Aml & Kyc Policy

AML & KYC Policy

Ffbet is committed to preventing money laundering, terrorist financing and related financial crime. This policy establishes the mandatory controls, processes and responsibilities to ensure compliance with applicable anti-money laundering (AML) and counter-terrorist financing (CTF) obligations across all business activities, channels and jurisdictions where Ffbet operates.

Scope and Purpose

This policy applies to all personnel and contractors acting on behalf of Ffbet and governs customer onboarding, ongoing due diligence, transaction monitoring and reporting of suspicious activities. It sets out the risk-based framework by which Ffbet identifies, assesses and mitigates AML/CTF risks arising from customer relationships and financial transactions.

Definitions

  • Money Laundering: The process of disguising the origin of illicit proceeds through placement, layering and integration into legitimate channels.
  • Terrorist Financing: Providing funds or financial support to individuals or organizations engaged in or supporting terrorist activities.
  • Sanctions and Restricted Jurisdictions: Legal or regulatory prohibitions or limitations on providing products or services to specific individuals, entities or countries, and related screening obligations.
  • Politically Exposed Persons (PEPs): Natural persons with elevated public functions or their immediate family members and close associates, subject to enhanced scrutiny.
  • Know Your Customer (KYC) and Customer Identification Program (CIP): The set of procedures to identify, verify and monitor customers, and to maintain ongoing knowledge of the customer.
  • Suspicious Activity Report (SAR): A report filed when there is reasonable suspicion of money laundering, terrorist financing or other illicit activity.
  • Enhanced Due Diligence (EDD): Additional verification and monitoring for higher-risk customers or activities.
  • Ongoing Monitoring: Continuous review of customer activity to detect deviations from expected behavior.
  • Geographic Blocking: Measures to restrict access or services in jurisdictions where prohibited or high-risk activity is identified.

Governance and Responsibilities

The Ffbet Board delegates AML/CTF oversight to a designated Compliance Officer who reports to executive management. A risk-based approach governs policy implementation, with periodic risk assessments and independent testing where required by law or regulation. The Compliance function is responsible for maintaining the effectiveness of the program and coordinating with relevant business units to ensure consistent application of controls.

Know Your Customer Program

Ffbet maintains a structured KYC program comprising onboarding controls, identity verification, ongoing monitoring, risk management, and suspicious activity reporting. The program relies on data integrity and timely updates to reflect changes in risk posture.

  • 4.1 Customer Onboarding and Acceptance
    • We collect baseline information, including full legal name, date of birth, residential address, and contact details; for accounts funded by crypto assets, we collect cryptocurrency wallet addresses where applicable; we may require supporting documents to establish identity and address.
    • Acceptance requires successful verification of identity. If identity cannot be verified or the customer is located in a jurisdiction with restrictions, the account shall be blocked or referred for review in accordance with applicable laws and internal risk criteria.
  • 4.2 Identity Verification and Age Validation
    • We verify the authenticity of provided identification documents and confirm that the customer meets the minimum age requirement to engage in gambling activities in the relevant jurisdiction.
  • 4.3 Ongoing Monitoring and Data Updating
    • We monitor account activity for consistency with the customer profile and risk rating, and we update KYC information upon material changes or at defined intervals not to exceed 24 months, whichever occurs first.
  • 4.4 Risk-Based Due Diligence
    • Each customer is assigned a risk rating based on factors including geography, product usage, expected transaction volumes and funding sources. Low-risk customers undergo standard due diligence; higher-risk customers trigger enhanced due diligence and ongoing heightened monitoring.
  • 4.5 Enhanced Due Diligence
    • For high-risk customers, we collect and verify additional data, including full legal name, country of citizenship, permanent address, identification numbers, identification documents, and evidence of source of funds and source of wealth. Beneficial ownership information for entities may be collected where applicable. We may engage third-party verifiers to establish a reasonable basis to know the customer’s true identity.
    • Enhanced due diligence includes strengthened ongoing monitoring and, where warranted by risk, temporary restrictions on activity pending further review.
  • 4.6 Sanctions Screening and Prohibited Jurisdictions
    • We conduct ongoing sanctions and sanctions-related screening to ensure customers and counterparties are not located in or affiliated with restricted jurisdictions or listed on relevant sanctions lists. Accounts associated with restricted individuals, entities or jurisdictions are blocked or escalated for review.
  • 4.7 Politically Exposed Persons (PEPs) and Related Controls
    • Customers identified as PEPs or family and close associates of PEPs are subjected to enhanced due diligence and ongoing monitoring commensurate with risk and regulatory requirements.

Information Sharing and Confidentiality

Ffbet may disclose customer information to regulatory authorities, law enforcement, or other competent government bodies, as required by applicable law, and to third-party service providers who assist in providing our services. Disclosures shall be limited to information reasonably necessary for AML/CTF compliance and related legal obligations. All data handling follows applicable privacy and data protection requirements, and records are maintained in secure systems with access restricted to authorized personnel.

Suspicious Activity Reporting

Any employee who knows, suspects or has reasonable grounds to suspect that a money laundering offence or other illicit activity is occurring must promptly report the matter through the designated internal channel. Staff are not required to actively seek indicators of wrongdoing; however, upon awareness or suspicion arising during the course of normal duties, a SAR must be filed. SARs should be submitted as soon as practicable and in any event within 3 business days of becoming aware of the matter.

Transactions Monitoring and Regulatory Reporting

Ffbet maintains transaction monitoring controls designed to identify unusual or suspicious activity in real time using rule-based and technology-assisted systems. Ongoing monitoring supports the timely identification of deviations from expected customer behavior and funding patterns. Any activities identified as suspicious, or any required regulatory reports, are escalated in accordance with internal procedures and applicable law. Records of monitoring, investigations and reports are kept in secure archives for the legally required retention period and made available to regulators or law enforcement as mandated.

Geo-Blocking and Jurisdictional Compliance

Ffbet shall apply geo-blocking measures to restrict access to services from jurisdictions where participation is not permitted or creates unacceptable risk. Customer-provided information, IP address data and device signals are used to determine location for compliance purposes. If a customer’s location changes such that entry into services becomes prohibited, access to the account may be suspended or terminated in accordance with policy and law.

Training and Governance

All relevant personnel receive annual AML/CTF training and periodic updates on regulatory developments, KYC procedures, SAR processes, and data privacy obligations. The Compliance function conducts ongoing governance activities, including policy reviews, risk assessments and independent testing where required by regulation or internal risk appetite.

Data Retention and Access

Ffbet retains KYC records, transaction histories and SARs for a minimum of five years after the end of the customer relationship, or longer where required by applicable law. Access to records is restricted to authorized personnel and auditors, and records are protected with appropriate security controls and encryption during storage and transmission.

Policy Maintenance and Contact

The AML/CTF policy is reviewed at least annually and whenever there are material changes to the regulatory framework, business operations, or risk profile. Updates require approval by the Compliance leadership and board where applicable. Questions or reports related to this policy may be directed to the Ffbet Compliance Team at [email protected].