Compliance
Anti-Money Laundering and Countering the Financing of Terrorism Policy
Last updated: June 2026
The Company is committed to upholding robust standards to prevent and counter money laundering (AML) and the financing of terrorism (CFT) across all areas of its business and operations. This Policy summarises the framework, controls and obligations we apply.
Terms and Definitions
“Commission” means the Tobique Gaming Commission.
“Financing of terrorism” includes an activity where: (a) a person provides or collects funds, and intends or is negligent or reckless as to whether the funds will be used to facilitate or engage in a terrorist act; or (b) a person becomes involved in an arrangement which makes money or other property available to another if he or she knows, or has reasonable cause to suspect, it may be used for terrorist purposes.
“Financing of terrorism offence” is an offence whether committed in the Tobique First Nation or under the laws of another jurisdiction, which criminalizes the financing of terrorism, and includes circumstances where financing was provided even if the terrorist act does not occur.
“Gaming Act” means the Tobique Gaming Act 2023.
“Money Laundering” is the activity whereby: (a) a person uses, transfers the possession of, sends or delivers to any person or place, or otherwise deals with, in any manner and by any means, any property or any proceeds of any property with intent to conceal or convert that property or those proceeds, knowing or believing that, or being reckless as to whether, all or part of that property or those proceeds was obtained or derived directly or indirectly as a result of criminal activity; or (b) a person enters into, or becomes concerned in, an arrangement which he or she knows, or has reasonable cause to suspect, facilitates the acquisition, retention, use or control of criminal property by or on behalf of another person.
“Money laundering offence” is an offence whether committed in the Tobique First Nation or under the laws of another jurisdiction, which criminalizes money laundering or disposal of the proceeds of crime.
“Person” includes an individual, corporation, partnership, limited liability company and any other business entity recognized under the laws applicable within the Tobique First Nation.
“Politically Exposed Person (PEP)” means an individual who holds a prominent public position or function in a government body or an international organization, including:
- Head of State or head of a country or government;
- Government minister or equivalent senior politician;
- Senior government official;
- Senior judge in a foreign country or international organization;
- Governor of a central bank;
- Senior foreign representative, ambassador, or high commissioner;
- High-ranking member of the armed forces; or
- Board chair, chief executive, or chief financial officer of, or any other position that has comparable influence in, any State enterprise or international organization.
In this Policy, PEP also includes an immediate family member (spouse, de facto partner, child and a child’s spouse or de facto partner, parent) and a close associate (any individual known — having regard to information that is public or readily available — to have joint beneficial ownership of a legal entity or legal arrangement with a PEP, or sole beneficial ownership of a legal entity or legal arrangement known to exist for the benefit of a PEP).
“Person having a close connection to a sport or sporting event” includes an individual who (having regard to information that is public or readily available) owns, plays with, coaches, trains or manages a sporting team, or who has a senior role with the governing body of a sport. This definition also includes the immediate family members and close associates of such a person.
“Transaction” includes a single transaction or a series of transactions which appear to be linked.
“Restricted Jurisdiction” refers to any country or territory subject to sanctions or restrictions imposed by international regulatory bodies such as the United Nations (UN), European Union (EU), United Kingdom (UK), United States (US), or any other relevant international or national authority as provided in Annex IV. This includes jurisdictions or entities designated under UN Security Council (“UNSC”) resolutions, such as resolutions 1267 (1999), 1373 (2001), and their successors, which mandate the freezing of assets and the prohibition of financial dealings with specified entities or individuals. These jurisdictions are considered entirely out of the Company’s risk appetite, and the Company prohibits any form of business engagement with entities or individuals operating from them.
“High-Risk Jurisdiction” is a country or territory having a high corruption scoring or identified by the Financial Action Task Force (FATF) as having significant deficiencies in its AML/CFT frameworks as provided in Annex IV. These jurisdictions are categorized under the FATF “grey list” or other similar regulatory or corruption risk lists and are subject to Enhanced Due Diligence (EDD) measures. Relationships or transactions with parties associated with high-risk jurisdictions are assessed on a case-by-case basis.
