Politique anti-blanchiment
Version 1.1 · last update 25/09/2026
Ces conditions existent uniquement en anglais. Le texte anglais est la version qui fait foi.
Anti-Money Laundering and Know Your Customer Policy
INTERNAL PROCEDURE FOR COUNTERACTING MONEY LAUNDERING AND TERRORIST FINANCING REFERRED TO IN in line with applicable obligations under EU AML legislation on the prevention of the use of the financial system for money laundering or terrorist financing
Xnity SA with its registered seat in Avenue Louise 231, 1050 Brussels, Belgium.
Issued and Approved by: President of the Management Board - senior management member responsible for the performance of the obligations resulting from provision of money laundering and terrorist financing regulations in line with applicable obligations under EU AML legislation
Version: 1.0
Issuance date: 01.05.2025
Definitions:
Terms used below shall have the following meaning in whole AML Policy and Annexes
- AML Officer – person, based on employment contract (or equivalent contractual basis), responsible for ensuring the compliance of activity of the obligated institution and its employees and other persons performing activities for the Xnity SA with the provisions on money laundering and terrorist financing according to in line with applicable obligations under EU AML legislation. If AML Officer has not been appointed or is temporarily absent for health or other reasons, the responsibility and functions of the AML Officer bears on the Management Board Member, designated to the area of AML compliance in the Company with accordance with Article 6 and 7 of in line with applicable obligations under EU AML legislation;
- AML Policy – this document, Internal Procedure for Counteracting Money Laundering and Terrorist Financing referred to In in line with applicable obligations under EU AML legislation on Counteracting Money Laundering And Terrorist Financing;
- AML Specialist – person, based on employment contract (or equivalent contractual basis), who perform complex assessments of the Customers’ documents, which are obtained during the Customers’ document verification and after financial security measures make decisions for establishing of business relationships and opening Customers’ accounts. In case Company does not employ AML Specialists, his or her duties are performed by AML Officer;
- Company - Xnity SA with its registered seat at Av. Louise 231, 1050 Brussels, Belgium (hereinafter: “Xnity SA”), is legal entity incorporated by law of Belgium and entered into Commercial Register under Company number 1023.778.877;
- Company System – technological solutions, including software and Customer relationship management, which is use to manage interactions with Customers and potential Customers;
- Customer – natural or legal persons, with whom or with which Company is entering into business relation or occasional transaction;
- CTIF-CFI – the Belgian Financial Intelligence Processing Unit responsible for supervising compliance with anti-money laundering and counter-terrorist financing regulations. Full name: “Cellule de traitement des informations financières (CTIF-CFI)” in French / “Cel voor Financiële Informatieverwerking (CTIF-CFI)” in Dutch.
- Spółkan line with applicable obligations under EU AML legislation - the EU directive of 1st March 2018 on counteracting money laundering and financing terrorism (European Journal of Laws 2023, item. 1124, 1285, 1723, 1843 - consolidated text);
AML Policy content
- Xnity SA with its registered seat in Av. Louise 231, 1050 Brussels, Belgium (hereinafter: “Xnity SA ”), is legal entity incorporated by law of Belgium and entered into Commercial Register under Company number 1023.778.877.
- The issue of anti-money laundering and counteracting terrorism has been regulated in:
- the EU directive of 1st March 2018 on counteracting money laundering and financing terrorism (European Journal of Laws 2023, item. 1124, 1285, 1723, 1843 - consolidated text);
- Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, amending Regulation (EU) No 648/2012 of the European Parliament and of the Council, and repealing Directive 2005/60/EC of the European Parliament and of the Council and Commission Directive 2006/70/EC (OJ L 141, 5.6.2015, p. 73)
- Directive (EU) 2018/843 of the European Parliament and of the Council of 30 May 2018 amending Directive (EU) 2015/849 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, and amending Directives 2009/138/EC and 2013/36/EU (OJ L 156, 19.6.2018, p. 43–74)
- Money laundering shall be understood as the act referred to in Article 299 of the Act of 6 June 1997 – European Penal Code, that is:
Art. 299
§ 1. Anyone who receives, transfers or transports abroad, or assists in the transfer of title or possession of legal tender, securities or other foreign currency values, property rights or real or movable property obtained from the profits of offences committed by other people, or takes any other action that may prevent or significantly hinder the determination of their criminal origin or place of location, their detection or forfeiture, is liable to imprisonment for between six months and eight years.
§ 2. Anyone who, as an employee of a bank, financial or credit institution, or any other entity legally obliged to register transactions and the people performing them, unlawfully receives a cash amount of money or foreign currency, or who transfers or converts it, or receives it under other circumstances raising a justified suspicion as to its origin from the offences specified in § 1, or who provides services aimed at concealing its criminal origin or in securing it against forfeiture, is liable to the penalty specified in § 1.
- Terrorist financing shall be understood as the act referred to in Article 165a of the Act of 6 June 1997 – European Penal Code; that is:
Art. 165a
Anyone who collects, transfers or offers means of payment, financial instruments, securities, foreign exchange, property rights or other movable or immovable property in order to finance a terrorist offence is liable to imprisonment for between two and 12 years.
- The aim of money laundering is to transfer the proceeds from criminal activity into a legitimate financial space and business cycle. Detailed criteria as to when money laundering is considered such in a legal sense are specified in the Law.
- The process of money laundering can be divided into three stages: placement, layering, and integration:
- Placement
Introduction of cash or other physical valuables originating from illegal / criminal activities into financial or non-financial institutions.
- Layering
Separating the proceeds of criminal activity from their source through the use of layers of complex financial transactions. These layers are designed to hamper the audit trail, disguise the origin of funds and provide anonymity. - Integration
Placing the laundered proceeds back into the economy in such a way that they re-enter the financial system as apparently legitimate funds. - Financial/non-financial institutions may be misused at any point in the money laundering process.
- Money laundering shall be regarded as such regardless of whether the exact criminal act from which funds are derived has been identified.
- Financing of terrorism is collection or transfer of any funds or other assets, whether directly or indirectly, to be used for (or with knowledge that they will be used for, either in full or in part) committing acts of terror or any related action.
- The financing of the manufacture, storage, transfer, use or distribution of weapons of mass destruction (hereinafter referred to as proliferation) – any direct or indirect collection or transfer of funds or other property obtained in any form, with a view to using them or knowing that they will be used in whole or in part to finance proliferation.
- Virtual currencies are developing quickly and are an example of digital innovation. However, at the same time, there is a risk that virtual currencies could be used by terrorist organizations to circumvent the traditional financial system and conceal financial transactions as these can be carried out in an anonymous manner.
- Xnity SA performs business activity consisting in the provision of services in the scope of providing virtual assets services. According to in line with applicable obligations under EU AML legislation, scope of the business activity of the Xnity SA has to be recognized as exchange between virtual currencies and means of payment. According to Article 2 point 1 section 12 letter a of in line with applicable obligations under EU AML legislation Xnity SA has to be recognized as “obligated entity”.
- The authority of European government administration exercising control over the compliance with the provisions on counteracting money laundering and terrorist financing is the Belgian Financial Intelligence Processing Unit (CTIF-CFI), hereinafter referred to as the “CTIF-CFI”.
- This Policy outlines the minimum general unified standards of internal KYC / AML control which would be adhered to by the Xnity SA in order to mitigate the legal, regulatory, reputational, operational, and as a consequence financial risks.
- The main objectives of this policy are:
- prevent Xnity SA from being used, intentionally or unintentionally, by criminal elements for money laundering or financing terrorist activities;
- enable Xnity SA to know and understand its Customers with which Xnity SA has any financial dealings with and their financial background and source of funds better, which in turn would help it to manage its risks prudently;
- compliance with all applicable regulations, rules and laws and will be reviewed and updated on a regular basis to ensure appropriate policies, procedures and internal controls are in place to account for both changes in regulations and changes in Xnity SA business;
- put in place appropriate controls for detection and reporting of suspicious activities in accordance with applicable laws, procedures and regulatory guidelines; and
- equip Xnity SA s personnel with the necessary training and measures to deal with matters concerning KYC/AML procedures and reporting obligations.
- This Policy and defined KYC and AML procedures are revisited periodically and amended from time to time (especially in relation to changes in the risk factors concerning Customers, countries or geographical areas, products, services, transactions or their delivery channels – according to art. 27 point 3 EU directive of 1st March 2018 on counteracting money laundering and financing terrorism) based on prevailing industry standards and international regulations designed to facilitate the prevention of illicit activity including money laundering and terrorist financing.
- This Policy is subject to approval by the senior management of Xnity SA .
Customer identification – KYC Procedure
- In order to establish business relation with Xnity SA, Customers have to proceed through specific identity verification procedure.
- The aim of this section is to ensure the proper identification and verification of Customers participating in transactions, as well as ongoing monitoring of business relationships, including transactions carried out during business relationships, regular verification of data used for identification, update of relevant documents, data or information and, when necessary, identification of the source and origin of funds used in transactions.
- Customer due diligence is one of the main tools for ensuring the implementation of legislation aimed at preventing money laundering and terrorist financing and at applying sound business practices.
- Customer due diligence comprises a set of activities and practices arising from the organizational and functional structure of the Company and described in internal procedures, which have been approved by the directing bodies of the Company and the implementation of which is subject to control systems established and applied by internal control rules.
- The purpose of Customer due diligence is to prevent the use of assets and property obtained in a criminal manner in the economic activities of credit institutions and financial institutions and in the services provided by them whose goal is to prevent the exploitation of the financial system and economic space of the Belgium for money laundering and terrorist financing. Customer due diligence is aimed, first and foremost, at applying the Know-Your-Customer principle, under which a Customer shall be identified and the appropriateness of transactions shall be assessed based on the Customer’s principal business and prior pattern of payments. In addition, Customer due diligence serves to identify unusual circumstances in the operations of a Customer or circumstances whereby an employee of the Company has reason to suspect money laundering or terrorist financing.
- Customer due diligence ensures the application of adequate risk management measures in order to ensure constant monitoring of Customers and their transactions and the gathering and analysis of relevant information. Upon applying the Customer due diligence measures, the Company will follow the principles compatible with its business strategy and, based on prior risk analysis and depending on the nature of the Customer’s business relationships, apply Customer due diligence to a different extent.
- Customer due diligence are applied based on risk sensitive basis, i.e. the nature of the business relationship or transaction and the risks arising therefrom shall be taken into account upon selection and application of the measures. Risk-based Customer due diligence calls for the prior weighing of the specific business relationships or transaction risks and, as a result thereof, qualification of the business relationship in order to decide on the nature of the measure to be taken (for instance, normal, enhanced or simplified due diligence measures could be applied).
- Upon establishing a business relationship, the Company will identify the person and verify their right of representation based on reliable sources, identify the beneficial owner and, in the case of companies, the control structure, as well as identify the nature and purpose of possible transactions, including, if necessary, the source and origin of the funds involved in the transactions.
- Customer due diligence measures are appropriate and with suitable scope if they make it possible to identify transactions aimed at money laundering and terrorist financing and identify suspicious and unusual transactions as well as transactions that do not have a reasonable financial purpose or if they at least contribute to the attainment of these goals.
- Where the risk associated with a business relationship is low, and to the extent permitted by national legislation, the Company applies simplified Customer due diligence measures (SDD). Where the risk associated with a business relationship is increased, the Company applies enhanced Customer due diligence measures (EDD).
Natural person Customer identification
- To enter into business relation with Xnity SA Customer who is natural person has to provide following data:
a. Full Name (first name and last name separately);
b. Residential Address (or another verifiable address of correspondence);
c. Citizenship;
d. Date of Birth and Place of Birth;
e. Type, series, and number of a valid identity document (e.g., passport, national ID);
f. Proof of current residence (utility bill, lease agreement, or equivalent);
g. If registered as a business: the business name, address of primary activity, and Tax Identification Number (if available).
If not registered: this requirement is waived but may be supplemented with a statement of self-employment or freelance status.
- Customers should submit their identification data and other information (address verification document, information about payment methods) requested by the Company, doing registration process in the Company System, or provide such data to the AML Specialist after AML Specialist request.
- Verification of identity is required by obtaining a high-resolution, non-expired copy of the Customer’s government-issued ID:
Passport (national or international), - National identity card with MRZ code (front and back),
- Natural person should submit a national identity document issued by the resident country, or equivalent identity document, or identity document, which is valid for entry into the country there identification are taken.
- The Company verifies the correctness of the data specified in this section, using information originating from a credible and independent source for that purpose.
- The AML Specialist using the Document Verification System provided by an authorized KYC service provider and shall perform the following checks:
- Face Match Check, which allow to confirm matches of an image of a person face among a range of other photo images found in various documents, for example a passport, a photo ID as well as selfies or avatar images. A completed search results in a “match” or “doesn’t match” result. Required data for input: image of person face and images of document containing the image of the persons face;
- Identity Check, which allow to verify of a person identity by matching persons data against data from mutiple document check databases.
- After providing of necessary information the authorized KYC service provider makes checks in Global Watchlist.
- The database of a variety of lists across the globe that the partner uses to run regular identity checks against known or suspected terrorists, money launderers, frauds or PEPs. The watchlist includes domestic and international, government, law enforcement and regulatory databases that store information on individuals who are on a criminal list or prohibited in certain industries such as finance and healthcare. Among such people are specially designated nationals, terrorists, narcotics traffickers, money launderers, blocked persons, parties subject to various economic sanctioned programs who are forbidden from conducting business and those involved in the proliferation of mass destruction weapons.).
- If the Customer wants to continue collaboration with the Company he/she should to pass full verification process and provide requested documents.
- The potential or existing Customer shall present identity (personal) documents to the Company:
- in the form of original document (natural and legal entities) for identification in person;
- in the form of uncertified copies for remote identification.
- The Customer's identity (personal) document and other documents submitted to the Company shall satisfy the following requirements:
- Identity documents of natural entities shall contain the information listed in clause 28;
- The documents shall be valid (the validity term specified in the document has not expired at the time of presentation to the Company, and the document is not declared invalid);
- The documents should contain no evident signs of falsification, corrections, cross-outs or deletions;
- The documents should contain no damages (water, stains of dye, punches, etc.);
- Verification of residence is required by obtaining a copy of an acceptable address proof document issued in the 3 months prior to establishing an business relationship with Xnity SA . The document must carry the Customer’s name and address. A valid proof of residence document can be:
- bank statement;
- debit or credit card statement;
- utility bill (water, electricity, gas, internet, phone);
- payroll statement or official salary document from employer;
- insurance statement;
- tax document; or
- residence certificate.
