KYC/AML
Company policy
Purpose
The Anti-Money Laundering (AML) and Know Your Client (KYC) policy established by Changebox Limited, registered in the British Virgin Islands (hereinafter the “Company” or “We”), is intended to identify, prevent and suppress money laundering and terrorist financing activities. The purpose of this policy is full compliance with the requirements of the British Virgin Islands Financial Services Commission (hereinafter — the BVI) set out in the Anti-Money Laundering Regulations, 2008 and the Anti-Money Laundering and Terrorist Financing Code of Practice, 2008. This policy is aimed at creating reliable processes for identifying clients, verifying their identity, monitoring operations and reporting suspicious activity.
Terrorist financing may be associated not with proceeds from criminal activity but with an attempt to conceal either the origin of the funds or their intended use, which may be directed at criminal purposes. Legitimate sources of funds are a key difference between terrorist financiers and traditional criminal organizations. In addition to charitable donations, legitimate sources include sponsors from foreign governments, business ownership and personal employment. Although the motivation of traditional money launderers and terrorist financiers differs, the actual methods of financing terrorist operations may be the same as or similar to the methods used by other criminals to launder money. Financing terrorist attacks does not always require large amounts of money, and the operations associated with them may be uncomplicated.
This policy, procedures and internal controls are designed to ensure compliance with all applicable norms and rules and will be regularly reviewed and updated to ensure that appropriate policies, procedures and internal controls are in place, taking into account both changes in regulations and changes in our activities.
Scope of application
This policy applies to all employees, officers, directors, contractors and agents of the company. It covers all aspects of the company's activities, including payment processing, electronic funds transfers, money transfer services, cryptocurrency operations and any other services related to financial activity.
Commitments
The Company strives to implement a strong culture of legal compliance throughout the organization. The Company recognizes the importance of combating financial crime and ensuring that operations comply with current legislation, contributing to strengthening trust and integrity in the financial ecosystem.
Legal and regulatory framework
Overview of the main regulatory acts
- The Proceeds of Criminal Conduct Act, 1997 (as subsequently amended, the “POCA”) — criminalizes money laundering and grants law enforcement authorities the powers to investigate, prosecute and seize/confiscate assets associated with criminal activity.
- The Anti-Money Laundering Regulations, 2008 (as subsequently amended) — establish the baseline obligations for “relevant persons”: the need to carry out CDD, risk assessment, record keeping and the appointment of responsible officers (MLRO, MLCO).
- The Anti-Money Laundering and Terrorist Financing Code of Practice, issued on the basis of the aforementioned Regulations, — sets out detailed requirements for risk assessment, customer due diligence (CDD), ongoing monitoring of business relationships, identifying and reporting suspicious activity, and record keeping.
- The Beneficial Ownership Secure Search System Act, 2017 (the “BOSS Act”, as amended) — requires registered agents to collect and store information about the beneficial owners of BVI companies in a secure database accessible to regulatory and law enforcement authorities. As part of its obligations to the United Kingdom, the BVI is carrying out a phased transition to a more open register of beneficial owners; the current status and the scope of public access must be clarified separately, as this area is actively changing.
- UN sanctions regimes are implemented through acts such as the Anti-Terrorism (Financial and Other Measures) (Overseas Territories) Order, extending to the BVI the obligations to freeze the assets of persons and organizations included in the UN Security Council sanctions lists.
- The Financial Action Task Force (FATF). The Financial Action Task Force (FATF) is an intergovernmental body established in 1989 that sets international standards and promotes the effective implementation of legal, regulatory and operational measures to combat money laundering, terrorist financing and other related threats to the integrity of the international financial system. The FATF also monitors the implementation of its standards — the 40 “FATF Recommendations” — by its members and ensures that all FSRBs correctly apply the “FATF Methodology” for assessing compliance with the FATF Recommendations.
Definitions of key terms
Providing information to federal law enforcement authorities and other financial institutions
In response to a request concerning accounts and operations, the company immediately searches our records to determine whether the company maintains any accounts for, or has conducted any operations with, each individual, legal entity or organization specified in the request.
