Winfield LLC
1013 Centre Rd. Suite 403-A, Wilmington, DE 19805
Document Version Control
| Version ID | Approval Date | Reviewer Name/Title | Approver Name/Title | Revision Notes |
|---|---|---|---|---|
| 1.0 | June 19, 2026 | Syed Khalid | Syed Khalid | Document Creation |
1. Introduction
a. Background
Money laundering is defined as the process of covering up or "laundering" illegally obtained money to wipe away traces of criminal activity and make it appear as if it were legitimately obtained. The techniques used by money launderers constantly evolve to match the source and amount of funds to be laundered, and the legislative/regulatory/law enforcement environment of the market in which the money launderer operates. Since e-commerce and online gaming platforms can be used for money laundering ("ML") purposes, they face reputational, legal, and regulatory risks. Many companies invest large amounts of time and money to develop their business, and their reputation invariably takes years to build. However, this can be lost in an unbelievably short time if the organization becomes embroiled in an ML scandal.
Therefore, Winfield LLC (the "Company") will adopt measures to ensure that money gained through unlawful means is not channeled and laundered through the Company's platform, "SweepBurger" (the "Platform").
b. Objectives and Scope
This Anti-Money Laundering ("AML") Policy (the "Policy") is intended to define the policies and procedures implemented by the Company to prevent and effectively combat ML. By appropriately implementing this Policy, the Company will ensure that the users of its platform do not expose the Company to regulatory risks. To this end, the Company and its employees who interact with users of the Platform (hereinafter referred to as "Customers") should be aware and appropriately trained in how to recognize and address transactions and other activities that may be related to ML.
Accordingly, the objectives of this Policy are the following:
-
To raise the level of knowledge on ML and the manner in which the Company's products and services could be exploited to facilitate ML;
-
To provide awareness of the Company's AML Policy designed to assist in the detection, prevention, and deterrence of potential ML activities;
-
To provide a reference to employees of the procedures developed by the Company in relation to the implementation of its AML Policy and its legal obligations; and
-
To effectively combat ML and mitigate reputational and regulatory risks arising from ML activities.
c. Applicability
The Company is committed to identifying and mitigating ML risks emanating from its products and services. Thus, adherence to the provisions of this Policy is critical to the effective implementation of the AML program developed by the Company. Therefore, this Policy is applicable to Senior Management and all employees of the Company. Additionally, every newly onboarded employee is required to read this Policy and undergo the appropriate AML training. This Policy will also be made accessible to all employees upon request. In addition, the Company may offer periodic training to review the Policy.
The Company aims to attain company-wide awareness of its AML obligations along with an effective level of regulatory compliance commensurate with the nature and size of the business. The procedures and measures outlined herein are tailored for a remote social gaming business like the platform offered by the Company.
d. Document Updates
This document will be revised to reflect, as applicable, any regulatory updates and changes to internal procedures. The Company will identify an Anti-Money Laundering Officer ("AMLO") who will be responsible for facilitating any updates to the Policy and reviewing it regularly to ensure the Policy remains relevant to changing business and regulatory requirements. New versions of this Policy will be given a version number in the following manner "AML Policy V1.0" and saved for access to all employees.
Details regarding revised versions will be documented in the "Version Control" table preceding the Introduction of this Policy. Any material changes to the Policy will be communicated to all employees via email.
e. Disclaimer
The information contained in this Policy is confidential and for internal use only. However, the contents of this Policy may be shared with third parties (e.g., legal counsel, third-party service providers, etc.) as appropriate. Please seek your supervisor's consent before sharing the Policy.
