Methods and Risk Management
This policy applies to all payment methods offered by TIB Finance:
- Automatic bank debits
- Credit or debit card payments
- Electronic wire transfers
- Interac payments
- Any other payment method integrated into our services
Each payment method may present specific risks requiring adapted control measures.
5.6 Partner Responsibility for Their Merchants
For partners who provide services to their own merchants or end clients:
- Financial responsibility: The partner is fully responsible for the payment of fees, NSF, and disputes generated by their merchants
- Due diligence obligation: The partner must implement adequate procedures to verify and monitor their merchants
- File management: The partner is required to properly manage their merchants' files to prevent NSF, disputes, and other issues
- Prohibited risk transfer: The partner may not transfer to TIB Finance the risk related to poor management of their merchants
- Documentation: The partner must maintain adequate documentation concerning their merchants, readily accessible in case of dispute
TIB Finance reserves the right to require specific corrective measures from the partner if poor management of their merchants' files is identified as a source of increased risk. In case of persistent non-compliance, risk control measures may be applied until satisfactory resolution of the situation.
6. Contractual Basis and Application
6.1 Contractual Basis of Risk Management Measures
This risk management policy is based on several fundamental contractual provisions, including:
- Section 7.2: TIB Finance's right to impose risk management controls and terminate Merchant Services in accordance with its current policies, at its sole discretion and without delay
- Section 6.8: Right of set-off allowing TIB Finance to obtain amounts owed by bank debit or to require a wire transfer within one business day
- Section 12.2.1: Right of termination in case of material breach of the contract terms, with a 45-day remediation period after written notification
- Section 16.3: Partner's obligation to indemnify TIB Finance for losses incurred due to a Merchant's non-compliance with their obligations
The application of this policy is in accordance with the contractual commitments between TIB Finance and its partners/merchants. In the event of a conflict between this policy and specific contractual provisions, the latter shall prevail.
6.2 Decision-Making Process and Sequential Application
TIB Finance generally applies its risk management measures according to a progressive approach:
- Identification and notification: Risk detection and communication to the partner
- Temporary suspension of services: If necessary, immediate application of Section 7.2 to limit risk exposure
- Remediation period: Time granted to the partner to resolve identified issues
- Assessment of corrective measures: Analysis of the effectiveness of actions taken by the partner
- Final decision: Based on results, either reinstatement of services, or initiation of the termination procedure with the 45-day period provided for in Section 12.2.1
This approach allows combining the necessary responsiveness to risks (immediate temporary suspension) with contractual fairness (remediation period before definitive termination).
7. Review and Continuous Improvement
TIB Finance commits to keeping this policy up to date and adapted to market and regulatory environment changes:
- Periodic review at least once per year
- Updates based on regulatory developments or industry practices
- Continuous improvement based on incident analysis and risk evolution
Partners and merchants will be informed of any substantial modification to this policy.