Anti-Money Laundering (AML) and Know Your Customer (KYC) Policy
1. Introduction
Ventures Lab Malta Limited (the "Company", "we", "our", or "us")
is committed to protecting its gaming platform from being used
for money laundering, terrorist financing, fraud, or other
unlawful financial activities.
As the holder of a Business-to-Consumer Gaming Service Licence
issued by the Malta Gaming Authority ("MGA"), the Company is
required to comply with the Prevention of Money Laundering Act
(Chapter 373 of the Laws of Malta), the Prevention of Money
Laundering and Funding of Terrorism Regulations (PMLFTR), and
all applicable guidance issued by the Financial Intelligence
Analysis Unit ("FIAU") and the MGA.
To meet these obligations, the Company maintains a comprehensive
AML and KYC framework based on a risk-based approach that
applies throughout the customer lifecycle.
This Policy applies to every individual who registers for, or
maintains, an account with the Company.
2. Compliance Principles
The Company's AML and KYC programme is designed to:
- establish and verify the identity of customers;
- understand the purpose of the customer relationship;
-
identify and assess money laundering and terrorist financing
risks;
- monitor customer activity on an ongoing basis;
-
identify suspicious behaviour and report it where required;
-
maintain appropriate records to demonstrate regulatory
compliance; and
-
ensure that employees understand their legal and regulatory
responsibilities.
Compliance measures are proportionate to the level of risk
presented by each customer.
3. Customer Identification Measures
The Company requires customers to complete identity verification
whenever required under applicable legislation or internal
compliance procedures.
Verification may be completed before account activation, during
the customer relationship, or prior to specific transactions.
Information requested may include:
- full legal name;
- residential address;
- date of birth;
- nationality;
- government-issued identification;
- proof of address;
- ownership of payment instruments; and
-
any additional documentation reasonably required to satisfy
legal obligations.
Verification may be carried out through secure electronic
verification services, documentary review, or other reliable
independent sources.
Where the Company cannot satisfactorily verify a customer's
identity, it may refuse registration, suspend account activity,
restrict transactions, or terminate the business relationship.
4. Enhanced Due Diligence
Certain customers or transactions require additional scrutiny
because they present a higher risk of financial crime.
Enhanced Due Diligence ("EDD") may be applied where:
-
the customer is identified as a Politically Exposed Person
("PEP");
- sanctions screening identifies a potential match;
-
the customer is connected with a high-risk jurisdiction;
-
transaction values or behaviour exceed the Company's risk
appetite;
-
unusual or complex transaction patterns are detected; or
- the source of funds cannot readily be established.
Enhanced verification measures may include:
- obtaining supplementary identity documentation;
-
requesting evidence of source of funds or source of wealth;
- conducting additional independent verification;
- increased transaction monitoring; and
-
approval by senior compliance management before continuing the
relationship.
5. Source of Funds Verification
Where appropriate, the Company may request evidence
demonstrating the lawful origin of funds used within the
customer's account.
Depending on the circumstances, documentation requested may
include:
- recent bank statements;
- employment or salary documentation;
- tax records;
- business ownership documentation;
- investment portfolios;
- inheritance records;
- property sale agreements; or
-
other documentation reasonably demonstrating legitimate
ownership of funds.
Until satisfactory information has been provided, the Company
may restrict account functionality or delay transactions.
6. Ongoing Monitoring
The Company performs continuous monitoring throughout the
duration of the customer relationship.
Monitoring procedures are designed to identify activity
including:
- unusually large or frequent deposits;
- rapid deposits followed by immediate withdrawals;
- betting activity inconsistent with customer behaviour;
- structuring of transactions;
- use of multiple payment instruments;
-
transactions inconsistent with known customer information; and
- other indicators of potential financial crime.
Where monitoring identifies unusual activity, the Company may
conduct additional compliance reviews before permitting further
transactions.
7. Withdrawal Verification Requirements
To comply with applicable AML, CTF, fraud prevention, and
regulatory obligations, the Company may require additional
verification before processing withdrawal requests.
Identity verification will ordinarily be required where a
customer's cumulative deposits exceed €2,000.
For this purpose, cumulative deposits may be calculated either:
-
on a daily cumulative basis, taking into account every deposit
made since the business relationship commenced; or
-
by aggregating deposits made during a rolling period of one
hundred and eighty (180) days.
Where enhanced verification becomes necessary, withdrawal
requests may remain pending until all requested documentation
has been received and successfully reviewed.
The Company may additionally require customers to verify
ownership of payment methods, provide supporting evidence
regarding the origin of deposited funds, or submit further
documentation where considered necessary for compliance
purposes.
8. Sanctions and PEP Screening
The Company screens customers against recognised sanctions and
Politically Exposed Person databases during onboarding and
throughout the customer relationship.
Screening includes, where applicable:
- European Union sanctions lists;
- United Nations sanctions lists;
- domestic sanctions registers;
- PEP databases; and
- other recognised compliance screening systems.