2. Governance Framework
The Company has implemented an AML framework that encompasses appropriate governance and oversight roles, internal controls, and sound practices for the management and supervision of the risks associated with ML.
a. Senior Management Responsibility
Senior Management of the Company including but not limited to the CEO, General Counsel, Director of Finance and Director of Human Resources will support the Company's AML/Bank Secrecy Act ("BSA")/Office of Foreign Assets Control ("OFAC") efforts by creating a culture of compliance, including by remaining fully engaged in the implementation of this Policy. Accordingly, Senior Management will:
-
Allocate proper resources to support the compliance function;
-
Maintain compliance with all applicable AML/BSA/OFAC laws;
-
Create internal awareness of ML and terrorist financing risk;
-
Provide avenues for all employees to detect, deter, and internally refer incidents of unusual activity, especially suspected ML and terrorist financing;
-
Assist with the assessment of risks and the application of appropriate risk-mitigating controls; and
-
Assist the AMLO in updating this Policy as necessary to ensure compliance with relevant regulatory obligations.
b. AML Officer
The Fractional Compliance Officer has been designated as the AMLO. The AMLO has the authority to act independently in carrying out his or her responsibilities and will be provided with access to sufficient resources to carry out his or her duties.
The AMLO has knowledge of the ML risks associated with the Company's operation and understands applicable federal regulations. The AMLO is responsible for effectively developing, implementing, overseeing, and managing the AML program within the Company. To this end, the AMLO's duties may include the following:
-
Communicating with Senior Management about the effectiveness of this Policy;
-
Maintaining records created in accordance with this Policy;
-
Receiving internal disclosures and determining whether these should be communicated to the appropriate governmental authorities and/or outside counsel;
-
Training employees to ensure they are aware of the AML Policy.
The AMLO is also responsible for monitoring changes in the law and federal regulatory scheme that could impact the Company's AML program. The AMLO will be responsible for apprising employees of such changes and ensuring that the Policy and employee training accurately reflect the current state of the law.
If any AML-related tasks are delegated in the business, the AMLO will remain responsible for supervising the employee to whom the task has been delegated.
c. Employees' Responsibilities
All employees will be trained to follow this AML Policy and to carry out the AML measures described herein. Employees must provide notice to the AMLO of any knowledge or suspicion of ML, whether by Customers or other employees.
In addition to the measures otherwise described in this AML Policy, employees are expected to:
-
Be familiar with this AML Policy and the policies and procedures described herein;
-
Complete all assigned compliance training;
-
Protect Customer information in accordance with this AML Policy, AML training, and all other Company policies regarding Customer information protection;
-
Adhere to the Company's record retention schedules;
-
Refer any unusual and all suspicious activity to the AMLO;
-
Maintain, as strictly confidential, the filing or potential filing of any disclosure provided to the Government/applicable regulatory authorities; and
-
Cooperate with law enforcement as directed by the Company's General Counsel, compliance personnel, or outside counsel.
Any employee's failure to disclose knowledge or suspicion of ML or to otherwise carry out the measures set forth in this AML Policy will result in disciplinary action, which may result in termination. Any employee who engages in illegal acts related to ML or egregious violations of or repeat non-compliance with the AML Policy may be terminated.
d. Potential Consequences of Non-Compliance
The Company recognizes that failure to comply with applicable AML laws and regulations can result in the imposition of substantial civil and criminal penalties on the Company and/or its individual employees. Penalties for criminal violations may include fines, imprisonment, and forfeiture actions. In addition, failure to comply with the requirements of this Policy may result in termination of employment. Adherence to this Policy will be taken into account in an employee's annual performance evaluation, to the extent it is applicable to the employee's position and responsibilities. Non-compliance with applicable AML laws and regulations can also expose the Company to severe reputational damage.
e. Review of the Policy
The Company will conduct an audit of the AML Policy on an annual basis. The results of this audit will be communicated to the AMLO. The AMLO will determine, based on the results of the audit, whether changes need to be made to the substance or implementation of the Policy.