1. Introduction
The Company is committed to upholding robust standards to prevent and counter money laundering (AML) and terrorism financing (CTF) in all areas of its business and operations. The Company strictly prohibits the use of its services for any illegal activities, including money laundering and terrorism financing. The Company will not establish or maintain business relationships with any individual or entity where customer due diligence (CDD) cannot be completed satisfactorily, or where there is reason to believe or suspect involvement in money laundering or terrorist financing.
All employees, officers, and directors of the Company (collectively, “Employees”), as well as consultants, representatives, agents, brokers, distributors, and any other intermediaries acting on behalf of the Company, are required to fully adhere to this Policy and its associated procedures.
2. Legal Framework
The Company has implemented AML/CTF procedures, systems, and controls designed to prevent and detect money laundering and terrorism financing, in alignment with recognized international best practices such as those recommended by the FATF and:
- Regulations Concerning Anti-Money Laundering and Counter Terrorism Financing as enacted by the Commission pursuant to Section 22 of the Tobique Gaming Act 2023;
- Tobique Gaming Commission (“TGC”) Gaming Act 2023;
- TGC Remote Gambling Anti-Money Laundering (“AML”) Code of Practice; and
- TGC General Code of Practice.
These measures ensure that the Company’s operations align with global standards and contribute to a secure and compliant business environment.
3. Sanctions Compliance
The Company ensures full compliance with all applicable sanctions laws and regulations, including resolutions issued by the UNSC under Chapter VII of the UN Charter. This includes resolutions related to the prevention and suppression of terrorism, terrorist financing, and the proliferation of weapons of mass destruction. The Company will freeze without delay the funds or assets of, and ensure that no funds or assets are made available, directly or indirectly, to or for the benefit of, any Restricted Jurisdiction or any individual or entity designated by the UNSC or relevant authorities in accordance with resolutions such as 1267 (1999), 1373 (2001), and successor resolutions.
4. Compliance Officer
The Company has appointed a Compliance Officer as part of its senior management team to ensure the effective implementation, management, and oversight of all AML/CFT measures. The Compliance Officer is accountable to the Board of Directors and serves as the primary authority for managing the Company’s AML/CFT systems.
The Board of Directors and senior management have clearly defined and documented AML/CFT responsibilities. The Compliance Officer, performing the functions of the Money Laundering Reporting Officer (MLRO), owns the day-to-day management of ML/TF risks; however, senior executives remain personally and corporately accountable for preventing money laundering activities within the Company.
The Compliance Officer has sufficient autonomy, expertise, and influence to effectively challenge internal decisions and ensure independent oversight, and is empowered to escalate material ML/TF risks to the Board of Directors or an appropriate Risk Committee.
In accordance with Tobique regulatory requirements, the Company conducts an Enterprise-Wide Risk Assessment (EWRA) on an annual basis, led by the Compliance Officer. The EWRA takes into account a comprehensive set of risk factors, including:
- The typology and risk profile of the Company’s customers;
- The countries and geographic regions in which the Company operates or serves customers;
- The nature and risk level of products and services offered;
- Payment and transaction patterns, including volumes, frequency, and complexity;
- The operational delivery channels used, particularly non-face-to-face onboarding or remote services;
- The involvement of third-party service providers, including payment processors, agents, and technology vendors.
Following the assessment, the Compliance Officer prepares a formal report to the Board of Directors. The Compliance Officer acts as the primary point of contact for regulatory authorities, serves as the primary internal resource on ML/TF matters, maintains a comprehensive AML/CFT training program, and conducts periodic risk assessments of the Company’s controls.
