Legal

Anti-Money Laundering Policy

Our framework for preventing money laundering, terrorist financing and sanctions breaches.

Version 1.0|Effective 17 September 2026|Last updated 17 September 2026|Mikupay

Mikupay is committed to preventing the use of its services for money laundering, terrorist financing, proliferation financing, sanctions evasion or other financial crime. This policy summarises the framework we maintain to that end.

We operate a risk-based approach proportionate to the nature, scale and complexity of our business, and to the risk profile of each client relationship.

1. Policy statement

It is our policy to know our clients, to understand the activity we are asked to process, and to decline or exit relationships that we cannot support consistent with our legal obligations and our risk appetite.

This policy applies to all personnel, and to all accounts and transactions, without exception. Responsibility for its implementation rests with senior management.

2. Legal and regulatory framework

We comply with the anti-money laundering, counter-terrorist financing, sanctions and record-keeping requirements applicable to us in the jurisdictions in which we operate and in which our clients are established. Those requirements include obligations to identify clients, monitor activity, retain records, and report suspicions to the competent authorities.

Where the requirements of more than one jurisdiction apply, we apply the more demanding standard where they differ.

3. Risk-based approach

We assess risk at the level of the individual relationship and at the level of the transaction, and apply measures proportionate to that assessment.

  • Client risk factors: nature and location of the business, ownership structure, industry, source of funds, expected activity, and the jurisdictions involved.
  • Transaction risk factors: size, frequency, pattern, counterparties, geography, and consistency with the client’s stated profile.
  • Delivery channel risk: whether the relationship was established in person or remotely, and the reliability of the information available to us.

4. Client due diligence

We identify and verify every client before an account is activated, and we will not activate an account where we cannot satisfactorily complete that process.

  • Identification: obtaining the client’s name, legal form, registration particulars where applicable, and address.
  • Verification: corroborating identity information using reliable, independent sources, including government-issued documentation.
  • Beneficial ownership: identifying the natural persons who ultimately own or control a legal entity, and taking reasonable steps to verify them.
  • Authorised persons: identifying those authorised to give instructions, and the scope of their authority.
  • Purpose and nature: establishing the purpose of the account and the expected nature of the activity to be conducted.

5. Enhanced due diligence

We apply enhanced measures where a relationship presents higher risk. Enhanced measures may include additional identification requirements, corroboration of source of funds and source of wealth, more frequent review, and approval by senior management before the relationship is established or continued.

  • Politically exposed persons, their family members and close associates.
  • Clients established in, or transacting with, higher-risk jurisdictions.
  • Complex or opaque ownership structures, or structures whose rationale cannot be established.
  • Unusually large transactions, or activity materially inconsistent with the client’s profile.

6. Ongoing monitoring

We monitor activity throughout the relationship to confirm that it remains consistent with what we understand about the client, and to identify activity requiring examination.

  • Review of transactions against the client’s stated profile, expected volumes and expected counterparties.
  • Identification of patterns warranting scrutiny, including structuring, rapid movement of funds, and activity inconsistent with the stated business.
  • Examination of flagged activity with the client where appropriate, and documentation of the outcome.
  • Periodic refresh of client information and re-verification, including on a change of ownership, control or activity.

7. Sanctions and screening

We screen clients, beneficial owners and relevant transaction parties against applicable sanctions lists and against lists of politically exposed persons and persons subject to adverse media reporting, at onboarding and on an ongoing basis.

We do not provide services to persons or entities subject to sanctions, or where doing so would breach applicable sanctions, export controls or trade restrictions.

8. Reporting suspicious activity

Where we know or suspect, or have reasonable grounds to suspect, that funds are the proceeds of crime or are related to terrorist financing, we report to the competent authority in accordance with applicable law.

We may be prohibited by law from informing you that a report has been made or that an examination is being conducted. We may also be required to delay or decline a transaction, and to restrict or close an account, in connection with a report.

9. Record keeping

We retain records of client identification, of verification performed, of transactions and of the decisions taken in relation to them, for the periods prescribed by applicable law.

Records are held securely, with access restricted to personnel who require it, and are subject to the retention and deletion controls described in our Privacy Policy.

10. Governance and responsibility

  • A designated compliance function is responsible for the day-to-day operation of this policy.
  • Senior management approves this policy, receives regular reporting on its operation, and is responsible for the resources allocated to it.
  • Duties are segregated, so that onboarding, review and payout approval are not performed by a single individual.
  • Operational actions are recorded in an audit log that captures the actor, the action, the entity affected, and the time.

11. Personnel and training

Personnel receive training on this policy, on applicable legal requirements, and on the identification and escalation of suspicious activity, at induction and at regular intervals thereafter.

12. Prohibited activity and relationships

We do not provide services, and will decline or terminate a relationship, where it involves:

  • breach of applicable sanctions, embargoes or export controls;
  • terrorist financing or proliferation financing;
  • the proceeds of crime, fraud, or tax evasion;
  • unlicensed money transmission, or activity requiring a licence the client does not hold;
  • material misrepresentation of identity, ownership or the origin of funds;
  • a refusal to provide information reasonably required to complete verification or to explain activity.

13. Cooperation with authorities

We cooperate with competent authorities, regulators and law enforcement, including in response to lawful requests for information, and we maintain procedures to receive, assess and act on such requests.

14. Review of this policy

This policy is reviewed at least annually, and whenever there is a material change in applicable law, in our risk assessment, or in the nature of our business. Questions about it may be directed to compliance@mikupay.com.

Version history

Only substantive changes are listed. Superseded versions are retained and are available on request.

  • v1.017 September 2026First published version.

Questions about this document

Our compliance team can answer questions about this policy and can provide supporting documentation about Mikupay to counterparties and their advisers. The list of documents available on request is published on the disclosures page.