3. AML Framework
a. Money Laundering in Practice
Money laundering is defined as the process of covering up or "laundering" illegally obtained money to wipe away traces of criminal activity and make it appear as if it were legitimately obtained. When criminal activity generates substantial income, the individual or group involved must find a way to channel the proceeds of the crime through the financial system without attracting attention to the underlying activity or the persons involved. Criminals do this by disguising the sources, changing the form, or moving the funds to a place where they are less likely to attract attention. If undertaken successfully, money laundering allows criminals to maintain control over and enjoy their ill-gotten proceeds.
Money launderers seek to exploit the facilities of the world's financial institutions and e-commerce platforms to benefit from the proceeds of their criminal activities. The increased integration of the world's financial systems, the removal of barriers to the free movement of capital, and technological developments have enhanced the ease with which criminal money can be laundered, thereby complicating the tracing process.
There are two main forms of money laundering in the digital/e-commerce sector:
-
Exchanging money, assets, goods, and property that were acquired criminally for money or assets that appear to be legitimate or "clean." This is achieved by transferring or passing the funds through some form of legitimate business transaction or structure.
-
Using criminal proceeds to fund leisure activities and/or purchases.
b. Overview of the Structure of the AML Program
This AML Policy is governed broadly by AML regulations as well as a "best practices" approach to AML. At the heart of these laws and practices is a risk-based approach to identify, assess, mitigate, and manage potential ML risks within the Company. ML risks may vary from one sector to another and from one business platform to another. Therefore, to ensure that the AML measures, policies, controls, and procedures are effective, the applicable regulations oblige businesses in potentially high-risk sectors to implement measures on a risk-sensitive basis through the adoption of a risk-based AML policy. This requires the Company to (1) identify and assess the ML risks it is exposed to; and (2) adapt these measures, policies, controls, and procedures in a way that ensures that resources are applied where they are most needed.
A Customer-specific risk assessment will be carried out so that the Company is able to identify potential risks of engaging in a business relationship with a particular Customer. This assessment enables the Company to develop a risk profile for the Customer, categorize the ML risk posed by the Customer, and implement AML measures and procedures that are commensurate to the risk posed by the Customer.
We note that currently, AML statutes and regulations neither directly address nor explicitly apply to sweepstakes-style gaming platforms, such as the Platform offered by the Company. Nevertheless, the Company understands that there may be inherent risk in any online platform that engages in financial transactions with consumers, and, therefore, has adopted this Policy in an effort to mitigate the risk of ML and other suspicious activity.
The advent and popularity of virtual currency has resulted in increased scrutiny from law enforcement and regulators. As a result, regulatory restrictions and obligations are constantly evolving. The Company is mindful of this dynamic regulatory environment and, accordingly, adopts a fluid approach to its AML Policy – allowing for flexibility to adapt and update the Policy as needed. The Company will consult with outside counsel as needed to ensure it remains abreast of all developments and any resulting regulatory obligations that may arise.
4. The AML Policy
a. Customer Registration and Know Your Customer ("KYC") Protocol
The Company will take appropriate steps to obtain relevant identifying information from Customers who are utilizing the platform. To this end, to engage with the Company's platform, SweepBurger, each new Customer must register by creating an account. To create an account, users must provide their email address and create a password. There is no cost to create an account. Customers must verify their email in order to be granted full access to the Platform (e.g., gameplay, purchases, etc.).
Users must be physically located in one of the permitted states and not in an excluded state. By creating an account on the platform, the user must agree to be bound by the Company's Terms of Service, Sweeps Rules, and Privacy Policy. The Terms of Service require all users to be at least 18 years of age or older to play on the platform (and over 21 in certain states). Customers located in an excluded jurisdiction are not permitted to participate in the games on the Platform. No underage Customers will be permitted to play on the platform. The Company is committed to preventing underage people from using its platform and will take all necessary steps to ensure they are not permitted to create an account.
Verifying Customer Identity
Users are required to verify their identity in order to request redemption of Burger Coins. The Company will use a third-party services (Veriff) for its identity verification needs. To complete the verification process, the Customer will be required to submit their (1) full name; (2) date of birth; and (3) address. The Customer may also be required to provide proof of identification, proof of address (through photos of their Government ID or passport), and/or proof of source of funds. Users will be advised that the information requested is being collected in order to verify their identity for security purposes.