5. Risk-Based Approach and Risk Assessment
The Company acknowledges that the gaming sector is exposed to specific money laundering and terrorist financing risks. These include, but are not limited to:
- The introduction or movement of funds with illicit origins through deposit, gambling, withdrawal, or money transfer activities;
- Customers knowingly attempting to disguise, convert, or dispose of illicit funds as legitimate through gaming activities;
- Risks arising from ownership, control, or misuse of the Company’s platform by criminals or their associates;
- Peer-to-peer fund transfers, such as “chip-dumping” in poker, used to facilitate ML or TF activities.
The Company applies a risk-based approach to AML/CTF measures, prioritizing efforts in areas where risks are assessed as higher, tailoring its policies and controls to its specific risk profile, continuously assessing risks associated with services, customers, and jurisdictions, and allocating resources to higher-risk areas.
The Compliance Officer ensures robust procedures are in place to safeguard against common ML methods:
- Disguise: Misrepresentation of illicit funds as legitimate.
- Conversion: Transformation of “dirty money” into “clean” funds through winnings or account balances.
- Disposal: Use of illicit funds for gambling activities or settling debts.
Each customer is evaluated using the methodology detailed in the Customer Risk Rating Methodology (Annex VII), where risk levels are assigned as Low, Medium, or High. Key risk factors include:
Customer-related risks:
- Bearer share companies;
- Offshore entities;
- PEPs;
- Persons with a close connection to a sport or sporting event;
- Transactions involving large cash volumes;
- Customers from High-Risk jurisdictions.
Behavioral risks:
- Transactions lacking a clear financial rationale;
- Difficulties in verifying the origin of funds or wealth;
- Reluctance to provide beneficial ownership details.
Communication channel risks:
- Non-face-to-face customer interactions;
- Introductions from third parties.
Risks related to services and financial instruments:
- Services allowing third-party payments;
- Significant cash deposits or withdrawals.
The Company also sets alert triggers for the following warning signs (“Red Flags”):
- High losses inconsistent with the customer’s normal activity, player profile or documented financial means;
- Spikes in player activity that are inconsistent with the known or profiled activity for that customer;
- Avoidance or delay by the customer in connecting personally with the Company;
- Provision of false or implausible information or documentation in an attempt to conceal or withhold AML/CFT evidence;
- Inconsistent personal information or adverse media related to the customer’s reputation, financial standing or previous convictions;
- Customer withdrawals inconsistent with usual player activity, such as minimal play or spend;
- “Loading” of remote gambling accounts by transferring cash funds deposited in person in live betting shops;
- Deposits made from corporate cards or accounts, or by players with access to corporate funds;
- Problem gambling behaviour resulting in increased wagering, where the customer may be financing addiction from stolen funds;
- A customer misleading the Company about the source of deposits linked to criminal activity;
- A player transferring criminal funds to another player by play or other means;
- Very low-risk gambling or minimal play used to recycle illicit funds.
For high-risk customers, the Compliance Officer designs measures including identity verification, economic-profile building, enhanced transaction monitoring, enhanced KYC and EDD protocols, additional source-of-funds documentation, independent verification, senior management approval, and the maintenance of categorized (low, medium, high) customer lists.
6. On-Boarding and Customer Due Diligence
The Company applies CDD measures in line with Recommendation 10 of the FATF standards. These measures are required when:
- establishing business relationships (on-boarding);
- conducting occasional transactions;
- there is suspicion of money laundering or terrorist financing; or
- there is doubt about the veracity or adequacy of previously obtained customer identification data.
As part of CDD, KYC verification gathers key information such as identity, date of birth and residential address, confirms the source of funds, and performs standard screening checks (adverse media, PEPs and sanctions). KYC verification begins at whichever of the following thresholds is reached first:
- Within 30 days of first deposit;
- When cumulative deposits reach an equivalent of EUR 2,000 or more; and/or
- Before any money is paid out (first withdrawal).
Means of verifying identity. The Company requires government-issued identification (ID card, passport, social insurance card, or other document from an independent and reliable source) that includes the customer’s photo.
