Anti-Money Laundering and Counter-Terrorist Financing Policy (AML/CFT Policy)
Last Review Date: 01 May, 2026This AML Policy explains how Cryptomus website (“Cryptomus”, “Company”, “we”, “us”, “our”) ensure compliance with all applicable anti-money laundering, counter-terrorist financing, and sanctions laws and regulations.
1. Introduction and Purpose
This Policy is designed to:
- Ensure compliance with globally recognized standards, including the recommendations of the Financial Action Task Force (FATF);
- Establish a risk-based approach to the identification, assessment, and mitigation of financial crime risks;
- Promote a culture of integrity, transparency, and accountability across all operations;
- Protect the Company from being used, intentionally or unintentionally, for illicit purposes.
The Company adopts a zero-tolerance approach toward money laundering, terrorist financing, sanctions evasion, fraud, and any other form of financial crime. Any activity suspected to be linked to such conduct will be subject to immediate review, escalation, and, where appropriate, reporting to competent authorities.
The Company is committed to continuously improving its AML/CTF controls in line with evolving regulatory expectations, technological developments (including blockchain analytics), and emerging financial crime risks in the digital asset ecosystem.
2. Scope of the Policy
This Policy establishes the framework under which Company identifies, assesses, monitors, and mitigates risks related to money laundering, terrorist financing, sanctions evasion, and other forms of financial crime across all its operations.
The Policy applies to all business activities conducted by the Company globally.
In particular, this Policy covers:
2.1 Customer Types
This Policy applies to all categories of Customers, including:
- Individual Customers;
- Legal entities (including corporations, partnerships, and other legal arrangements).
The Company applies differentiated controls based on the risk profile of each Customer segment in accordance with its risk-based approach.
2.2 Geographic Scope
The Policy applies to all jurisdictions in which the Company operates or where its Customers are located. The Company conducts business on a cross-border basis and therefore considers:
- Country-specific AML/CTF risks;
- Sanctions regimes administered by relevant authorities;
- Jurisdictions identified as high-risk or non-cooperative by the Financial Action Task Force (FATF) and other international bodies.
The Company reserves the right to restrict or prohibit services in certain jurisdictions based on assessed risk.
2.3 Internal Applicability
This Policy is binding on:
- All employees, regardless of role or seniority;
- Senior management and directors;
- Contractors and consultants, where applicable;
- Any individuals acting on behalf of the Company.
All relevant personnel are required to understand and comply with this Policy, as well as with supporting procedures, controls, and internal guidelines.
Failure to comply with this Policy may result in consequences, including termination of the contractual relationship.
2.4 Integration with Internal Controls
This Policy is supported by and should be read in conjunction with the Company’s internal procedures, including:
- Customer onboarding and KYC procedures;
- Transaction monitoring rules and alert handling processes;
- Sanctions and screening protocols;
- Incident escalation and reporting procedures;
- Record-keeping and data retention standards.
These procedures operationalize the principles outlined in this Policy and ensure consistent implementation across the organization.
3. Definitions
In this Policy, unless the context otherwise requires, the following definitions apply:
“AML/CTF” means Anti-Money Laundering and Counter-Terrorist Financing, referring to laws, regulations, and procedures designed to prevent the use of the financial system for money laundering, terrorist financing, and other financial crime activities.
“CDD” or “Customer Due Diligence” means the process of identifying and verifying a Customer’s identity, understanding the nature of the business relationship, and assessing the associated risk of money laundering, terrorist financing, and other financial crime.
“Customer” means any individual or legal entity that accesses or uses the Company’s services.
“EDD” or “Enhanced Due Diligence” means program whereby Customers who have been designated as high risk undergo enhanced scrutiny and diligence.
“KYC” or “Know Your Customer” means the identification and verification procedures applied to Customers as part of the onboarding and ongoing monitoring process.
“PEP” or “Politically Exposed Person” means an individual who is or has been entrusted with a prominent public function, as well as their immediate family members and close associates, who may present higher risk due to their position and influence.
“Source of Funds (SoF)” means the origin of the funds involved in a transaction.
“Source of Wealth (SoW)” means the origin of a Customer’s overall wealth and assets.
