Doc 02

Anti-money laundering and counter-terrorist financing statement

MMFintech Ltd. operates a compliance programme designed to meet its obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and the regulations made under it. This statement summarises that programme. It is a summary, not the programme itself; the full policies and procedures are internal documents made available to providers, auditors and regulators on request.

Governance

  • A compliance officer is designated with the authority, resources and independence required to carry out the role, reporting to the governing body.
  • Policies and procedures are documented in writing and formally approved.
  • A risk assessment is maintained covering clients, products, delivery channels, geographies and technologies used, and is reviewed at least every two years or on material change.
  • Staff, and any agents acting on behalf of the company, receive training on appointment and periodically thereafter, with attendance and outcomes recorded.
  • The effectiveness of the programme is subject to independent review at least every two years, and findings are tracked to closure by the governing body.

Client identification and due diligence

  • Individuals are verified using government-issued identity documents, with a liveness check and biometric comparison.
  • Corporate clients undergo business due diligence, including constitutional documents, confirmation of existence, identification of directors and of ultimate beneficial owners, and verification of the declared activity.
  • Ownership and control structure is recorded, and reasonable measures are taken to confirm the accuracy of that information.
  • Politically exposed person status, and head of an international organisation status, is determined for clients and, where relevant, for their close associates and family members. A positive determination requires senior management approval and source of wealth enquiry.
  • The purpose and intended nature of the business relationship is recorded at onboarding.
  • Ownership of the accounts and addresses a client declares is verified before they are used.
  • Enhanced due diligence, including source of funds and source of wealth, applies to clients assessed as higher risk, together with more frequent review and closer monitoring.
  • Client information is kept current, with review frequency set by risk rating.
  • Where identity cannot be verified to the required standard, the relationship is not established, or is terminated.

Third-party determination

Where there are reasonable grounds to suspect that an account is being used, or a transaction conducted, on behalf of a person other than the client, a third-party determination is made and recorded. Where the third party cannot be identified to the required standard, the transaction is not processed.

Transaction monitoring and reporting

  • Transactions are monitored against scenarios calibrated to the profile of the client portfolio, with the effectiveness of those scenarios reviewed periodically.
  • Alerts are managed through a documented case process with defined escalation criteria and resolution timeframes, and the rationale for each decision is recorded.
  • Suspicious transactions, including attempted transactions, are reported to FINTRAC. No monetary threshold applies.
  • Large cash transactions, large virtual currency transactions and electronic funds transfers are reported in line with the applicable thresholds and the twenty-four hour aggregation rule.
  • Terrorist property is reported to FINTRAC and to the relevant law enforcement authority as required.
  • Records of transactions, supporting documentation, risk assessments and decisions are retained for the statutory periods, in a form that allows them to be produced within thirty days of a request.

Virtual currency

  • On-chain exposure analysis is performed before funds are credited, against defined risk thresholds, with a documented procedure for rejection or freezing.
  • Evidence of control of the originating address is required from the client.
  • Originator and beneficiary information is transmitted on transfers between service providers, in line with travel rule requirements.
  • Transfers involving mixing services, anonymity-enhancing techniques or addresses associated with illicit activity are not accepted.

Reliance on third parties

Where any element of client identification is carried out by an agent, a provider or another party, that arrangement is documented in writing, the underlying records remain available to MMFintech Ltd., and accountability for compliance with the applicable obligations remains with MMFintech Ltd.

Clients and activities not accepted

  • Persons or entities designated on applicable sanctions lists, or owned or controlled by them.
  • Entities without verifiable economic activity or without an identifiable ultimate beneficial owner.
  • Shell arrangements with no operating substance.
  • Gambling and betting operations without a licence in the relevant jurisdiction.
  • Unregistered money transmission or currency exchange businesses.
  • Virtual currency mixing and anonymisation services, and counterparties with exposure to sanctioned addresses.
  • Weapons, controlled substances and goods subject to export control.
  • Investment schemes with a pyramid structure or guaranteed returns.
  • Any client or activity excluded by the policy of a provider on whose infrastructure the service is delivered.