Verifying proof of residential address. Documentation matching the registered address, such as utility bills, a local authority tax bill (dated within the last six months), a telephone directory entry, or a bank statement (dated within the last six months).
Verifying source of funds. Introductions from employees, officers or reliable existing customers, references from banks or legal firms, agreements, and recent, authentic bank statements.
All customers are screened at registration and on an ongoing basis against industry databases to identify PEPs, sanctioned individuals, and adverse media. Sanctioned customers are barred from depositing or wagering, and identified PEP accounts are frozen until further checks are completed.
Circumstances requiring Enhanced Due Diligence (EDD):
- A change in the customer’s risk assessment;
- Suspicion regarding the true identity of the customer;
- Transactions inconsistent with the customer’s usual activity;
- Suspicion of money laundering or terrorist financing;
- Doubts about the veracity or adequacy of previously obtained identification data.
High-risk factors necessitating EDD:
- Association with High-Risk Jurisdictions;
- Use of forged or stolen identification documents;
- A customer previously excluded for problem gambling who has bypassed blocking measures;
- Use of high-risk payment methods, such as prepaid cards or cryptocurrency;
- Significant adverse media, particularly relating to financial crime;
- Identification of the customer as a PEP;
- An indirect link to a sanctioned individual, entity, or country;
- Transactional activity unusually high in value or volume relative to estimated affordability.
7. Politically Exposed Persons
PEPs are considered higher risk for money laundering due to the influence and access associated with their political positions. PEP status does not imply involvement in suspicious activities but requires heightened vigilance and categorization into a higher risk tier.
All customers identified as PEPs must undergo EDD measures and continuous monitoring, including a comprehensive risk assessment of the relationship, enhanced screening and ongoing monitoring for high-risk PEPs, and board-level approval for allowing PEPs to engage in wagering activities. The Compliance Officer maintains a PEP log.
The Company monitors individuals identified as PEPs for at least 12 months after they cease holding a prominent public function. PEPs associated with higher-risk jurisdictions are treated as extremely high risk, requiring additional stringent due diligence, a risk mitigation statement, and senior management approval to continue the relationship.
8. Person with a Close Connection to a Sport or Sporting Event
The Company implements EDD to identify and manage relationships with customers who may be Persons with a close connection to a sport or sporting event, specifically when the Company accepts bets related to the team, sport, or sporting event in question. These EDD measures include securing senior management approval, verifying the source of wealth and funds, and conducting enhanced ongoing monitoring.
If adverse information arises, or the source of funds cannot be reasonably verified, the Company reviews the integrity of the relationship and considers terminating it. All decisions to establish, continue, or terminate such relationships are fully documented, including the reasons.
9. Employee Due Diligence
The Company applies a risk-based approach to employee due diligence to minimize the risk of involvement in money laundering or terrorist financing. Prospective employees who may be in a position to facilitate ML/TF are screened according to the risk associated with their role, and employees are re-screened when transferred or promoted into roles carrying increased exposure. The Company maintains a system to manage non-compliance, including disciplinary measures and corrective actions.
10. Commercial or Business-to-Business (B2B) Relationships
Where the Company is a B2B licence holder, it applies initial CDD measures during the onboarding of B2C Operator Customers, gathering and verifying information about the customer, its owners, controllers, and related parties. Key elements of the onboarding process include:
- Verification of corporate existence via certificate of incorporation, business registration, or equivalent documentation;
- Directors — a complete list with proof of identity and address for each;
- Ownership and Ultimate Beneficial Owners (UBOs) — identified and verified at thresholds of 25% or more for Low/Medium-risk customers and 10% or more for High-risk customers;
- Control structure and proof of ownership via shareholder agreements, registries, or official records;
- Purpose and intended nature of the business relationship;
- Transactional profile and source of funds, including expected transaction types, volumes, and frequency.