The Company's Terms of Service explicitly reserve the Company's right to conduct identity verification checks and to request identification documentation, such as a government-issued identification, a utility bill that matches the address registered to the Customer's account, and/or source of wealth or source of funds documentation such as a pay slip or bank statement. The Company also reserves the right to use third-party service providers to run external identification, liveness verification, location verification, and other verification checks.
If a Customer refuses to provide the information described above when requested, or appears to have intentionally provided misleading information, the Company will not allow the Customer to create an account and/or will delete any existing account associated with the Customer. In either case, the AMLO will be notified and will determine whether the situation should be disclosed to appropriate authorities or counsel.
Each Customer's KYC information will be kept for five years from the end of the business relationship or the Customer's last visit to the platform.
Customer Geolocation
Upon login, a Customer's login location (IP address) will be recorded via a third-party geolocation system. Based on the location returned, the appropriate experience will be made accessible to the Customer. Customers who are in "blocked" jurisdictions will not be permitted to access and engage with the platform.
Sanctions Name Screening
The imposition of economic sanctions against foreign countries remains an important instrument for the international community in the enforcement of laws related to money laundering and fraud. Sanctions can encompass a wide variety of measures, which include limitations on official and diplomatic contacts or travel, and the imposition of legal measures to restrict or prohibit trade or other economic activity. The Company has an obligation to abide by these economic sanctions, to aid in the enforcement of these laws, and to meet applicable regulatory requirements.
To this end, the Company will periodically review the U.S. Treasury Department's OFAC Specifically Designated Nationals and Blocked Persons List (the "Designated Persons List"). Customers' names will be compared against the OFAC Designated Persons List both (1) at the time the Customer's account is created/verified; and (2) at regular intervals, to be determined by the AMLO. If a Customer's name is listed on the Designated Persons List, he or she will not be permitted to create and/or maintain an account with the Company, and the AMLO must be immediately notified. This process is described in further detail below.
Politically Exposed Persons Screening
At both (1) the time the Customer's account is created and (2) regular intervals to be determined by the AMLO, the Company will assess whether any Customers qualify as Politically Exposed Persons ("PEPs"). According to a Joint Statement on Bank Secrecy Act Due Diligence Requirements for Customers Who May Be Considered Politically Exposed Persons, published in 2020, the BSA and other AML regulations do not define the term "politically exposed persons," but the term is commonly used to refer to foreign individuals who are or have been entrusted with prominent public function, as well as their immediate family and close associates. By virtue of this public position or relationship, these individuals may present a higher risk that their funds may be the proceeds of corruption or other illicit activity. The level of risk associated with PEPs, however, varies and not all PEPs are automatically higher risk. Rather, the level of risk depends on facts and circumstances specific to the Customer relationship. U.S. public officials are not included within the definition of a PEP.
If a Customer is found to be a PEP at any time, the AMLO must be notified. This process is described in further detail below. With advice from the AMLO (and outside counsel if appropriate) Senior Management will determine whether that person may create and/or maintain an account with the Company or if the account should be restricted in any way.
b. Customer Risk Assessment
The Company will conduct a Customer Risk Assessment (1) at the creation of the Customer's account; and (2) at periodic intervals (to be determined by the AMLO). The Company will carry out a Customer Risk Assessment with the objective to:
-
Assess a Customer's ML risk and create an appropriate risk profile;
-
Determine the level of due diligence that would be appropriate with the Customer's identified level of risk;
-
Determine the frequency for ongoing monitoring and Customer information updates;
-
Ascertain the level of management review and approval required for an ongoing relationship with the Customer.
Extreme and High-Risk Customers
Extreme Risk
Customers with information that has been confirmed by law enforcement agencies to be part of or affiliated with organized crime groups or are a positive match to a sanctions list are to be rated as Extreme Risk. If the Company becomes aware of this information, the business relationship is to be terminated immediately based on extreme ML risk.