4. Risk-Based Approach
The Company applies a risk-based approach (RBA) to the management of money laundering, terrorist financing, and sanctions risks, in line with the principles set out by the Financial Action Task Force (FATF).
This approach ensures that resources and controls are allocated proportionately, with enhanced measures applied to higher-risk situations and simplified measures applied where risks are demonstrably lower.
4.1 Risk Assessment Framework
The Company maintains an ongoing process to identify, assess, and document its exposure to financial crime risks. This includes consideration of:
- Customer risk;
- Geographic risk;
- Product, service, and transaction risk;
- Delivery channel risk.
Risk assessments are:
- Conducted prior to onboarding new Customers;
- Reassessed periodically based on Customer activity and behavior;
- Updated upon material changes (e.g., change in ownership, business model, or transaction patterns).
Each Customer is assigned a risk rating, which determines the level of due diligence and monitoring applied.
4.2 Customer Risk
Customer risk is assessed based on factors including, but not limited to:
- Type of Customer (individual vs. legal entity);
- Ownership structure complexity;
- Identification of Ultimate Beneficial Owners (UBOs);
- Nature of the Customer’s business activities;
- Expected transaction behavior and volume;
- Whether the Customer qualifies as a Politically Exposed Person (PEP) or is linked to one;
- Adverse media or reputational concerns.
4.3 Geographic Risk
Geographic risk is evaluated based on:
- Customer residence, incorporation, or principal place of business;
- Exposure to jurisdictions identified as high-risk by the Financial Action Task Force (FATF);
- Countries subject to sanctions, embargoes, or heightened regulatory scrutiny.
4.4 Product and Service Risk
The Company assesses risks associated with its products and services, particularly those that may:
- Enable rapid movement of funds across borders;
- Involve increased anonymity or reduced transparency;
- Facilitate high transaction volumes or velocity;
- Involve interaction with external wallets or third-party platforms.
In addition, the Company maintains internal controls defining prohibited activities and business models, which are embedded within its onboarding and ongoing monitoring framework and which designate certain high-risk activities as strictly prohibited.
Customers engaged in activities that fall outside of prohibited categories but are assessed as higher risk are subject to enhanced monitoring and controls.
4.5 Delivery Channel Risk
The Company operates primarily through non-face-to-face (online) channels, which inherently increases risk.
To mitigate this, the Company implements:
- Robust digital identity verification processes;
- Two-factor authentication;
- Ongoing behavioral and transactional monitoring.
4.6 Risk Rating Methodology
The Company assigns each Customer a risk rating (Low, Medium, or High) based on a combination of the risk factors outlined above.
The risk rating is determined through an internal scoring model that takes into account:
- Customer profile and characteristics;
- Geographic exposure;
- Nature of products and services used;
- Transactional behavior and expected activity;
- Screening results (including sanctions, PEP status, and adverse media).
The overall risk classification is derived from the aggregated assessment of these factors and is subject to periodic review.
4.7 Risk Mitigation Measures
Based on the assessed risk level, the Company applies proportionate controls, including:
- Standard or Enhanced Customer Due Diligence;
- Transaction limits or restrictions;
- Increased frequency of monitoring and reviews;
- Requirement for additional documentation or source-of-funds verification;
- Refusal or termination of business relationships where risks cannot be adequately mitigated.
Customers presenting higher risk are subject to Enhanced Due Diligence and increased monitoring.
4.8 Ongoing Review
The Company’s risk-based approach is dynamic and subject to continuous improvement. Risk assessments are reviewed periodically and updated to reflect:
- Changes in regulatory expectations;
- Emerging typologies in financial crime, particularly in the digital asset sector;
- Internal findings, including audit results and compliance reviews.
5. Customer Due Diligence
The Company applies Customer Due Diligence (CDD) measures as a fundamental control within its AML/CTF framework to identify and verify Customers, understand the nature and purpose of the business relationship, and assess associated financial crime risks.
CDD is conducted in accordance with a risk-based approach and is applied to all Customers prior to the establishment of a business relationship.