The Company applies CDD to other relevant B2B partners, conducts due diligence on gambling software providers, and monitors gameplay and transactional activity to detect schemes such as chip dumping or P2P transfers. EDD measures for higher-risk customers include deeper ownership checks (UBOs of 10% or more), certified photo IDs for directors or controllers, evidence of source of wealth and funds for UBOs, enhanced screening across multiple data sources, and senior management and Compliance Officer approval.
11. Reliance on Third Parties
The Company may utilize third parties to assist with customer identification and CDD. When relying on third parties, the Company ensures that relevant data and documents are made available without delay, that the third party has appropriate AML/CTF controls, and that roles and responsibilities are clearly documented. All third-party arrangements must be reviewed and approved by the Compliance Officer, and are subject to ongoing monitoring. The ultimate responsibility for ensuring compliance with CDD requirements remains solely with the Company.
12. Ongoing Monitoring and Periodic Reviews
Ongoing monitoring of accounts and transactions is overseen by the Compliance Officer throughout the duration of the business relationship. The primary objectives include identifying high-risk customers, detecting transactions that deviate from expected activity, identifying complex or unusual transactions, ascertaining the source and origin of funds, screening customers regularly against PEP, sanctions, and adverse media databases, and monitoring linked accounts.
Transaction monitoring. The Company maintains a robust transaction-monitoring framework using automated and manual processes. Monitoring focuses on the frequency, volume, and value of transactions (bets, deposits, withdrawals) compared against each customer’s established profile and risk rating. Deviations — such as large, high-frequency, or inconsistent betting patterns — trigger alerts for further analysis against predefined thresholds and behavioral scenarios.
Periodic reviews of customer CDD and risk assessments are conducted based on risk level:
- High-Risk Customers: every 1 year;
- Medium-Risk Customers: every 2 years;
- Low-Risk Customers: every 3 years.
Event-Driven Reviews are triggered by specific circumstances indicating increased ML/TF risk, such as detection of Red Flags, a significant change in the ownership or control of a customer’s business, or other indicators of increased risk. They involve a full refresh of the customer’s KYC and CDD records and may result in reclassification of the risk level, new monitoring thresholds, or suspension or termination of the relationship.
Off-boarding. Where a customer poses an unacceptable level of risk, off-boarding is initiated. Triggering events include unresolvable ML/TF risks, non-compliance with KYC/CDD requests, evidence of fraudulent activity or links to criminal networks, and significant reputational risk. The process includes a final review, formal notification (except where prohibited by tipping-off provisions), review of pending transactions with funds returned via the original payment method where possible, and full documentation. Where off-boarding relates to suspected ML/TF, the relevant authorities are notified, and the account remains subject to monitoring.
13. Data Recording and Record-Keeping
The Company maintains comprehensive records of all customer data and associated documentation. Customer files are updated regularly — at least bi-annually — or whenever new information emerges. All records obtained through the CDD process, including copies of official identification documents, account files, and business correspondence, are retained for a minimum of five years after the termination of the business relationship or the date of an occasional transaction, including originator and beneficiary information for wire and electronic transfers. Should the Company relocate or cease operations, it will provide the relevant regulator with copies of all records.
14. Reporting
The Company has a responsibility to report any identified instances of suspicious activity to the Commission where it knows or reasonably suspects that a customer’s behavior may be related to money laundering, terrorism financing, or other criminal activity. The Compliance Officer evaluates information received and lodges Suspicious Activity Reports (SARs) within established timeframes.
A suspicious matter report must be submitted where there are reasonable grounds to suspect that the customer is not who they claim to be, that the provision of services is connected to ML/TF or other criminal activity, or that a transaction lacks a lawful economic purpose. Reporting timelines:
- Money laundering or other criminal activities: within 5 business days of forming the relevant suspicion;
- Terrorism financing: within 24 hours of forming the relevant suspicion.