If a Customer is identified and confirmed as a positive match for the OFAC Designated Persons List, the user account will not be created or will be terminated if already created, with the Company's AMLO immediately informed. The AMLO will consult with legal counsel to identify and comply with all necessary disclosure requirements.
High Risk
Any Customer that engages in any of the following behaviors will be categorized as High Risk and subject to Extra Due Diligence ("EDD") procedures:
-
The Customer's deposits or withdraws the equivalent of $10,000 or more within a 24-hour-period;
-
The Customer deposits or withdraws the equivalent of $5,000 within a 24-hour period and engages in other suspicious activities (such as those listed below);
-
The Customer makes a small purchase (below a particular threshold – e.g., $45) followed by a large purchase. This pattern is indicative of a bad actor testing the validity of certain funds and then proceeding to purchase a larger amount after validity is confirmed;
-
The Customer engages in IP shifting;
-
The Customer demonstrates unusual velocity in his or her activity. This means that the Customer changes the volume or value of transactions in a manner that is inconsistent with previous history or the Customer's "norm" or expected behavior;
-
The Customer requests that their funds be sent to several different accounts;
-
The Customer engages in an unusual withdrawal pattern such as artificially splitting redemptions to remain "below the radar." For example, splitting a redemption of $2,000 into four redemptions of $500 within a short period of time with the hope of avoiding a request for further identification;
-
The Customer is identified as a PEP and Senior Management, in consultation with the AMLO, determine that Customer to be a high risk.
Employees responsible for Customer and transaction monitoring should seek guidance from the AMLO if they identify a pattern of behavior that is not listed above but is otherwise potentially suspicious. The AMLO, relying on applicable laws, regulations, and internal policies, will determine whether the identified behavior should be considered "High Risk," and whether, as a result, (1) Enhanced Due Diligence procedures should be applied; (2) the user should be required to provide proof of source of funds or other documentation; (3) the Company should disclose the Customer's behavior to applicable regulatory authorities; or (4) the Customer's account should be closed and the business relationship should be terminated.
The AMLO will be responsible for determining whether High Risk Customers – i.e., those subject to EDD, will be required to provide evidence of the source of their funds before being permitted to withdraw funds from their account. The AMLO will determine the appropriate forms of documentation that may be provided as evidence of a source of funds. If the AMLO determines that proof of source of funds is required, the High Risk Customer will not be permitted to make a withdrawal from his or her account until the Customer provides verification of his or her source of funds. Failure to provide the requisite proof of source of funds will result in the termination of the Customer's account. The AMLO will assess whether it is appropriate to report the Customer to appropriate authorities.
c. Customer Due Diligence
By adopting a risk-based approach, the Company can determine the extent of due diligence required on a risk-sensitive basis. A risk-based approach also helps the Company to direct resources proportionately in accordance with the ML risk posed.
Customer Due Diligence ("CDD") includes ongoing monitoring of business relationships and transactions (discussed below) to identify suspicious activity or patterns to be recorded, maintain and update Customer information, and, if warranted, report the Customer to appropriate Governmental authorities.
If, while conducting CDD, an employee identifies user behavior that is deemed suspicious, he or she should communicate the behavior and the user to the AMLO. The AMLO will review the disclosure and determine whether (1) no further action is required; (2) the Customer should be labeled as High Risk; or (3) the business relationship should be terminated. These processes are outlined in further detail below. The AMLO is also encouraged to consult with legal counsel regarding any applicable reporting obligations.
d. Enhanced Due Diligence ("EDD")
The Company must apply extra measures and controls to mitigate/manage the risk associated with High Risk Customers. The Company must apply EDD to Customers rated as High Risk, which requires the following:
-
Regularly reviewing Customer's transaction history and Customer trends to identify patterns that require further examination;
-
Regularly reviewing Customer's login history and IP addresses;
-
Regularly assessing a Customer's use of funds for unusual trends.