Business entity Customer identification
- For Customers who are legal entities (e.g., registered businesses or associations), the following data is required to enter into a business relationship with Xnity SA:
a. Business name;
b. Organizational form (e.g., sole proprietorship, company, NGO);
c. Registered office or main business address;
d. Tax Identification Number (if applicable);
e. Commercial registration number;
f. Date of registration;
g. Identification details of the natural person(s) representing the entity, as described in sections 12–15.
Note: This section does not apply to natural persons (e.g., independent sex workers) registering individually. For such individuals, identity verification follows the process described in article 38.
- Xnity SA verifies the legal status of a Customer acting as a legal entity (e.g. registered business, association) using appropriate and relevant documentation, such as:
a. Excerpt from the official business or trade register;
b. Certificate of Incorporation or Registration;
c. Proof of business activity (e.g. VAT number, business license);
d. Governance documents (e.g. Articles of Association or Partnership Agreement, if applicable);
e. Proof of shareholding or ownership structure (if relevant);
f. Authorized representative list or power of attorney (if someone else acts on behalf of the entity).
Note: This section does not apply to individual service providers or independent sex workers registering as natural persons.
41. Xnity SA ensures that any person acting on behalf of a legal entity is duly authorized to do so.
42. Once all required documents have been received, the AML Specialist performs a verification of submitted documents through a secure Document Verification System provided by an authorized third-party KYC provider.
43. The Document Verification System may include the following checks:
a. Document integrity analysis – automatic detection of tampering or manipulation in scanned images or photographs of ID documents;
b. Text extraction – automatic reading and extraction of relevant fields from the documents;
c. Data consistency check – validation that information across multiple documents matches, identification of duplicate accounts, and confirmation that documents were not re-photographed from screens or altered
- Xnity SA verifies that any person purporting to act on behalf of the legal person / entity is properly authorized.
- When all required documents are received from the Customer, the AML Specialist shall perform a Customer’s documents verification against the Document Verification System provided by an authorized third-party KYC provider.
- The AML Specialist using the Document Verification System provided by an authorized third-party KYC provider shall perform the following checks:
- Document Integrity checks, automatically verification of the authenticity of photos and scanned copies of physical documents check. The documents Document Integrity checks means analysis of any image or series of images for signs of tampering or modification through the use of graphic editors. Each reviewed document receives a trust score;
- Text recognition, allows automatically extract data from the documents;
- Additional check. Includes checking of completeness of documents, check if photos have been retaken from a screen or not, cross checking of all data from all submitted documents (name, date and place of birth, signature), checking for duplicated accounts, address check.
- If AML Specialist detected any problems with verification documents, AML Specialist shall:
- if the verification of documents indicates that the identity document may be invalid, the AML Specialist shall contact the issuing authority of the identity document and establish the status of the identity document;
- if the identity document is invalid, the AML Specialist shall be notified and establishment of Business Relations with the Customer shall be refused;
- verify the data contained in the documents submitted to the Company by legal entities with the relevant information about them in the databases: for example in the Belgium it will be National Court Register -
- Natural persons acting on behalf of the Customer (UBO, directors, etc.) are checked automatically as part of the general KYC process. Checking process includes a combination of state and other public registers, corporate documents provided by the legal entity, and open sources is used. First, basic information about the company is collected (registration number, address, etc.); then a control and beneficial ownership structure is checking with a simultaneous verification of the uploaded documents for the validity and availability of all necessary details. The list of documents that the partner accepts depend from the jurisdiction of the legal entity. Additionally, AML-screening is automatically carried out (check against sanction lists, adverse media, blacklisting, etc.).
- The respective Customer’s excerpt from the register shows the actual authorized representatives of a Company in order to ensure that the extract really is up-to-date, it should not be older than 6 (six) months. If the present register extract is older, the AML Specialist must verifying its content online. The AML Specialist must compare the information available in register extract with the information received from the Customer.
- The AML Specialist contact the Customer to establish the reason of discrepancies, if the verification reveals any discrepancies. The AML Specialist shall refuse establishment of the business relations with the Customer unless the Customer is able to provide logical and reliable explanation of the reasons of such discrepancies.
- The AML Specialist verify the data contained in the documents submitted to the Company by legal entities (Customers from other countries if the relevant information about them is available from the European Business Register) against the information contained in the European Business Register database or other foreign registers available to the Company.
- Data from the registers (databases) in question shall be printed out as a part of verifications described above and shall be saved in form of electronic Customer files in the Company System.
Identification of Beneficial owner
- Company takes measures to identify the beneficial owner(s) of the contractor and verify his identity by obtaining data stipulated in point 28 of this Policy.
- Where business relationships are established or occasional transactions are conducted with a contractor which is the entity obligated to register of information on beneficial owners, the Company shall obtain the confirmation of the registration or a copy from the European Central Register of Beneficial Owners or the relevant register maintained in a Member State.
- Beneficial owner shall be understood as a natural person or natural persons who control, whether directly or indirectly, a contractor through their powers which result from legal or factual circumstances and enable exerting a decisive impact on a contractor’s acts or actions, or a natural person or natural persons on whose behalf business relationships are being established or an occasional transaction is being conducted, including:
- in the case of a contractor being a legal person other than a company whose securities are admitted to trading on a regulated market that is subject to disclosure requirements market that is subject to disclosure requirements in accordance with the EU law or subject to equivalent third country law:
- a natural person being the contractor’s shareholder or stockholder and holding the ownership right to more than 25 per cent of the total number of stocks or shares of such legal person, - a natural person holding more than 25 per cent of the total number of votes in the contractor’s decision-making body, also as a pledgee or usufructuary, or under arrangements with other holders of voting rights,
- a natural person exercising control over a legal person or legal persons holding in aggregate the ownership right to more than 25 per cent of the total number of stocks or shares of the contractor or holding in aggregate more than 25 per cent of the total number of votes in the contractor’s body, also as a pledgee or usufructuary, or under arrangements with other holders of voting rights,
- a natural person holding a senior management function in the case of the documented inability to determine beneficial owner in other way.
- in the case of a contractor being a trust: - the settlor, - the trustee, - the supervisor, if any, - the beneficiary, - other person exercising control over the trust;
- in the case of a contractor being a natural person carrying out economic activity with respect of whom/which no premises or circumstances were found which could indicate that any other natural person or natural persons exercise control over him/her, such contractor shall be assumed to be the beneficial owner at the same time.
- Identification of the Beneficiary serves the purpose of preventing the provision of services by the Company to one or more natural or legal entities that intentionally and purposefully conceal their actual identity, i.e., under the guise of another natural or legal entity.
- The AML Specialist shall identify the Beneficiary before establishment of business relations by means of obtaining the minimum information listed in clause 28, in any of the following ways:
- Obtaining the information about the Beneficiary of the Customer from the Company System;
- Using the data or documents from the information systems of the Belgium or another country, in particular information from European Central Register of Beneficial Owners: , however Company shall not rely exclusively on the information from the European Central Register of Beneficial Owners or the register referred to in Article 30 or 31 of Directive 2015/849 maintained in the relevant Member State;
- Establishing the identity of the Beneficiary based on the documents proving the identity of a Beneficiary, the document containing up-to-date particulars from the excerpt from the relevant register or other documents, particulars or information originating from a reliable or independent source.
- In accordance with the provisions hereof, the Responsible Officer shall take all and any steps required, useful, feasible and reasonable to identify the Beneficiaries of the potential and existing Customers. The AML Specialist shall identify the Beneficiary of the Customer as well as the Beneficiary from one or more related financial transactions if different from the Beneficiary identified earlier.
- The AML Specialist shall perform the steps again described in the AML Policy for identification of the Beneficiary whenever there are grounds to suspect that:
- The Beneficiary is a person other than that declared by the Customer; or
- The Customer has provided incorrect, inaccurate or incomplete information to the Company about the Beneficiary.
- Further, guided by considerations of reasonability, proportionality and usefulness on each individual occasion, and where the circumstances mentioned in clause 57 exist, the AML Specialist shall request one or more of the following documents (information) about the Beneficiary as appropriate on the given occasion:
- Information about the Beneficiary's occupation, profession, professional experience and the documents that support such information;
- An identification document of the Beneficiary signed by the Beneficiary to certify the status of Beneficiary of the Customer;
- A document signed by the Beneficiary to disclose the origin of their Assets and documents that support the legitimacy of the origin thereof (such as certifications from various property registers (the Land Register; the Register of Water Transport Vehicles; the Register of Road Transport Vehicles; the Aircraft Register; the Company Register, etc.), certificates issued by Tax Administration; loan agreements; last wills; current account statements and other documents);
- Documents supporting the information about the grounds on which the person in question should be treated as the Beneficiary of the Customer (such as current account statements that evidence benefitting from the Customer; reliable written explanation made by the Customer or the Beneficiary to the effect that the Beneficiary benefits from the Customer);
- Tax (income) returns; certificates of wages, dividends or income from existing contract agreements;
- Other information and documents about the Beneficiary found appropriate to establish that the declared Beneficiary is the actual Beneficiary.
- If the AML Specialist finds it appropriate, the AML Specialist may:
- request the Beneficiary to appear to the Company in person and provide the data specified in the AML Policy; or
- arrange the AML Specialist’s visit to the Beneficiary for obtaining the data specified in the AML Policy; or
- obtain further information about the Beneficiary from the sources available to the Company, such as public databases or the Internet.
- Having examined the information provided by the Customer and available from other sources about the declared Beneficiary, the AML Specialist shall check and assess the following:
- whether such information is sufficient and reliable (the considerations of sufficiency and reliability shall be documented with objective substantiation), that is, whether it is clear from the documents contained in the Customer's file that the Beneficiary is a person corresponding with the economic or personal activities of the Customer (in terms of scope and specifics);
- whether it demonstrates that the declared Beneficiary can be the actual Beneficiary;
- whether the age or social/financial condition or occupation of the Beneficiary corresponds with the specifics of economic activity of the Customer and raises no suspicion of Money Laundering or Terrorism Financing;
- whether the collected information otherwise raises suspicion of Money Laundering or Terrorism Financing.
Business relations with Politically Exposed Persons (PEP)
- Politically exposed persons (PEP)shall be understood as natural persons with prominent posts or prominent public functions, including:
- heads of State, heads of government, ministers, deputy ministers, secretaries of state, and undersecretaries of state, including the President of the Belgium, the Chairman of the Council of Ministers, and the Vice-Chairman of the Council of Ministers;
- members of parliament or similar legislative bodies, including deputies and senators;
- members of the governing bodies of political parties;
- members of supreme courts, of constitutional courts or of other high-level judicial bodies, the decisions of which are not subject to further appeal, except under exceptional procedures, including the judges of the Supreme Court, of the Constitutional Tribunal, of the Supreme Administrative Court, of voivodeship administrative courts and judges of appellate courts;
- members of courts of auditors or of the management boards of central banks, including the President and members of the Management Board of NBP;
- ambassadors, chargés d'affaires and high-ranking officers in the armed forces;
- members of the administrative, management or supervisory bodies of state-owned enterprises, including directors of state-owned enterprises and members of the management or supervisory boards of companies with the State Treasury shareholdings in which more than a half of stocks or shares are held by the State Treasury or other state-owned legal persons;
- directors, deputy directors and members of the bodies of international organizations or persons performing equivalent functions in these organizations;
- general directors of supreme and central offices of state authorities, general directors of voivodeship offices, and managers of field offices of the special government administration authorities.
- Family members of a politically exposed person - this shall be understood as:
- a spouse or a cohabitant of a politically exposed person;
- a child of a politically exposed person and his/her spouse or a cohabitant;
- parents of a politically exposed person.
- Persons known to be close associates of a politically exposed person - this shall be understood as:
- natural persons who have beneficial ownership of legal persons, organizational units having no legal personality or trusts with a politically exposed person, or any other close relationships with such a person related to the business activity conducted;
- natural persons who have sole beneficial ownership of legal persons, organizational units having no legal personality or a trust which is known to have been set up for the de facto benefit of a politically exposed person.
- In order to establish whether a natural person Customer or a beneficial owner is a PEP Xnity SA executes determinations as follows:
- receives a statement from the Customer or beneficial owner in written or document form, to the effect that the Customer/beneficial owner is or is not a politically exposed person, which statement shall be submitted under pain of penalty of perjury. The person submitting the statement shall include therein the clause reading as follows: “I am aware of the penalty of perjury.”. This clause according to European law replaces a notice of penalty of perjury;
Enhanced security measures
- Xnity SA undertakes enhanced financial security measures in the cases of
- higher risk of money laundering or terrorist financing;
- business relations with Politically Exposed Persons (PEP)
- A higher risk of money laundering and terrorist financing can be indicated in particular by:
- establishment of business relationships in unusual circumstances;
- the fact that the Customer is:
- a legal person or an organizational unit having no legal personality, whose activity serves to storage of personal assets;
- a company in which bearer shares were issued, whose securities are not admitted to organized trading, or a company in which the rights attached to shares or stocks are exercised by entities other than shareholders or stockholders;
- the subject of the business activity carried out by the Customer covering conducting of a significant number of cash transactions or cash transactions of high amounts;
- unusual or excessively complex ownership structure of the Customer, having regard to the type and scope of the business activity conducted by this Customer;
- the fact of the Customer making use of services or products offered as part of private banking;
- The use by the Customer of services or products that promote anonymity or hinder identification — including, but not limited to, services generating multiple virtual account numbers or payment identifiers linked to a single account, intended to mask the originator or recipient of funds,shall be treated as a high-risk indicator, in line with applicable EU AML guidelines.
- the fact of establishment or maintenance of business relationships or conducting an occasional transactions without the Customer being physically present - in the case when a higher risk of money laundering or terrorist financing related thereto was not mitigated in another manner, including by the use of the a notified electronic identification measure adequately to the medium security level referred to in Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC (OJ L 257, 28.8.2014, p. 73) or the requirement of using a qualified electronic signature or a signature confirmed by the Electronic Platform of Public Administration Services (ePUAP) trusted profile;
- the fact of ordering of transactions by third entities unknown or not linked to a Customer, the beneficiary of which transactions is the Customer;
- the fact of covering by business relationships or transactions of new products or services or offering of products or services with the use of new distribution channels;
- linking business relationships or an occasional transaction by Customer with:
- a high-risk third country;
- a country defined by reliable sources as a country of high corruption or other criminal activity levels, a country providing funding or support for committing activities of a terrorist nature, or with which an activity of an organization of a terrorist nature is associated;
- a country in relation to which the United Nations Organization or the European Union have taken a decision on imposing sanctions or specific restrictive measures.