5.1 Standard CDD
The Company performs Standard CDD for Customers assessed as low or medium risk. This includes, but is not limited to:
For individuals:
- Full name;
- Date of birth;
- Nationality;
- Residential address;
- Valid government-issued identification document;
- A liveness check;
- Screening against sanctions and PEP databases.
For legal entities:
- Legal name of the entity;
- Country of incorporation and registration details;
- Registered address and principal place of business;
- Corporate structure and ownership information;
- Identification of directors, shareholders and authorised signatories;
- Identification and verification of UBOs;
- Verification of existence and good standing via reliable sources;
- Screening of the entity and associated persons against sanctions and PEP databases.
5.2 Enhanced Due Diligence (EDD)
Enhanced Due Diligence is applied in cases where higher risk is identified, including but not limited to:
- Customers classified as high-risk under the Company’s risk scoring model;
- PEPs, their family members, or close associates;
- Customers from or connected to high-risk jurisdictions;
- Complex or opaque ownership structures;
- Unusual or inconsistent transactional behaviour;
- Exposure to higher-risk virtual asset activities or counterparties.
EDD measures may include:
- Collection of additional identification and verification documents;
- Detailed assessment of Source of Funds (SoF) and Source of Wealth (SoW);
- Senior management approval prior to onboarding or continuation of the relationship;
- Increased frequency of monitoring and periodic reviews;
- Enhanced blockchain analytics review for virtual asset transactions.
- Any additional information deemed necessary by the Company.
5.3 Ongoing Due Diligence
CDD is not a one-time process. The Company conducts ongoing due diligence through:
- Periodic review of Customer information based on risk level;
- Continuous transaction monitoring;
- Trigger-based reviews (e.g., changes in transaction patterns, ownership, or behaviour);
- Re-screening against sanctions, PEP, and adverse media databases on a regular basis.
6. Know Your Customer (KYC) Procedures
The Company implements Know Your Customer (KYC) procedures as the operational component of its CDD framework.
6.1 KYC Framework
KYC procedures are designed to:
- Ensure the accurate identification and verification of Customers;
- Support risk assessment and classification under the Company’s risk-based approach;
- Enable effective detection of suspicious or high-risk activity;
- Ensure that no business relationship is established without appropriate due diligence.
KYC controls are applied both at onboarding and on an ongoing basis.
6.2 Onboarding Controls
Prior to establishing a business relationship, the Company ensures that:
- All required Customer information and documentation are collected in accordance with Section 5 (Customer Due Diligence);
- Identity verification checks are successfully completed, including document validation and, where applicable, biometric verification;
- Screening against sanctions, PEP, and adverse media databases is performed;
- A risk rating is assigned to the Customer;
- The appropriate level of due diligence (CDD or EDD) is applied.
The Company does not onboard Customers where these requirements are not met.
6.3 Verification Standards
The Company applies verification measures based on reliable and independent sources, which may include:
- Automated identity verification solutions;
- Trusted third-party data providers;
- Official registries and corporate databases;
- Blockchain analytics tools.
Verification processes are designed to mitigate risks associated with impersonation, identity fraud, and misuse of the platform.
6.4 Ongoing KYC Controls
KYC is a continuous process. The Company ensures that Customer information remains accurate and up to date through:
- Periodic reviews based on Customer risk level;
- Trigger-based reviews initiated by changes in Customer behavior, transaction patterns, or profile data;
- Ongoing screening against sanctions, PEP, and adverse media databases;
- Re-verification of identity and documentation where required.
6.5 Exception Handling and Escalation
Any inconsistencies, incomplete information, or potential risk indicators identified during the KYC process are subject to review and escalation.
The Company may:
- Request additional information or documentation;
- Delay or suspend onboarding;
- Apply Enhanced Due Diligence measures;
- Reject or terminate the business relationship.
6.6 Prohibition on Anonymous Relationships
The Company does not establish or maintain anonymous or fictitious accounts.
Customers who fail to provide sufficient information to verify their identity will not be onboarded or will be subject to account termination.
7. Transaction Monitoring
The Company maintains a comprehensive transaction monitoring and blockchain analytics framework designed to identify, assess, and respond to potential indicators of money laundering, terrorist financing, sanctions evasion, fraud, and other illicit activity.