-
Conducting further investigation of the Customer's identity that may require the Company to contact third parties (e.g., financial institutions);
-
Requesting additional document from the Customer (e.g., proof of source of funds);
-
Freezing the Customer account/prohibiting redemption and withdrawal until further verification procedures are conducted to the Company's satisfaction.
Actions taken pursuant to EDD procedures will be documented, and the records of such will be kept for five years. Furthermore, the Company will keep accurate records of which Customers are categorized as High Risk and subject to EDD procedures.
If an employee believes, through the process of conducting EDD, that a Customer is engaged in suspicious activity, he or she should disclose the suspicious activity to the AMLO. The AMLO will consider the disclosure in light of all relevant information to determine whether or not to (1) consult legal counsel; and/or (2) report the suspicious behavior to the appropriate regulatory authorities.
All relevant staff understand that they are strictly prohibited from informing a Customer that their account activity has triggered a report to the authorities. Employees are trained to understand that they must not inform or warn a Customer that their transactions have been reported, either internally or externally.
Customers not assessed as High Risk do not require EDD.
e. Periodic Monitoring
The Company is required to appropriately monitor all business relationships it has with Customers as part of its normal due diligence practices. The purpose of ongoing monitoring is the following:
-
Ensure that all Customer information is accurate and current;
-
Continuously monitor Customer transaction activity for unusual behavior and potentially suspicious activity (see further details below); and
-
Adjust the Customer's risk profile as needed.
Customer information must be kept up to date. This includes information that is retained by the Company from the Customer, including the following:
-
Name
-
Date of birth to confirm that the Customer is over 18 years of age
-
Email
-
Name screening for OFAC sanctions
-
Name screening for PEP determination
The Company will, at regular intervals, request verification from the Customer that their personal information (e.g., name, address, date of birth, phone number, etc.) is accurate.
f. Ongoing Transaction Monitoring
As part of its Customer due diligence practices, the Company will have adequate controls in place to regularly monitor Customer activities for red flags and triggers.
The Company will monitor Customer activities for unusual/strange patterns of behavior and suspicious activities that must be further investigated. The Company will have procedures in place to raise unusual transaction activity to the AMLO and the associated risk management team. All reviews and investigation actions must be documented.
The following factors should be considered during the review of unusual transactions:
-
Account activity history;
-
Age of the account;
-
Transactions preceding purchases;
-
Average spend amount of the Customer;
-
Average Customer activity time on the platform;
-
Account dormancy period;
-
Login history;
-
IP address;
-
Velocity of activity;
-
Source of funds; and
-
Previous alerts or warnings on the account.
If after considering the above factors, and based upon the employee's training, the employee believes that the Customer is engaging in suspicious activity, the employee should communicate this information to the AMLO. The AMLO will consider the disclosure in light of all relevant information to determine whether or not to (1) consult legal counsel; (2) report the suspicious behavior to the appropriate regulatory authorities; or (3) label the Customer as High Risk and implement the appropriate protocol.
Customers will be advised that their transactional behavior is subject to review by the Company's risk management team, and that pursuant to this monitoring, the Company reserves the right to freeze or cancel the account based on identification of suspicious activity.
g. Escalation Process
The AMLO is responsible for receiving and reviewing disclosures submitted by employees regarding suspicious activity, behavior, or Customers. The AMLO must review the disclosure and determine the appropriate response – i.e., adjustment of the Customer's risk profile, restrictions on the Customer's account, imposition of EDD protocol, no further action, or termination of the Customer account. If the AMLO believes that termination of the account may be warranted, he or she should consult with Senior Management to determine whether the Customer relationship should be terminated. If a Customer relationship is terminated, the AMLO may consult with counsel to determine if any reporting obligation apply.