- the fact that business relationships or occasional transaction are related to crude oil, arms, precious metals, tobacco products, cultural artefacts, ivory, protected species or other items of archaeological, historical, cultural and religious importance, or of rare scientific value;
- the fact that business relationships or occasional transaction are related to a Customer who is a citizen of a third country and applies for a right to stay or citizenship in a Member State in exchange for capital transfers, immovable property acquisition or Treasury bonds or, as the case may be, investments in corporate entities in a given Member State.
- Enhanced security measures provides a greater level of scrutiny of potential and current Customers. In the cases of higher risk of money laundering or terrorist financing Xnity SA undertakes steps to understand the origin and legitimacy of the Customer’s wealth and ask Customer for additional documents and information other than stipulated in point 28-33 of the Policy, in particular:
- Official corporate records of amendments in corporate structure from last 18 months;
- Copy of Annual Financial Statements from last 3 years;
- Copy of Tax Declarations with confirmation of submission from last 3 years;
- Names and location of Customer’s Customers and suppliers;
- Bank statements from last 18 months;
- Copy of lease agreement of register office;
- Standard documents, which confirm the sale of property, inheritance, salary, etc.
- In the cases of higher risk of money laundering or terrorist financing Xnity SA verifies also Customer (its representatives and beneficial owner) in sanctions list, in particular:
- Warning of The European Financial Supervision Authority;
- Warnings of the European Office of Competition and Consumer Protection ;
- VIES – European Comission;
- United Nations Security Sanction list;
- Us Consolidated Sanctions,
- EU Financial Sanctions,
- UK Financial Sanctions,
- Interpol Wanted List,
- Office of the Superintendent of Financial Institutions (Canada)
Monitoring ongoing business relationship
- The Company undertakes ongoing monitoring of Customer’s business relationship, including:
- the analysis of transactions carried out throughout the course of business relationship in order to ensure that such transactions are compliant with the knowledge of the Company on the Customer, the type and scope of activity carried out by it, as well as compliant with the money laundering and terrorist financing risk associated with such a Customer,
- examining the origin of assets available to the Customer - in cases justified by circumstances,
- censuring that any possessed documents, data or information concerning the business relationship shall be updated on an on-going basis.
- The Company shall perform Customer monitoring compliance with legal requirements and follow the principle Know Your Customer (KYC) in order to minimize to as far as possible the eventual occasions of money laundering and terrorism financing.
- Customer monitoring shall be performed by the AML Specialist in cooperation with all Employees who are entrusted to performing such duties in accordance with the Internal Regulatory Documents.
- Customer monitoring shall take the form of:
- Monitoring and control of the Customers financial transactions;
- Regular supplementing and updating the Customer files;
- Regular supplementing and updating the Customer information in the Company System;
- contact with the Customers;
- On other affairs specified in the Internal Regulatory Documents.
- Customer monitoring through the control and monitoring of the Customers financial transactions should be performed under AML Policy. Each day the AML Specialist shall select the Customers for performing outgoing monitoring.
- The AML Specialist shall review the Customer identification under AML Policy if:
- Identification data of the Customer have changed;
- Name, surname, personal number of a natural person has changed;
- Name, registration number, legal status of a legal entity has changed;
- A new identity document has been issued to a natural person;
- A new legal corporate document has been issued to a legal entity;
- Legal or contractual representative of the Customer has been changed;
- There are basis for doubting in the validity of the representation right of legal or contractual representative of the Customer.
- Customers ongoing monitoring and updating documents/information in the Customer file shall be conducted, depending on the category or status of the Customer:
- for the High Risk Customers - at least every quarter;
- for the other category risk of Customers - at any time chosen for the Customer by the AML Specialist with due regard to the actual circumstances;
- The AML Specialist shall control the regular updates of documents/information in the Customer file, and other Employees shall be attracted in the process as appropriate in the manner prescribed by the AML Policy and the Internal Regulatory Documents.
- The AML Specialist must update the Customer file according to the following steps:
- Review the Customer file;
- Check the Customer data in the Company System;
- To get overview of financial transactions in the Company System ordered or performed by the Customer during the reporting period.
- Under the Customer file review, the AML Specialist shall ensure that the Customer file contains all documents and information required in accordance with the AML Policy and Internal Regulatory Documents.
- Under checking the Customer data in the Company System, the AML Specialist shall:
- ensure that the Customer file contains all required information regarding the Customer;
- ensure that all included information corresponds to the documents contained in the Customer file.
- The AML Specialist shall check the Customer data with focus on the following information:
- To which category the Customer belongs to;
- The declared economic activity of the Customer;
- The declared amounts of financial transactions performed by the Customer;
- The partners and geographic regions of economic activity of the Customer.
- Under checking the Customer file and Customer's financial transactions report (the report should be stored in electronic format in the Customer file), the AML Specialist shall prepare the assessment or opinion.
- Under the assessment or opinion on the Customer, the CMD officer shall issue any of the following decisions:
- Continue the previous business relationship with the Customer;
- Continue the previous business relationship with the Customer and request to submit the following documents and information;
- Propose termination of business relationship with the Customer.
- If the CMD officer makes the decision to continue the business relationship with the Customer and assign the status of high risk to the Customer, further documents or information shall be requested from the Customer to the extent required in accordance with the Internal Regulatory Documents from Customers accordance with the given category.
- If the CMD officer makes the decision for termination of the business relationship with Customer, business relationship with the Customer shall be terminated in accordance with this AML Policy.
- If Company send the notice to the Customer with request for documents/information it shall be clearly formulated with questions related to its research and understanding of the Customer's economic or personal activity, for establishing and identification of the Customer's Beneficiary and for taken the decision about business relationship with the Customer.
- Customers which turnover is equivalent or more than EUR 30.000 shall submit to the Company a written confirmation of legitimacy of origin of its capital or assets including description of the sources of origin by the request of the AML Specialist.
- The AML Specialist shall prepare the request for information including the following data:
- The Company’s forms which to be filled by the Customer;
- Link to the access to such forms by the Customer;
- Any other documents or information to be submitted by the Customer to the Company;
- The Company's questions to the Customer;
- The manner of the Customer's reply to the request;
- The period for replying to the request.
- The period for replying on the request for submitting the documents and information shall be 10 (ten) working days from the request date.
- The period specified in clause 87 above may be extended or reduced if the CMD officer finds it necessary and feasible.
- If the request for documents and information is prepared, the CMD officer shall ensure that the term for submitting the documents and information specified in the request is observed.
- The Customer may submit the documents and information to the Company:
- via Company System;
- by e-mail;
- in person to the Company.
- After Customer reply with requested documents and information is received, the AML Officer shall immediately (within the next following business day) check:
- Does the Customer has performed all requirements specified in the request for submitting of documents and information, including: all necessary forms are filled out; all requested information and documents submitted; all answers on the questions are submitted.
- Does the form comply with documents submitted by the Customer and perform the requirements of regulatory acts and the Internal Regulatory Documents concerning the executing of documents.
- If Customer submitted documents and information does not comply with all requirements specified in the request, with regulatory acts and the Internal Regulatory Documents, the AML Specialist shall request to the Customer to correct identified deficiencies within three business days and immediately notify the AML Officer (within the next following business day) by e-mail.
- If the Customer does not comply with requirements under request for remove of the identified flaws, the AML Officer shall immediately (next business day after following to expiration period granted for replying on the request and for presentation of information and documents) forward the documents received from the Customer in the volume and form received by the AML Officer on the period expiration day for provided for replying to the request for submitting the documents and information.
- If the Customer does not comply with requirements under request for documents and information under specified period or fails to meet the request for elimination of the identified shortcomings within the specified period, the AML Specialist shall e-mail a report on such fact to the AML Officer, along with the documents submitted by the Customer, and specify the following:
- The date and delivery method of the request for documents\information to the Customer;
- The period for providing the reply on the request for documents and information or remove of the identified flaws;
- Any reasons for not fulfilling answer deadline from the Customer site.
- The AML Officer should receive the reply with the requested documents and information from the Customer, if establish the failure of the Customer in presenting the requested documents or their insufficiency or non-compliance with the Company's requirements, the AML Officer shall take the following steps:
- Issue additional request for documents and information to the Customer specifying the additional documents to be submitted by the Customer to the Company and the term for answering to the request for documents and information;
- Issue request for documents and information to the Customer in accordance with the AML Policy.
- The AML Specialist shall remind, if Customer does not answer to the request for documents and information and ensure that all requirements are performed, the AML Specialist shall obtain approval with allocated instruction from the CMD officer (using the “reply” function via e-mail).
- Monitoring also involves identifying expired documents, changes in company structures, changes in address or business location and determining whether the Customer has become politically exposed, sanctioned or involved in dealings which are deemed to be high risk. Changes in the Customer profile might increase the Customer’s risk category assigned, therefore requiring enhanced security measures.
Screening of transactions
- The AML Specialist or AML Officer should check the ordered and performed transactions of the Customers for detecting suspicious transactions.
- In accordance with the AML Policy and Internal Regulatory Documents the AML Specialist or AML Officer should perform the following steps:
- Real-time screening;
- Retroactive searching;
- Transaction monitoring.
- Real-time screening mean screening of a transaction before performing.
- Real-time screening should be performed is aimed to prevent the access to the Company services by any person what could be subject to the international and national sanctions.
- Automatic real-time screening should be performed, if:
- The Company System issue a warning to the AML Specialist or AML Officer who accepts the transaction, therefore he or she should check the information included in the transaction details with the warning or sanctions lists;
- The AML Specialist or AML Officer should check the warning assess the coincidence and proceed with the steps prescribed in the AML Policy regarding to suspicious transactions, if the name and surname of the person or name of the company matches or differ from the name and surname of the respective person, or name of an organization contained in the matches lists by 3 or less digits.
- Retroactive searching means early performed transaction screening.
- Retroactive searching shall be conducted by the AML Specialist in cooperation with other Employees for the purpose of analysis of the Customer on the basis of the transactions ordered or performed by the Customer.
- Retroactive searching shall be conducted:
- Through the Company System where the information is saved about all and any transactions ordered/performed by the Customer;
- By the AML Specialist via e-mail request for information regarding the transactions or from the Employees which is performing Customer support;
- By the AML Specialist through the search functions of the Company System;
- By the AML Specialist using the reporting function in the Company System that allows different report printing in respect of the Customers, transactions or groups of Customers from the Company System according to specified criteria.
- The AML Specialist shall request information via e-mail about the transactions of interest from the Employees who perform Customer support, where it is appropriate and execute the request in writing.
- Before receiving the request from the AML Specialist about transactions, the Employee who performing Customer support shall replay via e-mail received request within the period specified in such request.
- The request issued by the AML Specialist, replies and analysis received from other Company Employees shall be stored in electronic format in the Customer file.
- Transaction monitoring means the monitoring of an individual transaction or a series of transactions aimed at preventing Money Laundering and Terrorism Financing.
- Transaction monitoring shall include assessment of relation of the Customer's economic or personal activity and financial condition with the nature and amount of the transaction and ensuring that the transaction neither meets the criteria of suspicious transaction nor raises suspicion of Money Laundering or Terrorism Financing.
- Transaction monitoring shall be provided by means of the various filters integrated in the Company System before performing the transaction and as a part of their analysis after the performance. The types of filters, what should be integrated into the Company System (such as filters for each individual type of electronic funds or virtual currency) shall be defined and documented by the Member of the Board of the Company. Integration of the filters defined by the Member of the Board of the Company into the Company System shall be ensured by the IT department.
- The filters integrated in the Company System shall be enable the Employees to focus on transactions exposed to higher risk and subject to manual treatment prior to their performance.
- The features and criteria for the filters, which should be integrated into the Company System shall be developed by the AML Officer or Member of the Board of the Company in cooperation with the IT department.
- Special attention before accepting of the ordered transactions shall be given to the following transactions:
- Large, complicated transactions on typical for the Customer or series of transactions without evident economic or legitimate purpose;
- Transactions with participation of parties from the Third Countries listed according to the opinion of the international bodies as jurisdictions with non-existing or weak regulatory acts for AntiMoney Laundering or Terrorism Financing or countries that have refused to cooperate with the international bodies in the area of Anti-Money Laundering and Terrorism Financing.
- In case of uncertainty or doubt, Employee, who is responsible for compliance assessment of transactions shall be available to request written approval for payment or separate written opinion regarding the transaction from AML Officer or Member of the Board of the Company.
Termination of business relations with the Customer
- Should the Company be unable to apply one of the Customer due diligence measures:
- it shall not establish a business relationship;
- it shall not perform an occasional transaction;
- it shall not conduct transactions through the bank account;
- The Company must terminate business relations with the Customer according to AML Policy and other Internal Regulatory Documents.
- If identification of the Customer is required by the Anti-Money Laundering and Terrorism Financing Law, but identification of the Customer and the Beneficiary in accordance with the AML Policy is impossible, the AML Specialist shall not allow the service for such persons, establish business relations and perform financial transactions with such persons; the AML Specialist shall terminate the business relations with Customer.
- The AML Specialist must terminate business relations with the Customer if identification of the Customer or received information and documents in the volume required to enable the relevant investigation of the Customer is not possible. The AML Specialist in collaboration with the Member of the Board of the Company shall also decide to terminate of business relations with other Customers that have the same Beneficiaries, or on early enforcement of such Customer's obligations.
- The Company must decide about termination of business relations with the Customer if minimum due diligence requirements regarding Customer cannot be performed within 14 days before establishment of the preconditions to due diligence of the Customer.
- The AML Specialist shall prepare a draft decision (in electronic format) about termination of business relations (Business Relations with the Company or performance of financial transactions) with the Customer and present such draft to the Member of the Board Member of the Company on the following occasions:
- The Customer does not perform the requirements of Internal Regulatory Documents in accordance with the applicable regulatory acts of the Belgium.
- The Customer does not submit to the Company complete data as requested or provide incorrect data or evidently falsified documents, or otherwise attempts to deceive the Company.
- According to the information available by the Company, the Customer is involved in fraudulent transactions, Money Laundering or Terrorism Financing, or the Customer, its legal or contractual representative or the Beneficiary, or a person otherwise related to the Customer is likely to expose the Company to increased legal, reputation or other risk.
- The Customer or persons related to it (legal or contractual representatives, the Beneficiaries, etc.) are among the persons in respect of which the Company abstains from cooperation.