Every report must clearly state the grounds for the suspicion and the circumstances that led to it. The Company documents the reasoning behind any decision to submit or not submit a report, may be required to provide additional compliance reports on request from the Commission, and reports all SARs to the domestic Financial Intelligence Unit (“FIU”).
15. Training
The Compliance Officer ensures that all employees receive adequate AML/CFT training, both general and role-specific. Key topics include ML/TF risks relevant to the business, applicable legislation and employee obligations, the Company’s risk-assessment methodology, how to identify and report suspicious activity, and indicators and Red Flags specific to the gaming sector.
After each session, employees complete an assessment requiring a minimum passing score of 75%; those who do not meet the standard must re-take the assessment and, if necessary, repeat the training. Refresher training is required annually, and comprehensive records of attendance, results, and remedial actions are maintained.
16. Review
This Policy is subject to review every two years by an independent audit. This frequency may be increased to an annual review in response to significant compliance findings. The review assesses the effectiveness of the Policy having regard to the Company’s ML/TF risk, whether it has been effectively implemented, and whether the Company has complied with its program. The results, including any report prepared, are provided to senior management, the governing body, and the Commission. Internal audits are performed annually to evaluate implementation, identify gaps, and recommend improvements.
Annex I — Internal Suspicious Report for Money Laundering and Terrorist Financing
Employees use this internal report to escalate knowledge or suspicion of money laundering or terrorist financing to the Compliance Officer. The report captures the following information:
Informer’s Details
- Name; Telephone; Department; Fax; Position.
Customer Details
- Name; Address; Date of Birth; Telephone; Occupation; Fax; Details of Employer;
- Passport Number; Nationality; ID Card Number; Other ID Details.
Information / Suspicion
- Brief description of the activities or transaction;
- Reason(s) for suspicion;
- Informer’s signature and date.
For Compliance Officer’s Use
- Date received; Time received; Reference;
- Reported to Commission (Yes/No); Date reported; Reference.
Annex II — Internal Evaluation Report for Money Laundering and Terrorist Financing
The Compliance Officer records the evaluation of each internal suspicious report using this form, which captures:
- Reference; Customer’s details; Informer; Department;
- Inquiries undertaken (brief description);
- Attached documents;
- Compliance Officer’s decision;
- File number; Compliance Officer’s signature and date.
Annex III — Compliance Officer’s Report to the Regulator
I. General Information
- Organisation’s name;
- Address where the customer’s account is kept;
- Date the business relationship was established, or the occasional transaction was carried out;
- Type of account(s) and number(s).
II. Details of Natural Person(s) and/or Legal Entity(ies) Involved
For natural persons — recorded for both the beneficial owner(s) and the authorised signatory(ies) of the account(s): name(s); residential address(es); business address(es); occupation and employer; date and place of birth; nationality and passport number.
For legal entities: legal entity’s name, country and date of incorporation; business address; main activities.
III. Details of Suspicious Activities
- Details of the suspicious activities;
- The knowledge or suspicion of money laundering or terrorist financing, explained as fully as possible;
- Other information — other services provided to the customer(s).
The report is signed and dated by the Compliance Officer and must be accompanied by photocopies of: (1) for natural persons, the relevant pages of the customer’s passport or ID card evidencing identity; (2) for legal entities, certificates of incorporation, directors and shareholders; and (3) all documents relating to the suspicious transaction(s).
Annex IV — Jurisdictions
Restricted Jurisdictions
The consolidated list of Restricted Jurisdictions is: Afghanistan, Canadian Province of New Brunswick, China, Cuba, Central African Republic, Democratic Republic of Congo, Haiti, Iran, Iraq, Israel, Libya, Myanmar, North Korea, Russia, Somalia, South Sudan, Syria, United Kingdom, United States, Yemen, Venezuela.
This list is based on the following sources:
- United Nations (UN) Sanctions Lists — the UN Consolidated Sanctions List (un.org/securitycouncil/sanctions/information).