If the company searches our records and does not find a matching account or operation, we will not respond to the request. We will keep documentation that we carried out the check.
We will not disclose the fact that law enforcement authorities or other financial institutions have requested or received information from us.
The company will direct any questions we have in connection with a request to the requesting federal law enforcement authority specified in the request.
The Company's legal obligations
The Company must fulfill the minimum legal obligations established by the BVI Financial Services Commission:
- Identify, assess and understand risks;
- Determine the scope of and take the necessary due diligence measures;
- Appoint a person responsible for compliance in accordance with the requirements of the relevant authority;
- Create adequate management and information systems, internal controls, policies and procedures to reduce risks and monitor their implementation;
- Establish indicators for identifying suspicious operations;
- Report suspicious activity and cooperate with the competent authorities;
- Promptly apply the directives of the competent authorities;
- Maintain proper records.
Risk assessment
Risk-based approach (RBA)
The Company applies a risk-based approach (RBA), which involves carrying out periodic risk assessments (at least once a year, or more frequently if significant changes occur) to identify potential money laundering and terrorist financing (ML/TF) risks. When carrying out such assessments, a standardized methodology is used to ensure consistency and traceability. The results of these assessments are reviewed and approved by the person responsible for legal compliance and are documented.
The Company applies an approach based on risk assessment, within which special attention is paid to understanding and prioritizing clients based on their risk profiles. This approach includes:
- Carrying out periodic risk assessments to identify potential risks associated with ML and TF.
- Adapting KYC procedures to the assessed risk of each client.
Risk factors
To determine the level of risk associated with each client, the following risk factors are assessed:
Client risks: Age, occupation, geographic location, nature of business and history of previous operations.
Client-related risks, the factors of which depend on the person participating in the transaction. These factors may include:
- Whether the client is a PEP, a family member of a PEP or a known close associate of a PEP;
- the Client's residency, including whether the Client is registered in a low-tax jurisdiction;
- whether the Client is included in international sanctions lists;
- circumstances (including those identified during previous business relations) arising from the experience of communicating with the Client, representatives and any other similar persons;
- whether the origin of the Client's assets or the source and origin of the funds used to carry out the transaction can be easily determined;
- The type and features of the Client's activity;
- the possibility of classifying the Client as a “typical Client”; and
- problems in carrying out Client identification procedures.
Product/service risks: The complexity of the product, the anonymity of the services offered and the presence of cash operations.
Geographic risks: factors arising from differences in the legal environment of different countries; these factors may include the situation where the Client is located in a jurisdiction that is:
- a country that, according to reliable sources such as mutual evaluations, detailed assessment reports or published follow-up reports, does not have effective anti-money-laundering or counter-terrorist-financing systems;
- a country in which, according to reliable sources, there is a significant level of corruption or other criminal activity, such as terrorism, money laundering, or the production and supply of prohibited drugs;
- a country subject to sanctions, embargoes or similar measures adopted, for example, by the European Union or the United Nations;
- a country that provides financing or support for terrorism;
- a country in whose territory organizations designated by the BVI or international organizations as terrorist organizations operate.
Transactional risks: Patterns of operations that may indicate high volatility, unusual frequency or large amounts inconsistent with the client's profile.
Risk assessment process
The risk assessment process includes:
- Initial risk assessment: Carrying out a risk assessment when onboarding new clients to classify them as low, medium or high risk.
- Periodic reassessments: Regularly updating clients' risk profiles based on new information, changes in operational behavior or updates to the regulatory framework.
- Documentation: Maintaining documentary records of risk assessments to confirm compliance and to carry out future audits.
Risk scoring model
The Company applies a points-based (scoring) model for assessing client risk. Each risk factor is assigned a score within an established range; the resulting risk score is the sum of the points across all categories of factors.
Categories of factors and maximum weights:
- Client risk (client type, reputation, PEP status, relationship history): 0–25 points.
- Product/service risk (product complexity, anonymity, cash operations): 0–20 points.