- The Beneficiary can’t provide to the Company additional information by the Company request without important reason.
- On the occasions described in clauses 74 and 75.
- Business relations with the Customer shall be terminated based on the decision approved by the Company in accordance with the AML Policy and Internal Regulatory Documents or by the Customer's initiative.
- The Company have the right to take decision about termination of the business relations approved on the grounds of the Internal Regulatory Documents specifying the following:
- The Company decision with reference to the applicable Internal Regulatory Documents, as well as to the clause of agreement entered with the Customer and/or to the regulatory act (for example, the Anti-Money Laundering and Terrorism Financing Law) that permits the implementation of such decision.
- Date of such decision is taken.
- Date of termination of business relations with the Customer.
- Restrictions imposed on the Customer when Customer performing financial transactions provided by the Company and the ordering/performance of financial transactions.
- Decision about business relations termination with the Customer shall be approved by the Member of the Board or CMD officer of the Company.
- Decision about termination of business relations with the Customer shall be implemented as follows:
- The AML Officer shall immediately take all necessary steps to terminate business relations with the Customer and block the Customer account in the Company System at the time specified in the decision.
- The AML Officer, which is responsible for preparing the respective draft decision shall notify all related Employees about the possibility of performing the financial transactions by the Customer and inform about taken decision via e-mail.
- The Customer and related persons must be entered into the Company's Blocked Client list, if termination of business relations with the Customer is a result of material breach on the part of the Customer.
- The AML Specialist shall immediately notify the Customer about the decision approved in accordance with AML Policy.
- If Employee, who is responsible for Customer service, after implementation of the instruction for termination business relations with the Customer within the prescribed period is prevented by contractual or overdue obligations on the part of the Company or the Customer, the Employee shall immediately report about such a fact via e-mail form to the AML Specialist that has prepared the decision on termination of cooperation, and the latter shall upon receipt of such report prepare a draft decision either on prolongation of the period for termination of cooperation or on early termination of obligations and present such draft to a Member of the Member of the Board of the Company for approval of decision.
- Business relations with the Customer shall be terminated in the same day until the end of the working day after decision about business relations with the Customer was notified, unless other period is prescribed by the AML Policy.
- If decision about termination of business relations with the Customer is approved by the Company on the basis of suspected involvement of the Customer in Money Laundering or Terrorism Financing, or fraud, business relations with the Customer shall be terminated immediately.
- The Member of the Board of the Company shall prescribe other periods for termination of business relations if the AML Specialist that has drafted the decision about termination of business relations with the Customer finds it necessary and feasible.
- The AML Officer, who prepare a draft decision about termination of business relations with the Customer shall be available on the basis of such decision to impose restrictions on the financial transactions performing by the Customer via Company during the period from the approve of such decision and the termination of cooperation.
- If the AML Specialist receive the appropriate approval with instructions from the AML Officer via e-mail (using the “reply” function), AML Specialist shall save the approval received from the AML Officer in the electronic format in the Customer file and activate in the Company System the function that prohibits the Employees (in the manner stipulated in the agreement entered into with the Customer) to perform financial transactions for the Customer; the AML Officer shall notify the Employee that services the Customer in question thereof in form of e-mail.
- The restrictions shall be imposed for the following conditions:
- The Customer category to which the Customer belongs;
- The basis for termination of business relations;
- The Company's experience from cooperation with the Customer in question;
- Other condition that may be relevant for accepting the appropriate decision.
- The Company shall assess whether the inability to apply the Customer due diligence measures forms basis for providing The FIU with the notification referred to in Article 74 or Article 86 of in line with applicable obligations under EU AML legislation.
Record keeping
- The Customer file shall include all documents and information executed in accordance with AML Policy and contains identification data of the Customer, the documents as evidence of the legal capacity and competence of the Customer and their representatives, other documents shall be stored in the Customer File in accordance with the AML Policy and other Internal Regulatory Documents.
- The Customer File shall include:
- All documents received from the Customer, as well as the documents executed by the Company in relation to the Customer.
- Electronic versions of the Customer Files at the Company information system including received/executed documents or information in electronic format (such as information tiled in the Company System, e-mail messages, etc.).
- The AML Specialist shall be responsible for storage (in electronic format) of the following documents in the Customer File, either initially submitted by the Customer or additionally received at any other time:
- All and any documents to be received and executed for the opening and subsequent operation of the Customer profile:
- Passport, ID card or driving licence;
- Address verification document, as utility bill (for gas, water, electricity, TV or Internet); bank statement with address; credit card statement with a list of transactions and address; registration page from national passport with photo;
- The Customer selfie;
- The Company retains the entire correspondence relating to the performance of the duties and obligations arising from legislation of Belgium and all the data and documents gathered in the course of monitoring the business relationship as well as data on suspicious or unusual transactions or circumstances which The FIU was not notified of.
- Additionally for identity confirmation or identity and resident country confirmation AML Specialist can request:
- applications;
- information about Customer source of funds;
- administrative acts of public authorities and officials;
- documents witch belongs to the economical, personal or financial activity of the Customer (if required);
- materials of internal investigation of the Customer's activity;
- all and any documents received by the Company under Customer due diligence process in accordance with the AML Policy regarding Customer and Customer’s performed transactions and documents submitted by the Customer regarding Customer and Customer’s performed transactions.
- The requirements specified in other Internal Regulatory Documents shall be additionally applied to the Customer Files.
- The Company is allowed to process personal data gathered upon implementation to the legislation of the Belgium only for the purpose of preventing money laundering and terrorist financing and the data must not be additionally processed in a manner that does not meet the purpose, for instance, for marketing purposes.
- General information on the duties and obligations of the Company upon processing personal data for AML/CFT purposes is available on the Company’s webpage in Section Privacy Policy.
- Xnity SA shall maintain, for the period of 5 years counting from the date on which business relationships with a Customer were terminated or on which occasional transactions were conducted, the following documents
- copies of documents and the information obtained as a result of application of financial security measures;
- evidence confirming conducted transactions and records of the transactions, said evidence including original documents and copies of documents necessary for identifying a transaction.
- Prior to the expiry of the period referred to point a and b of point 94, the General Inspector may demand the storing of the documentation for the subsequent period not longer than 5 years, counting from the day on which the period expires, if this is necessary in order to counteract money laundering or terrorist financing.
AML Officer and reporting
- Xnity SA shall appoint senior management members responsible for the performance of the obligations defined in the in line with applicable obligations under EU AML legislation. Where a management board or other governing body operates, a person responsible for the implementation of the obligations defined herein shall be appointed among members of such a governing body.
- Xnity SA shall appoint the AML Officer - an employee holding a management position, responsible for ensuring the compliance of activity of the obligated institution and its employees and other persons performing activities for this obligated institution with the provisions on money laundering and terrorist financing.
- The AML Officer is also responsible for submitting, on behalf of the Xnity SA, of the notifications referred to in Article 74, paragraph 1, Article 86, paragraph 1, Article 89, paragraph 1, and Article 90 EU directive of 1st March 2018 on counteracting money laundering and financing terrorism, that is:
- notification the General Inspector of the circumstances which could indicate a suspicion of commission of an offence of money laundering or terrorist financing;
- notification the General Inspector, by electronic communication means, of a case of justified suspicion that a given transaction or specific property values may be associated with money laundering or terrorist financing.
- notification the competent prosecutor of a case of a justified suspicion that the property values being the subject of a transaction or accumulated on an account are the proceeds of an offence other than an offence of money laundering or terrorist financing or a fiscal offence or are associated with an offence other than an offence of money laundering or terrorist financing or with a fiscal offence.
- notification the General Inspector, by electronic communication means, of conducting the suspicion, in the case when provision of the notification was impossible prior to its conducting. In the notification the Xnity SA shall justify the reasons for failure to previously provide the notification and provide the information confirming the suspicion;
- The AML Officer is also responsible for preparing and submitting any required statistical or compliance reports to the competent Financial Intelligence Unit (FIU), such as CTIF-CFI in Belgium, in accordance with applicable EU AML regulations.
- Xnity SA shall provide the competent Financial Intelligence Unit (FIU), such as CTIF-CFI in Belgium, with the following information upon request or as required by law:
- a received payment or disbursement of the funds of equivalent in excess of EUR 15,000 made;
- a transfer of funds of equivalent in excess of EUR 15,000 made, except:
- a national transfer of funds from other obliged institution;
- a transaction associated with the obliged institution's business dealings, which was conducted by the obliged institution in its own name and on its own behalf, including a transaction concluded on an interbank market;
- a transaction conducted on behalf of or for public finance sector entities referred to in Article 9 of the EU directive of 27 August 2009 on Public Finance;
- a transaction conducted by a bank associating cooperative banks, if the information on the transaction has been provided by an associated cooperative bank;
- conveyance of ownership for the purpose of securing property values made for the duration of a contract of ownership conveyance with an obliged institution.
- An obligation of providing of information as referred to in point 144 letter a and b shall refer also to a transfer of funds from outside the territory of the Belgium if the payment service provider is an obliged institution.
- Xnity SA shall provide the information within 7 days from the day of:
- receipt of the payment or making disbursement of funds - in the case of the information referred to in point 144 letter a;
- execution of a payment transaction in the form of a transfer of funds - in the case of the information referred to in point 144 letter b;
- making available the recipient's payment means - in the case of the information referred to in point 144.
- The information shall contain:
- a unique transaction identifier in the records of an Xnity SA ;
- the date or the date and the time of conducting the transaction;
- the identification data the Customer giving an instruction or order of conducting the transaction;
- the amount and currency being the subject of the transaction;
- the transaction type;
- the transaction description;
- the manner of issuing an instruction or order of conducting the transaction;
- the numbers of the accounts used for conducting the transaction marked with the identifier of the International Bank Account Number (IBAN) or an identifier including the code of the country and the account number in the case of accounts not marked with an IBAN.
- Xnity SA shall notify the General Inspector of the circumstances which could indicate a suspicion of commission of an offence of money laundering or terrorist financing.
- Specific instructions of fulfilling reporting obligations for AML Officer, AML Specialist and Company’ employee are stipulated in Annex No 1 “Reporting Manual”.
Exclusion of entering business relationship by Xnity SA
- Xnity SA is not entering into business relations with Customers from a high-risk third country or having a registered office in such a country. High-risk third country shall be understood as a country identified on the basis of information obtained from reliable sources, including reports from evaluation of national systems of counteracting money laundering and terrorist financing conducted by the Financial Action Task Force on Money Laundering (FATF) and the bodies or organizations associated with it, as not having an effective system of counteracting money laundering or terrorist financing or having strategic deficiencies in its system of combating money laundering or terrorist financing, in particular a third country identified by the European Commission in the delegated act adopted under Article 9 of Directive 2015/849 -
- On 7 January 2022, the European Commission adopted a Search for available translations of the preceding that pose significant threats to the financial system of the Union ('high-risk third countries'). Identification of such countries is a legal requirement stemming from Article 9 of and aiming at protecting the Union financial system and the proper functioning of the internal market. The Delegated Regulation amends
- Company is not entering into business relations with Customers of US residency.
AML audits
- Xnity SA is aware that external audits by qualified AML experts provide a needed degree of objectivity in evaluating the internal controls program. Xnity SA use services of licensed law firm in Belgium, which provides Xnity SA with a summary judgment about the quality of the Anti-Money laundering program.
Training
- As part of Xnity SA ’s Anti- Money Laundering program, all personnel is expected to be fully aware of the Anti- Money Laundering policies. Xnity SA ’s employees are obligated to read and comply with this document and sign the acknowledgement form confirming that he has read and understands Anti- Money Laundering policies. Moreover, all personnel is required to reconfirm their awareness of the contents of Anti- Money Laundering policies by signing the acknowledgement form every 4 months.
- All new employees receive anti-money laundering training as part of the mandatory new-hire training program. All applicable employees are also required to complete AML and KYC training annually. Participation in additional targeted training programs is required for all employees with day-to-day AML and KYC responsibilities.
- Xnity SA ensures participation of the persons performing the obligations associated with counteracting money laundering and terrorist financing in training programs covering the execution of those obligations. The training programs take into consideration the nature, type and size of activity conducted by Xnity SA and ensure up-to-date knowledge in the realm of the discharge of obligations of the obliged institution, in particular the obligations referred to Article 74, paragraph 1, Article 86, paragraph 1 and Article 89, paragraph 1 EU directive of 1st March 2018 on counteracting money laundering and financing terrorism
- Xnity SA ’s training program Includes, at a minimum:
- how to identify signs of money laundering or financing of terrorism that arise during the course of the employees’ duties;
- what to do once the risk is identified (including how, when and to whom report);
- what employees' roles are in Xnity SA ’s compliance efforts and how to perform them;
- the disciplinary consequences (including civil and criminal penalties) for non-compliance.
- Xnity SA ’s personnel is obligated:
- At a time specified by the AML Officer, to undertake training programs on anti-money laundering policies and procedures;
- Participate in training how to recognize and deal with transactions which may be related to money laundering;
- Timely escalate and report the matter to the AML Officer;
- To get themselves acquainted with Anti Money Laundering Policy;
- Direct any doubts or queries in regard of Xnity SA ‘Anti Money Laundering Policy to AML Officer.
Personnel protection
- Xnity SA shall develop and implement an internal procedure of anonymous reporting by employees actual or potential breaches of the provisions in the field of combating money laundering and terrorist financing.
- The procedure for anonymous reporting of breaches referred to in point 50 shall, in particular, specify:
- the person responsible for receiving the reports;
- the method of receiving the reports;
- the manner of protection of an employee, ensuring at least protection against actions of a repressive nature, discrimination or having an impact upon deterioration other types of their legal or actual situation or consisting in directing threats; unfair treatment;
- the manner of protection of personal data of an reporting employee and the person charged with committing a violation, pursuant to the provisions on protection of personal data;
- the rules for preserving confidentiality in the case of disclosure of identity;
- the type and the nature of follow-up actions taken after receipt of the report;
- the time limit of removal by Xnity SA of personal data contained in the reports.
- Xnity SA shall ensure employees protection against undertaking against them actions of a repressive nature or having an impact upon deterioration of their legal or actual situation or consisting in directing threats.
- Xnity SA shall ensure employees performing activities related to fulfillment by the obliged institutions of the duties referred to in Article 74, Articles 86, 89 and 90 EU directive of 1st March 2018 on counteracting money laundering and financing terrorism protection against undertaking against these persons actions of a repressive nature or having an impact upon deterioration of their legal or actual situation or consisting in directing threats.
