Aml & Kyc Policy
Policy Objective and Scope
Ffbet maintains an anti-money laundering (AML) and know-your-customer (KYC) framework designed to prevent financial crime, ensure regulatory compliance, and protect customers. This policy applies to all customers, accounts, deposits, withdrawals, transfers to other users, and payment methods used on the Ffbet platform. It governs the collection of customer information, verification of identity, ongoing monitoring of activity, and reporting of suspicious transactions to competent authorities.
Definitions
- Money laundering means the process of converting, transferring, or using funds or assets derived from criminal activity to conceal their illicit origin or to facilitate further wrongdoing; this includes concealing the true nature, source, location, disposition, movement, ownership, or rights in relation to such assets.
- Know-Your-Customer (KYC) and customer due diligence (CDD) refer to the measures taken to identify customers, verify their identity, and assess and monitor their risk profile.
- Source of Funds (SOF) and Source of Wealth (SOW) denote the origin of the funds used in a transaction and the overall wealth of the customer, respectively.
- Ongoing transaction monitoring is the continuous review of customer transactions to identify unusual or suspicious activity relative to the customer’s profile.
- AML Compliance Officer (AMLCO) is the designated senior executive responsible for implementing AML policies and reporting to senior management.
Governance and Compliance
Ffbet places ultimate responsibility for AML compliance with the board of directors. An AMLCO oversees day‑to‑day enforcement of AML policies, procedures, and controls, reporting directly to senior management. Material amendments to this policy require the approval of the AMLCO and the board. The policy is reviewed on an annual basis or as required by changes in law or guidance.
Customer Identification and Verification (KYC) Tiers
- Level 0 — No Verification Customers may initiate deposits up to a cumulative threshold of 2,000 USD. Withdrawals are not permitted until Level 1 verification is completed. This level requires only basic data capture and does not permit withdrawal until a subsequent level is attained.
- Level 1 — Basic Identity Before the first withdrawal, customers must provide and verify core identity data: full name, date of birth, residential address, country of residence, and a valid email address. Data must match the information held by payment processors. Deposits up to 2,000 USD and withdrawals up to 2,000 USD are allowed after successful Level 1 verification.
-
Level 2 — Identity Verification (ID Verification) Triggered automatically when lifetime deposits or withdrawals exceed 2,000 USD or when transfers to another user exceed 1,000 USD. Verification requires:
- Government-issued photo ID (front and back);
- Selfie image of the customer holding the ID with no obstructions; and
- Proof of address from a government or utility document issued within the last three months.
- Level 3 — Source of Funds Verification Triggered when cumulative deposits or withdrawals exceed 50,000 USD or transfers to another user exceed 3,000 USD. Verification requires demonstration of the origin of funds through acceptable evidence (examples include payslips, employment contracts, bank or investment statements, inheritance documents, or other documentation showing lawful origin of funds). Upon notification, customers have 28 days to provide satisfactory documentation; failure to comply may lead to account restrictions or closure. Level 3 allows unrestricted deposits and withdrawals subject to internal risk assessment and ongoing monitoring.
Source of Funds (SOW) and Wealth
Where Level 3 verification applies, Ffbet may request documentation sufficient to establish the lawful origin of funds and the customer’s wealth. Acceptable evidence includes, but is not limited to, employment income documentation, business ownership records, investment statements, inheritance documentation, and bank statements reflecting sources of funds. Ffbet may suspend or terminate the business relationship if the origin or legitimacy of funds remains unclear after reasonable opportunity to respond.
Risk Management
Ffbet applies a risk-based approach to AML controls, categorizing jurisdictions into Low, Medium, and High risk. High-risk regions may be restricted or banned. The enterprise maintains an annual Enterprise-Wide Risk Assessment (EWRA) to identify inherent AML risks across products, customer types, transaction patterns, channels, and geographies. The risk assessment informs the design and adjustment of verification thresholds, monitoring rules, and escalation procedures.
Ongoing Transaction Monitoring
Ongoing monitoring employs a two-line control framework:
- First Line of Control Engagement with trusted payment service providers (PSPs) that maintain robust AML programs to screen deposits at source and trigger initial due diligence on high-risk flows.
- Second Line of Control Internal KYC and transaction monitoring rules are applied to detect unusual activity relative to the customer profile. Transactions that appear atypical may be subjected to enhanced due diligence, freezing of funds where appropriate, and escalation to the AML team for evaluation. A data-driven approach incorporates anomaly detection, cross-checks of deposit and withdrawal patterns, changes in nationality or currency, and other risk indicators.
In all cases, the AMLCO and senior management supervise ongoing monitoring, and any high‑risk or suspicious activity is escalated for additional review.
Suspicious Activity Reporting
Ffbet maintains internal procedures that define when a transaction should be reported to the competent financial intelligence unit (FIU) or equivalent authorities. The AML team assesses reported activity against the customer profile and known risk factors; based on this assessment, a determination is made to report, continue monitoring, or terminate business relations. Records of suspicious activity and related decisions are maintained in accordance with retention requirements and regulatory obligations.
Record Keeping
Ffbet retains customer-identification records for a minimum of ten years following the end of the customer relationship. Transaction records are retained for at least ten years after execution or account closure. All records are stored securely in encrypted formats, with access limited to authorized personnel.
Data Security and Privacy
Customer data is protected by rigorous technical and organizational controls, including encryption in transit and at rest, access controls, and monitoring. Data may be disclosed only with explicit customer consent, as required by law, or to fulfil AML obligations. Ffbet complies with applicable data protection laws in the jurisdictions in which it operates and maintains policies to safeguard personal information.
Training and Awareness
Ffbet provides ongoing AML training to management and staff, with targeted updates for new regulatory requirements and emerging typologies. Training covers identification of red flags, escalation procedures, and the correct application of the KYC tiers and monitoring controls.
Policy Updates and Accountability
This policy is reviewed annually and updated as needed to reflect changes in law, guidance, or business practices. Material amendments require the approval of the AMLCO and the board of directors. All changes are communicated to relevant personnel and implemented with appropriate procedural updates.
Contact
For questions or concerns about this AML & KYC Policy, please contact the compliance team at compliance@ffbet.