- U.S. Department of the Treasury — Office of Foreign Assets Control (OFAC) — the Specially Designated Nationals and Blocked Persons List (SDN List) and the Consolidated Sanctions List (home.treasury.gov/policy-issues/financial-sanctions).
- European Union (EU) Sanctions Lists — the EU Sanctions Map (sanctionsmap.eu) and the EU Consolidated List of Sanctions.
- United Kingdom (UK) Sanctions List (gov.uk/government/publications/the-uk-sanctions-list).
- Conflict Zones — high-risk, unstable regions where armed hostility or terrorist organisations are present: Afghanistan, Central African Republic, Iran, Iraq, Lebanon, Libya, Mali, Myanmar, Nigeria, North Korea, Pakistan, Palestinian Territory, Somalia, South Sudan, Sudan, Syria, Ukraine, Yemen.
- Countries considered to be funding terrorism — per the U.S. State Department list of State Sponsors of Terrorism (state.gov/state-sponsors-of-terrorism).
- FATF High-Risk Jurisdictions (the “black list”) (fatf-gafi.org/en/countries/black-and-grey-lists.html).
High-Risk Jurisdictions
The consolidated list of High-Risk Jurisdictions is: Albania, Barbados, Bulgaria, Burkina Faso, Burundi, Chad, Comoros, Cameroon, Cayman Islands, Croatia, Equatorial Guinea, Gibraltar, Jamaica, Jordan, Lebanon, Mali, Mozambique, Nicaragua, Nigeria, Pakistan, Palestinian Territory, Panama, Philippines, Senegal, South Africa, Tanzania, Tajikistan, Turkey, Turkmenistan, Uganda, United Arab Emirates, Ukraine, Vietnam, Zimbabwe.
This list is based on:
- FATF Jurisdictions Under Increased Monitoring (the “grey list”) (fatf-gafi.org/en/countries/black-and-grey-lists.html).
- High corruption-scoring jurisdictions — those with a Corruption Perception Index (CPI) score of 20 or under are deemed the worst offenders and carry a high ML/TF risk (transparency.org/en/cpi).
Annex V — Natural Person On-Boarding Application Form
Section 1: Personal Information
- Full name; date of birth; residential address;
- Contact information: phone number and email address.
Section 2: Account Details
- Preferred username; preferred currency; cryptocurrency usage (Yes/No).
Section 3: Identity Verification
The following documents are uploaded for identity verification:
- Government-issued ID (e.g. passport, driver’s licence);
- Proof of address (e.g. utility bill, tax bill, bank statement).
Section 4: Politically Exposed Persons (PEP) Declaration
The applicant declares whether they, or anyone in their immediate family or close associates, is a Politically Exposed Person (Yes/No), and provides details where applicable.
Section 5: Acknowledgement
- Confirmation that the applicant is over 18 years old;
- Confirmation that the information provided is accurate and is not another person’s identity, and that the account remains restricted until verification is complete;
- Acknowledgement and agreement to the Company’s Terms and Conditions, including its AML and CFT policies;
- Consent to the processing of personal data for account creation, identity verification, and AML/CFT compliance, and agreement to the Privacy Policy.
Verification Checklist (Internal Use)
- Documents received: government-issued ID (Yes/No); proof of address (Yes/No);
- Screening results: PEP check, adverse media, and sanctions check (Clear / Further Review Required);
- Approval: verified by and date.
Annex VI — Company On-Boarding Application Form
Section 1: Corporate Information
- Registered company name; trading name (if applicable); country and date of incorporation; company registration number;
- Registered office address; head office address (if different); telephone number; email address; company website.
Section 2: Directors and Key Controllers
Details for all company directors and key controllers — full name, position, date of birth, nationality, proof of identity (type and number), and proof of address. Supporting documents required: government-issued ID (passport/ID card) and proof of address (utility bill or bank statement issued within the last 6 months).