- Xnity SA shall not undertake against the employees actions of a repressive nature or having an impact upon deterioration of their legal or actual situation or consisting in directing threats against them, in particular actions adversely affecting their working or employment conditions.
- Employees and other persons performing activities for the Xnity SA exposed to the actions referred to in point 53 shall be entitled to report to the General Inspector the instances of such actions.
This AML Policy was prepared on 11.01.2024 is effective as of this date.
Robert Masse
Member of the Management Board
Signature:_____________________
Johann Sebastiaan Caubergh
Member of the Management Board
Signature:_____________________
Johann Sebastiaan Caubergh
AML Officer
Signature:_____________________
01.05.2025.
Annexes:
1. Annex 1 “Reporting Manual”;
2. Annex 2 “Risk Assessment”;
3. Annex 3 “Customer Acceptance Policy”
4. Annex 4 “Anti-Bribery & Corruption Policy”
Annex No 1 “Reporting Manual”
Xnity SA with its registered seat in Avenue Louise 231, 1050 Brussels, Belgium
§ 1 Introduction
- Xnity SA, with registered address Av. Louise 231, 1050 Brussels, Belgium (hereinafter: “Xnity SA ”), is legal entity incorporated by laws of the Belgium with company number 1023.778.877
- The main objective of Reporting Manual is providing appropriate controls for reporting of transactions exceeding threshold limit and suspicious activities in accordance with applicable laws, procedures and regulatory guidelines.
- This Reporting Manual is revisited periodically and amended from time to time (especially in relation to changes in the risk factors concerning contractors, countries or geographical areas, products, services, transactions or their delivery channels – according to art. 27 point 3 EU directive of 1st March 2018 on counteracting money laundering and financing terrorism) based on prevailing industry standards and international regulations designed to facilitate the prevention of illicit activity including money laundering and terrorist financing.
- This Policy is subject to approval by the senior management of Xnity SA .
§ 2 AML Officer and reporting
- Xnity SA shall appoint senior management members responsible for the performance of the obligations defined in the in line with applicable obligations under EU AML legislation. Where a management board or other governing body operates, a person responsible for the implementation of the obligations defined herein shall be appointed among members of such a governing body.
- Xnity SA shall appoint the AML Officer - an employee holding a management position, responsible for ensuring the compliance of activity of the obligated institution and its employees and other persons performing activities for this obligated institution with the provisions on money laundering and terrorist financing. The appointed employee shall be also responsible for the submission of notifications referred to in Article 74(1), Article 86(1), Article 89(1) and Article 90 of in line with applicable obligations under EU AML legislation on behalf of the Xnity SA, that is:
- information on transactions exceeding threshold limits prescribed in in line with applicable obligations under EU AML legislation;
- notification The FIU of the circumstances which could indicate a suspicion of commission of an offence of money laundering or terrorist financing;
- notification The FIU, by electronic communication means, of a case of justified suspicion that a given transaction or specific property values may be associated with money laundering or terrorist financing.
- notification the competent prosecutor of a case of a justified suspicion that the property values being the subject of a transaction or accumulated on an account are the proceeds of an offence other than an offence of money laundering or terrorist financing or a fiscal offence or are associated with an offence other than an offence of money laundering or terrorist financing or with a fiscal offence.
- notification The FIU, by electronic communication means, of conducting the suspicion, in the case when provision of the notification was impossible prior to its conducting. In the notification the Xnity SA shall justify the reasons for failure to previously provide the notification and provide the information confirming the suspicion;
- The AML Officer is responsible also for preparing and submitting quarterly statistical report to The FIU.
§ 3 Information on transactions exceeding threshold limits prescribed in in line with applicable obligations under EU AML legislation (Article 72 of in line with applicable obligations under EU AML legislation)
- Xnity SA shall provide to The FIU the information on:
- a received payment or disbursement of the funds of equivalent in excess of EUR 15,000;
- transfer of funds exceeding the equivalent of EUR 15,000 from outside the territory of the Belgium;
- Xnity SA shall provide the information within 7 days from the day of:
- receipt of the payment or making disbursement of funds - in the case of the information referred to § 3 point 1 letter a;
- making means of payment available to the recipient - in the case of the information referred to in§ 3 point 2 letter b.
- For the calculating the deadline referred to in § 3 point 2, the provisions of the EU directive of 14 June 1960 Code of Administrative Procedure (Journal of Laws of 2018, item 2096, as amended). When calculating the deadline for submitting the above-mentioned information, the day on which the event subject to reporting occurred is not taken into account, therefore the counting of the deadline starts from the day following the event, e.g. if receipt of the payment or making disbursement of funds occurred on 22 July, then the deadline for reporting will expire on 29 July (29 July at 23:59:59).
- If the end of the deadline for submitting the aforementioned information to The FIU falls on a day that is a public holiday or on Saturday, the deadline for reporting will expire on the next day that is neither a public holiday nor a Saturday.
- The information shall contain:
- a unique transaction identifier in the records of an Xnity SA ;
- the date or the date and the time of conducting the transaction;
- the identification data prescribed in § 3 point 6 of the contractor giving an instruction or order of conducting the transaction:
- available identification data referred to in § 3 point 6 related to other parties of the transaction;
- the amount and currency being the subject of the transaction;
- the transaction type;
- the transaction description;
- method of issuing the instruction or order to perform the transaction;;
- the numbers of the accounts used for conducting the transaction marked with the identifier of the International Bank Account Number (IBAN) or an identifier including the code of the country and the account number in the case of accounts not marked with an IBAN.
- The data of a the contractor involves providing following information in the case of:
- natural person:
- name and surname,
- citizenship,
- number of the Universal Electronic System for Registration of the Population (national identification number (if applicable)) or date of birth in the case if the national identification number (if applicable) number has not been assigned, and the state of birth,
- series and number of the document confirming the identity of a person,
- residence address,
- legal person or an organizational unit without legal personality:
- name,
- organizational form,
- address of the registered office or address of pursuing the activity,
- Tax Identification Number (TIN), and in the case of a lack of such a number – the state of registration, the commercial register as well as the number and date of registration,
- identification data referred to in point 5 letter a subparagraph i and iii of a person representing such legal person or organizational unit without legal personality.
§ 4 Notification The FIU of the circumstances which could indicate a suspicion of commission of an offence of money laundering or terrorist financing (art. 74 of in line with applicable obligations under EU AML legislation)
- The obligated institution shall notify The FIU of any circumstances which may indicate the suspicion of committing the crime of money laundering or financing of terrorism.
- The notification shall be submitted immediately, not later than two business days following the day of confirming the suspicion referred to in point 1 by the Xnity SA .
- The following data shall be provided in the notification:
- identification data referred to in § 3 point 6 related to the customer of the Xnity SA providing the notification;
- available identification data referred to in § 3 point 6 related to natural persons, legal persons or organizational units without legal personality other than customers of the Xnity SA ;
- type and value of assets and place of their storage;
- number of the account maintained for the customer of the Xnity SA, identified by the IBAN or identification containing country code and account number in case of accounts other than identified by IBAN;
- available identification data referred to in § 3 point 5 related to the transactions or their attempted performance;
- indicating a state of the European Economic Area the transaction is associated with, if it was conducted under the cross-border activity;
- available information concerning the identified money laundering or financing of terrorism risk and a prohibited act from which assets can originate;
- justification of providing the notification.
- In accordance with § 4 point 3 letter h the notification to CTIF-CFI should, inter alia, contains a justification. This means that the Xnity SA, in the context of establishing circumstances that may indicate a suspicion of the commission of a money laundering or terrorist financing offence, describes, in particular:
- what information and documents were collected prior to the establishment of economic relations (e.g., what business profile of the customer was established, what was the declared frequency of transactions, what was the source of origin of the assets indicated),
- what information the obliged institution collected in the course of economic relations (e.g. whether the obtained assets and executed transactions were in line with the established profile of economic activity, whether there were any changes of ownership, whether any circumstances changed the risk assigned to the customer, whether the domestic bank received a communication from the foreign bank regarding the return of funds, and if so - what reason was indicated by the foreign bank),
- what financial security measures were applied after the circumstances that might indicate a suspicion of crime were identified and what was their outcome (e.g. whether the client's transactions with selected counterparties were analysed and specific cases were selected for further in-depth analysis),
- what actions were taken in relation to the client after establishing the circumstances that could indicate a suspicion of crime, and what was the result (e.g. whether telephone contact was made with the client or the client was obliged to present contracts and invoices, whether the client presented the requested documentation in full or in part),
- what information and documents were reviewed after determining the circumstances that might indicate a suspected crime, and what was the outcome (e.g. whether ambiguities were found in contracts and invoices submitted by the client),
- what was the impact of the finding of circumstances that might indicate a suspicion of a criminal offence on the business relationship (e.g. whether, as a result of the customer's failure to provide documents, the obliged institution decided not to carry out transactions through the bank account or to terminate the business relationship).
§ 5 Notification to The FIU of any case of acquiring justified suspicion that the specific transaction or specific assets may be associated with money laundering or financing of terrorism (art. 86 of in line with applicable obligations under EU AML legislation)
- The Xnity SA shall immediately notify The FIU of any case of acquiring justified suspicion that the specific transaction or specific assets may be associated with money laundering or financing of terrorism.
- In the notification, the Xnity SA shall provide information available to it, associated with the acquired suspicion and information on the expected time of performing the transaction referred to in point 1. With respect to the notification, the provision of § 4 point 3 shall apply accordingly.
- Upon the receipt of the notification, The FIU shall immediately confirm the receipt thereof in the form of an official confirmation of the receipt, containing in particular the date and the time of accepting the notification.
- Until the time of receipt of the request referred to in point 5, or the exemption referred to in point 6, no longer than for 24 hours counting from the moment of the confirmation of the receipt of the notification referred to in point 3, the Xnity SA shall not perform the transaction referred to in point 1 or other transactions charging the account on which assets referred to in point 1 have been collected.
- In case of recognizing that the transaction referred to in point 1 can be associated with money laundering or financing of terrorism, The FIU shall provide the Xnity SA with a request to suspend the transaction or block the account for no more than 96 hours from the date and time indicated in the confirmation referred to in point 3. The Xnity SA shall suspend the transaction or block the account immediately upon the receipt of such request. In the request, The FIU shall determine assets subject to the request.
- The FIU may exempt the obligated institution from the obligation referred to in paragraph 5 in the case if the available information does not provide grounds to notify the prosecutor of suspected crime of money laundering or financing of terrorism or in the case of recognising that the transaction suspension or account blocking could jeopardise the performance of tasks by the judicial authorities and forces or institutions responsible for the protection of public order, citizens’ security or prosecution of perpetrators of crimes or fiscal crimes.
- The FIU shall submit the request referred to in point 5 or the exemption referred to in point 6 to The FIU with the use of electronic communication means.
- Immediately after the submission of the demand referred to in point 5, The FIU shall notify the competent prosecutor on a suspicion of committed crime of money laundering or financing of terrorism.
- Upon receipt of the notification referred to in point 8, the prosecutor may issue the decision to suspend the transaction or block the account for a definite period, no longer than 6 months from the day of receipt of such notification.
- The decision concerning the suspension of the transaction or the blocking of the account referred to in point 9 can be also issued despite the absence of the notification defined in point 8.
- In the decision referred to in point 9, the scope, method and time of suspending the transaction or blocking the account shall be determined. The decision may be appealed to the court competent to hear the case.
- The Xnity SA, on request of the customer issuing the instruction or the order to perform the transaction referred to in point 1, or being the account holder or owner of assets referred to in point 1, may inform such customer about the submission of the request referred to in point 5 by The FIU.
- The suspension of the transaction or the blocking of the account shall fall before the expiry of 6 months from the receipt of the notification referred to in point 8 unless a decision on asset seizure or a decision concerning material evidence is issued.
§ 6 Notification to the competent prosecutor of any case of acquiring reasonable suspicion that the assets subject to transaction or collected on the account originate from a crime other than the crime of money laundering or financing of terrorism or a fiscal crime, or are associated with a crime other than the crime of money laundering or financing of terrorism or a fiscal crime (art. 89 of in line with applicable obligations under EU AML legislation)
- The Xnity SA shall immediately notify the competent prosecutor of any case of acquiring reasonable suspicion that the assets subject to transaction or collected on the account originate from a crime other than the crime of money laundering or financing of terrorism or a fiscal crime, or are associated with a crime other than the crime of money laundering or financing of terrorism or a fiscal crime.
- In the notification, the Xnity SA shall provide information available to it, associated with the suspicion and information on the expected time of performing the transaction referred to in point 1.
- Until the time of receipt of the decision referred to in § 6 point 4, in any case no longer than for 96 hours from the moment of submission of the notification referred to in point 1, the Xnity SA shall not perform the transaction referred to in § 6 point 1 or any other transactions charging the account on which assets referred to in point 1 have been collected.
- Within the time limit defined in § 6 point 3, the prosecutor shall issue the decision on institution or refusal to institute the proceedings, immediately notifying the Xnity SA thereof. In the event of institution of the proceedings, the prosecutor shall suspend the transaction or block the account, by way of the decision, for a period not longer than 6 months from the date of receipt of the notification referred to in § 6 point 1.
- The decision concerning the suspension of the transaction or the blocking of the account referred to in § 6 point 4 can be also issued despite the absence of the notification defined in § 6 point 1.
- In the decision referred to in § 6 point 4, the scope, method and time of suspending the transaction or blocking the account shall be determined. The decision may be appealed to the court competent to hear the case.
- The suspension of the transaction or the blocking of the account shall fall before the expiry of 6 months from the issuance of the decision referred to in § 6 point 4 and 5 unless a decision on asset seizure or a decision concerning material evidence is issued.
- Immediately upon the receipt of the decisions referred to in § 6 point 4 and 7, the Xnity SA shall submit, with the use of electronic communication means, information on the notifications referred to in point 1 and copies thereof to The FIU.
§ 7 Notification to The FIU of performing transaction in the event if the submission of the notification prior to the performance of the transaction was impossible (art. 90 of in line with applicable obligations under EU AML legislation)
- The Xnity SA shall immediately notify The FIU of performing the transaction referred to in § 5 in the event if the submission of the notification prior to the performance of the transaction was impossible. In the notification, the Xnity SA shall justify the reasons of its failure to submit the notification in advance and provides information available to it confirming the acquired suspicion referred to in § 5. The provision of § 3 point 5 shall apply accordingly.