Given the nature of virtual assets and the cross-border scope of operations, the Company applies enhanced monitoring controls consistent with international best practices.
7.1 Monitoring Framework
The Company conducts ongoing monitoring of all Customer activity to ensure that transactions are consistent with the Customer’s profile, expected activity, and assigned risk rating.
The monitoring framework includes:
- Automated transaction monitoring systems with risk-based rules and scenarios;
- Detection of unusual patterns, transaction velocity, and behavioral anomalies;
- Risk-based thresholds;
- Continuous assessment of transaction flows and counterparty exposure.
Monitoring is applied on a real-time basis.
7.2 Blockchain Analytics Integration
To address risks specific to digital assets, the Company integrates blockchain analytics into its monitoring processes.
Such tools are used to:
- Assess the risk profile of wallet addresses and transactions;
- Identify exposure to high-risk sources, including illicit or sanctioned activity;
- Detect links to terrorism financing, child exploitation, darknet markets, fraud schemes, ransomware, or other criminal typologies;
- Trace transaction flows across blockchain networks;
The Company may utilize third-party service providers to support blockchain analytics and transaction monitoring activities.
The Company ensures that such providers are appropriately assessed. Blockchain analytics are applied on an ongoing basis.
7.3 Risk Indicators and Typologies
The Company maintains and regularly updates a set of risk indicators and typologies.
These include, but are not limited to:
- Interaction with wallet addresses associated with illicit or high-risk activity;
- Use of mixers, tumblers, or other obfuscation mechanisms;
- Structuring or fragmentation of transactions;
- Rapid movement of funds across multiple wallets or platforms (layering);
- Sudden or unexplained changes in transaction volume or behavior;
- Activity inconsistent with the Customer’s known profile;
- Repeated exposure to high-risk counterparties;
- Use of newly created or dormant wallets without clear economic rationale.
The presence of such indicators triggers further review and, where appropriate, escalation.
7.4 Alert Review and Case Management
All alerts generated through monitoring systems are subject to review by the compliance function.
The Company ensures that:
- Alerts are reviewed in a timely and risk-based manner;
- Investigations consider Customer profile, transaction history, and external risk indicators;
- Additional information may be requested from the Customer where necessary.
7.5 Enhanced Monitoring
Customers assessed as higher risk are subject to enhanced monitoring, which may include:
- Lower thresholds for alert generation;
- Increased frequency and depth of transaction reviews;
- Detailed on-chain analysis of transaction flows;
- Ongoing reassessment of Customer risk classification.
7.6 Escalation and Link to Reporting
Where suspicious activity is identified, the matter is escalated internally in accordance with the Company’s escalation procedures.
Such cases may result in:
- Application of Enhanced Due Diligence;
- Restriction or suspension of the account;
- Termination of the business relationship;
- Filing of a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR), where applicable.
7.7 Continuous Improvement
The Company regularly reviews and enhances its transaction monitoring systems to ensure effectiveness and alignment with:
- Emerging financial crime typologies;
- Developments in blockchain technology;
- Regulatory expectations and industry best practices.
Monitoring rules, thresholds, and scenarios are updated periodically to reflect evolving risks.
7.8 Data Request
To mitigate the risks associated with money laundering and terrorist financing, the Company does not permit the use of its services for transactions involving unidentified or unauthorized third parties.
As part of its ongoing transaction monitoring and risk management procedures, the Company may request additional information and documentation from Customers in order to verify the legitimacy of specific transactions.
Such requests may include, but are not limited to:
- Information regarding the purpose and nature of the transaction;
- Information on the source of funds and, where applicable, source of wealth;
- Supporting documentation evidencing the origin of funds (e.g., contracts, invoices, bank statements, or other relevant records);
- Transaction-related evidence, including confirmations or records demonstrating the flow of funds;
- Any additional information deemed necessary by the Company to assess the risk associated with the transaction.
The Company reserves the right to delay, reject, or suspend any transaction where sufficient information is not provided or where there are reasonable grounds to suspect that the transaction may be related to money laundering, terrorist financing, or other illicit activity.