- Geographic risk (jurisdiction of registration/residence, countries from FATF lists and sanctions lists): 0–30 points.
- Transactional risk (volume, frequency, deviation from the expected operations profile): 0–25 points.
Maximum resulting risk score: 100 points.
Thresholds and risk categories:
- 0–25 points — low risk: standard CDD, risk reassessment at least once a year.
- 26–50 points — medium risk: standard CDD with enhanced monitoring of operations, risk reassessment at least once every 2 years (for individuals) / annually (for medium-risk legal entities, at the MLRO's discretion).
- 51–85 points — high risk: enhanced due diligence (EDD) is applied, establishment of the relationship is approved by senior management, monitoring at least once a quarter.
- 86–100 points, or a direct match with a sanctions list — unacceptable risk: refusal to establish a business relationship or immediate suspension of the exchange/operation.
Circumstances under which an exchange (operation) is suspended:
- the client's resulting risk score reaches or exceeds 86 points;
- a direct or probable match of the client, counterparty or beneficial owner with sanctions lists (UN, EU, OFAC, HM Treasury, etc.) is identified;
- the client cannot, within a reasonable time, confirm the source of origin of the funds or assets as part of enhanced due diligence (EDD);
- signs of structuring of operations (splitting amounts to circumvent reporting thresholds) or other red flags indicating possible ML/TF are identified;
- the client refuses or evades providing the requested documentation within the established period (10 calendar days);
- the operation is initiated from a jurisdiction under international sanctions/embargo or classified by the FATF as a high-risk country or a country under increased monitoring;
- an official instruction or requirement of an authorized authority (BVI FSC, FIA) to suspend the operation is received.
A suspended operation is resumed only after the written approval of the person responsible for compliance (MLRO/MLCO) or after obtaining the relevant authorization from the competent authority.
Customer due diligence (CDD)
Client identification and verification
Client identification: Acceptable identity documents are utility bills (not older than three months), bank statements (not older than three months) and other verifiable documents. If a client cannot provide standard identity documents, the company will use alternative verification methods, such as notarized documents or third-party verification services. The use of alternative identification methods must be approved by the compliance officer.
Clients who refuse to provide information: If a potential or existing client refuses to provide the information described above upon request or appears to intentionally provide false information, we will not open a new account and, having considered the associated risks, will consider closing any existing account. In any case, we will report this to our anti-money-laundering compliance officer so that we can determine whether we should report the situation.
Insufficient verification: If we cannot form a reasonable belief that we know the true identity of a client, we must do the following: (1) not open the account; (2) establish conditions under which the client may carry out operations while we attempt to verify their identity; (3) close the account after attempts to verify the client's identity have been unsuccessful; and (4) determine the need to submit reports to the authorities in accordance with applicable laws and regulations.
Verification process: To confirm the validity of identity documents, electronic verification systems will be used where possible. If discrepancies are detected, a manual check is carried out, of which the compliance officer is notified.
Identification of beneficial owners
The Company must identify and verify the beneficial owners of corporate clients. The procedures include:
- Collecting information about the client's ownership structure and identifying persons who own or control 25% or more of the shares or voting rights.
- Using corporate registers, financial statements and similar documents to confirm beneficial ownership.
- Updating information about beneficial owners in accordance with the document review periods established by the company.
Detailed KYC procedure and timelines
List of documents for individuals: (i) a valid photo identity document (passport or national ID card); (ii) proof of address not older than 3 months (utility bill, bank statement); (iii) for higher-risk clients — additionally documents confirming the source of origin of the funds/assets.
List of documents for legal entities: (i) a Certificate of Incorporation and constitutional documents (Memorandum & Articles of Association); (ii) a register of directors and a register of shareholders/members; (iii) a Certificate of Good Standing issued no more than 3 months ago; (iv) identity documents of the directors and beneficial owners holding 25% or more of the shares/voting rights; (v) an ownership structure chart in the case of multi-level ownership; (vi) for trusts — the trust deed and details of the settlor, trustee and beneficiaries.