- The Xnity SA shall immediately notify the competent prosecutor of performing the transaction referred to in § 6 in the event if the submission of the notification prior to the performance of the transaction was impossible. In the notification, the Xnity SA shall justify the reasons of its failure to submit the notification in advance and provide information available to it confirming the acquired suspicion referred to in § 6 point 1. The provision of § 6 point 8 shall apply accordingly.
§ 8 Identification form
- For the purpose of the first fulfillment of the obligations referred to in § 3, § 4, § 5, § 6 and § 7 the Xnity SA shall submit a form identifying the Xnity SA to The FIU.
- The form identifying the obligated institution contains:
- name, including determining of the organisational form of the obligated institution;
- Tax Identification Number (TIN);
- determining of the type of activity carried out by the obligated institution;
- address of the registered office or address of pursuing the activity;
- name, surname, position, telephone number and address of electronic mailbox of the AML Officer;
- names, surnames, positions, telephone numbers and addresses of electronic mailboxes of other employees responsible for the implementation of the provisions of the in line with applicable obligations under EU AML legislation, whom the obligated institution is willing to indicate for contacts with The FIU
- In the case of change of the data referred to in paragraph § 8 point 2 the Xnity SA shall immediately update them.
§ 9 Information requested by CTIF-CFI
- On request of The FIU, the Xnity SA shall immediately submit or make available any information or documents held, required for the implementation of The FIU’s tasks defined in the in line with applicable obligations under EU AML legislation, including those referring to:
- customers;
- performed transactions in the scope of data defined in § 3 point 5;
- type and value of assets and place of their storage;
- application of the customer due diligence measure;
- IP addresses from which the connection with the informatics system of the Xnity SA took place and times of connections with this system.
- In the request referred to in § 9 point 1 and 2, The FIU may indicate:
- the deadline and form of providing or making information or documents available;
- the scope of information as well as the time limit of its acquisition by the obligated institution in connection with the application of the customer due diligence measure or in connection with specific occasional transactions.
- The information and documents referred to in § 9 point 1 shall be provided and made available free of charge.
This Reporting Manual was prepared on 01.05.2025 is effective as of this date.
Robert Masse
Member of the Management Board
Signature:
Johann Sebastiaan Caubergh
Member of the Management Board
Signature:
Johann Sebastiaan Caubergh
AML Officer
Signature:
01.05.2025
Annex No 2 “Risk Assessment”
Xnity SA . with its registered seat in Avenue Louise 231, 1050 Brussels, Belgium
§ 1 Legal basis
- This document is prepared on the basis of Article 27 of the EU directive of March 1, 2018 on counteracting money laundering and financing of terrorism (European Journal of Laws 2023, item. 1124, 1285, 1723, 1843 - consolidated text).
- Following to above mentioned article, Xnity SA, a company with limited liability under Belgian law, with its registered seat in Brussels, Belgium (hereinafter: “Xnity SA ”), as obliged institution, shall identify and assess the risk connected with money laundering and terrorist financing related to its operations, taking account of the factors of risk concerning customers, countries or geographical areas, products, services, transactions or delivery channels. These actions shall be proportionate to the nature and size of the obliged institution.
- While assessing the risk, the Xnity SA may take into account the binding national risk assessment, as well as the report of the European Commission referred to in Article 6(1)-(3) of Directive 2015/849.
- The Risk Assessment is prepared by Xnity SA in hard copy or electronic form and where necessary, however at least once every 2 years, the Xnity SA shall update this assessments, especially in relation to changes in the risk factors concerning customers, countries or geographical areas, products, services, transactions or delivery channels or the documents referred to in paragraph 2.
§ 2 Information sources
Xnity SA, as an obligated institution, to identify the risk of money laundering or terrorist financing, takes into account, in particular:
- information contained in the international risk assessments prepared by the European Commission,
- Information included in the national or supranational risk assessments prepared by the competent authorities, including the Belgian Financial Intelligence Processing Unit (CTIF-CFI) and EU-level institutions;
- Information made available through official websites of the relevant Financial Intelligence Unit (FIU), such as https://www.ctif-cfi.be, or published by the European Commission in relation to AML/CFT risks;own knowledge and professional experience,
- information obtained from clients, their proxies or statutory representatives,
- information disclosed in public registers,
- information contained in official documents submitted to Xnity SA .
§ 3 Purpose of risk assessment
- The purpose of the risk assessment is for the Xnity SA, as an obliged institution, to identify and determine the level of risk related to money laundering and terrorist financing, taking into consideration its professional activity in respect of the business activity as defined in Article 2(1)(13) of the EU directive of March 1, 2018 on counteracting money laundering and financing of terrorism:
- exchange between virtual currencies and means of payment
- exchange between virtual currencies;
- Risk assessment takes into account the risk factors relating to the client, the beneficial owner, the countries or geographical areas, the type and subject matter of the activity covered by Xnity SA ’s business activity.
- The risk assessment was made taking into account the size of the Xnity SA ’s undertaking and the nature of its business, which is characterized by:
- subject of Xnity SA ’s transactions are virtual currencies, which are developing very quickly and are an example of digital innovation. However, at the same time, there is a risk that virtual currencies could be used by terrorist organizations to circumvent the traditional financial system and conceal financial transactions as these can be carried out in an anonymous manner. However, these could be more accurately described as ‘pseudonymous’. The nature of distributed ledger technology means that every transaction carried out on a DLT-based system is recorded in multiple locations. Therefore transactions and owners can ultimately be tracked. The difficulty can then lie in identifying who it is carrying out transactions, particularly when multiple transactions are carried out to obscure a trail. Hence the use of ‘mixers’ or ‘tumblers’ which mix potentially identifiable currencies with others so as to make it more difficult to trace those engaged in illicit activities.
- virtual currencies are characterized by the lack of a central oversight body;
- The Fifth Anti-Money Laundering Directive (5AMLD) introduced essential transparency and regulatory obligations for the virtual asset and cryptocurrency sector across the EU, including customer due diligence, registration requirements, and enhanced monitoring for virtual asset service providers (VASPs);
- the price of virtual currencies fluctuates constantly;
- the data of the clients are always established and verified on the basis of presented original documents stating identity or scan copies;
- there is possibility to perform the transaction in physical absence of the client;
- transactions are always financed with funds from client’s bank accounts, which means that the client has been additionally verified by an obliged institution other than Xnity SA ;
- payments made by the clients are not flexible, i.e. they do not provide for a possibility to pay more than the amount specified in the transaction and later return the overpayment to the paying party or a third party.
§ 3 Money laundering or terrorist financing risk factors
In identifying the risk of money laundering or terrorist financing and assessing the level of such risk, the Xnity SA consider factors relating to:
- the client;
- beneficial owner;
- countries and geographical areas,
Above mentioned factors may be grouped into following criteria:
- Economic - consisting of assessing the client's transactions in terms of the purpose of its business activity;
- Geographical - involving transactions not justified by the nature of the business concluded with entities from countries where there is a high risk of money laundering and terrorist financing;
- Object-oriented - consisting in carrying out by the client of a high-risk business activity from the point of view of vulnerability to money laundering and terrorist financing;
- Behavioral - consisting of atypical, in a given situation, behavior of the client.
§ 4 Risk factors concerning client and beneficial owner
- When recognizing the risk of money laundering or terrorist financing and assessing the level of such risk related to the client, the Xnity SA considers:
- the profile of the client's professional or business activity, in particular:
- whether the client is engaged in virtual currency business activity,
- whether the client is engaged in non-profit activities,
- whether the type or subject matter of the activity covered by the transaction falls within the profile of the client's professional or business activity,
- circumstances concerning the person of the client, in particular:
- whether there is reasonable doubt as to the identity of the client,
- whether the client is an entity other than a natural person,
- whether the client is a person holding a politically exposed position within the meaning of Art. 2 sec. 2 item 11) of the in line with applicable obligations under EU AML legislation or has ceased to hold such a politically exposed position in the last 12 months, or is a family member of a person holding a politically exposed position within the meaning of Art. 2(3) of the in line with applicable obligations under EU AML legislation or a person who has ceased to hold such a politically exposed position within the last 12 months, or is a person known to be a close associate of a politically exposed person within the meaning of section 2(2)(12) of the in line with applicable obligations under EU AML legislation or a person who has ceased to hold such a politically exposed position within the last 12 months,
- whether the client, whose appearance may indicate that he is not a wealthy person, engages in a transaction of substantial property value,
- whether the ownership structure of a client that is a legal entity is transparent,
- whether the client is a person or entity entered by The FIU on the list of persons and entities subject to special restrictive measures referred to in Chapter 10 of the in line with applicable obligations under EU AML legislation,
- client's behavior during the conducting the transaction, in particular:
- whether the client uses a false identity as evidenced by the documents presented,
- whether the client refuses to submit documents within the meaning of Article 37 of the in line with applicable obligations under EU AML legislation confirming the identity of the client or real beneficiary, despite the fact that the documents may be submitted by the client without obstacles,
- whether the client intentionally provides data that is inconsistent with reality,
- whether the client demands an unreasonably high level of confidentiality,
- whether the customer behaves in an unusual manner (e.g. shows signs of unjustified nervousness or fear),
- whether the client is conducting transaction in the presence of third party, which acts in a suspicious manner,
- whether the client carries out the transaction in the company of a third party who gives him instructions concerning the transaction,
- whether the customer transports a significant amount of money in cash in an unusual manner,
- whether the documents submitted by the client raise reasonable suspicion as to their authenticity,
- whether the client refrains from conducting the transaction in the event that the Xnity SA ’s personnel shows interest in the details of the transaction,
- whether the client does not disclose data allowing identification of the beneficial owner, despite knowing such data,
- whether the client provides information requested by the Xnity SA with undue delay.
- When recognizing the risk of money laundering or terrorist financing and assessing the level of this risk related to the beneficial owner, Xnity SA takes into account the circumstances concerning the person of the beneficial owner, in particular:
- whether the beneficial owner is a person holding a politically exposed position within the meaning of art. 2 par. 2 item 11) of the Act or has ceased to hold such a politically exposed position within the last 12 months, or is a family member of a person holding a politically exposed position within the meaning of art. 2(3) of the Act or a person who has ceased to hold such a politically exposed position within the last 12 months, or is a person known to be a close associate of a person holding a politically exposed position within the meaning of Article 2(2)(12) of the Act or a person who has ceased to hold such a politically exposed position within the last 12 months,
- whether the beneficial owner is a person entered by the General Inspector for Financial Information on the list of persons and entities subject to special restrictive measures referred to in Chapter 10 of the in line with applicable obligations under EU AML legislation.
- A higher risk of money laundering or terrorist financing may be indicated in particular by the fact that:
- the ownership structure of the client being a legal entity is not transparent,
- the client or beneficial owner is a person holding a politically exposed position within the meaning of Art. 2 sec. 2 item 11) of the Act or has ceased to hold such a politically exposed position in the last 12 months, or is a family member of a person holding a politically exposed position within the meaning of Art. 2(3) of the Act or a person who ceased to hold such a politically exposed position within the last 12 months, or is a person known to be a close associate of a person holding a politically exposed position within the meaning of Article 2(2)(12) of the Act or a person who ceased to hold such a politically exposed position within the last 12 months,
- despite taking reasonable actions, the Xnity SA could not establish whether the client or the beneficial owner is a person holding a politically exposed position within the meaning of art. 2 sec. 2 item 11) of the Act or has ceased to hold such a politically exposed position in the last 12 months, or is a family member of a person holding a politically exposed position within the meaning of art. 2(2)(3) of the Act or a person who has ceased to hold such a politically exposed position within the last 12 months, or is a person known to be a close associate of a person who holds a politically exposed position within the meaning of Article 2(2)(12) of the Act or a person who has ceased to hold such a politically exposed position within the last 12 months,
- A low risk of money laundering or terrorist financing is indicated in particular by the fact that the client is:
- a unit of the public finance sector referred to in Article 9 of the Act of 27 August 2009 on public finance (Journal of Laws of 2017, item 2077 and of 2018, item 62),
- a company with a majority stake held by the State Treasury, local government units or their associations,
- a company whose securities are admitted to trading on a regulated market subject to the requirements of disclosure of information about its beneficial owner arising from the provisions of European Union law or equivalent provisions of law of a third country, or a company with a majority shareholding of such a company.
§ 6 Risk factors concerning countries and geographical areas
- When identifying the risk of money laundering or terrorist financing and assessing the level of such risk related to the country and geographical areas, the Xnity SA shall take into account, in particular:
- the country of residence or registered office of the client,
- country of citizenship of the client,
- country of citizenship of the beneficial owner.
- A higher risk of money laundering or terrorist financing may be evidenced, in particular, by the fact that:
- the country of residence or domicile of the customer, or
- country of citizenship of the customer, or
- the country of citizenship of the beneficial owner,
is:
- a high-risk third country, as defined under Article 9 of Directive (EU) 2015/849 and identified by the European Commission or the Financial Action Task Force (FATF), as published on the official FATF website (https://www.fatf-gafi.org) or relevant EU sources;
- a country with a high level of corruption or other criminal activity, or as a country which finances or supports the commission of acts of a terrorist nature, or with which the activities of organizations of a terrorist nature are associated, or
- a country with respect to which the United Nations or the European Union has decided to impose sanctions or specific restrictive measures,
- A low risk of money laundering or terrorist financing is indicated in particular by the fact that:
- the country of residence or domicile of the customer, or
- the country of which the customer is a national, or
- the country of citizenship of the beneficial owner,
is:
- a Member State of the European Union, a Member State of the European Free Trade Association (EFTA) - a party to the Agreement on the European Economic Area,
- a country with a low level of corruption or other criminal activity,
- a country which has in force anti-money laundering and anti-terrorist financing regulations corresponding to the requirements arising from the European Union anti-money laundering and anti-terrorist financing regulations.
§ 7 Risk factors regarding the type and subject matter of the transaction
- When recognizing the risk of money laundering or terrorist financing and assessing the level of the risk associated with the type and subject of the transaction the Xnity SA considers, in particular
- the type of virtual currency being the subject of the transaction,
- market value of the virtual currency being the subject of the transaction,
- form of transaction,
- whether the client demand conclusion of the transaction which is non-equivalent on the basis of economic factors,
- whether payment by client is made in the amount exceeding 15.000 euro,
- whether payment of a pecuniary obligation resulting from the activity included in the notarial deed is funded in significant part with the money obtained from a bank loan or a bank credit,
- whether the transaction is carried out in untypical circumstances,
- whether transactions of the same property value are performed within a very short time interval,
- A higher risk of money laundering or terrorist financing may be evidenced in particular by the fact that:
- the client demands the conclusion of a transaction which is non-equivalent on the basis of economic factors
- payment is made in the amount exceeding EUR 15.000;
- the transaction is carried out in untypical circumstances.