8. Suspicious Activity Reporting (SAR/STR)
The Company maintains procedures for the identification, escalation, and handling of potentially suspicious activity as part of its AML/CTF framework.
8.1 Identification and Escalation
Potentially suspicious activity may be identified through transaction monitoring, blockchain analytics, CDD, or internal reporting.
8.2 Internal Review
The Company conducts internal reviews of flagged activity to assess whether the activity is consistent with the Customer’s profile and has a reasonable economic or lawful purpose.
Where necessary, additional information may be requested, and appropriate risk mitigation measures may be applied, including account restrictions or termination.
8.3 Reporting Approach
Where applicable, the Company submits Suspicious Activity Reports (SARs) or Suspicious Transaction Reports (STRs) to competent authorities in relevant jurisdictions, or through appropriate financial institution or partner channels.
8.4 Cooperation with Authorities
The Company responds to lawful requests for information in a timely manner and provides relevant data and records in accordance with applicable laws and internal procedures.
8.5 Confidentiality
All matters related to suspicious activity are handled on a confidential basis. The Company prohibits any form of disclosure to Customers or third parties that may constitute tipping-off.
9. Record Keeping
The Company maintains comprehensive record-keeping procedures to ensure that all relevant Customer, transactional, and compliance-related information is properly documented, retained, and made available when required.
9.1 Data Integrity and Accessibility
The Company ensures that all records:
- Are accurate, complete, and up to date;
- Are stored securely and protected against unauthorized access, alteration, or loss;
- Can be retrieved in a timely manner upon request by authorized personnel or competent authorities.
10. AML Governance
The Company maintains an AML/CTF governance framework to ensure effective oversight and implementation of its financial crime compliance program.
The Company appoints a designated AML/CTF Compliance Officer (the “AML Officer”) responsible for the implementation and ongoing management of the Company’s AML/CTF framework.
11. Employee Training
The Company provides AML/CTF training to ensure that employees understand their obligations and are able to identify and respond to potential financial crime risks.
12. Independent Audit
The Company ensures that its AML/CTF framework is subject to periodic review.
Such reviews may be conducted by qualified internal personnel or external third parties and are designed to assess the effectiveness of policies, procedures, and controls.
Findings from such reviews are addressed in a timely manner, and appropriate remedial actions are implemented.
13. Data Protection and Confidentiality
The Company is committed to protecting Customer data and ensuring the confidentiality of information obtained in the course of its AML/CTF processes.
Personal and transactional data is accessed only by authorized personnel on a need-to-know basis and is protected against unauthorized access, disclosure, or misuse.
Further details on the Company’s data protection practices are set out in Privacy Policy.
14. Prohibited Activities
The Company maintains controls to prevent the use of its services for unlawful, fraudulent, or otherwise prohibited activities.
The Company strictly prohibits the use of its services in connection with activities that are illegal, abusive, or present an unacceptable level of financial crime risk.
14.1 Prohibited Activities
Any use of the Company’s services in connection with any of the following categories of activities or businesses is prohibited (“Prohibited Activities”), and the Company reserves the right to refuse the opening of an account, or to suspend or terminate any existing account and cease the provision of services, at its sole discretion, where involvement in such Prohibited Activities is identified:
- banks or financial institutions lacking a physical presence in any jurisdiction (“shell banks”), or those engaging in financial activities or providing services that fail to comply with applicable laws, regulations, or other legal requirements, or that could place the Company or its affiliates in breach of such obligations;
- restricted financial services, including, without limitation, credit repair, bail bond services, and collection agencies;
- unlicensed money service businesses, including, without limitation, payment service providers, the issuance or sale of money orders or cashier’s checks, as well as any activities involving the transmission of funds.
