AML/CTF, KYC and KYT Policy
This Policy describes the measures that ASIRU LIMITED (Hong Kong, registration number 80997831; the “Company”, “Service”) applies in the ASIRU service to counter money laundering, terrorist financing and proliferation financing (AML/CTF), to identify customers (KYC/KYB) and to monitor transactions (KYT).
1. Definitions
- AML/CTF — anti-money laundering and counter-terrorist financing.
- KYC / KYB — identification and due diligence of an individual customer / a legal-entity customer, its representatives and ultimate beneficial owners (UBO).
- KYT — monitoring and analysis of digital asset transactions, including risk assessment of addresses and origin of funds.
- EDD — Enhanced Due Diligence applied where risk is elevated.
- PEP — politically exposed person, their family members and close associates.
- SoF / SoW — Source of Funds / Source of Wealth of the customer.
2. Legal framework
2.1. The Company is incorporated in Hong Kong and follows Hong Kong AML/CFT legislation, including: the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615, AMLO); the Organized and Serious Crimes Ordinance (Cap. 455, OSCO); the Drug Trafficking (Recovery of Proceeds) Ordinance (Cap. 405, DTROP); the United Nations (Anti-Terrorism Measures) Ordinance (Cap. 575, UNATMO).
2.2. Hong Kong has been a member of the FATF since 1991 and is a member of the Asia/Pacific Group on Money Laundering (APG); the Company’s procedures are based on FATF international standards, including those for virtual asset service providers.
2.3. ASIRU LIMITED does not hold a Hong Kong VASP/SFC licence and does not claim to; this Policy is applied by the Company voluntarily as part of its internal controls and counterparty requirements.
3. Internal control organisation
- A Compliance Officer is appointed from the Company’s management; contact: george@asiru.capital.
- Staff involved in the procedures receive internal training on KYC/KYB, AML/KYT, sanctions screening, identification of elevated risk and additional checks; training records are kept.
- Specialised external providers are used for AML/KYT transaction analysis and list screening — in particular Crystal, as well as other KYC/AML infrastructure and blockchain analytics providers.
- There is no separate internal audit unit; compliance and effectiveness of procedures are assessed within the compliance function by responsible staff using the results of external providers and internal analysis.
- Results of automated and manual checks are recorded and retained.
4. Risk-based approach
4.1. Each customer is assigned a risk level — Low, Medium or High — taking into account jurisdiction, customer type and nature of activity, KYC/KYB results, ownership structure and UBO, AML/KYT and sanctions results, nature and volume of transactions and other factors.
4.2. Where risk is elevated, additional measures apply: EDD, additional identification of the customer and UBO, SoF/SoW checks, in-depth KYT analysis of transactions and related addresses, additional sanctions and PEP screening, document requests and manual review. The scope of measures depends on the risk identified.
5. Identification and verification (KYC/KYB)
5.1. Individuals. Verification is required for certain exchange directions, above certain limits and when risk-model rules trigger. The identity document (passport) is checked and additional visual/video identity verification is performed.
5.2. Legal entities. KYB is performed: registration details and status, directors and representatives, ownership and control structure (direct and indirect ownership, chain up to the natural person), identification and verification of ultimate beneficial owners; UBOs undergo KYC, AML, sanctions and, where necessary, PEP checks. A customer and beneficial-owner profile is created and retained.
5.3. Specialised KYC providers and aggregators may be used for automated identification.
5.4. Documents for individual verification
- personal data: country, full name (as in passport), phone number;
- photo of the main passport page (with photo and details);
- for citizens of Russia — the passport page with registration; for others — proof of residential address;
- a selfie to confirm identity; video verification where required.
File requirements: clear image without glare, all data legible, JPG, PNG or WebP, up to 10 MB. Review usually takes up to 1 hour during working hours; the result is “verified” or “declined” (with the reason and the option to resubmit).
6. Sanctions and PEP screening
6.1. Customers and related persons (UBOs, directors, representatives) are screened against applicable international and national sanctions lists and official sources, including: OFAC lists and programmes (USA), European Union sanctions lists, the UK Sanctions List / OFSI, United Nations Security Council sanctions lists, Rosfinmonitoring lists (Russia) and other relevant lists. Where relevant, economic and sectoral sanctions are taken into account with regard to jurisdiction, activity and the nature of the transaction.
6.2. Screening is performed predominantly automatically through specialised providers; potential matches and other factors requiring review are escalated to manual review by a responsible employee.
6.3. The Company identifies customers and beneficial owners who are PEPs, as well as their associates. Where a PEP is identified, additional risk assessment is performed and EDD measures apply, including SoF/SoW checks and manual review. PEP handling is part of the Company’s documented procedures.
7. Source of funds and wealth
7.1. Where risk factors are present or as part of EDD, the Company requests documents and/or explanations confirming the Source of Funds or digital assets and, where necessary, the customer’s Source of Wealth and nature of activity. The scope and depth of the check are determined on a risk basis.
8. Transaction monitoring (KYT)
8.1. Every incoming transaction is automatically risk-scored before crediting and payout, based on analysis of the origin of funds and the address’s links to unlawful activity. Reports of specialised providers, in particular Crystal, are used; a report on the check may be provided to the customer on request.
8.2. The result is expressed as a risk score from 0% to 100%:
- 0–24% — low risk: the exchange proceeds normally;
- 25–40% — medium risk: the transaction is admitted, possibly with additional control and information requests;
- above 40% — high risk: the exchange is suspended and the measures in section 9 apply.
8.3. The base threshold is 40%; a stricter threshold may be set for particular networks and directions in line with the internal risk model.
9. Actions when risk is identified
9.1. In the event of high risk, signs of a suspicious transaction, or the customer’s non-compliance with the Terms of Service, the Company may:
- suspend execution of the order and request additional documents and explanations (KYC/KYB, SoF/SoW);
- conduct a manual review and, based on its outcome, execute or decline the order;
- refund the funds to the details (address) from which they were received, less the network fee — where the exchange cannot be executed and there are no grounds for freezing;
- freeze the funds and report to the competent authority — where the funds are linked to sanctioned persons, addresses or services, mixers, darknet marketplaces, stolen assets or show other signs of criminal origin; such funds are not refunded until a decision of the competent authority;
- refuse further service to the customer.
9.2. The Company does not withhold customer funds without grounds provided for by this Policy and applicable law.
10. Reporting and cooperation with authorities
10.1. Where a legal obligation arises, the Company files a suspicious transaction report with the competent authority of Hong Kong — the Joint Financial Intelligence Unit (JFIU) — and complies with lawful requests of authorised bodies. The customer is not informed of a report where such disclosure is prohibited by law.
11. Record keeping
11.1. Documents and information obtained in KYC/KYB and AML checks, including identification data of customers, representatives and beneficial owners, check results and training records, are retained for at least 5 years after the relationship with the customer ends. Personal data of citizens of the Russian Federation is stored using infrastructure located in the Russian Federation (see the Privacy Policy).
12. Changes
12.1. The Company reviews this Policy as legislation, FATF recommendations and its own risk model evolve; the current version is published on this page.