- A low risk of money laundering or terrorist financing is indicated in particular by the fact that:
- payment for transaction is financed in a significant part with money obtained from a bank loan or a bank credit,
- payment for transaction is financed in full by means of a bank transfer,
- transaction is concluded due to the occurrence of a legal or economic event which previously caused legal effects for the client.
§ 8 Risk factors balance
- Xnity SA, after recognizing the risk factors listed in § 5, 6 and 7 and taking into account the nature of its business as defined in § 2(2), shall assess the risk of money laundering and terrorist financing by applying listed risk factors weighing to determine whether the analyzed transaction is associated with:
- a higher risk of money laundering and terrorist financing, or
- a medium risk of money laundering and terrorist financing, or
- low risk of money laundering and terrorist financing.
- In accordance with the assessment of the risk of money laundering and terrorist financing the Xnity SA shall apply appropriate financial security measures as specified in the internal procedure on prevention of money laundering and terrorist financing.
- Determination by the Xnity SA of a higher risk associated with a particular transaction, does not prejudge the fact that there are circumstances that may indicate a suspicion of money laundering or terrorist financing.
- The weighing of risks shall not lead to circumvention of the provisions of the in line with applicable obligations under EU AML legislation or Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015 on the prevention of the use of the financial system for money laundering or terrorist financing.
- The result of the application of the risk assessment analysis by the Xnity SA is classification of the client into the appropriate risk group:
- Low risk level - group 1 (1)
- Normal risk level - group 2 (2-3)
- High risk level - group 3 (4-5)
- Company have developed categories of impact as follows:
- Each category of impact is accompanied by a score.
- Company uses the following process in measuring the likelihood:
- The overall risk score is calculated using the following formula:
Likelihood x Impact²
- Scores to identify the overall level of risk:
- Each score is categorized with a color. The color that your risk score comes out at translates into a response to that risk as follows:
§ 9
- Given that the degree of exposure of each obliged institution to the risks of money laundering and terrorist financing depends on the nature and size of that institution and the economic environment in which such entity operates, Xnity SA assesses the Risk of its own activities taking into account the Risk Based Analysis (RBA) approach . To this end, Xnity SA has divided the risk assessment process into a series of activities and stages, distinguishing three main stages:
- identification of risks,
- risk assessment,
- risk management.
- The distinguished stages are based on Xnity SA ability to collect, communicate and analyze statistical and qualitative data extracted from the assumed Risk Factors. Xnity SA risk assessment process follows the following scheme:
- The objective of the first stage is to structure the problem of Xnity SA possible use in the ML/TF process. Sources of risk that may affect Xnity SA operations are identified on the basis of available ML/TF scenarios. Then, on the basis of the ML/TF scenarios describing the current methods, techniques and modus operandi of ML/TF offenders, Xnity SA undertakes a decomposition of the source of the identified risk, extracting Risk Factors specific to each identified ML/TF scenario. The Risk Factors are aggregated in nature. From a number of unstructured ML/TF scenarios, specific evidence is extracted whose emergence in the course of Xnity SA operations may justify Xnity SA involvement in ML/TF. The evidence is then categorized and assigned to individual Risk Factors, taking into account the characteristics or attributes they possess. The categorization of individual evidence, i.e. the attribution to individual Risk Factors taking into account their attributes, is made on the basis of the description of the characteristics and attributes of the identified evidence (e.g. the conduct of a business by the Customer, consisting of the sale of weapons, is evidence of the object of the business conducted by the Customer, which has been recognized as an attribute of the Risk Factor that is the Customer, while this Risk Factor is one of the elements of the ML/TF scenario). Ultimately, the level of Threat resulting from the presence of specific Risk Factors is determined by Xnity SA based on the number of evidences of Threat identified by Company in the course of its operations. Irrespective of the overall intensity of the Threat determined by the number of evidences detected, Xnity SA examines and determines the materiality of each Risk Factor from the perspective of its operations, determining the share (weight) of each Risk Factor in the total level of Xnity SA Threat.
- The Risk Assessment carried out on the basis of the hierarchical and structured ML/TF scenario structure described above allows for a numerical (quantifiable) representation of the complex and multi-criteria problem of money laundering and terrorist financing and, consequently, a representation of the relationships between the various elements of this practice, which are usually represented descriptively in the form of an ML/TF scenario.
- Next, Xnity SA assesses the Inherent Risk associated with its business activities. The level of this risk determines the degree of Xnity SA Vulnerability to exploitation of its business for ML/TF, which is described by ML/TF scenarios (Threat). The greater the Threat of exploitation of Xnity SA Vulnerability and the more Xnity SA is Vulnerable to exploitation of its business for a criminal purpose, the greater the probability of the Risk. The juxtaposition of the value of the probability of the Risk and its consequences for Xnity SA determines the level of the inherent Risk associated with Xnity SA activities. At this stage, Xnity SA assesses the level of Vulnerability of its own organization, determines the level of probability of the Threat and the severity of the consequences, where the overall assessment leads to the determination of the value of the Inherent Risk.
- Finally, the value determining the Inherent Risk was compared with the total level of effectiveness of the Control Factors, i.e. the organizational solutions adopted by Xnity SA and Xnity SA actions limiting its exposure to the identified Inherent Risk. In this way, the level of Residual Risk dependent on Xnity SA ability to manage the Risk was determined for Xnity SA operations.
- Xnity SA manages the Inherent Risks by introducing organizational mitigation measures and measures to control the level of these Risks (Control Factors). The percentages listed below, understood as the effectiveness of the individual Control Factors, are the result of Xnity SA assessment process of determining the facts relating to each issue.
- List of Control factors:
- Policies and Procedures
- Financial security measures when establishing business relationships
- Financial security measures during the course of the business relationship
- Record keeping
- Designated Board Member and AML Specialist
- Internal control
- Sanction screenings
- Reporting obligations
- Training system.
- Each of the above mentioned has been given the same weight which adds to total score of 100%.
For purpose of this table: Xnity SA - Company
| Control factors | ||
| Category | Area/Activity/Control Procedure | Execution |
| Does Company have and apply an internal AML/CFT procedure tailored to the nature, type and size of its business to the extent required by the Act? | YES | |
| Policies and Procedures (11,11%) | Does Company have adequate policies and procedures in place to confirm the establishment or continuation of a PEP relationship? | YES |
| Does Company have an internal procedure for anonymous reporting of violations? | YES | |
| Does Company have and apply internal control procedures? | YES | |
| Is there a correlation between the internal AML/CFT procedure and the internal control procedure? | YES | |
| Do Company's policies and procedures require that information be obtained from the customer as to whether it is transacting on its own behalf or on behalf of a third party? | YES | |
| Whether Company's internal procedures require additional verification of a Customer in the event of new material information affecting that Customer's risk profile as determined by Company. (e.g., new circumstances regarding its identity, activities or other Risk Factors) | YES | |
| Does Company have adequate policies, procedures and automated risk rules targeted to prevent ML/TF in the monitoring stage ? | YES | |
| Evaluation of effectiveness for the category | 11,11% (of 11,11%) | |
| Financial security measures when establishing business relationships (11,11%) | Does Company recognize the level of risk associated with the customer and attribute the level of that risk when the business relationship begins? | YES |
| Does Company apply financial security measures with an intensity correlated to the identified level of risk? | YES | |
| Does Company update the risk assessment of an existing customer, taking into account the level of associated risk (RBA), in the event of subsequent changes in this risk? | YES | |
| In the absence of a PEP statement from a customer, does Company verify that customer via a commercial or public database (e.g. namescan.io)? | YES | |
| Does Company carry out remote identification and verification of customer identity? | YES | |
| When determining its customer's risk profile (KYC), does Company examine the source of the assets and the source of the assets held by the customer when its risk profile is set high? | YES | |
| Has Company implemented a mechanism to immediately terminate its relationship with a customer if an unacceptable level of customer risk is identified? | YES | |
| Does Company identify and verify the identity of the beneficial owner and determine the ownership and control structure of the customer, taking into account the level of risk identified? | YES | |
| Is the verification of the identity of the customer and beneficial owner completed during the establishment of the business relationship substantiated in writing, approved by the AML Specialist and included in the customer file? | YES | |
| Has Company implemented rules for establishing business relationships through an intermediary? | NO | |
| Does Company assess its business relationships with its customers? | YES | |
| Has Company implemented a mechanism to immediately terminate its relationship with the customer if financial security measures cannot be applied? | YES | |
| Does Company verify customer information against independent and reliable databases? | YES | |
| Evaluation of effectiveness for the category | 10,25% (of 11,11%) | |
| Financial security measures during the course of the business relationship (11,11%) | Does Company review the business relationship and risk level assessments undertaken, including the rationale for the assessment undertaken and the frequency of assessments? | YES |
| Does Company carry out more thorough verification of the transaction or the customer if doubts are raised as to the completeness, authenticity or accuracy of any documents provided by the customer? | YES | |
| Does Company carry out in-depth verification of a transaction or customer when suspicious activity related to the customer or its transaction is detected? | YES | |
| Does Company request additional information from the Customer on the Customer's source of funding and assets for transactions that are not consistent with the Customer's risk profile? | YES | |
| Does Company use automated IT tools or an electronic transaction monitoring system? | YES | |
| Whether Company conducts ongoing monitoring, consisting of analysis of transactions, and ensures that transactions executed by the customer are consistent with Company's knowledge of the customer, the type and extent of the customer's business and are consistent with ML/TF risk | YES | |
| Has Company established the rationale and frequency for performing ongoing monitoring? | YES | |
| Evaluation of effectiveness for the category | 11,11% (of 11,11%) | |
| Record keeping (11,11%) | Does Company document the identified ML/TF risks? | YES |
| Does Company have a documented policy for dealing with the loss of customer records? | NO | |
| Is Company able to disclose the complete KYC documentation promptly upon request of the FIU or any other authority of the country entitled to inspect such documentation? | YES | |
| Does Company have procedures in place to ensure compliance with its record keeping and data protection policies, including the retention of evidence of financial security measures and transaction records for at least five (5) years? | YES | |
| Does Company document the results of its ongoing analysis of transactions carried out? | YES | |
| Evaluation of effectiveness for the category | 8,89% (of 11,11%) | |
| Designated Board Member and AML Specialist (11,11%) | Designation of the board member responsible for implementing the obligations set out in the Act | YES |
| AML/CFT qualifications of the responsible board member | YES | |
| Exercise of day-to-day oversight of AML/CFT processes by the board of directors | YES | |
| Appointment of a separate member of staff to the post of AML Specialist | YES | |
| AML/CFT Qualifications of AML Specialist | YES | |
| Evaluation of effectiveness for the category | 11,11% (of 11,11%) | |
| Internal control (11,11%) | Company's employees involved in the performance of AML/CFT duties perform first line of defense functions (functional control) | YES |
| Internal controls by the AML Specialist as part of the second line of defense | YES | |
| Company has an independent institutional internal control (internal audit) function | NO | |
| Company uses external auditors in the field of AML/CFT | NO | |
| Evaluation of effectiveness for the category | 5,55% (of 11,11%) | |
| Company screens customers and customer’s payments against sanctions list. | YES | |
| Procedure of screening against sanction lists is automated. | YES | |
| Sanction screenings (11,11%) | For a new customer sanction screenings is done before a transaction is executed. | YES |
| For a stable and mature customers sanction screenings is conducted periodically, depending on the type of customers. | YES | |
| Evaluation of effectiveness for the category | 11,11% (of 11,11%) | |
| Reporting obligations (11,11%) | Staff awareness of obligation to report information on suspicious transactions or suspicious customer activity to the FMS | YES |
| Staff awareness of reporting to the FM of circumstances that may indicate a suspected ML/TF crime | YES | |
| Staff awareness of providing information and documents at the request of the FMS | YES | |
| Awareness of staff on the reporting of actual or potential violations of the Act to the FMS by employees | YES | |
| Awareness of staff on the provision of information to the FMS on the occurrence of a suspicious transaction or asset values. | YES | |
| Evaluation of effectiveness for the category | 11,11% (of 11,11%) | |
| Training system (11,11%) | Company has and is implementing a training plan tailored to the nature of Company? | YES |
| Does Company provide training on: legislation on the prevention of money laundering or terrorist financing Company’s Risk Assessments Customer acceptance and risk assessment procedures Financial security measures Periodic check of customer data Ongoing customer follow-up indications of a particular risk of money laundering ("red flags") Reporting of suspicious behaviour Record keeping | YES | |
| Is the scope of Company's training program personalized and dependent on the position or function held by Company's personnel and dependent on the importance of the tasks of such personnel for the proper implementation of AML / CFT regulations? | YES | |
| Is the delivery of training outsourced to independent, external providers whose expertise and experience is verified? | YES | |
| Is the completion of the training by Company's staff dependent on the successful outcome of the knowledge verification carried out during this training (e.g., a certain score threshold obtained for correct answers)? | YES | |
| Evaluation of effectiveness for the category | 11,11% (of 11,11%) | |
| OVERALL LEVEL OF EFFECTIVENESS OF CONTROL FACTORS | 91,35% |
- Residual Risk has been calculated in accordance with the principles described in the matrix below:
| INHERENT RISK | SUM OF CONTROL FACTORS | RESIDUAL RISK |
LOW | 91-100% | low |
| 70-90% | moderate | |
| <70% | high | |
| MEDIUM | 91-100% | low |
| 80-90% | moderate | |
| <80% | high | |
| HIGH | 85-100% | moderate |
| <85% | high |
- Company estimated risk rating based on assumptions from this document:
| Residual risk | ||
| INHERENT RISK | SUM OF CONTROL FACTORS | RESIDUAL RISK |
| MEDIUM (assumption) | 93,57% | LOW (assumption) |
Final provisions
- The Xnity SA shall update this risk assessment periodically, at least every 2 years, whenever the risk factors described in this assessment change.
- In applying this risk assessment, the nature of the Xnity SA as an obliged institution and the provisions of the specification of the business activity in the field of virtual currencies should be taken into account.
This Risk Assessment was prepared on 01.05.2025 is effective as of this date.
