Anti-money Laundering Policy

1. Introduction and Scope

This Anti-Money Laundering Policy (the Policy) governs Mmk121's compliance framework for anti-money laundering and counter-terrorist financing (AML/CFT) applicable to all accounts and activities on the Mmk121 platform. The Policy defines responsibilities, controls and processes designed to detect and prevent misuse of the platform for money laundering, terrorist financing, or other illicit activity.

2. Objectives and Regulatory Basis

The Company implements measures consistent with applicable AML/CFT laws, FATF guidance, and data protection laws. The objectives are to detect, deter and report suspicious activity, preserve information relevant to investigations, and cooperate with competent authorities as required by law.

3. Risk-Based Approach and Risk Assessment

The Company adopts a risk-based approach to AML, evaluating risks across three dimensions: Customer risk, Geographic risk, and Transaction risk. The assessment considers criteria including:

  • Country risk: residence or domicile in jurisdictions designated as high-risk, or as having strategic deficiencies, or flagged by FATF;
  • Customer risk: presence of politically exposed persons (PEPs), sanctions status, or suspicious activities;
  • Transaction risk: patterns of unusually large or rapid deposits or withdrawals, or transactions that deviate from the customer’s profile.

The Company updates risk assessments periodically and whenever significant changes occur in products, customers, or regulatory requirements. Controls are calibrated to the assessed risk level of each customer.

4. Customer Due Diligence and Verification

The Company applies standard verification (due diligence) under defined conditions. On onboarding and during ongoing monitoring, the Company collects and verifies information to confirm identity and assess risk. In particular, the Company requires, and shall retain, the following:

  • Personal data: full name, date of birth, residential address, contact details, and a valid email address;
  • Identity documents: a government-issued photo ID (e.g., passport or national ID);
  • Payment information: primary payment instrument details (card number and expiry, or wallet details) used to fund the account; cardholder name must match the account holder; card CVV and middle digits may be concealed where allowed.
  • Proof of address: utility bill or equivalent document showing the user’s name and address.
  • Proof of activity data: information requested by the Company to verify the user’s identity and to ensure compliance with this Policy.

The Company may require additional documents or live verification via video call. The Company may close or suspend an account if information proves false or misleading.

5. Enhanced Due Diligence for PEPs and High-Risk Jurisdictions

Where the user is a Politically Exposed Person (PEP) or located in a high-risk jurisdiction, the Company applies enhanced due diligence, including:

  • Additional verification of identity, address, and source of wealth;
  • Senior management approval for continued activity;
  • Collection of source of funds information in accordance with applicable local requirements;
  • In certain cases, temporary limitations on transactions or access until verification is complete.

If the user refuses to provide required information or if the Company has sufficient grounds to suspect illegal use, the Company may notify competent authorities and may restrict access or terminate the account.

6. Ongoing Activity Monitoring

All user activity is monitored for indicators of suspicious activity. Indicators include, but are not limited to:

  • Multiple devices or sessions within a short period; unusual login patterns;
  • Frequent changes in payment methods; inconsistent geolocation data;
  • Unusual or inconsistent spending and depositing patterns; rapid activity increases;
  • Discrepancies between device identity, IP address, or account details.

When suspicious activity is detected, the Company’s AML team evaluates the risk and escalates to the appropriate department for action, including possible temporary restrictions or further verification.

7. Transaction Monitoring and Payment Integrity

Transaction monitoring and payment controls ensure funds move only to and from properly identified sources. The Company enforces:

  • Card payments: cardholder name must match the account holder’s name. Third-party card payments are prohibited;
  • Wallet payments: the wallet email must match the account email; deposits from a payment instrument must be traceable to the user;
  • No acceptance of anonymous or untraceable payment instruments for deposits or withdrawals;
  • Withdrawals will be conducted using the same or verifiably linked instrument as the deposit where possible; otherwise to a verified instrument in the user’s name.

All transactions are subject to monitoring for compliance with this Policy and applicable law. The Company does not withdraw funds to payment instruments belonging to third parties or to anonymous wallets without lawful justification.

8. Record-Keeping and Data Retention

The Company shall securely store verification documents, transactional records, and related data in accordance with applicable AML/CFT laws and data protection regulations. Retention shall be compliant with legal requirements and not shorter than the minimum period prescribed by law. Records shall be protected by appropriate security measures and access controls, and may be disclosed to relevant authorities or regulators as required.

9. Cooperation with Authorities and Reporting

The Company will report suspicious activity and cooperate with investigations pursuant to applicable law. The designated AML Officer (the MLRO) is responsible for reporting to competent authorities, preserving evidentiary materials, and facilitating regulatory cooperation. The Company may suspend or freeze accounts or transactions pending investigation where warranted by risk assessment or regulatory requirements.

10. Roles, Training and Governance

The Company designates an AML Officer (the MLRO) responsible for program governance, policy maintenance, risk assessment updates, and regulatory reporting. The function includes staff training on AML procedures and ongoing risk reassessment, with appropriate internal controls to ensure independence and segregation of duties.

11. Amendments and Public Availability

The Policy may be amended at any time by the Company. Material changes will be communicated to registered users via email; continued use after notification constitutes acceptance of the updated Policy. The effective date of each amendment will be stated in the notice.