Review timelines (SLA):
- Standard due diligence (low/medium risk): a decision on accepting the client — no later than 10 business days from receipt of the complete set of documents.
- Enhanced due diligence (EDD, high risk, PEP): a decision — no later than 20 business days from receipt of the complete set of documents.
- The period for the client to provide missing documents upon the company's request — no more than 10 calendar days; upon expiry of the period the application is rejected, and the account (if any) is blocked pending clarification of the circumstances.
- Periodic updating of documents and data: low risk — at least once every 3 years; medium risk — at least once every 2 years; high risk — at least once a year.
The Company has the right to extend the review periods if this is required by an order of government authorities, a request for additional information, or to obtain information from state registers.
Step-by-step stages of carrying out KYC:
- Stage 1. Acceptance of the application and collection of primary data (the client questionnaire and the set of documents according to the list above).
- Stage 2. Screening of the client, beneficiaries and counterparties against sanctions lists, PEP lists and adverse-information databases.
- Stage 3. Verification of the authenticity of documents (automated check; manual check — if discrepancies are identified).
- Stage 4. Identification and verification of beneficial owners and the ownership structure (for legal entities).
- Stage 5. Calculation of the risk score and assignment of a risk category in accordance with the risk scoring model (see the “Risk assessment” section).
- Stage 6. Approval or rejection of the establishment of a business relationship by the person responsible for compliance; for the high-risk category, additional approval by senior management is required.
- Stage 7. Ongoing monitoring of the business relationship and periodic reassessment of risk in accordance with the established timelines.
Ongoing monitoring
To continuously assess client activity, a comprehensive monitoring program will be implemented that includes:
- Transaction monitoring: Regular monitoring of transactions to identify patterns or anomalies that may raise suspicion.
- Risk-based approach: Applying enhanced monitoring to high-risk clients, including thorough review of large operations or operations that deviate from the norm established during the CDD process.
- Analysis and reporting: Documenting any signs of suspicious activity and promptly informing the organization's authorized compliance officer about them.
Enhanced due diligence (EDD)
High-risk clients
With respect to clients classified as high risk, the company must take additional measures to mitigate potential risks:
- Conduct interviews or meetings with clients to better understand the source of their funds and their business operations.
- Request additional documentation and explanations for operations that go beyond expected patterns, including documentation on the source of funds.
Special procedures
For higher-risk categories, including politically exposed persons (PEPs) and non-resident clients, extended procedures will be established:
For persons exposed to political risk, categorization must include an assessment of the risk level of the person, their close circle and family members, which will lead to stricter requirements when approving business relations.
For non-residents, additional documentation may be required to confirm their business purposes and the source of funds used for operations with the Company.
Reporting obligations
Suspicious Activity Reports (SARs)
The Company is obliged to report to the authorized authorities any operations that it considers suspicious. The reporting procedures are as follows:
- Identifying red flags, including unusual transactional activity, requests for anonymity or transactions inconsistent with the client's profile.
- Documenting the grounds for suspicion, including relevant operation details, communications and the collected supporting evidence.
- Promptly submitting a SAR to the authorities in electronic form and keeping a copy for the company's records.
Large Cash Transaction Reports (LCTRs)
Any cash operations exceeding USD 10,000 must be submitted within the established deadlines. The process includes:
- Collecting detailed records of the transaction, including the date, amount, payment method and purpose, and ensuring compliance when collecting information about cash clients.
- Ensuring that management is informed of large cash operations for proper record keeping and oversight.
Training and awareness
Employee training
In order for the assessment and measures to mitigate AML risks to be effective, the company must ensure that its employees have a clear understanding of the relevant risks and can exercise sound judgment both in complying with the company's AML risk-mitigation measures and in identifying suspicious operations. In addition, due to the constantly changing nature of AML risks, the company must ensure that its employees are constantly informed about emerging AML typologies and new internal and external risks. Thus, in order to ensure a high level of competence and effectiveness of the AML program, the company must develop and implement appropriate policies, procedures and controls with respect to the selection and training of personnel. Training measures include, but are not limited to, the following:
- Understanding the company's AML/KYC policies and procedures.