Robert Masse
Member of the Management Board
Signature:_____________________
Johann Sebastiaan Caubergh
Member of the Management Board
Signature:_____________________
Johann Sebastiaan Caubergh
AML Officer
Signature:_____________________
01.05.2025
Annex No 3 “Customer Acceptance Policy”
Xnity SA . with its registered seat in Avenue Louise 231, 1050 Brussels, Belgium
Xnity SA. has set out customer acceptance guidelines as follows:
1. Know Your Customer (KYC) and Customer Due Diligence (CDD) needs to be carried out prior to any Business Relationship or transaction or acceptance of customer transactions.
2. Know Your Customer (KYC) and Customer Due Diligence (CDD) needs to be carried out prior to any Business Relationship or acceptance of customer transactions occasionally.
3. Each Customer, before entering into any Business Relationship or carrying out an Occasional Transaction must pass full verification process. The AML Specialist using the Document Verification System provided by a authorized KYC service providershall perform the following checks:
- Face Match Check, which allow to confirm matches of an image of a person face among a range of other photo images found in various documents, for example a passport, on name badge, a driver’s license or other photo ID as well as selfies or avatar images. A completed search results in a “match” or “doesn’t match” result. Required data for input: image of person face and images of document containing the image of the persons face;
- Identity Check, which allow to verify of a person identity by matching persons data against data from multiple document check databases;
- Document Integrity checks, automatically verification of the authenticity of photos and scaned copies of physical documents check. Document Integrity checks means analysis of any image or series of images for signs of tampering or modification through the use of graphic editors. Each reviewed document receives a trust score;
- Text recognition which allows automatically extract data from the documents;
- Additional check includes checking of completeness of documents, check if photos have been retaken from a screen or not, cross checking of all data from all submitted documents (name, date and place of birth, signature), checking or duplicated accounts, address check;
- Global Watchlist check after all necessary information being provided SumSub makes checks in Global Watchlist (). The database of a variety of lists across the globe is used to run regular identity checks against known or suspected terrorists, money launderers, frauds or PEPs. The watchlist includes domestic and international, government, law enforcement and regulatory databases that store information on individuals who are on a criminal list or prohibited in certain industries such as finance and healthcare.
4. Each Customer before entering into Business Relationship with Xnity SA or if he/she wants to continue collaboration with the Xnity SA . should provide requested documents:
- in the form of original document (natural and legal entities) for identification in person;
- in the form of uncertified copies for remote identification.
5. The Customer's identity (personal) document and other documents submitted to the Company shall satisfy the following requirements:
- Identity documents of natural entities shall contain the information like: full name (including middle name), residential address, citizenship, number entered in the European Universal Electronic System for Civil Registration (national identification number (if applicable)), date and place of birth, series and number of the document confirming the identity;
- The documents shall be valid (the validity term specified in the document has not expired at the time of presentation to the Company, and the document is not declared invalid;
- The documents should contain no evident signs of falsification, corrections, cross-outs or deletions;
- The documents should contain no damages (water, stains of dye, punches, etc.).
6. Verification of residence is required by obtaining a copy of an acceptable address proof document issued in the 3 months prior to establishing an business relationship with Xnity SA . The document must carry the Customer’s name and address, if refers to bank statement must carry the sort code and account number. A valid proof of residence document can be:
- bank statement;
- debit or credit card statement;
- utility bill (water, electricity, gas, internet, phone);
- payroll statement or official salary document from employer;
- insurance statement;
- tax document;
- residence certificate.
7. Before entering into a Business Relationship with Xnity SA, the Customer must provide identifying information appropriate to their legal status:
A. If the Customer is a legal person or an organizational unit granted legal capacity under national or EU law (e.g., a company, NGO, or registered association), the following information is required:
a) The full legal name;
b) The organizational form;
c) The address of the registered office and business location (if different);
d) The Tax Identification Number (TIN);
e) Company registration number;
f) Date of registration;
g) Identification of natural persons acting on behalf of the entity (e.g., UBOs, directors, or authorized signatories), which is performed as part of the KYC process using corporate documents, public registries, and open sources.
B. If the Customer is a natural person:
a) Full name (first and last name);
b) Date and place of birth;
c) Residential or correspondence address;
d) Citizenship;
e) Copy of a valid government-issued identity document (passport, national ID, or driving license);
f) Proof of address (e.g., utility bill, rental agreement, or bank statement);
g) Tax Identification Number (if available). If not available, a declaration of self-employment or freelance status may be requested.
8. Conducting Enhanced Due Diligence (EDD) for high-risk Customers.
9. Enhanced security measures provides a greater level of scrutiny of potential and current Customers. In the cases of higher risk of money laundering or terrorist financing Xnity SA undertakes steps to understand the origin and legitimacy of the Customer’s wealth and ask Customer for additional documents and information other than stipulated above, in particular:
- official corporate records of amendments in corporate structure from last 18 months;
- copy of Annual Financial Statements from last 3 years;
- copy of Tax Declarations with confirmation of submission from last 3 years;
- names and location of Customer’s Customers and suppliers;
- Bank statements from last 18 months;
- copy of lease agreement of register office;
- standard documents, which confirm the sale of property, inheritance, salary, etc.
9. Senior Management needs to consider and make the final decision to engage in any business relationship or accept customer transactions with high-risk customers.
10. Prohibited Customer means a customer with whom Xnity SA does not establish a Business Relationship or does not carry out Occasional Transactions and includes:
- persons who have refused to provide required information or documentation, fail to provide sufficient information, fail to provide information regarding their identity, or KYC cannot be conducted;
- persons who use alias or conceal their true names, or provide false information to conceal themselves;
- financial institutions that are residents of countries or territories without being physically present in such countries or territories (also referred to as shell banks);
- correspondent banks that do not have any policies or measures on AML/CTF, or the same fail to comply with global standards or international laws;
- a person or group of persons or entity that triggers sanctions lists, as announced or provided by AMLO and international organizations;
- persons suspected of using the institution as a money laundering channel or using the transactions to finance terrorism and proliferation of weapon of mass destruction financing.
11. Regular and continuous review of Customer information needs to be conducted until a relationship with the customer is terminated.
12. Transaction movements need to be tracked continuously until a relationship with the customer is terminated.
13. Transaction reporting needs to be carried out in accordance with AML/CTF laws. Once suspicious transactions that may constitute money laundering and terrorism financing are detected, MLRO needs to be notified immediately, for considering further reporting to CTIF-CFI.
14. The Customer’s risk levels on money laundering and terrorism financing need to be reviewed in accordance with the results of customer information review and customer transaction monitoring.
This Customer Acceptance Policy was prepared on 01.05.2025 is effective as of this date.
Johann Sebastiaan Caubergh
Member of the Management Board
Signature:
Johann Sebastiaan Caubergh
AML Officer
Signature:
01.05.2025
Annex No 4 “Anti-Bribery & Corruption Policy”
Xnity SA . with its registered seat in Avenue Louise 231, 1050 Brussels, Belgium
Xnity SA . (hereinafter: “Xnity SA ”) has set out Anti-Bribery & Corruption Policy as follows:
1. Introduction
This Anti-Bribery & Corruption Policy ("Policy") outlines the commitment of Xnity SA to maintaining the highest standards of ethical conduct and integrity in all its business dealings and relationships. The Policy applies to all employees, officers, directors, contractors, consultants, agents, and any other parties associated with Xnity SA .
2. Definitions
Bribery: Offering, giving, receiving, or soliciting anything of value as a means of influencing the actions of an individual or entity, including public officials, in order to gain a commercial, contractual, regulatory, or personal advantage ()
Corruption: Abuse of public office for private gain. Corruption is the promising, offering, giving, demanding, accepting by any person directly or indirectly, any undue, pecuniary, non-pecuniary or other advantage, or accepting the offer or promise of such an advantage in return for an act or failure to act in the exercise of a public function or in the course of business.
3. Compliance with Laws
3.1. Xnity SA is committed to complying with all applicable anti-bribery and corruption laws and regulations in every jurisdiction in which it operates, including, but not limited to following below:
- Act of 9 June 2006 on the Central Anti-Corruption Bureau (Journal of Laws 2006 No. 104 item 708 with further amendments)
- Act of 6 June 1997 - Criminal Code (Journal of Laws. 1997 No. 88 item 553 with further amendments)
- Act of 10 September 1999 - Fiscal Penal Code (Journal of Laws 1999 No. 83 item 930 with further amendments).
3.2. This Policy establishes mandatory guidelines for compliance with all applicable ABC requirements in the various territories in which Xnity SA operates, especially with the core provisions of the U.S. Foreign Corrupt Practices Act and the UK Bribery Act 2010.
4. Scope and Applicability
4.1. This Policy applies to all individuals working for or on behalf of Xnity SA at all levels and grades, whether permanent, fixed-term or temporary, and wherever located, including consultants, contractors, seconded staff, casual staff, agency staff, volunteers, agents, sponsors and any other person who performs services for or on behalf of Xnity SA (collectively referred to as “Employees” in this Policy).
4.2. It is the responsibility of all mentioned in point 4.1. individuals to act in accordance with this Policy.
4.3. Failure by any individual to comply with this Policy may have negative consequences for the both Xnity SA and the one who breached the provisions of the abovementioned Policy related to civil and criminal field.
4.4. A disciplinary penalty may be imposed on any individual, who has breached the provisions of this policy, including suspension (where applicable), disciplinary measures (where applicable), fines and/or termination of employment (where applicable), as well as referral to relevant government authorities (based on the type of act and decision of Management Board).
5. Prohibited Conduct
5.1. Bribery: Employees and associated parties must not offer, promise, give, request, or accept bribes, kickbacks, facilitation payments, or any other improper advantages, whether directly or indirectly, to or from any Third Party in order to obtain or retain business or gain any other improper advantage.
5.2. In this Policy, Third Party means any individual or organisation that Employees come into contact with during the course of work and the running of the Xnity SA ’s business, and includes actual and potential clients, intermediaries, referrers of work, suppliers, distributors, business contacts, agents, advisers, government and public bodies (including their advisers, representatives and officials), politicians and political parties.
5.3. Facilitation payments, also known as "grease payments," are prohibited under this Policy. No exceptions will be made, regardless of the commonality of such payments in a particular region or industry.
5.4 The term “greasy payment” in the context of the matter regulated by this Policy, refers to a situation where a person or company pays or promises a payment in order to insulate themselves from potential corrupt consequences or to be seen to be honest with law enforcement or other regulatory institutions. A skimming payment can be used in situations where a person or company has already been involved in corrupt activities or has knowledge of corruption, but wants to avoid legal or reputational consequences.
6. Gifts, Hospitality, and Entertainment
6.1. This Policy does not prohibit normal and appropriate gifts and hospitality (given and received) to or from Third Parties unless otherwise specifically stated, however gifts, hospitality and entertainment may be offered or accepted in compliance with applicable laws and regulations and must not be excessive or intended to improperly influence business decisions or relationships.
6.2 Employees must exercise caution when giving or receiving gifts, hospitality or entertainment, particularly when dealing with government officials (PEPs) or representatives of business partners. Such type of behavior:
- must not be made with the intention of improperly influencing a Third Party or Employees to obtain or retain business or a business advantage, or to reward the provision or retention of business or a business advantage, or in explicit or implicit exchange for favours or benefits;
- must comply with local law in all relevant countries;
- must be given in the name of the organization, not in an individual’s name;
- must not include cash or a cash equivalent;
- must be appropriate in the circumstances;
- must be of an appropriate type and value and given at an appropriate time taking into account the reason for the gift;
- must be given openly, not secretly.
7. Conflicts of Interest
Employees must avoid situations where their personal interests conflict, or appear to conflict, with the interests of Xnity SA . Any actual or potential conflicts of interest must be disclosed promptly to the appropriate authority.
8. Reporting Procedures
8.1. Employees are encouraged to report any suspected or actual instances of bribery, corruption, or related misconduct promptly using the reporting channels provided by Xnity SA .
8.2. Reports will be treated confidentially and investigated promptly and impartially.
9. Training and Awareness
Xnity SA will provide regular training and awareness programs to ensure that all Employees and associated parties understand their obligations under this Policy and are equipped to identify and address bribery and corruption risks.
10. Monitoring and Review
This Policy will be subject to regular review by Senior Management to ensure its effectiveness and relevance in addressing the evolving risks of bribery and corruption. Any necessary updates or revisions will be made in consultation with relevant stakeholders.
11. Leadership Commitment
11.1. Senior Management is committed to leading by example and fostering a culture of integrity, transparency, and compliance with anti-bribery and corruption standards throughout the organization.
11.2. Senior Management commitment includes also the periodic review, approval of this Policy and the allocation of sufficient resources to ensure ABC Compliance, including the appointment of qualified, dedicated and experienced compliance officer who will be responsible for ensuring compliance throughout Xnity SA to maintain this Policy through the implementation and execution of appropriate internal controls.
12. Conclusion
Xnity SA expects all employees, contractors, and associated parties to adhere to the principles and requirements outlined in this Policy at all times. Upholding these standards is fundamental to maintaining the trust and reputation of Xnity SA and safeguarding its interests and stakeholders.
This Anti-Bribery & Corruption Policy was prepared on 01.05.2025 is effective as of this date.
Johann Sebastiaan Caubergh
Member of the Management Board
Signature:
Johann Sebastiaan Caubergh
AML Officer
Signature:_____________________
01.05.2025
Geographical Scope and Prohibited Jurisdictions
Geographical Scope and Prohibited Jurisdictions
Xnity SA conducts its business activities exclusively within the European Union (EU), the European Economic Area (EEA), the United Kingdom (UK), and Switzerland.
In the United Kingdom and Switzerland, Xnity SA’s services are limited to account and crypto-related functionalities; Payconiq, Wero, and Visa/Mastercard payment services are not offered in those jurisdictions.
Xnity SA shall not establish or maintain any business relationship, process transactions, or provide services to any individual or legal entity resident in, incorporated in, or otherwise connected with the following prohibited jurisdictions, as aligned with the XBO restriction list and applicable EU/UN sanctions:
Afghanistan, Algeria, Bangladesh, Belarus, Bolivia, Burkina Faso, Burundi, Cambodia, Congo (Brazzaville), Congo (Kinshasa), Crimea Region, Donetsk Region, Gabon, Haiti, Iran, Iraq, Jamaica, Kherson Region, Korea (the Democratic People's Republic of Korea – North Korea), Lesotho, Libya, Luhansk Region, Mali, Myanmar/Burma, Russian Federation, Syria, United Arab Emirates, United States of America, Virgin Islands (U.S.), Yemen, and Zaporizhzhia Region.
Any attempt to register, transact, or otherwise interact with Xnity SA from the above jurisdictions shall be automatically blocked and reported to the AML Officer for further assessment.