5. Collusion and Cheating
The Company has systems to detect cheating, collusion, and illegal activity. If cheating and/or collusion is identified, the Customer's account will be terminated and, if appropriate, the Customer will be reported to the authorities. If an employee is implicated in any cheating, collusion, or other illegal activity, they will be suspended pending a full investigation.
6. AML Training Program
One of the most important controls over the detection and prevention of ML activities is for the Company to have employees who are knowledgeable in ML risks and who are well trained in the identification of unusual activities or transactions that appear to be suspicious. The effectiveness of AML training is therefore an important component to the overall success of the Company's AML Policy.
The Company will implement AML training that advises employees of this Policy. AML training is required for all personnel whose duties require knowledge or involve some aspect of BSA/AML compliance, including those whose duties involve Customer interaction, management of Customer accounts, etc., and senior management. These employees are required to complete the AML training at the time of new-hire onboarding (prior to any Customer interaction or fulfillment of any AML-related activities). Employees may also be required to engage in ongoing/periodic "refresher training" as needed. The frequency of refresher training is to be determined by the AMLO.
a. Form of Delivery
Employees will be advised of the contents of this Policy at the time of hire and as part of new-hire onboarding. The AMLO will determine the appropriate medium through which any additional information with regard to this Policy should be communicated to new employees.
Records of training completion, including the date of the training, will be kept in each employee's personnel file.
b. Frequency of Training
There will be two instances when AML training is to be conducted:
-
New Employee Onboarding: New hires are required to complete training at the time of onboarding.
-
Ongoing Training: Periodic training sessions will occur at regular intervals to refresh employee familiarity with this Policy and all applicable regulations. The purpose of ongoing training is to ensure all employees are familiar with any updates made to applicable federal regulations or to this Policy.
c. Training Content
The AML training material will cover the substance of this Policy which includes the following:
-
Background on AML concepts and requirements:
-
What is ML?
-
The manner in which the Company could be vulnerable to ML activities.
-
-
Governance role and oversight:
- Roles and responsibilities of the Company's AMLO and associated risk-management team.
-
AML Policies and Procedures:
-
Policies and procedures developed by the Company.
-
Roles and responsibilities of the Company's employees in detecting and deterring ML.
-
-
Risk Assessment and high-risk Customer management:
-
Provide an overview of high-risk areas.
-
Provide an introduction to risk-based approach and risk assessments.
-
7. Record Keeping
a. Requirements
The Company will maintain records of the actions taken to adopt and implement the risk-based approach outlined in this Policy, which include the following:
-
A copy of the Company's most recent AML Policy;
-
Records of employees who have undergone AML training;
-
A list of jurisdictions in which the Company operates;
-
Any audit reports or assessments dealing with AML issues;
-
Customer KYC information;
-
An accurate list of Customers identified as Extreme High Risk (even if the Customer's account is ultimately terminated);
-
An accurate list of Customers categorized as High Risk and subject to EDD procedures;
-
All reviews and investigations conducted as part of the Company's ongoing Customer and/or transaction monitoring practices;
-
Correspondence between the AMLO/compliance department with staff members relating to AML issues (including communications providing notice of suspicious activity);
-
Documentation related to the AMLO's treatment of potentially high-risk Customers (e.g., whether to subject them to EDD);
-
Any documentation of disclosures/reports made to regulatory authorities;
-
An accurate list of Customers whose accounts have been terminated (or otherwise prevented from being allowed to establish an account) due to AML concerns or being rated as Extreme High Risk.
The records should be kept for at least five years. Customer information should be kept for at least five years from the end of the business relationship or the Customer's last visit to the platform. Furthermore, Customer verification and KYC material must be maintained in line with the Company's internal data protection process.
8. Audit
On an annual basis the Company will engage in an audit to review the AML Policy. The review is intended to evaluate the Company's AML Policy and to provide an evaluation on the effectiveness and adequacy of the AML Policy and resources (employees and systems), considering the size, complexity, and offerings of the Company.