- adult content and services, including but not limited to any type of pornography or other obscene materials, or sites offering any sexually related services such as prostitution, pay-per view, escorts, or adult live chat features;
- deceptive marketing or false advertising services;
- the sale or distribution of weapons of any kind, including but not limited to firearms, ammunition, or related accessories;
- marijuana dispensaries and related businesses; sale of tobacco, e-cigarettes, and e-liquid; online prescription or pharmaceutical services; age restricted goods or services; and toxic, flammable, and radioactive materials;
- drugs and related paraphernalia, including, without limitation, the sale of narcotics, controlled substances, or equipment intended for the manufacture or use of drugs;
- the use of shell entities or non-transparent ownership arrangements where the ultimate beneficial owner cannot be reasonably identified;
- gambling-related activities, including but not limited to sports betting, casino games, lotteries, games of chance, and any other activities that facilitate or are substantially similar to the foregoing, as determined at the Company’s sole discretion;
- money laundering, fraud, terrorist financing, or any other type of financial crime;
- any sort of pyramid scheme;
- goods or services that infringe upon or violate any intellectual property rights, including copyrights, trademarks, or other proprietary rights;
- counterfeit or unauthorized products, including, without limitation, the sale or resale of fake or novelty identification documents, or goods and services that are illegally imported, exported, or stolen;
- market abuse practices such as wash trading, front-running, insider trading, market manipulation, or any other form of deceptive or fraudulent market conduct;
- the purchase of goods through hidden service marketplaces (also known as “darknet” markets) or any platform facilitating the trade of illegal goods, even if such platforms also offer lawful items;
- any form of child exploitation;
- any additional goods, services, or activities that the Company may, from time to time, determine to be unacceptable or high-risk, including those restricted by the Company’s or the Customer’s banking or payment partners;
- any other unlawful services or activities that, in the Company’s sole discretion, violate or contribute to the violation of any applicable laws, statutes, regulations, or sanctions regimes in jurisdictions where the Company operates, or that involve proceeds derived from illegal conduct;
- any activity or business which, at the Company’s sole and absolute discretion, may pose a reputational, operational, or integrity risk to the Company or its services, is otherwise deemed inappropriate, or fails to comply with applicable laws and regulations.
In the event that the Company becomes aware of, or reasonably suspects, in its sole discretion, that a Customer or a Customer’s Account is or may be associated with any Prohibited Activities as defined in this AML/CTF Policy, such circumstances shall constitute a violation of this Policy. The Company may, without prior notice, suspend or terminate access to the Account or any of its services, block transactions, or freeze funds, and reserves the right to report any suspected or confirmed Prohibited Activities to the relevant competent authorities.
15. Restricted Jurisdictions
The Company does not provide services to individuals or entities located in, incorporated in, or otherwise associated with jurisdictions subject to comprehensive international sanctions.
15.1 Prohibited Jurisdictions
The Company prohibits business relationships and transactions involving jurisdictions subject to comprehensive sanctions regimes or equivalent restrictions, including those administered by relevant international authorities such as the United Nations Security Council (UN), the Office of Foreign Assets Control (OFAC), the European Union (EU), the United Kingdom (HMT/OFSI), and other applicable national sanctions authorities, as well as jurisdictions where such restrictions are applied or recognized.
15.2 High-Risk Jurisdictions
In addition, the Company may restrict or apply enhanced due diligence measures to Customers or transactions involving jurisdictions identified as high-risk or non-cooperative, including those listed by the Financial Action Task Force (FATF).
Such jurisdictions may be subject to:
- Enhanced due diligence (EDD);
- Additional documentation requirements;
- Transaction monitoring restrictions or limits;
- Case-by-case approval by the Compliance function.
15.3 Monitoring and Updates
The Company continuously monitors changes in sanctions regimes and risk classifications issued by relevant international bodies and regulatory authorities.
The list of restricted jurisdictions is reviewed and updated on an ongoing basis to reflect:
- Changes in international sanctions frameworks;
- FATF updates and public statements;
- Internal risk assessments and compliance reviews.
- Evolving legal, regulatory, and operational risk considerations associated with providing services in certain jurisdictions.
The Company reserves the right to update its geographic restrictions at any time without prior notice.
15.4 General Principle
The Company will not knowingly establish or maintain relationships that would expose it, its partners, or financial institutions to sanctions violations or unacceptable regulatory risk.
16. Policy Review and Updates
This Policy is reviewed periodically to ensure its continued effectiveness and alignment with:
- Changes in business activities;
- Emerging financial crime risks;
- Regulatory developments and industry best practices.
The Company reserves the right to amend this Policy at any time. Updated versions will be made available as appropriate.