- Recognizing the types of operations that may indicate money laundering or terrorist financing.
- Understanding legal compliance obligations and internal reporting processes.
Training will include, at a minimum:
- how to identify red flags and signs of money laundering that arise in the course of employees performing their duties;
- what to do after identifying a risk (including how, when and to whom to escalate unusual client activity or other red flags for analysis);
- the disciplinary consequences (including civil and criminal sanctions) for non-compliance with AML requirements.
Continuous awareness-raising
The Company will periodically conduct training sessions and seminars and update information on the latest trends, findings and changes in AML/KYC legislation. This will also include:
- Distributing newsletters or bulletins to share information about developments in the industry, including examples of recent prosecutions, emerging frauds and preventive measures.
Record keeping
Storage of documentation
The Company will keep all client identification records, transaction records, due diligence documentation and reports submitted to the authorities for at least five years from the completion of the transaction or the last operation on the client's account. The information to be retained includes:
- Documents certifying the identity of clients.
- Records of operations (including amounts, dates, the currency used and the parties).
- Documentation of activities related to the risk assessment and customer due diligence process.
Compliance with storage requirements
The Company ensures the reliable storage of documentation in both physical and electronic form to protect client confidentiality and sensitive data, ensuring compliance with privacy laws and regulations.
Compliance review and monitoring
Internal audit
The Company will conduct independent internal audits to assess the effectiveness of the AML/KYC program. The internal audit process includes:
- A regular assessment of compliance with the AML/KYC policy.
- Identifying areas requiring improvement and ensuring that corrective actions are carried out.
- Preparing a report on the results, which must be submitted to management, along with recommendations for improving performance.
Continuous improvement
The Company will carry out an ongoing analysis of its policies and procedures to ensure that they comply with:
- Changes in AML/CFT legislation and regulations.
- Emerging risks and trends in the area of financial crime.
- Feedback from internal audits and employee reports.
Confidentiality and data protection
Data protection measures
The Company recognizes the importance of protecting client information and has implemented strict data protection protocols. These include:
- Encryption of confidential client data during transmission and storage.
- Restricting access to client records to authorized personnel only.
Confidentiality obligations
All employees, contractors and agents must maintain confidentiality with respect to client information and not disclose it without appropriate authorization or a legal obligation. A breach of confidentiality entails disciplinary sanctions.
Consequences of non-compliance
Disciplinary measures
Any employee found to be in violation of this policy, whether through negligence or a willful breach, will be subject to disciplinary action, which may include dismissal. Disciplinary measures will depend on the severity of the violation.
Reporting violations
Employees are encouraged to report any suspected violations of this policy to their immediate supervisor or the designated compliance officer. The Company assures employees that reports will be treated confidentially and without fear of retaliation.
International sanctions
The Company applies applicable international sanctions and pays particular attention to all of its Clients, their activities, and any facts indicating the possibility that a Client is subject to international sanctions.
Conclusion
Compliance commitments
The Company confirms its commitment to complying with all AML/CFT provisions and instructions. By actively combating money laundering and terrorist financing, the company strives to maintain the integrity of the financial system and strengthen the trust of clients and stakeholders.
Implementation and accountability
All employees will receive a copy of this policy and will be required to sign an acknowledgment of its receipt and understanding. Each employee is responsible for complying with the policies and procedures set out in this document. The company's management will exercise ongoing oversight of compliance with the rules and will create an ethical environment conducive to adherence to these principles.
Amendments to the policy
The Company has the right to make changes to this AML/KYC Policy. If changes are made to the current version, the date of the last update of the new Policy takes effect from the moment of its publication on the website, unless otherwise provided by the new AML/KYC Policy.
Contact us
If any ambiguities remain in the text of this AML/KYC Policy, we will be happy to clarify its provisions. Please contact us via the Platform for any additional questions about this KYC/AML Policy, or at info@changebox.io.