Section 3: Ultimate Beneficial Owners (UBOs)
Information on all individuals or entities with ownership thresholds of 25% or more (10% or more for high-risk customers) — full name, ownership percentage, date of birth, nationality, proof of identity, and proof of address. Supporting documents required: proof of identity and proof of address for each UBO.
Section 4: Control Structure and Ownership Details
- Shareholder details, with supporting documents demonstrating ownership percentages (e.g. Certificate of Shareholders, Share Registry);
- A visual chart or description of the company’s ownership and control structure;
- Declaration for nominee shareholders (if applicable), with a trust deed/agreement attached where they act on behalf of beneficial owners.
Section 5: Purpose and Business Relationship Details
- Purpose of establishing the business relationship; nature of business / professional activities; services required; anticipated duration of the relationship; scale of operations.
Section 6: Transactional Profile
- Expected transaction types; expected monthly transaction volumes; expected transaction frequency; source of funds used to finance the business relationship.
Section 7: Supporting Document Checklist
- Certificate of Incorporation; Memorandum and Articles of Association; Certificate of Registered Office Address; Certificate of Directors and Secretary; Certificate of Shareholders;
- Declaration for UBOs and ownership structure; trust deed/agreement (if nominee shareholders are involved);
- Proof of identity and proof of address for directors, key controllers, and UBOs;
- Audited financial statements or management accounts; recent bank statement / utility bill.
Section 8: Declaration
The authorised signatory confirms that the information provided is true, accurate, and complete, and undertakes to promptly inform the Company of any changes. For internal use, the Compliance function records the customer risk level (High/Medium/Low), whether initial CDD is complete, additional comments, the reviewer, and the approval details.
Annex VII — Customer Risk Rating Methodology
Customer Risk Rating Matrix
| Risk Category | Risk Factor | Risk Level |
|---|---|---|
| Customer-Related | Bearer share companies | High |
| Customer-Related | Offshore entities | High |
| Customer-Related | Politically Exposed Persons (PEPs) | High |
| Customer-Related | Persons closely connected to a sport or sporting event | Medium |
| Customer-Related | Transactions involving large volumes of cash | High |
| Customer-Related | Customer from a High-Risk Jurisdiction | High |
| Behavioral | Transactions without clear financial rationale | High |
| Behavioral | Inability to verify source of funds or wealth | High |
| Behavioral | Refusal or delay in providing beneficial ownership information | High |
| Communication Channel | Non-face-to-face customer onboarding | Medium |
| Communication Channel | Introduction via third parties | Medium |
| Service/Product | Services allowing third-party payments | High |
| Service/Product | Significant use of cash deposits or withdrawals | High |
| Red Flags | Losses inconsistent with customer profile or means | Medium |
| Red Flags | Unusual spikes in betting or gambling activity | Medium |
| Red Flags | Avoidance or delay in connecting with the Company | Medium |
| Red Flags | False, implausible, or misleading KYC documentation | High |
| Red Flags | Adverse media or inconsistent identity/financial background | High |
| Red Flags | Withdrawals not aligned with betting behavior | High |
| Red Flags | Use of cash deposits to fund online account via betting shops | High |
| Red Flags | Deposits using corporate cards/accounts or by individuals with access to company funds | High |
| Red Flags | Problem gambling patterns linked to potential embezzlement or theft | High |
| Red Flags | Misleading statements about source of funds tied to criminal activity | High |
| Red Flags | Player-to-player criminal fund transfers (regardless of collusion) | High |
| Red Flags | Minimal gambling behavior used to recycle illicit funds | High |
Risk Scoring Guidelines
| Total High-Risk Factors | Total Medium-Risk Factors | Overall Risk Rating |
|---|---|---|
| ≥ 3 High | — | High |
| 1–2 High | ≥ 2 Medium | Medium |
| 0 High | ≥ 3 Medium | Medium |
| 0 High | 0–2 Medium | Low |
Contact
For AML/CFT queries, contact our compliance team at compliance@zplnn.st.