Anti-Money Laundering /
Counter-Terrorism Financing Policy
This policy outlines MothPay's commitment and procedures for preventing money laundering and terrorist financing, applicable to all clients and partners using MothPay services.
1. Policy Purpose & Scope
MothPay is committed to preventing its platform from being used for money laundering, terrorist financing, or any other financial crime.
This policy applies to all MothPay employees, contractors, and all partners accessing services via API or direct agreement.
2. Applicable Regulations
This policy is established in accordance with the following key laws and regulations:
- Hong Kong Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO)
- Singapore Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act (CDSA)
- UK Proceeds of Crime Act 2002 (POCA)
- EU 6th Anti-Money Laundering Directive (6AMLD)
- US Bank Secrecy Act (BSA) and related FinCEN regulations
- Financial Action Task Force (FATF) Recommendations
3. Customer Due Diligence (KYC/KYB)
3.1 Standard Due Diligence (SDD)
For low to medium risk customers, we perform standard due diligence, including:
- Verifying full name, date of birth, nationality, and government-issued ID for individual clients
- Verifying registration information, business license, and director details for corporate clients
- Identifying and verifying Ultimate Beneficial Owners (25%+ ownership)
- Understanding the purpose and nature of the business relationship
- Ongoing monitoring of customer relationships and transaction patterns
3.2 Identity Verification Methods
We accept the following verification methods:
- Passport, national ID, or driver's license (government-issued)
- Certificate of incorporation and articles of association
- Proof of address documents dated within the last 3 months
- Bank statements or utility bills
- eKYC: Liveness detection combined with automated document OCR verification
- Video verification (for high-risk or specific regional clients)
3.3 Ongoing Due Diligence
We periodically review client profiles, with frequency based on risk level: high-risk clients annually, medium-risk every two years, low-risk every three years.
4. Enhanced Due Diligence (EDD)
For the following high-risk scenarios, we perform enhanced due diligence:
- Politically Exposed Persons (PEPs) and their immediate family members and close associates
- Clients from FATF high-risk or non-cooperative jurisdictions
- Single transactions exceeding USD 50,000 or monthly cumulative exceeding USD 200,000
- Clients with unclear business purpose or source of funds
- Non-face-to-face account opening in high-risk regions
- High-risk industry clients (e.g., cryptocurrency exchanges, gambling platforms)
- Clients with historical Suspicious Activity Reports
5. Transaction Monitoring
We deploy automated systems for real-time monitoring of all transactions, focusing on identifying:
- Transactions with unusual amounts or inconsistent with account history
- Multiple transactions close to regulatory reporting thresholds in a short period (structuring)
- Transactions involving high-risk countries or sanctioned regions
- Transaction types or beneficiaries inconsistent with the client's known business
- Frequent changes in beneficiary accounts or target regions
- Large cash equivalent transactions with unclear source or destination
- Transactions linked to blacklisted entities or IP addresses
Transactions triggering monitoring rules will be manually reviewed by the compliance team, with account freezing if necessary.
6. Suspicious Activity Reporting (SAR)
When suspicious activity is identified, our procedures are:
- Any employee discovering suspicious activity must immediately report to the Compliance Officer without disclosing to the subject
- Compliance Officer evaluates within 24 hours and determines whether to open a case
- Confirmed reportable cases are submitted to the relevant Financial Intelligence Unit within the legal timeframe
- Related accounts are frozen during investigation to preserve evidence
- Strict confidentiality throughout the process — no "tipping off" permitted
7. Sanctions Screening
We perform real-time sanctions screening on all clients and counterparties, covering the following lists:
- United Nations: UN Security Council Consolidated Sanctions List
- United States: OFAC SDN List and sector-specific sanctions
- United Kingdom: HM Treasury Financial Sanctions List
- European Union: EU Consolidated Sanctions List
- Hong Kong: Hong Kong UN Sanctions Implementation List
Transactions matching sanctions lists are automatically frozen, and the compliance team is immediately notified.
8. Record Keeping
In accordance with regulatory requirements, we retain the following records for a minimum of five (5) years:
- All customer due diligence documents and identity verification materials
- Complete transaction records (including timestamps, amounts, counterparty details)
- Internal Suspicious Activity Reports and final disposition decisions
- Sanctions screening records and results
- All client communications involving compliance judgments
9. Staff Training
All employees must complete AML/CTF training with the following frequency and content:
- Onboarding: All new employees must complete basic AML training within 30 days of joining
- Annual: Yearly refresher covering the latest regulatory changes and case studies
- Role certification: Compliance, sales, and customer service staff must obtain professional AML certifications
- Drills: Semi-annual suspicious activity identification and SAR submission procedure exercises
- Knowledge tests: Must pass assessment after each training session; retrain if below passing score
- Training records: All completions archived by HR for regulatory inspection
10. Policy Updates
This policy is maintained through the following means:
- Comprehensive review at least annually, or promptly updated when significant regulatory changes occur
- Material changes communicated in advance to all affected employees and partners
- Policy versions and change history fully archived for regulatory review
For questions regarding this policy, please contact us or email service@mothpay.com.