1. Purpose and scope
This Policy sets out the framework Y Tokens LTD ("Y tokens", "we") applies to prevent its services from being used for money laundering (ML), terrorist financing (TF), proliferation financing or the evasion of sanctions.
It applies to all directors, employees, contractors, agents and business partners, and to every product, jurisdiction and channel through which we operate.
2. Regulatory framework
This Policy is designed in line with:
- Directive (EU) 2015/849 (4th AML Directive) as amended by Directives (EU) 2018/843 (5AMLD) and 2018/1673 (6AMLD)
- Regulation (EU) 2024/1624 (EU AML Regulation) and Directive (EU) 2024/1640 (6th AML Directive), as they enter into application
- Regulation (EU) 2023/1113 on information accompanying transfers of funds
- EU restrictive measures (sanctions) and UN Security Council resolutions
- FATF Recommendations and guidelines of the European Banking Authority and the EU AML Authority (AMLA)
- Applicable national legislation of our jurisdiction of incorporation
3. Governance and responsibilities
The Board of Directors holds ultimate responsibility for AML/CTF compliance and approves this Policy at least annually.
A designated Money Laundering Reporting Officer (MLRO), [Name of Money Laundering Reporting Officer], with sufficient seniority, independence and resources, oversees the programme, receives internal reports and liaises with the Financial Intelligence Unit (FIU) and supervisory authorities.
The compliance function is independent from business lines and has direct access to the Board.
4. Risk-based approach
We maintain a documented business-wide risk assessment, reviewed at least annually and whenever a material change occurs. It considers customer, product, service, transaction, delivery channel and geographic risk factors.
Each customer receives a risk rating (low, medium, high) that determines the depth of due diligence and the frequency of ongoing monitoring.
5. Customer Due Diligence (KYC / KYB)
Before establishing a business relationship we:
- Identify and verify the customer using reliable, independent documents, data or information (including eIDAS-compliant electronic identification where available)
- Verify legal existence, registration, directors and authorised signatories of legal entities
- Identify and take reasonable measures to verify ultimate beneficial owners (holding more than 25%, or exercising control by other means) and consult central beneficial ownership registers
- Understand the purpose and intended nature of the business relationship and the source of funds
- Screen the customer, beneficial owners and directors against sanctions, PEP and adverse media lists
We do not open anonymous accounts, work with shell banks or establish relationships where due diligence cannot be completed.
6. Enhanced Due Diligence
Enhanced measures, including senior management approval and verification of source of wealth and source of funds, are applied to:
- Politically exposed persons (PEPs), their family members and close associates
- Customers connected to high-risk third countries identified by the European Commission or FATF
- Complex or unusually large transactions and structures without an apparent economic or lawful purpose
- Any other situation assessed as high risk
7. Sanctions screening
All customers, beneficial owners and relevant counterparties are screened at onboarding and continuously against EU consolidated sanctions lists, UN lists and other applicable lists (including OFAC and UK HMT where relevant). Confirmed matches result in the refusal or freezing of the relationship and reporting to the competent authorities without delay.
8. Ongoing monitoring
We monitor business relationships and activity on an ongoing basis to ensure consistency with our knowledge of the customer and its risk profile. Customer data is periodically refreshed according to risk rating, and alerts generated by monitoring systems are investigated and documented.
9. Suspicious activity reporting
Employees must promptly report any knowledge or suspicion of ML/TF to the MLRO. The MLRO assesses internal reports and, where appropriate, files a Suspicious Transaction/Activity Report with the national FIU.
Tipping-off is strictly prohibited. Employees who report in good faith are protected from retaliation.
10. Record keeping
Customer due diligence records, transaction records, internal and external reports are kept for at least five (5) years after the end of the business relationship or occasional transaction, or longer where required by law, in accordance with the GDPR.
11. Training and awareness
All relevant staff receive AML/CTF and sanctions training upon joining and at least annually thereafter. Training content is adapted to role and risk exposure, and completion is recorded.
12. Independent audit and review
The effectiveness of this Policy and related procedures is tested by an independent internal or external audit function. Findings are reported to the Board and remediated within defined timelines.
13. Prohibited activities
We do not provide services to persons or businesses engaged in illegal activity, sanctioned persons, unlicensed financial services, shell banks, or any activity listed in our prohibited business list. We may refuse, suspend or terminate any relationship where AML/CTF concerns arise.
Contact
Y Tokens LTD, registration no. [Company registration number], [Registered office address]. Questions about this document: compliance@ytokens.com.