Compliance

Compliance & regulatory framework

How Wallet Partners LLC operates within card-network rules, Dominican financial regulation and the oversight of a sponsoring bank. This page summarises the programme; full policies are shared with banks and regulators under NDA.

Last updated 2026-09-08

Status. Bombero Partners is pre-launch. The controls below are being built to the standard a sponsoring bank will require and are validated before the first live transaction.

1. Regulatory map

Dominican Republic

  • Law No. 183-02, Monetary and Financial Law, and the Monetary Board's Payment Systems Regulation (SIPARD), amended August 2025. The Banco Central oversees the payment system; acquiring is performed by or under financial intermediaries supervised by the Superintendencia de Bancos. Bombero Partners will operate as program manager / payment facilitator under a licensed member bank and will register any locally required entity.
  • Law No. 155-17 against money laundering and terrorist financing, its regulations and UAF guidance: merchant due diligence, beneficial-ownership identification, transaction monitoring, record-keeping and suspicious-transaction reporting through the sponsoring bank.
  • Law No. 172-13 on personal data protection: lawful processing, security measures and data-subject rights.
  • Law No. 358-05 on consumer protection (Pro Consumidor): transparent pricing, receipts and complaint handling at the point of sale.
  • Tax. DGII rules on card-transaction withholding (Norma General 08-04 and successors) and the fuel tax regime (Laws 112-00 and 557-05, under which retail fuel bears selective and ad-valorem taxes rather than ITBIS). Withholding parameters for stations are confirmed with the sponsoring bank and tax counsel before launch.
  • Fuel sector. Only stations with a valid MICM operating resolution are eligible; the resolution and DGII registration form part of every merchant file.

United States and international

  • BSA/AML programme aligned with the sponsor's requirements and, where applicable, FinCEN registration; OFAC and other sanctions screening of all merchants and beneficial owners.
  • Card-network rules (Visa Core Rules and Mastercard Rules) for payment facilitators and sponsored merchants, including MCC 5541 (service stations) and 5542 (automated fuel dispensers), AFD authorisation and completion rules, and MATCH checks.
  • PCI DSS v4.0 as a Level 1 service provider at launch, with P2PE terminals so no cardholder data touches Bombero Partners' systems in clear text.

2. Merchant onboarding (KYB / KYC)

  • Legal-entity verification: constitutive documents, RNC, commercial registry, MICM resolution, proof of address and site photographs.
  • Identification of directors and beneficial owners at 10% or more; identity documents; PEP, sanctions and adverse-media screening.
  • Financial profile: expected monthly volume, average ticket, card-present share; bank-account ownership verification.
  • Risk rating and approval workflow: Bombero Partners prepares and recommends; the bank approves, conditions or declines. Refresh at least every two years or on trigger events.

3. Monitoring and fraud

  • Fuel rules: per-card and per-pump velocity limits, ticket caps consistent with tank capacity, duplicate detection, unusual night-time patterns and card-testing detection.
  • Portfolio monitoring against network chargeback and fraud thresholds; early-warning reporting to the bank.
  • Escalation to the bank's compliance function; suspicious-transaction reporting through the bank to the UAF and, where applicable, FinCEN.

4. Funds, settlement and reserves

  • Network settlement is received by the sponsoring bank into a program account it controls. Bombero Partners does not hold merchant funds outside that structure.
  • Settlement to merchants in US dollars, with reserves and release rules set with the bank per risk tier.
  • Daily reconciliation and monthly reporting to the bank.

5. Information security

  • Validated P2PE terminals; tokenisation; no PAN, track or CVV stored.
  • Segmented cloud environment, encryption at rest, dual-control key management, MFA for all administrative access, central logging and alerting.
  • Annual penetration testing, vulnerability management, vendor assessments and an incident-response plan with notification timelines agreed with the bank and under Law 172-13.
  • Coordinated vulnerability disclosure via security.txt.

6. Governance

  • Designated compliance officer; board-approved AML, sanctions, privacy and information-security policies; annual independent review.
  • Training for all staff and field technicians.
  • Records retained at least five years (ten where Law 155-17 requires), available to the bank and regulators; contractual right-to-audit for the bank.
  • Merchant complaints handled per the bank's terms and Pro Consumidor rules.

7. Documents available to banks

  • AML/CFT programme and risk assessment
  • Sanctions screening procedure
  • Merchant underwriting policy and file template
  • Transaction-monitoring rule set (fuel)
  • Information-security policy set and PCI DSS plan
  • Privacy programme (Law 172-13)
  • Business-continuity and incident-response plans
  • Draft sponsorship term sheet and reserve model

References

  1. Ley No. 183-02 Monetaria y Financiera (Cámara de Cuentas copy)
  2. Junta Monetaria, Res. 28 Aug 2025 — Modificación del Reglamento de Sistemas de Pago (SIPARD)
  3. Superintendencia de Bancos — Normativas

Links open on third-party sites. Figures are quoted as published; where a source gives a range we show the range. Last checked 2026-09-08.