Potential matches are reviewed by the Compliance function before
any decision affecting the customer relationship is made.
9. Suspicious Activity Reporting
Where knowledge, suspicion, or reasonable grounds for suspicion
of money laundering, terrorist financing, or related criminal
conduct exist, the Company will submit a Suspicious Activity
Report ("SAR") to the Financial Intelligence Analysis Unit
("FIAU") in accordance with Maltese law.
Employees are prohibited from informing customers that a report
has been submitted or that an investigation is taking place.
The Company will cooperate fully with the FIAU, the Malta Gaming
Authority, law enforcement agencies, and any other competent
authority acting within its legal powers.
10. Customer Responsibilities
Customers are responsible for:
-
providing accurate and complete registration information;
-
maintaining current personal details throughout the business
relationship;
- supplying verification documents upon request;
- responding promptly to compliance enquiries; and
-
ensuring that documentation submitted is authentic and valid.
Failure to comply with these obligations may result in
restrictions on account activity, suspension of services,
delayed transactions, or closure of the customer account.
11. Governance and Internal Controls
The Company's AML framework is supported through appropriate
governance arrangements, including:
-
appointment of a Money Laundering Reporting Officer (MLRO);
- documented AML and CTF policies;
- internal escalation and reporting procedures;
- periodic enterprise-wide risk assessments;
- compliance monitoring activities;
- independent internal reviews where appropriate; and
-
regular AML and financial crime awareness training for
employees.
These measures are reviewed periodically to ensure their
effectiveness and ongoing compliance with regulatory
expectations.
12. Record Keeping and Confidentiality
The Company maintains records relating to customer due
diligence, verification, monitoring activities, transactions,
risk assessments, and regulatory reporting as required under
applicable legislation.
Records are retained for a minimum period of five (5) years
following the termination of the business relationship or the
completion of the relevant transaction, unless a longer
retention period is required by law.
All personal information collected under this Policy is
processed securely and confidentially in accordance with the
General Data Protection Regulation (GDPR) and the Company's
internal information security procedures.
13. Policy Administration
This Policy forms part of the Company's compliance management
framework and is subject to periodic review by the Compliance
function and Senior Management.
The Company may amend this Policy whenever necessary to reflect
legislative developments, regulatory guidance, operational
changes, or enhancements to its financial crime prevention
framework. The latest approved version will be made available
through the Company's official channels.
Anti-Money Laundering (AML) and Know Your Customer (KYC) Policy
1. Introduction
Ventures Lab Malta Limited (the "Company", "we", "our", or "us")
is committed to protecting its gaming platform from being used
for money laundering, terrorist financing, fraud, or other
unlawful financial activities.
As the holder of a Business-to-Consumer Gaming Service Licence
issued by the Malta Gaming Authority ("MGA"), the Company is
required to comply with the Prevention of Money Laundering Act
(Chapter 373 of the Laws of Malta), the Prevention of Money
Laundering and Funding of Terrorism Regulations (PMLFTR), and
all applicable guidance issued by the Financial Intelligence
Analysis Unit ("FIAU") and the MGA.
To meet these obligations, the Company maintains a comprehensive
AML and KYC framework based on a risk-based approach that
applies throughout the customer lifecycle.
This Policy applies to every individual who registers for, or
maintains, an account with the Company.
2. Compliance Principles
The Company's AML and KYC programme is designed to:
- establish and verify the identity of customers;
- understand the purpose of the customer relationship;
-
identify and assess money laundering and terrorist financing
risks;
- monitor customer activity on an ongoing basis;
-
identify suspicious behaviour and report it where required;
-
maintain appropriate records to demonstrate regulatory
compliance; and
-
ensure that employees understand their legal and regulatory
responsibilities.
Compliance measures are proportionate to the level of risk
presented by each customer.
3. Customer Identification Measures
The Company requires customers to complete identity verification
whenever required under applicable legislation or internal
compliance procedures.
Verification may be completed before account activation, during
the customer relationship, or prior to specific transactions.
Information requested may include:
- full legal name;
- residential address;
- date of birth;
- nationality;
- government-issued identification;
- proof of address;
- ownership of payment instruments; and
-
any additional documentation reasonably required to satisfy
legal obligations.
Verification may be carried out through secure electronic
verification services, documentary review, or other reliable
independent sources.
Where the Company cannot satisfactorily verify a customer's
identity, it may refuse registration, suspend account activity,
restrict transactions, or terminate the business relationship.
4. Enhanced Due Diligence
Certain customers or transactions require additional scrutiny
because they present a higher risk of financial crime.
Enhanced Due Diligence ("EDD") may be applied where:
-
the customer is identified as a Politically Exposed Person
("PEP");
- sanctions screening identifies a potential match;
-
the customer is connected with a high-risk jurisdiction;
-
transaction values or behaviour exceed the Company's risk
appetite;
-
unusual or complex transaction patterns are detected; or
- the source of funds cannot readily be established.
Enhanced verification measures may include:
- obtaining supplementary identity documentation;
-
requesting evidence of source of funds or source of wealth;
- conducting additional independent verification;
- increased transaction monitoring; and
-
approval by senior compliance management before continuing the
relationship.
5. Source of Funds Verification
Where appropriate, the Company may request evidence
demonstrating the lawful origin of funds used within the
customer's account.
Depending on the circumstances, documentation requested may
include:
- recent bank statements;
- employment or salary documentation;
- tax records;
- business ownership documentation;
- investment portfolios;
- inheritance records;
- property sale agreements; or
-
other documentation reasonably demonstrating legitimate
ownership of funds.
Until satisfactory information has been provided, the Company
may restrict account functionality or delay transactions.
6. Ongoing Monitoring
The Company performs continuous monitoring throughout the
duration of the customer relationship.
Monitoring procedures are designed to identify activity
including:
- unusually large or frequent deposits;
- rapid deposits followed by immediate withdrawals;
- betting activity inconsistent with customer behaviour;
- structuring of transactions;
- use of multiple payment instruments;
-
transactions inconsistent with known customer information; and
- other indicators of potential financial crime.
Where monitoring identifies unusual activity, the Company may
conduct additional compliance reviews before permitting further
transactions.
7. Withdrawal Verification Requirements
To comply with applicable AML, CTF, fraud prevention, and
regulatory obligations, the Company may require additional
verification before processing withdrawal requests.
Identity verification will ordinarily be required where a
customer's cumulative deposits exceed €2,000.
For this purpose, cumulative deposits may be calculated either:
-
on a daily cumulative basis, taking into account every deposit
made since the business relationship commenced; or
-
by aggregating deposits made during a rolling period of one
hundred and eighty (180) days.
Where enhanced verification becomes necessary, withdrawal
requests may remain pending until all requested documentation
has been received and successfully reviewed.
The Company may additionally require customers to verify
ownership of payment methods, provide supporting evidence
regarding the origin of deposited funds, or submit further
documentation where considered necessary for compliance
purposes.
8. Sanctions and PEP Screening
The Company screens customers against recognised sanctions and
Politically Exposed Person databases during onboarding and
throughout the customer relationship.
Screening includes, where applicable:
- European Union sanctions lists;
- United Nations sanctions lists;
- domestic sanctions registers;
- PEP databases; and
- other recognised compliance screening systems.
Potential matches are reviewed by the Compliance function before
any decision affecting the customer relationship is made.
9. Suspicious Activity Reporting
Where knowledge, suspicion, or reasonable grounds for suspicion
of money laundering, terrorist financing, or related criminal
conduct exist, the Company will submit a Suspicious Activity
Report ("SAR") to the Financial Intelligence Analysis Unit
("FIAU") in accordance with Maltese law.
Employees are prohibited from informing customers that a report
has been submitted or that an investigation is taking place.
The Company will cooperate fully with the FIAU, the Malta Gaming
Authority, law enforcement agencies, and any other competent
authority acting within its legal powers.
10. Customer Responsibilities
Customers are responsible for:
-
providing accurate and complete registration information;
-
maintaining current personal details throughout the business
relationship;
- supplying verification documents upon request;
- responding promptly to compliance enquiries; and
-
ensuring that documentation submitted is authentic and valid.
Failure to comply with these obligations may result in
restrictions on account activity, suspension of services,
delayed transactions, or closure of the customer account.
11. Governance and Internal Controls
The Company's AML framework is supported through appropriate
governance arrangements, including:
-
appointment of a Money Laundering Reporting Officer (MLRO);
- documented AML and CTF policies;
- internal escalation and reporting procedures;
- periodic enterprise-wide risk assessments;
- compliance monitoring activities;
- independent internal reviews where appropriate; and
-
regular AML and financial crime awareness training for
employees.
These measures are reviewed periodically to ensure their
effectiveness and ongoing compliance with regulatory
expectations.
12. Record Keeping and Confidentiality
The Company maintains records relating to customer due
diligence, verification, monitoring activities, transactions,
risk assessments, and regulatory reporting as required under
applicable legislation.
Unless otherwise required by law, such records are retained for
a minimum period of five (5) years following the termination of
the business relationship or the completion of the relevant
transaction, unless a longer retention period is required by
law.
All personal information collected under this Policy is
processed securely and confidentially in accordance with the
General Data Protection Regulation (GDPR) and the Company's
internal information security procedures.
13. Policy Administration
This Policy forms part of the Company's compliance management
framework and is subject to periodic review by the Compliance
function and Senior Management.
The Company may amend this Policy whenever necessary to reflect
legislative developments, regulatory guidance, operational
changes, or enhancements to its financial crime prevention
framework. The latest approved version will be made available
through the Company's official channels.